Battle-hardened Rails 8 API foundation with Devise JWT, IAM/RBAC, Stripe subscriptions, Solid Queue workers, Action Cable WebSockets, DeepSeek AI, Monitoring Dashboards and client telemetry.
JavaScript
5
433 commits
updated Sep 29, 2026
A sovereign, production-grade API core for modern web and mobile products. Authentication, hierarchical IAM, Stripe billing, access control, media pipelines, notifications, durable AI queues, real-time Action Cable WebSockets, background job topologies, operational administration, and glass-box observability stand ready—not as scattered trophies, but as one disciplined system.
Built under an immutable creed: Start from One. Not from Zero. Clear in thought, exact in structure, simple in use, and strong enough to endure what comes after launch.
API-first · Modular · Observable · Queue-aware · Built to grow
Live Demo ↗ · Quick Start · Explore the foundation · Foundation Guide · Ecosystem Architecture · Visual Walkthrough · Who it is for · Development Law · Agent Governance · Production Deployment
| Resource | Purpose & Canonical Specification |
|---|---|
| 🏛️ Unified Ecosystem | Complete cross-platform architecture, feature parity matrix, and communication protocols across Core, Web, and Mobile: ECOSYSTEM.md |
| 📖 Interactive API Docs & Swagger | Full OpenAPI 3.0 specification & interactive Swagger UI explorer at /api-docs: swagger.yaml (Spec: spec/openapi/v1.rb) |
| 🏛️ System Architecture | High-level system topology, domain services, Solid Queue, and provider boundaries: docs/ARCHITECTURE.md |
| 🗄️ Database Schema & Models | Complete database schema, tables, UUID indexes, and model associations: docs/SCHEMA.md |
| 🗺️ Visual Walkthrough | Screenshot-driven, feature-by-feature tour of RexOne across all surfaces and operations: VISUAL_WALKTHROUGH.md |
| 💳 Universal Payments & IAP | Unified Stripe, Google Play, Apple App Store, coupons, and entitlement state machines: docs/PAYMENT.md |
| 🚀 Production Deployment | Contabo VPS + Coolify deployment, zero-downtime rolling updates, and reverse proxy: docs/DEPLOYMENT.md |
| 🧹 Telemetry & VPS Maintenance | Automated log rotation, Solid Queue/Cache pruning, and VPS cleanup: docs/MAINTENANCE.md |
| 📜 Constitutional Law | Non-negotiable architecture, pure parameter contracts, zero legacy shims, and plain English laws: LAW.md (Zero exceptions) |
| 🤖 Operational Agent Governance | Immutable operational rules for AI coding assistants (secret isolation, git safety, synchronous doc sync): AGENTS.md |
| 🛡️ Production Security | Origin isolation, Cloudflare edge defense, and rate-limiting protocols: Production DDoS & API Abuse Protection |
| 🌐 AI Discovery & GEO | Generative Engine Optimization, crawler allowlists, and LLM context files: AI Discovery & GEO Guide |
Every product eventually meets the same old enemies: accounts, permissions, billing, uploads, jobs, notifications, dashboards, audit trails, failures, and the darkness between “it works” and “we know why it works.” Especially, the ultimate killer of momentum: “it works on my machine.”
RexOne Core exists because this ground should never have to be conquered again for every product.
Software has never been easier to generate, but more code does not automatically mean better systems. Human developers and AI coding agents can move fast, but speed without disciplined architecture burns money, AI compute, and human energy—wasting thousands of expensive tokens rewriting weak abstractions, fixing hallucinatory debt, or having to rebuild the exact same foundation again and again for every product.
RexOne turns that repeated, expensive grind into a battle-tested, sovereign baseline.
RexOne pioneers Discipline-Driven Development (DDD). While legacy paradigms spent decades debating Domain-Driven Design or Test-Driven Development, the AI era created a fundamentally different reality: typing code is free. Generating 10,000 lines of code takes 30 seconds.
90% of modern software projects never survive to master the business domain because their architecture collapses first under an avalanche of hallucinatory abstractions, conflicting shims, and zombie code. Tests cannot save a rotten architecture.
Discipline-Driven Development establishes that architectural discipline, sovereign foundation, and constitutional law are the primary drivers of sustainable engineering.
You bring the idea. AI writes the code. RexOne keeps both of you from destroying the foundation.
Every software founder and engineering lead tells themselves the exact same comfortable lie:
“We just need a lightweight MVP. We’ll build our core feature in 4 weeks, and worry about infrastructure later.”
Here is the unvarnished, brutal truth of what actually happens over the subsequent 9 months:
┌────────────────────────────────────────────────────────────────────────────────────────┐
│ THE TRADITIONAL 9-MONTH ROADMAP TO TECH DEBT COLLAPSE │
├────────────────────────────────────────────────────────────────────────────────────────┤
│ Month 1–2: Auth & Identity Hell │
│ JWT tokens, refresh cycles, email confirmation codes, password resets, │
│ and basic RBAC. The "4-week MVP" is already 100% consumed by login screens.│
│ │
│ Month 3–4: Stripe & Billing Agony │
│ Checkout sessions seem simple until edge cases hit: webhook reconciliation,│
│ subscription cancellations, proration races, coupon discounts, failed │
│ invoices, and idempotent state transitions. Two months gone. │
│ │
│ Month 5: Storage, Media & Async Jobs │
│ S3 bucket credentials, presigned upload tickets, image/video variant │
│ resizing, Redis broker configuration, and bloated hosting bills. │
│ │
│ Month 6–7: Web Admin & Real-Time Sync │
│ Operations needs an admin portal. Engineers scramble to build CRUD tables,│
│ metrics charts, and WebSocket event channels from scratch. │
│ │
│ Month 8: Mobile Client Frustration │
│ Connecting Flutter or React Native exposes 50 mismatched JSON keys, │
│ missing endpoints, and fragile auth persistence between Web and Mobile. │
│ │
│ Month 9: The Tech Debt Wall & Refactoring Paralysis │
│ Zero automated tests. Spaghetti code. The team is terrified to touch │
│ a single line because changing one model breaks 4 disparate screens. │
└────────────────────────────────────────────────────────────────────────────────────────┘
┌────────────────────────────────────────────────────────────────────────────────────────┐
│ STARTING FROM ONE (REXONE SOVEREIGN FOUNDATION) │
├────────────────────────────────────────────────────────────────────────────────────────┤
│ Day 1: Spin up Docker. Rails 8 + React 19 + Flutter 3 + Garage S3 + Postgres 18. │
│ Full Auth, 96 IAM permissions, Stripe billing, and WebSockets live. │
│ │
│ Week 1: Define your proprietary domain entities and customize brand styling. │
│ │
│ Week 2: Wire your business logic to existing, fully-tested controllers. │
│ │
│ Week 3: Run 1,690+ passing automated tests. Deploy staging. Ship to production. │
└────────────────────────────────────────────────────────────────────────────────────────┘
Result: 8 to 11 months of soul-crushing plumbing deleted. You launch in weeks.
