← Ventures — GCStore Constellation

GCStore Core — Level-2 Deep Dive

GCStore Core is the constellation's central component: the single source of truth for customer identity, entitlement, app catalog, licensing and delivery. Every product — the desktop Hub fleet, the web SaaS apps, the storefront — delegates the same two questions to it: who is this customer, and what may they do? It answers with short-lived signed tokens and server-side decisions; no client is ever trusted to decide anything.

GCStore Core Level-2 internal architecture

Internal architecture

Four API surfaces over a shared core, one small Go binary:

Behind the surfaces:

Design decisions worth naming

Interfaces

WithProvidesConsumes
Hub fleetdevice auth, signed leases/packages, push contentdevice claims (license, fingerprint, TPM)
Web appsscoped Ed25519 app tokens, published key set, per-content video gateverified Keycloak bearers
Storefrontpurchase context: identity, eligibility (denylist), profile, documentsverified Keycloak bearers
ERPthe whole admin API (cockpit), customer reconciliationadmin operations
Keycloakrole projection, user sync/backfillOIDC token verification, profile events (webhook + poll)

Tech stack

Go · MySQL via sqlc (typed SQL, versioned migrations) · Ed25519/JWS (RFC 7515/8037) · OIDC (customers realm) · Docker multi-stage → distroless · host nginx TLS front · companion Java: the in-house Keycloak SPI event-listener provider.

Status & near roadmap

Production — serving the Hub fleet, GCruiter, GCflix and the storefront today. Near roadmap: payment-confirmed grant flow (checkout → entitlement), ERP-driven customer import (past marketplace buyers → invited accounts), finer per-content denial reasons, and viewing-session validation/concurrency caps for video.