Compare commits
7
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
4ab2ef4285 | ||
|
|
8474b72bf4 | ||
|
|
271c54197e | ||
|
|
b32c352f20 | ||
|
|
4274fd30d1 | ||
|
|
4fe9915816 | ||
|
|
5f8ab4dbcd |
@@ -142,6 +142,8 @@ jobs:
|
|||||||
# reaches green health" smoke (it replaces the old compose-smoke job).
|
# reaches green health" smoke (it replaces the old compose-smoke job).
|
||||||
- name: Bring up the full stack & wait for health
|
- name: Bring up the full stack & wait for health
|
||||||
run: make verify-up
|
run: make verify-up
|
||||||
|
- name: Observability backplane (Grafana + Tempo + Prometheus datasources)
|
||||||
|
run: OBS_TIMEOUT=180 make verify-observability
|
||||||
- name: ACL ↔ OpenZaak integration tests
|
- name: ACL ↔ OpenZaak integration tests
|
||||||
run: make verify-acl
|
run: make verify-acl
|
||||||
- name: OpenZaak → NRC notification delivery
|
- name: OpenZaak → NRC notification delivery
|
||||||
@@ -152,12 +154,14 @@ jobs:
|
|||||||
run: make verify-domain
|
run: make verify-domain
|
||||||
- name: BFF → Keycloak + domain + projection
|
- name: BFF → Keycloak + domain + projection
|
||||||
run: make verify-bff
|
run: make verify-bff
|
||||||
|
- name: Distributed traces reach Tempo (one connected trace across services)
|
||||||
|
run: TRACING_TIMEOUT=120 make verify-tracing
|
||||||
- name: Self-service e2e (Playwright, login → submit → success)
|
- name: Self-service e2e (Playwright, login → submit → success)
|
||||||
run: make verify-e2e
|
run: make verify-e2e
|
||||||
# Log dump must precede teardown (which removes the containers).
|
# Log dump must precede teardown (which removes the containers).
|
||||||
- name: Dump container logs on failure
|
- name: Dump container logs on failure
|
||||||
if: failure()
|
if: failure()
|
||||||
run: docker compose -f infra/docker-compose.yml logs --no-color --tail=100 oz-init openzaak nrc-init nrc-web nrc-celery nrc-beat flowable-db flowable-rest flowable-init keycloak acl bff domain projection-db event-subscriber projection-api self-service openbaar behandel 2>&1 || true
|
run: docker compose -f infra/docker-compose.yml logs --no-color --tail=100 oz-init openzaak nrc-init nrc-web nrc-celery nrc-beat flowable-db flowable-rest flowable-init keycloak acl bff domain projection-db event-subscriber projection-api self-service openbaar behandel tempo prometheus grafana 2>&1 || true
|
||||||
- name: Tear down
|
- name: Tear down
|
||||||
if: always()
|
if: always()
|
||||||
run: make down
|
run: make down
|
||||||
|
|||||||
+9
-3
@@ -253,13 +253,19 @@ Split (issue #11 closed) into two independently-demoable slices per §13 — the
|
|||||||
|
|
||||||
**Outcome:** Beheer portal lets an admin view ZTC catalogi (read-only first), and manage the ACL's default-fill configuration via a CRUD UI. MFA on the medewerker realm enforced.
|
**Outcome:** Beheer portal lets an admin view ZTC catalogi (read-only first), and manage the ACL's default-fill configuration via a CRUD UI. MFA on the medewerker realm enforced.
|
||||||
|
|
||||||
### S-16 · OpenTelemetry traces + Grafana dashboard
|
### S-16 · OpenTelemetry traces + Grafana dashboard *(split — #17 closed)*
|
||||||
|
|
||||||
**Outcome:** Traces span portal → BFF → Domain → ACL → OpenZaak and portal → BFF → Domain → Flowable. Grafana dashboards pre-built for golden signals.
|
**Outcome:** Traces span portal → BFF → Domain → ACL → OpenZaak and portal → BFF → Domain → Flowable. Grafana dashboards pre-built for golden signals.
|
||||||
|
|
||||||
### S-17 · Quartz.NET scheduler — herregistratie reminder sweep
|
Split into independently deployable sub-slices (CLAUDE.md §13):
|
||||||
|
|
||||||
**Outcome:** Nightly job that finds entries within 90 days of expiry and emits a domain event. (No outbound notification in v1 — logged.)
|
- **S-16a** (#122) · Observability backplane — Grafana Tempo + Prometheus + Grafana in compose, datasources auto-provisioned (ADR-0023). No collector; config baked into built images.
|
||||||
|
- **S-16b** (#123) · Distributed traces across the five .NET services (OTLP → Tempo; traceparent propagates via the typed HttpClients). Depends on S-16a. ✅
|
||||||
|
- **S-16c** (#124) · Prometheus metrics + golden-signal Grafana dashboards. Depends on S-16a.
|
||||||
|
|
||||||
|
### S-17 · Quartz.NET scheduler — herregistratie reminder sweep ✅
|
||||||
|
|
||||||
|
**Outcome:** Daily Quartz.NET cron job finds inscriptions within 90 days of their herregistratie deadline and reminds each (flag on the aggregate + log). No outbound notification and no domain event in v1 — the reminder is the persisted flag, surfaced on the read model (ADR-0022, #120). Quartz fires time-triggered sweeps; the existing pumps stay as queue-drainers.
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
|
|||||||
@@ -43,7 +43,7 @@ export DOCKER_HOST := unix://$(PODMAN_SOCK)
|
|||||||
endif
|
endif
|
||||||
endif
|
endif
|
||||||
|
|
||||||
.PHONY: ci lint build unit mutation frontend integration verify verify-up verify-acl verify-nrc verify-projection verify-bff verify-domain verify-notifications smoke up down local verify-local local-down changelog openzaak-up openzaak-smoke openzaak-seed openzaak-down stack-up stack-smoke stack-down keycloak-up keycloak-smoke keycloak-down flowable-up flowable-smoke flowable-down help
|
.PHONY: ci lint build unit mutation frontend integration verify verify-up verify-acl verify-nrc verify-projection verify-bff verify-domain verify-observability verify-tracing verify-notifications smoke up down local verify-local local-down changelog openzaak-up openzaak-smoke openzaak-seed openzaak-down stack-up stack-smoke stack-down keycloak-up keycloak-smoke keycloak-down flowable-up flowable-smoke flowable-down help
|
||||||
|
|
||||||
## ci: run the full pipeline — lint, build, unit, mutation, frontend, verify (mirrors Gitea Actions)
|
## ci: run the full pipeline — lint, build, unit, mutation, frontend, verify (mirrors Gitea Actions)
|
||||||
## `verify` is the live-stack stage (full stack up once → ACL + notification checks).
|
## `verify` is the live-stack stage (full stack up once → ACL + notification checks).
|
||||||
@@ -170,6 +170,16 @@ verify-bff:
|
|||||||
verify-e2e:
|
verify-e2e:
|
||||||
bash infra/run-e2e-check.sh
|
bash infra/run-e2e-check.sh
|
||||||
|
|
||||||
|
## verify-observability: assert the observability backplane (Grafana + provisioned Tempo &
|
||||||
|
## Prometheus datasources) is live, against the already-running stack (S-16a).
|
||||||
|
verify-observability:
|
||||||
|
bash infra/run-observability-check.sh
|
||||||
|
|
||||||
|
## verify-tracing: assert one connected distributed trace spans the .NET services in Tempo
|
||||||
|
## (S-16b), against the already-running stack.
|
||||||
|
verify-tracing:
|
||||||
|
bash infra/run-tracing-check.sh
|
||||||
|
|
||||||
## verify: local mirror of the CI verify-stack job — full stack up once, all checks,
|
## verify: local mirror of the CI verify-stack job — full stack up once, all checks,
|
||||||
## tear down (always). For fast single-concern local iteration use `integration`
|
## tear down (always). For fast single-concern local iteration use `integration`
|
||||||
## (oz-only) or `verify-notifications` (oz+nrc) instead.
|
## (oz-only) or `verify-notifications` (oz+nrc) instead.
|
||||||
|
|||||||
@@ -0,0 +1,79 @@
|
|||||||
|
# ADR-0022: Quartz.NET for time-triggered fleet sweeps
|
||||||
|
|
||||||
|
- **Status:** Accepted
|
||||||
|
- **Date:** 2026-07-23
|
||||||
|
- **Deciders:** Respellion engineering
|
||||||
|
- **Slice:** S-17 (#18) · **Proposal issue:** #120
|
||||||
|
|
||||||
|
## Context
|
||||||
|
|
||||||
|
A BIG inscription is valid for a fixed term; before it lapses the zorgprofessional
|
||||||
|
must herregistreren. S-17 adds a **herregistratie reminder sweep**: once a day,
|
||||||
|
scan the register for inscriptions whose deadline is within the reminder window and
|
||||||
|
remind each one.
|
||||||
|
|
||||||
|
The Domain Service already runs periodic background work — `OpenZaakJobPump`,
|
||||||
|
`BeoordelingEscalatiePump`, `RegistratieVerlopenPump`. Those are **continuous job
|
||||||
|
pollers**: they drain Flowable's external-task/job queues at-least-once, picking up
|
||||||
|
work as soon as it is parked, on a short poll interval. The reminder sweep is a
|
||||||
|
different shape of work: **time-triggered**, once a day, over our own store — there
|
||||||
|
is no queue to drain and no "as soon as possible" requirement.
|
||||||
|
|
||||||
|
The PRD already names the scheduler component: "Scheduler (Quartz.NET): fleet-wide
|
||||||
|
sweeps (expiry, reminders)" (§39, §94). Adding Quartz.NET is nonetheless a new
|
||||||
|
dependency, so this decision is recorded before the code lands (CLAUDE.md §14).
|
||||||
|
|
||||||
|
## Decision
|
||||||
|
|
||||||
|
**Use Quartz.NET for time-triggered fleet sweeps, starting with the herregistratie
|
||||||
|
reminder sweep. Leave the existing pumps as `BackgroundService` job pollers.**
|
||||||
|
|
||||||
|
- `HerregistratieReminderJob` (a Quartz `IJob`) is fired by a cron trigger — daily
|
||||||
|
at 03:00 by default, overridable with `Quartz__Cron`. It is a thin shell: it
|
||||||
|
resolves the pure `HerregistratieReminderSweep` (application layer) and logs how
|
||||||
|
many reminders went out.
|
||||||
|
- The sweep's rule lives in the domain: `Registration.HerregistratieReminderDue(asOf)`,
|
||||||
|
which the store query and the sweep both build on. The sweep marks each reminded
|
||||||
|
inscription (`HerregistratieReminderVerstuurd`), so a re-fire reminds no one twice
|
||||||
|
(§8.6).
|
||||||
|
|
||||||
|
Two options were rejected:
|
||||||
|
|
||||||
|
1. **A `BackgroundService` with a 24h `Task.Delay`.** No new dependency, but it
|
||||||
|
drifts to process-start time, has no cron/misfire semantics, and contradicts the
|
||||||
|
PRD's named component. A daily "run at 03:00" is exactly what cron scheduling is
|
||||||
|
for.
|
||||||
|
2. **Migrating the three pumps onto Quartz too, for one mechanism.** Rejected: the
|
||||||
|
pumps are not schedulers. Forcing a "run at time T" tool onto "drain this queue
|
||||||
|
continuously" work is churn and a boundary change for negative benefit. The
|
||||||
|
teachable distinction is worth keeping: **pumps drain queues; Quartz fires
|
||||||
|
sweeps.**
|
||||||
|
|
||||||
|
## Consequences
|
||||||
|
|
||||||
|
**Positive**
|
||||||
|
|
||||||
|
- Cron scheduling with restart-stable timing and misfire handling, for free.
|
||||||
|
- The reminder rule is one domain method, reused by the store query and the sweep;
|
||||||
|
the scheduler owns none of the policy.
|
||||||
|
- The reference app now demonstrates the intended Scheduler component.
|
||||||
|
|
||||||
|
**Negative / costs**
|
||||||
|
|
||||||
|
- One new dependency (`Quartz`, `Quartz.Extensions.Hosting`) in the Domain Service.
