meysamhadeli/shop-golang-microservices
59.0
Adequate · 21 September 2026
4.6k
lines of production code
Go
primary language
4
measurements over time
What this system is
This system is a Go-based microservices architecture that manages product and identity domains through distinct services. It provides HTTP and gRPC interfaces for creating, retrieving, and searching products, alongside user authentication via OAuth2 and JWT validation. The architecture leverages PostgreSQL for persistence, RabbitMQ for asynchronous event publishing, and OpenTelemetry for distributed tracing and observability.
How it got here
2022 — internal infrastructure and security
10 changes.
This period focused on establishing the project's internal infrastructure, introducing structured logging, HTTP and gRPC server implementations, and essential security middleware for authentication and tracing. The work standardized cross-cutting concerns like correlation IDs, JWT validation, and OpenTelemetry integration across the codebase.
2023 — Microservices and testing infrastructure
13 changes.
This period focused on implementing core microservices for product and identity management, alongside establishing the necessary testing infrastructure. The work included building out the product and inventory services with full CRUD and search capabilities, while simultaneously introducing test containers and mock implementations for PostgreSQL and RabbitMQ to support integration and end-to-end testing.
Features
Add ability to create products with inventory count
Users can now create new products by specifying a name, description, price, inventory ID, and a count. The system validates the input, persists the product, and publishes a 'ProductCreated' event to the message queue, exposing the creation via a new POST /api/v1/products endpoint.
_internal/services/product\_service/product/features/creating\product · high confidence
Add gRPC client/server and OpenTelemetry tracing infrastructure
The codebase now includes a new gRPC package providing a configurable gRPC client and server implementation, along with mocks for testing. Additionally, OpenTelemetry tracing support is introduced, featuring a Jaeger exporter for trace data, an Echo framework middleware for HTTP request tracing, and utility functions for propagating tracing headers in AMQP messages.
internal/pkg/grpc · high confidence
Added OAuth2 password credentials authentication flow
The application now supports authenticating users via username and password using the OAuth2 protocol. This change introduces a new \password\_credentials.go\ module that configures an OAuth2 server with a password authorization handler, allowing clients to exchange user credentials for access tokens. The implementation includes a \validateBearerToken\ endpoint for token validation and registers the OAuth2 token endpoint at \/connect/token\.
internal/pkg/oauth2 · high confidence
Added contribution guidelines and API testing tools
The repository now includes a CONTRIBUTION.md file that outlines the process for submitting pull requests and the conventional commit message format required for releases. Additionally, a shop.rest file has been added to facilitate API testing using the VS Code REST Client, and the Makefile has been updated to include targets for generating Swagger OpenAPI documentation for each microservice.
(repo-wide) · high confidence
Added microservices architecture diagram assets
Added a new Excalidraw diagram file and its corresponding SVG export for the shop-golang-microservices architecture, providing a visual representation of the system's components and their interactions.
assets · high confidence
Added product retrieval and search endpoints
Introduced new API endpoints for the product service: a GET /api/v1/products/{id} route to fetch a single product by ID, a GET /api/v1/products route to retrieve a paginated list of all products, and a GET /api/v1/products/search route to search products by text. Each feature includes the full stack of request/response DTOs, HTTP handlers, and query handlers to support these operations.
_internal/services/product\_service/product/features/getting\_product\_by\_id, internal/services/product\_service/product/features/getting\_products, internal/services/product\_service/product/features/searching\product · high confidence
Added utility packages for pagination, password hashing, and worker management
The internal/pkg/utils package now includes three new files: pagination.go provides a generic ListResult struct and ListQuery helper to standardize API pagination, filtering, and ordering; password.go adds HashPassword and ComparePasswords functions using bcrypt for secure password handling; and workers\_runner.go introduces a WorkersRunner to manage the lifecycle (Start/Stop) of multiple background workers concurrently.
