Sign inSign up

embraceable/goldview-frontend

By embraceable

•Updated 2 months ago

GOLDview — Analysis-, Optimization & Compliance Management Platform for n8n

Image
Monitoring & observability
Web analytics
0

1.4K

embraceable/goldview-frontend repository overview

⁠GOLDview — Analysis, Optimization & Compliance Dashboard for n8n

Prebuilt image for GOLDview, a governance and analytics dashboard purpose-built for n8n⁠ workflows.

GOLDview connects directly to the n8n PostgreSQL database, polls it for changes, and turns workflow, execution, credential, user and cost data into a unified operations view — no Kafka, no Flink, no Debezium required.


⁠What you get

  • Builder Station — workflow + execution search, error analysis, retry chains, dependency mapping, anomaly feed
  • Management Console — overview, briefing room (AI assistant), insights, recommendations
  • Compliance & Audit — regulation map, risk matrix, security posture, PII scanner, audit trail, workflow change log, credential usage
  • Platform & Settings — model pricing, connections

Role-based visibility: n8n regular users see only the Builder section, n8n owners/admins see everything, and built-in Better Auth users always see everything.


⁠Quick start — full stack (GOLDview + n8n + Postgres)

Everything below is self-contained. No source checkout required — just copy the two files into an empty folder and run docker compose up.

⁠1. Create docker-compose.yml
# ============================================================================
# GOLDview + n8n — Prebuilt Image Stack
# ============================================================================
#
# Services:
#   1. PostgreSQL 16  — Shared database for n8n + GOLDview polling source
#   2. n8n            — Workflow automation platform
#   3. GOLDview       — Governance dashboard (prebuilt, pulled from Docker Hub)
#
# Usage:
#   docker compose up -d
#
# To upgrade to a newer GOLDview release, bump GOLDVIEW_VERSION in .env and:
#   docker compose pull goldview
#   docker compose up -d goldview
#
# ============================================================================

services:
  # ── PostgreSQL Database (shared by n8n + GOLDview) ─────────────────
  postgres:
    image: postgres:16-alpine
    restart: unless-stopped
    environment:
      POSTGRES_USER: ${POSTGRES_USER:-postgres}
      POSTGRES_PASSWORD: ${POSTGRES_PASSWORD:-postgres}
      POSTGRES_DB: ${POSTGRES_DB:-n8n}
    volumes:
      - postgres_data:/var/lib/postgresql/data
    ports:
      - ${POSTGRES_PORT:-5432}:5432
    healthcheck:
      test:
        - CMD-SHELL
        - pg_isready -h localhost -U ${POSTGRES_USER:-postgres} -d ${POSTGRES_DB:-n8n}
      interval: 5s
      timeout: 5s
      retries: 20
    networks:
      - goldview_net

  # ── n8n Workflow Automation ────────────────────────────────────────
  n8n:
    image: n8nio/n8n:${N8N_VERSION:-latest}
    restart: unless-stopped
    depends_on:
      postgres:
        condition: service_healthy
    ports:
      - ${N8N_PORT:-5678}:5678
    environment:
      DB_TYPE: postgresdb
      DB_POSTGRESDB_HOST: postgres
      DB_POSTGRESDB_PORT: 5432
      DB_POSTGRESDB_DATABASE: ${POSTGRES_DB:-n8n}
      DB_POSTGRESDB_USER: ${POSTGRES_USER:-postgres}
      DB_POSTGRESDB_PASSWORD: ${POSTGRES_PASSWORD:-postgres}
      N8N_HOST: ${N8N_HOST:-localhost}
      N8N_PORT: 5678
      N8N_PROTOCOL: http
      N8N_DIAGNOSTICS_ENABLED: "false"
      N8N_PERSONALIZATION_ENABLED: "false"
      N8N_ENCRYPTION_KEY: ${N8N_ENCRYPTION_KEY:-change-this-encryption-key-in-production}
      N8N_USER_MANAGEMENT_JWT_SECRET: ${N8N_USER_MANAGEMENT_JWT_SECRET:-change-this-jwt-secret-in-production}
      GENERIC_TIMEZONE: ${GENERIC_TIMEZONE:-Europe/Berlin}
    volumes:
      - n8n_data:/home/node/.n8n
    healthcheck:
      # n8n only exposes /healthz once bootstrap finishes (DB migrations done).
      test:
        - CMD-SHELL
        - node -e "require('http').get('http://127.0.0.1:5678/healthz',r=>process.exit(r.statusCode===200?0:1)).on('error',()=>process.exit(1))"
      interval: 10s
      timeout: 10s
      retries: 60
      start_period: 120s
    networks:
      - goldview_net

