Skip to content
CAI
Software that uses CAICheck a score

mehdihadeli/food-delivery-microservices

47.5

Weak · 20 September 2026

15.6k

lines of production code

C#

with TypeScript

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a food delivery microservices platform built on .NET 10, featuring dedicated services for product catalog management, customer profiles, and identity verification. It enables core business operations such as product CRUD, stock level tracking, and automated restock notifications for customers. The architecture supports multiple client types through Backend-for-Frontend services and an API gateway, with infrastructure managed via Kubernetes and local orchestration using .NET Aspire.

How it got here

2022–2023 — Microservices modernization and tooling

9 changes.

The project was restructured into a Food Delivery Microservices architecture targeting .NET 10, introducing .NET Aspire for local orchestration and centralized dependency management. Comprehensive development tooling was established, including Husky pre-commit hooks, CSharpier formatting, and automated Docker and test scripts to streamline the developer workflow.

2024 — v1 API implementation and infrastructure setup

16 changes.

This period focused on implementing v1 API endpoints for the Catalog, Identity, and Customers services, introducing features such as product management, user identity verification, and restock subscriptions. The work also established the foundational infrastructure, including a YARP-based API gateway, Kubernetes deployment manifests, and a standardized development container environment. Additionally, the codebase migrated event consumption to Wolverine and adopted the CloudNativeKit framework for minimal APIs, accompanied by comprehensive test coverage for the new services.

2025–2026 — BFF architecture and SPA implementation

5 changes.

This period focused on establishing a Backend-for-Frontend (BFF) architecture with dedicated services for Web, Mobile, and SPA clients, supported by comprehensive observability and identity configurations. The React SPA was developed with new home, user profile, and product management features, integrated via the BFF layer. Standardized HTTP error handling using RFC 9457 Problem Details was also implemented to ensure a consistent user experience.

Features

Add product management UI and API integration

The React SPA now includes a complete set of components for managing products, including a paginated list view with low-stock and inactive status indicators, a detailed product view with image display, and forms for creating and editing product details. These components are backed by a new \productApiService\ that communicates with the backend via the SPA BFF gateway, supporting full CRUD operations (create, read, update, delete) and product search.

src/UIs/Spa/react-food-delivery/src/features/products · high confidence

Added HTTP client request files for API testing

New \.http\ files and environment configuration files have been added to the \\_httpclients\ directory to support manual API testing and development. These files define request templates for the Identity, Catalogs, and Customers services, covering authentication flows (Implicit, Client Credentials, PKCE) and CRUD operations for products, customers, and restock subscriptions. Environment variables for local development endpoints and secrets are now centralized in \http-client.env.json\ and \http-client.private.env.json\.

_\httpclients · high confidence

Automated devcontainer setup with .NET Aspire, fonts, and tooling

The development container environment now automatically configures essential tools and resources upon creation. It installs the .NET Aspire project templates and CLI tools (including 'aspirate'), sets up the MesloLGM Nerd Font for better terminal rendering, trusts HTTPS development certificates, and installs global utilities like the xunit v3 templates, the Just task runner, and the latest npm version. This streamlines the initial setup process for developers by ensuring all necessary dependencies and configurations are ready out of the box.

.devcontainer/scripts · high confidence

Customers service implements restock subscription management and customer retrieval features

The Customers service now exposes endpoints to retrieve customers by ID or customer ID, and manages restock subscriptions. Users can query paginated restock subscriptions by email and date range, and the service processes restock notifications by marking subscriptions as processed and sending email alerts to subscribed customers when products are back in stock. These features are implemented using the CloudNativeKit framework for minimal APIs, validation, and command/query handling.