|
||||||
|
- Two periodic-work mechanisms coexist (pumps + Quartz). Deliberate — they model
|
||||||
|
two genuinely different concerns, documented here.
|
||||||
|
|
||||||
|
**Follow-up**
|
||||||
|
|
||||||
|
- The validity term (5 years) and reminder lead time (16 weeks) are domain
|
||||||
|
calibration knobs; promote them to beheer config (S-15) if a demo needs them
|
||||||
|
per-catalogus.
|
||||||
|
- The Quartz job stores its schedule in RAM (`RAMJobStore`); a persistent/clustered
|
||||||
|
store is a later concern if the Domain Service is scaled out.
|
||||||
|
|
||||||
|
## Coupling rules touched (CLAUDE.md §8)
|
||||||
|
|
||||||
|
None. Quartz is internal to the Domain Service and drives an application use case
|
||||||
|
over the store port. No ZGW or Flowable coupling is added; the sweep talks to no
|
||||||
|
peer module.
|
||||||
@@ -0,0 +1,74 @@
|
|||||||
|
# ADR-0023: Grafana-native observability stack (Tempo + Prometheus + Grafana)
|
||||||
|
|
||||||
|
- **Status:** Accepted
|
||||||
|
- **Date:** 2026-07-23
|
||||||
|
- **Deciders:** Respellion engineering
|
||||||
|
- **Slice:** S-16a (#122), first of the S-16 (#17) split
|
||||||
|
|
||||||
|
## Context
|
||||||
|
|
||||||
|
The PRD calls for "OpenTelemetry traces, Prometheus metrics; a local Grafana with
|
||||||
|
pre-built dashboards" (§80). S-16 was split (CLAUDE.md §13) into a backplane slice
|
||||||
|
(this one), distributed tracing (#123), and metrics + dashboards (#124). The
|
||||||
|
backplane must stand up first: a local, CI-friendly place for traces and metrics to
|
||||||
|
land, viewable in one UI, reaching green health within the 3-minute compose budget.
|
||||||
|
|
||||||
|
Two shape decisions are non-obvious enough to record.
|
||||||
|
|
||||||
|
## Decision
|
||||||
|
|
||||||
|
**Run a Grafana-native stack — Grafana Tempo (traces) + Prometheus (metrics) +
|
||||||
|
Grafana (UI) — with the services exporting OTLP straight to Tempo (no collector),
|
||||||
|
and ship the config baked into small built images.**
|
||||||
|
|
||||||
|
### Trace backend: Tempo (not Jaeger)
|
||||||
|
|
||||||
|
Tempo keeps everything under one Grafana pane alongside metrics (and later logs),
|
||||||
|
which is exactly the "local Grafana with dashboards" the PRD asks for. Jaeger would
|
||||||
|
add a second UI and a second mental model for no benefit at this scale.
|
||||||
|
|
||||||
|
### No OTLP collector
|
||||||
|
|
||||||
|
Tempo ingests OTLP directly (gRPC 4317 / HTTP 4318) and Prometheus scrapes each
|
||||||
|
service's `/metrics`, so a collector would be a hop that processes nothing. Skipped.
|
||||||
|
If we later need fan-out, tail sampling, or log processing, a collector is an
|
||||||
|
additive change — the services already speak OTLP.
|
||||||
|
|
||||||
|
### Config baked into built images, not config volumes
|
||||||
|
|
||||||
|
The upstream Common Ground modules (OpenZaak, NRC, Keycloak, Flowable) run as
|
||||||
|
**verbatim** images and get their config streamed into external named volumes by
|
||||||
|
`infra/seed-config.sh`, because bind mounts don't reach sibling containers on the
|
||||||
|
CI runner (see `docs/runbooks/gitea-actions-gotchas.md`). The observability tools
|
||||||
|
are **not** peer modules we must run verbatim, so we take the simpler path: a
|
||||||
|
three-line `Dockerfile` per tool that `COPY`s its config in. This reaches sibling
|
||||||
|
containers everywhere (docker, podman, CI) with no seed step, no `CFG_VOLS` entry,
|
||||||
|
and no Makefile sprawl.
|
||||||
|
|
||||||
|
### Verified, not assumed
|
||||||
|
|
||||||
|
`infra/run-observability-check.sh` (the `verify-observability` step, run early in CI
|
||||||
|
`verify-stack`) asks Grafana to reach both datasources — Prometheus via its health
|
||||||
|
method, Tempo via the datasource proxy (Tempo's Grafana plugin implements no health
|
||||||
|
method) — so the check proves the datasources are actually wired, not merely that
|
||||||
|
containers started. The containers are not in `WAIT_SVCS`; the check polls Grafana
|
||||||
|
itself, so no in-image healthcheck tool is required.
|
||||||
|
|
||||||
|
## Consequences
|
||||||
|
|
||||||
|
**Positive**
|
||||||
|
|
||||||
|
- One UI for traces + metrics + (future) logs. Config is versioned in
|
||||||
|
`infra/observability/` and self-contained in the images.
|
||||||
|
- Backplane is independent of app instrumentation — #123 and #124 build on it.
|
||||||
|
|
||||||
|
**Negative / costs**
|
||||||
|
|
||||||
|
- Three more images built each CI run (kept small; not on the health-gate list).
|
||||||
|
- Storage is ephemeral container fs — a demo backplane, not a retention target.
|
||||||
|
Object storage for Tempo / remote-write for Prometheus is a later concern.
|
||||||
|
|
||||||
|
## Coupling rules touched (CLAUDE.md §8)
|
||||||
|
|
||||||
|
None. The stack is passive infrastructure: services *push* OTLP and *expose*
|
||||||
|
`/metrics`; nothing in the stack calls into a service or a peer module.
|
||||||
@@ -5,6 +5,87 @@ copy-pasteable walkthrough against a local `make up` stack.
|
|||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
|
## S-16b — distributed traces across the .NET services (#123, ADR-0023)
|
||||||
|
|
||||||
|
**Outcome:** the five .NET services (BFF, Domain, ACL, projection-api, event-subscriber) now emit
|
||||||
|
OpenTelemetry traces — ASP.NET Core + `HttpClient` auto-instrumentation, exported over OTLP to Tempo.
|
||||||
|
Because every cross-service call goes through a typed `HttpClient`, the W3C `traceparent` propagates for
|
||||||
|
free, so a request is **one connected trace** across the services (bff → domain → acl → openzaak;
|
||||||
|
bff → projection-api). `/health` is filtered out. No browser-side instrumentation yet, so the trace
|
||||||
|
begins at the BFF; the async Flowable-poll boundary is a separate trace (ADR-0023).
|
||||||
|
|
||||||
|
```bash
|
||||||
|
# 1. Automated (a CI verify-stack step): generate BFF traffic and assert Tempo holds one trace
|
||||||
|
# spanning multiple services.
|
||||||
|
make verify-tracing # → OK — trace <id> spans ['bff', 'projection-api']
|
||||||
|
|
||||||
|
# 2. By hand: drive the stack, then explore traces in Grafana.
|
||||||
|
make up
|
||||||
|
curl -s localhost:8080/openbaar/register >/dev/null # BFF → projection-api
|
||||||
|
open http://localhost:3000 # Grafana → Explore → Tempo → Search → service.name = bff → open a trace
|
||||||
|
```
|
||||||
|
|
||||||
|
**The path:** each host wires `AddOpenTelemetry().WithTracing(AddAspNetCoreInstrumentation +
|
||||||
|
AddHttpClientInstrumentation + AddOtlpExporter)`; `OTEL_SERVICE_NAME` / `OTEL_EXPORTER_OTLP_ENDPOINT`
|
||||||
|
come from compose; spans export to **tempo:4317** and render in Grafana against the provisioned Tempo
|
||||||
|
datasource.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## S-16a — observability backplane: Tempo + Prometheus + Grafana (#122, ADR-0023)
|
||||||
|
|
||||||
|
**Outcome:** the compose stack now includes a Grafana-native observability backplane — **Tempo** (OTLP
|
||||||
|
trace ingest on 4317/4318), **Prometheus**, and **Grafana** with both datasources auto-provisioned.
|
||||||
|
Nothing is instrumented yet (traces land in S-16b, metrics + dashboards in S-16c); this slice stands the
|
||||||
|
backplane up and proves Grafana can reach both datasources. Config is baked into small built images
|
||||||
|
(`infra/observability/`) — no collector, no config-volume seeding.
|
||||||
|
|
||||||
|
```bash
|
||||||
|
# 1. Bring the stack up, then assert the backplane is live (Grafana healthy + Tempo/Prometheus
|
||||||
|
# datasources reachable through Grafana). This is a CI verify-stack step.
|
||||||
|
make up
|
||||||
|
make verify-observability # → ✓ Grafana healthy ✓ Prometheus reachable ✓ Tempo reachable
|
||||||
|
|
||||||
|
# 2. Or just the backplane, no full stack needed (no external egress):
|
||||||
|
docker compose -f infra/docker-compose.yml up -d --build tempo prometheus grafana
|
||||||
|
open http://localhost:3000 # Grafana (admin/admin) → Connections → Data sources: Prometheus + Tempo
|
||||||
|
open http://localhost:9090 # Prometheus
|
||||||
|
```
|
||||||
|
|
||||||
|
**The path:** services will export OTLP → **Tempo:4317** and expose `/metrics` ← **Prometheus** scrapes;
|
||||||
|
**Grafana** (:3000) reads both via provisioned datasources with fixed uids `tempo` / `prometheus`.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
## S-17 — herregistratie reminder sweep on a Quartz cron (#18, ADR-0022)
|
||||||
|
|
||||||
|
**Outcome:** an inscription (INGESCHREVEN) now carries the moment it was entered in the register, from
|
||||||
|
which its herregistratie deadline is derived (inscription + 5-year validity). A **Quartz.NET** cron job
|
||||||
|
in the Domain Service sweeps once a day (03:00, overridable via `Quartz__Cron`): every inscription
|
||||||
|
inside the 90-day window before its deadline is flagged `HerregistratieReminderVerstuurd` and logged.
|
||||||
|
The sweep is idempotent — a re-fire reminds no one twice — and is a deliberately different mechanism
|
||||||
|
from the queue-draining pumps (Quartz fires time-triggered sweeps; pumps drain Flowable queues,
|
||||||
|
ADR-0022). There is no outbound notification in v1: the reminder is the flag on the aggregate plus a
|
||||||
|
log line.
