powerman/go-monolith-example
50.0
Weak · 21 September 2026
5.3k
lines of production code
Go
primary language
4
measurements over time
What this system is
This release establishes the foundational architecture for a Go monolith with embedded microservices, introducing the auth and example services alongside a shared infrastructure layer. Key additions include a comprehensive gRPC and JSON-RPC 2.0 API surface, complete with HTTP gateways, OpenAPI specifications, and embedded Swagger UI. The update also delivers robust utility packages for concurrent service management, database migrations, and network handling, while implementing strict linting rules to prevent sensitive data exposure.
Features
Add JSON-RPC 2.0 client and server-side helpers
The pkg/jsonrpc2x package introduces a new JSON-RPC 2.0 client wrapper that automatically recovers from connection errors and wraps standard errors for easier handling. On the server side, it provides middleware for logging, metrics collection (using Prometheus), and error validation, along with a custom error type that supports code-based matching for JSON-RPC errors.
pkg/jsonrpc2x · high confidence
Add PostgreSQL data access layer for the auth service
The auth service now persists user and access token data in a PostgreSQL database. The new Data Access Layer (DAL) provides functions to add and retrieve users by name, email, or access token, and to manage access tokens. This change introduces the database schema, connection configuration, and integration tests for the auth module.
ms/auth/internal/dal · high confidence
Add PostgreSQL support and metrics instrumentation to the repository layer
The repository package now supports PostgreSQL in addition to MySQL, with new files (repo-postgres.go, types-postgres.go) providing Postgres-specific configuration, connection handling, and type wrappers (e.g., PostgresFromIP, PostgresFromDuration). A new metrics.go file introduces Prometheus-based instrumentation for the Data Access Layer, tracking call duration and error counts for all repository methods. This enables observability for both MySQL and PostgreSQL backends.
pkg/repo · high confidence
Add configuration management for the example microservice
Introduces a new configuration package for the example microservice, defining shared and service-specific settings for MySQL, NATS, and STAN. The config package provides a centralized way to load configuration from environment variables and command-line flags, supporting both the main service and the Goose MySQL migration subcommand. It includes test coverage for required fields, default values, environment variable overrides, and flag parsing.
ms/example/internal/config · high confidence
Add database migration support for MySQL and PostgreSQL
The migration package now includes connectors for both MySQL and PostgreSQL, allowing the application to manage database schema migrations for either or both databases. This introduces new command-line interfaces for running goose migrations against MySQL and PostgreSQL databases, each with their own configuration structures and connection handling. The core migration logic has been refactored to support multiple database types, with specific implementations for each database's connection and initialization requirements.
pkg/migrate · high confidence
Add gRPC server for the auth microservice
The auth microservice now exposes a gRPC API for identity management. The new \ms/auth/internal/srv/grpc\ package implements handlers for account creation, sign-in (by user ID or email), sign-out, and access token validation. It includes authentication and authorization middleware, error mapping, and metrics collection for the gRPC server.
ms/auth/internal/srv/grpc · high confidence
Add gRPC-Gateway HTTP server for authentication service
The auth service now exposes a gRPC-Gateway HTTP server, enabling RESTful HTTP/JSON access to the authentication and no-auth gRPC services. The server registers the gRPC-Gateway handlers and serves the OpenAPI specification and Swagger UI at configurable patterns. HTTP middleware is added to prevent caching and allow all CORS headers.
ms/auth/internal/srv/grpcgw · medium confidence
Add health-check endpoint and metrics to the mono service
The mono service now exposes a /health-check endpoint that returns 'OK' for health verification, and registers Prometheus metrics (process and Go runtime collectors, plus a build\_info gauge) via a new metrics module. An integration test verifies the health-check endpoint responds with status 200 and body 'OK'.
ms/mono · high confidence
Added Go linting rules to detect sensitive data exposure
A new Go linting rule has been introduced to the build system to prevent sensitive values from being printed or logged. The \gorules\ package now includes a rule that flags structs containing unexported fields of sensitive types (like \AccessToken\) and forbids the use of \print\ and \println\ functions, suggesting \fmt.Print\ and \fmt.Println\ instead to avoid accidental exposure of sensitive data in logs.
