Fernando Jose Capeletto Neto
Electronics Systems Engineer, Software Development Engineer  
CV - Education - Credentials - Extension - Cover Letter - GPS Curriculum

             

U.S.A. Green Card Holder
E.U. Citizenship

i.am@fernando.engineer



Ventures — The GCStore Constellation

GCStore is the software venture of Gabriel Capeletto LLC: a constellation of products in production — an app store with device-bound licensing shipped on every machine the company sells, a live marketplace storefront, SaaS products (recruiting, video), and a market-data platform — built from scratch by one engineer, orchestrated around GCStore Core, a single identity & entitlement authority.

This page is the Level-1 system design: the components, their trust boundaries, and the integration fabric that binds them — a living portfolio of systems that are selling and serving real customers today, not a lab exercise.

GCStore Constellation — Level-1 System Design

The components

Each component name below links to its Level-2 deep dive: internal architecture, the design decisions and rejected alternatives behind it, interfaces, stack and roadmap — with its own internal diagram in the same visual language as the constellation map above.

  1. GCStore Core
    • Source of truth for customer identity, entitlement, app catalog, licensing & delivery across every product.
    • Mints short-lived Ed25519 (EdDSA) tokens that apps verify offline; projects entitlement into Keycloak roles; serves the admin API the ERP drives.
    • Composable entitlement: plans grant scopes and include other plans (store → app → feature) — new tiers are data, not code.
    • Go · MySQL (sqlc, typed SQL, versioned migrations) · Docker multi-stage → distroless.
  2. GCStore Hub — production
    • Desktop client installed on every machine the company sells — an app-class runtime, not just an installer: installable apps, in-hub web apps, and a descriptor-driven API client that renders third-party API apps with no per-app client code (live end-to-end against GCruiter).
    • Device-bound licensing: the license key is the identity anchor, the hardware fingerprint is advisory, and the TPM endorsement key is a hardware-attestation tier; entitlement leases are Ed25519-signed and verified offline.
    • Push channel to the installed fleet: offers published from the ERP admin arrive as notifications (the GC Deals inbox). Self-updating fleet (Velopack); releases ship via GitHub Actions on tag. Untrusted by design — every decision is server-side.
    • C# / .NET · Avalonia (Windows) · Velopack · GitHub Actions release pipeline · public contract repo.
  3. GCStore Shop — production, expanding daily
    • The marketplace storefront, live with real products fed by the ERP's listings — and a full PWA: installable on Android/iOS, offline shell, web push (back-in-stock, order-shipped) from the same events that send email. It also runs Milton, an AI seller embedded on every page. He is signed-in only, answers from the whole published catalogue rather than from a search over it, and never writes a price: he names a machine and a configuration, and the storefront resolves the figure through the same code the checkout uses.
    • Public anonymous catalog; identified checkout; payments live — PayPal (cards included) and Zelle, signature-verified webhooks, processing fee passed through as a fee-free-method discount. Server-side durable cart (merges the browser cart on sign-in); destination-based tax via the state authority's live lookup with a committed quarterly fallback, plus address verification.
    • Centerpiece: highly configurable products — a base listing carries options and per-variant pricing, so the buyer composes the exact machine and the catalog stays manageable.
    • Catalog is a projection of the ERP (notify-then-fetch, versioned listings); sales are reported back through a transactional outbox (retry/backoff — an ERP outage loses nothing); identity & purchase eligibility come from GCStore Core at checkout.
    • Java 21 / Spring Boot (API) · Angular (SSR rendering service) · MariaDB · Liquibase · OAuth2 resource server.
  4. GCruiter — production
    • Candidate-facing job-search + skills-matching SaaS: aggregates live postings from employer ATS platforms, normalizes them, builds a skills ontology from open data (ESCO / O*NET / Wikidata / Stack Overflow), and matches a résumé against postings.
    • Runs both token models at once: GCStore Core Ed25519 app tokens verified offline (JDK-native crypto) on the API surface, and Keycloak OIDC on the user/admin surfaces. A locked response renders the entitlement paywall from the returned offer — the product's web entry gate. Roles projected by GCStore Core from purchased plans.
    • Java 21 / Spring Boot · Angular (oidc-client-ts) · MariaDB — read/write-split JPA datasource.
  5. GCflix — production
    • Video-on-demand platform serving its first title in production: Enfermeira Remota ("Remote Nurse" — how to turn clinical experience into remote opportunity), a professional-training live workshop by Nurse Cristiane (Cristiane Capeletto), sold within the company's services.
    • Entitlement-gated per content item: GCStore Core issues tokens carrying the viewing session and the licensee identity that GCflix paints over the video as an anti-sharing deterrent; GCflix owns the catalogue and media storage/transcode/serving.
    • Media plane: the application signs a short-lived, asset-scoped credential; the nginx edge verifies it and serves the bytes directly from disk — streaming load never touches the application tier. The same encode also produces an audio-only medium (the podcast / in-car direction).
    • Go · React 18 + Vite/TypeScript · MariaDB · nginx edge-verified media serving.
  6. GCStocks Stream — pre-production, commercial data licensing underway
    • Real-time market-data backend — ticks · quote · candles · fundamentals · news (ticks/news streamed, everything also as REST pull) — a multi-source aggregation hub with a subscription control plane.
    • Sources sit behind a MarketSource abstraction, so the licensed commercial feed is a drop-in — no pipeline change. A relational read-model (last price, history, per-symbol stats) and volume-gated catalog data-mining focus a capped vendor budget on a volatility-ranked working universe.
    • Foundation for capital-markets features: GCStocks provides the marks; the ERP consumes them to value open positions (intraday/daily).
    • Java 21 · Spring Boot WebFlux (reactive) · Maven monorepo (contracts / simulator / aggregator) · WebSocket→SSE.
  7. ERP — the control plane — production
    • The operational control plane of the LLC: purchasing → inventory → sales → COGS → KPIs → fiscal close. The fiscal/KPI layer is view-derived — one source of truth, no parallel bookkeeping.
    • Owns product truth: listings, options/variants, and a content-addressed media library — photos are ingested into its own store (SHA-256 addressed) and re-served from its own domain, so the catalog never depends on an external host.
    • Also the admin cockpit for GCStore Core (proxies its admin API) — including publishing the offers pushed to the Hub fleet. Internal operators authenticate in a dedicated staff realm, never mixed with the customer realm.
    • Python / FastAPI · SQLAlchemy Core (privilege-split read/write) · Angular · MariaDB.
  8. Identity — Keycloak — production
    • Single customer identity provider (dedicated realm) for every web surface: OIDC Authorization Code + PKCE, one public client per app, single sign-on across the constellation.
    • Two-way sync with GCStore Core: GCStore Core owns the customer record; a custom Java event-listener SPI provider (built in-house) webhooks profile changes back in real time, with polling as backup and per-change history snapshots.
    • Keycloak · custom Java SPI provider jar.
  9. Shared Data Plane
    • One MariaDB container serves the app schemas (GCruiter · GCflix · Shop · GCStocks), reached container-to-container over a shared Docker network — no host hop. The ERP and GCStore Core keep their own databases.

Platform conventions



Archive: the previous generation of this page — the DevOps Laboratory Portfolio (Combat Management System simulator: AIS/NMEA decoding, Kafka, AVRO contracts, Jenkins/SonarQube/Nexus pipelines) — remains available as the record of the Lab era.