Sign inSign up

jdwlabs/profile-service

By jdwlabs

•Updated 2 days ago

Profiles, addresses and icons API for the jdwlabs platform.

Image
0

582

jdwlabs/profile-service repository overview

⁠jdwlabs/profile-service

Profiles, addresses and icons API for the jdwlabs platform.

Docker Image Version Docker Image Size Docker Pulls

⁠What it is

A Go service serving the fifteen /api/profiles operations of the jdwlabs auth surface: profile records, their addresses and a single PNG icon each. It reads and writes the same auth schema the JVM usersrole service uses, and authorizes from the verified JWT alone — no call to another service on the request path. Built on distroless for a minimal attack surface, running as a numeric non-root uid.

⁠Quick start

docker run -p 8080:8080 \
  -e UR_JWT_SECRET_KEY="$(base64 < /dev/urandom | head -c 44)" \
  -e UR_PG_DATASOURCE_URL="jdbc:postgresql://authdb:5432/jdw" \
  -e UR_PG_USERNAME=jdw \
  -e UR_PG_PASSWORD=jdw \
  -e PS_JWT_ISSUER_ORIGIN="http://localhost:8080" \
  jdwlabs/profile-service:latest

curl http://localhost:8080/actuator/health

The service needs a reachable Postgres carrying the auth schema — the jdwlabs/authdb image ships it — and refuses to start without one.

⁠Exposed ports

PortPurpose
8080HTTP API

⁠Environment

VariableDefaultPurpose
UR_JWT_SECRET_KEYrequiredBase64 HMAC key shared with the token issuer
UR_PG_DATASOURCE_URLrequiredJDBC URL of the auth database
UR_PG_USERNAME—Database user
UR_PG_PASSWORD—Database password
PS_PORT8080Listen port
PS_JWT_ISSUER_ORIGINrequiredOrigin the tokens are minted from
PS_JWT_ALLOW_ANY_ISSUER_AND_AUDIENCEunsettrue accepts a token from any issuer
PS_DB_MAX_CONNECTIONS5Connection pool ceiling
PS_DB_MIN_CONNECTIONS2Connection pool floor
PS_CORS_ALLOWED_ORIGIN_PATTERNSany originComma-separated allowed-origin patterns
PS_CORS_ALLOWED_METHODSsevenComma-separated preflight methods
PS_CORS_ALLOWED_HEADERStwoComma-separated preflight headers
PS_SHUTDOWN_TIMEOUT_SECONDS10Drain window on SIGTERM

⁠Observability

PathPurpose
/actuator/healthLiveness and readiness, {"status":"UP"}
/actuator/prometheusScrape endpoint
/healthAlias, for parity with the sibling Go services

Request timings are published as http_server_requests_seconds, labelled method, uri, status and outcome — the series name and labels Micrometer publishes for the JVM service, so existing dashboards keep working.

⁠Tags

  • latest — most recent release
  • X.Y.Z — immutable semver release

⁠Source

⁠License

PolyForm Noncommercial 1.0.0

Tag summary

Content type

Image

Digest

sha256:922a5848d…

Size

16.7 MB

Last updated

2 days ago

docker pull jdwlabs/profile-service