Skip to content
CAI
Software that uses CAICheck a score

powerman/go-monolith-example

50.0

Weak · 21 September 2026

5.3k

lines of production code

Go

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This release establishes the foundational architecture for a Go monolith with embedded microservices, introducing the auth and example services alongside a shared infrastructure layer. Key additions include a comprehensive gRPC and JSON-RPC 2.0 API surface, complete with HTTP gateways, OpenAPI specifications, and embedded Swagger UI. The update also delivers robust utility packages for concurrent service management, database migrations, and network handling, while implementing strict linting rules to prevent sensitive data exposure.

Features

Add JSON-RPC 2.0 client and server-side helpers

The pkg/jsonrpc2x package introduces a new JSON-RPC 2.0 client wrapper that automatically recovers from connection errors and wraps standard errors for easier handling. On the server side, it provides middleware for logging, metrics collection (using Prometheus), and error validation, along with a custom error type that supports code-based matching for JSON-RPC errors.

pkg/jsonrpc2x · high confidence

Add PostgreSQL data access layer for the auth service

The auth service now persists user and access token data in a PostgreSQL database. The new Data Access Layer (DAL) provides functions to add and retrieve users by name, email, or access token, and to manage access tokens. This change introduces the database schema, connection configuration, and integration tests for the auth module.

ms/auth/internal/dal · high confidence

Add PostgreSQL support and metrics instrumentation to the repository layer

The repository package now supports PostgreSQL in addition to MySQL, with new files (repo-postgres.go, types-postgres.go) providing Postgres-specific configuration, connection handling, and type wrappers (e.g., PostgresFromIP, PostgresFromDuration). A new metrics.go file introduces Prometheus-based instrumentation for the Data Access Layer, tracking call duration and error counts for all repository methods. This enables observability for both MySQL and PostgreSQL backends.

pkg/repo · high confidence

Add configuration management for the example microservice

Introduces a new configuration package for the example microservice, defining shared and service-specific settings for MySQL, NATS, and STAN. The config package provides a centralized way to load configuration from environment variables and command-line flags, supporting both the main service and the Goose MySQL migration subcommand. It includes test coverage for required fields, default values, environment variable overrides, and flag parsing.

ms/example/internal/config · high confidence

Add database migration support for MySQL and PostgreSQL

The migration package now includes connectors for both MySQL and PostgreSQL, allowing the application to manage database schema migrations for either or both databases. This introduces new command-line interfaces for running goose migrations against MySQL and PostgreSQL databases, each with their own configuration structures and connection handling. The core migration logic has been refactored to support multiple database types, with specific implementations for each database's connection and initialization requirements.

pkg/migrate · high confidence

Add gRPC server for the auth microservice

The auth microservice now exposes a gRPC API for identity management. The new \ms/auth/internal/srv/grpc\ package implements handlers for account creation, sign-in (by user ID or email), sign-out, and access token validation. It includes authentication and authorization middleware, error mapping, and metrics collection for the gRPC server.

ms/auth/internal/srv/grpc · high confidence

Add gRPC-Gateway HTTP server for authentication service

The auth service now exposes a gRPC-Gateway HTTP server, enabling RESTful HTTP/JSON access to the authentication and no-auth gRPC services. The server registers the gRPC-Gateway handlers and serves the OpenAPI specification and Swagger UI at configurable patterns. HTTP middleware is added to prevent caching and allow all CORS headers.

ms/auth/internal/srv/grpcgw · medium confidence

Add health-check endpoint and metrics to the mono service

The mono service now exposes a /health-check endpoint that returns 'OK' for health verification, and registers Prometheus metrics (process and Go runtime collectors, plus a build\_info gauge) via a new metrics module. An integration test verifies the health-check endpoint responds with status 200 and body 'OK'.

ms/mono · high confidence

Added Go linting rules to detect sensitive data exposure

A new Go linting rule has been introduced to the build system to prevent sensitive values from being printed or logged. The \gorules\ package now includes a rule that flags structs containing unexported fields of sensitive types (like \AccessToken\) and forbids the use of \print\ and \println\ functions, suggesting \fmt.Print\ and \fmt.Println\ instead to avoid accidental exposure of sensitive data in logs.

