jorge07/symfony-7-es-cqrs-boilerplate
58.7
Adequate · 22 September 2026
4.8k
lines of production code
PHP
primary language
7
measurements over time
What this system is
This system is a Symfony-based boilerplate designed to scaffold applications using a Command-Query Responsibility Segregation (CQRS) architecture with event sourcing capabilities. It provides a complete infrastructure stack for user authentication, including registration, sign-in, and profile management, backed by MySQL for read models and Elasticsearch for event storage. The platform supports both REST API and web UI interfaces, managed through Docker and Kubernetes for consistent local development and production deployment.
How it got here
2018 — Symfony 7 migration and CQRS adoption
30 changes.
The project underwent a major architectural overhaul, migrating from Symfony 4 to Symfony 7 and replacing the Broadway event-sourcing library with Symfony Messenger for command and query handling. This transition established a CQRS-based structure with dedicated REST and web UI layers, while simultaneously modernizing the development stack with PHP 8.3, updated tooling, and comprehensive end-to-end test coverage.
2020–2021 — CQRS boilerplate and user authentication
9 changes.
This period focused on establishing the foundational architecture for a Symfony 5 CQRS boilerplate, introducing shared domain components, command/query buses, and infrastructure for MySQL and Elasticsearch. It also implemented a complete User bounded context with authentication, registration, and read-model support, alongside comprehensive testing and deployment configurations for both CI and production environments.
Features
Add CI environment configuration for MySQL and Docker Compose
This change introduces new configuration files for the CI environment. A new \docker-compose.yml\ file is added as an override that relies on the base configuration, and a \custom.cnf\ file is created for MySQL to optimize performance and compatibility settings, including binding to all addresses, adjusting InnoDB flush and lock wait timeouts, increasing connection limits, setting UTF-8 character sets, and enforcing InnoDB as the default storage engine.
etc/ci · high confidence
Add REST API endpoint for listing events with input validation
Introduces the GetEventsController to expose a GET /events endpoint that retrieves a paginated list of events. The controller validates the 'page' and 'limit' query parameters using the Assert library to ensure they are numeric, casting them to integers before passing them to the underlying GetEventsQuery. It returns a JSON collection response and includes OpenAPI annotations for documentation, requiring Bearer token authentication.
src/UI/Http/Rest/Controller/Event · high confidence
Add default Kibana development configuration
A new default configuration file for Kibana in the development environment has been added, establishing the basic connection settings required to run the service locally. This configuration sets the server name to 'kibana', binds the server to '0.0.0.0' to allow external access, and points the Elasticsearch host to 'http://elasticsearch:9200', ensuring the Kibana instance can communicate with the Elasticsearch container in the local dev stack.
etc/dev/kibana · high confidence
Add production Docker Compose configuration and infrastructure
This change introduces the necessary Docker Compose files and configuration to run the application in production mode. It adds a main \docker-compose.yml\ defining services for Nginx, PHP, workers, MySQL, RabbitMQ, Kibana, and Elasticsearch, with PHP and workers explicitly configured for \APP\_ENV=prod\ and debugging disabled. A Windows-specific Docker Compose file is also added to configure Xdebug connectivity. Additionally, Nginx configuration is provided with security headers and PHP-FPM proxying, while Kibana configuration is set up to connect to the Elasticsearch service.
etc/prod · high confidence
Add web UI templates for authentication and profile pages
The web interface now includes Twig templates for the sign-in, sign-up, and profile pages, along with a base layout and reusable components. Users can now log in, register new accounts, and view their profile information through a Bulma-styled interface that includes a responsive navigation menu and form handling for credentials.
src/UI/Http/Web/templates · high confidence
Added Nginx configuration for PHP application serving
A new Nginx configuration file has been added to serve the PHP application from the /app/public directory. The configuration includes security headers (X-Frame-Options, X-Content-Type-Options, X-XSS-Protection, Referrer-Policy), limits client upload size to 10MB, and routes requests through FastCGI to a PHP-FPM process listening on 127.0.0.1:9000, supporting standard PHP routing via try\_files.
etc/artifact/nginx · high confidence
Added health check endpoint for ElasticSearch and MySQL
A new /healthz REST endpoint has been introduced to monitor the availability of downstream dependencies. When accessed, the controller checks the health status of both the ElasticSearch event repository and the MySQL user read-model repository, returning a 200 OK response if both are healthy, or a 500 Internal Server Error with details on which service is failing if either is down.
