Skip to content
CAI
Software that uses CAICheck a score

GStones/moke-kit

54.9

Adequate · 3 August 2026

4.7k

lines of production code

Go

primary language

3

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a modular Go application framework that provides a unified infrastructure for managing server lifecycles, data persistence, and messaging. It integrates gRPC, HTTP, and WebSocket services with a pluggable architecture for NoSQL (MongoDB, Redis) and SQL (GORM) storage, alongside support for multiple message queue backends (NATS, Kafka, etc.). The codebase emphasizes testability through extensive mock implementations and dependency injection, enabling secure, observable, and scalable service development.

How it got here

2023 — infrastructure and service layer expansion

24 changes.

The project significantly expanded its internal architecture by introducing a modular, dependency-injection-based framework using Uber fx. This period focused on building out core infrastructure components, including a unified server interface with connection multiplexing, a structured logging system, and a comprehensive message queue abstraction. Additionally, the codebase established robust data access layers for both SQL (GORM) and NoSQL (MongoDB, Redis) operations, supported by centralized error handling and utility packages.

2024–2025 — Agones integration and infrastructure modularization

14 changes.

This period focused on integrating the Agones game server framework by introducing SDK wrappers, interfaces, and mock implementations to support local development and testing. Concurrently, the codebase was refactored to adopt a modular, dependency-injection-based architecture, adding support for message queues, authentication, and secure gRPC communication.

Features

Add Agones SDK interface for game server lifecycle management

A new interface, IAgones, has been introduced to abstract the Agones SDK, providing methods for game server lifecycle management (Init, Ready, Health, Allocate, Shutdown, Reserve) and counter/list operations. This allows the application to interact with the Agones game server infrastructure through a defined contract, facilitating potential mocking or alternative implementations.

3rd/agones/aiface · high confidence

Add Agones SDK wrapper and mock implementations

Added a new Agones SDK wrapper in 3rd/agones/internal/sdk/agones.go that implements core lifecycle methods (Init, Ready, Health, Allocate, Shutdown, Reserve) and game server management (SetLabel, SetAnnotation, GameServer, WatchGameServer). Also added mock implementations in mock\_agones.go and mock\_alpha.go to support testing, including a MockCounterList for counter and list operations.

3rd/agones/internal/sdk · high confidence

Add Agones integration modules for SDK and allocation client

The application now includes support for the Agones Kubernetes game server framework. This change introduces Go modules for the Agones SDK and the allocation client, utilizing the fx dependency injection framework. The SDK module provides a production Agones client or a mock implementation for local development, while the allocation client module configures a secure gRPC client for the Agones allocator service, with environment variables available to configure URLs, certificates, and deployment modes.

3rd/agones/pkg · high confidence

Add IAP module with Apple and Google client initialization

The 3rd/iap area now includes a new IAP module that initializes clients for Apple App Store and Google Play Store. The module reads configuration from environment variables (such as private key paths, bundle IDs, and sandbox flags) and uses the go-iap library to create and inject these clients via the fx dependency injection framework.

3rd/iap · high confidence

Add MongoDB NoSQL driver implementation

Users can now persist data to MongoDB via the new internal NoSQL driver. The \driver.go\ file implements the \DatabaseDriver\ with \Set\, \Get\, \Delete\, and \Incr\ operations, supporting versioned updates and upserts. The \provider.go\ file introduces \DriverProvider\ to manage the MongoDB client lifecycle and create collection drivers.

orm/nosql/mongo/internal · high confidence

Add MongoDB client and provider factory

A new factory module for MongoDB has been introduced, providing a \NewProvider\ function to create document providers and a \NewMongoClient\ function to establish and verify connections to MongoDB instances.

orm/nosql/mongo · medium confidence

Add NATS message queue implementation

The NATS message queue implementation has been added to the internal message queue system. This includes the core message queue logic in \mq/internal/nats/message\_queue.go\, configuration in \mq/internal/nats/config.go\, and a Zap logger adapter in \mq/internal/logger/zaplogger.go\. The implementation integrates with the \watermill-nats\ library to provide subscribe and publish capabilities for NATS-based messaging.