(repo-wide) · high confidence

Initial Kubernetes deployment manifests and Kustomize structure

This change introduces the foundational Kubernetes deployment configuration for the food-delivery microservices. It adds a \.env.prod\ file defining environment variables and ports for services like RabbitMQ, MongoDB, Postgres, and the application microservices (Catalogs, Customers, Identity, Orders). It includes raw Kubernetes manifests in \kubernetes/\ (e.g., \infrastructure.yaml\ for RabbitMQ/MongoDB deployments, services, and ingresses) and a \kubectl\ helper script for environment variable substitution. Additionally, it establishes a Kustomize structure under \kustomize/food-delivery/\ with base configurations and \dev\/\prod\ overlays for each microservice, enabling environment-specific deployments with name prefixes.

deployments/k8s · high confidence

Introduce .NET Aspire application host and service defaults for local development

Developers can now launch the entire food delivery ecosystem locally using .NET Aspire, which provisions and wires up infrastructure resources like Postgres, MongoDB, RabbitMQ, Redis, and observability tools (Jaeger, Zipkin, Prometheus, Grafana) automatically. This change adds the \FoodDelivery.AppHost\ project to orchestrate these services and the \FoodDelivery.ServiceDefaults\ library to provide shared configuration for health checks, OpenTelemetry diagnostics, HTTP logging, and resilient HTTP/gRPC client registration, ensuring consistent behavior across all microservices.

src/Services · high confidence

Introduce YARP-based API Gateway with BFF routing and observability

The ApiGateway service has been implemented using YARP (Yet Another Reverse Proxy) to route incoming requests to specific backend clusters, including dedicated routes for SPA, API, and mobile BFFs as well as identity and health check services. The gateway now automatically injects correlation IDs and forwards user context (X-User-Id) and authorization headers to downstream services. It also enforces CORS policies for React applications and integrates with OpenTelemetry for distributed tracing, exporting telemetry to OTLP, Zipkin, and Jaeger endpoints.

src/ApiGateway/FoodDelivery.ApiGateway · high confidence

Introduce dedicated BFF services for Web, Mobile, and SPA clients

This change introduces three new Backend-for-Frontend (BFF) services—Web, Mobile, and SPA—located in src/Bffs, each tailored to its client type. The Web BFF uses JWT Bearer authentication and typed HttpClient instances for direct microservice calls, while the Mobile BFF and SPA BFF utilize OpenID Connect with cookie-based sessions and Duende BFF middleware for secure token management and anti-forgery protection. All three services are configured with YARP reverse proxy settings to route requests to backend clusters (catalogs, customers, identity) and include specific OAuth options, telemetry configurations, and launch settings for local development.

src/Bffs, src/UIs · high confidence

Introduce v1 APIs for creating products and retrieving users

This change adds the initial v1 implementation for two core capabilities: creating a new product in the Catalog service and retrieving a user by ID in the Identity service. For product creation, the diff introduces a minimal API endpoint (POST /api/v1/catalog/products) that accepts product details, validates them via FluentValidation, and persists the product to the database, while also emitting a domain event to update the product view. For user retrieval, a new GET /api/v1/users/{userId} endpoint is added to the Identity service, which fetches the user details using ASP.NET Core Identity and returns the DTO. Both endpoints are versioned at 1.0 and use the CloudNativeKit abstractions for command/query handling.

src/Services/Catalogs/FoodDelivery.Services.Catalogs/Products/Features/CreatingProduct, src/Services/Identity/FoodDelivery.Services.Identity/Users/Features/GettingUserById · high confidence

New Docker and test automation scripts for development workflows

Added shell scripts to streamline local development and CI processes: \base-run.sh\, \debug-run.sh\, \dev-run.sh\, and \prod-run.sh\ provide standardized ways to start Docker containers with appropriate volume mounts for source code, debugging symbols (vsdbg), and NuGet packages, specifically supporting VS Code remote debugging. A new \lint-dockerfiles.sh\ script integrates hadolint to validate Dockerfiles, and \run-tests.sh\ automates .NET test execution with configurable coverage and verbosity settings.

