Private product · sanitized case study
Outsider Studio · AI short-video production
An AI short-video creation tool taken from a desktop production pipeline to a full commercialization loop: licensing, quotas, distribution and operations.
- Role
- Solo developer
- Period
- 2026.05 – 2026.07
- Scale
- Private monorepo · 105 commits · v0.3.18
- Shape
- Desktop + cloud · four apps
The problem
POV short-video creators using AI face a fragmented flow: topic, script, storyboard, image generation, voiceover and editing scattered across tools, with context constantly re-shipped. Selling it as a product also requires licensing checks, quota billing, key distribution, invite-based growth, and risk-control auditing — a whole layer of commercial infrastructure.
The project answers two questions at once: production — a desktop pipeline from topic → script → storyboard → image gen → TTS → export, with retry and checkpoint resume for long-running tasks; business — a self-built licensing service + admin console + distribution system + soft-OTA release pipeline, so the desktop product can actually be sold and operated.
System boundary
A four-app monorepo with no shared npm packages; the apps couple through JSON contracts (field names, camelCase), and contract changes require synchronized releases on both ends.
| App | Form | Responsibility |
|---|---|---|
| Studio | Desktop (Tauri v2, React 19 + Rust) | Production pipeline: script → storyboard → image gen → voiceover → cover → editing-software draft export |
| License | Licensing service (CF Pages Functions + D1) | Per-machine activation keys, expiry authority, quota counting, heartbeat, risk control |
| License Admin | Admin console (Vite + React, 28 pages) | Keys / redemption codes / invite rewards / distribution / audit / system settings |
| Site | Product site (Next.js) | Landing page, downloads, docs |
- The desktop app talks to model providers directly; users bring their own API keys, stored in the Rust side, never relayed through our servers;
- Our cloud only handles licensing and the commercial loop — generation traffic never touches it;
- The WebView never calls the licensing domain; everything goes through Rust IPC (invoke).
Key decisions
- 1
Tauri v2 over Electron
For a personal desktop tool, bundle size, memory footprint and system-level capabilities (secure IPC, auto-update) are decisive; see the public write-up below.
- 2
Sensitive material lives in Rust process memory, never on disk
Licensing session tokens and built-in prompt decryption keys are memory-only, cleared on validation failure or expiry; disk keeps only the activation key itself. Built-in prompts ship encrypted and unlock after activation.
- 3
Three-state licensing gate with graceful degradation
active = full features / expired = browse past work + renew panel / blocked = clear error and retry path. Every generation, write and export command goes through a unified license guard; reading history is never restricted — expiring never deletes user assets.
- 4
Merchant-of-Record payment orchestration, outsource tax & compliance
A solo seller should not hand-roll global tax compliance; an MoR payment orchestrator handles invoicing, sales tax and chargebacks end to end (ADR-0001).
- 5
Commercial model first
Offers / Promotions were modeled before any UI; redemption codes, trial pools, invite rewards and rush channels are all instances of the same model, preventing later marketing needs from breaking the data model (ADR-0002).
- 6
Long-running task engineering
Storyboard splitting runs up to 4 segments in parallel, a global image queue caps concurrency, with failure retry / batch cancel / checkpoint resume; quotas are pre-checked at the pipeline entrance — fail fast, never half-done billing.
- 7
Soft OTA updates
In-app update channel with a documented release pipeline and version management, so users never manually reinstall.
View sanitized architecture (Mermaid source) ›
The diagram uses generic role labels only — no real domains, paths or provider names.
%% Outsider Studio 脱敏架构图(公开版)
%% 所有节点使用通用角色标注:不含真实域名、接口路径、供应商名称、管理路径
flowchart TB
User([创作者])
subgraph Client["桌面端 · Tauri v2(React 19 + Rust)"]
UI["制作流水线 UI<br/>选题 · 脚本 · 分镜 · 生图 · 配音 · 导出"]
Core["Rust 核心<br/>授权会话 / API Key / 解密材料<br/>只存进程内存 · 不落盘"]
Queue["全局任务队列<br/>并发控制 · 重试 · 批量取消 · 断点续跑"]
Gate["License 门禁<br/>active / expired / blocked 三态"]
UI -->|"invoke (IPC)"| Core
UI --> Queue
Gate -.守卫所有生成/写入/导出命令.-> Queue
end
subgraph Cloud["自有云端 · 授权与商业闭环(Serverless + 边缘数据库)"]
Lic["授权服务<br/>一机一码 · 到期权威 · 配额计数 · 风控"]
Admin["管理后台(28 页面)<br/>密钥 · 兑换码 · 邀请奖励 · 分销 · 审计"]
Portal["分销商门户"]
Site["产品站(Next.js)"]
Admin --> Lic
Portal --> Lic
end
Ext["外部模型服务(多家)<br/>文本 / 图像 · 路由与降级"]
TTS["自托管开源 TTS 引擎"]
Pay["支付编排商(MoR 模式)<br/>税务 / 合规外包"]
Export["剪映草稿导出"]
User --> Client
Client -->|"HTTPS 授权 API<br/>激活 / 校验 / 心跳 / 配额"| Lic
Core -->|"用户自带 API Key · 直连不经中转"| Ext
Client --> TTS
Client --> Export
Lic --> Pay
Ops([运营者]) --> Admin
Dist([分销商]) --> Portal
Verification
- A full-stack test report (352 lines, maintained per release) covering 10 Studio API endpoints, 28 admin pages, 6 distributor-portal pages and 5 product-site pages;
- 7 end-to-end business flows (invite rewards, code activation, rush approval → key issuance, card review, notification stack, audit trail, access log) re-tested with curl, all passing;
- Per-app unit tests + type checks + build verification;
- Known issues are publicly recorded in the report — nothing hidden.
Public artifacts
- Product site (public) →
- Write-up: Tauri vs Electron for personal desktop tools (CN) →
- Reproducible test commands and coverage matrix in the project verification.md
Redaction boundary
The following are intentionally excluded from this case study:
- Real domains, API paths and admin-console paths;
- Licensing signing / encryption implementation details (mechanism design only, no cryptography specifics);
- Model-provider credentials and commercial terms;
- Customer, distribution and invitation data;
- Real voice material or copyrighted assets (screenshots / demos always use synthetic data).