| Dimension / Capability | 🛡️ RexOne Sovereign Trinity | 📦 Next.js Full-Stack Boilerplates | 🔥 Firebase / Cloud Serverless | 🪤 Supabase / BaaS Starter Kits | 🚂 Rails & Laravel Monoliths |
|---|---|---|---|---|---|
| Architectural Model | ✅ Sovereign Tri-Platform: Rails 8 API + React 19 SPA + pure Flutter 3 native client | ❌ Node Monolith: API, DB, jobs & DOM crammed into 1 fragile runtime | ❌ Serverless Spaghetti: Disconnected Cloud Functions + NoSQL Firestore | ⚠️ Client-Heavy BaaS: Direct client DB queries + scattered edge functions | ⚠️ HTML Monolith: Server-rendered HTML with Turbo/Livewire |
| Native Mobile App | ✅ Native 60fps Flutter: Shared contracts, biometrics, hardware media & push | ❌ None or Webview Shell: Sluggish Capacitor/Cordova wrapper | ⚠️ Fragmented SDKs: Direct NoSQL queries from mobile with zero encapsulation | ⚠️ Raw Client SDK: Mobile apps directly expose database tables via client key | ⚠️ Turbo / Webview: Web pages wrapped in a native navigation shell |
| Offline-First Durability | ✅ Drift SQLite (rexone_offline): Schema mirroring, offline subtitles & AES-256 saves | ❌ None: Application breaks entirely on network disconnect | ⚠️ Flaky Document Cache: Primitive document cache prone to sync desync | ⚠️ No Relational Offline: Unreliable offline sync across foreign keys | ❌ None: Server-rendered pages require constant connectivity |
| Database Integrity | ✅ Strict Relational PostgreSQL: Foreign keys, ACID, UUIDs, soft-deletes | ⚠️ ORM Inconsistencies: Serverless connection pool limits on Prisma/Drizzle | ❌ NoSQL Hell: No joins, no cascading deletes, data duplication nightmare | ✅ PostgreSQL: Relational integrity via managed Postgres instance | ✅ PostgreSQL / MySQL: Mature relational ORM (ActiveRecord / Eloquent) |
| Background Processing | ✅ Solid Queue (Fibers + Threads): Workload pooling, recurring cron, zero Redis costs | ❌ Serverless Timeouts: Forced into third-party Inngest, QStash, or Celery ($$$) | ❌ Execution Timeouts: Severe execution limits, cold starts & high invocation bills | ⚠️ Edge Functions: Strict 10s CPU limits, no persistent background workers | ⚠️ Redis Dependency: Requires external Redis broker & extra hosting RAM |
| Real-Time Delivery | ✅ Native Action Cable: Persistent WebSockets, auto-reconnect & binary STT/TTS | ❌ Broken on Serverless: Forced into expensive Pusher / Ably tiers ($$$) | ⚠️ Firestore Listeners: Pay-per-document-read billing nightmare under active polling | ⚠️ Supabase Realtime: Row-level broadcast, high connection pricing tiers | ⚠️ External Broker: Requires Redis/Reverb/Soketi daemon configuration |
| Object Storage | ✅ Self-Hosted Garage S3: High-performance local S3, zero egress bills | ❌ Vendor Cloud: AWS S3 / Cloudflare R2 egress fees | ❌ Google Cloud Storage: Proprietary bucket pricing & steep download egress fees | ⚠️ Proprietary Storage: Vendor-locked BaaS pricing ladders | ⚠️ ActiveStorage / Flysystem: Tied to third-party cloud S3 bucket bills |
| AI Workflows & Speech | ✅ Durable Queued AI: Chunked streaming, 16kHz live STT, binary MP3 TTS | ⚠️ Edge Timeouts: LLM streams crash on cold starts or Vercel limits | ❌ Synchronous Timeouts: Long-running LLM inferences hit function deadlines | ❌ Client Leaks: Client-side API keys or basic Edge Function calls | ⚠️ Basic Wrappers: Simple synchronous chat endpoints |
| Anti-Vibe Governance | ✅ Constitutional Law (LAW.md): Laws U14/U15 stop AI tech debt and zombie code | ❌ Unguided Vibe-Coding: Fragile abstractions, dead shims & runaway debt | ❌ Scattered Cloud Logic: Code fragmented across dozens of uncoordinated functions | ❌ RLS Spaghetti: 100+ line SQL security policies prone to data leaks | ⚠️ Conventions Only: No explicit constitutional AI agent rules |
| Cost & Sovereignty | ✅ 100% Free & Open (Apache 2.0): Zero paywalls, zero "Pro" upsells, sovereign VPS deploy | ❌ $199–$499 Paid License: Features gated behind tier paywalls | ❌ Google Vendor Trap: Massive cloud bills as user volume scales ($5k–$20k/mo) | ❌ Monthly Cloud Lock-in: Free tier lulls you into $5,000/mo hostage bill | ❌ $299–$799 Paid License: Commercial starter kit paywalls (Jumpstart, Spark) |
Without immutable architectural boundaries:
Agent 1 invents Pattern A
↓
Agent 2 arrives on the next prompt, treats Pattern A as "legacy",
and adds a backward-compatibility shim with Pattern B
↓
Agent 3 arrives, bypasses both, and hardcodes an inline workaround
↓
Deadlines loom; human developers layer more glue code
↓
Context windows fill with duplicate abstractions & zombie code
↓
Exponential technical debt & token burn before the product even launches
RexOne breaks this cycle decisively:
LAW.md): Law U14 enforces zero loose code, zero backward-compatibility shims, complete wipeout and replacement. If code deviates from the law, the code is wrong—fix the code. Law U15 enforces human-readable plain English with zero esoteric syntax.AGENTS.md): Strict guidelines for AI coding tools—never read .env secrets, never run destructive git operations, and synchronize documentation in the exact same turn as code changes.RexOne was not born from framework fandom or an abstract weekend thought experiment. It is the hard-won distillation of years of shipping real-world production systems across:
The Golden Architectural Rule: Server frameworks on the frontend create clumsy UX; client languages on the backend create loose, messy architectures. RexOne combines the strongest technologies that survived this crucible—Rails 8 API Core + React 19 Web + Flutter 3 Mobile—with crystal-clear boundaries, workload-separated queues, self-hosted S3 storage (Garage), full-stack observability, and constitutional laws.
The foundation is designed to bend around the product, never to make the product kneel before the framework.
Instead of hardcoding a rigid SaaS "Teams" hierarchy into domains where it doesn't belong (which is painful to dismantle if the product is an educational platform, clinic, or marketplace), RexOne provides rock-solid IAM primitives (roles, permissions, and 23 canonical resources), leaving domain hierarchy entirely to the business.
RexOne Core brings startup speed with battle-tested discipline—and zero final-hour whispers of “we should probably build that before launch.”
It is a particularly good fit when you want to:
RexOne is not a no-code application generator or a promise that every product domain is already modeled. It supplies the disciplined platform foundation; the product remains responsible for its own domain, workflows, interface, and operating decisions.
The public open-source growth roadmap tracks how RexOne will improve evaluation, evidence, contribution readiness, and responsible distribution.
RexOne Core follows a simple doctrine:
Clarity before cleverness. Precision before haste. Simplicity without weakness. Strength without spectacle.
