ScanDrix Architecture
How webhook ingestion, queueing, workers, and the review engine fit together.
ScanDrix is a queue-driven system designed so that review latency never blocks your Git provider, and failures are retried without duplicating comments.
Components
Validates provider signatures, normalizes events, writes outbox records.
RabbitMQ with delayed-message exchange, quorum queues, and dead-letter routing.
Pull jobs, expand context, run AST + AI analysis, post results.
Rule management, Dry Runs, integration config, audit logs.
Event lifecycle
Git provider ──webhook──▶ Ingest API ──outbox──▶ Relay ──▶ RabbitMQ
│
Dashboard ◀──DB── Workers ◀─┘
│
PR comment / check ◀── posting
- Ingest is fire-and-fast. The webhook is signature-validated, normalized into an internal event, and acknowledged in milliseconds. Work happens elsewhere.
- Outbox → relay. The event is written transactionally with an idempotency key, then published to RabbitMQ by the relay — so a crash between DB write and publish loses nothing.
- Workers consume with at-least-once semantics. An inbox/claim mechanism makes processing idempotent: a redelivered event finds its claim and no-ops.
- Retries & DLQ. Transient failures (provider API 5xx, rate limits) retry with exponential backoff, max 5 attempts, then park in a dead-letter queue with a dashboard re-run button.
- Delayed messages. Re-review requests and "wait for push" logic use the delayed-message exchange instead of polling.
Isolation boundaries
- Per-tenant rate limiting — a noisy organization cannot starve others; workers pull per-team fair-share queues.
- Ephemeral analysis sandboxes — diff context is loaded into per-review environments that are destroyed when the review finishes.
- Provider credentials are stored encrypted and decrypted only in the worker that needs them.
Why async matters to you
Your provider's webhook delivery is acknowledged immediately, so:
- Reviews never make your CI/merge UI "wait on HTTP" for analysis.
- A provider-side timeout or retry delivers the same event safely (idempotency key).
- ScanDrix outages degrade to a queued review that posts when service returns — your pipeline never hangs.
Scaling
Stateless API and workers scale horizontally on queue depth. Quorum queues survive broker loss; PostgreSQL holds configuration/state and MongoDB holds review artifacts metadata. See Self-Hosted Deployment for running the stack yourself.