|
||||||
|
|
||||||
|
```bash
|
||||||
|
# 1. The domain unit tests prove the rule and the sweep end to end (rule → store query → sweep):
|
||||||
|
cd services/domain && dotnet test Big.Tests/Big.Tests.csproj \
|
||||||
|
--filter "FullyQualifiedName~Herregistratie|FullyQualifiedName~ReminderSweep"
|
||||||
|
# → the reminder is due once the 90-day window opens, not before; a reminded inscription is skipped
|
||||||
|
# on the next sweep; the sweep flags + persists every due inscription and returns their ids.
|
||||||
|
|
||||||
|
# 2. The read model surfaces the deadline once a registration is approved — the field the sweep acts on:
|
||||||
|
curl -s localhost:8000/registrations/<id> | jq '{status, herregistratieVoor, herregistratieReminderVerstuurd}'
|
||||||
|
# → after approval: herregistratieVoor is inscription + 5 years; the flag flips true once swept.
|
||||||
|
```
|
||||||
|
|
||||||
|
**The path:** `Registration.Approve(now)` stamps `IngeschrevenOp` → daily Quartz `HerregistratieReminderJob`
|
||||||
|
→ `HerregistratieReminderSweep` → `IRegistrationStore.FindDueForHerregistratieReminderAsync` (filtered by
|
||||||
|
the aggregate's own `HerregistratieReminderDue` rule) → `MarkHerregistratieReminderVerstuurd` + log.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
## S-B04 — `make local` completes the whole flow with no manual seeding (#110, ADR-0020)
|
## S-B04 — `make local` completes the whole flow with no manual seeding (#110, ADR-0020)
|
||||||
|
|
||||||
**Outcome:** the host-browser stack (`make local`) now self-seeds at bring-up — it publishes the BIG
|
**Outcome:** the host-browser stack (`make local`) now self-seeds at bring-up — it publishes the BIG
|
||||||
|
|||||||
@@ -296,6 +296,10 @@ services:
|
|||||||
dockerfile: Dockerfile
|
dockerfile: Dockerfile
|
||||||
image: register-referentie/acl:dev
|
image: register-referentie/acl:dev
|
||||||
environment:
|
environment:
|
||||||
|
# OpenTelemetry traces → Tempo (S-16b, ADR-0023).
|
||||||
|
OTEL_EXPORTER_OTLP_ENDPOINT: http://tempo:4317
|
||||||
|
OTEL_EXPORTER_OTLP_PROTOCOL: grpc
|
||||||
|
OTEL_SERVICE_NAME: acl
|
||||||
# Overridable so verify-domain can point the ACL at the same OpenZaak host that
|
# Overridable so verify-domain can point the ACL at the same OpenZaak host that
|
||||||
# owns the seeded zaaktype URL (host-consistent zaak creation, ADR-0009).
|
# owns the seeded zaaktype URL (host-consistent zaak creation, ADR-0009).
|
||||||
Acl__OpenZaak__BaseUrl: ${ACL_OPENZAAK_BASEURL:-http://openzaak:8000/}
|
Acl__OpenZaak__BaseUrl: ${ACL_OPENZAAK_BASEURL:-http://openzaak:8000/}
|
||||||
@@ -334,6 +338,10 @@ services:
|
|||||||
dockerfile: Dockerfile
|
dockerfile: Dockerfile
|
||||||
image: register-referentie/domain:dev
|
image: register-referentie/domain:dev
|
||||||
environment:
|
environment:
|
||||||
|
# OpenTelemetry traces → Tempo (S-16b, ADR-0023).
|
||||||
|
OTEL_EXPORTER_OTLP_ENDPOINT: http://tempo:4317
|
||||||
|
OTEL_EXPORTER_OTLP_PROTOCOL: grpc
|
||||||
|
OTEL_SERVICE_NAME: domain
|
||||||
Flowable__BaseUrl: http://flowable-rest:8080/flowable-rest/
|
Flowable__BaseUrl: http://flowable-rest:8080/flowable-rest/
|
||||||
Flowable__Username: rest-admin
|
Flowable__Username: rest-admin
|
||||||
Flowable__Password: test
|
Flowable__Password: test
|
||||||
@@ -360,6 +368,10 @@ services:
|
|||||||
dockerfile: Dockerfile
|
dockerfile: Dockerfile
|
||||||
image: register-referentie/bff:dev
|
image: register-referentie/bff:dev
|
||||||
environment:
|
environment:
|
||||||
|
# OpenTelemetry traces → Tempo (S-16b, ADR-0023).
|
||||||
|
OTEL_EXPORTER_OTLP_ENDPOINT: http://tempo:4317
|
||||||
|
OTEL_EXPORTER_OTLP_PROTOCOL: grpc
|
||||||
|
OTEL_SERVICE_NAME: bff
|
||||||
# The BFF is the portals' only backend; it validates digid tokens and fans out (ADR-0010).
|
# The BFF is the portals' only backend; it validates digid tokens and fans out (ADR-0010).
|
||||||
# Keycloak (start-dev) derives the issuer from the request host, so the BFF authority and the
|
# Keycloak (start-dev) derives the issuer from the request host, so the BFF authority and the
|
||||||
# verify token request both use keycloak:8080 to keep the issuer consistent.
|
# verify token request both use keycloak:8080 to keep the issuer consistent.
|
||||||
@@ -412,6 +424,10 @@ services:
|
|||||||
dockerfile: services/event-subscriber/Dockerfile
|
dockerfile: services/event-subscriber/Dockerfile
|
||||||
image: register-referentie/event-subscriber:dev
|
image: register-referentie/event-subscriber:dev
|
||||||
environment:
|
environment:
|
||||||
|
# OpenTelemetry traces → Tempo (S-16b, ADR-0023).
|
||||||
|
OTEL_EXPORTER_OTLP_ENDPOINT: http://tempo:4317
|
||||||
|
OTEL_EXPORTER_OTLP_PROTOCOL: grpc
|
||||||
|
OTEL_SERVICE_NAME: event-subscriber
|
||||||
ConnectionStrings__Projection: Host=projection-db;Database=projection;Username=projection;Password=projection
|
ConnectionStrings__Projection: Host=projection-db;Database=projection;Username=projection;Password=projection
|
||||||
# The subscriber enriches the projection with each zaak's reference (identificatie) by asking
|
# The subscriber enriches the projection with each zaak's reference (identificatie) by asking
|
||||||
# the ACL — the only code allowed to read ZGW (§8.1, #78).
|
# the ACL — the only code allowed to read ZGW (§8.1, #78).
|
||||||
@@ -441,6 +457,10 @@ services:
|
|||||||
dockerfile: services/projection-api/Dockerfile
|
dockerfile: services/projection-api/Dockerfile
|
||||||
image: register-referentie/projection-api:dev
|
image: register-referentie/projection-api:dev
|
||||||
environment:
|
environment:
|
||||||
|
# OpenTelemetry traces → Tempo (S-16b, ADR-0023).
|
||||||
|
OTEL_EXPORTER_OTLP_ENDPOINT: http://tempo:4317
|
||||||
|
OTEL_EXPORTER_OTLP_PROTOCOL: grpc
|
||||||
|
OTEL_SERVICE_NAME: projection-api
|
||||||
ConnectionStrings__Projection: Host=projection-db;Database=projection;Username=projection;Password=projection
|
ConnectionStrings__Projection: Host=projection-db;Database=projection;Username=projection;Password=projection
|
||||||
ports:
|
ports:
|
||||||
- "8120:8080"
|
- "8120:8080"
|
||||||
@@ -524,6 +544,50 @@ services:
|
|||||||
condition: service_started
|
condition: service_started
|
||||||
networks: [cg]
|
networks: [cg]
|
||||||
|
|
||||||
|
# ── Observability backplane (S-16a, ADR-0023) ──────────────────────────────
|
||||||
|
# Grafana-native stack: Tempo ingests OTLP traces (the .NET services export
|
||||||
|
# straight to it — no collector hop, S-16b), Prometheus scrapes service
|
||||||
|
# /metrics (S-16c), and Grafana reads both with datasources auto-provisioned.
|
||||||
|
# Config is baked into small built images (COPY) rather than streamed into
|
||||||
|
# external config volumes like the upstream CG modules — these aren't verbatim
|
||||||
|
# peer images, so a built image is the simpler path that still reaches sibling
|
||||||
|
# containers on the CI runner. Not in WAIT_SVCS: run-observability-check.sh
|
||||||
|
# polls Grafana itself, so no in-image healthcheck tool is needed.
|
||||||
|
tempo:
|
||||||
|
build:
|
||||||
|
context: ./observability/tempo
|
||||||
|
image: register-referentie/tempo:dev
|
||||||
|
command: ["-config.file=/etc/tempo.yaml"]
|
||||||
|
# Cap the backplane's footprint so it can't starve the app stack + the Playwright browser on the
|
||||||
|
# memory-tight CI runner (verify-e2e OOM history, commit d5e5fa2). Generous vs idle (~150M).
|
||||||
|
mem_limit: 400m
|
||||||
|
networks: [cg]
|
||||||
|
|
||||||
|
prometheus:
|
||||||
|
build:
|
||||||
|
context: ./observability/prometheus
|
||||||
|
image: register-referentie/prometheus:dev
|
||||||
|
mem_limit: 400m
|
||||||
|
ports:
|
||||||
|
- "9090:9090"
|
||||||
|
networks: [cg]
|
||||||
|
|
||||||
|
grafana:
|
||||||
|
build:
|
||||||
|
context: ./observability/grafana
|
||||||
|
image: register-referentie/grafana:dev
|
||||||
|
mem_limit: 512m
|
||||||
|
environment:
|
||||||
|
GF_SECURITY_ADMIN_USER: admin
|
||||||
|
GF_SECURITY_ADMIN_PASSWORD: admin
|
||||||
|
GF_AUTH_ANONYMOUS_ENABLED: "true"
|
||||||
|
ports:
|
||||||
|
- "3000:3000"
|
||||||
|
depends_on:
|
||||||
|
- tempo
|
||||||
|
- prometheus
|
||||||
|
networks: [cg]
|
||||||
|
|
||||||
volumes:
|
volumes:
|
||||||
oz-db:
|
oz-db:
|
||||||
nrc-db:
|
nrc-db:
|
||||||
|
|||||||
@@ -0,0 +1,4 @@
|
|||||||
|
# Grafana with datasources baked in via provisioning (S-16a, ADR-0023).
|
||||||
|
# Dashboards (S-16c, #124) are added under provisioning/dashboards later.
|
||||||
|
FROM grafana/grafana:11.3.0
|
||||||
|
COPY provisioning/ /etc/grafana/provisioning/
|
||||||
@@ -0,0 +1,17 @@
|
|||||||
|
# Auto-provisioned datasources (S-16a, ADR-0023). Fixed uids so dashboards (S-16c)
|
||||||
|
# and the verify-observability check can reference them by a stable id.
|
||||||
|
apiVersion: 1
|
||||||
|
|
||||||
|
datasources:
|
||||||
|
- name: Prometheus
|
||||||
|
uid: prometheus
|
||||||
|
type: prometheus
|
||||||
|
access: proxy
|
||||||
|
url: http://prometheus:9090
|
||||||
|
isDefault: true
|
||||||
|
|
||||||
|
- name: Tempo
|
||||||
|
uid: tempo
|
||||||
|
type: tempo
|
||||||
|
access: proxy
|
||||||
|
url: http://tempo:3200
|
||||||
@@ -0,0 +1,2 @@
|
|||||||
|
FROM prom/prometheus:v2.55.1
|
||||||
|
COPY prometheus.yml /etc/prometheus/prometheus.yml
|
||||||
@@ -0,0 +1,10 @@
|
|||||||
|
# Prometheus scrape config (S-16a, ADR-0023). For the backplane slice it scrapes
|
||||||
|
# only itself; the .NET services' /metrics scrape targets are added in S-16c
|
||||||
|
# (#124) when the services expose metrics.
|
||||||
|
global:
|
||||||
|
scrape_interval: 15s
|
||||||
|
|
||||||
|
scrape_configs:
|
||||||
|
- job_name: prometheus
|
||||||
|
static_configs:
|
||||||
|
- targets: ['localhost:9090']
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
# Tempo with our config baked in — so it reaches sibling containers on the CI
|
||||||
|
# runner without the external-config-volume dance the upstream CG images need.
|
||||||
|
FROM grafana/tempo:2.6.1
|
||||||
|
COPY tempo.yaml /etc/tempo.yaml
|
||||||
@@ -0,0 +1,27 @@
|
|||||||
|
# Grafana Tempo — single-binary, all-in-one, local storage (S-16a, ADR-0023).
|
||||||
|
# Ingests OTLP directly (services export straight to Tempo; no collector hop).
|
||||||
|
# Storage is ephemeral container fs — this is a local/CI demo backplane, not a
|
||||||
|
# retention target. ponytail: local backend, swap for object storage if traces
|
||||||
|
# must outlive the stack.
|
||||||
|
server:
|
||||||
|
http_listen_port: 3200
|
||||||
|
|
||||||
|
distributor:
|
||||||
|
receivers:
|
||||||
|
otlp:
|
||||||
|
protocols:
|
||||||
|
grpc:
|
||||||
|
endpoint: 0.0.0.0:4317
|
||||||
|
http:
|
||||||
|
endpoint: 0.0.0.0:4318
|
||||||
|
|
||||||
|
ingester:
|
||||||
|
max_block_duration: 5m
|
||||||
|
|
||||||
|
storage:
|
||||||
|
trace:
|
||||||
|
backend: local
|
||||||
|
local:
|
||||||
|
path: /var/tempo/blocks
|
||||||
|
wal:
