Crown is a multi-application clinical audit platform built as a Bun/Turbo monorepo.
At a high level it is composed of:
- frontend apps built with Rsbuild and TypeScript
- backend services built mainly with Hono on Bun
- shared packages for auth, schema tooling, realtime, routing, and database abstractions
- SurrealDB as the primary operational database
- Docker Compose for local orchestration and deployment packaging
- Traefik for routed access in local and production deployments
Platform layers
Experience layer
User-facing applications include:
auth-uiauditsapplication-listadmin-uischema-designer-v2nela-risk-calculatoranalytics-ui
Service layer
Key runtime services include:
auth-servicerecords-serviceentity-serviceaudit-serviceanalytics-serviceuser-activity-servicecms-servicesupport-servicenela-servicerisk-score-service
The ordinary Bun/Hono APIs can be deployed either as those logical services or inside one crown-core-api process. The combined runtime preserves each service hostname and route contract, so frontend deployments do not change. NELA, risk scoring, AI, and ML training remain independent workloads.
Shared platform layer
Shared packages provide the internal platform primitives:
@crown/realtimefor live updates and WebSocket helpers@crown/routerfor client navigation@crown/db-adapterfor database schema abstractions@crown/schema-*packages for DSL, metadata, validation, and documentation@crown/better-auth-*packages for auth plugins and permission models@crown/uifor reusable interface components
Core characteristics
- Monorepo build orchestration via Turbo
- Runtime consistency through Docker Compose
- Direct service ownership — apps retain service-specific URLs; in combined
deployments those hostnames terminate at the crown-core-api dispatcher
- Mixed protocols — HTTP for standard request/response flows, WebSockets for live dashboards, notifications, locks, and content streams
- Shared auth — a central auth service issues tokens and publishes JWKS metadata for validation in other services
Runtime topology
Source: service-topology.mmd
Workspace dependency graph
Source: dependency-graph.mmd
How to read the architecture docs
- Use deployment architecture when you care about containers, ports, startup order, or environment separation.
- Use service communication when you care about HTTP vs WebSocket flows and who calls whom.
- Use database architecture when you care about SurrealDB, migrations, or schema generation.
- Use the interactive explorer when the static graph becomes delightfully spaghetti-like.