Operator surfaces¶
Dyson currently has two separate HTTP applications: the control panel and the Strategy API. They are not a frontend/backend pair at this revision.
Control panel¶
The control panel is a Next.js trading desk for one configured deployment and strategy.
| Source | Used for |
|---|---|
| NATS | Runtime status, events, open orders, live market data, and Start |
| InfluxDB | Strategy state, quote decisions, actions, responses, fills, and venue health |
| Kuru public WebSocket | Direct public orderbook view |
Browser clients use server-side routes; they do not receive NATS or InfluxDB credentials. Start is the only lifecycle mutation exposed by the UI. A publish acknowledgement is not proof that trading began—the subsequent runtime status is authoritative.
Strategy API¶
The Rust Strategy API is currently a foundation with three V0 routes:
- liveness;
- MongoDB-backed readiness; and
- the generated OpenAPI document.
It does not currently expose strategy CRUD, deployment selection, or lifecycle commands, and the control panel does not call it. Future mutations must preserve its repository and event-publisher boundaries instead of placing database or NATS clients directly in handlers.
Access boundary¶
Neither application is the identity or authorization layer. Keep operator surfaces behind the approved network and identity boundary, keep service credentials server-side, and treat runtime status—not UI state—as the source of truth for whether a strategy is running.