build · high confidence

Added concurrent service management and NATS connectivity helpers

Introduced a new 'concurrent' package providing utilities to start and shut down multiple services in parallel, including a 'Setup' function for parallel initialization and a 'Serve' function for concurrent execution with context cancellation. Additionally, added a 'natsx' package that wraps the NATS Go client to provide context-aware connection handling, automatic reconnection, and monitoring for both standard NATS and STAN (Streaming) connections.

pkg/concurrent, pkg/natsx · high confidence

Added configuration for the auth microservice

Introduced the configuration package for the auth microservice, defining settings for PostgreSQL, TLS certificates, secrets, and network addresses. The config supports environment variables and CLI flags for serving, internal communication, gRPC gateway, and database migrations.

ms/auth/internal/config · high confidence

Added gRPC and HTTP API definitions for the auth service

The api/proto location now includes the complete protocol buffer definitions for the authentication service. This introduces a public API (NoAuthSvc) for account creation and sign-in, and a private internal API (AuthIntSvc) for token validation. The change also adds the necessary build configuration (buf.gen.yaml) to generate Go code for gRPC, the gRPC-Gateway, and OpenAPI v2 specifications, alongside an embed file to bundle the generated resources.

api/proto · high confidence

Added initial database schema and migration infrastructure for Postgres

The auth service now supports Postgres database migrations, introducing the initial schema for user and access token management. This includes a 'users' table with role-based access, an 'access\_tokens' table for session management, and helper functions like 'trigger\_set\_updated\_at' to automatically update timestamps. The migration framework is set up using the 'goose' library, with a corresponding integration test to verify the migration lifecycle (up/down).

ms/auth/internal/migrations · high confidence

Added network serving helpers and reflection utilities

Added new packages to simplify starting and managing network services. The 'serve' package provides reusable functions for running HTTP, gRPC, and JSON-RPC 2.0 servers with proper context and logging support. Additionally, the 'reflectx' package introduces reflection helpers to inspect interface methods and detect RPC-compatible methods, including a copy of Go's net/rpc method selection logic for JSON-RPC handlers.

pkg/reflectx · high confidence

Initial implementation of the auth microservice

The auth microservice is introduced, providing user authentication and account management via gRPC and a gRPC-Gateway HTTP/REST interface. The service manages its own PostgreSQL database, exposing internal and external gRPC endpoints, a metrics endpoint, and a Swagger UI for API documentation. Integration tests verify account creation, sign-in, token validation, and logout flows.

ms/auth · high confidence

Initial project scaffolding and configuration

The repository was initialized with a comprehensive set of configuration files and documentation to support a Go monolith with embedded microservices. This includes a golangci-lint configuration, a Dockerfile for containerization, a docker-compose setup for local development services (MySQL, PostgreSQL, NATS, STAN), and an environment variable template. The project also introduces a tools.go file to manage development dependencies like buf, golangci-lint, and gRPC tools, alongside a README that outlines the Clean Architecture structure and features.

(repo-wide) · high confidence

Initial release of the example microservice application logic

The example microservice now includes its core application logic, exposing an \Appl\ interface with \Example\ and \IncExample\ use cases. The implementation enforces access control, returning \ErrAccessDenied\ for unauthorized users, and integrates Prometheus metrics to track errors such as access denials. This change introduces the business logic layer, its associated tests, and the metrics initialization required for observability.

ms/example/internal · high confidence

Introduce API request context and authentication helpers

The internal/apix package now provides structured helpers for managing API requests. A new Authn interface and its gRPC-based client implementation validate access tokens and return user information, with invalid tokens mapped to a specific ErrAccessTokenInvalid error. Context helpers (Ctx, FromContext, AccessTokenFromContext) store and retrieve request metadata like remote IP, method name, and authentication state. Additionally, a UserAgent interface and its implementation wrap the standard http.Client with configurable timeouts, body size limits, and debug logging capabilities.

internal/apix · high confidence

Introduce Data Access Layer for the example service

Added the Data Access Layer (DAL) for the example service, including the core implementation (dal.go, methods.go, sql.go) that manages MySQL database connections, schema versioning, and query execution. The change also introduces database migration scripts (00001 through 00004) to create and manage the 'example' table, along with integration tests to verify the new DAL and migration functionality.

