System Architecture & Security

Engineered for Zero-Trust Cloud Resilience

Dual-port network topology, automated TLS termination, real-time Fail2ban intrusion defense, and continuous S3 backup replication in a self-healing stack.

System Architecture

Unified Dual-Port Network Topology

One single robust engine answering both off-box serverless edge runtimes and on-box zero-overhead local microservices.

1. Client Ingress

Connect from anywhere with standard PostgreSQL drivers or type-safe SDK clients.

Edge / Serverless LambdasTLS
Local Docker Apps / VPSMesh
Developer Laptop / CLIpsql
2. Dual Network Router

Segregates public TLS ingress and private zero-overhead bridge.

Public EndpointTLS 1.3
pg.pgboxhub.com
Internal Network0ms overhead
pgbox-postgres
3. PostgreSQL 16 Core

100% ACID storage, PostGIS spatial indexing, and automated snapshotting.

JSONB GIN CollectionsIndexed
PostGIS 3.4 SpatialReady
Automated .sql.gz SnapshotsZero-Ops

Detailed Layer-by-Layer Architecture

Each component is isolated in minimal container environments designed for high throughput and zero vulnerabilities.

LAYER 01Managed External TLS

Public Edge & TLS Termination Layer

Direct entry point for internet traffic, serverless lambdas, Vercel edge functions, and developer laptops. Secured by high-grade TLS 1.3 encryption with strict certificate validation.

Guarantees & Specs
  • Cryptographically isolated TLS termination wrapper
  • Enforces strict sslmode=require for all external client connections
  • Prevents man-in-the-middle attacks over untrusted public Wi-Fi or networks
LAYER 02Security Layer (Active Watchdog)

Intrusion Defense & Fail2ban Daemon

Continuous real-time analysis of connection logs. Any remote IP address exhibiting repeated failed password attempts or suspicious port scanning is instantly banned via iptables firewall rules.

Guarantees & Specs
  • Pre-configured jail with maxretry=5 and 24-hour progressive ban times
  • Protects both the public database endpoint and the web control UI
  • Zero performance impact on legitimate client queries
LAYER 03Internal Docker DNS Mesh

Private Docker Mesh & Zero-Latency Interconnect

For backend services, microservices, and background workers running on the same VPS. Communication happens over internal bridge networking with zero encryption overhead and sub-0.1ms latency.

Guarantees & Specs
  • Not exposed to public internet interfaces
  • Direct Unix socket or internal Docker network DNS (pgbox-postgres)
  • Ideal for high-throughput batch processors and collocated API servers
LAYER 04Storage & Compute Core

PostgreSQL 16.3 Engine & PostGIS Extension

Standard, unadulterated PostgreSQL 16 compiled on Alpine Linux with PostGIS 3.4 and GIN path indexing enabled. 100% compliant with the official PostgreSQL wire protocol.

Guarantees & Specs
  • PostgreSQL 16 query planner with parallel sequential scans and SIMD JSON acceleration
  • PostGIS 3.4 geospatial functions and spatial indexing
  • Persistent data volumes with WAL archiving and crash recovery
LAYER 05Durability Daemon (Background Cron)

Automated Platform Cloud Backup Vault

Scheduled background workers generate atomic database snapshots, encrypt them with AES-256-GCM, and stream them securely to offsite cloud storage.

Guarantees & Specs
  • Automated daily snapshot schedules across all tenant databases
  • Encrypted offsite replication to high-durability cloud storage
  • Instant 1-click restore directly from the PGBox control dashboard
Compliance & Hardening

PGBox Security Standard

Specification Version: 2026.8.2 · PostgreSQL 16.3
Cryptographic Standards

TLS 1.3 and 1.2 with ChaCha20-Poly1305 and AES-256-GCM cipher suites. Internal role credentials generated with 32-byte cryptographic entropy.

Access Control & RBAC

Role-based privilege segregation per database. Superuser privileges are locked to maintenance tasks; application connections use non-superuser roles.

Disaster Recovery SLA

Point-in-time recovery capabilities via scheduled compressed SQL dumps. Direct streaming to cloud object storage with zero VPS disk bloat.

A3. Granular Audit Logging

Comprehensive audit trail tracking who did what: schema modifications (DDL), role privilege updates, backup restorations, and Action RPC invocations with actor timestamps.

A4. IP Range Allowlisting

Self-serve network firewall rules allowing teams to restrict database wire protocol endpoints and control plane management strictly to designated CIDR blocks or corporate VPNs.

A5. SOC2-Readiness Posture

Documented internal security controls, continuous encrypted backups to Cloudflare R2 / AWS S3, strict tenant isolation, and automated patch management.

Build AI-Native Applications Today

Ready to build on a truly programmable cloud?

Provision databases, serverless compute, microVM containers, maps, auth, storage, and agent MCP tooling under one unified sovereign endpoint.

No Credit Card Required
8 Sovereign Cloud Services
Sub-10ms Global Edge Ingress