GCStore is the software venture of Gabriel Capeletto LLC: a constellation of products in production —
an app store with device-bound licensing shipped on every machine the company sells, a live marketplace storefront,
SaaS products (recruiting, video), and a market-data platform — built from scratch by one engineer, orchestrated
around GCStore Core, a single identity & entitlement authority.
This page is the Level-1 system design: the components, their trust boundaries, and the integration fabric
that binds them — a living portfolio of systems that are selling and serving real customers today, not a lab exercise.
The components
Each component name below links to its Level-2 deep dive: internal architecture, the design decisions and rejected alternatives behind it, interfaces, stack and roadmap — with its own internal diagram in the same visual language as the constellation map above.
Desktop client installed on every machine the company sells — an app-class runtime, not just an installer: installable apps, in-hub web apps, and a descriptor-driven API client that renders third-party API apps with no per-app client code (live end-to-end against GCruiter).
Device-bound licensing: the license key is the identity anchor, the hardware fingerprint is advisory, and the TPM endorsement key is a hardware-attestation tier; entitlement leases are Ed25519-signed and verified offline.
Push channel to the installed fleet: offers published from the ERP admin arrive as notifications (the GC Deals inbox). Self-updating fleet (Velopack); releases ship via GitHub Actions on tag. Untrusted by design — every decision is server-side.
The marketplace storefront, live with real products fed by the ERP's listings — and a full PWA: installable on Android/iOS, offline shell, web push (back-in-stock, order-shipped) from the same events that send email. It also runs Milton, an AI seller embedded on every page. He is signed-in only, answers from the whole published catalogue rather than from a search over it, and never writes a price: he names a machine and a configuration, and the storefront resolves the figure through the same code the checkout uses.
Public anonymous catalog; identified checkout; payments live — PayPal (cards included) and Zelle, signature-verified webhooks, processing fee passed through as a fee-free-method discount. Server-side durable cart (merges the browser cart on sign-in); destination-based tax via the state authority's live lookup with a committed quarterly fallback, plus address verification.
Centerpiece: highly configurable products — a base listing carries options and per-variant pricing, so the buyer composes the exact machine and the catalog stays manageable.
Catalog is a projection of the ERP (notify-then-fetch, versioned listings); sales are reported back through a transactional outbox (retry/backoff — an ERP outage loses nothing); identity & purchase eligibility come from GCStore Core at checkout.
Candidate-facing job-search + skills-matching SaaS: aggregates live postings from employer ATS platforms, normalizes them, builds a skills ontology from open data (ESCO / O*NET / Wikidata / Stack Overflow), and matches a résumé against postings.
Runs both token models at once: GCStore Core Ed25519 app tokens verified offline (JDK-native crypto) on the API surface, and Keycloak OIDC on the user/admin surfaces. A locked response renders the entitlement paywall from the returned offer — the product's web entry gate. Roles projected by GCStore Core from purchased plans.
Video-on-demand platform serving its first title in production: Enfermeira Remota ("Remote Nurse" — how to turn clinical experience into remote opportunity), a professional-training live workshop by Nurse Cristiane (Cristiane Capeletto), sold within the company's services.
Entitlement-gated per content item: GCStore Core issues tokens carrying the viewing session and the licensee identity that GCflix paints over the video as an anti-sharing deterrent; GCflix owns the catalogue and media storage/transcode/serving.
Media plane: the application signs a short-lived, asset-scoped credential; the nginx edge verifies it and serves the bytes directly from disk — streaming load never touches the application tier. The same encode also produces an audio-only medium (the podcast / in-car direction).
Go · React 18 + Vite/TypeScript · MariaDB · nginx edge-verified media serving.
GCStocks Stream — pre-production, commercial data licensing underway
Real-time market-data backend — ticks · quote · candles · fundamentals · news (ticks/news streamed, everything also as REST pull) — a multi-source aggregation hub with a subscription control plane.
Sources sit behind a MarketSource abstraction, so the licensed commercial feed is a drop-in — no pipeline change. A relational read-model (last price, history, per-symbol stats) and volume-gated catalog data-mining focus a capped vendor budget on a volatility-ranked working universe.
Foundation for capital-markets features: GCStocks provides the marks; the ERP consumes them to value open positions (intraday/daily).
The operational control plane of the LLC: purchasing → inventory → sales → COGS → KPIs → fiscal close. The fiscal/KPI layer is view-derived — one source of truth, no parallel bookkeeping.
Owns product truth: listings, options/variants, and a content-addressed media library — photos are ingested into its own store (SHA-256 addressed) and re-served from its own domain, so the catalog never depends on an external host.
Also the admin cockpit for GCStore Core (proxies its admin API) — including publishing the offers pushed to the Hub fleet. Internal operators authenticate in a dedicated staff realm, never mixed with the customer realm.
Single customer identity provider (dedicated realm) for every web surface: OIDC Authorization Code + PKCE, one public client per app, single sign-on across the constellation.
Two-way sync with GCStore Core: GCStore Core owns the customer record; a custom Java event-listener SPI provider (built in-house) webhooks profile changes back in real time, with polling as backup and per-change history snapshots.
Keycloak · custom Java SPI provider jar.
Shared Data Plane
One MariaDB container serves the app schemas (GCruiter · GCflix · Shop · GCStocks), reached container-to-container over a shared Docker network — no host hop. The ERP and GCStore Core keep their own databases.
Platform conventions
Trust boundary first: public clients are assumed hostile; entitlement is always decided server-side. Contracts live in a public repo and are the single source of truth per boundary.
One server-side deploy pattern: Docker Compose per stack behind a host nginx that owns TLS; services publish loopback-only ports; every secret lives in an env file with fail-fast guards — never in git. Go services ship as distroless images.
Client-side release pattern (Hub): tag-triggered GitHub Actions builds the release; the installed fleet self-updates.
Typed data access (sqlc in Go, JPA in Java), versioned SQL migrations, append-only history where auditability matters.
Archive: the previous generation of this page — the DevOps Laboratory Portfolio
(Combat Management System simulator: AIS/NMEA decoding, Kafka, AVRO contracts, Jenkins/SonarQube/Nexus pipelines) — remains available as the record of the Lab era.