ms/example/internal/dal · high confidence

Introduce auth service with user registration, login, and token management

The auth microservice now provides core authentication capabilities, including user registration, login by user ID or email, and access token management. The implementation uses Argon2 for password hashing and manages access tokens for session handling. Tests are included to verify registration, login, and authentication flows.

ms/auth/internal · high confidence

Introduce centralized configuration for microservices

A new internal configuration module has been added to manage shared settings for microservices, including network addresses and ports for authentication, example services, MySQL, PostgreSQL, and NATS. The module defines a \Shared\ struct that loads environment variables prefixed with \MONO\_\ and provides a \Get()\ function to safely retrieve the global configuration once.

internal/config · high confidence

Introduce domain types for names and authentication

Added new domain types for representing entity names and authentication context. The \Name\ type provides a structured way to handle entity identifiers in the format "collection/id", with validation and parsing logic, while the \Auth\ struct encapsulates user identity and admin status for authorization checks.

internal/dom · high confidence

Introduce monolithic Go application entry point

Added the main entry point for the monolith application, which initializes and registers embedded microservices (auth, example, and mono) using Cobra commands. The application now supports a 'serve' command to start all embedded services with graceful shutdown handling and configurable startup/shutdown timeouts.

cmd · high confidence

Introduce new build, test, and utility scripts

The repository now includes a set of new shell scripts in the scripts/ directory to automate the build, testing, and maintenance workflows. The build script compiles Go binaries and creates Docker images, while the test script orchestrates linting, code generation, and integration tests, including specific checks for proto files and Go rules. Additional utility scripts provide code coverage reporting, source line counting, and automated PostgreSQL user/schema setup for development environments.

scripts · high confidence

Introduce public JSON-RPC 2.0 API definitions

The api/jsonrpc2-example location now contains the public API definitions for the JSON-RPC 2.0 service. This includes the RPC method signatures (Example, IncExample) and associated error codes (e.g., ErrNotFound, ErrForbidden) that clients will receive. The API uses 'RPC' as the name prefix for method names.

api/jsonrpc2-example · medium confidence

Introduce shared configuration and initialization utilities in pkg/def

A new \pkg/def\ package has been added, providing a centralized set of default values, configuration helpers, and initialization routines for the application. This includes standardizing logging setup, configuring Prometheus metrics, and offering factory functions to create default configurations for MySQL and PostgreSQL databases. The package also introduces context management utilities, such as merging cancellation contexts, and exposes application versioning and hostname information.

pkg/def · high confidence

JSON-RPC 2.0 service implementation with CORS and metrics

The JSON-RPC 2.0 server implementation is introduced in the \ms/example/internal/srv/jsonrpc2\ package. This includes the HTTP handler setup with CORS support, error mapping for JSON-RPC 2.0 responses, and Prometheus metrics initialization. The implementation also includes tests for the handlers and CORS headers.

ms/example/internal/srv · medium confidence

New gRPC client and server helpers with authentication and metrics

The pkg/grpcx package introduces new utilities for building gRPC services and clients. Server-side, it provides interceptors for logging, panic recovery, access logging, and pluggable authentication (AuthnFunc) that can be chained. Client-side, it offers a Dial function that chains unary and stream interceptors for metrics, logging, and access logging. The package also includes helpers for extracting X-Forwarded-For headers and OAuth2 access tokens from incoming requests, as well as Prometheus metrics registration for both client and server gRPC activity.

pkg/grpcx · high confidence

New network utility functions in the netx package

The netx package now includes helpers for managing TCP ports and TLS certificates. Users can obtain a unique unused TCP port via UnusedTCPPort, wait for a TCP port to become available with WaitTCPPort, and load CA certificates from a file using LoadCACert. A new Addr struct is also provided to manage host and port combinations.

pkg/netx · high confidence

Behavioural changes

Embedded Swagger UI for API documentation

The web package now embeds the Swagger UI interface directly into the application binary using Go's built-in embed feature, replacing the previous statik-based approach. This change bundles the static assets required for the Swagger UI, allowing users to access the interactive API documentation without relying on external file paths or separate asset servers.

web · medium confidence

Embedded Swagger UI static assets

The project now embeds Swagger UI static files (including CSS, JavaScript, and HTML templates) directly into the binary using Go's go:embed directive, replacing the previous statik-based approach.