|
||||||
|
path: /var/tempo/wal
|
||||||
Executable
+45
@@ -0,0 +1,45 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
#
|
||||||
|
# S-16a (#122): assert the observability backplane is live against an ALREADY-RUNNING
|
||||||
|
# stack. Runs curl INSIDE the compose network (like the other verify checks) because
|
||||||
|
# the stack's published ports aren't on the CI runner's localhost — the stack is a set
|
||||||
|
# of sibling containers on the host daemon. It asks Grafana to reach its provisioned
|
||||||
|
# datasources — Prometheus via its health method, Tempo via the datasource proxy (Tempo's
|
||||||
|
# Grafana plugin implements no health method) — so it proves the datasources are wired,
|
||||||
|
# not merely that the containers started. Polls, so it tolerates a cold Grafana.
|
||||||
|
#
|
||||||
|
# Does NOT manage the stack lifecycle (the caller owns bring-up + teardown).
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
|
TIMEOUT="${OBS_TIMEOUT:-60}"
|
||||||
|
AUTH="${GRAFANA_AUTH:-admin:admin}"
|
||||||
|
|
||||||
|
gf="$(docker ps -q --filter 'name=[-_]grafana[-_]' | head -1)"
|
||||||
|
[ -n "$gf" ] || { echo "ERROR: no running grafana container — bring the stack up first" >&2; exit 1; }
|
||||||
|
net="$(docker inspect -f '{{range $k,$_ := .NetworkSettings.Networks}}{{$k}}{{"\n"}}{{end}}' "$gf" | head -1)"
|
||||||
|
gf_ip="$(docker inspect -f '{{range .NetworkSettings.Networks}}{{.IPAddress}}{{end}}' "$gf")"
|
||||||
|
base="http://$gf_ip:3000"
|
||||||
|
echo ">> grafana=$gf_ip network=$net"
|
||||||
|
|
||||||
|
# Run curl inside a throwaway container on the stack network (reaches services by IP).
|
||||||
|
net_curl() { docker run --rm --network "$net" curlimages/curl:latest "$@"; }
|
||||||
|
|
||||||
|
# poll <description> <grep -E pattern> <curl args...>
|
||||||
|
poll() {
|
||||||
|
local desc="$1" pat="$2"; shift 2
|
||||||
|
local deadline=$(( $(date +%s) + TIMEOUT ))
|
||||||
|
while :; do
|
||||||
|
if net_curl -fsS "$@" 2>/dev/null | grep -Eq "$pat"; then echo " ✓ $desc"; return 0; fi
|
||||||
|
if [ "$(date +%s)" -ge "$deadline" ]; then echo " ✗ $desc ($*)" >&2; return 1; fi
|
||||||
|
sleep 3
|
||||||
|
done
|
||||||
|
}
|
||||||
|
|
||||||
|
echo "Checking observability backplane at $base ..."
|
||||||
|
poll "Grafana is healthy" \
|
||||||
|
'"database":[[:space:]]*"ok"' "$base/api/health"
|
||||||
|
poll "Prometheus datasource reachable" \
|
||||||
|
'"status":[[:space:]]*"OK"' -u "$AUTH" "$base/api/datasources/uid/prometheus/health"
|
||||||
|
poll "Tempo datasource reachable (via Grafana proxy)" \
|
||||||
|
'"version"' -u "$AUTH" "$base/api/datasources/proxy/uid/tempo/api/status/buildinfo"
|
||||||
|
echo "Observability backplane OK."
|
||||||
Executable
+27
@@ -0,0 +1,27 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
#
|
||||||
|
# S-16b (#123): assert one connected distributed trace spans the .NET services in Tempo,
|
||||||
|
# against an ALREADY-RUNNING full stack. Runs the driver in a python:3-slim container on the
|
||||||
|
# stack network (services reached by container IP; the runner can't reach published ports —
|
||||||
|
# gitea-actions-gotchas.md §5/§6). Does NOT manage the stack lifecycle.
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
|
here="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
||||||
|
|
||||||
|
ip() { docker inspect -f '{{range .NetworkSettings.Networks}}{{.IPAddress}}{{end}}' "$1"; }
|
||||||
|
|
||||||
|
bff="$(docker ps -q --filter 'name=[-_]bff[-_]' | head -1)"
|
||||||
|
tempo="$(docker ps -q --filter 'name=[-_]tempo[-_]' | head -1)"
|
||||||
|
[ -n "$bff" ] && [ -n "$tempo" ] || { echo "ERROR: bff and/or tempo not running — bring the stack up first" >&2; exit 1; }
|
||||||
|
net="$(docker inspect -f '{{range $k,$_ := .NetworkSettings.Networks}}{{$k}}{{"\n"}}{{end}}' "$bff" | head -1)"
|
||||||
|
bff_ip="$(ip "$bff")"; tempo_ip="$(ip "$tempo")"
|
||||||
|
echo ">> network=$net bff=$bff_ip tempo=$tempo_ip"
|
||||||
|
|
||||||
|
cid="$(docker create --network "$net" \
|
||||||
|
-e "BFF=http://$bff_ip:8080" -e "TEMPO=http://$tempo_ip:3200" \
|
||||||
|
-e "TRACING_TIMEOUT=${TRACING_TIMEOUT:-90}" \
|
||||||
|
python:3-slim python /tracing-check.py)"
|
||||||
|
docker cp "$here/tracing-check.py" "$cid:/tracing-check.py" >/dev/null
|
||||||
|
rc=0; docker start -a "$cid" || rc=$?
|
||||||
|
docker rm -f "$cid" >/dev/null
|
||||||
|
exit $rc
|
||||||
Executable
+81
@@ -0,0 +1,81 @@
|
|||||||
|
#!/usr/bin/env python3
|
||||||
|
"""S-16b (#123): prove distributed tracing works end to end.
|
||||||
|
|
||||||
|
Generate anonymous BFF traffic (GET /openbaar/register, which the BFF serves by
|
||||||
|
calling projection-api — no auth, no OpenZaak egress), then query Tempo and assert
|
||||||
|
that ONE trace contains spans from both `bff` and `projection-api`. That proves the
|
||||||
|
services export OTLP to Tempo AND that the W3C traceparent propagates across the
|
||||||
|
HttpClient hop, stitching the request into a single connected trace.
|
||||||
|
|
||||||
|
Stdlib only (urllib/json) so it runs in a bare python:3-slim container in-network.
|
||||||
|
"""
|
||||||
|
import json
|
||||||
|
import os
|
||||||
|
import sys
|
||||||
|
import time
|
||||||
|
import urllib.error
|
||||||
|
import urllib.parse
|
||||||
|
import urllib.request
|
||||||
|
|
||||||
|
BFF = os.environ["BFF"] # http://<bff-ip>:8080
|
||||||
|
TEMPO = os.environ["TEMPO"] # http://<tempo-ip>:3200
|
||||||
|
TIMEOUT = int(os.environ.get("TRACING_TIMEOUT", "90"))
|
||||||
|
WANT = {"bff", "projection-api"} # the two services that must share one trace
|
||||||
|
|
||||||
|
|
||||||
|
def _get(url):
|
||||||
|
with urllib.request.urlopen(url, timeout=10) as r:
|
||||||
|
return r.read()
|
||||||
|
|
||||||
|
|
||||||
|
def generate_traffic():
|
||||||
|
# A non-2xx still produces spans; only total unreachability of the BFF is fatal.
|
||||||
|
for _ in range(3):
|
||||||
|
try:
|
||||||
|
_get(f"{BFF}/openbaar/register")
|
||||||
|
except urllib.error.HTTPError:
|
||||||
|
pass
|
||||||
|
|
||||||
|
|
||||||
|
def search_trace_ids():
|
||||||
|
q = urllib.parse.quote('{ resource.service.name = "bff" }')
|
||||||
|
try:
|
||||||
|
data = json.loads(_get(f"{TEMPO}/api/search?q={q}&limit=50"))
|
||||||
|
except Exception:
|
||||||
|
return []
|
||||||
|
return [t["traceID"] for t in data.get("traces", [])]
|
||||||
|
|
||||||
|
|
||||||
|
def services_in_trace(trace_id):
|
||||||
|
try:
|
||||||
|
data = json.loads(_get(f"{TEMPO}/api/traces/{trace_id}"))
|
||||||
|
except Exception:
|
||||||
|
return set()
|
||||||
|
names = set()
|
||||||
|
for batch in data.get("batches", []):
|
||||||
|
for attr in batch.get("resource", {}).get("attributes", []):
|
||||||
|
if attr.get("key") == "service.name":
|
||||||
|
names.add(attr.get("value", {}).get("stringValue"))
|
||||||
|
return names
|
||||||
|
|
||||||
|
|
||||||
|
def main():
|
||||||
|
deadline = time.time() + TIMEOUT
|
||||||
|
generate_traffic()
|
||||||
|
seen = set()
|
||||||
|
while time.time() < deadline:
|
||||||
|
for tid in search_trace_ids():
|
||||||
|
names = services_in_trace(tid)
|
||||||
|
seen |= names
|
||||||
|
if WANT.issubset(names):
|
||||||
|
print(f"OK — trace {tid} spans {sorted(names)}")
|
||||||
|
return 0
|
||||||
|
time.sleep(3)
|
||||||
|
generate_traffic()
|
||||||
|
print(f"FAIL — no single trace spanned {sorted(WANT)}; services seen: {sorted(seen)}",
|
||||||
|
file=sys.stderr)
|
||||||
|
return 1
|
||||||
|
|
||||||
|
|
||||||
|
if __name__ == "__main__":
|
||||||
|
sys.exit(main())
|
||||||
@@ -5,6 +5,13 @@
|
|||||||
<ProjectReference Include="..\Acl.Infrastructure\Acl.Infrastructure.csproj" />
|
<ProjectReference Include="..\Acl.Infrastructure\Acl.Infrastructure.csproj" />
|
||||||
</ItemGroup>
|
</ItemGroup>
|
||||||
|
|
||||||
|
<ItemGroup>
|
||||||
|
<PackageReference Include="OpenTelemetry.Exporter.OpenTelemetryProtocol" Version="1.17.0" />
|
||||||
|
<PackageReference Include="OpenTelemetry.Extensions.Hosting" Version="1.17.0" />
|
||||||
|
<PackageReference Include="OpenTelemetry.Instrumentation.AspNetCore" Version="1.17.0" />
|
||||||
|
<PackageReference Include="OpenTelemetry.Instrumentation.Http" Version="1.17.0" />
|
||||||
|
</ItemGroup>
|
||||||
|
|
||||||
<PropertyGroup>
|
<PropertyGroup>
|
||||||
<TargetFramework>net10.0</TargetFramework>
|
<TargetFramework>net10.0</TargetFramework>
|
||||||
<Nullable>enable</Nullable>
|
<Nullable>enable</Nullable>
|
||||||
|
|||||||
@@ -1,8 +1,21 @@
|
|||||||
using Acl.Application;
|
using Acl.Application;
|
||||||
using Acl.Infrastructure;
|
using Acl.Infrastructure;
|
||||||
|
using OpenTelemetry.Resources;
|
||||||
|
using OpenTelemetry.Trace;
|
||||||
|
|
||||||
var builder = WebApplication.CreateBuilder(args);
|
var builder = WebApplication.CreateBuilder(args);
|
||||||
|
|
||||||
|
// OpenTelemetry tracing (S-16b, ADR-0023): auto-instrument incoming ASP.NET Core requests and
|
||||||
|
// outgoing HttpClient calls (the ACL → OpenZaak hop), exported over OTLP to Tempo. Service name +
|
||||||
|
// OTLP endpoint come from OTEL_* env (compose); the exporter no-ops when Tempo is unreachable.