scripts · high confidence

New home page and user session details view

The SPA now includes a new home page component that displays a hero banner, placeholder sections for categories and popular items, and a 'How It Works' feature overview. Additionally, a new user session view has been added to the user-profile feature, allowing users to see their current authentication claims in a table format with loading and error states.

src/UIs/Spa/react-food-delivery/src/features/home, src/UIs/Spa/react-food-delivery/src/features/user-profile · high confidence

New observability and identity configuration for deployment

This update introduces a comprehensive set of configuration files for the \deployments/configs\ area, establishing the infrastructure for application monitoring and identity management. It adds provisioning and dashboard definitions for Grafana (including ASP.NET Core, Node Exporter, PostgreSQL, and RabbitMQ metrics), along with configuration for the OpenTelemetry Collector, Prometheus, Loki, Tempo, and Jaeger to enable distributed tracing and logging. Additionally, it includes a Keycloak realm JSON file defining users and roles for the microservices, an SQL script to initialize PostgreSQL databases, and a Traefik gateway configuration to route traffic to the new BFF (Backend for Frontend) services.

deployments/configs · high confidence

New product catalog and identity API endpoints

This release introduces new API endpoints for the Catalog and Identity services. In the Catalog service, users can now retrieve a paginated, filtered, and sorted view of products via the new GET /products-view endpoint, and the codebase now includes the command and event structures for changing product max thresholds, restock thresholds, brands, and suppliers. In the Identity service, a new GET /claims endpoint allows authenticated users to retrieve their current identity claims.

(repo-wide) · high confidence

New product catalog and identity management endpoints

The Catalogs service now exposes v1 API endpoints for retrieving products by ID, updating product details, and managing stock levels (debiting and replenishing), along with domain events for stock changes and category updates. The Identity service adds endpoints for sending email verification codes and verifying user emails, as well as a query to retrieve user details by email address.

(repo-wide) · high confidence

New v1 API endpoints for product listing, customer retrieval, and restock subscription management

This change introduces a set of new v1 API endpoints for the Catalogs and Customers services, implemented using the CloudNativeKit framework and Minimal APIs. Users can now retrieve paginated product lists via the Catalogs service and fetch customer data via the Customers service. Additionally, the Customers service exposes new endpoints to manage restock subscriptions, including retrieving a specific subscription by ID, deleting a single subscription, and bulk-deleting subscriptions by a time range. These endpoints handle validation, authorization (where specified), and database interactions through the new CloudNativeKit-based handlers.

(repo-wide) · high confidence

Project restructured as Food Delivery Microservices with .NET 10 and new tooling

The repository has been rebranded from 'Store Microservices' to 'Food Delivery Microservices' and upgraded to target .NET 10.0, utilizing the new .slnx solution format. This change introduces a comprehensive development toolchain, including a Makefile for build and quality checks, Husky for conventional commits, CSharpier for code formatting, and Gitleaks for secret detection. The project also integrates the CloudNativeKit submodule for building blocks and configures .NET Aspire for local orchestration.

(repo-wide) · high confidence

Behavioural changes

Add Husky pre-commit hooks for code formatting and analysis

The repository now enforces code style and analysis standards automatically before commits are accepted. A new Husky configuration runs C\# formatting via CSharpier, verifies code style consistency, and checks analyzers on every pre-commit, ensuring that submitted code meets the project's quality requirements without manual intervention.

.husky · high confidence

Adopt Wolverine for event consumption in customer and order services

The Customer and Orders services now use Wolverine to handle integration events, replacing the previous messaging implementation. New consumer classes (ProductCreatedConsumer, ProductStockReplenishedConsumer, CustomerCreatedConsumer) have been added to process incoming messages via the Wolverine framework, enabling automatic acknowledgment handling and integration with the CloudNativeKit sub-module for message execution.

src/Services/Customers/FoodDelivery.Services.Customers/Products/Features/CreatingProduct, src/Services/Customers/FoodDelivery.Services.Customers/Products/Features/ReplenishingProductStock, src/Services/Orders/FoodDelivery.Services.Orders/Customers/Features/CreatingCustomer · high confidence

