Skip to content
CAI
Software that uses CAICheck a score

evrone/go-clean-template

61.6

Adequate · 6 October 2026

4.8k

lines of production code

Go

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a multi-protocol backend service that manages user authentication, task workflows, and translation operations. It exposes functionality through HTTP REST, gRPC, RabbitMQ RPC, and NATS RPC interfaces, all secured by JWT authentication. The application persists data in PostgreSQL and integrates with the Google Translate API, while maintaining comprehensive observability via OpenTelemetry tracing and structured logging.

How it got here

2021 — Application bootstrap and multi-protocol support

15 changes.

The project established its core application structure by introducing a new entry point, 12-factor configuration, and structured logging. It implemented a multi-protocol server architecture supporting HTTP, gRPC, RabbitMQ RPC, and NATS RPC, alongside foundational domain entities and database migrations for user and task management.

2025 — Core service infrastructure and API implementation

6 changes.

This period focused on establishing the foundational backend architecture by implementing persistent repositories for PostgreSQL and external APIs, alongside a new gRPC server with JWT authentication. It also introduced a NATS-based RPC layer with OpenTelemetry tracing and secured the existing REST API with token-based authentication, creating a cohesive, observable, and secure service mesh.

Features

Add Nginx reverse proxy configuration for development services

A new Nginx configuration file has been added to act as a reverse proxy for local development, routing traffic from specific hostnames (app.lvh.me, grpc.lvh.me, rabbitmq.lvh.me, nats.lvh.me, jaeger.lvh.me) to their respective upstream services on port 80. This setup enables access to the main application, gRPC interface, RabbitMQ management, NATS monitoring, and Jaeger tracing UI through a single entry point with proper WebSocket and HTTP upgrade support.

nginx · high confidence

Application bootstrap and multi-protocol server initialization

The application entry point now initializes and runs four concurrent servers: HTTP (using Fiber with optional prefork mode), gRPC (with JWT authentication and OpenTelemetry tracing), RabbitMQ RPC, and NATS RPC. It also manages PostgreSQL connection pooling, JWT token management, and OpenTelemetry tracing configuration, while a separate migration entry point handles database schema updates via golang-migrate.

internal/app · high confidence

Application logic and observability for user, task, and translation domains

The internal/usecase layer now implements the core business logic for user authentication (register, login, get), task management (create, get, list, update, transition, delete), and translation (translate, history). Each domain is wrapped with OpenTelemetry tracing to provide end-to-end visibility from transport to repository. The implementation includes comprehensive unit tests for all use cases and generated mocks for the repository and use-case interfaces to support isolated testing.

internal/usecase · high confidence

Database schema updates for user authentication and task management

This change introduces new database migrations to support user authentication and task management features. It creates a \users\ table with unique username and email fields, a \tasks\ table linked to users via a foreign key with cascade deletion, and updates the \history\ table to include a \user\_id\ reference. These schema changes enable the storage of user credentials, task assignments, and user-specific history records.

migrations · high confidence

Introduce RabbitMQ RPC client with OpenTelemetry tracing and JSON optimization

Added a new RPC client implementation for RabbitMQ that enables request-reply messaging patterns. The client integrates OpenTelemetry for distributed tracing, automatically capturing spans for RPC calls, and utilizes the goccy/go-json library for high-performance JSON serialization. It supports configurable connection attempts, wait times, and call timeouts via functional options, while managing concurrent calls and connection lifecycle through structured error handling.

_pkg/rabbitmq/rmq\rpc/client · high confidence

Introduce core domain entities for user, task, and translation management

The internal entity package now defines the foundational data structures for the application's core features. This includes a User entity with authentication-related fields, a Task entity that enforces strict status transitions (todo, in\_progress, done) and includes validation logic, and Translation entities for handling source and target language data. Additionally, specific error variables for user and task operations have been added to support these business rules.

internal/entity · high confidence

Introduce persistent and web API repositories with OpenTelemetry tracing

The application now includes concrete repository implementations for Users, Tasks, and Translations, separating data access logic from use cases. Users and Tasks are backed by PostgreSQL using the pgx driver and Squirrel query builder, while Translations are fetched via the Google Translate web API. All repository operations are automatically instrumented with OpenTelemetry tracing spans, providing visibility into database queries and external API calls.

internal/repo · high confidence

Introduce structured logging with zerolog and caller information

The application now uses the zerolog library for structured, JSON-formatted logging. The new logger implementation supports configurable log levels (debug, info, warn, error) and automatically includes caller information (file and line number) in log entries to aid in debugging. This replaces previous logging mechanisms, providing consistent, machine-readable output for all application events.

