Skip to main content

Repositories

Entrosity is developed in separate repositories in the entrosity GitHub organization. They were split out of the entrosity/RMM monorepo with their history; production is deployed from them since the cutover on 2026-09-26.

RepositoryWhatReleased as
entrosity-shared-goGo packages shared by the services and binaries: protocol types (proto), agentkit, apperr, authkit, mailkit, reqctx, secretbox, versionGo module, tags vX.Y.Z
entrosity-ui@entrosity/ui: shadcn/ui primitives, design tokens, Tailwind preset, shared componentsnpm package on GitHub Packages, tags vX.Y.Z
entrosity-axis.backendAxis API server, WebSocket hub, workers, migrations, simulators, publish-agentghcr.io/entrosity/axis-backend, tags vX.Y.Z
entrosity-axis.frontendAxis portal (served at /axis)ghcr.io/entrosity/axis-frontend:main
entrosity-axis-agentWindows endpoint agent and its MSIGitHub releases (dev pre-release, tags vX.Y.Z)
entrosity-axis-connectorSite connector and its MSIGitHub releases (dev pre-release, tags vX.Y.Z)
entrosity-hub.backendEntrosity Hub API serverghcr.io/entrosity/hub-backend, tags vX.Y.Z
entrosity-hub.frontendEntrosity Hub web app (served at /)ghcr.io/entrosity/hub-frontend:main
entrosity-edge.backendEntrosity Edge API server, workers, migrationsghcr.io/entrosity/edge-backend, tags vX.Y.Z
entrosity-edge.frontendEntrosity Edge web app (served at /edge)ghcr.io/entrosity/edge-frontend:main
entrosity-edge-connectorEdge connector (with the controller simulator) and its MSIGitHub releases (dev pre-release, tags vX.Y.Z), published to Edge for self-update
entrosity-sphere.backendEntrosity Sphere API server, media server hook, workers, migrationsghcr.io/entrosity/sphere-backend, tags vX.Y.Z
entrosity-sphere.frontendEntrosity Sphere web app (served at /sphere)ghcr.io/entrosity/sphere-frontend:main
entrosity-sphere-connectorSphere connector (with the NVR simulator) and its MSIGitHub releases, tags vX.Y.Z
entrosity-matrix.backendEntrosity Matrix API server, workers, migrations, the stop-internet importghcr.io/entrosity/matrix-backend, tags vX.Y.Z
entrosity-matrix.frontendEntrosity Matrix web app (served at /matrix)ghcr.io/entrosity/matrix-frontend:main
entrosity-matrix-connectorMatrix connector (FortiGate REST client, local guard, simulator) and its MSIGitHub releases (dev pre-release, tags vX.Y.Z), published to Matrix for self-update
entrosity-vertex.backendEntrosity Vertex API server (Active Directory management), workers, migrations; runs its jobs on Axis connectorsghcr.io/entrosity/vertex-backend, tags vX.Y.Z
entrosity-infraCompose stacks, Caddy, deploy and backup scripts, monitoring, cross-product tests–
entrosity-docsThis site, CHANGELOG.md, engineering records (engineering/)ghcr.io/entrosity/docs:main

Dependencies between repositories​

  • Go: the services and binaries require github.com/entrosity/entrosity-shared-go at a tag. Change shared code there, tag it, then go get …@vX.Y.Z in each consumer. To work on both at once, create an untracked go.work in the consumer (go work init . ../entrosity-shared-go).
  • UI: tagging entrosity-ui publishes the package and sends ui-released to both apps. Their ui-bump workflow updates @entrosity/ui, runs lint, typecheck, tests and build, and pushes the bump to main only if all pass.
  • API contracts: each backend owns its api/openapi.yaml. A change on main sends openapi-updated to its app (the openapi-bump workflow regenerates the typed client from the committed api/openapi.yaml snapshot) and to this site (the API reference is rendered from specs/*.yaml).
  • Runtime: Axis, Edge, Sphere and Matrix pull the access snapshot from the Hub's internal API and verify Hub tokens; Sphere's media server (MediaMTX, configured in entrosity-infra) asks the Sphere backend about every publish and read; the Hub's import-rmm reads Axis's database; Matrix's import-stop-internet reads an export of the stop-internet panel; Vertex and Axis call each other's internal APIs (jobs for Axis connectors, the connectors' secrets and results). Those contracts are HTTP and SQL, not code.

Access​

Everything is private. Developers need:

  • GOPRIVATE=github.com/entrosity and Git credentials for GitHub (gh auth setup-git);
  • a token with read:packages in ~/.npmrc for @entrosity/ui: //npm.pkg.github.com/:_authToken=<token>.

CI uses the ENTROSITY_CI_TOKEN secret in every repository (read the private repositories and packages, send repository_dispatch, push the automated bumps).

Deployment​

Production (hub.entrosity.com) is deployed by the deploy workflow of entrosity-infra. After their checks pass on main, the backends, the frontends and this site publish their main images and send it a deploy repository_dispatch; it deploys the current main image of every component (Continuous deployment). Its CUTOVER.md records the switch from entrosity/RMM on 2026-09-26, whose deploy and release workflows are now disabled. Agent and connector builds are published to production by their own repositories (Self-update publishing).