  # ── GOLDview Dashboard (prebuilt image from Docker Hub) ────────────
  goldview:
    image: embraceable/goldview-frontend:${GOLDVIEW_VERSION:-latest}
    restart: unless-stopped
    depends_on:
      postgres:
        condition: service_healthy
      n8n:
        condition: service_started
    ports:
      - ${GOLDVIEW_PORT:-3001}:3001
    environment:
      # ── n8n PostgreSQL connection + poller tuning ──
      N8N_PG_CONNECTION_STRING: postgresql://${POSTGRES_USER:-postgres}:${POSTGRES_PASSWORD:-postgres}@postgres:5432/${POSTGRES_DB:-n8n}
      N8N_PG_POLL_INTERVAL_MS: ${N8N_PG_POLL_INTERVAL_MS:-10000}
      N8N_PG_EXECUTION_LIMIT: ${N8N_PG_EXECUTION_LIMIT:-5000}
      N8N_PG_EXECUTION_DATA_LIMIT: ${N8N_PG_EXECUTION_DATA_LIMIT:-1000}
      N8N_PG_LOAD_EXECUTION_DATA: ${N8N_PG_LOAD_EXECUTION_DATA:-true}

      # ── GOLDview server ──
      PORT: 3001
      DEMO_MODE: ${DEMO_MODE:-false}
      NODE_ENV: production
      DATABASE_URL: "file:./dev.db"
      GOLDVIEW_PUBLIC_URL: ${GOLDVIEW_PUBLIC_URL:-http://localhost:3001}

      # ── Auth ──
      GOLDVIEW_LOGIN_EMAIL: ${GOLDVIEW_LOGIN_EMAIL:[email protected]}
      GOLDVIEW_LOGIN_PASSWORD: ${GOLDVIEW_LOGIN_PASSWORD:-goldview}
      BETTER_AUTH_SECRET: ${BETTER_AUTH_SECRET:-change-me-to-a-random-secret-at-least-32-chars}

      # ── n8n SSO (sign in with n8n credentials) ──
      N8N_AUTH_ENABLED: ${N8N_AUTH_ENABLED:-true}
      N8N_REST_BASE_URL: ${N8N_REST_BASE_URL:-http://n8n:5678}

      # ── AI Briefing Room Assistant ──
      # PAT is configured via the in-app UI; the server does not read
      # OPENAI_API_KEY from the environment.
      AI_ASSISTANT_ENABLED: ${AI_ASSISTANT_ENABLED:-true}
      OPENAI_BASE_URL: ${OPENAI_BASE_URL:-''}
      OPENAI_MODEL: ${OPENAI_MODEL:-auto}
      AI_ASSISTANT_MAX_TOOL_CALLS: ${AI_ASSISTANT_MAX_TOOL_CALLS:-6}
      AI_ASSISTANT_RATE_LIMIT_PER_5MIN: ${AI_ASSISTANT_RATE_LIMIT_PER_5MIN:-30}
      EMBRACEABLE_BASE_URL: https://app-preview.embraceable.ai
      INFINITY_MOCK: ${DEMO_MODE:-false}
    volumes:
      - goldview_data:/data
    networks:
      - goldview_net

networks:
  goldview_net:
    name: goldview_net

volumes:
  postgres_data:
  n8n_data:
  goldview_data:
⁠2. Create .env next to it
# ── GOLDview Docker image ──
# Pinned version for reproducible deployments, or `latest` to track the
# newest release.
GOLDVIEW_VERSION=v0.4.6

# ── PostgreSQL ──
POSTGRES_USER=postgres
POSTGRES_PASSWORD=postgres
POSTGRES_DB=n8n
POSTGRES_PORT=5432

# ── n8n ──
N8N_VERSION=latest
N8N_PORT=5678
N8N_HOST=localhost
N8N_ENCRYPTION_KEY=change-this-encryption-key-in-production
N8N_USER_MANAGEMENT_JWT_SECRET=change-this-jwt-secret-in-production
GENERIC_TIMEZONE=Europe/Berlin

# ── GOLDview ──
GOLDVIEW_PORT=3001
GOLDVIEW_PUBLIC_URL=http://localhost:3001
[email protected]
GOLDVIEW_LOGIN_PASSWORD=goldview
# Generate with: openssl rand -base64 32
BETTER_AUTH_SECRET=change-me-to-a-random-secret-at-least-32-chars

# ── Demo mode ──
# When true, pre-populates the dashboard with built-in seed data and
# pre-fills demo credentials ([email protected] / demo) on the login page.
# Useful to explore the UI before you have real n8n activity.
DEMO_MODE=true

# ── PostgreSQL Poller (tune for your workload) ──
N8N_PG_POLL_INTERVAL_MS=10000
N8N_PG_EXECUTION_LIMIT=5000
N8N_PG_EXECUTION_DATA_LIMIT=1000
N8N_PG_LOAD_EXECUTION_DATA=true

