Skip to content

Technology

A stack you can read and own

PACSinfra is built from a small set of proven, open-source parts. There's no ORM, no task-queue framework and no policy engine, so a developer can read and own the whole codebase.

Application

Go

API

Handles everything on the request path: logins and sessions, organisations and permissions, the audit trail, reports, and the secure image feed to the viewer.

  • chi router; pgx for PostgreSQL; sqlc for type-checked SQL; goose migrations
  • Argon2id password hashing; signed access tokens that can be revoked
  • Built-in Prometheus metrics and structured logging

Python

DICOM worker

Does the DICOM processing and nothing else: validation, de-identification and ingest.

  • pydicom, with pylibjpeg (JPEG and JPEG 2000) for compressed images
  • psycopg 3, httpx, pydantic v2; managed with uv
  • Jobs are queued in a PostgreSQL table, so there's no message broker to run

Limitation: De-identification covers DICOM metadata, not text burned into image pixels.

React + TypeScript

Frontend

Built with Vite, TanStack Query, React Router and Tailwind CSS.

  • The OHIF viewer is next on the roadmap.

Imaging and storage

Orthanc

The open-source DICOM server, used as the image archive. It's never exposed to the internet.

PostgreSQL 17

Application data and the Orthanc index.

Garage

S3-compatible object storage for upload staging.

Deployment

Docker Compose on a single server, with nginx as the only public entry point. There's no Kubernetes to manage.

Single server, Docker Compose

  • internet → nginx (only public entry point)
  • → Go API (permissions, audit, reports, image feed)
  • → Orthanc (private)
  • → PostgreSQL 17 (private)
  • Python DICOM worker (jobs from a PostgreSQL table)
  • → Garage (upload staging, private)

Quality

  • Every change has to pass linting (golangci-lint, ruff), strict type checking (mypy --strict, TypeScript strict) and the test suites, including the tenant-isolation suite.
  • The code is organised as a Turborepo monorepo with pnpm.

Want to read the code?

The Self-Hosted plan includes the full source code. Book a call if you'd like a walkthrough first.