|
||||||
|
builder.Services.AddOpenTelemetry()
|
||||||
|
.ConfigureResource(r => r.AddService(
|
||||||
|
builder.Configuration["OTEL_SERVICE_NAME"] ?? builder.Environment.ApplicationName))
|
||||||
|
.WithTracing(tracing => tracing
|
||||||
|
.AddAspNetCoreInstrumentation(o => o.Filter = ctx => ctx.Request.Path != "/health")
|
||||||
|
.AddHttpClientInstrumentation()
|
||||||
|
.AddOtlpExporter());
|
||||||
|
|
||||||
builder.Services.AddSingleton<IClock, SystemClock>();
|
builder.Services.AddSingleton<IClock, SystemClock>();
|
||||||
builder.Services.AddSingleton(sp => sp.GetRequiredService<IConfiguration>()
|
builder.Services.AddSingleton(sp => sp.GetRequiredService<IConfiguration>()
|
||||||
.GetSection("Acl:Defaults").Get<AclDefaults>()
|
.GetSection("Acl:Defaults").Get<AclDefaults>()
|
||||||
|
|||||||
@@ -10,6 +10,10 @@
|
|||||||
<!-- OIDC/JWT validation of Keycloak-issued tokens (ADR-0010) and OpenAPI generation. -->
|
<!-- OIDC/JWT validation of Keycloak-issued tokens (ADR-0010) and OpenAPI generation. -->
|
||||||
<PackageReference Include="Microsoft.AspNetCore.Authentication.JwtBearer" Version="10.0.8" />
|
<PackageReference Include="Microsoft.AspNetCore.Authentication.JwtBearer" Version="10.0.8" />
|
||||||
<PackageReference Include="Microsoft.AspNetCore.OpenApi" Version="10.0.8" />
|
<PackageReference Include="Microsoft.AspNetCore.OpenApi" Version="10.0.8" />
|
||||||
|
<PackageReference Include="OpenTelemetry.Exporter.OpenTelemetryProtocol" Version="1.17.0" />
|
||||||
|
<PackageReference Include="OpenTelemetry.Extensions.Hosting" Version="1.17.0" />
|
||||||
|
<PackageReference Include="OpenTelemetry.Instrumentation.AspNetCore" Version="1.17.0" />
|
||||||
|
<PackageReference Include="OpenTelemetry.Instrumentation.Http" Version="1.17.0" />
|
||||||
</ItemGroup>
|
</ItemGroup>
|
||||||
|
|
||||||
</Project>
|
</Project>
|
||||||
|
|||||||
@@ -3,9 +3,23 @@ using System.Text.Json;
|
|||||||
using System.Text.Json.Serialization;
|
using System.Text.Json.Serialization;
|
||||||
using Bff.Api;
|
using Bff.Api;
|
||||||
using Microsoft.AspNetCore.Authentication.JwtBearer;
|
using Microsoft.AspNetCore.Authentication.JwtBearer;
|
||||||
|
using OpenTelemetry.Resources;
|
||||||
|
using OpenTelemetry.Trace;
|
||||||
|
|
||||||
var builder = WebApplication.CreateBuilder(args);
|
var builder = WebApplication.CreateBuilder(args);
|
||||||
|
|
||||||
|
// OpenTelemetry tracing (S-16b, ADR-0023): auto-instrument incoming ASP.NET Core requests and
|
||||||
|
// outgoing HttpClient calls (BFF → Domain, BFF → projection-api), exported over OTLP to Tempo, so a
|
||||||
|
// portal request is one connected trace across the services. Service name + OTLP endpoint come from
|
||||||
|
// OTEL_* env (compose); the exporter no-ops when Tempo is unreachable. /health is filtered out.
|
||||||
|
builder.Services.AddOpenTelemetry()
|
||||||
|
.ConfigureResource(r => r.AddService(
|
||||||
|
builder.Configuration["OTEL_SERVICE_NAME"] ?? builder.Environment.ApplicationName))
|
||||||
|
.WithTracing(tracing => tracing
|
||||||
|
.AddAspNetCoreInstrumentation(o => o.Filter = ctx => ctx.Request.Path != "/health")
|
||||||
|
.AddHttpClientInstrumentation()
|
||||||
|
.AddOtlpExporter());
|
||||||
|
|
||||||
var keycloakAuthority = builder.Configuration["Keycloak:Authority"]
|
var keycloakAuthority = builder.Configuration["Keycloak:Authority"]
|
||||||
?? throw new InvalidOperationException("Missing configuration 'Keycloak:Authority'");
|
?? throw new InvalidOperationException("Missing configuration 'Keycloak:Authority'");
|
||||||
// Behandelaars authenticate against a *different* Keycloak realm (medewerker) than citizens (digid),
|
// Behandelaars authenticate against a *different* Keycloak realm (medewerker) than citizens (digid),
|
||||||
|
|||||||
@@ -5,6 +5,14 @@
|
|||||||
<ProjectReference Include="..\Big.Infrastructure\Big.Infrastructure.csproj" />
|
<ProjectReference Include="..\Big.Infrastructure\Big.Infrastructure.csproj" />
|
||||||
</ItemGroup>
|
</ItemGroup>
|
||||||
|
|
||||||
|
<ItemGroup>
|
||||||
|
<PackageReference Include="OpenTelemetry.Exporter.OpenTelemetryProtocol" Version="1.17.0" />
|
||||||
|
<PackageReference Include="OpenTelemetry.Extensions.Hosting" Version="1.17.0" />
|
||||||
|
<PackageReference Include="OpenTelemetry.Instrumentation.AspNetCore" Version="1.17.0" />
|
||||||
|
<PackageReference Include="OpenTelemetry.Instrumentation.Http" Version="1.17.0" />
|
||||||
|
<PackageReference Include="Quartz.Extensions.Hosting" Version="3.18.2" />
|
||||||
|
</ItemGroup>
|
||||||
|
|
||||||
<PropertyGroup>
|
<PropertyGroup>
|
||||||
<TargetFramework>net10.0</TargetFramework>
|
<TargetFramework>net10.0</TargetFramework>
|
||||||
<Nullable>enable</Nullable>
|
<Nullable>enable</Nullable>
|
||||||
|
|||||||
@@ -1,9 +1,25 @@
|
|||||||
using Big.Application;
|
using Big.Application;
|
||||||
using Big.Domain;
|
using Big.Domain;
|
||||||
using Big.Infrastructure;
|
using Big.Infrastructure;
|
||||||
|
using OpenTelemetry.Resources;
|
||||||
|
using OpenTelemetry.Trace;
|
||||||
|
using Quartz;
|
||||||
|
|
||||||
var builder = WebApplication.CreateBuilder(args);
|
var builder = WebApplication.CreateBuilder(args);
|
||||||
|
|
||||||
|
// OpenTelemetry tracing (S-16b, ADR-0023): auto-instrument incoming ASP.NET Core requests and
|
||||||
|
// outgoing HttpClient calls, exported over OTLP to Tempo, so a request is one connected trace across
|
||||||
|
// the services. Service name + OTLP endpoint come from OTEL_* env (compose); the exporter no-ops
|
||||||
|
// harmlessly when Tempo is unreachable (e.g. a service run standalone). /health is filtered out so
|
||||||
|
// liveness polls don't flood the traces.
|
||||||
|
builder.Services.AddOpenTelemetry()
|
||||||
|
.ConfigureResource(r => r.AddService(
|
||||||
|
builder.Configuration["OTEL_SERVICE_NAME"] ?? builder.Environment.ApplicationName))
|
||||||
|
.WithTracing(tracing => tracing
|
||||||
|
.AddAspNetCoreInstrumentation(o => o.Filter = ctx => ctx.Request.Path != "/health")
|
||||||
|
.AddHttpClientInstrumentation()
|
||||||
|
.AddOtlpExporter());
|
||||||
|
|
||||||
// Options bound from configuration (compose sets Flowable__* and Acl__* env vars).
|
// Options bound from configuration (compose sets Flowable__* and Acl__* env vars).
|
||||||
builder.Services.AddSingleton(sp => sp.GetRequiredService<IConfiguration>()
|
builder.Services.AddSingleton(sp => sp.GetRequiredService<IConfiguration>()
|
||||||
.GetSection("Flowable").Get<FlowableOptions>()
|
.GetSection("Flowable").Get<FlowableOptions>()
|
||||||
@@ -15,6 +31,10 @@ builder.Services.AddSingleton(sp => sp.GetRequiredService<IConfiguration>()
|
|||||||
// The in-memory registration store is shared between the submit endpoint and the worker (ADR-0009).
|
// The in-memory registration store is shared between the submit endpoint and the worker (ADR-0009).
|
||||||
builder.Services.AddSingleton<IRegistrationStore, InMemoryRegistrationStore>();
|
builder.Services.AddSingleton<IRegistrationStore, InMemoryRegistrationStore>();
|
||||||
|
|
||||||
|
// The system clock, injected wherever a use case needs "now" (e.g. stamping the inscription moment
|
||||||
|
// on approval, S-17). Injected as TimeProvider so tests can substitute a fixed clock.
|
||||||
|
builder.Services.AddSingleton(TimeProvider.System);
|
||||||
|
|
||||||
// The Workflow Client is one type behind two ports (start side + worker side); both resolve to the
|
// The Workflow Client is one type behind two ports (start side + worker side); both resolve to the
|
||||||
// same HttpClient-backed implementation — the only code that talks to Flowable (§8.2).
|
// same HttpClient-backed implementation — the only code that talks to Flowable (§8.2).
|
||||||
builder.Services.AddHttpClient<FlowableWorkflowClient>();
|
builder.Services.AddHttpClient<FlowableWorkflowClient>();
|
||||||
@@ -36,6 +56,7 @@ builder.Services.AddScoped<OpenZaakJobProcessor>();
|
|||||||
builder.Services.AddScoped<BeoordelingEscalatieProcessor>();
|
builder.Services.AddScoped<BeoordelingEscalatieProcessor>();
|
||||||
builder.Services.AddScoped<ExpireRegistrationWorker>();
|
builder.Services.AddScoped<ExpireRegistrationWorker>();
|
||||||
builder.Services.AddScoped<RegistratieVerlopenProcessor>();
|
builder.Services.AddScoped<RegistratieVerlopenProcessor>();
|
||||||
|
builder.Services.AddScoped<HerregistratieReminderSweep>();
|
||||||
|
|
||||||
// The hosted external-task job worker polls Flowable and drives OpenZaakAanmaken to completion.
|
// The hosted external-task job worker polls Flowable and drives OpenZaakAanmaken to completion.
|
||||||
builder.Services.AddHostedService<OpenZaakJobPump>();
|
builder.Services.AddHostedService<OpenZaakJobPump>();
|
||||||
@@ -46,6 +67,19 @@ builder.Services.AddHostedService<BeoordelingEscalatiePump>();
|
|||||||
// parks and expires each lapsed registration to VERLOPEN (S-10a, ADR-0017).
|
// parks and expires each lapsed registration to VERLOPEN (S-10a, ADR-0017).
|
||||||
builder.Services.AddHostedService<RegistratieVerlopenPump>();
|
builder.Services.AddHostedService<RegistratieVerlopenPump>();
|
||||||
|
|
||||||
|
// The herregistratie reminder sweep runs on a daily cron via Quartz.NET (S-17, ADR-0022) — a
|
||||||
|
// time-triggered fleet sweep, deliberately a different mechanism from the queue-draining pumps above.
|
||||||
|
// The cron is overridable with Quartz__Cron; it defaults to 03:00 daily.
