Dental Platform · Internal Docs
ArchitectureDecision records (ADR)

Architecture Decision Records

20 accepted decisions. ADRs are immutable; changes require a superseding ADR.

Owner: Platform EngineeringLast reviewed:

Format: [MADR-lite]. Status one of Proposed / Accepted / Superseded. Every ADR lists context, decision, consequences. ADRs are immutable once accepted; changes require a superseding ADR.

#TitleStatus
0001pnpm + Turborepo + go.work monorepoAccepted
0002Go modular-monolith core-api with focused satellite servicesAccepted
0003Next.js App Router apps with BFF cookie sessions (no browser tokens)Accepted
0004PostgreSQL 18 with row-level security for tenant isolationAccepted
0005NATS JetStream for durable async events and jobsAccepted
0006Redis for cache, rate limits, idempotency — never source of truthAccepted
0007MinIO tenant-prefixed object storage with opaque keysAccepted
0008Keycloak 26 OIDC with passkeys, TOTP fallback, recovery codesAccepted
0009OpenBao for secrets and envelope-encryption KEKsAccepted
0010RKE2 + Cilium + Envoy Gateway + Coraza on Canadian metalAccepted
0011Single ai-gateway with AI_PHI_MODE privacy gate and pinned model routingAccepted
0012Hash-chained append-only audit and approval eventsAccepted
0013Immutable versioning for transcripts, notes, plans, templates, documentsAccepted
0014ContextIsland driven by an explicit typed state machineAccepted
0015Hugeicons Stroke Rounded behind a semantic AppIcon registryAccepted
0016Envelope encryption: per-tenant DEKs wrapped by OpenBao KEKsAccepted
0017Integration adapters behind a uniform port with sandbox fixturesAccepted
0018REST + NATS only; ConnectRPC deferred until a justified need existsAccepted
0019pgx repositories with hand-reviewed SQL instead of sqlc codegenAccepted
0020Built-in evidence-package e-signature; provider abstraction for QESAccepted