Skip to content
CAI
Software that uses CAICheck a score

powerman/go-service-example

61.2

Adequate · 20 September 2026

2.4k

lines of production code

Go

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a Go-based address-book microservice that manages contact records using a MySQL backend with seek-based pagination. It exposes a secure HTTP API defined by an OpenAPI specification, featuring API key-based authentication and role-based authorization to restrict write access. The architecture follows Clean Principles, separating concerns into data access, application logic, and server layers, while providing comprehensive observability through Prometheus metrics and standardized error handling.

Features

Add MySQL database configuration support

The service now supports configuring a MySQL database connection via environment variables (prefixed with EXAMPLE\_) and CLI flags. Users can set the host, port, database name, username, and password for MySQL, as well as the directory for database migrations. The configuration also includes settings for the main service API host/port and Prometheus metrics port, with defaults provided for local development.

internal/config · high confidence

Added MySQL data access layer with seek-based pagination

The internal data access layer now supports MySQL as a persistent storage backend, complementing the existing in-memory implementation. This addition includes database schema migrations (creating a Contact table), SQL query definitions, and integration tests to verify functionality. For users, this enables the application to store contacts persistently using MySQL, with the listing endpoint supporting efficient seek-based pagination (filtering by ID) rather than simple offset-based paging.

internal/dal · high confidence

Initial implementation of the application core and API context helpers

This change introduces the foundational business logic and supporting utilities for the service. It adds the \internal/app\ package, which defines the \Appl\ and \Repo\ interfaces along with the \App\ implementation for managing contacts (listing and adding) and health checks, including specific error handling for duplicate contacts. It also introduces \internal/apix\ to provide context helpers for propagating remote IP addresses. Additionally, Prometheus metrics initialization is added to the application package to support observability.

internal/app · high confidence

Initial project scaffolding and configuration

The repository has been initialized with the core structure for a Go service example, including a Dockerfile, docker-compose configuration for local development with MySQL, and environment variable templates. It introduces a strict golangci-lint configuration, a tools.go file to manage development dependencies (such as go-swagger and mockgen), and standard Git/Docker ignore attributes. The project also includes a comprehensive README detailing the Clean Architecture implementation, package structure, and usage instructions for running the service via Docker.

(repo-wide) · high confidence

Initial release of the address-book microservice entry point

The \cmd/address-book\ directory now contains the complete entry point for the example microservice. This includes the main executable logic with graceful shutdown handling, service initialization wiring (connecting the MySQL data access layer, application logic, and OpenAPI server), Prometheus metrics registration, and a CLI interface via Cobra. An integration test suite is also provided to verify the service's HTTP API behavior against a temporary MySQL database.

cmd · high confidence

Introduce OpenAPI-based HTTP server with authentication and metrics

The service now exposes an HTTP API using the OpenAPI (Swagger) specification, replacing or supplementing previous transport mechanisms. This new server layer implements API key-based authentication (distinguishing between admin and standard users) and authorization, ensuring that non-admin users cannot perform write operations. It includes a health check endpoint, contact listing with seek pagination, and contact creation, all wrapped in middleware for logging, access metrics (Prometheus), CORS, and error recovery. Error responses now follow a standardized format with both HTTP status codes and application-specific error codes, and internal errors are masked from clients to prevent information leakage.

internal/srv · high confidence

New build, test, and CI automation scripts

Added shell scripts to automate the development workflow: \scripts/build\ compiles Go binaries with version injection and builds Docker images; \scripts/test\ runs linting (hadolint, shellcheck, golangci-lint) and integration tests with race detection; \scripts/cover\ generates code coverage reports; \scripts/stat\ outputs source line counts; and \scripts/test-ci-circle\ facilitates local execution of CircleCI configurations.

scripts · high confidence

New shared utility packages for service scaffolding

This change introduces a new \pkg/\ directory containing a collection of reusable utility packages designed to standardize common service patterns. Key additions include \pkg/def\ for centralized application initialization, logging configuration, and metrics setup; \pkg/migrate\ and \pkg/cobrax\ to provide a structured, type-safe interface for running database migrations (specifically MySQL via Goose) as CLI commands; \pkg/repo\ to offer a Data Access Layer wrapper that handles transaction management, schema version locking, and automatic instrumentation; and \pkg/serve\ to simplify starting and managing HTTP and OpenAPI servers with context-aware shutdown. These packages collectively reduce boilerplate for new services by providing pre-built components for dependency injection, database access, and server lifecycle management.

pkg · high confidence

Behavioural changes

API specification update: new health check endpoint and seek-based pagination

The OpenAPI specification (swagger.yml) has been updated to version 0.2.0, introducing a new /health-check endpoint that returns a 200 status when the service is operational. Additionally, the /contacts GET endpoint now supports seek-based pagination via the SeekPagination model, requiring since\_id and limit parameters to return contacts ordered by ID. The spec also defines a standardized Error model for consistent error responses across the API.

api · high confidence

Dependencies

Initial dependency manifest for Go service

The project introduces a new go.mod file establishing the initial dependency set for the Go service. This includes core libraries for HTTP handling (go-openapi/runtime, swag, strfmt, validate, spec, loads, errors), database access (go-sql-driver/mysql, lib/pq, sqlx), CLI tools (spf13/cobra, pflag), and internal utility packages (powerman/structlog, dockerize, appcfg). The manifest also sets the Go version to 1.16 and includes development tools for linting, mocking, and testing.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 58 → 61 (+3.5)
  • Rubric changed (rubric-2026.08.17 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 99 → 100 (+0.3)
  • Architecture 100 → 92 (-7.8)
  • Maturity 52 → 54 (+1.8)
  • Readiness 52 → 58 (+6.0)
  • Security 50 → 57 (+7.5)
  • Domain Modelling 100 → 100 (+0.0)

Resolved (27)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — no supported dependency manifest was read
  • Duplicated block (6 lines × 2) (internal/config/config.go)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 7 more

New (86)

  • Critical CVE: [GHSA redacted] (go.sum)
  • Critical CVE: [GHSA redacted] (go.sum)
  • Dependency pinned to a stale untagged commit: github.com/cheekybits/genny
  • Dependency pinned to a stale untagged commit: github.com/sebest/xff
  • Dependency pinned to a stale untagged commit: golang.org/x/net
  • Duplicated block (5 lines × 2) (internal/config/config.go)
  • High CVE: [GHSA redacted] (go.mod)
  • High CVE: [GHSA redacted] (go.sum)
  • High CVE: [GHSA redacted] (go.sum)
  • High CVE: [GHSA redacted] (go.mod)
  • High CVE: [GHSA redacted] (go.sum)
  • High IaC: WD-DOCKER-0013 (Dockerfile)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 66 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

powerman/go-service-example was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 20 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 7c7c69f4015856446016c0ee1b8eaba01947aa43 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.