mq/internal/nats · high confidence

Add NoSQL document base with read-through caching and concurrent update support

Introduced a new \DocumentBase\ in the \orm/nosql\ package that provides a base structure for NoSQL document operations. The implementation includes Create, Load, Update, Save, and Delete methods, with built-in read-through caching via an \ICache\ interface. The \Update\ method supports concurrent modifications using a compare-and-swap (CAS) pattern with exponential backoff retries. A corresponding test file \\_document\_test.go\ was added to verify CRUD operations and concurrent update scenarios.

orm/nosql · high confidence

Add NoSQL key abstraction for structured identifier management

Introduced a new \orm/nosql/key\ package that provides a \Key\ type for managing NoSQL identifiers. This includes validation of key formats, support for hierarchical paths with prefixes, and a global namespace mechanism to automatically prefix keys for multi-tenant isolation. Users can now construct, validate, and manipulate structured keys with built-in error handling and namespace support.

orm/nosql/key · high confidence

Add ORM and NoSQL module initialization for MongoDB, GORM, and Redis

The \orm/pkg/ofx\ package introduces new modules to initialize database and cache connections via the fx dependency injection framework. This includes \SettingsModule\ to load configuration from environment variables, \MongoPureModule\ to connect to MongoDB with optional authentication, \GormModule\ to open SQL database connections, and \RedisModule\ to establish Redis client connections for both primary and cache databases. Additionally, \DocumentStoreModule\ and \RedisCacheModule\ provide the respective providers and cache instances to the application graph.

orm/pkg/ofx · high confidence

Add ORM module with dependency injection for Redis, MongoDB, and GORM

A new Go module at orm/pkg/module.go introduces an fx.Module named 'orm' that registers the settings, MongoDB, document store, Redis, and GORM components for dependency injection.

orm/pkg/module · high confidence

Add Redis cache implementation

A new Redis cache implementation has been added to the system, introducing a \RedisCache\ struct that wraps the \go-redis/v9\ client. This provides concrete methods for getting, setting, and deleting cache entries using JSON serialization, with configurable expiration times ranging from 40 to 60 minutes.

orm/nosql/cache · high confidence

Add Zinx server implementation with logging and rate-limiting interceptors

A new Zinx-based server implementation has been added to the internal zinx package. The factory creates a Zinx server instance configured with TCP and WebSocket ports, worker pool sizes, and TLS settings. The server is initialized with two interceptors: a logger interceptor for structured logging and a rate-limiting interceptor, both using the zap logger.

server/internal/zinx · high confidence

Add authentication middleware and cloud configuration modules

New modules are introduced to support authentication and cloud configuration. For authentication, Firebase and Supabase middleware modules are added, enabling gRPC requests to be authenticated via Firebase ID tokens or Supabase tokens, with support for excluding specific methods from authentication checks. Additionally, an AWS configuration module is added to provide AWS SDK v2 configuration via environment variables for region, key, and secret.

3rd/auth · high confidence

Add connection multiplexing with TLS support

The server now includes a new connection multiplexer (cmux) that routes traffic to HTTP, gRPC, and WebSocket endpoints. The multiplexer supports TLS configuration, including automatic reloading of TLS certificates and client CA verification, providing a secure, unified entry point for multiple protocols on a single port.

server/internal/cmux · high confidence

Add internal error definitions for the message queue module

The file mq/internal/qerrors/errors.go was added, introducing a set of sentinel errors for the message queue (MQ) package. These errors cover subscription failures, unsupported MQ types, topic parsing issues, and missing implementations for Kafka, Nsq, NATS, and Local queues, as well as validation errors for subscriptions, data payloads, and topic values.

mq/internal/qerrors · high confidence

Add local in-memory message queue implementation

A new local message queue implementation has been added to the mq/internal/local package, providing an in-memory pub/sub mechanism backed by Watermill's GoChannel. This allows the application to use a lightweight, non-persistent message broker for local development or testing scenarios, supporting standard publish and subscribe operations with configurable buffer sizes and blocking behavior.

mq/internal/local · high confidence

Add local message queue support via fx modules

The mq/pkg/mfx package now includes a local message queue implementation alongside existing NATS, Kafka, and NSQ providers. A new \LocalModule\ is registered to provide a local \MessageQueue\ instance, and the central \MqModule\ aggregates all four implementations (NATS, Kafka, NSQ, and Local) to allow runtime selection of the active message queue. Configuration for the local queue (buffer size, persistence, and ack blocking) is exposed via environment variables and fx injection.