Years of building software teach the same lesson as any long campaign: the first victory is easy to celebrate; surviving everything that follows is the true test.
The difficult part is rarely another controller or CRUD endpoint. It is preserving a system that remains understandable when the product grows, integrations multiply, failures arrive from unfamiliar directions, and the original developer is no longer the only one carrying the blade.
So the ambition was never to build the largest foundation possible.
It was to build a clear one—strong enough to carry ambitious products, flexible enough to surrender its shape to them, and disciplined enough that the next developer can enter the codebase without a map drawn in blood.
No prophecy. No magic. No shortcuts disguised as momentum.
Just deliberate engineering, tested boundaries, and a foundation built to remain standing.
| Foundation | What is ready | Details |
|---|---|---|
| Identity | Devise, JWT, confirmation, recovery, Google sign-in, platform sessions, self-account deletion | Authentication & security |
| Authorization | Roles, permissions, user-role and role-permission assignments | IAM & access control |
| Commerce | Universal multi-provider billing (Stripe, Google Play, Apple App Store, Free tiers), one-time purchases, subscriptions, coupons & referrals, access entitlements | Universal Payments · Entitlements |
| Async work | Solid Queue, dedicated queues, retries, concurrency controls, recurring cleanup | Background processing |
| Notifications | Socket, push, and email coordination through Action Cable, OneSignal, and Brevo (Master Shell & client URL normalization) | Notifications & real time |
| Media | Provider-neutral storage (Garage S3), silent background optimization (FFmpeg + libvips), SVG conversion, posters, SRT subtitle tracks, and progressive playback | Media playback |
| Speech | Synchronous and async TTS, batch STT, and live audio WebSocket streaming through Azure/Nova | AI & speech |
| AI | Durable queued chat, Telegram-style multi-message chunking, persisted history, completion alerts, and language tools | AI & speech |
| Localization | Request-scoped English and Myanmar responses with modular domain translations | Data & API design |
| Data lifecycle | PostgreSQL, global soft deletion, actor-aware auditing, JSON:API serialization | Data & API design |
| Operations | Performance, errors, client logs, queues, cache, cable, health checks | Observability & administration |
| Administration | Administrate for Server plus Client Admin API for users (with quick confirmation), IAM, products (with access inspection), chat, assets, notifications, app versions | Observability & administration |
| Security | Boot Guard, Zero-Trust CORS, Rate Limiting (Rack::Attack), Pre-Commit Secret Scanner | Security Architecture |
| Governance | Constitutional Law (LAW.md: pure deterministic contracts, zero legacy shims) & Agent Operations (AGENTS.md) | LAW.md · AGENTS.md |
| Delivery | Docker images, 5-container topology (API/waka/media/db/garage), graceful shutdown | Deployment |
| Quality | RSpec, factories, security scanning, dependency auditing, linting | Quality toolchain |
RexOne Core keeps framework concerns conventional and integrations replaceable.
Controllers own HTTP contracts, models own data rules, services own business and provider boundaries, jobs own deferred work, and serializers own response representation. Serializers standardize on 5 canonical methods (record, collection, collection_pagy, record_attributes, collection_attributes), ensuring uniform JSON:API representations and eliminating raw serialization logic from controllers. All collection endpoints enforce Pagy offset pagination (Law U8), returning standard pagination envelopes and defaulting to a complete single page when parameters are omitted.
flowchart LR
Clients[Web & mobile clients] --> API[Rails API]
Clients <-->|Action Cable| Realtime[Solid Cable]
API --> Auth[Authentication & IAM]
API --> Domain[Product domain]
API --> Services[Service interfaces]
API --> Jobs[Solid Queue]
Domain --> PostgreSQL[(PostgreSQL)]
Auth --> PostgreSQL
Jobs --> PostgreSQL
Services --> Stripe[Stripe]
Services --> OneSignal[Push]
Services --> Brevo[Email]
Services --> Storage[Garage S3 · Cloudinary]
Services --> AI[DeepSeek · Google Gemini]
Services --> Speech[Nova · Azure Speech]
Jobs --> Services
Jobs --> MediaWorker[Media Worker · libvips/FFmpeg]
API --> Observability[Pulse · RED · client logs]
External vendor and provider integrations live behind focused gateway clients (e.g., payment, storage, AI, speech, and notification clients). Swapping or extending an upstream vendor never leaks into controllers or domain logic.
For example, queued AI chat orchestrates message chunking, multi-provider execution (DeepSeek, Google Gemini), universal bidirectional TOON serialization (30-60% token savings, LLMs never eat or output raw JSON), and live WebSocket streaming through clean service boundaries with server-owned profiles and run telemetry. For deep implementation details, see the AI Manual and Foundation Guide.
The same principle applies to product-specific functionality: the foundation provides the structure, while the product remains free to define its own domain, workflows, and experience.
Solid Queue is part of the application architecture, not an afterthought. RexOne leverages a hybrid Fiber + Thread concurrency model powered by Ruby Fibers (async), Rails 8 fiber isolation (config.active_support.isolation_level = :fiber), and Solid Queue 1.7.0:
| Work | Queue | Concurrency Engine | Why |
|---|---|---|---|
| Payment webhook processing & batch coupon sync | payments | Fibers (50 concurrent) | Durable ingestion, idempotency, non-blocking HTTP verification, async provider coupon generation (Payment::SyncBatchCouponsJob) |
| AI completions & TTS synthesis | ai | Fibers (50 concurrent) | I/O-bound LLM socket streaming; 50 in-flight requests without thread exhaustion |
| Socket, push, and email delivery | notifications | Fibers (50 concurrent) | Provider latency (OneSignal, Brevo, ActionCable) must not block OS threads |
| Default application tasks | default | Fibers (50 concurrent) | Dynamic shared capacity with instant failover |
| System maintenance & recurring cron | solid_queue_recurring | Threads (2 isolated OS threads) | Sequential, transactional DB table maintenance (config/recurring.yml) |
| Media transcoding & image processing | media | Threads (2 isolated OS threads) | Isolated in dedicated media worker/container; prevents CPU-heavy libvips/FFmpeg from starving I/O |
[ payments, ai, notifications, default ]) are pooled under the fiber worker with deterministic priority order. When notifications surge, all 50 fibers instantly pivot to deliver notifications. When AI requests spike, free fibers immediately prioritize AI completions. Zero idle worker capacity is wasted.media container so image/video compression never starves payment webhooks or live chat completions.config/queue.yml maintains the exact same fiber + thread configuration in both development and production, allowing engineers to observe and benchmark real-world concurrent execution locally.The API, worker (waka), and media processor run as separate services in Docker, keeping request handling, async I/O, and CPU-intensive operations independently scalable.
With Docker installed, you do not need multiple terminals. All Core services (PostgreSQL 18, Rails 8 API, Solid Queue workers, self-hosted Garage S3 storage, and media processor) run together in a single command:
git clone https://github.com/rex-9/rexone-core.git
cd rexone-core && git switch dev
cp .env.example .env
./scripts/install_pre_commit.sh
./scripts/dev.sh
Seed the initial IAM roles, accounts, and client version (1.0.0):
docker compose -f docker-compose.dev.yaml exec api bin/rails db:seed
Start the companion RexOne Web client:
cd ../rexone-web && ./scripts/dev.sh
[!TIP] Testing Stripe payments locally? Forward webhooks in an optional second terminal:
./scripts/listen_webhook.sh. For granular debugging commands and manual process supervision, see the Ecosystem Quick Start.
