Designing a VPS Reseller System: Integrating Domestic Payments (VND) and KYC (Know Your Customer) Process
Designing a Reseller VPS System: Domestic Payment Integration (VND) and KYC Compliance
Building a Reseller VPS (Virtual Private Server) system is more than just connecting APIs to major providers like DigitalOcean, Vultr, or Proxmox. To operate a professional platform in the Vietnamese market, the real challenge lies in risk management, optimizing domestic cash flow, and establishing a rigorous Know Your Customer (KYC) process. This article dives deep into the technical architecture and operational workflows for a comprehensive Reseller VPS platform.
1. System Architecture and Role-Based Access Control (RBAC)
In a reseller system, defining clear boundaries between user groups is vital for security and transparency. A multi-tier RBAC (Role-Based Access Control) model is essential.
- Super Admin: Full system control, manages root API connections, configures exchange rates, and approves high-level KYC requests.
- Seller: The primary stakeholder. They lease resources from the Admin or connect their own infrastructure, set pricing in VND, and manage their end-customers.
- Standard User: The end-customer who directly uses the VPS. They perform payments via domestic gateways and manage their servers through the dashboard.
// Defining Role-Based Access Control in a NestJS system
enum UserRole {
ADMIN = 'ADMIN',
SELLER = 'SELLER',
USER = 'USER'
}
interface UserProfile {
id: string;
email: string;
role: UserRole;
isKycVerified: boolean;
walletBalanceVND: number;
}
// Middleware to verify VPS resource management permissions
function canManageVPS(user: UserProfile, targetVpsOwnerId: string): boolean {
if (user.role === UserRole.ADMIN) return true;
if (user.role === UserRole.SELLER && user.id === targetVpsOwnerId) return true;
return user.id === targetVpsOwnerId;
}
2. KYC (Know Your Customer) Workflow for Sellers
Why is strict KYC necessary for Sellers? In this model, the Seller holds direct legal responsibility for the content running on the VPS. A system without KYC becomes a breeding ground for fraud, DDoS attacks, or mail spamming.
A standard KYC process involves these steps:
- Data Collection: Photos of ID/Passport (both sides) and a portrait (selfie).
- OCR Validation: Utilizing AI APIs to extract data from photos and match it with registered info.
- Risk Scoring: Checking if phone numbers or emails are blacklisted in security databases.
- Manual Approval: The final step by an Admin to ensure absolute authenticity before granting "Seller" status.
// Simulating the KYC approval state
type KycStatus = 'PENDING' | 'APPROVED' | 'REJECTED';
interface KycDocument {
userId: string;
idNumber: string;
frontImageUrl: string;
backImageUrl: string;
selfieImageUrl: string;
status: KycStatus;
}
async function processKycSubmission(doc: KycDocument): Promise {
// Calling an AI OCR service (e.g., Google Vision or AWS Textract)
const ocrResult = await ocrService.extractInfo(doc.frontImageUrl);
if (ocrResult.idNumber !== doc.idNumber) {
throw new Error("ID Number does not match the provided image!");
}
// Save to database pending Admin review
return await database.saveKycStatus(doc.userId, 'PENDING');
}
3. Domestic Payment: VND Integration and Gateways
In the Vietnamese market, international credit card payments (Visa/Mastercard) still face barriers regarding currency conversion fees and trust. A successful Reseller VPS system must integrate: Bank Transfers (VietQR), MoMo, and ZaloPay.
Cash Flow Optimization:
The system requires an "Internal E-Wallet" mechanism. Users deposit VND into the wallet, and the system deducts funds based on hourly usage (Pay-as-you-go) or monthly subscriptions. This helps Sellers manage steady cash flow and allows users to control costs easily.
| Method | Advantages | Disadvantages |
|---|---|---|
| VietQR (Banking) | Low fees (~0%), instant settlement. | Difficult to automate without direct Banking APIs. |
| E-Wallets (MoMo/ZaloPay) | Great UX, stable APIs. | High transaction fees (1.5% - 2.5%). |
| Domestic Cards (NAPAS) | Widely used, trustworthy. | Requires integration through intermediaries (PayOS, Alepay). |
4. API Synchronization and Message Queues
When a customer clicks "Buy VPS," the system cannot ask them to wait 5-10 minutes while the server initializes. However, upstream provider APIs often have latency. We must use Message Queues (Redis/RabbitMQ) for asynchronous processing.
// Example of a Task Queue handling VPS provisioning
import { InjectQueue } from '@nestjs/bull';
import { Queue } from 'bull';
class VpsService {
constructor(@InjectQueue('provisioning') private vpsQueue: Queue) {}
async createVpsOrder(orderData: any) {
// 1. Check VND wallet balance
// 2. Deduct funds (Escrow)
// 3. Add to processing queue
await this.vpsQueue.add('setup-vps', {
planId: orderData.planId,
userId: orderData.userId,
region: 'Hanoi-1'
}, { attempts: 3, backoff: 5000 });
return { message: "Order is being processed, please wait a moment." };
}
}
5. Reseller Policies and Commissions
To grow the reseller network, you need a flexible commission engine. However, a strict rule must be applied: Sellers cannot earn commission from their own purchases.
Wallet structures should be separated:
- Main Wallet: Used for service payments.
- Affiliate Wallet: Stores commissions from referrals (Standard Users only).
- Seller Credit: A credit limit granted by Admin for reselling purposes.
// Calculating commission based on Tier level
function calculateCommission(amount: number, tier: number): number {
const rates = { 1: 0.05, 2: 0.1, 3: 0.15 }; // 5%, 10%, 15%
const rate = rates[tier] || 0.02;
return amount * rate;
}
const orderValue = 500000; // 500,000 VND
const commission = calculateCommission(orderValue, 2);
console.log(`Commission added to wallet: ${commission.toLocaleString()} VND`);
6. Security and Anti-Fraud Measures
In a VPS environment, the biggest risk is customers using servers for illegal crypto mining or launching cyberattacks, which damages IP Reputation. The system needs integrated monitoring tools:
- Bandwidth Limiting: Automatically throttle bandwidth if abnormal traffic spikes are detected.
- Port Monitoring: Block port 25 by default to prevent mass spam emails.
- Behavioral Analytics: Trigger alerts if an account deposits large sums using multiple different cards in a short time.
7. Conclusion: The Optimal Implementation Roadmap
Building a Reseller VPS platform is a technical marathon. To begin, focus on three core pillars:
- API Connectivity Stability: Always have a failover plan if the root provider goes down.
- Payment Transparency: Automated reconciliation between Bank records and internal wallets must be 100% accurate.
- User Experience: A clean Dashboard with one-click installs for popular OS like Ubuntu, CentOS, and Windows Server.
Hopefully, this analysis provides the technical insights needed to design a robust Reseller VPS system that meets the growing demands of the 2026 market!