pkg/logger · high confidence

Introduction of gRPC server infrastructure and JWT authentication support

This change introduces the core gRPC server implementation in pkg/grpcserver, providing a configurable, concurrency-safe server with graceful shutdown capabilities and option-based configuration (e.g., port, gRPC server options). It also adds a new JWT authentication package (pkg/jwt) that enables token generation and validation using HS256 signing, supporting user identity verification. These components lay the foundation for secure, authenticated gRPC services.

pkg/grpcserver · high confidence

NATS RPC v1 API with JWT authentication and task/translation management

The NATS RPC controller now exposes a v1 API layer that handles user registration and login, translation history and translation requests, and full CRUD operations for tasks (create, get, list, update, transition, delete). All endpoints except registration and login require a JWT token passed in the request envelope, which is validated via the JWT manager before the handler processes the payload. The router wires these handlers to specific NATS subject names (e.g., v1.task.create, v1.auth.login) and enforces input validation using go-playground/validator on all request structs.

_internal/controller/nats\rpc · high confidence

NATS RPC with OpenTelemetry tracing support

The NATS package now includes a new RPC layer (client and server) that implements the Request-Reply pattern over NATS, enabling structured remote calls with JSON serialization and specific error handling for timeouts, bad handlers, and internal errors. This RPC implementation is integrated with OpenTelemetry, automatically injecting trace context into NATS message headers and creating spans for client requests and server processing, while a new tracing package provides a configurable OTLP/gRPC exporter to send these traces to a backend.

pkg/nats · high confidence

New PostgreSQL connection package with configurable pool and retry settings

A new \pkg/postgres\ package has been introduced to manage PostgreSQL connections using the \pgx/v5\ driver. This package provides a \New\ function that accepts a connection URL and optional functional options to configure the connection pool size (\MaxPoolSize\), the number of connection attempts (\ConnAttempts\), and the timeout between retries (\ConnTimeout\). It automatically configures OpenTelemetry tracing via \otelpgx\ and includes a built-in retry mechanism that attempts to establish the connection multiple times before failing, improving resilience during startup.

pkg/postgres · high confidence

New RabbitMQ RPC client with OpenTelemetry trace propagation

The \pkg/rabbitmq/rmq\_rpc\ package introduces a new RabbitMQ RPC client implementation that uses the \github.com/rabbitmq/amqp091-go\ library for AMQP connections. This client supports configurable connection attempts and wait times, and includes built-in OpenTelemetry support via a \TableCarrier\ that injects and extracts trace context from AMQP message headers, enabling distributed tracing for RPC calls.

_pkg/rabbitmq/rmq\rpc · high confidence

New RabbitMQ RPC server with configurable connection and tracing support

A new RabbitMQ RPC server implementation has been added to the \pkg/rabbitmq/rmq\_rpc/server\ package, providing a structured way to handle RPC calls over AMQP. The server supports configurable connection retry attempts and wait times via functional options, uses the \goccy/go-json\ library for serialization, and integrates OpenTelemetry for distributed tracing of incoming messages. It runs a single goroutine for message handling to ensure ordered processing and provides a notification channel for shutdown errors.

_pkg/rabbitmq/rmq\rpc/server · high confidence

Behavioural changes

AMQP RPC controller now requires JWT authentication for all endpoints except registration and login

The AMQP RPC controller in \internal/controller/amqp\_rpc\ has been updated to enforce user authentication on all task and translation operations. The new \v1\ router registers handlers for \v1.auth.register\ and \v1.auth.login\ without requiring a token, but all other routes (task CRUD, task status transitions, and translation history/translation) now use the \extractUserID\ helper to validate a JWT token provided in the request envelope. If the token is missing, invalid, or expired, the RPC call fails with an authentication error. This change ensures that only authenticated users can manage tasks or access translation history via the AMQP RPC interface.

_internal/controller/amqp\rpc · high confidence

HTTP server migrated to Fiber with configurable prefork and timeouts

The HTTP server implementation in pkg/httpserver has been replaced with a new Fiber-based server. This change introduces support for Fiber's prefork mode via a new configuration option, allowing for improved concurrency handling. It also exposes configurable read, write, and shutdown timeouts to control server behavior. Additionally, the server now uses the goccy/go-json library for JSON encoding and decoding, replacing the standard library implementation.

pkg/httpserver · high confidence

Introduce new application entry point with configuration initialization

A new main entry point has been added to the cmd/app package. This file initializes the application configuration using the config package and passes it to the app.Run function to start the application, replacing the previous entry point structure.