mq/pkg/mfx · high confidence

Add logging and rate-limiting interceptors for the Zinx server

The Zinx server now includes two new interceptors in the internal zinx package: a logging interceptor that records incoming messages at the debug level, and a rate-limiting interceptor that enforces request limits using the application's rate limiter middleware. These interceptors are now available for use in the server's request processing chain.

server/internal/zinx/interceptors · medium confidence

Add server module with unified service binding and lifecycle management

The server now includes a new \module\ package that centralizes the registration and lifecycle management of gRPC, Zinx (TCP/UDP/WebSocket), and HTTP gateway services. This module integrates OpenTelemetry provider initialization and shutdown, and uses the \fx\ framework to manage the start/stop lifecycle of all registered services and the connection mux.

server/pkg/module · high confidence

Add utility package with authentication, configuration, and deployment helpers

A new 'utility' package has been introduced, providing shared infrastructure for the application. This includes an authentication helper (auth.go) that allows methods to be called without an access token, a configuration loader (config.go) that retrieves settings from environment variables and HashiCorp Vault, a context helper (context.go) for managing bearer tokens and user IDs, and a deployment environment parser (deployment.go) to identify local, dev, or prod environments.

utility · high confidence

Added NoSQL interface and options for document and cache operations

The codebase now includes new interfaces for NoSQL document and cache operations. The \idocument.go\ file defines \IDocumentProvider\ and \ICollection\ interfaces, providing methods to open database drivers, and perform Set, Get, Delete, and Incr operations on NoSQL documents. The \icache.go\ file introduces the \ICache\ interface for caching documents, along with a default implementation. Additionally, \noptions/options.go\ provides a flexible options system for these operations, supporting versioning (WithVersion, WithAnyVersion), TTL, and source/destination data handling.

orm/nosql/diface · high confidence

Added gRPC server and client middleware infrastructure

The server/middlewares area now includes new files (auth.go, grpc\_middleware.go, logger.go, ratelimit.go, recovery.go) that implement core gRPC server and client interceptors. These provide rate limiting, authentication, structured logging, panic recovery, and OpenTelemetry integration for both unary and stream RPCs.

server/middlewares · high confidence

Added mock implementations for NoSQL database interactions

New mock implementations for NoSQL database interactions have been added to the orm/nosql/mock package. This includes a mock driver provider and collection that simulate database operations such as Set, Get, Delete, and Incr, allowing for easier testing of components that depend on NoSQL storage without requiring a real database instance.

orm/nosql/mock · high confidence

Introduce MQ module initialization

A new Go module is added to initialize the message queue (MQ) subsystem. The module registers the MQ and its associated settings via the fx dependency injection framework, wiring together the core MQ functionality and configuration.

mq/pkg/module · high confidence

Introduce SRPC server and gateway implementations

Added new files in server/internal/srpc to provide concrete implementations for gRPC and HTTP gateway servers. The GrpcServer struct manages a gRPC server instance, handling lifecycle methods to start and stop the server. The GatewayServer struct manages an HTTP server that acts as a gRPC-JSON gateway, including CORS headers and preflight handling. The factory functions NewGrpcServer and NewGatewayServer construct these instances, integrating with existing middleware and dependency injection patterns.

server/internal/srpc · high confidence

Introduce centralized error definitions for ORM operations

A new file, errors.go, has been added to the orm/nerrors package, defining a set of standard error variables (such as ErrNotFound, ErrVersionNotMatch, and ErrTooManyRetries) to be used across the ORM layer for consistent error handling.

orm/nerrors · high confidence

Introduce common message queue abstractions

Added new Go files in the mq/common package to define shared message queue types and utilities. This includes ConsumptionCode for handling message acknowledgment states (ack, final, nack transient/persistent), DeliverySemantics for at-least-once and at-most-once delivery guarantees, Header constants for different messaging protocols (Kafka, Nats, Nsq, Local), and a global namespace mechanism to support multi-tenant topic naming conventions.

mq/common · medium confidence

Introduce fxmain module for application lifecycle management

A new fxmain module has been added to the project, providing a structured way to initialize and run the application using the Uber fx dependency injection framework. This includes an application wrapper (fxmain.go) that manages the start and stop lifecycle, an internal package (internal/) that handles the core fx.App logic and server launching, and a settings module (pkg/mfx/app\_setting.go) that loads application configuration (AppName, AppId, Deployment, Version) from environment variables. The main application module (pkg/module/app\_module.go) ties together the settings, server, ORM, logging, and message queue modules, allowing users to bootstrap the application with a single call.