|
||||||
|
builder.Services.AddQuartz(q =>
|
||||||
|
{
|
||||||
|
var jobKey = new JobKey("herregistratie-reminder");
|
||||||
|
q.AddJob<HerregistratieReminderJob>(jobKey);
|
||||||
|
q.AddTrigger(t => t
|
||||||
|
.ForJob(jobKey)
|
||||||
|
.WithCronSchedule(builder.Configuration["Quartz:Cron"] ?? "0 0 3 * * ?"));
|
||||||
|
});
|
||||||
|
builder.Services.AddQuartzHostedService(o => o.WaitForJobsToComplete = true);
|
||||||
|
|
||||||
var app = builder.Build();
|
var app = builder.Build();
|
||||||
|
|
||||||
app.MapGet("/health", () => "Healthy");
|
app.MapGet("/health", () => "Healthy");
|
||||||
@@ -165,7 +199,8 @@ app.MapGet("/registrations/{id}", async (string id, IRegistrationStore store, Ca
|
|||||||
return registration is null
|
return registration is null
|
||||||
? Results.NotFound()
|
? Results.NotFound()
|
||||||
: Results.Ok(new RegistrationResponse(
|
: Results.Ok(new RegistrationResponse(
|
||||||
registration.Id.ToString(), registration.Status.ToString(), registration.ZaakUrl?.ToString()));
|
registration.Id.ToString(), registration.Status.ToString(), registration.ZaakUrl?.ToString(),
|
||||||
|
registration.HerregistratieVoor?.ToString("O"), registration.HerregistratieReminderVerstuurd));
|
||||||
});
|
});
|
||||||
|
|
||||||
await app.RunAsync();
|
await app.RunAsync();
|
||||||
@@ -178,6 +213,11 @@ public sealed record WithdrawRequest(string Bsn);
|
|||||||
|
|
||||||
public sealed record ProvideDocumentsRequest(string Bsn, string ContentBase64, string? FileName = null, string? ContentType = null);
|
public sealed record ProvideDocumentsRequest(string Bsn, string ContentBase64, string? FileName = null, string? ContentType = null);
|
||||||
|
|
||||||
public sealed record RegistrationResponse(string RegistrationId, string Status, string? ZaakUrl);
|
public sealed record RegistrationResponse(
|
||||||
|
string RegistrationId,
|
||||||
|
string Status,
|
||||||
|
string? ZaakUrl,
|
||||||
|
string? HerregistratieVoor = null,
|
||||||
|
bool HerregistratieReminderVerstuurd = false);
|
||||||
|
|
||||||
public partial class Program;
|
public partial class Program;
|
||||||
|
|||||||
@@ -12,7 +12,7 @@ public sealed record ApproveRegistrationCommand(RegistrationId RegistrationId);
|
|||||||
/// zaak status is the projection's source of truth (it flows back over NRC); the aggregate transition
|
/// zaak status is the projection's source of truth (it flows back over NRC); the aggregate transition
|
||||||
/// keeps the domain's own view consistent.
|
/// keeps the domain's own view consistent.
|
||||||
/// </summary>
|
/// </summary>
|
||||||
public sealed class ApproveRegistration(IRegistrationStore store, IAclClient acl)
|
public sealed class ApproveRegistration(IRegistrationStore store, IAclClient acl, TimeProvider clock)
|
||||||
{
|
{
|
||||||
public async Task HandleAsync(ApproveRegistrationCommand command, CancellationToken ct = default)
|
public async Task HandleAsync(ApproveRegistrationCommand command, CancellationToken ct = default)
|
||||||
{
|
{
|
||||||
@@ -30,7 +30,7 @@ public sealed class ApproveRegistration(IRegistrationStore store, IAclClient acl
|
|||||||
$"Registration {command.RegistrationId} has no zaak yet; it cannot be approved.");
|
$"Registration {command.RegistrationId} has no zaak yet; it cannot be approved.");
|
||||||
|
|
||||||
await acl.ApproveZaakAsync(registration.ZaakUrl, ct);
|
await acl.ApproveZaakAsync(registration.ZaakUrl, ct);
|
||||||
registration.Approve();
|
registration.Approve(clock.GetUtcNow());
|
||||||
await store.SaveAsync(registration, ct);
|
await store.SaveAsync(registration, ct);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -25,7 +25,7 @@ public sealed record BeoordeelRegistratieCommand(RegistrationId RegistrationId,
|
|||||||
/// decisions are idempotent — a repeated or redelivered decision that matches the current terminal
|
/// decisions are idempotent — a repeated or redelivered decision that matches the current terminal
|
||||||
/// state is a no-op, so the ACL is not called and the task not completed twice.
|
/// state is a no-op, so the ACL is not called and the task not completed twice.
|
||||||
/// </summary>
|
/// </summary>
|
||||||
public sealed class BeoordeelRegistratie(IRegistrationStore store, IAclClient acl, IUserTaskClient tasks)
|
public sealed class BeoordeelRegistratie(IRegistrationStore store, IAclClient acl, IUserTaskClient tasks, TimeProvider clock)
|
||||||
{
|
{
|
||||||
public async Task HandleAsync(BeoordeelRegistratieCommand command, CancellationToken ct = default)
|
public async Task HandleAsync(BeoordeelRegistratieCommand command, CancellationToken ct = default)
|
||||||
{
|
{
|
||||||
@@ -44,7 +44,7 @@ public sealed class BeoordeelRegistratie(IRegistrationStore store, IAclClient ac
|
|||||||
throw new InvalidOperationException(
|
throw new InvalidOperationException(
|
||||||
$"Registration {command.RegistrationId} has no zaak yet; it cannot be approved.");
|
$"Registration {command.RegistrationId} has no zaak yet; it cannot be approved.");
|
||||||
await acl.ApproveZaakAsync(registration.ZaakUrl, ct);
|
await acl.ApproveZaakAsync(registration.ZaakUrl, ct);
|
||||||
registration.Approve();
|
registration.Approve(clock.GetUtcNow());
|
||||||
break;
|
break;
|
||||||
|
|
||||||
case BeoordelingsBesluit.Afwijzen:
|
case BeoordelingsBesluit.Afwijzen:
|
||||||
|
|||||||
@@ -0,0 +1,30 @@
|
|||||||
|
using Big.Domain;
|
||||||
|
|
||||||
|
namespace Big.Application;
|
||||||
|
|
||||||
|
/// <summary>
|
||||||
|
/// The herregistratie reminder sweep (S-17): find the inscriptions whose herregistratie deadline is
|
||||||
|
/// within the reminder window and have not yet been reminded, mark each reminded, and persist it. Pure
|
||||||
|
/// application logic over ports — it knows nothing of Quartz; the scheduled job that fires it on a cron
|
||||||
|
/// lives in Infrastructure (mirroring how the pumps' processors are pure and the pump is the shell).
|
||||||
|
/// Idempotent: <see cref="Registration.MarkHerregistratieReminderVerstuurd"/> drops an inscription from
|
||||||
|
/// the next sweep's candidate set, so a re-fire reminds no one twice. Returns the reminded ids so the
|
||||||
|
/// caller can observe the sweep's effect — the reminder itself is the flag persisted on the aggregate.
|
||||||
|
/// </summary>
|
||||||
|
public sealed class HerregistratieReminderSweep(IRegistrationStore store, TimeProvider clock)
|
||||||
|
{
|
||||||
|
public async Task<IReadOnlyList<RegistrationId>> SweepAsync(CancellationToken ct = default)
|
||||||
|
{
|
||||||
|
var due = await store.FindDueForHerregistratieReminderAsync(clock.GetUtcNow(), ct);
|
||||||
|
|
||||||
|
var reminded = new List<RegistrationId>(due.Count);
|
||||||
|
foreach (var registration in due)
|
||||||
|
{
|
||||||
|
registration.MarkHerregistratieReminderVerstuurd();
|
||||||
|
await store.SaveAsync(registration, ct);
|
||||||
|
reminded.Add(registration.Id);
|
||||||
|
}
|
||||||
|
|
||||||
|
return reminded;
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -107,6 +107,13 @@ public interface IRegistrationStore
|
|||||||
/// registration, or <c>null</c> if they have none in flight. Lets the self-service portal resume
|
/// registration, or <c>null</c> if they have none in flight. Lets the self-service portal resume
|
||||||
/// an existing registration after a refresh (S-26); terminal registrations are not resumed.</summary>
|
/// an existing registration after a refresh (S-26); terminal registrations are not resumed.</summary>
|
||||||
Task<Registration?> FindOpenByBsnAsync(string bsn, CancellationToken ct = default);
|
Task<Registration?> FindOpenByBsnAsync(string bsn, CancellationToken ct = default);
|
||||||
|
|
||||||
|
/// <summary>The inscriptions whose herregistratie reminder is due as of <paramref name="asOf"/> and
|
||||||
|
/// not yet sent — the herregistratie reminder sweep's candidate set (S-17). The predicate is the
|
||||||
|
/// aggregate's own <see cref="Registration.HerregistratieReminderDue"/> rule, so the store never
|
||||||
|
/// duplicates the herregistratie policy.</summary>
|
||||||
|
Task<IReadOnlyList<Registration>> FindDueForHerregistratieReminderAsync(
|
||||||
|
DateTimeOffset asOf, CancellationToken ct = default);
|
||||||
}
|
}
|
||||||
|
|
||||||
/// <summary>
|
/// <summary>
|
||||||
|
|||||||
@@ -92,11 +92,12 @@ public sealed class Registration
|
|||||||
|
|
||||||
/// <summary>
|
/// <summary>
|
||||||
/// Approve the registration — the behandelaar's decision to enter it in the register. Advances a
|
/// Approve the registration — the behandelaar's decision to enter it in the register. Advances a
|
||||||
/// submitted or in-behandeling registration to <see cref="RegistrationStatus.Ingeschreven"/>.
|
/// submitted or in-behandeling registration to <see cref="RegistrationStatus.Ingeschreven"/> and
|
||||||
/// Requires an opened zaak (the approval sets that zaak's status via the ACL); a registration that
|
/// records <paramref name="ingeschrevenOp"/> as the moment of inscription, which starts the
|
||||||
/// has already been decided cannot be approved again.
|
/// herregistratie clock (S-17). Requires an opened zaak (the approval sets that zaak's status via
|
||||||
|
/// the ACL); a registration that has already been decided cannot be approved again.
|
||||||
/// </summary>
|
/// </summary>
|
||||||
public void Approve()
|
public void Approve(DateTimeOffset ingeschrevenOp)
|
||||||
{
|
{
|
||||||
if (ZaakUrl is null)
|
if (ZaakUrl is null)
|
||||||
throw new InvalidOperationException(
|
throw new InvalidOperationException(
|
||||||
@@ -104,6 +105,54 @@ public sealed class Registration
|
|||||||
|
|
||||||
RequireOpenForDecision(nameof(Approve));
|
RequireOpenForDecision(nameof(Approve));
|
||||||
Status = RegistrationStatus.Ingeschreven;
|
Status = RegistrationStatus.Ingeschreven;
|
||||||
|
IngeschrevenOp = ingeschrevenOp;
|
||||||
|
}
|
||||||
|
|
||||||
|
// --- Herregistratie (S-17) — RED stubs, implemented in the green commit ---------------------
|
||||||
|
|
||||||
|
/// <summary>How long a BIG inscription stays valid before herregistratie is required.</summary>
|
||||||
|
// ponytail: fixed 5-year term — a calibration knob, not a config surface. If a demo needs it
|
||||||
|
// per-catalogus, promote it to policy passed in from the beheer config (S-15).
|
||||||
|
public static readonly TimeSpan HerregistratieGeldigheid = TimeSpan.FromDays(365 * 5);
|
||||||
|
|
||||||
|
/// <summary>How long before the deadline the herregistratie reminder is sent (S-17: 90 days).</summary>
|
||||||
|
// ponytail: fixed 90-day lead time — calibration knob; same promotion path as HerregistratieGeldigheid.
