Architecture and security

Technical specifications detailing Inco's auto-sharding infrastructure, database connection pooling, memory pruning, and anti-abuse defenses.

1. System Topology

Inco is designed as a modular, stateless Discord application optimized for high-concurrency message throughput and minimal resource footprints.

Key Architectural Principles:

  • Auto-Sharding (discord.AutoShardedBot): Automatically partitions WebSocket gateway connections across Discord shards as the bot grows, maintaining low latency and 100% gateway uptime.
  • Dual-Mode Database Adapter: Supports seamless hot-swapping between lightweight local SQLite development and high-availability remote MySQL / MariaDB / TiDB Cloud production clusters.
  • Keep-Alive Daemon: Integrated lightweight HTTP health-check server allowing external monitoring daemons (UptimeRobot, BetterStack) to verify process liveness.

2. Database Adapter Architecture

Database connections are mediated through a robust asynchronous connection pool with automatic connection recycling, statement caching, and transaction rollbacks:

.env.example
# Production Database Credentials (TiDB Cloud / MySQL / MariaDB)
IS_PRODUCTION=True
DB_HOST_PROD=gateway01.ap-southeast-1.prod.aws.tidbcloud.com
DB_PORT_PROD=4000
DB_USER_PROD=inco_app.root
DB_PASSWORD_PROD=your_secure_password_here
DB_NAME_PROD=inco_production
DB_POOL_SIZE=8

3. Memory Lifecycle & Pruning

To eliminate memory leaks on constrained VPS instances, Inco employs proactive in-memory eviction policies:

  • Persistent Button Debouncing: Interaction states are tracked using expiring sliding-window buckets and cleared every 5 minutes.
  • Ephemeral Cache Eviction: Resolved slash command interactions and temporary modals are purged immediately following response dispatch.
  • Presence Cache Optimization: Inco only retains member presence activities for users with open question boxes, ignoring idle guild presence bursts.

4. Security Standards

StandardProtocolImplementation
Standard 01Zero-Trust User DataInput sanitized against SQL injection, XSS patterns, and control characters.
Standard 02Credential SegregationAll secrets, bot tokens, and cluster keys isolated in strict environment variables.
Standard 03Anti-Phishing ShieldStrict regex rejection of invite URLs and raw links in modal payloads.
Standard 04Silent Drop DefenseBlocked users receive mock success responses to deter retaliation and sock-puppeting.
Standard 05Rate Limit ThrottleStrict 60-second dispatch cooldown enforced per sender snowflake.
Standard 06Stateless DMsMessage content is not retained on disk once delivery correlation terminates.
Standard 07Audited Administrative ActionsAdministrative grants and financial events logged to private audit channels.
Standard 08GDPR Erasure DirectivesUser deletion requests processed and purged within 72 hours via /feedback.