src/UI/Http/Rest/Controller/Healthz · high confidence
Initial Helm chart for Symfony 5 CQRS boilerplate
This change introduces the complete Helm chart for the Symfony 5 CQRS boilerplate application, enabling deployment to Kubernetes. The chart defines the application's infrastructure, including deployments for the PHP-FPM and Nginx containers, a dedicated worker deployment for handling asynchronous messages via RabbitMQ, and a migration job to run database schema updates on install or upgrade. It also configures the necessary Kubernetes resources such as Services, Ingress (with TLS support), and Horizontal Pod Autoscaling. The chart manages secrets for application configuration, MySQL connection strings, and JWT keys, and includes dependencies for RabbitMQ, MySQL, Elasticsearch, and Traefik, allowing users to deploy the full stack with a single Helm release.
etc/artifact/chart · high confidence
Initial project scaffolding and configuration
This change introduces the foundational configuration files for the Symfony 7 boilerplate, including environment templates (.env, .env.test), Docker Compose definitions for the application and dependencies (MySQL 8, RabbitMQ, Elasticsearch), and static analysis tooling (PHPStan, Psalm, Easy Coding Standard). It also establishes the project's coding standards, contributor tracking, and CI/CD integration points.
(repo-wide) · high confidence
Introduce shared application, domain, and infrastructure components
This change adds a new set of shared foundational components to the application, including command and query bus interfaces, a query collection handler for paginated event retrieval, and domain value objects like DateTime. It also introduces infrastructure implementations for these buses using Symfony Messenger, an asynchronous event publisher, and repositories for both MySQL and Elasticsearch, alongside custom Doctrine migration factories and type mappings to support the new architecture.
src/App/Shared · high confidence
New CLI command for user creation and HTTP session helper
Users can now create new users via the command line using the new \app:create-user\ command, which accepts email, password, and an optional UUID. Additionally, a new \Session\ helper class in the HTTP UI layer has been introduced to retrieve the currently authenticated user from the token storage, throwing an exception if the credentials are invalid.
src/UI/Cli · high confidence
New OpenApi response class for structured JSON:API-style payloads
A new OpenApi class has been added to the HTTP REST response layer, extending Symfony's JsonResponse to provide factory methods for generating structured API responses. This class supports creating single-item responses with relationships, empty responses, created responses with location headers, and paginated collections with metadata, enabling consistent formatting of API output for clients.
src/UI/Http/Rest/Response · high confidence
New User Authentication and Read-Model Infrastructure
The User module now includes a complete authentication stack and read-model infrastructure. A new Auth class implements Symfony's security interfaces, supported by an AuthProvider for user loading and a LoginAuthenticator for handling sign-in requests. Password handling is managed via a dedicated PasswordHasher, while JWT token generation is provided by an AuthenticationProvider. For data persistence, custom Doctrine types (EmailType, HashedPasswordType) ensure value objects are correctly mapped, and a MysqlReadModelUserRepository handles read-side queries. Event projections (UserProjectionFactory) keep the read model in sync with domain events, and a UniqueEmailSpecification enforces email uniqueness at the application level.
src/App/User/Infrastructure · high confidence
New User Domain and Application Layer for Authentication
The User bounded context now includes a complete domain and application layer to support user registration, sign-in, and email management. This introduces command handlers for signing in and signing up users, query handlers for retrieving authentication tokens and user details by email, and domain entities that utilize event sourcing for user state changes. The implementation enforces unique email constraints, validates credentials using hashed passwords, and defines specific domain exceptions for invalid credentials and duplicate emails.
src/App/User/Domain · high confidence
New web UI controllers for home, profile, sign-in, and sign-up
The web UI layer now includes dedicated controllers to handle core user-facing pages. A new AbstractRenderController provides a base for rendering Twig templates and delegating to command/query buses. Concrete controllers expose routes for the home page (/), user profile (/profile), authentication (/sign-in with login/logout handling), and account creation (/sign-up with GET form and POST submission logic including conflict/bad-request handling).
