Context
This is the AS_IS architecture of Maze Legacy, reconstructed from maze-legacy/maze branch develop at commit 03522c898990b0794c2526ef942aa6dd3c32b27a. It describes repository evidence, not the Maze Next Gen target design. Where source, local Compose, and Kubernetes artifacts disagree, the uncertainty is called out rather than resolved by assumption.
Purpose and users
Maze Legacy is a browser-based multi-cloud design and infrastructure lifecycle application. Its repository supports these observable user groups:
- Cloud architects and platform engineers create visual resource canvases, manage cloud credentials, import existing infrastructure, generate Terraform, estimate cost, and publish project artifacts.
- Project collaborators share projects through owner, maintainer, developer, and viewer roles.
- Administrators approve and manage users, configuration, messages, versions, reports, and service status.
- Prism users and automation exchange project data and generated infrastructure files through the Prism integration.
System context
loading...| External dependency | Observed relationship | Evidence |
|---|---|---|
| IBM W3 / OIDC provider | Browser authentication uses discovery, authorization, token, user-info, client, and callback settings. | packages/api/services/AuthService.ts; packages/api/lib/apiDefaults.ts |
| GitHub and GitHub Enterprise | OAuth, repository, branch, commit, pull request, tag, and release operations. Prism publishing targets github.ibm.com/api/v3. | packages/thirdparty/git/github/GitController.ts; packages/api/services/PrismIntegrationService.ts |
| AWS, Azure, Google Cloud, IBM Cloud | Cloud credentials, resource templates, import, Terraform generation/execution, machine images, and cost workflows. | packages/api/controllers/CloudAccountController.ts; packages/thirdparty/*; packages/api/services/TerraformEngineService.ts |
| Prism | Authenticates a Prism token, imports project YAML, and publishes generated infrastructure files. | packages/api/services/PrismIntegrationService.ts |
| S3-compatible object storage | Stores canvas icons, user images, and project images through AWS S3 or IBM Cloud Object Storage. | packages/api/services/ImageService.ts |
| AWS SES | Sends account and password-reset email from noreply@maze-multicloud.com. | packages/api/services/EmailService.ts |
| PostgreSQL | Persists users, projects, canvases, credentials, imports, templates, activities, costs, reports, notifications, and integration state. | packages/api/prisma/schema.prisma |
Boundaries and trust observations
- Public traffic is intended to enter through an NGINX Kubernetes Ingress with TLS managed by cert-manager.
/routes to the UI,/apito Maze Core, and/api/gitto Maze Git according to the Helm values. - The browser sends Maze JWTs and a GitHub token to API routes. Authentication and authorization are enforced by NestJS guards on many, but not visibly all, controller methods.
- Cloud-account credentials are persisted as a string field in PostgreSQL. The repository does not establish whether storage-level encryption or an external secret manager protects that field in deployed environments.
- Maze Core executes infrastructure tooling and interacts with cloud control planes. This makes its runtime identity and credential boundary materially more privileged than a typical CRUD API.
Evidence limits
The repository contains active code beside older migration and local-development artifacts. tooling/docker/docker-compose.yml describes many legacy services whose start scripts and application workspaces no longer exist, while the current Helm registry deploys only UI, Core, and Git. This analysis treats the Helm registry plus current workspaces as the strongest deployable-topology evidence and records the Compose model as historical drift.