cmd · high confidence

Introduction of 12-factor environment-based configuration

The application now uses a centralized configuration system that reads settings from environment variables using the 12-factor methodology. This change introduces support for configuring the HTTP server (including Fiber's prefork mode), gRPC, PostgreSQL, RabbitMQ, NATS, JWT authentication, metrics, Swagger documentation, and OpenTelemetry tracing. All configuration values are loaded at startup via the \caarlos0/env/v11\ library, allowing users to control application behavior entirely through environment variables without code changes.

config · high confidence

REST API now requires JWT authentication for protected endpoints

The REST API controller layer now enforces JWT-based authentication on user, task, and translation endpoints. A new middleware validates the Authorization header, rejecting requests with missing or malformed tokens and returning 401 Unauthorized. Protected routes under /v1/user, /v1/tasks, and /v1/translation now require a valid Bearer token to access, while /v1/auth/register and /v1/auth/login remain public. The router also integrates OTEL tracing for the API group and standard middleware for logging and panic recovery.

internal/controller/restapi · high confidence

Test coverage

Added integration tests for user authentication, task management, and translation features

The integration-test directory now includes a Dockerfile and Go test suite (helpers\_test.go, task\_test.go, translation\_test.go, user\_test.go) that verify the application's HTTP and gRPC endpoints. These tests cover user registration and login flows, task CRUD operations and status transitions, translation service history retrieval, and profile access, ensuring end-to-end functionality across HTTP REST, gRPC, RabbitMQ RPC, and NATS RPC interfaces.

integration-test · high confidence

Dependencies

Dependency and Go version update

The project's go.mod and go.sum files have been updated to use Go 1.27 and refresh numerous dependencies, including upgrading gRPC to v1.84.0, the PostgreSQL driver (pgx/v5) to v5.11.0, the Fiber web framework to v2.52.15, and the validator library to v10.30.4.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 64 → 62 (-2.5)
  • Rubric changed (rubric-2026.09.15 → rubric-2026.10.1) — scores are not directly comparable.

Lenses

  • Code Health 100 → 88 (-11.6)
  • Architecture 89 (new)
  • Maturity 61 → 63 (+2.2)
  • Readiness 55 → 57 (+1.8)
  • Security 82 → 83 (+1.3)
  • Domain Modelling 57 (new)

Resolved (4)

  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • High CVE: [GHSA redacted] (go.mod)
  • Off-boarding risk: anonymized user #1

New (43)

  • Duplicated block (11 lines × 2) (internal/controller/amqp_rpc/v1/auth.go)
  • Duplicated block (11 lines × 2) (pkg/nats/nats_rpc/errors.go)
  • Duplicated block (13 lines × 2) (internal/controller/amqp_rpc/v1/router.go)
  • Duplicated block (13 lines × 2) (internal/controller/grpc/v1/task.go)
  • Duplicated block (13 lines × 2) (internal/controller/restapi/v1/task.go)
  • Duplicated block (13 lines × 2) (pkg/nats/nats_rpc/client/client.go)
  • Duplicated block (20 lines × 2) (pkg/rabbitmq/rmq_rpc/client/client.go)
  • Duplicated block (34 lines × 2) (internal/controller/amqp_rpc/v1/request/task.go)
  • Duplicated block (6 lines × 2) (internal/controller/amqp_rpc/v1/task.go)
  • Duplicated block (6 lines × 2) (internal/controller/amqp_rpc/v1/task.go)
  • Duplicated block (6 lines × 2) (internal/controller/amqp_rpc/v1/task.go)
  • Duplicated block (6 lines × 2) (internal/controller/amqp_rpc/v1/task.go)
  • Duplicated block (6 lines × 2) (internal/controller/amqp_rpc/v1/task.go)
  • Duplicated block (6 lines × 2) (internal/controller/amqp_rpc/v1/user.go)
  • Duplicated block (6 lines × 2) (internal/controller/amqp_rpc/v1/user.go)
  • Duplicated block (7 lines × 2) (internal/controller/amqp_rpc/v1/translation.go)
  • Duplicated block (7 lines × 6) (internal/controller/restapi/v1/task.go)
  • Duplicated block (8 lines × 2) (internal/controller/amqp_rpc/v1/controller.go)
  • Duplicated block (8 lines × 2) (pkg/nats/nats_rpc/otel_carrier.go)
  • Duplicated block (8 lines × 3) (internal/controller/grpc/v1/task.go)
  • …and 23 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

evrone/go-clean-template was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 6 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit d40c828aa650497453db13ac3d8539c4086b96d9 — the exact code this score is about.
  • Scored under rubric-2026.10.1 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-1f9c535fa862.