src/UI/Http/Web/Controller · high confidence
Removals
Removal of Broadway event bus adapter and database migration
The \CommandBusBroadwayAdapter\ class, which previously bridged the Tactician command bus with the Broadway event handling system, has been removed from the infrastructure layer. Additionally, the database migration file \Version20180102233829.php\, responsible for configuring the schema for the \DBALEventStore\ and managing the \api.events\ table, has been deleted. These changes indicate a decoupling or removal of the Broadway event sourcing components from this part of the application.
src/Infrastructure · high confidence
Removal of legacy Symfony Kernel and User domain class
The \src/Kernel.php\ file, which configured the Symfony application environment, bundles, and routing, has been deleted. Additionally, the \src/Domain/User/User.php\ class, which implemented the user aggregate root using the Broadway event-sourcing library, has been removed. These deletions indicate a structural shift away from the previous Symfony/Broadway setup in this area.
src/Domain/User · high confidence
Removal of legacy user creation command and handler
The CreateUserCommand and CreateUserHandler classes in the Application layer have been removed. This eliminates the previous mechanism for creating users via a command handler that instantiated a User aggregate and stored it via the repository, indicating a shift in how user creation is processed within the application.
src/Application · high confidence
Behavioural changes
Debug mode defaults to false in production environments
The public entry point now explicitly calculates the debug state and defaults it to false when the application environment is set to 'prod'. This ensures that detailed error pages and debugging tools are disabled by default in production deployments, improving security and performance. The change also updates the kernel instantiation to use this calculated debug flag and adds strict typing declarations.
public · high confidence
Enhanced Nginx security headers and PHP-FPM configuration
The development Nginx configuration now includes security headers (X-Frame-Options, X-Content-Type-Options, X-XSS-Protection, Referrer-Policy) and sets a client body size limit of 10MB. Additionally, the PHP-FPM location block has been updated to explicitly define the fastcgi\_index and PATH\_INFO parameters, ensuring more robust handling of PHP requests in the dev environment.
etc/dev/nginx · high confidence
Introduction of CQRS-based REST controller hierarchy
The REST API layer now utilizes a Command-Query Responsibility Segregation (CQRS) structure through three new abstract base controllers: QueryController, CommandController, and CommandQueryController. QueryController provides helpers for executing queries via a QueryBus and formatting responses as JSON collections or items, including automatic cache decoration for immutable data. CommandController offers a standardized method to dispatch commands via a CommandBus. CommandQueryController combines both capabilities, allowing endpoints to handle both reads and writes within a single controller class.
src/UI/Http/Rest/Controller · high confidence
Migrate to Symfony 7 and replace Tactician with Messenger for command/query buses
The application has been upgraded to Symfony 7, introducing several significant configuration changes. The Tactician library has been removed and replaced with Symfony Messenger for handling command, query, and async event buses, requiring updates to service bindings and handler tags in \services.yaml\. Routing has shifted from annotations to attributes, and controllers are now split into API and web namespaces. New bundles for Security, JWT Authentication, API Documentation, and Monolog have been added, while legacy bundles like DoctrineCache and SensioFrameworkExtra have been removed. Additionally, a new exception-to-HTTP-status mapping is configured to automatically translate domain exceptions into appropriate API responses.
config · high confidence
Modernized User and Auth REST controllers with Symfony 6+ attributes and OpenAPI documentation
The User and Auth REST controllers have been refactored to use Symfony 6+ native attributes (replacing deprecated Sensio annotations) and include OpenAPI (Swagger) documentation for all endpoints. New controllers were added for authentication (CheckController for sign-in), user lookup by email (GetUserByEmailController), and user sign-up (SignUpController). The existing UserChangeEmailController was updated to enforce stateless Bearer token authentication, validate UUIDs against the current session, and return proper HTTP status codes. The legacy CreateUserController was removed as its functionality is superseded by the new SignUpController.
src/UI/Http/Rest/Controller/User · high confidence
Refactored HTTP event subscribers for Symfony 6 compatibility and JSON-only exception handling
The \ExceptionSubscriber\ has been updated to implement \EventSubscriberInterface\ and now exclusively handles exceptions for JSON requests, ignoring non-JSON content types. It no longer exposes stack trace details in the error response body for non-development environments, and status codes are determined via a configurable \exceptionToStatus\ map rather than hardcoded exception type checks. Additionally, a new \JsonBodyParserSubscriber\ has been introduced to automatically parse JSON request bodies and populate the request parameters, ensuring consistent input handling for REST endpoints.
