echo6-docs/vault/docs/software/central.md
echo6-autocommit 3363f59b4b auto: docs sync 2026-06-29T06:00:08+00:00
Files changed: credentials engine/lint-report.md vault/.obsidian/workspace.json vault/docs/software/central.md
2026-06-29 06:00:08 +00:00

5.3 KiB

title type tags related updated
central — Data-Hub Spine reference
recon
navi
services
environment
2026-06-27

central — Data-Hub Spine

Overview

central is a multi-domain real-time data-hub spine. Adapters normalize upstream sources, publish CloudEvents to NATS/JetStream, and archive to TimescaleDB/PostGIS for historical and geospatial query. It is the live data backbone for navi traffic tiles and related situational-awareness feeds.

  • URL (internal): http://central.echo6.mesh:8000 (mesh-only, no public exposure)
  • Host: utility CT 104 (unprivileged Ubuntu LXC)
  • Repo: github.com/zvx-echo6/central (public, Python, deployed at detached HEAD, tag v0.14.5)
  • Deploy path: /opt/central (venv: /opt/central/.venv, env: /etc/central/central.env, system user: central)

Host

Attribute Value
Container utility CT 104
Local IP 192.168.1.104
Tailscale / mesh 100.64.0.12 → central.echo6.mesh
Resources 4 cores / 12 GB RAM / 100 GB disk
OS Ubuntu LXC (unprivileged)

Architecture

The data flow is: upstream APIs → adapters (central-supervisor) → NATS/JetStream :4222 → central-archive (TimescaleDB/PostGIS :5432). The central-gui (FastAPI + HTMX, :8000) exposes the API consumed by navi via recon-vm's nginx (port 8440, ^~ /api/traffic/central.echo6.mesh:8000).

Systemd Services

All three units are enabled and active; deployment survives reboot. Deps: nats-server, postgresql@16-main.

Unit Role
central-supervisor Adapter scheduler + CloudEvents publisher
central-archive JetStream → TimescaleDB consumer
central-gui FastAPI + HTMX web app + API (the :8000 listener)

Ports

Port Protocol Purpose
:8000 HTTP GUI / API (bound 0.0.0.0)
:4222 TCP NATS client connections
:8222 HTTP NATS monitoring
:5432 TCP PostgreSQL 16 + TimescaleDB/PostGIS

Adapters (23 configured, 22 enabled)

Domain Sources
Traffic ITD 511, WZDX, TomTom flow/incidents, 511 cameras
Wildfire WFIGS incidents/perimeters, InciWeb, FIRMS
Weather / Space-weather NWS, SWPC k-index/protons/alerts
Hydro NWIS
Earthquakes USGS
Avalanche avalanche.org
Disasters GDACS, EONET
Satellite CelesTrak TLE, sat positions/orbits, satpass_predict (n2yo_visualpasses disabled 2026-06-27)

GUI / API Surface

Authenticated app with login/sessions/CSRF, first-run setup wizard, operator management, adapter configuration, stream viewer, JetStream consumer management (/consumers — view + delete consumers; central's own archive-* durable consumers are protected/non-deletable; CSRF + audit-logged), enrichment pipeline, monitoring-area management, API key management, audit log, and manual resend.

Auth-exempt tile endpoints (used by navi, verified HTTP 200):

Endpoint Format
/api/traffic/flow/{z}/{x}/{y}.png PNG tile (raster, image/png)
/api/traffic/flow/{z}/{x}/{y}.pbf PBF tile (vector, application/x-protobuf)

/health is also auth-exempt (returns {"status":"ok"}). All other /api/ endpoints redirect to /login.

Consumer — navi Integration

navi-traffic (navi's in-VM :8421 extraction service) was retired on 2026-05-26 and cut over to central. recon-vm's nginx (/etc/nginx/sites-available/navi.echo6.co, port 8440) now proxies ^~ /api/traffic/central.echo6.mesh:8000 with a 120s tile cache. navi-traffic:8421 is confirmed dead and disabled. Tile endpoints verified returning HTTP 200.

Dependencies

Component Location
NATS / JetStream Local (central CT 104)
PostgreSQL 16 + TimescaleDB + PostGIS Local (central CT 104)
Upstream APIs ~20 external sources (see Adapters table)

Data Plane

Single TimescaleDB hypertable public.events (~22 GB, ~3.19 M rows, 331 chunks, compression not enabled). JetStream ~5.86 GB / 20 GB across 12 streams.

Deploy / State Notes (as of 2026-06-29)

  • Deployed HEAD: v0.14.7 (detached HEAD — the box tracks tags). All prior drift resolved: migration 036 committed, pyproject.toml version current, README operational.
  • Deploy mechanism: manual, tag-based (git checkout <tag>uv synccentral-migrate → restart). One-command scripts/deploy.sh ships in-repo; full procedure in the central-deploy-cutover runbook. No CI/CD; no automated DB backup (pre-flight pg_dump is the only migration safety net; migrations are forward-only).
  • central-migrate env gotcha: manual calls need cd /opt/central && set -a && . /etc/central/central.env && set +a && … (the units supply this via WorkingDirectory + EnvironmentFile).
  • EONET: now global as of v0.14.6 (2026-06-28) — bypass_bbox_filter=True + the adapter region key removed. NOTE: its events-table row count is a misleading health signal (dedup + partition expiry); use the CENTRAL_DISASTER stream as the EONET flow signal. avalanche_org zero-events is expected (off-season gate).
  • Supervisor CPU ~17%→~1.4% and cursors.db 1.3 GB→496 MB after the v0.14.6 dedup/WAL fix + a VACUUM.

Last updated: 2026-06-29 — v0.14.7 deployed (consumers admin page); drift cleared, EONET global, perf fixes verified.