Skip to content
CAI
Software that uses CAICheck a score

sanjyotagureddy/aspnetrun-microservices

59.2

Adequate · 21 September 2026

10.6k

lines of production code

C#

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a .NET 10 microservices platform for e-commerce operations, orchestrating distinct services for products, cart, orders, inventory, and discounts. It manages the full shopping lifecycle by handling cart updates, applying discounts via gRPC, processing checkouts, and tracking stock levels. The architecture relies on an API Gateway for routing, Kafka for event-driven messaging with a transactional outbox pattern, and Redis for caching, all supported by centralized observability and structured logging.

Features

Automated Windows hosts file management for local microservices

A new PowerShell script (update-hosts.ps1) is introduced to automatically configure the local hosts file for the microservices environment. The script requires administrator privileges, backs up the existing hosts file, and injects entries for services such as the API gateway, product, basket, ordering, and various infrastructure components (RabbitMQ, PostgreSQL, OpenSearch) under the aspnetrun.local domain. This simplifies local development setup by ensuring DNS resolution for all internal services is handled programmatically.

scripts · high confidence

Initial repository scaffolding for .NET 10 microservices platform

The repository has been initialized with a complete project structure for an ASP.NET Core microservices application targeting .NET 10. This includes an Aspire AppHost for orchestrating local resources (PostgreSQL, Kafka), a YARP-based API Gateway, and service projects for Products, Cart, Order, Inventory, and a Discount gRPC service. The codebase introduces a shared kernel with broker-agnostic messaging contracts, a transactional outbox pattern for reliable event publishing, and centralized logging/observability via OpenTelemetry and Serilog. Documentation has been added to guide local development, including a Postman collection for API testing and a detailed README outlining the current architecture, prerequisites, and build/test instructions.

(repo-wide) · high confidence

Introduce YARP Gateway, Cart, Discount, and Inventory microservices with unified observability and messaging

This change adds four new service components to the platform: a YARP-based API Gateway that routes traffic to products, inventory, cart, and orders; a Cart API backed by Redis for distributed caching and integrated with a gRPC Discount client; a Discount gRPC service using SQLite for coupon management; and an Inventory API for tracking stock levels. All services are containerized with .NET 10 Dockerfiles and share a standardized observability stack, including AppCallContext middleware for correlation/tenant tracking, request logging with payload protection and redaction, and a broker-agnostic messaging architecture with contract versioning (e.g., cart checkout and inventory initialized events).

src/Services · high confidence

Introduce cart and order management APIs

This change introduces the API surface for cart and order management. For carts, it adds endpoints to get, update, and delete a shopping cart, as well as a checkout endpoint that publishes a checkout event and clears the cart. For orders, it adds endpoints to create an order, retrieve orders by user name, retrieve a specific order by ID, and cancel an order. These endpoints wire up MediatR handlers that interact with repositories and, for cart updates, a gRPC discount service.

src/Services/Cart/Cart.Api/Features/Cart, src/Services/Order/Order.Api/Features/Orders · high confidence

Introduce shared architectural primitives and web infrastructure

The Common.SharedKernel library now provides foundational building blocks for the application, including base types for entities, value objects, and auditing, as well as contracts for domain and integration events. It adds a result-pattern for handling operation outcomes, a validation pipeline behavior for MediatR requests, and a guard helper for input validation. For web services, it introduces a dynamic endpoint discovery mechanism that respects environment-based scopes (Development, UAT, Production) and integrates Swagger UI with support for both JWT Bearer and Keycloak OAuth2 authentication flows.

src/Shared/Common.SharedKernel · high confidence

New structured logging library with payload protection and OpenSearch integration

The \Common.SharedKernel.Logging\ package has been introduced to provide a unified, structured logging infrastructure. It replaces ad-hoc logging with a typed system supporting Trace, API, and Error log categories, enriched with correlation, trace, tenant, and user context. The library features a configurable pipeline that includes built-in log enrichers, filters, and formatters (JSON and Text). A key capability is payload protection, which allows masking or removing sensitive data from request/response bodies before storage, with configurable rules and failure behaviors. Logs can be routed to Console, File, or Elasticsearch (OpenSearch) sinks, with specific index prefixes for application, messaging, audit, and security logs. The library integrates with ASP.NET Core via a request logging middleware that automatically captures HTTP context and applies payload protection.

src/Shared/Common.SharedKernel.Logging · high confidence

Test coverage

Added integration and unit tests for logging, messaging, inventory, and cart services

Added comprehensive test coverage for the shared logging pipeline, Kafka-based messaging with Postgres outbox, the new Inventory microservice persistence, and Cart API business logic. The changes include integration tests verifying that log entries are dispatched to configured sinks, that messages are correctly published to Kafka with proper envelopes and headers, and that the outbox publisher reliably marks rows as published or failed with retry logic. Inventory tests confirm that the Postgres schema initializer creates the required tables and indexes and that the inventory store correctly persists and queries stock data. Cart unit tests validate core shopping cart operations including retrieving, updating, and deleting carts, as well as the checkout flow which publishes integration events and clears the cart. Supporting test infrastructure includes Docker-based fixtures for Kafka and Postgres, recording loggers, and code coverage configurations.