Built-in operational consoles are mounted directly into the engine, secured by administrative RBAC:
/admin (Administrate engine for core models, users, and credentials)/admin/ai/profiles (prompt models) & /admin/ai/runs (telemetry audit)/admin/pulse (request, SQL query, and job latency metrics)/admin/red (Rails Error Dashboard with stack traces and request parameters)/admin/queue (Solid Queue), /admin/cache, and /admin/cable/api-docs (Swagger / OpenAPI 3.0 specification)/up (automated zero-downtime container health probes)Client runtime errors are accepted at POST /v1/client/logs and correlated with backend traces.
To maintain high architectural discipline without cluttering the primary showcase, exhaustive technical specifications, API routes, and operational playbooks are organized in docs/:
| Resource | Scope & Canonical Specification |
|---|---|
| 📖 Master Documentation Hub | Comprehensive engineering reference and scripts catalog: docs/README.md |
| 📑 OpenAPI & Swagger Documentation | Interactive Swagger UI at /api-docs and live API schema: swagger/v1/swagger.yaml (Rake: rake rswag:specs:swaggerize) |
| 🚀 Ecosystem Quick Start | Local Docker setup, database seeding, and startup debugging: docs/QUICK_START.md |
| 🏛️ Foundation Architecture | Deep dive into IAM, Devise JWT, Soft Deletion, and JSON:API: docs/FOUNDATION.md |
| 🗄️ Database Schema & Models | Complete database schema, tables, UUID indexes, and associations: docs/SCHEMA.md |
| 📦 Object Storage (Garage S3) | Self-hosted S3 Garage setup (port 3100), buckets, and Cyberduck: docs/GARAGE.md |
| 🎬 Media Streaming & Playback | Progressive video/audio, FFmpeg background compression, and SRT subtitles: docs/MEDIA_PLAYBACK.md |
| 🤖 AI Assistant & Speech | Queued chat, multi-message chunking, DeepSeek/Gemini, and TTS/STT: docs/AI_MANUAL.md |
| 🛡️ Security & Boot Guard | Zero-trust CORS, startup secret validation, pre-commit scanners: docs/SECURITY.md |
| 🛑 DDoS & Rate Limiting | Rack::Attack rate-limiting ladders, IP throttling, and abuse defense: docs/DDOS.md |
| 🚀 Production Deployment | Multi-stage Docker, Coolify VPS maintenance, log rotation, and SSL: docs/DEPLOYMENT.md |
The production image is multi-stage, runs as an unprivileged non-root user, precompiles Bootsnap, and includes health-check probes.
RAILS_SECRET_KEY_BASE, PG_PASSWORD, S3_ADMIN_TOKEN) match placeholders../scripts/vps_cleanup.sh for recurring Coolify image pruning and builder cache recycling.For the complete production deployment playbook, see docs/DEPLOYMENT.md.
All logs and database monitoring tables are governed by automated retention policies to guarantee zero disk exhaustion. Complete maintenance guide: docs/MAINTENANCE.md.
| Target / Subsystem | Retention Window | Schedule / Frequency | Mechanism |
|---|---|---|---|
| Docker Container Logs | Max 30 MB / container (10m $\times$ 3 files) | Continuous runtime | Docker json-file rotation (prod & dev) |
| Rails Pulse (Requests & Queries) | 1 month (max 50k req / 250k ops) | Daily at 01:00 AM | RailsPulse::CleanupJob |
| Rails Pulse (Summary Rollups) | Permanent aggregated charts | Hourly at minute :05 | RailsPulse::SummaryJob |
| Solid Queue (Failed Jobs) | 1 month (1.month.ago) | Sundays at 03:00 AM | clear_solid_queue_failed_jobs |
| Solid Queue (Finished Jobs) | Continuous batch clean | Hourly at minute :12 | clear_solid_queue_finished_jobs |
| Solid Cache (Expired Entries) | 24 hours (1.day.ago) | Daily at 02:00 AM | clear_solid_cache_expired_entries |
AI Telemetry (Ai::Run) | 90 days (90.days.ago) | Sundays at 04:00 AM | clear_old_ai_runs |
| Payment Webhook Records | 30 days | Daily at 03:30 AM | clear_old_payment_webhook_events |
| User Notifications | 30 days (read / discarded) | Daily at 02:30 AM | notification_cleanup |
| Docker Images & Build Cache | 7 days (168 hours) | Weekly host cron | ./scripts/vps_cleanup.sh |
RexOne Core serves as the master rebranding engine for the entire ecosystem:
# 1. Rebrand all 3 repositories from rexone-core:
./scripts/rebrand.sh brand.config.json
# 2. Local environment variables in .env:
APP_NAME="My New App Name"
DEFAULT_MAIL_SENDER="no-reply@mynewapp.com"
FROM_EMAIL="support@mynewapp.com"
[!NOTE] The rebranding script intentionally leaves the landing module (
src/modules/landing) and SEO / AI discovery assets (index.htmlmetadata/Schema.org,robots.txt,sitemap.xml,llms.txt,llms-full.txt) completely untouched. RexOne SEO belongs to the foundation architecture; product-specific landing and SEO design are 100% the developer's responsibility.
This API core is built on top of the RexOne Ecosystem (rex-9). When creating derivative products or white-label backends:
"I'm not a wealthy founder or a venture-backed company ~ I'm an independent developer and meditator who built RexOne with my own hands. I could have easily closed-sourced this enterprise foundation or charged $800+ behind a commercial paywall. Instead, out of pure loving-kindness (mettā) cultivated through my meditation journey under Theravada Buddhist teachings, I chose to gift RexOne 100% free and open-source under Apache 2.0 to empower builders, indie hackers, and learners worldwide.
If this foundation saves you months of engineering, thousands of dollars, or sparks your product journey, please consider supporting me so I can sustain my life and craft. Kindly return the loving-kindness: Sponsor Rex on GitHub and star the repositories. Thank you so much for your generosity and kindness. 🙏"
RexOne is architected, forged, and maintained by Rex (@rex-9). If RexOne saves you engineering months, AI tokens, or cloud compute costs, please consider supporting the foundation!
"Sharing is like lighting candles from one candle to another: sharing one's light does not make its own flame dimmer or weaker, but the world illuminates more and more with each light shared... making the world more and more beautiful... one light at a time..."
— Htet Naing (Rex9), Creator of RexOne
Architected with Discipline-Driven Development (DDD), by Htet Naing (Rex9).
A full-stack architect, product craftsman, and long-time practitioner of meditation.
I build systems the same way I approach the path itself: with a clear mind, deliberate steps, and zero unnecessary weight.
