Repositories
Entrosity is developed in separate repositories in the
entrosity GitHub organization. They
were split out of the entrosity/RMM monorepo with their history;
production is deployed from them since the cutover on
2026-09-26.
| Repository | What | Released as |
|---|---|---|
entrosity-shared-go | Go packages shared by the services and binaries: protocol types (proto), agentkit, apperr, authkit, mailkit, reqctx, secretbox, version | Go module, tags vX.Y.Z |
entrosity-ui | @entrosity/ui: shadcn/ui primitives, design tokens, Tailwind preset, shared components | npm package on GitHub Packages, tags vX.Y.Z |
entrosity-axis.backend | Axis API server, WebSocket hub, workers, migrations, simulators, publish-agent | ghcr.io/entrosity/axis-backend, tags vX.Y.Z |
entrosity-axis.frontend | Axis portal (served at /axis) | ghcr.io/entrosity/axis-frontend:main |
entrosity-axis-agent | Windows endpoint agent and its MSI | GitHub releases (dev pre-release, tags vX.Y.Z) |
entrosity-axis-connector | Site connector and its MSI | GitHub releases (dev pre-release, tags vX.Y.Z) |
entrosity-hub.backend | Entrosity Hub API server | ghcr.io/entrosity/hub-backend, tags vX.Y.Z |
entrosity-hub.frontend | Entrosity Hub web app (served at /) | ghcr.io/entrosity/hub-frontend:main |
entrosity-edge.backend | Entrosity Edge API server, workers, migrations | ghcr.io/entrosity/edge-backend, tags vX.Y.Z |
entrosity-edge.frontend | Entrosity Edge web app (served at /edge) | ghcr.io/entrosity/edge-frontend:main |
entrosity-edge-connector | Edge connector (with the controller simulator) and its MSI | GitHub releases (dev pre-release, tags vX.Y.Z), published to Edge for self-update |
entrosity-sphere.backend | Entrosity Sphere API server, media server hook, workers, migrations | ghcr.io/entrosity/sphere-backend, tags vX.Y.Z |
entrosity-sphere.frontend | Entrosity Sphere web app (served at /sphere) | ghcr.io/entrosity/sphere-frontend:main |
entrosity-sphere-connector | Sphere connector (with the NVR simulator) and its MSI | GitHub releases, tags vX.Y.Z |
entrosity-matrix.backend | Entrosity Matrix API server, workers, migrations, the stop-internet import | ghcr.io/entrosity/matrix-backend, tags vX.Y.Z |
entrosity-matrix.frontend | Entrosity Matrix web app (served at /matrix) | ghcr.io/entrosity/matrix-frontend:main |
entrosity-matrix-connector | Matrix connector (FortiGate REST client, local guard, simulator) and its MSI | GitHub releases (dev pre-release, tags vX.Y.Z), published to Matrix for self-update |
entrosity-vertex.backend | Entrosity Vertex API server (Active Directory management), workers, migrations; runs its jobs on Axis connectors | ghcr.io/entrosity/vertex-backend, tags vX.Y.Z |
entrosity-infra | Compose stacks, Caddy, deploy and backup scripts, monitoring, cross-product tests | – |
entrosity-docs | This site, CHANGELOG.md, engineering records (engineering/) | ghcr.io/entrosity/docs:main |
Dependencies between repositories
- Go: the services and binaries
require github.com/entrosity/entrosity-shared-goat a tag. Change shared code there, tag it, thengo get …@vX.Y.Zin each consumer. To work on both at once, create an untrackedgo.workin the consumer (go work init . ../entrosity-shared-go). - UI: tagging
entrosity-uipublishes the package and sendsui-releasedto both apps. Theirui-bumpworkflow updates@entrosity/ui, runs lint, typecheck, tests and build, and pushes the bump tomainonly if all pass. - API contracts: each backend owns its
api/openapi.yaml. A change onmainsendsopenapi-updatedto its app (theopenapi-bumpworkflow regenerates the typed client from the committedapi/openapi.yamlsnapshot) and to this site (the API reference is rendered fromspecs/*.yaml). - Runtime: Axis, Edge, Sphere and Matrix pull the access snapshot from the Hub's internal API and verify Hub tokens; Sphere's media server (MediaMTX, configured in
entrosity-infra) asks the Sphere backend about every publish and read; the Hub'simport-rmmreads Axis's database; Matrix'simport-stop-internetreads an export of the stop-internet panel; Vertex and Axis call each other's internal APIs (jobs for Axis connectors, the connectors' secrets and results). Those contracts are HTTP and SQL, not code.
Access
Everything is private. Developers need:
GOPRIVATE=github.com/entrosityand Git credentials for GitHub (gh auth setup-git);- a token with
read:packagesin~/.npmrcfor@entrosity/ui://npm.pkg.github.com/:_authToken=<token>.
CI uses the ENTROSITY_CI_TOKEN secret in every repository (read the private repositories and packages, send repository_dispatch, push the automated bumps).
Deployment
Production (hub.entrosity.com) is deployed by the deploy workflow of
entrosity-infra. After their checks pass on main, the backends, the
frontends and this site publish their main images and send it a deploy
repository_dispatch; it deploys the current main image of every
component (Continuous deployment).
Its CUTOVER.md records the switch from entrosity/RMM on 2026-09-26,
whose deploy and release workflows are now disabled. Agent and connector
builds are published to production by their own repositories
(Self-update publishing).