src/UI/Http/Rest/EventSubscriber · high confidence
Removal of UserEmailChanged event
The UserEmailChanged domain event has been removed from the system. This change eliminates the specific event used to track when a user's email address is updated, which may affect any existing projections or handlers that relied on this event to maintain consistency.
src/Domain/User/Event · high confidence
Fixes
Updated console kernel namespace and Dotenv configuration
The application console now instantiates the kernel from the new App\\Shared\\Infrastructure\\Kernel namespace instead of the previous App\\Kernel location. Additionally, the Dotenv loader in the console entry point now explicitly allows loading from the .env file even if it does not exist, preventing potential runtime errors during environment setup.
bin · high confidence
Test coverage
Added AbstractConsoleTestCase for CLI command testing; Added and refactored end-to-end tests for user and authentication controllers; Added comprehensive test suite for User domain and application logic; Added end-to-end test for the Healthz controller; Added end-to-end tests for the GetEvents API controller; Added end-to-end tests for web UI controllers; Added integration test for CreateUserCommand; Added test infrastructure for REST API controllers and OpenAPI response formatting; Added unit tests for JsonBodyParserSubscriber; Removed ChangeEmailHandler integration test; Removed User domain unit tests; Removed integration test for user creation command handler.
Dependencies
Upgrade to Symfony 7 and PHP 8.3 with modernized dependencies
The project has been upgraded to require PHP 8.3 and Symfony 7.0, replacing the previous Symfony 4.x stack. This update introduces several new capabilities and changes: Doctrine ORM 3.2 is now used for persistence, replacing older versions; Elasticsearch 7.11 is added for search functionality; and Symfony Messenger with AMQP support is included for asynchronous communication. Development tooling has also been significantly updated, adding PHPStan 2.0, Psalm 5.0, Rector 2.0, and PHPUnit 10.5, while removing legacy packages like SensioFrameworkExtraBundle and broadway/broadway in favor of broader ecosystem standards. The autoloading structure has been refined to separate App and UI namespaces.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 70 → 59 (-11.5)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 100 → 100 (+0.0)
- Architecture 100 → 74 (-25.9)
- Maturity 59 → 59 (+0.0)
- Readiness 73 → 73 (+0.6)
- Security 70 → 77 (+7.1)
- Domain Modelling 100 → 100 (-0.0)
- Event Sourcing 100 → 100 (+0.0)
- Accessibility 46 (new)
Resolved (10)
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- LLM evaluation failed
- Medium IaC: CKV_DOCKER_3 (etc/artifact/Dockerfile)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- No exposed public API
- Off-boarding risk: anonymized user #1
- Test reliability not included
New (29)
- Abandoned package: broadway/broadway-bundle
- Abandoned package: broadway/event-store-dbal
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Medium IaC: WD-COMPOSE-0002 (docker-compose.yml)
- Medium IaC: WD-COMPOSE-0002 (docker-compose.yml)
- Medium IaC: WD-COMPOSE-0002 (docker-compose.yml)
- Medium IaC: WD-COMPOSE-0002 (docker-compose.yml)
- Medium IaC: WD-COMPOSE-0002 (etc/dev/docker-compose.yml)
- Medium IaC: WD-COMPOSE-0002 (etc/prod/docker-compose.yml)
- Medium IaC: WD-DOCKER-0003 (etc/artifact/Dockerfile)
- Medium IaC: WD-DOCKER-0003 (etc/artifact/Dockerfile)
- Medium IaC: WD-DOCKER-0003 (etc/artifact/Dockerfile)
- Medium IaC: WD-K8S-0004 (etc/artifact/chart/templates/deployment-worker.yaml)
- Medium IaC: WD-K8S-0004 (etc/artifact/chart/templates/deployment.yaml)
- Medium IaC: WD-K8S-0004 (etc/artifact/chart/templates/migrations.yaml)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- …and 9 more
Changes since last survey
- 1 commits — 1 feature/other, 0 fixes
By area
- (root) — 1 commit
Notable commits
- change: Bump squizlabs/php_codesniffer from 3.13.5 to 3.13.6 (#262)
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
jorge07/symfony-7-es-cqrs-boilerplate was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 22 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 7dce1e52669f392903a04f397e8b4cb80465b5ff — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-821afab8930d.