Skip to main content

API Service — Container

This C3 Component view opens the API Service container and shows its service, identity, real-time, and data-access boundaries.

loading...

Components​

ComponentResponsibility
Fastify HTTP boundaryProvides typed HTTPS/JSON routes, request validation, error mapping, and API composition
Keycloak identity guardValidates JWT signatures and claims through Keycloak JWKS and attaches the authenticated subject context
Pilot profile serviceMaintains Keycloak-subject linkage and pilot preferences
Progress serviceMaintains resumable activity, outcomes, and progress
Socket.IO gatewayAuthenticates and validates typed socket traffic but rejects flight commands when the production command forwarder is unavailable; it is not an active browser flight path
Prisma data adapterApplies PostgreSQL transactions, schema types, and pilot-ownership checks through the namespace NetworkPolicy boundary
Health serviceProvides liveness and readiness endpoints for Gondor

Interface rules​

  • Osgiliath terminates public HTTPS/WSS, then Kubernetes Ingress routes /api and /socket.io to this container over HTTP with WebSocket upgrade support.
  • HTTP uses JSON contracts. The exposed /socket.io route authenticates and validates typed traffic but is fail-closed scaffolding in the Release 1 production composition.
  • All pilot-owned routes and sockets require a valid Keycloak identity.
  • Liveness and readiness probes bypass the pilot identity guard and disclose no pilot data.
  • The API validates ownership before every pilot-data read or write.
  • Only the Prisma adapter communicates with the Pilot Data Store.
  • No catalogue route or catalogue service is registered; Release 1 catalogues are compiled into the Web Application.