Solid arrows show runtime connections. Dashed connections mark optional LogicalDOC or OTLP integration. The project names listed inside API, UI and Worker are libraries loaded into those hosts, not separate network services.
nginx routes browser requests to MVC UI and API. UI makes HTTP calls to API using the configured authentication cookie.
API and Worker use PostgreSQL through Infrastructure. The database owns INQAS Identity, application, audit and messaging data. UI does not connect to PostgreSQL directly.
UI and API share the mounted Data Protection key ring. API and Worker share mounted local document storage, including quarantine.
Only Worker connects to RabbitMQ. PostgreSQL outbox/inbox records support at-least-once messaging; production business consumers are not yet implemented.
LogicalDOC CE is a separate optional service accessed through Infrastructure adapters composed into API and Worker. Its dedicated MariaDB and repository/configuration volumes belong to the document provider. INQAS never directly queries MariaDB. Local document storage remains a separate port.
Optional API/Worker OpenTelemetry exports go to an externally configured OTLP collector; no collector service is bundled. UI has no configured exporter.