Skip to content

Known gaps

This project is a learning and portfolio platform. The architecture and delivery tooling are broad, and several production concerns are still open. Everything below was found by reading the code. The roadmap tracks the fixes.

Checkout publish and delete are not atomic

Section titled “Checkout publish and delete are not atomic”

Basket publishes BasketCheckoutEvent, then deletes the cart, in two steps with no transactional outbox (src/Services/Basket/Basket.API/Controllers/BasketController.cs). Duplicates are harmless now, because Ordering’s consumer is idempotent on CorrelationId, but a crash between the steps can still leave a cart behind after the order was created.

Validation runs outside UnhandledExceptionBehaviour, so rejected commands are returned as 400 problem details but are not logged by the pipeline.

Gap Evidence
No authentication or authorization on any API No AddAuthentication or [Authorize] anywhere in src/; UseAuthorization() has nothing to enforce
CORS allows any origin AllowAnyOrigin() in every Program.cs and the gateway
Card number and CVV travel in events and are stored in plain text src/BuildingBlocks/EventBus.Messages/Events/BasketCheckoutEvent.cs, src/Services/Ordering/Ordering.Core/Entities/Order.cs
Actors hard-coded "system" in Catalog events, "slowey" in Ordering audit fields
Basket trusts client prices ShoppingCartItem.Price comes from the request body
mTLS permissive only; Ordering outside the mesh No PeerAuthentication in deploy/istio; sidecar.istio.io/inject: "false" for Ordering
Development credentials in the repo .env.example, deploy/k8s/secrets.yaml
Gap Evidence
No health endpoints or probes Health-check packages referenced, never mapped; API Deployments have no probes
No app-level metrics Business dashboards query revenue_total and similar series that nothing emits
Traces break at RabbitMQ MassTransit activity source not registered
NetworkPolicies and PDBs are not applied, and would break things if they were default-deny with no allow rules; minAvailable: 1 with 1 replica
Elasticsearch version drift Sink templates for ES 8; containers run ES 7.9.2; AWS uses OpenSearch 2.11
Gap Evidence
Test gates are soft in CI 97 backend tests exist, but the CI integration job is still continue-on-error; the k8s deployment test swallows failures
Security scans and CD smoke test never block exit-code: 0, fail-build: false, smoke test exits 0 when the LB is not ready
Two IaC paths that disagree Terraform provisions managed data stores; CD deploys in-cluster databases with Helm; resource names differ
Terraform state is local Backend block commented out in deploy/terraform/backend.tf
Dead gateway routes /Discount REST routes and the Istio discount VirtualService target a gRPC-only service