Built with ❤️ by Htet Naing (Rex9) on the RexOne Ecosystem
JavaScript
50.3%
Ruby
45.6%
Shell
2.2%
CSS
1.8%
Battle-hardened Rails 8 API foundation with Devise JWT, IAM/RBAC, Stripe subscriptions, Solid Queue workers, Action Cable WebSockets, DeepSeek AI, Monitoring Dashboards and client telemetry.
JavaScript
5
433 commits
updated Sep 29, 2026
A sovereign, production-grade API core for modern web and mobile products. Authentication, hierarchical IAM, Stripe billing, access control, media pipelines, notifications, durable AI queues, real-time Action Cable WebSockets, background job topologies, operational administration, and glass-box observability stand ready—not as scattered trophies, but as one disciplined system.
Built under an immutable creed: Start from One. Not from Zero. Clear in thought, exact in structure, simple in use, and strong enough to endure what comes after launch.
API-first · Modular · Observable · Queue-aware · Built to grow
Live Demo ↗ · Quick Start · Explore the foundation · Foundation Guide · Ecosystem Architecture · Visual Walkthrough · Who it is for · Development Law · Agent Governance · Production Deployment
| Resource | Purpose & Canonical Specification |
|---|---|
| 🏛️ Unified Ecosystem | Complete cross-platform architecture, feature parity matrix, and communication protocols across Core, Web, and Mobile: ECOSYSTEM.md |
| 📖 Interactive API Docs & Swagger | Full OpenAPI 3.0 specification & interactive Swagger UI explorer at /api-docs: swagger.yaml (Spec: spec/openapi/v1.rb) |
| 🏛️ System Architecture | High-level system topology, domain services, Solid Queue, and provider boundaries: docs/ARCHITECTURE.md |
| 🗄️ Database Schema & Models | Complete database schema, tables, UUID indexes, and model associations: docs/SCHEMA.md |
| 🗺️ Visual Walkthrough | Screenshot-driven, feature-by-feature tour of RexOne across all surfaces and operations: VISUAL_WALKTHROUGH.md |
| 💳 Universal Payments & IAP | Unified Stripe, Google Play, Apple App Store, coupons, and entitlement state machines: docs/PAYMENT.md |
| 🚀 Production Deployment | Contabo VPS + Coolify deployment, zero-downtime rolling updates, and reverse proxy: docs/DEPLOYMENT.md |
| 🧹 Telemetry & VPS Maintenance | Automated log rotation, Solid Queue/Cache pruning, and VPS cleanup: docs/MAINTENANCE.md |
| 📜 Constitutional Law | Non-negotiable architecture, pure parameter contracts, zero legacy shims, and plain English laws: LAW.md (Zero exceptions) |
| 🤖 Operational Agent Governance | Immutable operational rules for AI coding assistants (secret isolation, git safety, synchronous doc sync): AGENTS.md |
| 🛡️ Production Security | Origin isolation, Cloudflare edge defense, and rate-limiting protocols: Production DDoS & API Abuse Protection |
| 🌐 AI Discovery & GEO | Generative Engine Optimization, crawler allowlists, and LLM context files: AI Discovery & GEO Guide |
Every product eventually meets the same old enemies: accounts, permissions, billing, uploads, jobs, notifications, dashboards, audit trails, failures, and the darkness between “it works” and “we know why it works.” Especially, the ultimate killer of momentum: “it works on my machine.”
RexOne Core exists because this ground should never have to be conquered again for every product.
Software has never been easier to generate, but more code does not automatically mean better systems. Human developers and AI coding agents can move fast, but speed without disciplined architecture burns money, AI compute, and human energy—wasting thousands of expensive tokens rewriting weak abstractions, fixing hallucinatory debt, or having to rebuild the exact same foundation again and again for every product.
RexOne turns that repeated, expensive grind into a battle-tested, sovereign baseline.
RexOne pioneers Discipline-Driven Development (DDD). While legacy paradigms spent decades debating Domain-Driven Design or Test-Driven Development, the AI era created a fundamentally different reality: typing code is free. Generating 10,000 lines of code takes 30 seconds.
90% of modern software projects never survive to master the business domain because their architecture collapses first under an avalanche of hallucinatory abstractions, conflicting shims, and zombie code. Tests cannot save a rotten architecture.
Discipline-Driven Development establishes that architectural discipline, sovereign foundation, and constitutional law are the primary drivers of sustainable engineering.
You bring the idea. AI writes the code. RexOne keeps both of you from destroying the foundation.
Every software founder and engineering lead tells themselves the exact same comfortable lie:
“We just need a lightweight MVP. We’ll build our core feature in 4 weeks, and worry about infrastructure later.”
Here is the unvarnished, brutal truth of what actually happens over the subsequent 9 months:
┌────────────────────────────────────────────────────────────────────────────────────────┐
│ THE TRADITIONAL 9-MONTH ROADMAP TO TECH DEBT COLLAPSE │
├────────────────────────────────────────────────────────────────────────────────────────┤
│ Month 1–2: Auth & Identity Hell │
│ JWT tokens, refresh cycles, email confirmation codes, password resets, │
│ and basic RBAC. The "4-week MVP" is already 100% consumed by login screens.│
│ │
│ Month 3–4: Stripe & Billing Agony │
│ Checkout sessions seem simple until edge cases hit: webhook reconciliation,│
│ subscription cancellations, proration races, coupon discounts, failed │
│ invoices, and idempotent state transitions. Two months gone. │
│ │
│ Month 5: Storage, Media & Async Jobs │
│ S3 bucket credentials, presigned upload tickets, image/video variant │
│ resizing, Redis broker configuration, and bloated hosting bills. │
│ │
│ Month 6–7: Web Admin & Real-Time Sync │
│ Operations needs an admin portal. Engineers scramble to build CRUD tables,│
│ metrics charts, and WebSocket event channels from scratch. │
│ │
│ Month 8: Mobile Client Frustration │
│ Connecting Flutter or React Native exposes 50 mismatched JSON keys, │
│ missing endpoints, and fragile auth persistence between Web and Mobile. │
│ │
│ Month 9: The Tech Debt Wall & Refactoring Paralysis │
│ Zero automated tests. Spaghetti code. The team is terrified to touch │
│ a single line because changing one model breaks 4 disparate screens. │
└────────────────────────────────────────────────────────────────────────────────────────┘
┌────────────────────────────────────────────────────────────────────────────────────────┐
│ STARTING FROM ONE (REXONE SOVEREIGN FOUNDATION) │
├────────────────────────────────────────────────────────────────────────────────────────┤
│ Day 1: Spin up Docker. Rails 8 + React 19 + Flutter 3 + Garage S3 + Postgres 18. │
│ Full Auth, 96 IAM permissions, Stripe billing, and WebSockets live. │
│ │
│ Week 1: Define your proprietary domain entities and customize brand styling. │
│ │
│ Week 2: Wire your business logic to existing, fully-tested controllers. │
│ │
│ Week 3: Run 1,690+ passing automated tests. Deploy staging. Ship to production. │
└────────────────────────────────────────────────────────────────────────────────────────┘
Result: 8 to 11 months of soul-crushing plumbing deleted. You launch in weeks.
| Dimension / Capability | 🛡️ RexOne Sovereign Trinity | 📦 Next.js Full-Stack Boilerplates | 🔥 Firebase / Cloud Serverless | 🪤 Supabase / BaaS Starter Kits | 🚂 Rails & Laravel Monoliths |
|---|---|---|---|---|---|
| Architectural Model | ✅ Sovereign Tri-Platform: Rails 8 API + React 19 SPA + pure Flutter 3 native client | ❌ Node Monolith: API, DB, jobs & DOM crammed into 1 fragile runtime | ❌ Serverless Spaghetti: Disconnected Cloud Functions + NoSQL Firestore | ⚠️ Client-Heavy BaaS: Direct client DB queries + scattered edge functions | ⚠️ HTML Monolith: Server-rendered HTML with Turbo/Livewire |
| Native Mobile App | ✅ Native 60fps Flutter: Shared contracts, biometrics, hardware media & push | ❌ None or Webview Shell: Sluggish Capacitor/Cordova wrapper | ⚠️ Fragmented SDKs: Direct NoSQL queries from mobile with zero encapsulation | ⚠️ Raw Client SDK: Mobile apps directly expose database tables via client key | ⚠️ Turbo / Webview: Web pages wrapped in a native navigation shell |
| Offline-First Durability | ✅ Drift SQLite (rexone_offline): Schema mirroring, offline subtitles & AES-256 saves | ❌ None: Application breaks entirely on network disconnect | ⚠️ Flaky Document Cache: Primitive document cache prone to sync desync | ⚠️ No Relational Offline: Unreliable offline sync across foreign keys | ❌ None: Server-rendered pages require constant connectivity |
| Database Integrity | ✅ Strict Relational PostgreSQL: Foreign keys, ACID, UUIDs, soft-deletes | ⚠️ ORM Inconsistencies: Serverless connection pool limits on Prisma/Drizzle | ❌ NoSQL Hell: No joins, no cascading deletes, data duplication nightmare | ✅ PostgreSQL: Relational integrity via managed Postgres instance | ✅ PostgreSQL / MySQL: Mature relational ORM (ActiveRecord / Eloquent) |
| Background Processing | ✅ Solid Queue (Fibers + Threads): Workload pooling, recurring cron, zero Redis costs | ❌ Serverless Timeouts: Forced into third-party Inngest, QStash, or Celery ($$$) | ❌ Execution Timeouts: Severe execution limits, cold starts & high invocation bills | ⚠️ Edge Functions: Strict 10s CPU limits, no persistent background workers | ⚠️ Redis Dependency: Requires external Redis broker & extra hosting RAM |
| Real-Time Delivery | ✅ Native Action Cable: Persistent WebSockets, auto-reconnect & binary STT/TTS | ❌ Broken on Serverless: Forced into expensive Pusher / Ably tiers ($$$) | ⚠️ Firestore Listeners: Pay-per-document-read billing nightmare under active polling | ⚠️ Supabase Realtime: Row-level broadcast, high connection pricing tiers | ⚠️ External Broker: Requires Redis/Reverb/Soketi daemon configuration |
| Object Storage | ✅ Self-Hosted Garage S3: High-performance local S3, zero egress bills | ❌ Vendor Cloud: AWS S3 / Cloudflare R2 egress fees | ❌ Google Cloud Storage: Proprietary bucket pricing & steep download egress fees | ⚠️ Proprietary Storage: Vendor-locked BaaS pricing ladders | ⚠️ ActiveStorage / Flysystem: Tied to third-party cloud S3 bucket bills |
| AI Workflows & Speech | ✅ Durable Queued AI: Chunked streaming, 16kHz live STT, binary MP3 TTS | ⚠️ Edge Timeouts: LLM streams crash on cold starts or Vercel limits | ❌ Synchronous Timeouts: Long-running LLM inferences hit function deadlines | ❌ Client Leaks: Client-side API keys or basic Edge Function calls | ⚠️ Basic Wrappers: Simple synchronous chat endpoints |
| Anti-Vibe Governance | ✅ Constitutional Law (LAW.md): Laws U14/U15 stop AI tech debt and zombie code | ❌ Unguided Vibe-Coding: Fragile abstractions, dead shims & runaway debt | ❌ Scattered Cloud Logic: Code fragmented across dozens of uncoordinated functions | ❌ RLS Spaghetti: 100+ line SQL security policies prone to data leaks | ⚠️ Conventions Only: No explicit constitutional AI agent rules |
| Cost & Sovereignty | ✅ 100% Free & Open (Apache 2.0): Zero paywalls, zero "Pro" upsells, sovereign VPS deploy | ❌ $199–$499 Paid License: Features gated behind tier paywalls | ❌ Google Vendor Trap: Massive cloud bills as user volume scales ($5k–$20k/mo) | ❌ Monthly Cloud Lock-in: Free tier lulls you into $5,000/mo hostage bill | ❌ $299–$799 Paid License: Commercial starter kit paywalls (Jumpstart, Spark) |
Without immutable architectural boundaries:
Agent 1 invents Pattern A
↓
Agent 2 arrives on the next prompt, treats Pattern A as "legacy",
and adds a backward-compatibility shim with Pattern B
↓
Agent 3 arrives, bypasses both, and hardcodes an inline workaround
↓
Deadlines loom; human developers layer more glue code
↓
Context windows fill with duplicate abstractions & zombie code
↓
Exponential technical debt & token burn before the product even launches
RexOne breaks this cycle decisively:
LAW.md): Law U14 enforces zero loose code, zero backward-compatibility shims, complete wipeout and replacement. If code deviates from the law, the code is wrong—fix the code. Law U15 enforces human-readable plain English with zero esoteric syntax.AGENTS.md): Strict guidelines for AI coding tools—never read .env secrets, never run destructive git operations, and synchronize documentation in the exact same turn as code changes.RexOne was not born from framework fandom or an abstract weekend thought experiment. It is the hard-won distillation of years of shipping real-world production systems across:
The Golden Architectural Rule: Server frameworks on the frontend create clumsy UX; client languages on the backend create loose, messy architectures. RexOne combines the strongest technologies that survived this crucible—Rails 8 API Core + React 19 Web + Flutter 3 Mobile—with crystal-clear boundaries, workload-separated queues, self-hosted S3 storage (Garage), full-stack observability, and constitutional laws.
The foundation is designed to bend around the product, never to make the product kneel before the framework.
Instead of hardcoding a rigid SaaS "Teams" hierarchy into domains where it doesn't belong (which is painful to dismantle if the product is an educational platform, clinic, or marketplace), RexOne provides rock-solid IAM primitives (roles, permissions, and 23 canonical resources), leaving domain hierarchy entirely to the business.
RexOne Core brings startup speed with battle-tested discipline—and zero final-hour whispers of “we should probably build that before launch.”
It is a particularly good fit when you want to:
RexOne is not a no-code application generator or a promise that every product domain is already modeled. It supplies the disciplined platform foundation; the product remains responsible for its own domain, workflows, interface, and operating decisions.
The public open-source growth roadmap tracks how RexOne will improve evaluation, evidence, contribution readiness, and responsible distribution.
RexOne Core follows a simple doctrine:
Clarity before cleverness. Precision before haste. Simplicity without weakness. Strength without spectacle.
