Maze Git
| Field | AS_IS value |
|---|---|
| Kind | Git/GitHub integration API |
| C4 classification | Container: independently deployable API artifact; live deployment unconfirmed |
| Deployment evidence | Dedicated NestJS entry point and image; Helm Deployment, Service, ingress route and port 8082; omitted from direct Terraform application map |
| Source | applications/maze-git, packages/thirdparty/git |
| Technology | Node.js, NestJS, Git CLI, GitHub REST APIs, JWT guards |
| Image | maze-git in AWS ECR; tooling/docker/core/Dockerfile.gitsvc |
| Runtime | Port 8082; global prefix /api/; ingress path /api/git |
| Persistence | GitHub/GitHub Enterprise repositories and ephemeral local clone/work directories |
Responsibilities
- Start and complete GitHub OAuth.
- List organization repositories, branches, tags, releases, and commit contents.
- Clone repository content into a working directory.
- Create repositories, branches, blobs, trees, commits, pull requests, tags, and releases.
- Delete Git references.
Interfaces and dependencies
The browser calls /api/git/*. Maze Core also calls Git routes through MAZE_API_INTERNAL_URL or Git endpoint settings. The service depends on GitHub/GitHub Enterprise APIs, Git credentials/tokens, local Git/Python tooling, and writable filesystem space.
Architectural ambiguity
There are two Git implementations in the snapshot:
- Maze Git boots
GitModulefrompackages/thirdparty/gitas a separate runtime. - Maze Core's
CoreModulealso registersGitControllerandGitServicefrompackages/api.
Both expose routes under /api/git. The Helm Ingress's more specific /api/git path is intended to select Maze Git, but route precedence and deployment configuration must be verified in a running environment. This duplication is a migration seam and a source of behavioral drift.
Risks and migration implications
- Git tokens pass through browser and service headers.
- Clone and generated-file workflows accept directory inputs and rely on ephemeral filesystem state.
- The service image includes Git, Python, pip, npm, and Yarn, increasing its runtime surface.
- Consolidate one authoritative Git integration contract in TO_BE architecture and separate repository API operations from workspace execution where practical.