Milestone 1: Go API + React 19 SPA + compose scaffold - #2
Merged
Merged
Conversation
Adds the next baseline behind Milestone 0's docs site:
api/
- Go 1.25 module github.com/Exonical/stig-manager-react/api
- chi router with RequestID / RealIP / Recoverer / Timeout + CORS
- Scaffold endpoints behind /api/v1: op/appinfo, op/appdata/tables
- /health liveness probe
- log/slog JSON handler + graceful shutdown on SIGINT/SIGTERM
- pgx v5 pool helper in internal/store (no connection at startup;
real schema + queries arrive in Milestone 2)
- go test ./... covers the three scaffold handlers
- Multi-stage distroless Dockerfile
web/
- Vite 6 + React 19 + TypeScript (strict) + path alias @/*
- Tailwind CSS v4 (@tailwindcss/vite) with shadcn-flavoured theme
tokens (oklch palette, dark/light)
- shadcn/ui Button + Card scaffolded as project-local components
(variants extracted to a separate module so react-refresh stays clean)
- Theme toggle, landing page that exercises GET /api/v1/op/appinfo
through the Vite dev proxy
- ESLint flat config + Prettier
- Multi-stage Dockerfile that serves the built SPA via nginx and
proxies /api/* to the Go API in the compose network
deploy/
- docker-compose stack: Postgres 18 + Keycloak 26 + api + web
- Keycloak realm import with the stig-manager SPA client, OIDC
scopes matching upstream (collection / stig / user / op + :read
variants), and demo users (admin / evaluator)
ci/
- .github/workflows/web.yaml: lint, typecheck, build, artifact
- .github/workflows/api.yaml: vet, test (-race), build, artifact
- .github/workflows/docs.yaml updated to use the new root lockfile
pnpm workspace:
- pnpm-workspace.yaml (docs, web) and a single pnpm-lock.yaml at
the repo root, replacing docs/pnpm-lock.yaml
Signed-off-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-Authored-By: Bryce Anglin <brycemanglin@gmail.com>
Contributor
Author
🤖 Devin AI EngineerI'll be helping with this pull request! Here's what you should know: ✅ I will automatically:
Note: I can only respond to comments from users who have write access to this repository. ⚙️ Control Options:
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Lands the next baseline behind Milestone 0's docs site: a Go API, a
React 19 + shadcn/ui SPA, a docker-compose stack, and CI for both.
Stubs only — real
/api/v1handlers (from the upstream OpenAPI spec)and the Postgres schema arrive in Milestones 2–4.
api/— Go 1.25 backendgithub.com/Exonical/stig-manager-react/api.chirouter withRequestID/RealIP/Recoverer/Timeoutmiddleware and
go-chi/cors./api/v1:op/appinfo,op/appdata/tables./healthliveness probe.log/slogJSON handler + graceful shutdown on SIGINT/SIGTERM.pgxv5 pool helper ininternal/store(no connection at startupduring the scaffold; real schema + queries arrive in Milestone 2).
go test ./...covers the three scaffold handlers.web/— React 19 SPA@/*.@tailwindcss/vitewith a shadcn-flavoured theme(oklch palette, dark/light tokens in
src/styles/globals.css).Button+Cardscaffolded as project-local components.buttonVariantsis extracted to its own module soreact-refresh/only-export-componentsstays clean.GET /api/v1/op/appinfothrough the Vite dev proxy./api/*to the Go API in the compose network.deploy/— local stackdocker-compose.yaml: Postgres 18 + Keycloak 26 + api + web.deploy/keycloak/stigman-realm.json) with thestig-managerSPA client, OIDC scopes matching upstream(
stig-manager:collection,:stig,:user,:op+:readvariants), and demo users
admin/evaluator.CI
.github/workflows/web.yaml— lint → typecheck → build → artifact..github/workflows/api.yaml— vet → test (-race) → build → artifact..github/workflows/docs.yaml— updated to use the new root lockfile.pnpm workspace
pnpm-workspace.yaml(docs,web).pnpm-lock.yamlat the repo root, replacingdocs/pnpm-lock.yaml.Review & Testing Checklist for Human
docker compose -f deploy/compose/docker-compose.yaml up -d --buildand confirm the SPA on http://localhost:54000 loads, the
Keycloak admin console on http://localhost:8080 opens, and the
API answers
curl -s http://localhost:54001/health.landing page and verify the version JSON renders. The Vite dev
server proxies
/api/*through to:54001.three demo cards, and check the layout looks clean at both
desktop and mobile widths.
app compiles and
/api/v1/op/appinforeturns the right JSON,but they don't exercise the compose stack, the Keycloak realm
import, or any real persistence. The compose smoke test above
is the meaningful check.
Test plan
Notes
connecting on startup — that lands in Milestone 2 along with the
goose-managed baseline schema. The pgx pool helper is already
factored into
internal/storeso wiring it is a small, isolateddiff.
are imported, but the SPA does not yet do an OIDC PKCE flow and the
API does not yet verify tokens. That's Milestone 3, where it lands
end-to-end (login → token → scope-checked handler).
workspace mode. This PR re-introduces it correctly: workspace file
at the root, single lockfile at the root, and the docs workflow has
been updated alongside. Both
pnpm --filter docs buildandpnpm --filter @stig-manager-react/web buildsucceed from a cleaninstall locally.
1.25.4 because
pgx/v5@v5.9.2requires Go ≥ 1.25.scaffold endpoints are hand-rolled so the diff stays small and
understandable. Milestone 2 plugs in
oapi-codegenand replacesthem with generated stubs.
Link to Devin session: https://app.devin.ai/sessions/022810763c4643c0848ba894c1512b92
Requested by: @Exonical