Known gaps
This project is a learning and portfolio platform. The architecture and delivery tooling are broad, and several production concerns are still open. Everything below was found by reading the code. The roadmap tracks the fixes.
Correctness
Section titled “Correctness”Checkout publish and delete are not atomic
Section titled “Checkout publish and delete are not atomic”Basket publishes BasketCheckoutEvent, then deletes the cart, in two steps with no transactional outbox (src/Services/Basket/Basket.API/Controllers/BasketController.cs). Duplicates are harmless now, because Ordering’s consumer is idempotent on CorrelationId, but a crash between the steps can still leave a cart behind after the order was created.
Validation failures are not logged
Section titled “Validation failures are not logged”Validation runs outside UnhandledExceptionBehaviour, so rejected commands are returned as 400 problem details but are not logged by the pipeline.
Security
Section titled “Security”| Gap | Evidence |
|---|---|
| No authentication or authorization on any API | No AddAuthentication or [Authorize] anywhere in src/; UseAuthorization() has nothing to enforce |
| CORS allows any origin | AllowAnyOrigin() in every Program.cs and the gateway |
| Card number and CVV travel in events and are stored in plain text | src/BuildingBlocks/EventBus.Messages/Events/BasketCheckoutEvent.cs, src/Services/Ordering/Ordering.Core/Entities/Order.cs |
| Actors hard-coded | "system" in Catalog events, "slowey" in Ordering audit fields |
| Basket trusts client prices | ShoppingCartItem.Price comes from the request body |
| mTLS permissive only; Ordering outside the mesh | No PeerAuthentication in deploy/istio; sidecar.istio.io/inject: "false" for Ordering |
| Development credentials in the repo | .env.example, deploy/k8s/secrets.yaml |
Operability
Section titled “Operability”| Gap | Evidence |
|---|---|
| No health endpoints or probes | Health-check packages referenced, never mapped; API Deployments have no probes |
| No app-level metrics | Business dashboards query revenue_total and similar series that nothing emits |
| Traces break at RabbitMQ | MassTransit activity source not registered |
| NetworkPolicies and PDBs are not applied, and would break things if they were | default-deny with no allow rules; minAvailable: 1 with 1 replica |
| Elasticsearch version drift | Sink templates for ES 8; containers run ES 7.9.2; AWS uses OpenSearch 2.11 |
Delivery
Section titled “Delivery”| Gap | Evidence |
|---|---|
| Test gates are soft in CI | 97 backend tests exist, but the CI integration job is still continue-on-error; the k8s deployment test swallows failures |
| Security scans and CD smoke test never block | exit-code: 0, fail-build: false, smoke test exits 0 when the LB is not ready |
| Two IaC paths that disagree | Terraform provisions managed data stores; CD deploys in-cluster databases with Helm; resource names differ |
| Terraform state is local | Backend block commented out in deploy/terraform/backend.tf |
| Dead gateway routes | /Discount REST routes and the Istio discount VirtualService target a gRPC-only service |