Waypoint is a demo application that showcases automated application provisioning into a Kubernetes cluster provisioned to AWS using Entigo Infralib. It demonstrates data gathering from an external public API, storing the results in a database, and serving them through a web interface. Capable of running as multiple replicas for redundancy.
The application is API-first: both components generate their client and server code from a shared OpenAPI specification.
Backend is a Go application that features:
- Database sql schema and migrations management.
- Collector that collects data from Andmete Teabevärav and stores it in a PostgreSQL database. Collected data includes categories, EMS categories and themes. Supports multiple instances by using table locks to ensure that only one instance is collecting data at a time.
- REST API server that serves the collected data from the database from
/apiendpoints. - Prometheus metrics endpoint for observability.
- Technical documentation in README.md.
Frontend is a React application that features:
- Client for retrieving the collected data from the backend API.
- Ant Design based components for displaying the data.
- Accessibility features.
- Technical documentation in README.md.
To run the full application locally:
- Start the database:
docker compose up -din thebackend/directory. - Run database migrations, described in backend/README.md.
- Start the backend.
- Start the frontend.
Pull requests and pushes to main run linting and tests as a quality gate for both backend and frontend, as well as Helm chart linting.
The release pipeline is triggered by a version tag (vX.Y.Z) and:
- Runs all quality gates.
- Builds and publishes Docker images for the backend, database migrations, and frontend to GHCR with build provenance attestations.
- Packages and publishes the
waypoint-helmHelm chart to GHCR. - On successful release, the package is deployed to the
devenvironment.
The database Helm chart (waypoint-db-helm) is versioned and published independently on every merge to main that modifies backend/db files.
Build provenance and SBOMs are attached to each image by BuildKit. To inspect:
docker buildx imagetools inspect ghcr.io/entigolabs/waypoint:latest --format '{{json .Provenance}}'
docker buildx imagetools inspect ghcr.io/entigolabs/waypoint:latest --format '{{json .SBOM}}'Build provenance and CycloneDX SBOMs are also attested via GitHub Attestations. To verify and download with GitHub CLI:
# Verify provenance
gh attestation verify oci://ghcr.io/entigolabs/waypoint:latest --owner entigolabs
# Verify and download SBOM
gh attestation verify oci://ghcr.io/entigolabs/waypoint:latest --owner entigolabs --predicate-type https://cyclonedx.org/bom
gh attestation download oci://ghcr.io/entigolabs/waypoint:latest --owner entigolabs --predicate-type https://cyclonedx.org/bomThe above commands apply to all three images: waypoint, waypoint-front, and waypoint-db.
Prerequisites: a Kubernetes cluster with ArgoCD provisioned by Entigo Infralib into AWS.
Important: The database application must be deployed and synced before the Waypoint application.
waypoint-db-helm uses the Entigo Platform API to provision:
- An RDS instance with a waypoint database.
- A PostgreSQL OWNER role (without login) and a user that inherits it.
waypoint-helm provisions in order:
- A database migration job using the owner credentials.
- An application database user with read/write permissions.
- Backend and frontend deployments with AWS ALB Ingress.
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
name: waypoint-db
spec:
destination:
namespace: default
server: https://kubernetes.default.svc
source:
path: ''
repoURL: ghcr.io/entigolabs
targetRevision: '*.*.*'
chart: waypoint-db-helm
helm:
parameters:
- name: deletionProtection
value: 'true'
sources: []
project: defaultapiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
name: waypoint
spec:
destination:
namespace: default
server: https://kubernetes.default.svc
source:
path: ''
repoURL: ghcr.io/entigolabs
targetRevision: '*.*.*'
chart: waypoint-helm
helm:
parameters:
- name: backend.config.ALLOWED_ORIGINS
value: https://waypoint.example.com
- name: ingress.host
value: waypoint.example.com
- name: database.releaseName
value: waypoint-db
sources: []
project: default