ScanDrix Architecture

How webhook ingestion, queueing, workers, and the review engine fit together.

ScanDrix is a queue-driven system designed so that review latency never blocks your Git provider, and failures are retried without duplicating comments.

Components

Event lifecycle

code
Git provider ──webhook──▶ Ingest API ──outbox──▶ Relay ──▶ RabbitMQ
                                                          │
                              Dashboard ◀──DB── Workers ◀─┘
                                   │
                       PR comment / check ◀── posting
  1. Ingest is fire-and-fast. The webhook is signature-validated, normalized into an internal event, and acknowledged in milliseconds. Work happens elsewhere.
  2. Outbox → relay. The event is written transactionally with an idempotency key, then published to RabbitMQ by the relay — so a crash between DB write and publish loses nothing.
  3. Workers consume with at-least-once semantics. An inbox/claim mechanism makes processing idempotent: a redelivered event finds its claim and no-ops.
  4. Retries & DLQ. Transient failures (provider API 5xx, rate limits) retry with exponential backoff, max 5 attempts, then park in a dead-letter queue with a dashboard re-run button.
  5. Delayed messages. Re-review requests and "wait for push" logic use the delayed-message exchange instead of polling.

Isolation boundaries

  • Per-tenant rate limiting — a noisy organization cannot starve others; workers pull per-team fair-share queues.
  • Ephemeral analysis sandboxes — diff context is loaded into per-review environments that are destroyed when the review finishes.
  • Provider credentials are stored encrypted and decrypted only in the worker that needs them.

Why async matters to you

Your provider's webhook delivery is acknowledged immediately, so:

  • Reviews never make your CI/merge UI "wait on HTTP" for analysis.
  • A provider-side timeout or retry delivers the same event safely (idempotency key).
  • ScanDrix outages degrade to a queued review that posts when service returns — your pipeline never hangs.

Scaling

Stateless API and workers scale horizontally on queue depth. Quorum queues survive broker loss; PostgreSQL holds configuration/state and MongoDB holds review artifacts metadata. See Self-Hosted Deployment for running the stack yourself.