Architecture and security
Technical specifications detailing Inco's auto-sharding infrastructure, database connection pooling, memory pruning, and anti-abuse defenses.
1. System Topology
Inco is designed as a modular, stateless Discord application optimized for high-concurrency message throughput and minimal resource footprints.
Key Architectural Principles:
- Auto-Sharding (
discord.AutoShardedBot): Automatically partitions WebSocket gateway connections across Discord shards as the bot grows, maintaining low latency and 100% gateway uptime. - Dual-Mode Database Adapter: Supports seamless hot-swapping between lightweight local SQLite development and high-availability remote MySQL / MariaDB / TiDB Cloud production clusters.
- Keep-Alive Daemon: Integrated lightweight HTTP health-check server allowing external monitoring daemons (UptimeRobot, BetterStack) to verify process liveness.
2. Database Adapter Architecture
Database connections are mediated through a robust asynchronous connection pool with automatic connection recycling, statement caching, and transaction rollbacks:
.env.example
# Production Database Credentials (TiDB Cloud / MySQL / MariaDB)
IS_PRODUCTION=True
DB_HOST_PROD=gateway01.ap-southeast-1.prod.aws.tidbcloud.com
DB_PORT_PROD=4000
DB_USER_PROD=inco_app.root
DB_PASSWORD_PROD=your_secure_password_here
DB_NAME_PROD=inco_production
DB_POOL_SIZE=83. Memory Lifecycle & Pruning
To eliminate memory leaks on constrained VPS instances, Inco employs proactive in-memory eviction policies:
- Persistent Button Debouncing: Interaction states are tracked using expiring sliding-window buckets and cleared every 5 minutes.
- Ephemeral Cache Eviction: Resolved slash command interactions and temporary modals are purged immediately following response dispatch.
- Presence Cache Optimization: Inco only retains member presence activities for users with open question boxes, ignoring idle guild presence bursts.
4. Security Standards
| Standard | Protocol | Implementation |
|---|---|---|
| Standard 01 | Zero-Trust User Data | Input sanitized against SQL injection, XSS patterns, and control characters. |
| Standard 02 | Credential Segregation | All secrets, bot tokens, and cluster keys isolated in strict environment variables. |
| Standard 03 | Anti-Phishing Shield | Strict regex rejection of invite URLs and raw links in modal payloads. |
| Standard 04 | Silent Drop Defense | Blocked users receive mock success responses to deter retaliation and sock-puppeting. |
| Standard 05 | Rate Limit Throttle | Strict 60-second dispatch cooldown enforced per sender snowflake. |
| Standard 06 | Stateless DMs | Message content is not retained on disk once delivery correlation terminates. |
| Standard 07 | Audited Administrative Actions | Administrative grants and financial events logged to private audit channels. |
| Standard 08 | GDPR Erasure Directives | User deletion requests processed and purged within 72 hours via /feedback. |