← Ventures — GCStore Constellation
GCflix — Level-2 Deep Dive
GCflix is the constellation's video-on-demand platform: customers who bought a recording sign in with their store identity and watch it in the browser. Access is decided per content item — not per account, not per app — so a single lecture, a whole collection, or the entire catalogue can each be sold as its own thing without any code change. GCflix owns the media: ingest, transcoding, storage and delivery. It owns no entitlement whatsoever; it enforces what GCStore Core tells it. Its first title is in production: Enfermeira Remota ("Remote Nurse"), a professional-training live workshop by Nurse Cristiane (Cristiane Capeletto), sold within the company's services.
Internal architecture — three planes that meet only at a token
- The application plane is a single Go binary. It serves the catalogue API, the playback authorisation call, viewer progress and telemetry, and the built front end. It holds a small resident footprint and starts instantly, which matters because it shares a host with the rest of the constellation.
- The media plane is an HLS library on disk, served directly by nginx and authorised at the edge. The application signs a credential; it never proxies a media byte. This is the single most consequential decision in the design: a lecture streaming to a room full of viewers costs the application process nothing, because the bytes go from disk to socket inside the kernel and the Go service never learns anyone is watching.
- The auth plane: the identity provider authenticates the human, GCStore Core decides and mints a short-lived Ed25519 token, and GCflix verifies that token offline against GCStore Core's published key set. There is no callback to GCStore Core on the request path. The key-set client caches, refreshes on a schedule, and re-fetches on an unrecognised key id — which makes key rotation at GCStore Core a non-event here rather than a coordinated deploy.
Inside the service: a token verifier (Ed25519 JWS validated with the standard library only, algorithm pinned — closing the algorithm-confusion class of attack outright); scope authorisation (default deny; content keys constrained to a strict alphabet because they are interpolated into scope strings — the constraint is a security control, not a style rule); a media credential signer (edge-verifiable, scoped to exactly one asset version, short-lived — with a dev-mode handler that validates the identical construction in Go, so drift between app and edge fails on a laptop instead of in production); and the catalogue store (collections, modules, sessions, chapters, media assets, viewer progress, telemetry).
Design decisions worth defending
- GCStore Core does not sign media access. The original brief had it issuing signed manifest URLs. GCflix proposed the opposite and GCStore Core ratified it: GCStore Core asserts entitlement, GCflix derives media access from the verified assertion. Otherwise the two systems would share a signing secret across a trust boundary, and GCStore Core would be coupled to a storage layout that is guaranteed to change.
- A credential scoped to an asset prefix, not per-URL signatures. An adaptive manifest lists hundreds of segments; signing each URL means generating the manifest per request with a signature on every line. One credential covering the asset prefix costs one signature, refreshes in one response header, and maps cleanly onto the renewal loop that has to exist anyway.
- Constant-quality encoding with a ceiling, not an average-bitrate target — measured on the real content. Targeting an average makes the encoder chase a number: it pads bits into a motionless slide and rations them when the picture finally moves. Constant quality with a peak ceiling produced visually indistinguishable output at roughly a quarter of the bytes. Profiling showed keyframes were 57% of all bytes, so segment length was raised to cut their frequency, for another 17%. A three-hour recording ships in about a seventh of what a conventional fixed-bitrate ladder would cost — on a host where bandwidth is the binding constraint, the difference between viable and not.
- One shared audio track that doubles as a medium. Audio is encoded once and referenced by every video variant. The same encode is also offered as an audio-only stream: a full listen costs about a fifteenth of watching — for lecture content a legitimate way to consume it, and it gives adaptive bitrate somewhere to go on a bad connection other than stalling.
- Versioned assets with an atomic publish. A re-encode is built alongside the live one and goes live by moving a single pointer inside a transaction. Viewers mid-playback are unaffected — their credential names the previous version, whose files are still on disk. Rollback is the same move backwards. Publishing never deletes.
- No customer record. The database holds no name, email, password, plan or price. The only identity persisted is the opaque subject from the identity provider. The licensee details shown on screen arrive inside the token, are rendered, and are never written to disk — the sensitive data stays borrowed, not owned.
- The entitlement check is deliberately redundant. GCStore Core has already decided; GCflix re-checks what the token actually says. It costs a map lookup and is the difference between trusting an issuer and verifying an assertion — if GCStore Core ever over-issues, the blast radius stops here.
- Failure modes are kept distinguishable. An expired media credential and an invalid one return different statuses, because the player must renew on one and stop on the other. Denial reasons are split by who can actually know: GCStore Core owns entitlement refusals; GCflix owns "this content does not exist" and "not published yet", because GCStore Core treats content identifiers as opaque.
- A contract double that deliberately shares no code. A local stand-in implements the boundary contract literally — every denial reason, and a short token lifetime so the renewal loop is exercised many times inside a short clip. A double that shares the app's code cannot catch the app misreading the contract.
The player
Raw hls.js over a plain video element — no off-the-shelf player. The licensee overlay and the timeline-synchronised activities on the roadmap need full control of the render layer. The player runs the renewal loop (the token expires long before a feature-length recording ends, and each renewal re-resolves entitlement from scratch at GCStore Core), reports playback quality — stalls and quality switches are the direct measurement of whether the host is keeping up — and persists resume position and a separately tracked furthest point, so completion cannot be faked by dragging the scrubber.
The anti-sharing overlay names the licensee over the video and moves so a static crop cannot remove it. Its values come from signed claims, so altering them means forging a signature. It is a social deterrent, described exactly as such — a deliberate engineering-honesty stance in the design.
Interfaces
- Identity provider: OIDC Authorization Code + PKCE against the shared customers realm, one public client. GCflix asks for identity and nothing else; it never consults the provider on its own API path.
- GCStore Core — two calls: a delivery request carrying the content identifier and, on renewal, the viewing-session identifier; and the published key set, fetched and cached for offline verification. Refusals come back as a structured denial that GCflix relays to the lock screen: GCStore Core owns commerce, so GCflix holds no prices, no plans, no purchase rules — it renders what it is given.
- The edge: GCflix and its nginx configuration share one signing construction, enforced on every segment — the only secret GCflix shares with anything, and it is shared with its own edge, not across a system boundary.
- Shared database: its own schema, typed access, versioned migrations applied deliberately. The application's database user holds no schema-altering rights, so a container restart can never alter the schema.
Tech stack
Go service (standard-library HTTP routing, no web framework; standard-library cryptography, no JWT library) · React 18 + Vite + TypeScript front end with hls.js · MariaDB · ffmpeg for the adaptive ladder · nginx for TLS and the media plane · Docker multi-stage build with vet and tests inside the build stage, shipping a distroless non-root image; the media library lives outside the image so a rebuild never touches gigabytes of video.
Status & roadmap
In production, serving Enfermeira Remota end to end: login, per-content gate, adaptive streaming, licensee overlay, token renewal across a multi-hour session, and playback telemetry.
Roadmap — the chokepoints are already in place: chapters for the live recording (schema and player ready); the audio-only mode in the player UI (already produced and served by the API); the admin publishing interface (the pipeline runs as a specified command-line procedure today); the timeline-synchronised interactive layer (quizzes, exercises — already modelled in the schema); and the concurrency/device cap, which attaches to the renewal call with no change on the wire. Burned-in watermarking is the answer recorded for the one platform boundary worth naming: iOS-Safari fullscreen hands playback to the system player, where no overlay can follow.