internal/pkg/utils · high confidence
Adds correlation ID and JWT validation middleware
Two new middleware functions have been added to the HTTP server pipeline. The first, CorrelationIdMiddleware, automatically generates and propagates a unique correlation ID for each request to improve observability. The second, ValidateBearerToken, enforces authentication by parsing and validating a JWT access token from the Authorization header or request form data, returning a 401 Unauthorized error if validation fails (except in test environments).
internal/pkg/http/echo/middleware · high confidence
Introduce GORM PostgreSQL client and generic repository
Added new files in internal/pkg/gorm\_pgsql to provide a GORM-based PostgreSQL client (db.go) and a generic repository implementation (generic\_repository.go). The client handles database connection, automatic database creation, and migration, while the repository offers standard CRUD operations (Add, Get, Update, Delete, etc.) with context support.
_internal/pkg/gorm\pgsql · high confidence
Introduce new identity and product microservices
The diff introduces two new microservices, \identity\_service\ and \product\_service\, each with a complete application structure including configuration, dependency injection, and server setup. The identity service provides user registration and retrieval via HTTP and gRPC, while the product service exposes endpoints for creating, retrieving, and searching products. Both services include Swagger documentation, database migrations, and data seeding capabilities.
_internal/services/product\service · high confidence
Introduce structured logging and object mapping utilities
Added a new internal logging package that wraps the Logrus library to provide a consistent, configurable logging interface for the application, and a new internal mapping package that enables automatic struct-to-struct and custom function-based object mapping via reflection.
internal/pkg/logger · high confidence
Introduce the new Inventory Service
The new Inventory Service is now available, providing core inventory management capabilities. It introduces a \ProductItem\ model to track product stock levels and an \InventoryUpdated\ event to notify other services of inventory changes. The service is configured to connect to a PostgreSQL database and a RabbitMQ broker, with initial seed data for 'food' and 'health' inventories. This service enables the system to manage and update product inventory counts asynchronously via message queues.
_internal/services/inventory\service · high confidence
Introduces HTTP server implementation with header-based API versioning
A new Echo-based HTTP server implementation is added, providing configuration for timeouts, headers, and host. The server supports graceful shutdown and includes a middleware to inject the 'version' header into the request path for API versioning.
internal/pkg/http/echo/server · high confidence
New RabbitMQ client library with retry and tracing
The internal/pkg/rabbitmq package now provides new Consumer and Publisher implementations that automatically declare exchanges, queues, and bindings, and include OpenTelemetry tracing and logging. The connection setup uses exponential backoff retries (up to 5 attempts over 10 seconds) to handle RabbitMQ connectivity issues.
internal/pkg/rabbitmq · medium confidence
New internal reflection and HTTP client utilities
Added a new HTTP client implementation in \internal/pkg/http\_client\ that configures a \resty\ client with OpenTelemetry tracing and custom transport settings. Additionally, introduced reflection helper utilities in \internal/pkg/reflection\ to access and modify struct fields by name or index, including support for unexported (private) fields via unsafe pointers. Also added a type mapper and registry in \internal/pkg/reflection\ to discover, register, and instantiate types by name or package path at runtime.
_internal/pkg/http\client, internal/pkg/reflection · high confidence
Behavioural changes
Refactored HTTP package structure and naming conventions
The internal/pkg/http package has been refactored to align with updated folder and file naming conventions. This change includes the introduction of a new file, context\_provider.go, which provides a NewContext function to manage application lifecycle signals (interrupt, SIGTERM, SIGINT) and log context cancellation events.
internal/pkg/http · medium confidence
Test coverage
Add end-to-end test for creating a product; Added RabbitMQ test container for integration testing; Added integration test for creating a product; Added mock implementations for RabbitMQ consumer and publisher interfaces; Added tests for the new PostgreSQL test container helper; Added unit tests for the product creation handler.