Years of building software teach the same lesson as any long campaign: the first victory is easy to celebrate; surviving everything that follows is the true test.
The difficult part is rarely another controller or CRUD endpoint. It is preserving a system that remains understandable when the product grows, integrations multiply, failures arrive from unfamiliar directions, and the original developer is no longer the only one carrying the blade.
So the ambition was never to build the largest foundation possible.
It was to build a clear one—strong enough to carry ambitious products, flexible enough to surrender its shape to them, and disciplined enough that the next developer can enter the codebase without a map drawn in blood.
No prophecy. No magic. No shortcuts disguised as momentum.
Just deliberate engineering, tested boundaries, and a foundation built to remain standing.
| Foundation | What is ready | Details |
|---|---|---|
| Identity | Devise, JWT, confirmation, recovery, Google sign-in, platform sessions, self-account deletion | Authentication & security |
| Authorization | Roles, permissions, user-role and role-permission assignments | IAM & access control |
| Commerce | Universal multi-provider billing (Stripe, Google Play, Apple App Store, Free tiers), one-time purchases, subscriptions, coupons & referrals, access entitlements | Universal Payments · Entitlements |
| Async work | Solid Queue, dedicated queues, retries, concurrency controls, recurring cleanup | Background processing |
| Notifications | Socket, push, and email coordination through Action Cable, OneSignal, and Brevo (Master Shell & client URL normalization) | Notifications & real time |
| Media | Provider-neutral storage (Garage S3), silent background optimization (FFmpeg + libvips), SVG conversion, posters, SRT subtitle tracks, and progressive playback | Media playback |
| Speech | Synchronous and async TTS, batch STT, and live audio WebSocket streaming through Azure/Nova | AI & speech |
| AI | Durable queued chat, Telegram-style multi-message chunking, persisted history, completion alerts, and language tools | AI & speech |
| Localization | Request-scoped English and Myanmar responses with modular domain translations | Data & API design |
| Data lifecycle | PostgreSQL, global soft deletion, actor-aware auditing, JSON:API serialization | Data & API design |
| Operations | Performance, errors, client logs, queues, cache, cable, health checks | Observability & administration |
| Administration | Administrate for Server plus Client Admin API for users (with quick confirmation), IAM, products (with access inspection), chat, assets, notifications, app versions | Observability & administration |
| Security | Boot Guard, Zero-Trust CORS, Rate Limiting (Rack::Attack), Pre-Commit Secret Scanner | Security Architecture |
| Governance | Constitutional Law (LAW.md: pure deterministic contracts, zero legacy shims) & Agent Operations (AGENTS.md) | LAW.md · AGENTS.md |
| Delivery | Docker images, 5-container topology (API/waka/media/db/garage), graceful shutdown | Deployment |
| Quality | RSpec, factories, security scanning, dependency auditing, linting | Quality toolchain |
RexOne Core keeps framework concerns conventional and integrations replaceable.
Controllers own HTTP contracts, models own data rules, services own business and provider boundaries, jobs own deferred work, and serializers own response representation. Serializers standardize on 5 canonical methods (record, collection, collection_pagy, record_attributes, collection_attributes), ensuring uniform JSON:API representations and eliminating raw serialization logic from controllers. All collection endpoints enforce Pagy offset pagination (Law U8), returning standard pagination envelopes and defaulting to a complete single page when parameters are omitted.
flowchart LR
Clients[Web & mobile clients] --> API[Rails API]
Clients <-->|Action Cable| Realtime[Solid Cable]
API --> Auth[Authentication & IAM]
API --> Domain[Product domain]
API --> Services[Service interfaces]
API --> Jobs[Solid Queue]
Domain --> PostgreSQL[(PostgreSQL)]
Auth --> PostgreSQL
Jobs --> PostgreSQL
Services --> Stripe[Stripe]
Services --> OneSignal[Push]
Services --> Brevo[Email]
Services --> Storage[Garage S3 · Cloudinary]
Services --> AI[DeepSeek · Google Gemini]
Services --> Speech[Nova · Azure Speech]
Jobs --> Services
Jobs --> MediaWorker[Media Worker · libvips/FFmpeg]
API --> Observability[Pulse · RED · client logs]
External vendor and provider integrations live behind focused gateway clients (e.g., payment, storage, AI, speech, and notification clients). Swapping or extending an upstream vendor never leaks into controllers or domain logic.
For example, queued AI chat orchestrates message chunking, multi-provider execution (DeepSeek, Google Gemini), universal bidirectional TOON serialization (30-60% token savings, LLMs never eat or output raw JSON), and live WebSocket streaming through clean service boundaries with server-owned profiles and run telemetry. For deep implementation details, see the AI Manual and Foundation Guide.
The same principle applies to product-specific functionality: the foundation provides the structure, while the product remains free to define its own domain, workflows, and experience.
Solid Queue is part of the application architecture, not an afterthought. RexOne leverages a hybrid Fiber + Thread concurrency model powered by Ruby Fibers (async), Rails 8 fiber isolation (config.active_support.isolation_level = :fiber), and Solid Queue 1.7.0:
| Work | Queue | Concurrency Engine | Why |
|---|---|---|---|
| Payment webhook processing & batch coupon sync | payments | Fibers (50 concurrent) | Durable ingestion, idempotency, non-blocking HTTP verification, async provider coupon generation (Payment::SyncBatchCouponsJob) |
| AI completions & TTS synthesis | ai | Fibers (50 concurrent) | I/O-bound LLM socket streaming; 50 in-flight requests without thread exhaustion |
| Socket, push, and email delivery | notifications | Fibers (50 concurrent) | Provider latency (OneSignal, Brevo, ActionCable) must not block OS threads |
| Default application tasks | default | Fibers (50 concurrent) | Dynamic shared capacity with instant failover |
| System maintenance & recurring cron | solid_queue_recurring | Threads (2 isolated OS threads) | Sequential, transactional DB table maintenance (config/recurring.yml) |
| Media transcoding & image processing | media | Threads (2 isolated OS threads) | Isolated in dedicated media worker/container; prevents CPU-heavy libvips/FFmpeg from starving I/O |
[ payments, ai, notifications, default ]) are pooled under the fiber worker with deterministic priority order. When notifications surge, all 50 fibers instantly pivot to deliver notifications. When AI requests spike, free fibers immediately prioritize AI completions. Zero idle worker capacity is wasted.media container so image/video compression never starves payment webhooks or live chat completions.config/queue.yml maintains the exact same fiber + thread configuration in both development and production, allowing engineers to observe and benchmark real-world concurrent execution locally.The API, worker (waka), and media processor run as separate services in Docker, keeping request handling, async I/O, and CPU-intensive operations independently scalable.
With Docker installed, you do not need multiple terminals. All Core services (PostgreSQL 18, Rails 8 API, Solid Queue workers, self-hosted Garage S3 storage, and media processor) run together in a single command:
git clone https://github.com/rex-9/rexone-core.git
cd rexone-core && git switch dev
cp .env.example .env
./scripts/install_pre_commit.sh
./scripts/dev.sh
Seed the initial IAM roles, accounts, and client version (1.0.0):
docker compose -f docker-compose.dev.yaml exec api bin/rails db:seed
Start the companion RexOne Web client:
cd ../rexone-web && ./scripts/dev.sh
[!TIP] Testing Stripe payments locally? Forward webhooks in an optional second terminal:
./scripts/listen_webhook.sh. For granular debugging commands and manual process supervision, see the Ecosystem Quick Start.
