Architecture Overview
jokowipe.id is a multi-tenant SaaS platform designed for reliability, security, and scalability. This document describes the high-level architecture.
System Architecture
Component Responsibilities
Control Plane (Go API)
- Authenticates agents and API clients
- Dispatches backup jobs to agents via long-polling
- Stores backup metadata in PostgreSQL
- Injects job results into ClickHouse for analytics
- Manages multi-tenant organization isolation
- Enforces plan limits
Agents
- Execute backup commands locally
- Stream status updates to the API
- Upload backup files directly to customer storage
- Perform retention cleanup
- Report health metrics
Background Workers
- Scheduler: Evaluates cron expressions and enqueues backup jobs at the right time
- Cleanup: Purges expired backup metadata and files
- Anomaly Detection: Queries ClickHouse for statistical deviations and calls the AI API
Data Isolation
Each organization's data is logically isolated using organization_id foreign keys across all database tables. Row-level security is enforced at the API layer — no cross-organization data access is possible.
Key Design Principles
| Principle | Implementation |
|---|---|
| Zero data custody | Backup files never touch jokowipe.id servers |
| Zero inbound ports | Agents communicate outbound-only |
| Encryption at rest | All database fields encrypted, secrets in Vault |
| Encryption in transit | TLS 1.3 enforced for all communication |
| Least privilege | Fine-grained RBAC, short-lived tokens |
| Defense in depth | WAF, rate limiting, input validation, audit logging |
Regions
jokowipe.id is deployed in AWS ap-southeast-1 (Singapore) as the primary region. The data plane (your backups) lives wherever your storage is — the control plane latency only affects job dispatch and monitoring, not backup throughput.
Enterprise plans can request dedicated instances in specific regions.