build · high confidence
Added concurrent service management and NATS connectivity helpers
Introduced a new 'concurrent' package providing utilities to start and shut down multiple services in parallel, including a 'Setup' function for parallel initialization and a 'Serve' function for concurrent execution with context cancellation. Additionally, added a 'natsx' package that wraps the NATS Go client to provide context-aware connection handling, automatic reconnection, and monitoring for both standard NATS and STAN (Streaming) connections.
pkg/concurrent, pkg/natsx · high confidence
Added configuration for the auth microservice
Introduced the configuration package for the auth microservice, defining settings for PostgreSQL, TLS certificates, secrets, and network addresses. The config supports environment variables and CLI flags for serving, internal communication, gRPC gateway, and database migrations.
ms/auth/internal/config · high confidence
Added gRPC and HTTP API definitions for the auth service
The api/proto location now includes the complete protocol buffer definitions for the authentication service. This introduces a public API (NoAuthSvc) for account creation and sign-in, and a private internal API (AuthIntSvc) for token validation. The change also adds the necessary build configuration (buf.gen.yaml) to generate Go code for gRPC, the gRPC-Gateway, and OpenAPI v2 specifications, alongside an embed file to bundle the generated resources.
api/proto · high confidence
Added initial database schema and migration infrastructure for Postgres
The auth service now supports Postgres database migrations, introducing the initial schema for user and access token management. This includes a 'users' table with role-based access, an 'access\_tokens' table for session management, and helper functions like 'trigger\_set\_updated\_at' to automatically update timestamps. The migration framework is set up using the 'goose' library, with a corresponding integration test to verify the migration lifecycle (up/down).
ms/auth/internal/migrations · high confidence
Added network serving helpers and reflection utilities
Added new packages to simplify starting and managing network services. The 'serve' package provides reusable functions for running HTTP, gRPC, and JSON-RPC 2.0 servers with proper context and logging support. Additionally, the 'reflectx' package introduces reflection helpers to inspect interface methods and detect RPC-compatible methods, including a copy of Go's net/rpc method selection logic for JSON-RPC handlers.
pkg/reflectx · high confidence
Initial implementation of the auth microservice
The auth microservice is introduced, providing user authentication and account management via gRPC and a gRPC-Gateway HTTP/REST interface. The service manages its own PostgreSQL database, exposing internal and external gRPC endpoints, a metrics endpoint, and a Swagger UI for API documentation. Integration tests verify account creation, sign-in, token validation, and logout flows.
ms/auth · high confidence
Initial project scaffolding and configuration
The repository was initialized with a comprehensive set of configuration files and documentation to support a Go monolith with embedded microservices. This includes a golangci-lint configuration, a Dockerfile for containerization, a docker-compose setup for local development services (MySQL, PostgreSQL, NATS, STAN), and an environment variable template. The project also introduces a tools.go file to manage development dependencies like buf, golangci-lint, and gRPC tools, alongside a README that outlines the Clean Architecture structure and features.
(repo-wide) · high confidence
Initial release of the example microservice application logic
The example microservice now includes its core application logic, exposing an \Appl\ interface with \Example\ and \IncExample\ use cases. The implementation enforces access control, returning \ErrAccessDenied\ for unauthorized users, and integrates Prometheus metrics to track errors such as access denials. This change introduces the business logic layer, its associated tests, and the metrics initialization required for observability.
ms/example/internal · high confidence
Introduce API request context and authentication helpers
The internal/apix package now provides structured helpers for managing API requests. A new Authn interface and its gRPC-based client implementation validate access tokens and return user information, with invalid tokens mapped to a specific ErrAccessTokenInvalid error. Context helpers (Ctx, FromContext, AccessTokenFromContext) store and retrieve request metadata like remote IP, method name, and authentication state. Additionally, a UserAgent interface and its implementation wrap the standard http.Client with configurable timeouts, body size limits, and debug logging capabilities.
internal/apix · high confidence
Introduce Data Access Layer for the example service
Added the Data Access Layer (DAL) for the example service, including the core implementation (dal.go, methods.go, sql.go) that manages MySQL database connections, schema versioning, and query execution. The change also introduces database migration scripts (00001 through 00004) to create and manage the 'example' table, along with integration tests to verify the new DAL and migration functionality.