ApiGateway Dockerfiles updated to .NET 10 and .NET 9 with build caching

The Dockerfiles for the ApiGateway have been updated to use the .NET 10.0 SDK and ASP.NET runtime images for production builds (Dockerfile) and .NET 9.0 for development builds (Dockerfile.dev). The development Dockerfile now includes NuGet package caching via BuildKit mounts to optimize build times, while both files retain the existing multi-stage build structure and entrypoint configuration.

src/ApiGateway · high confidence

Customers and Restock Subscription features migrated to CloudNativeKit minimal API pattern

The Customers service's Create, Update, and Get Restock Subscription endpoints have been rewritten to use the CloudNativeKit framework. This change introduces a new command/query handler pattern for business logic, replaces the previous endpoint implementation with CloudNativeKit's minimal API abstractions, and enforces inline validation using FluentValidation within the command/query objects. Users will see these features operating under the new v1 API structure with updated authorization requirements (e.g., admin-only for restock subscriptions) and consistent problem-detail error responses.

src/Services/Customers/FoodDelivery.Services.Customers/Customers/Features/CreatingCustomer/v1, src/Services/Customers/FoodDelivery.Services.Customers/Customers/Features/UpdatingCustomer, src/Services/Customers/FoodDelivery.Services.Customers/RestockSubscriptions/Features/GetRestockSubscriptionById · high confidence

New product price change event and stock query introduced

The catalog service now includes a new domain event, ProductPriceChanged, which validates that prices are positive before being recorded, and a new query, GetAvailableStockById, to retrieve the available stock for a specific product.

src/Services/Catalogs/FoodDelivery.Services.Catalogs/Products/Features/ChangingProductPrice, src/Services/Catalogs/FoodDelivery.Services.Catalogs/Products/Features/GettingAvailableStockById · high confidence

Standardized HTTP error handling with RFC 9457 Problem Details

The React food delivery UI now uses a consistent, standards-compliant approach for displaying API errors. A new shared library introduces RFC 9457 Problem Details support, providing a type definition and utility functions that automatically fill in missing status codes, titles, and error types with sensible defaults based on HTTP status codes (e.g., 400 Bad Request, 404 Not Found). This logic is integrated into the Axios HTTP client via response interceptors, which now detect Problem Details responses and display user-friendly toast notifications for any API errors, ensuring a uniform error experience across the application.

src/UIs/Spa/react-food-delivery/src/shared/libs/axios, src/UIs/Spa/react-food-delivery/src/shared/libs/problem-details · high confidence

Supplier event consumers migrated to Wolverine

The integration event consumers for supplier creation, deletion, and updates now use the Wolverine framework instead of the previous messaging library. These consumers handle incoming supplier events via the CloudNativeKit integration layer, ensuring that header propagation is maintained when processing external messages.

src/Services/Catalogs/FoodDelivery.Services.Catalogs/Suppliers/Features/SupplierCreated, src/Services/Catalogs/FoodDelivery.Services.Catalogs/Suppliers/Features/SupplierDeleted, src/Services/Catalogs/FoodDelivery.Services.Catalogs/Suppliers/Features/SupplierUpdated · high confidence

Test coverage

Added integration tests for customer retrieval features; Added test infrastructure for Catalogs and Customers services; Added unit tests for customer creation and update features; Added unit tests for customer retrieval features; New shared integration test infrastructure for authentication and containerized dependencies.

Dependencies

Centralized dependency management and .NET Aspire 9.4 integration

The project now uses centralized package version management via a new Directory.Packages.props file, setting the Aspire version to 9.4. The Aspire hosting infrastructure has been updated to use the Aspire.AppHost.Sdk version 9.4 and includes references to Azure, Docker, and Kubernetes hosting packages. Additionally, the API Gateway and BFF services now reference Duende.BFF.Yarp and Duende.AccessTokenManagement.OpenIdConnect, while the core services reference CloudNativeKit building blocks for integration, caching, and persistence.