_third\party · medium confidence

Moved insecure development PKI assets to a dedicated subdirectory

The \configs\ directory has been reorganized to group all insecure development PKI (Public Key Infrastructure) assets under a new \insecure-dev-pki\ subdirectory. This includes the CA certificate, private keys, issued certificates, certificate signing requests, and configuration files. This change simplifies the top-level \configs\ directory and clearly separates development-only security materials from production or shared configurations.

configs · high confidence

Test coverage

Added integration tests for the example microservice

Added integration tests for the example microservice, including a test suite that validates the service's HTTP/JSON-RPC2 endpoints and database interactions using a temporary MySQL instance. The tests verify authentication, data persistence, and error handling, ensuring the service behaves correctly in a realistic environment.

ms/example · high confidence

Dependencies

Initial Go module and dependency setup

The project now includes a go.mod file that defines the module github.com/powerman/go-monolith-example using Go 1.16. This file establishes the project's dependencies, including gRPC, PostgreSQL, MySQL, NATS, and various utility and testing libraries, providing the foundation for the application's build and runtime environment.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 46 → 50 (+3.9)
  • Rubric changed (rubric-2026.08.18 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 99 → 99 (-0.3)
  • Architecture 100 → 93 (-7.1)
  • Maturity 74 → 74 (+0.0)
  • Readiness 35 → 39 (+4.0)
  • Security 27 → 35 (+7.4)
  • Domain Modelling 100 → 100 (+0.0)

Resolved (33)

  • Build action pinned to a mutable branch
  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (10 lines × 2) (pkg/migrate/goose-mysql.go)
  • Duplicated block (11 lines × 2) (pkg/repo/repo-mysql.go)
  • Duplicated block (13 lines × 2) (ms/auth/internal/dal/dal.go)
  • Duplicated block (6 lines × 2) (ms/auth/internal/config/testing.go)
  • Duplicated block (6 lines × 2) (ms/example/internal/config/config.go)
  • Duplicated block (7 lines × 2) (ms/auth/internal/config/config.go)
  • Duplicated block (8 lines × 2) (ms/auth/internal/srv/grpc/srv.go)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 13 more

New (119)

  • Critical CVE: [GHSA redacted] (go.mod)
  • Critical CVE: [GHSA redacted] (go.sum)
  • Critical CVE: [GHSA redacted] (go.mod)
  • Dependency pinned to a stale untagged commit: github.com/cheekybits/genny
  • Dependency pinned to a stale untagged commit: github.com/sebest/xff
  • Dependency pinned to a stale untagged commit: golang.org/x/crypto
  • Dependency pinned to a stale untagged commit: golang.org/x/oauth2
  • Dependency pinned to a stale untagged commit: google.golang.org/genproto
  • Dependency pinned to a stale untagged commit: google.golang.org/grpc
  • Dependency pinned to a stale untagged commit: google.golang.org/protobuf
  • Duplicated block (10 lines × 2) (pkg/migrate/goose-mysql.go)
  • Duplicated block (12 lines × 2) (ms/auth/internal/dal/dal.go)
  • Duplicated block (12 lines × 2) (pkg/repo/repo-mysql.go)
  • Duplicated block (23 lines × 2) (ms/auth/internal/app/metrics.go)
  • Duplicated block (5 lines × 2) (ms/auth/internal/config/testing.go)
  • Duplicated block (5 lines × 2) (ms/example/internal/config/config.go)
  • Duplicated block (6 lines × 2) (ms/auth/internal/srv/grpc/srv.go)
  • Duplicated block (8 lines × 2) (ms/auth/internal/dal/methods.go)
  • Duplicated block (9 lines × 2) (ms/auth/internal/config/config.go)
  • Duplicated block (9 lines × 2) (pkg/cobrax/goose-mysql.go)
  • …and 99 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

powerman/go-monolith-example was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit a990187d04a516269277410c48882a14ba843ccc — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.