--- type: overview tags: [parking, overview, synthesis] sources: [parking-system-architecture] updated: 2026-06-21 --- # Parking System — Overview The synthesis / entry point for this wiki. Start here, then follow links. Catalog of every page: [[index]]. Source summaries: [[parking-system-architecture]]. ## What it is A **parking-management web application** running on a **dedicated, hardened Linux appliance** deployed on-site at a parking facility. Two forces shape nearly every decision: 1. **[[offline-first]]** — a park may be air-gapped; nothing core may depend on a network. 2. **[[threat-model]]** — the primary adversary is the **legitimate operator at the booth**, not an outsider. The classic fraud is *take the cash, delete the record.* ## The architecture in one pass - **Stack** ([[technology-stack]] / [[standing-decisions]]): [[turborepo]] · [[fastify]] · [[react-vite-spa]] · [[sqlite]] + [[drizzle-orm]] · [[local-jwt-auth]] — all open-licensed to avoid lock-in (cf. rejected [[payload-cms]], [[refine]], [[logto-zitadel-oidc]]). The operator UI ships as a thin **[[desktop-shell-tauri|Tauri v2]]** kiosk shell (chosen over Electron). - **Integrity** is the heart of it: an [[append-only-event-chain]] (hash-chained, signed) plus external [[reconciliation]] — *that's* what remote sync really is. Signing is **software today** (key on-disk → forgeable by a host owner); a non-extractable **hardware signer** (TPM / USB-HSM; the [[atecc608]] is upcoming) is the pending fix — [[hardware-signer-options]]. Encryption at rest ([[disk-os-hardening]]) defends a secondary threat. - **Devices** sit behind a [[device-adapter-pattern]] (swap hardware → new adapter only), with the [[barrier-not-a-door]] safety principle keeping physical safety in barrier-operator firmware. - **Access control** today is the **[[dingtian-relay]]** relay+input controller behind [[network-isolation]] — chosen because its inputs are **decoupled from its relays**, enabling host-in-the-loop ticket-first entry (resolving [[access-controller-button-flow]]). The [[uhppote-controller]] and [[zkteco-controller]] were evaluated and **rejected** (historical). The deeper fork is still the [[trust-boundary]] ([[uhppote-vs-esp32|detection vs. prevention]]); the [[esp32-custom-controller]] remains the prevention-grade alternative. - **Readers** split two ways ([[entry-exit-readers]]): permit holders via [[wiegand]] (autonomous), casual/transient via host-side [[lpr-camera]] / QR; both can share a relay. - A reference [[bom]] lists recommended devices. ## Where it stands 6 [[open-questions]] still drive procurement — most critically **lane topology**, **failure modes (fail-open on exit)**, the **reconciliation channel**, and **backup/durability**. ## Reading paths - *Security-first:* [[threat-model]] → [[append-only-event-chain]] → [[reconciliation]] → [[uhppote-vs-esp32]]. - *Hardware-first:* [[bom]] → [[dingtian-relay]] → [[access-controller-button-flow]] → [[entry-exit-readers]]. - *Stack-first:* [[technology-stack]] → [[offline-first]] → [[device-adapter-pattern]].