ms/example/internal/dal · high confidence
Introduce auth service with user registration, login, and token management
The auth microservice now provides core authentication capabilities, including user registration, login by user ID or email, and access token management. The implementation uses Argon2 for password hashing and manages access tokens for session handling. Tests are included to verify registration, login, and authentication flows.
ms/auth/internal · high confidence
Introduce centralized configuration for microservices
A new internal configuration module has been added to manage shared settings for microservices, including network addresses and ports for authentication, example services, MySQL, PostgreSQL, and NATS. The module defines a \Shared\ struct that loads environment variables prefixed with \MONO\_\ and provides a \Get()\ function to safely retrieve the global configuration once.
internal/config · high confidence
Introduce domain types for names and authentication
Added new domain types for representing entity names and authentication context. The \Name\ type provides a structured way to handle entity identifiers in the format "collection/id", with validation and parsing logic, while the \Auth\ struct encapsulates user identity and admin status for authorization checks.
internal/dom · high confidence
Introduce monolithic Go application entry point
Added the main entry point for the monolith application, which initializes and registers embedded microservices (auth, example, and mono) using Cobra commands. The application now supports a 'serve' command to start all embedded services with graceful shutdown handling and configurable startup/shutdown timeouts.
cmd · high confidence
Introduce new build, test, and utility scripts
The repository now includes a set of new shell scripts in the scripts/ directory to automate the build, testing, and maintenance workflows. The build script compiles Go binaries and creates Docker images, while the test script orchestrates linting, code generation, and integration tests, including specific checks for proto files and Go rules. Additional utility scripts provide code coverage reporting, source line counting, and automated PostgreSQL user/schema setup for development environments.
scripts · high confidence
Introduce public JSON-RPC 2.0 API definitions
The api/jsonrpc2-example location now contains the public API definitions for the JSON-RPC 2.0 service. This includes the RPC method signatures (Example, IncExample) and associated error codes (e.g., ErrNotFound, ErrForbidden) that clients will receive. The API uses 'RPC' as the name prefix for method names.
api/jsonrpc2-example · medium confidence
Introduce shared configuration and initialization utilities in pkg/def
A new \pkg/def\ package has been added, providing a centralized set of default values, configuration helpers, and initialization routines for the application. This includes standardizing logging setup, configuring Prometheus metrics, and offering factory functions to create default configurations for MySQL and PostgreSQL databases. The package also introduces context management utilities, such as merging cancellation contexts, and exposes application versioning and hostname information.
pkg/def · high confidence
JSON-RPC 2.0 service implementation with CORS and metrics
The JSON-RPC 2.0 server implementation is introduced in the \ms/example/internal/srv/jsonrpc2\ package. This includes the HTTP handler setup with CORS support, error mapping for JSON-RPC 2.0 responses, and Prometheus metrics initialization. The implementation also includes tests for the handlers and CORS headers.
ms/example/internal/srv · medium confidence
New gRPC client and server helpers with authentication and metrics
The pkg/grpcx package introduces new utilities for building gRPC services and clients. Server-side, it provides interceptors for logging, panic recovery, access logging, and pluggable authentication (AuthnFunc) that can be chained. Client-side, it offers a Dial function that chains unary and stream interceptors for metrics, logging, and access logging. The package also includes helpers for extracting X-Forwarded-For headers and OAuth2 access tokens from incoming requests, as well as Prometheus metrics registration for both client and server gRPC activity.
pkg/grpcx · high confidence
New network utility functions in the netx package
The netx package now includes helpers for managing TCP ports and TLS certificates. Users can obtain a unique unused TCP port via UnusedTCPPort, wait for a TCP port to become available with WaitTCPPort, and load CA certificates from a file using LoadCACert. A new Addr struct is also provided to manage host and port combinations.
pkg/netx · high confidence
Behavioural changes
Embedded Swagger UI for API documentation
The web package now embeds the Swagger UI interface directly into the application binary using Go's built-in embed feature, replacing the previous statik-based approach. This change bundles the static assets required for the Swagger UI, allowing users to access the interactive API documentation without relying on external file paths or separate asset servers.
web · medium confidence
Embedded Swagger UI static assets
The project now embeds Swagger UI static files (including CSS, JavaScript, and HTML templates) directly into the binary using Go's go:embed directive, replacing the previous statik-based approach.
