--- type: overview tags: [parking, overview, synthesis] sources: [parking-system-architecture] updated: 2026-06-14 --- # Parking System — Overview The synthesis / entry point for this wiki. Start here, then follow links. Catalog of every page: [[index]]. Source summaries: [[parking-system-architecture]]. ## What it is A **parking-management web application** running on a **dedicated, hardened Linux appliance** deployed on-site at a parking facility. Two forces shape nearly every decision: 1. **[[offline-first]]** — a park may be air-gapped; nothing core may depend on a network. 2. **[[threat-model]]** — the primary adversary is the **legitimate operator at the booth**, not an outsider. The classic fraud is *take the cash, delete the record.* ## The architecture in one pass - **Stack** ([[technology-stack]] / [[standing-decisions]]): [[turborepo]] · [[fastify]] · [[react-vite-spa]] · [[sqlite]] + [[drizzle-orm]] · [[local-jwt-auth]] — all open-licensed to avoid lock-in (cf. rejected [[payload-cms]], [[refine]], [[logto-zitadel-oidc]]). - **Integrity** is the heart of it: an [[append-only-event-chain]] (hash-chained, [[atecc608]]- signed) plus external [[reconciliation]] — *that's* what remote sync really is. Encryption at rest ([[disk-os-hardening]]) defends a secondary threat. - **Devices** sit behind a [[device-adapter-pattern]] (swap hardware → new adapter only), with the [[barrier-not-a-door]] safety principle keeping physical safety in barrier-operator firmware. - **Access control** hinges on the [[trust-boundary]] fork: [[uhppote-vs-esp32|detection vs. prevention]]. Today: [[uhppote-controller]] behind [[network-isolation]], its open [[uhppote-udp-protocol]] contained, its log made trustworthy by [[event-log-ingestion]]. Upgrade path: the [[esp32-custom-controller]] with [[challenge-response-auth]] and [[fail-state-safety]]. - **Readers** split two ways ([[entry-exit-readers]]): permit holders via [[wiegand]] (autonomous), casual/transient via host-side [[lpr-camera]] / QR; both can share a relay. - A reference [[bom]] lists recommended devices. ## Where it stands 6 [[open-questions]] still drive procurement — most critically **lane topology**, **failure modes (fail-open on exit)**, the **reconciliation channel**, and **backup/durability**. ## Reading paths - *Security-first:* [[threat-model]] → [[append-only-event-chain]] → [[reconciliation]] → [[uhppote-vs-esp32]]. - *Hardware-first:* [[bom]] → [[uhppote-controller]] → [[entry-exit-readers]] → [[esp32-custom-controller]]. - *Stack-first:* [[technology-stack]] → [[offline-first]] → [[device-adapter-pattern]].