Maze Core
| Field | AS_IS value |
|---|---|
| Kind | Modular-monolith API and infrastructure workflow engine |
| C4 classification | Container: independently deployable API process |
| Deployment evidence | Dedicated NestJS entry point and image; Helm Deployment, Service, ingress route and port 8080 |
| Source | applications/maze-core, packages/api, packages/shared, packages/thirdparty/* |
| Technology | Node.js, NestJS, Express, Prisma, PostgreSQL, Swagger, JWT, server-sent events, provider SDKs and Terraform tooling |
| Image | maze in AWS ECR; tooling/docker/core/Dockerfile |
| Runtime | Port 8080; global prefix /api/; ingress path /api |
| Persistence | PostgreSQL, S3-compatible object storage, and local working directories |
Responsibilities
CoreModule assembles controllers and services for authentication, users, roles, cloud accounts, projects, resources, canvases, templates, imports, Terraform lifecycle, costs, insights, images, notifications, status, feedback, reports, administration, Prism, Git, CLI, and machine images. Those modules, controllers, and services are components inside Maze Core; they are not independently deployable containers.
Principal interfaces
- REST/JSON under
/api/*, with Swagger also mounted at/api/. - Server-Sent Events under
/api/ssefor notifications. - Prisma access through
DATABASE_URL. - HTTP/SDK calls to OIDC, GitHub/GitHub Enterprise, Prism, AWS/Azure/GCP/IBM APIs, AWS SES, AWS S3 or IBM COS.
- Local process and filesystem operations for Terraform, import, generated files, temporary credentials, and Git workflows.
Internal component boundaries
| Component | Main source |
|---|---|
| HTTP controllers and guards | packages/api/controllers, packages/api/guards |
| Domain/application services | packages/api/services |
| Persistence model | packages/api/prisma/schema.prisma, migrations, PrismaService |
| Infrastructure generation/execution | packages/api/lib/terraform, TerraformEngineService, provider packages |
| Shared cloud resource metadata | packages/thirdparty/aws, azurerm, google, ibm |
| Cross-cutting contracts | packages/shared, packages/logger |
Security and operational observations
- The runtime combines database, user, Git, object-storage, email, cloud, Prism, and infrastructure-execution privileges.
- Session and JWT code has development fallback secrets; safe deployment depends on environment variables.
- The cloud-account model persists
cloudAccountCredentialsas a string; encryption behavior is not established by repository evidence. - Helm does not visibly define readiness/liveness probes, resource limits, a security context, network policy, or persistent volumes.
- Nest's schedule module is enabled. Any scheduled behavior belongs to the legacy application; this documentation does not introduce a Corp v1 scheduler job.
Migration implications
Separate target capabilities by trust and lifecycle rather than copying every historical service name. In particular, isolate credential custody and Terraform execution from general CRUD/API responsibilities, define durable workflow state, and replace ambiguous local filesystem state with explicit storage contracts.