Early beta (0.1.0), not yet for critical processes. See the roadmap
PNeX logo

Architecture

How the PNeX stack fits together

PNeX is a single Rust workspace. The same types (pnex-core) compile natively for the server and to WebAssembly for the web app, so the client-server contract is checked at compile time. The same UI code also ships as native apps for Linux, Windows and Android.

Explore the architecture

Click a block for details, follow a request end to end, or light up each security layer.

CLIENTSEDGE · TLSCOREDATAHTTPS · WSSHTTPSWSS · TLS 1.2WSScerts/auth/v1/ · /wsOIDCsuperviseSQL · jobsingest · querylast valuesliveartifacts · mediaWeb appDioxus · WASMNative appsDioxus · same codeDevicesESP32 · ESP8266Your codePublic APITLS edgenginx:443 · one originCertificatesCA · Let’s EncryptIdentityRauthyPNeX serverRust · Loco + SeaORMFlow engineEdgeLink · RustDatabasePostgreSQLTelemetryOpenObserveLive cacheValkeyObject storageS3-compatible
TLS-encrypted on the wire Private internal networkDocker Compose · Helm (coming) · Wolfi (Chainguard) images · Raspberry Pi → cloud

Components

ComponentTechnologyRole
TLS edgenginxSingle HTTPS origin for browsers, native apps and devices; local CA or Let's Encrypt
ServerLoco (Axum, SeaORM)REST + WebSocket API, workers, firmware build service
Web, desktop & mobile appsDioxus (Rust)Every user-facing screen from one codebase: web (WebAssembly), Linux desktop (x86_64, ARM64), Windows desktop (x86_64), Android
Flow runtimevendored EdgeLink, headless Rust binaryExecutes visual flows, supervised and hot-reloaded by the server
TelemetryOpenObserveMetrics and logs, per-organization isolation
Live cacheValkeyInstant last-value reads for charts
IdentityRauthyOIDC single sign-on, JIT provisioning
Object storageAny S3-compatible store (RustFS bundled)Firmware artifacts, media assets
ThermophysicsCoolProp (vendored C++), in-processFluid properties inside flow nodes and diagrams

Three data bricks

PNeX needs exactly three storage bricks: PostgreSQL (configuration, assets and the job queue), OpenObserve (time series and logs) and Valkey (live last values). Queue and workflow needs are covered by Postgres-backed workers and the flow runtime itself.

Server and edge split

The server stores data, builds firmware, casts configurations and never writes pins on its own. Today devices run in connected mode: flows drive them through the server. Autonomous devices — configuration cast onto the device, local regulation that survives server or internet outages — are coming, followed by a device-to-device mesh. See flows.

See Self-hosting for deployment options per tier.

On this page