Skip to content

Latest commit

 

History

90 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Waypoint

Waypoint is a demo application that showcases automated application provisioning into a Kubernetes cluster provisioned to AWS using Entigo Infralib. It demonstrates data gathering from an external public API, storing the results in a database, and serving them through a web interface. Capable of running as multiple replicas for redundancy.

The application is API-first: both components generate their client and server code from a shared OpenAPI specification.

Components

Backend is a Go application that features:

  • Database sql schema and migrations management.
  • Collector that collects data from Andmete Teabevärav and stores it in a PostgreSQL database. Collected data includes categories, EMS categories and themes. Supports multiple instances by using table locks to ensure that only one instance is collecting data at a time.
  • REST API server that serves the collected data from the database from /api endpoints.
  • Prometheus metrics endpoint for observability.
  • Technical documentation in README.md.

Frontend is a React application that features:

  • Client for retrieving the collected data from the backend API.
  • Ant Design based components for displaying the data.
  • Accessibility features.
  • Technical documentation in README.md.

Local development

To run the full application locally:

  1. Start the database: docker compose up -d in the backend/ directory.
  2. Run database migrations, described in backend/README.md.
  3. Start the backend.
  4. Start the frontend.

CI/CD

Pull requests and pushes to main run linting and tests as a quality gate for both backend and frontend, as well as Helm chart linting.

The release pipeline is triggered by a version tag (vX.Y.Z) and:

  1. Runs all quality gates.
  2. Builds and publishes Docker images for the backend, database migrations, and frontend to GHCR with build provenance attestations.
  3. Packages and publishes the waypoint-helm Helm chart to GHCR.
  4. On successful release, the package is deployed to the dev environment.

The database Helm chart (waypoint-db-helm) is versioned and published independently on every merge to main that modifies backend/db files.

Attestations

Build provenance and SBOMs are attached to each image by BuildKit. To inspect:

docker buildx imagetools inspect ghcr.io/entigolabs/waypoint:latest --format '{{json .Provenance}}'
docker buildx imagetools inspect ghcr.io/entigolabs/waypoint:latest --format '{{json .SBOM}}'

Build provenance and CycloneDX SBOMs are also attested via GitHub Attestations. To verify and download with GitHub CLI:

# Verify provenance
gh attestation verify oci://ghcr.io/entigolabs/waypoint:latest --owner entigolabs

# Verify and download SBOM
gh attestation verify oci://ghcr.io/entigolabs/waypoint:latest --owner entigolabs --predicate-type https://cyclonedx.org/bom
gh attestation download oci://ghcr.io/entigolabs/waypoint:latest --owner entigolabs --predicate-type https://cyclonedx.org/bom

The above commands apply to all three images: waypoint, waypoint-front, and waypoint-db.

Deployment

Prerequisites: a Kubernetes cluster with ArgoCD provisioned by Entigo Infralib into AWS.

ArgoCD application examples

Important: The database application must be deployed and synced before the Waypoint application.

waypoint-db-helm uses the Entigo Platform API to provision:

  1. An RDS instance with a waypoint database.
  2. A PostgreSQL OWNER role (without login) and a user that inherits it.

waypoint-helm provisions in order:

  1. A database migration job using the owner credentials.
  2. An application database user with read/write permissions.
  3. Backend and frontend deployments with AWS ALB Ingress.

Waypoint database application

apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
  name: waypoint-db
spec:
  destination:
    namespace: default
    server: https://kubernetes.default.svc
  source:
    path: ''
    repoURL: ghcr.io/entigolabs
    targetRevision: '*.*.*'
    chart: waypoint-db-helm
    helm:
      parameters:
        - name: deletionProtection
          value: 'true'
  sources: []
  project: default

Waypoint application

apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
  name: waypoint
spec:
  destination:
    namespace: default
    server: https://kubernetes.default.svc
  source:
    path: ''
    repoURL: ghcr.io/entigolabs
    targetRevision: '*.*.*'
    chart: waypoint-helm
    helm:
      parameters:
        - name: backend.config.ALLOWED_ORIGINS
          value: https://waypoint.example.com
        - name: ingress.host
          value: waypoint.example.com
        - name: database.releaseName
          value: waypoint-db
  sources: []
  project: default

About

Example application for Infralib

Resources

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages