AstroBaaS

Presentation · August 2026

The technical
blueprint.

Fifteen slides on how AstroBaaS is put together and why it is put together that way — the same argument the documentation makes, drawn rather than written. Read it here, or take the file and present it yourself.

Before you read it

This deck was made on 30 August 2026 and is republished as it was. One thing in it has since moved: slide two says Astro 6, and the engine has been on Astro 7since. Everything else still describes the system that ships — and where the deck and the documentation ever disagree, the documentation is the one that is checked against the code on every push.

  1. Title slide. A server, drawn in exploded view, with four labelled layers stacked above it: API, CMS, Auth, Commerce.
    01AstroBaaS: the precision-engineered backend
  2. React, Vue, Astro and AI agents all point at a single unified API seam in front of one SSR application containing Auth, Storage, REST API, Content Admin and Data.
    02One unified engine replaces the fragmented stack
  3. Four rules as cards: integer money (amount_cents), zero inline scripts (hash-based CSP), deny-by-default (explicit scopes), atomic mutations (reserveStock).
    03Absolute strictness prevents structural failures
  4. The application layer sits above a storage interface seam that feeds three drivers: lowdb for local development, libSQL for portable and edge deployments, and relational SQL for multi-writer production.
    04A pluggable persistence seam scales with your deployment
  5. Three concentric rings: a hash-based CSP on the outside, scoped API keys in the middle, and 2FA with secret-free settings at the centre.
    05Defence in depth is built into the foundation
  6. A table comparing code plugins and declarative plugins across installation, execution, capabilities and security posture.
    06Extensibility splits by privilege and execution
  7. A JSON manifest passes through a schema validator and is interpreted onto metadata, CSS injection and webhooks; a red path shows eval() and dynamic import refused.
    07Extend the system without executing arbitrary code
  8. Three concurrent checkout requests meet a database mutex: one decrements stock where stock is above zero, the other two receive 409 Conflict.
    08Atomic inventory mutations structurally prevent overselling
  9. A payment webhook is admitted only after the signature verifies, the fetched-back record matches, and amount and currency agree; anything else is rejected and audited.
    09A strict validation state machine protects revenue
  10. An optical rules engine validating dioptres and cylinders docks onto a generic commerce core through a plugin hook, and the core degrades to standard commerce without it.
    10Complex domain logic docks into a pristine generic core
  11. The core connects to headless frontends through a typed SDK, to third-party services through a documented REST API, and outward through signed, retried webhooks.
    11A hardened perimeter connects the backend to the outside world
  12. An AI agent exchanges JSON-RPC over standard I/O with a bundled Model Context Protocol server, which validates and authorises before performing scoped CRUD.
    12AI models read and operate the backend natively
  13. Three panels: locale-prefixed URL routing from one template set, consent-gated queuing before any third-party script loads, and GDPR erasure that scrubs personal data while keeping order records for accounting.
    13Localisation and privacy compliance operate at scale
  14. A GPL-3.0 core carries a contributor licence agreement, and proprietary commercial verticals sit on top of it as separate modules.
    14Structural synergy between open source and commercial viability
  15. Closing slide: the whole architecture as one schematic, from the storage core out to the commercial verticals.
    15A meticulously engineered foundation, ready for deployment

Where the detail is

Every claim on these slides is written out, at length, in the documents the repository ships — the storage drivers, the plugin platform, the commerce integrity rules, the compliance work. The documentation is generated from those files, so it cannot drift from them.

Or read the code

The deck describes an architecture; the repository is that architecture. It is GPL-3.0, public, and you can run it on your own machine in about ten minutes —the six steps are here.