(dependencies) · high confidence

Housekeeping

Initialize src directory with submodules and build props

The src directory is initialized with a new submodule reference (BuildingBlocks) and standard MSBuild import files (Directory.Build.props and Directory.Build.targets) to support the project's build structure.

src · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 48 → 47 (-0.7)
  • Rubric changed (rubric-2026.08.18 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 80 → 63 (-17.0)
  • Architecture 85 → 92 (+6.3)
  • Maturity 68 → 54 (-13.9)
  • Readiness 57 → 79 (+22.6)
  • Security 55 → 54 (-1.2)
  • Accessibility 34 → 34 (-0.0)
  • Performance 65 → 75 (+10.0)

Resolved (72)

  • Bounded contexts not declared
  • Build action pinned to a mutable branch
  • Build did not complete in the analyzer
  • Command bus methods are split between 'SendExternalAsync' and 'SendAsync' with inconsistent naming and generic constraints. 'SendExternalAsync' implies a specific type of command, while 'SendAsync' is overloaded for both generic and non-generic commands.
  • Critical CVE: Marten 7.39.1
  • Critical CVE: Scriban.Signed 5.5.0
  • Critical CVE: System.Drawing.Common 4.7.0
  • Critical CVE: System.Linq.Dynamic.Core 1.2.23
  • High CVE: Azure.Identity 1.3.0
  • High CVE: MessagePack 3.1.4
  • High CVE: MessagePack 3.1.4
  • High CVE: MessagePack 3.1.4
  • High CVE: SQLitePCLRaw.lib.e_sqlite3 2.1.11
  • High CVE: Scriban.Signed 5.5.0
  • High CVE: Scriban.Signed 5.5.0
  • High CVE: Scriban.Signed 5.5.0
  • High CVE: Scriban.Signed 5.5.0
  • High CVE: Scriban.Signed 5.5.0
  • High CVE: Scriban.Signed 5.5.0
  • High CVE: Scriban.Signed 5.5.0
  • …and 52 more

New (483)

  • AnalyzerSeverityNone (.editorconfig)
  • AnalyzerSeverityNone (.editorconfig)
  • AnalyzerSeverityNone (.editorconfig)
  • AnalyzerSeverityNone (.editorconfig)
  • AnalyzerSeverityNone (.editorconfig)
  • AnalyzerSeverityNone (.editorconfig)
  • AnalyzerSeverityNone (.editorconfig)
  • AnalyzerSeverityNone (.editorconfig)
  • AnalyzerSeverityNone (.editorconfig)
  • AnalyzerSeverityNone (.editorconfig)
  • AnalyzerSeverityNone (.editorconfig)
  • AnalyzerSeverityNone (.editorconfig)
  • AnalyzerSeverityNone (.editorconfig)
  • AnalyzerSeverityNone (.editorconfig)
  • AnalyzerSeverityNone (.editorconfig)
  • AnalyzerSeverityNone (.editorconfig)
  • AnalyzerSeverityNone (.editorconfig)
  • AnalyzerSeverityNone (.editorconfig)
  • AnalyzerSeverityNone (.editorconfig)
  • AnalyzerSeverityNone (.editorconfig)
  • …and 463 more

Changes since last survey

  • 1 commits — 1 feature/other, 0 fixes

By area

  • src/BuildingBlocks — 1 commit

Notable commits

  • change: feat: use cloudnativekit sub-module instead of buidling-blocks (#257)

API surface

  • 0 added · 1 removed (a removed endpoint is potentially breaking)

Removed endpoints (breaking) (1)

  • GET /swagger/{resourceName}/{documentName}

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

mehdihadeli/food-delivery-microservices was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 20 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit c83bca390ce294e1cbad4a5f9fe0844494f66cc2 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.