|
||||||
|
public static readonly TimeSpan Herinneringstermijn = TimeSpan.FromDays(90);
|
||||||
|
|
||||||
|
/// <summary>When the registration was entered in the register, once approved; the start of its
|
||||||
|
/// herregistratie clock. Null until it is <see cref="RegistrationStatus.Ingeschreven"/>.</summary>
|
||||||
|
public DateTimeOffset? IngeschrevenOp { get; private set; }
|
||||||
|
|
||||||
|
/// <summary>The date by which herregistratie must happen: inscription + validity. Null until
|
||||||
|
/// inscribed.</summary>
|
||||||
|
public DateTimeOffset? HerregistratieVoor =>
|
||||||
|
IngeschrevenOp is DateTimeOffset ingeschrevenOp ? ingeschrevenOp + HerregistratieGeldigheid : null;
|
||||||
|
|
||||||
|
/// <summary>Whether the herregistratie reminder has been sent for this inscription (S-17).</summary>
|
||||||
|
public bool HerregistratieReminderVerstuurd { get; private set; }
|
||||||
|
|
||||||
|
/// <summary>Whether, as of <paramref name="asOf"/>, this registration is due a herregistratie
|
||||||
|
/// reminder: it is inscribed, the reminder window before its deadline has opened, and it has not
|
||||||
|
/// already been reminded. Once inside the window it stays due until reminded (an overdue inscription
|
||||||
|
/// is still due). This is the single rule the store query and the sweep both build on.</summary>
|
||||||
|
public bool HerregistratieReminderDue(DateTimeOffset asOf) =>
|
||||||
|
Status == RegistrationStatus.Ingeschreven
|
||||||
|
&& !HerregistratieReminderVerstuurd
|
||||||
|
&& IngeschrevenOp is DateTimeOffset ingeschrevenOp
|
||||||
|
&& asOf >= ingeschrevenOp + HerregistratieGeldigheid - Herinneringstermijn;
|
||||||
|
|
||||||
|
/// <summary>Record that the herregistratie reminder has been sent. Idempotent — a re-sweep is a
|
||||||
|
/// no-op (§8.6); only an inscribed registration can be reminded.</summary>
|
||||||
|
public void MarkHerregistratieReminderVerstuurd()
|
||||||
|
{
|
||||||
|
if (HerregistratieReminderVerstuurd)
|
||||||
|
return;
|
||||||
|
|
||||||
|
if (Status != RegistrationStatus.Ingeschreven)
|
||||||
|
throw new InvalidOperationException(
|
||||||
|
$"Registration {Id} is {Status}; only an INGESCHREVEN registration can be sent a herregistratie reminder.");
|
||||||
|
|
||||||
|
HerregistratieReminderVerstuurd = true;
|
||||||
}
|
}
|
||||||
|
|
||||||
/// <summary>
|
/// <summary>
|
||||||
|
|||||||
@@ -19,6 +19,7 @@
|
|||||||
<PackageReference Include="Microsoft.Extensions.Hosting.Abstractions" Version="10.0.0" />
|
<PackageReference Include="Microsoft.Extensions.Hosting.Abstractions" Version="10.0.0" />
|
||||||
<PackageReference Include="Microsoft.Extensions.Logging.Abstractions" Version="10.0.0" />
|
<PackageReference Include="Microsoft.Extensions.Logging.Abstractions" Version="10.0.0" />
|
||||||
<PackageReference Include="Microsoft.Extensions.DependencyInjection.Abstractions" Version="10.0.0" />
|
<PackageReference Include="Microsoft.Extensions.DependencyInjection.Abstractions" Version="10.0.0" />
|
||||||
|
<PackageReference Include="Quartz" Version="3.18.2" />
|
||||||
</ItemGroup>
|
</ItemGroup>
|
||||||
|
|
||||||
</Project>
|
</Project>
|
||||||
|
|||||||
@@ -0,0 +1,26 @@
|
|||||||
|
using Big.Application;
|
||||||
|
using Microsoft.Extensions.Logging;
|
||||||
|
using Quartz;
|
||||||
|
|
||||||
|
namespace Big.Infrastructure;
|
||||||
|
|
||||||
|
/// <summary>
|
||||||
|
/// The Quartz job that fires the herregistratie reminder sweep on a cron schedule (S-17, ADR-0022).
|
||||||
|
/// A deliberately thin shell — it resolves the pure <see cref="HerregistratieReminderSweep"/> (Quartz's
|
||||||
|
/// MS-DI job factory gives each fire its own scope) and logs how many reminders went out; all the
|
||||||
|
/// sweep logic is unit-tested in the application layer. Quartz drives this — rather than a
|
||||||
|
/// BackgroundService poll loop like the pumps — because it is a time-triggered fleet sweep, not a
|
||||||
|
/// queue to drain (the distinction recorded in ADR-0022). <see cref="DisallowConcurrentExecutionAttribute"/>
|
||||||
|
/// stops a slow sweep overlapping the next fire against the shared store.
|
||||||
|
/// </summary>
|
||||||
|
[DisallowConcurrentExecution]
|
||||||
|
public sealed class HerregistratieReminderJob(
|
||||||
|
HerregistratieReminderSweep sweep, ILogger<HerregistratieReminderJob> logger) : IJob
|
||||||
|
{
|
||||||
|
public async Task Execute(IJobExecutionContext context)
|
||||||
|
{
|
||||||
|
var reminded = await sweep.SweepAsync(context.CancellationToken);
|
||||||
|
logger.LogInformation(
|
||||||
|
"Herregistratie-sweep voltooid: {Count} herinnering(en) verstuurd.", reminded.Count);
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -26,4 +26,9 @@ public sealed class InMemoryRegistrationStore : IRegistrationStore
|
|||||||
public Task<Registration?> FindOpenByBsnAsync(string bsn, CancellationToken ct = default)
|
public Task<Registration?> FindOpenByBsnAsync(string bsn, CancellationToken ct = default)
|
||||||
=> Task.FromResult(_byId.Values.FirstOrDefault(r =>
|
=> Task.FromResult(_byId.Values.FirstOrDefault(r =>
|
||||||
r.Bsn == bsn && r.Status is RegistrationStatus.Ingediend or RegistrationStatus.InBehandeling));
|
r.Bsn == bsn && r.Status is RegistrationStatus.Ingediend or RegistrationStatus.InBehandeling));
|
||||||
|
|
||||||
|
public Task<IReadOnlyList<Registration>> FindDueForHerregistratieReminderAsync(
|
||||||
|
DateTimeOffset asOf, CancellationToken ct = default)
|
||||||
|
=> Task.FromResult<IReadOnlyList<Registration>>(
|
||||||
|
_byId.Values.Where(r => r.HerregistratieReminderDue(asOf)).ToList());
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -19,7 +19,7 @@ public class ApproveRegistrationTests
|
|||||||
var acl = new FakeAclClient();
|
var acl = new FakeAclClient();
|
||||||
var registration = WithZaak();
|
var registration = WithZaak();
|
||||||
store.Seed(registration);
|
store.Seed(registration);
|
||||||
var handler = new ApproveRegistration(store, acl);
|
var handler = new ApproveRegistration(store, acl, TimeProvider.System);
|
||||||
|
|
||||||
await handler.HandleAsync(new ApproveRegistrationCommand(registration.Id));
|
await handler.HandleAsync(new ApproveRegistrationCommand(registration.Id));
|
||||||
|
|
||||||
@@ -36,7 +36,7 @@ public class ApproveRegistrationTests
|
|||||||
{
|
{
|
||||||
var store = new FakeRegistrationStore();
|
var store = new FakeRegistrationStore();
|
||||||
var acl = new FakeAclClient();
|
var acl = new FakeAclClient();
|
||||||
var handler = new ApproveRegistration(store, acl);
|
var handler = new ApproveRegistration(store, acl, TimeProvider.System);
|
||||||
|
|
||||||
await Assert.ThrowsAsync<ArgumentNullException>(() => handler.HandleAsync(null!));
|
await Assert.ThrowsAsync<ArgumentNullException>(() => handler.HandleAsync(null!));
|
||||||
Assert.Equal(0, acl.ApproveCallCount);
|
Assert.Equal(0, acl.ApproveCallCount);
|
||||||
@@ -47,7 +47,7 @@ public class ApproveRegistrationTests
|
|||||||
{
|
{
|
||||||
var store = new FakeRegistrationStore();
|
var store = new FakeRegistrationStore();
|
||||||
var acl = new FakeAclClient();
|
var acl = new FakeAclClient();
|
||||||
var handler = new ApproveRegistration(store, acl);
|
var handler = new ApproveRegistration(store, acl, TimeProvider.System);
|
||||||
|
|
||||||
var ex = await Assert.ThrowsAsync<InvalidOperationException>(
|
var ex = await Assert.ThrowsAsync<InvalidOperationException>(
|
||||||
() => handler.HandleAsync(new ApproveRegistrationCommand(RegistrationId.New())));
|
() => handler.HandleAsync(new ApproveRegistrationCommand(RegistrationId.New())));
|
||||||
@@ -62,7 +62,7 @@ public class ApproveRegistrationTests
|
|||||||
var acl = new FakeAclClient();
|
var acl = new FakeAclClient();
|
||||||
var registration = Registration.Submit("123456782"); // no zaak yet
|
var registration = Registration.Submit("123456782"); // no zaak yet
|
||||||
store.Seed(registration);
|
store.Seed(registration);
|
||||||
var handler = new ApproveRegistration(store, acl);
|
var handler = new ApproveRegistration(store, acl, TimeProvider.System);
|
||||||
|
|
||||||
var ex = await Assert.ThrowsAsync<InvalidOperationException>(
|
var ex = await Assert.ThrowsAsync<InvalidOperationException>(
|
||||||
() => handler.HandleAsync(new ApproveRegistrationCommand(registration.Id)));
|
() => handler.HandleAsync(new ApproveRegistrationCommand(registration.Id)));
|
||||||
@@ -77,7 +77,7 @@ public class ApproveRegistrationTests
|
|||||||
var acl = new FakeAclClient();
|
var acl = new FakeAclClient();
|
||||||
var registration = WithZaak();
|
var registration = WithZaak();
|
||||||
store.Seed(registration);
|
store.Seed(registration);
|
||||||
var handler = new ApproveRegistration(store, acl);
|
var handler = new ApproveRegistration(store, acl, TimeProvider.System);
|
||||||
|
|
||||||
await handler.HandleAsync(new ApproveRegistrationCommand(registration.Id));
|
await handler.HandleAsync(new ApproveRegistrationCommand(registration.Id));
|
||||||
await handler.HandleAsync(new ApproveRegistrationCommand(registration.Id));
|
await handler.HandleAsync(new ApproveRegistrationCommand(registration.Id));
|
||||||
|
|||||||
@@ -29,7 +29,7 @@ public class BeoordeelRegistratieTests
|
|||||||
var registration = WithZaak();
|
var registration = WithZaak();
|
||||||
store.Seed(registration);
|
store.Seed(registration);
|
||||||
var tasks = TaskFor(registration);
|
var tasks = TaskFor(registration);
|
||||||
var handler = new BeoordeelRegistratie(store, acl, tasks);
|
var handler = new BeoordeelRegistratie(store, acl, tasks, TimeProvider.System);
|
||||||
|
|
||||||
await handler.HandleAsync(new BeoordeelRegistratieCommand(registration.Id, BeoordelingsBesluit.Goedkeuren));
|
await handler.HandleAsync(new BeoordeelRegistratieCommand(registration.Id, BeoordelingsBesluit.Goedkeuren));
|
||||||
|
|
||||||
@@ -50,7 +50,7 @@ public class BeoordeelRegistratieTests
|
|||||||
var registration = WithZaak();
|
var registration = WithZaak();
|
||||||
store.Seed(registration);
|
store.Seed(registration);
|
||||||
var tasks = TaskFor(registration);
|
var tasks = TaskFor(registration);
|
||||||
var handler = new BeoordeelRegistratie(store, acl, tasks);
|
var handler = new BeoordeelRegistratie(store, acl, tasks, TimeProvider.System);
|
||||||
|
|
||||||
await handler.HandleAsync(new BeoordeelRegistratieCommand(registration.Id, BeoordelingsBesluit.Afwijzen));
|
await handler.HandleAsync(new BeoordeelRegistratieCommand(registration.Id, BeoordelingsBesluit.Afwijzen));
|
||||||
|
|
||||||
@@ -69,7 +69,7 @@ public class BeoordeelRegistratieTests
|
|||||||
var registration = WithZaak();
|
