Skip to main content

Maze Core

FieldAS_IS value
KindModular-monolith API and infrastructure workflow engine
C4 classificationContainer: independently deployable API process
Deployment evidenceDedicated NestJS entry point and image; Helm Deployment, Service, ingress route and port 8080
Sourceapplications/maze-core, packages/api, packages/shared, packages/thirdparty/*
TechnologyNode.js, NestJS, Express, Prisma, PostgreSQL, Swagger, JWT, server-sent events, provider SDKs and Terraform tooling
Imagemaze in AWS ECR; tooling/docker/core/Dockerfile
RuntimePort 8080; global prefix /api/; ingress path /api
PersistencePostgreSQL, S3-compatible object storage, and local working directories

Responsibilities​

CoreModule assembles controllers and services for authentication, users, roles, cloud accounts, projects, resources, canvases, templates, imports, Terraform lifecycle, costs, insights, images, notifications, status, feedback, reports, administration, Prism, Git, CLI, and machine images. Those modules, controllers, and services are components inside Maze Core; they are not independently deployable containers.

Principal interfaces​

  • REST/JSON under /api/*, with Swagger also mounted at /api/.
  • Server-Sent Events under /api/sse for notifications.
  • Prisma access through DATABASE_URL.
  • HTTP/SDK calls to OIDC, GitHub/GitHub Enterprise, Prism, AWS/Azure/GCP/IBM APIs, AWS SES, AWS S3 or IBM COS.
  • Local process and filesystem operations for Terraform, import, generated files, temporary credentials, and Git workflows.

Internal component boundaries​

ComponentMain source
HTTP controllers and guardspackages/api/controllers, packages/api/guards
Domain/application servicespackages/api/services
Persistence modelpackages/api/prisma/schema.prisma, migrations, PrismaService
Infrastructure generation/executionpackages/api/lib/terraform, TerraformEngineService, provider packages
Shared cloud resource metadatapackages/thirdparty/aws, azurerm, google, ibm
Cross-cutting contractspackages/shared, packages/logger

Security and operational observations​

  • The runtime combines database, user, Git, object-storage, email, cloud, Prism, and infrastructure-execution privileges.
  • Session and JWT code has development fallback secrets; safe deployment depends on environment variables.
  • The cloud-account model persists cloudAccountCredentials as a string; encryption behavior is not established by repository evidence.
  • Helm does not visibly define readiness/liveness probes, resource limits, a security context, network policy, or persistent volumes.
  • Nest's schedule module is enabled. Any scheduled behavior belongs to the legacy application; this documentation does not introduce a Corp v1 scheduler job.

Migration implications​

Separate target capabilities by trust and lifecycle rather than copying every historical service name. In particular, isolate credential custody and Terraform execution from general CRUD/API responsibilities, define durable workflow state, and replace ambiguous local filesystem state with explicit storage contracts.