Dependencies
Add Go module files for internal packages and services
Introduced go.mod and go.sum files for the internal/pkg, internal/services/identity\_service, and internal/services/inventory\_service modules. These files define the Go version (1.23.2) and declare direct and indirect dependencies, including libraries for HTTP clients, database drivers, and OpenTelemetry, establishing the module structure for the project's internal packages and microservices.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 56 → 59 (+3.2)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 95 → 96 (+1.4)
- Architecture 100 → 93 (-6.5)
- Maturity 62 → 62 (+0.0)
- Readiness 49 → 53 (+3.1)
- Security 57 → 67 (+10.1)
- Domain Modelling 56 → 59 (+3.2)
- Event-Driven 76 → 76 (+0.0)
Resolved (65)
- Coverage not included — suite not readable by the collector
- Critical CVE: [GHSA redacted] (internal/pkg/go.mod)
- Critical CVE: [GHSA redacted] (internal/services/identity_service/go.mod)
- Critical CVE: [GHSA redacted] (internal/services/inventory_service/go.mod)
- Critical CVE: [GHSA redacted] (internal/pkg/go.mod)
- Critical CVE: [GHSA redacted] (internal/pkg/go.mod)
- Critical CVE: [GHSA redacted] (internal/pkg/go.mod)
- Dependency hygiene not measured — no supported dependency manifest was read
- Duplicated block (13 lines × 2) (internal/pkg/reflection/reflection_helper/reflection_helper.go)
- Duplicated block (13 lines × 3) (internal/services/identity_service/server/server.go)
- Duplicated block (18 lines × 3) (internal/services/identity_service/config/config.go)
- Duplicated block (6 lines × 2) (internal/pkg/mapper/mapper.go)
- Duplicated block (6 lines × 2) (internal/pkg/reflection/reflection_helper/reflection_helper.go)
- Duplicated block (6 lines × 2) (internal/pkg/reflection/reflection_helper/reflection_helper.go)
- Duplicated block (6 lines × 3) (internal/services/identity_service/server/server.go)
- Duplicated block (7 lines × 2) (internal/pkg/reflection/reflection_helper/reflection_helper.go)
- Duplicated block (8 lines × 2) (internal/pkg/reflection/reflection_helper/reflection_helper.go)
- Duplicated block (9 lines × 2) (internal/pkg/mapper/mapper.go)
- Duplicated block (9 lines × 2) (internal/pkg/reflection/reflection_helper/reflection_helper.go)
- Duplicated block (9 lines × 2) (internal/services/identity_service/cmd/main.go)
- …and 45 more
New (141)
- Critical CVE: [GHSA redacted] (internal/pkg/go.mod)
- Critical CVE: [GHSA redacted] (internal/services/identity_service/go.mod)
- Critical CVE: [GHSA redacted] (internal/services/inventory_service/go.mod)
- Critical CVE: [GHSA redacted] (internal/pkg/go.mod)
- Critical CVE: [GHSA redacted] (internal/pkg/go.mod)
- Critical CVE: [GHSA redacted] (internal/pkg/go.mod)
- Deprecated module: github.com/streadway/amqp
- Deprecated module: github.com/streadway/amqp
- Deprecated module: github.com/streadway/amqp
- Deprecated module: go.opentelemetry.io/otel/exporters/jaeger
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Duplicated block (10 lines × 2) (internal/pkg/mapper/mapper.go)
- Duplicated block (11 lines × 2) (internal/services/inventory_service/config/config.go)
- Duplicated block (16 lines × 3) (internal/services/identity_service/server/server.go)
- Duplicated block (17–18 lines × 3) (internal/services/identity_service/identity/configurations/middleware_configurations.go)
- Duplicated block (21 lines × 2) (internal/pkg/reflection/reflection_helper/reflection_helper.go)
- Duplicated block (32 lines × 3) (internal/services/identity_service/config/config.go)
- Duplicated block (5 lines × 2) (internal/services/product_service/product/features/creating_product/v1/endpoints/create_product_endpoint.go)
- Duplicated block (5 lines × 3) (internal/services/identity_service/config/config.go)
- …and 121 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
meysamhadeli/shop-golang-microservices was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 76c34f1ab7e428f6106c5cf291570502df4ff257 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.