_third\party · medium confidence
Moved insecure development PKI assets to a dedicated subdirectory
The \configs\ directory has been reorganized to group all insecure development PKI (Public Key Infrastructure) assets under a new \insecure-dev-pki\ subdirectory. This includes the CA certificate, private keys, issued certificates, certificate signing requests, and configuration files. This change simplifies the top-level \configs\ directory and clearly separates development-only security materials from production or shared configurations.
configs · high confidence
Test coverage
Added integration tests for the example microservice
Added integration tests for the example microservice, including a test suite that validates the service's HTTP/JSON-RPC2 endpoints and database interactions using a temporary MySQL instance. The tests verify authentication, data persistence, and error handling, ensuring the service behaves correctly in a realistic environment.
ms/example · high confidence
Dependencies
Initial Go module and dependency setup
The project now includes a go.mod file that defines the module github.com/powerman/go-monolith-example using Go 1.16. This file establishes the project's dependencies, including gRPC, PostgreSQL, MySQL, NATS, and various utility and testing libraries, providing the foundation for the application's build and runtime environment.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 46 → 50 (+3.9)
- Rubric changed (rubric-2026.08.18 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 99 → 99 (-0.3)
- Architecture 100 → 93 (-7.1)
- Maturity 74 → 74 (+0.0)
- Readiness 35 → 39 (+4.0)
- Security 27 → 35 (+7.4)
- Domain Modelling 100 → 100 (+0.0)
Resolved (33)
- Build action pinned to a mutable branch
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Duplicated block (10 lines × 2) (pkg/migrate/goose-mysql.go)
- Duplicated block (11 lines × 2) (pkg/repo/repo-mysql.go)
- Duplicated block (13 lines × 2) (ms/auth/internal/dal/dal.go)
- Duplicated block (6 lines × 2) (ms/auth/internal/config/testing.go)
- Duplicated block (6 lines × 2) (ms/example/internal/config/config.go)
- Duplicated block (7 lines × 2) (ms/auth/internal/config/config.go)
- Duplicated block (8 lines × 2) (ms/auth/internal/srv/grpc/srv.go)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 13 more
New (119)
- Critical CVE: [GHSA redacted] (go.mod)
- Critical CVE: [GHSA redacted] (go.sum)
- Critical CVE: [GHSA redacted] (go.mod)
- Dependency pinned to a stale untagged commit: github.com/cheekybits/genny
- Dependency pinned to a stale untagged commit: github.com/sebest/xff
- Dependency pinned to a stale untagged commit: golang.org/x/crypto
- Dependency pinned to a stale untagged commit: golang.org/x/oauth2
- Dependency pinned to a stale untagged commit: google.golang.org/genproto
- Dependency pinned to a stale untagged commit: google.golang.org/grpc
- Dependency pinned to a stale untagged commit: google.golang.org/protobuf
- Duplicated block (10 lines × 2) (pkg/migrate/goose-mysql.go)
- Duplicated block (12 lines × 2) (ms/auth/internal/dal/dal.go)
- Duplicated block (12 lines × 2) (pkg/repo/repo-mysql.go)
- Duplicated block (23 lines × 2) (ms/auth/internal/app/metrics.go)
- Duplicated block (5 lines × 2) (ms/auth/internal/config/testing.go)
- Duplicated block (5 lines × 2) (ms/example/internal/config/config.go)
- Duplicated block (6 lines × 2) (ms/auth/internal/srv/grpc/srv.go)
- Duplicated block (8 lines × 2) (ms/auth/internal/dal/methods.go)
- Duplicated block (9 lines × 2) (ms/auth/internal/config/config.go)
- Duplicated block (9 lines × 2) (pkg/cobrax/goose-mysql.go)
- …and 99 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
powerman/go-monolith-example was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit a990187d04a516269277410c48882a14ba843ccc — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.