# ── n8n SSO ──
# When true: GOLDview users sign in with their n8n credentials.
#   - n8n owners/admins      → full dashboard access
#   - n8n regular users      → Builder section only
#   - Built-in Better Auth   → full dashboard access
N8N_AUTH_ENABLED=true
N8N_REST_BASE_URL=http://n8n:5678

# ── AI Briefing Room Assistant ──
# The API token is configured via the in-app UI on /briefing → Settings
# (admin only) and persisted to the dashboard database. The server does
# NOT read OPENAI_API_KEY from the environment.
AI_ASSISTANT_ENABLED=true
# OpenAI-compatible endpoint. The default targets the embraceable.ai
# gateway, where GOLDview-issued PATs (epat-…) are accepted. Override
# only if you proxy through your own host or point at OpenAI directly
# (leave empty to use the official OpenAI API).
OPENAI_BASE_URL=
# OPENAI_MODEL:
#   - "auto" (default for embraceable.ai): GOLDview discovers the active
#     model by calling <baseURL origin>/api/preview/model and picking
#     the first model whose name starts with "goldview".
#   - "gpt-4o-mini" or any explicit model id: pass the value verbatim.
OPENAI_MODEL=auto
AI_ASSISTANT_MAX_TOOL_CALLS=6
AI_ASSISTANT_RATE_LIMIT_PER_5MIN=30
EMBRACEABLE_BASE_URL=https://dev.embraceable.ai
INFINITY_MOCK=false

Before going to production: change BETTER_AUTH_SECRET, N8N_ENCRYPTION_KEY, N8N_USER_MANAGEMENT_JWT_SECRET, POSTGRES_PASSWORD, and GOLDVIEW_LOGIN_PASSWORD.

⁠3. Launch the stack
docker compose up -d
⁠4. Open the services
ServiceURLDefault login
GOLDviewhttp://localhost:3001⁠[email protected] / goldview
n8nhttp://localhost:5678⁠Prompts for owner setup on first visit
Postgreslocalhost:5432postgres / postgres

Demo mode is on by default (DEMO_MODE=true). The login form shows pre-filled demo credentials ([email protected] / demo) and the dashboard is populated with seed data baked into the image. Set DEMO_MODE=false once you connect a real n8n instance.


⁠Running standalone (GOLDview only, existing n8n + Postgres)

If you already run n8n and Postgres elsewhere, start just GOLDview:

docker run -d \
  --name goldview \
  -p 3001:3001 \
  -e N8N_PG_CONNECTION_STRING="postgresql://user:pass@host:5432/n8n" \
  -e BETTER_AUTH_SECRET="$(openssl rand -base64 32)" \
  -e DEMO_MODE=false \
  -e N8N_AUTH_ENABLED=true \
  -e N8N_REST_BASE_URL="http://your-n8n-host:5678" \
  -e OPENAI_BASE_URL="https://app-preview.embraceable.ai/api/openai-compat/v1" \
  -v goldview_data:/data \
  embraceable/goldview-frontend:latest

⁠Environment variables

⁠Required
VariableDescription
N8N_PG_CONNECTION_STRINGPostgreSQL URL for the n8n database. GOLDview polls this — connect with read access only if possible.
BETTER_AUTH_SECRETSession encryption key (min 32 chars). Generate with openssl rand -base64 32.
⁠Bootstrap admin (built-in Better Auth user)
VariableDefaultDescription
GOLDVIEW_LOGIN_EMAIL[email protected]Email of the admin user created on first boot.
GOLDVIEW_LOGIN_PASSWORDgoldviewPassword of that admin. Change this before production.
⁠Demo mode
VariableDefaultDescription
DEMO_MODEtrueWhen true, populates the dashboard with built-in seed data, creates a demo user ([email protected] / demo) and pre-fills its credentials on the login form. Set false for real use.
VariableDefaultDescription
N8N_AUTH_ENABLEDfalseIf true, GOLDview verifies logins against the n8n user table (REST first, PG fallback). n8n MFA users are honored.
N8N_REST_BASE_URL—Base URL of the n8n instance for SSO login lookups (e.g. http://n8n:5678). Required when SSO is enabled.
VITE_N8N_BASE_URL—Public n8n URL used to build "Open in n8n" deep-links from the dashboard.
⁠Public URL
VariableDefaultDescription
GOLDVIEW_PUBLIC_URLhttp://localhost:3001Public URL where this GOLDview instance is reachable. Used inside the AI assistant's deep-links and the "where is X?" copy. No trailing slash.
⁠AI Briefing Room Assistant

The AI assistant talks to any OpenAI-compatible chat-completions endpoint. The actual API token is set via the in-app UI (/briefing → Settings, admin only) and persisted in the dashboard database — the server does not read OPENAI_API_KEY from the environment.