tests · high confidence

Dependencies

Upgrade to .NET 10 and adopt Aspire 13.4 with centralized package management

The project has been upgraded to target .NET 10.0 across all services, shared kernels, and test projects. It now uses Aspire 13.4.2 for hosting and orchestration, introducing centralized package version management via Directory.Packages.props. Key dependencies include Grpc.AspNetCore 2.80.0, MediatR 14.1.0, FluentValidation 12.1.1, and OpenTelemetry 1.16.0, while test infrastructure has been updated to use xUnit v3 and the Microsoft Testing Platform.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 60 → 59 (-1.2)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 86 → 79 (-7.6)
  • Architecture 78 → 77 (-0.7)
  • Maturity 72 → 72 (+0.5)
  • Readiness 68 → 60 (-7.8)
  • Security 50 → 52 (+1.6)
  • Event-Driven 100 → 100 (+0.0)
  • Performance 64 → 63 (-1.2)

Resolved (36)

  • Bounded contexts not declared
  • Coverage not measured
  • Duplicated block (12 lines × 2) (src/Services/Inventory/Inventory.Api/Program.cs)
  • Duplicated block (13 lines × 2) (src/Services/Inventory/Inventory.Api/Infrastructure/Persistence/InventoryTransactionExecutor.cs)
  • Duplicated block (13 lines × 2) (src/Services/Inventory/Inventory.Api/Observability/InventoryRequestLoggingMiddleware.cs)
  • Duplicated block (15 lines × 2) (src/Shared/Common.SharedKernel.Logging/Options/LoggingPolicyOptions.cs)
  • Duplicated block (17 lines × 2) (src/Shared/Common.SharedKernel.Logging/Pipeline/DefaultPayloadMaskingEngine.cs)
  • Duplicated block (37 lines × 2) (src/Gateway/Gateway.Yarp/Program.cs)
  • Duplicated block (40 lines × 2) (src/Services/Inventory/Inventory.Api/Infrastructure/GlobalExceptionHandler.cs)
  • Duplicated block (5 lines × 2) (src/Services/Product/Products.Api/Features/Products/Create/CreateProductCommandValidator.cs)
  • High CVE: MessagePack 2.5.192
  • High CVE: MessagePack 2.5.192
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • IL efficiency: 1 authored method(s) exceed the IL budget (src/Shared/Common.SharedKernel.Logging/DependencyInjection/LoggingBuilder.cs)
  • LLM evaluation failed
  • Medium CVE: MessagePack 2.5.192
  • Medium CVE: MessagePack 2.5.192
  • …and 16 more

New (75)

  • Build failed
  • CommentedOutCode (src/aspire/aspnetrun-microservices.ServiceDefaults/Extensions.cs)
  • CoverageExclusion (src/Services/Inventory/Inventory.Api/Infrastructure/ServiceRegistration.cs)
  • CoverageExclusion (src/Services/Product/Products.Api/Infrastructure/ServiceRegistration.cs)
  • CoverageExclusion (src/Shared/Common.SharedKernel/Web/EndpointRegistrationExtensions.cs)
  • CoverageExclusion (src/Shared/Common.SharedKernel/Web/EndpointScopeAttribute.cs)
  • CoverageExclusion (src/Shared/Common.SharedKernel/Web/EndpointScopeResolver.cs)
  • CoverageExclusion (src/Shared/Common.SharedKernel/Web/SwaggerExtensions.cs)
  • Documentation: no architecture or design documentation (README.md)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (12 lines × 2) (src/Services/Inventory/Inventory.Api/Program.cs)
  • Duplicated block (13 lines × 2) (src/Services/Cart/Cart.Api/Program.cs)
  • Duplicated block (13 lines × 2) (src/Services/Inventory/Inventory.Api/Infrastructure/Persistence/InventoryTransactionExecutor.cs)
  • Duplicated block (13 lines × 5) (src/Gateway/Gateway.Yarp/Program.cs)
  • Duplicated block (14 lines × 5) (src/Gateway/Gateway.Yarp/Observability/AppCallContextMiddleware.cs)
  • Duplicated block (16 lines × 2) (src/Shared/Common.SharedKernel.Logging/Pipeline/DefaultPayloadMaskingEngine.cs)
  • Duplicated block (16–17 lines × 2) (src/Shared/Common.SharedKernel.Logging/Options/LoggingPolicyOptions.cs)
  • Duplicated block (17 lines × 6) (src/Gateway/Gateway.Yarp/Observability/GatewayRequestLoggingMiddleware.cs)
  • Duplicated block (18 lines × 4) (src/Gateway/Gateway.Yarp/Observability/AppCallContextMiddleware.cs)
  • …and 55 more

Changes since last survey

  • 1 commits — 1 feature/other, 0 fixes

By area

  • src/Services — 1 commit

Notable commits

  • change: feat: implement observability middleware, add unit tests for Yarp gateway, and expand service domain logic

API surface

  • 8 added · 1 removed (a removed endpoint is potentially breaking)

Added endpoints (8)

  • DELETE /api/v1/cart/{userName}
  • DELETE /api/v1/orders/{id}
  • GET /api/v1/cart/{userName}
  • GET /api/v1/orders/user/{userName}
  • GET /api/v1/orders/{id}
  • POST /api/v1/cart
  • POST /api/v1/cart/checkout
  • POST /api/v1/orders

Removed endpoints (breaking) (1)

  • GET /weatherforecast

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

sanjyotagureddy/aspnetrun-microservices was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit b5aebdbade0938f4ed1a34accd16deb27ce0887e — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.