Built-in operational consoles are mounted directly into the engine, secured by administrative RBAC:
/admin (Administrate engine for core models, users, and credentials)/admin/ai/profiles (prompt models) & /admin/ai/runs (telemetry audit)/admin/pulse (request, SQL query, and job latency metrics)/admin/red (Rails Error Dashboard with stack traces and request parameters)/admin/queue (Solid Queue), /admin/cache, and /admin/cable/api-docs (Swagger / OpenAPI 3.0 specification)/up (automated zero-downtime container health probes)Client runtime errors are accepted at POST /v1/client/logs and correlated with backend traces.
To maintain high architectural discipline without cluttering the primary showcase, exhaustive technical specifications, API routes, and operational playbooks are organized in docs/:
| Resource | Scope & Canonical Specification |
|---|---|
| 📖 Master Documentation Hub | Comprehensive engineering reference and scripts catalog: docs/README.md |
| 📑 OpenAPI & Swagger Documentation | Interactive Swagger UI at /api-docs and live API schema: swagger/v1/swagger.yaml (Rake: rake rswag:specs:swaggerize) |
| 🚀 Ecosystem Quick Start | Local Docker setup, database seeding, and startup debugging: docs/QUICK_START.md |
| 🏛️ Foundation Architecture | Deep dive into IAM, Devise JWT, Soft Deletion, and JSON:API: docs/FOUNDATION.md |
| 🗄️ Database Schema & Models | Complete database schema, tables, UUID indexes, and associations: docs/SCHEMA.md |
| 📦 Object Storage (Garage S3) | Self-hosted S3 Garage setup (port 3100), buckets, and Cyberduck: docs/GARAGE.md |
| 🎬 Media Streaming & Playback | Progressive video/audio, FFmpeg background compression, and SRT subtitles: docs/MEDIA_PLAYBACK.md |
| 🤖 AI Assistant & Speech | Queued chat, multi-message chunking, DeepSeek/Gemini, and TTS/STT: docs/AI_MANUAL.md |
| 🛡️ Security & Boot Guard | Zero-trust CORS, startup secret validation, pre-commit scanners: docs/SECURITY.md |
| 🛑 DDoS & Rate Limiting | Rack::Attack rate-limiting ladders, IP throttling, and abuse defense: docs/DDOS.md |
| 🚀 Production Deployment | Multi-stage Docker, Coolify VPS maintenance, log rotation, and SSL: docs/DEPLOYMENT.md |
The production image is multi-stage, runs as an unprivileged non-root user, precompiles Bootsnap, and includes health-check probes.
RAILS_SECRET_KEY_BASE, PG_PASSWORD, S3_ADMIN_TOKEN) match placeholders../scripts/vps_cleanup.sh for recurring Coolify image pruning and builder cache recycling.For the complete production deployment playbook, see docs/DEPLOYMENT.md.
All logs and database monitoring tables are governed by automated retention policies to guarantee zero disk exhaustion. Complete maintenance guide: docs/MAINTENANCE.md.
| Target / Subsystem | Retention Window | Schedule / Frequency | Mechanism |
|---|---|---|---|
| Docker Container Logs | Max 30 MB / container (10m $\times$ 3 files) | Continuous runtime | Docker json-file rotation (prod & dev) |
| Rails Pulse (Requests & Queries) | 1 month (max 50k req / 250k ops) | Daily at 01:00 AM | RailsPulse::CleanupJob |
| Rails Pulse (Summary Rollups) | Permanent aggregated charts | Hourly at minute :05 | RailsPulse::SummaryJob |
| Solid Queue (Failed Jobs) | 1 month (1.month.ago) | Sundays at 03:00 AM | clear_solid_queue_failed_jobs |
| Solid Queue (Finished Jobs) | Continuous batch clean | Hourly at minute :12 | clear_solid_queue_finished_jobs |
| Solid Cache (Expired Entries) | 24 hours (1.day.ago) | Daily at 02:00 AM | clear_solid_cache_expired_entries |
AI Telemetry (Ai::Run) | 90 days (90.days.ago) | Sundays at 04:00 AM | clear_old_ai_runs |
| Payment Webhook Records | 30 days | Daily at 03:30 AM | clear_old_payment_webhook_events |
| User Notifications | 30 days (read / discarded) | Daily at 02:30 AM | notification_cleanup |
| Docker Images & Build Cache | 7 days (168 hours) | Weekly host cron | ./scripts/vps_cleanup.sh |
RexOne Core serves as the master rebranding engine for the entire ecosystem:
# 1. Rebrand all 3 repositories from rexone-core:
./scripts/rebrand.sh brand.config.json
# 2. Local environment variables in .env:
APP_NAME="My New App Name"
DEFAULT_MAIL_SENDER="no-reply@mynewapp.com"
FROM_EMAIL="support@mynewapp.com"
[!NOTE] The rebranding script intentionally leaves the landing module (
src/modules/landing) and SEO / AI discovery assets (index.htmlmetadata/Schema.org,robots.txt,sitemap.xml,llms.txt,llms-full.txt) completely untouched. RexOne SEO belongs to the foundation architecture; product-specific landing and SEO design are 100% the developer's responsibility.
This API core is built on top of the RexOne Ecosystem (rex-9). When creating derivative products or white-label backends:
"I'm not a wealthy founder or a venture-backed company ~ I'm an independent developer and meditator who built RexOne with my own hands. I could have easily closed-sourced this enterprise foundation or charged $800+ behind a commercial paywall. Instead, out of pure loving-kindness (mettā) cultivated through my meditation journey under Theravada Buddhist teachings, I chose to gift RexOne 100% free and open-source under Apache 2.0 to empower builders, indie hackers, and learners worldwide.
If this foundation saves you months of engineering, thousands of dollars, or sparks your product journey, please consider supporting me so I can sustain my life and craft. Kindly return the loving-kindness: Sponsor Rex on GitHub and star the repositories. Thank you so much for your generosity and kindness. 🙏"
RexOne is architected, forged, and maintained by Rex (@rex-9). If RexOne saves you engineering months, AI tokens, or cloud compute costs, please consider supporting the foundation!
"Sharing is like lighting candles from one candle to another: sharing one's light does not make its own flame dimmer or weaker, but the world illuminates more and more with each light shared... making the world more and more beautiful... one light at a time..."
— Htet Naing (Rex9), Creator of RexOne
Architected with Discipline-Driven Development (DDD), by Htet Naing (Rex9).
A full-stack architect, product craftsman, and long-time practitioner of meditation.
I build systems the same way I approach the path itself: with a clear mind, deliberate steps, and zero unnecessary weight.
Built with ❤️ by Htet Naing (Rex9) on the RexOne Ecosystem
JavaScript
50.3%
Ruby
45.6%
Shell
2.2%
CSS
1.8%