VariableDefaultDescription
AI_ASSISTANT_ENABLEDtrueMaster switch. Set false to disable the assistant entirely.
OPENAI_BASE_URLhttps://app-preview.embraceable.ai/api/openai-compat/v1OpenAI-compatible API base (the SDK appends /chat/completions). The default targets the embraceable.ai gateway where GOLDview-issued PATs (epat-…) are accepted. Leave empty to talk to OpenAI directly.
OPENAI_MODELautoauto discovers the active model by calling <baseURL origin>/api/preview/model and picking the first model whose name starts with goldview. Pass any explicit model id verbatim to override.
AI_ASSISTANT_MAX_TOOL_CALLS6Hard ceiling on tool-call iterations per turn — guards against runaway loops.
AI_ASSISTANT_RATE_LIMIT_PER_5MIN30Per-user turns allowed in a rolling 5-minute window.
⁠Poller tuning
VariableDefaultDescription
N8N_PG_POLL_INTERVAL_MS10000How often to poll the n8n database (ms). Lower = more real-time, higher DB load.
N8N_PG_EXECUTION_LIMIT5000Max executions fetched per poll cycle.
N8N_PG_EXECUTION_DATA_LIMIT1000Max executions loaded with full payload data per cycle.
N8N_PG_LOAD_EXECUTION_DATAtrueLoad per-node I/O payloads for granular analytics. Set false to reduce memory / bandwidth.
⁠Server
VariableDefaultDescription
PORT3001HTTP port GOLDview listens on (inside the container).
NODE_ENVproductionNode runtime mode.
DATABASE_URLfile:./dev.dbLocal SQLite file for GOLDview's own state.

⁠Persistence

GOLDview stores its own state (users, comments, saved views, feedback) in a SQLite database at /data/goldview.db inside the container. Mount a volume at /data to persist it across restarts — the bundled compose file does this automatically via the goldview_data volume.

Important: do not mount a volume at /app/server/prisma. That directory holds the Prisma schema, migrations and seed scripts shipped with the image; a volume there would mask them and the container will crash on startup. Always mount at /data instead.

The n8n database itself (workflows, executions, credentials) lives on the Postgres instance GOLDview polls — GOLDview never writes there.

⁠On Kubernetes / OpenShift
  • PVC mount path: /data
  • DATABASE_URL: leave unset or set to file:/data/goldview.db (the default baked into the image)
  • Schema migrations: run automatically at container start via prisma db push; no Job or initContainer needed.
⁠Notes for production deployments
  • GOLDVIEW_PUBLIC_URL must be the public URL of the GOLDview service itself, not the n8n URL. Wrong value → AI-assistant deep-links point at the wrong host.
  • BETTER_AUTH_URL (optional) overrides the cookie domain Better Auth uses. Set when running behind a non-localhost domain.
  • CORS_ORIGIN (optional, comma-separated) should list every frontend origin that calls the API. If GOLDview is only reached through the same origin, leave it unset.
  • N8N_REST_BASE_URL can (and should) use in-cluster DNS (e.g. http://n8n.my-ns.svc:5678) — it does not need to be publicly reachable.

⁠Architecture at a glance

  ┌──────────┐     store    ┌───────────────┐    poll    ┌─────────────┐
  │   n8n    │─────────────▶│   Postgres   │◀───────────│  GOLDview  │
  │          │             │ (workflows, │     read    │ (dashboard)│
  │          │             │  executions)│             │            │
  └──────────┘              └───────────────┘             └─────┬───────┘
                                                                │
                                                         ┌──────▼──────┐
                                                         │   SQLite    │
                                                         │ (dashboard  │
                                                         │   state)    │
                                                         └─────────────┘

⁠Supported tags

  • latest — always points to the most recent stable release.
  • v0.5.0 — current release. Added policy review mechanic with the INFINITY Stack
  • v0.4.6 — Embraceable endpoints migrated to app-preview.embraceable.ai.
  • v0.4.5 — Imprint / Privacy / Terms links on the About page.
  • v0.4.4 — fixes AI-assistant default endpoint + resilient token validation.
  • v0.4.3 — /ai-costs and /compliance routes disabled, DEMO_MODE=true becomes the default.
  • v0.4.2 — earlier release.

Images are published for linux/amd64 and linux/arm64.


⁠License & attribution

© embraceable Technology. All rights reserved.

Published by embraceable⁠.

Tag summary

Content type

Image

Digest

sha256:576a11c00…

Size

402.1 MB

Last updated

2 months ago

docker pull embraceable/goldview-frontend