fxmain · high confidence

Introduce modular server configuration and infrastructure setup

Added new modules for server settings, security (TLS/mTLS) configuration, connection multiplexing, and OpenTelemetry tracing. The server now loads environment variables for ports, timeouts, rate limits, and TLS certificates, and initializes the OTel provider for metrics and traces.

server/pkg/sfx · high confidence

Introduce mq/miface package with message queue abstractions

Added the mq/miface package, which defines the core interfaces for the message queue system. This includes the MessageQueue interface for subscribing and publishing, the Subscription interface for managing subscriptions, and the Message interface for accessing message metadata. The package also introduces functional options for configuring publish operations (WithBytes, WithJSON, WithDelay) and subscription delivery semantics (WithAtLeastOnceDelivery, WithAtMostOnceDelivery).

mq/miface · high confidence

Introduce server interface definitions for authentication, server lifecycle, and service registration

Added new interface definitions in the server package to standardize how components interact with the server infrastructure. The changes introduce IAuthMiddleware for request authentication and unauthenticated method configuration, IServer and its specialized variants (IConnectionMux, IGrpcServer, IGatewayServer, IZinxServer) to manage server lifecycle and listener creation, and service interfaces (IGatewayService, IZinxService, IGrpcService) to define how services register with their respective server types.

server/siface · high confidence

Introduce structured logging with environment-aware configuration

The application now uses a structured logging library (zap) with a new logger module that configures output based on the deployment environment: production mode uses standard logging, while development mode enables colored, human-readable output. A separate slogger package provides simple console logging for shell interactions. The logger is provided via dependency injection for use throughout the application.

logging · high confidence

Behavioural changes

Secure gRPC client with automatic TLS certificate hot-reload

The server's gRPC client now supports mutual TLS (mTLS) connections, allowing clients to authenticate using client certificates. The implementation in server/tools introduces a new DialWithSecurity function that configures TLS with a specified server CA and client certificate/key pair. A key behavioral change is the addition of filesystem watching for the client certificate and key files; when these files are updated on disk, the client automatically reloads the certificate without requiring a restart, ensuring secure connections remain valid after certificate rotations.

server/tools · high confidence

Test coverage

Added comprehensive tests for logging, message queue, NoSQL, server, and utility modules; Added mock allocation service client for testing; Added tests for local and NATS message queue implementations.

Dependencies

Updated Go dependencies and module configuration

The project's go.mod and go.sum files have been updated to include a comprehensive set of dependencies, including AWS SDK v2, Google Cloud libraries, OpenTelemetry, Redis, and NATS. The Go version has been upgraded to 1.24.2, and various libraries such as go-jose, golang-jwt, and golang.org/x packages have been updated to their latest versions.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 55 → 55 (+0.0)
  • Rubric changed (rubric-2026.08.18 → rubric-2026.08.19) — scores are not directly comparable.

Lenses

  • Code Health 97 → 97 (+0.0)
  • Architecture 100 → 100 (+0.0)
  • Maturity 58 → 58 (+0.0)
  • Readiness 66 → 66 (+0.0)
  • Security 39 → 39 (+0.0)

Resolved (9)

  • Duplicated block (6 lines × 2) (3rd/auth/pkg/authfx/firebase_middleware.go)
  • Duplicated block (6 lines × 2) (server/internal/srpc/gateway.go)
  • Duplicated block (6 lines × 3) (mq/internal/logger/zaplogger.go)
  • Duplicated block (9 lines × 2) (mq/internal/local/message_queue.go)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)

New (9)

  • Duplicated block (5 lines × 2) (3rd/auth/pkg/authfx/firebase_middleware.go)
  • Duplicated block (5 lines × 2) (server/internal/srpc/gateway.go)
  • Duplicated block (5 lines × 3) (mq/internal/logger/zaplogger.go)
  • Duplicated block (8 lines × 2) (mq/internal/local/message_queue.go)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

GStones/moke-kit was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 3 August 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 51decbce448c3649857ae0bcfc6c986cbbe9b655 — the exact code this score is about.
  • Scored under rubric-2026.08.19 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer latest.