nkz-soft/rust-microservice-template
64.5
Adequate · 21 September 2026
2.9k
lines of production code
Rust
primary language
4
measurements over time
What this system is
This system is a Rust-based web service for managing to-do items, structured as a workspace with distinct domain, application, infrastructure, and presentation layers. It exposes a versioned REST API that supports CRUD operations, audit retrieval for soft-deleted items, and health checks, while enforcing data integrity through optimistic locking and strict input validation. The backend utilizes PostgreSQL via Diesel for persistence and includes comprehensive observability features such as structured logging, request tracing, and Prometheus metrics.
Features
Add Docker Compose configuration for local development
New Docker Compose files and helper scripts have been added to the deployment directory to simplify running the application locally. The configuration defines a Rust application service exposing port 8080 and a PostgreSQL 16 service with a health check, sharing a custom network. A shell script combines both configurations, and an initialization SQL file creates the required database upon startup.
deployment · high confidence
Added observability with tracing, request IDs, and Prometheus metrics
The application now includes built-in observability features. HTTP requests are logged with structured JSON output via tracing, and a unique request ID is propagated through the request lifecycle (extracted from headers or auto-generated). Additionally, Prometheus metrics are exposed, tracking HTTP request counts, durations, and error rates, configurable via environment variables.
src/starter/src · high confidence
Introduce versioned API, observability endpoints, and request validation
The API presentation layer now exposes a versioned \/api/v1\ route structure for to-do item operations (create, read, update, delete) and a separate \/api/v1/audit\ path for retrieving soft-deleted items. This update adds health check endpoints (\/startup\, \/live\, \/ready\) to verify application and database connectivity, as well as a \/metrics\ endpoint for Prometheus-compatible runtime metrics. To ensure data integrity and better error handling, the API now validates incoming request payloads and query parameters, implements optimistic locking via ETags on updates, and returns standardized Problem Details responses for errors. Additionally, an OpenAPI specification is generated to document the available paths and parameters.
src/presentation/src/api · high confidence
PostgreSQL persistence layer with Diesel and optimistic locking
The infrastructure module now provides a complete PostgreSQL-backed repository for to-do items using the Diesel ORM. This includes database connection pooling, embedded migration support (initial schema, versioning, lifecycle fields, and soft-delete columns), and a typed error system that maps database conflicts to application-level errors. The repository implementation enforces optimistic locking via a version column to prevent concurrent update collisions and supports filtering, sorting, and pagination for item retrieval.
src/infrastructure · high confidence
Removals
Removal of Rust application source code
The Rust source files for the application have been removed from the repository. Specifically, \src/config.rs\ (which defined the application configuration structure and default URL) and \src/main.rs\ (which initialized the Actix-web server and loaded configuration) are no longer present. This change eliminates the core application logic and configuration handling previously located in the \src\ directory.
src · high confidence
Behavioural changes
Introduce CQRS-based application layer with typed commands, queries, and optimistic locking
The application layer has been restructured to enforce a strict Command Query Responsibility Segregation (CQRS) pattern. Users can now create, update, and delete to-do items via explicit command objects (e.g., \CreateToDoItemCommand\, \UpdateToDoItemCommand\), while read operations are handled by distinct query objects (e.g., \GetAllToDoItemsQuery\, \GetDeletedToDoItemForAuditQuery\). This separation is supported by dedicated command and query repositories, handlers, and a service container that manages these boundaries. The update command now requires a \version\ field, enabling optimistic locking to prevent concurrent modification conflicts. Additionally, the system supports soft deletes, allowing deleted items to be retained for audit retrieval via a specific query handler.
src/application · high confidence
Introduce structured API presentation layer with validation and problem details
The presentation layer has been replaced with a structured implementation that enforces request validation and standardized error responses. JSON payloads are now limited to 8 KB, and query parameters are validated against defined schemas, returning 400 Bad Request with RFC 7807 Problem Details for invalid input. Internal application errors are sanitized to prevent leaking sensitive details to clients, while specific errors like Not Found or Conflict map to appropriate HTTP status codes. The API is exposed under the /api/v1 prefix, supporting CRUD operations for to-do items, audit retrieval, and health checks.
src/presentation/src · high confidence
Test coverage
Added integration and unit tests for the starter application
Added a new test suite in \src/starter/tests\ that includes integration tests verifying the API endpoints (such as \GET /to-do-items\ and \POST /to-do-items\), request ID handling, and health checks, as well as unit tests for memory management and concurrency patterns within the \ToDoItemService\. The test infrastructure utilizes \testcontainers\ to spin up a PostgreSQL database and the application server, ensuring end-to-end validation of the starter project's core functionality.
src/starter/tests · high confidence
Dependencies
Upgrade to Rust workspace with comprehensive dependency updates
The project has been restructured into a Rust workspace, introducing a new \src/starter\ binary crate and updating the \domain\, \application\, \infrastructure\, and \presentation\ crates. This change upgrades core dependencies including \actix-web\ to 4.13.0, \tokio\ to 1.52.1, \diesel\ to 2.3.8, and \utoipa-swagger-ui\ to 9.0.2, while adding new libraries such as \problem\_details\, \validator\, and \readonly\ to support typed error handling, request validation, and immutable state management.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 63 → 64 (+2.0)
- Rubric changed (rubric-2026.08.18 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 100 → 100 (+0.0)
- Architecture 100 → 87 (-13.0)
- Maturity 66 → 66 (+0.6)
- Readiness 56 → 53 (-3.1)
- Security 53 → 70 (+16.5)
- Domain Modelling 100 → 100 (+0.0)
Resolved (35)
- Build action pinned to a mutable branch
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- High CVE: [GHSA redacted] (Cargo.lock)
- High vulnerability: [GHSA redacted] (Cargo.lock)
- High vulnerability: [GHSA redacted] (Cargo.lock)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Medium CVE: [GHSA redacted] (Cargo.lock)
- …and 15 more
New (42)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- High CVE: [GHSA redacted] (Cargo.lock)
- High CVE: [GHSA redacted] (Cargo.lock)
- High vulnerability: [GHSA redacted] (Cargo.lock)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Inconsistent Handler Naming vs Query Naming
- …and 22 more
Changes since last survey
- 1 commits — 1 feature/other, 0 fixes
By area
- .github/workflows — 1 commit
Notable commits
- change: chore(deps): bump actions/cache from 5 to 6 (#231)
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
nkz-soft/rust-microservice-template was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit ab11e641b6b911eea47c5f9958aa744c7cd62e52 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.