API Service — Container
This C3 Component view opens the API Service container and shows its service, identity, real-time, and data-access boundaries.
loading...
Components
| Component | Responsibility |
|---|---|
| Fastify HTTP boundary | Provides typed HTTPS/JSON routes, request validation, error mapping, and API composition |
| Keycloak identity guard | Validates JWT signatures and claims through Keycloak JWKS and attaches the authenticated subject context |
| Pilot profile service | Maintains Keycloak-subject linkage and pilot preferences |
| Progress service | Maintains resumable activity, outcomes, and progress |
| Socket.IO gateway | Authenticates and validates typed socket traffic but rejects flight commands when the production command forwarder is unavailable; it is not an active browser flight path |
| Prisma data adapter | Applies PostgreSQL transactions, schema types, and pilot-ownership checks through the namespace NetworkPolicy boundary |
| Health service | Provides liveness and readiness endpoints for Gondor |
Interface rules
- Osgiliath terminates public HTTPS/WSS, then Kubernetes Ingress routes
/apiand/socket.ioto this container over HTTP with WebSocket upgrade support. - HTTP uses JSON contracts. The exposed
/socket.ioroute authenticates and validates typed traffic but is fail-closed scaffolding in the Release 1 production composition. - All pilot-owned routes and sockets require a valid Keycloak identity.
- Liveness and readiness probes bypass the pilot identity guard and disclose no pilot data.
- The API validates ownership before every pilot-data read or write.
- Only the Prisma adapter communicates with the Pilot Data Store.
- No catalogue route or catalogue service is registered; Release 1 catalogues are compiled into the Web Application.