var registration = WithZaak();
|
||||||
registration.TakeIntoBehandeling();
|
registration.TakeIntoBehandeling();
|
||||||
store.Seed(registration);
|
store.Seed(registration);
|
||||||
var handler = new BeoordeelRegistratie(store, acl, TaskFor(registration));
|
var handler = new BeoordeelRegistratie(store, acl, TaskFor(registration), TimeProvider.System);
|
||||||
|
|
||||||
await handler.HandleAsync(new BeoordeelRegistratieCommand(registration.Id, BeoordelingsBesluit.Goedkeuren));
|
await handler.HandleAsync(new BeoordeelRegistratieCommand(registration.Id, BeoordelingsBesluit.Goedkeuren));
|
||||||
|
|
||||||
@@ -81,7 +81,7 @@ public class BeoordeelRegistratieTests
|
|||||||
{
|
{
|
||||||
var store = new FakeRegistrationStore();
|
var store = new FakeRegistrationStore();
|
||||||
var acl = new FakeAclClient();
|
var acl = new FakeAclClient();
|
||||||
var handler = new BeoordeelRegistratie(store, acl, new FakeUserTaskClient([]));
|
var handler = new BeoordeelRegistratie(store, acl, new FakeUserTaskClient([]), TimeProvider.System);
|
||||||
|
|
||||||
await Assert.ThrowsAsync<ArgumentNullException>(() => handler.HandleAsync(null!));
|
await Assert.ThrowsAsync<ArgumentNullException>(() => handler.HandleAsync(null!));
|
||||||
Assert.Equal(0, acl.ApproveCallCount);
|
Assert.Equal(0, acl.ApproveCallCount);
|
||||||
@@ -93,7 +93,7 @@ public class BeoordeelRegistratieTests
|
|||||||
{
|
{
|
||||||
var store = new FakeRegistrationStore();
|
var store = new FakeRegistrationStore();
|
||||||
var acl = new FakeAclClient();
|
var acl = new FakeAclClient();
|
||||||
var handler = new BeoordeelRegistratie(store, acl, new FakeUserTaskClient([]));
|
var handler = new BeoordeelRegistratie(store, acl, new FakeUserTaskClient([]), TimeProvider.System);
|
||||||
|
|
||||||
var ex = await Assert.ThrowsAsync<InvalidOperationException>(() =>
|
var ex = await Assert.ThrowsAsync<InvalidOperationException>(() =>
|
||||||
handler.HandleAsync(new BeoordeelRegistratieCommand(RegistrationId.New(), BeoordelingsBesluit.Goedkeuren)));
|
handler.HandleAsync(new BeoordeelRegistratieCommand(RegistrationId.New(), BeoordelingsBesluit.Goedkeuren)));
|
||||||
@@ -108,7 +108,7 @@ public class BeoordeelRegistratieTests
|
|||||||
var acl = new FakeAclClient();
|
var acl = new FakeAclClient();
|
||||||
var registration = Registration.Submit("123456782"); // no zaak yet
|
var registration = Registration.Submit("123456782"); // no zaak yet
|
||||||
store.Seed(registration);
|
store.Seed(registration);
|
||||||
var handler = new BeoordeelRegistratie(store, acl, TaskFor(registration));
|
var handler = new BeoordeelRegistratie(store, acl, TaskFor(registration), TimeProvider.System);
|
||||||
|
|
||||||
var ex = await Assert.ThrowsAsync<InvalidOperationException>(() =>
|
var ex = await Assert.ThrowsAsync<InvalidOperationException>(() =>
|
||||||
handler.HandleAsync(new BeoordeelRegistratieCommand(registration.Id, BeoordelingsBesluit.Goedkeuren)));
|
handler.HandleAsync(new BeoordeelRegistratieCommand(registration.Id, BeoordelingsBesluit.Goedkeuren)));
|
||||||
@@ -123,7 +123,7 @@ public class BeoordeelRegistratieTests
|
|||||||
var acl = new FakeAclClient();
|
var acl = new FakeAclClient();
|
||||||
var registration = WithZaak();
|
var registration = WithZaak();
|
||||||
store.Seed(registration);
|
store.Seed(registration);
|
||||||
var handler = new BeoordeelRegistratie(store, acl, TaskFor(registration));
|
var handler = new BeoordeelRegistratie(store, acl, TaskFor(registration), TimeProvider.System);
|
||||||
|
|
||||||
await handler.HandleAsync(new BeoordeelRegistratieCommand(registration.Id, BeoordelingsBesluit.Goedkeuren));
|
await handler.HandleAsync(new BeoordeelRegistratieCommand(registration.Id, BeoordelingsBesluit.Goedkeuren));
|
||||||
await handler.HandleAsync(new BeoordeelRegistratieCommand(registration.Id, BeoordelingsBesluit.Goedkeuren));
|
await handler.HandleAsync(new BeoordeelRegistratieCommand(registration.Id, BeoordelingsBesluit.Goedkeuren));
|
||||||
@@ -139,7 +139,7 @@ public class BeoordeelRegistratieTests
|
|||||||
var acl = new FakeAclClient();
|
var acl = new FakeAclClient();
|
||||||
var registration = WithZaak();
|
var registration = WithZaak();
|
||||||
store.Seed(registration);
|
store.Seed(registration);
|
||||||
var handler = new BeoordeelRegistratie(store, acl, TaskFor(registration));
|
var handler = new BeoordeelRegistratie(store, acl, TaskFor(registration), TimeProvider.System);
|
||||||
|
|
||||||
await handler.HandleAsync(new BeoordeelRegistratieCommand(registration.Id, BeoordelingsBesluit.Afwijzen));
|
await handler.HandleAsync(new BeoordeelRegistratieCommand(registration.Id, BeoordelingsBesluit.Afwijzen));
|
||||||
await handler.HandleAsync(new BeoordeelRegistratieCommand(registration.Id, BeoordelingsBesluit.Afwijzen));
|
await handler.HandleAsync(new BeoordeelRegistratieCommand(registration.Id, BeoordelingsBesluit.Afwijzen));
|
||||||
@@ -158,7 +158,7 @@ public class BeoordeelRegistratieTests
|
|||||||
var registration = WithZaak();
|
var registration = WithZaak();
|
||||||
store.Seed(registration);
|
store.Seed(registration);
|
||||||
var tasks = new FakeUserTaskClient([]); // no open task for this registration
|
var tasks = new FakeUserTaskClient([]); // no open task for this registration
|
||||||
var handler = new BeoordeelRegistratie(store, acl, tasks);
|
var handler = new BeoordeelRegistratie(store, acl, tasks, TimeProvider.System);
|
||||||
|
|
||||||
await handler.HandleAsync(new BeoordeelRegistratieCommand(registration.Id, BeoordelingsBesluit.Goedkeuren));
|
await handler.HandleAsync(new BeoordeelRegistratieCommand(registration.Id, BeoordelingsBesluit.Goedkeuren));
|
||||||
|
|
||||||
|
|||||||
@@ -26,6 +26,11 @@ internal sealed class FakeRegistrationStore : IRegistrationStore
|
|||||||
=> Task.FromResult(_byId.Values.FirstOrDefault(r =>
|
=> Task.FromResult(_byId.Values.FirstOrDefault(r =>
|
||||||
r.Bsn == bsn && r.Status is RegistrationStatus.Ingediend or RegistrationStatus.InBehandeling));
|
r.Bsn == bsn && r.Status is RegistrationStatus.Ingediend or RegistrationStatus.InBehandeling));
|
||||||
|
|
||||||
|
public Task<IReadOnlyList<Registration>> FindDueForHerregistratieReminderAsync(
|
||||||
|
DateTimeOffset asOf, CancellationToken ct = default)
|
||||||
|
=> Task.FromResult<IReadOnlyList<Registration>>(
|
||||||
|
_byId.Values.Where(r => r.HerregistratieReminderDue(asOf)).ToList());
|
||||||
|
|
||||||
public void Seed(Registration registration) => _byId[registration.Id] = registration;
|
public void Seed(Registration registration) => _byId[registration.Id] = registration;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -85,6 +90,13 @@ internal sealed class FakeUserTaskClient(IReadOnlyList<BeoordelingTask> open) :
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/// <summary>A <see cref="TimeProvider"/> pinned to a fixed instant, so time-based use cases (the
|
||||||
|
/// herregistratie sweep, S-17) are deterministic without the TimeProvider.Testing package.</summary>
|
||||||
|
internal sealed class FixedClock(DateTimeOffset now) : TimeProvider
|
||||||
|
{
|
||||||
|
public override DateTimeOffset GetUtcNow() => now;
|
||||||
|
}
|
||||||
|
|
||||||
/// <summary>A fake ACL client that records the bsn it was asked to open a zaak for and returns a
|
/// <summary>A fake ACL client that records the bsn it was asked to open a zaak for and returns a
|
||||||
/// fixed zaak URL.</summary>
|
/// fixed zaak URL.</summary>
|
||||||
internal sealed class FakeAclClient(Uri? zaakUrl = null) : IAclClient
|
internal sealed class FakeAclClient(Uri? zaakUrl = null) : IAclClient
|
||||||
|
|||||||
@@ -0,0 +1,67 @@
|
|||||||
|
using Big.Application;
|
||||||
|
using Big.Domain;
|
||||||
|
|
||||||
|
namespace Big.Tests;
|
||||||
|
|
||||||
|
// S-17 (#18): the sweep behind the Quartz job. It reminds every inscription whose herregistratie
|
||||||
|
// reminder is due, marks each so a re-fire is a no-op (§8.6), and returns the reminded ids. Pure over
|
||||||
|
// the store + an injected clock — no Quartz here.
|
||||||
|
public class HerregistratieReminderSweepTests
|
||||||
|
{
|
||||||
|
private static readonly DateTimeOffset Now = new(2026, 7, 23, 0, 0, 0, TimeSpan.Zero);
|
||||||
|
|
||||||
|
private static Registration Inscribed(string bsn, DateTimeOffset ingeschrevenOp)
|
||||||
|
{
|
||||||
|
var registration = Registration.Submit(bsn);
|
||||||
|
registration.AttachZaak(FakeAclClient.DefaultZaakUrl);
|
||||||
|
registration.Approve(ingeschrevenOp);
|
||||||
|
return registration;
|
||||||
|
}
|
||||||
|
|
||||||
|
// Inscribed exactly (geldigheid - herinneringstermijn) before Now: the reminder window is open.
|
||||||
|
private static Registration Due(string bsn)
|
||||||
|
=> Inscribed(bsn, Now - Registration.HerregistratieGeldigheid + Registration.Herinneringstermijn);
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
public async Task Reminds_and_persists_every_due_inscription_and_returns_their_ids()
|
||||||
|
{
|
||||||
|
var store = new FakeRegistrationStore();
|
||||||
|
var a = Due("123456782");
|
||||||
|
var b = Due("111111110");
|
||||||
|
var freshlyInscribed = Inscribed("222222222", Now); // not yet in the window
|
||||||
|
store.Seed(a);
|
||||||
|
store.Seed(b);
|
||||||
|
store.Seed(freshlyInscribed);
|
||||||
|
|
||||||
|
var reminded = await new HerregistratieReminderSweep(store, new FixedClock(Now)).SweepAsync();
|
||||||
|
|
||||||
|
Assert.Equal(new HashSet<RegistrationId> { a.Id, b.Id }, reminded.ToHashSet());
|
||||||
|
Assert.True((await store.GetAsync(a.Id))!.HerregistratieReminderVerstuurd);
|
||||||
|
Assert.True((await store.GetAsync(b.Id))!.HerregistratieReminderVerstuurd);
|
||||||
|
Assert.False((await store.GetAsync(freshlyInscribed.Id))!.HerregistratieReminderVerstuurd);
|
||||||
|
Assert.Equal(2, store.SaveCount);
|
||||||
|
}
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
public async Task A_second_sweep_reminds_no_one_again()
|
||||||
|
{
|
||||||
|
var store = new FakeRegistrationStore();
|
||||||
|
store.Seed(Due("123456782"));
|
||||||
|
var sweep = new HerregistratieReminderSweep(store, new FixedClock(Now));
|
||||||
|
|
||||||
|
await sweep.SweepAsync();
|
||||||
|
var second = await sweep.SweepAsync();
|
||||||
|
|
||||||
|
Assert.Empty(second);
|
||||||
|
Assert.Equal(1, store.SaveCount); // only the first sweep persisted anything
|
||||||
|
}
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
public async Task Reminds_no_one_when_nothing_is_due()
|
||||||
|
{
|
||||||
|
var store = new FakeRegistrationStore();
|
||||||
|
store.Seed(Inscribed("123456782", Now)); // freshly inscribed — deadline is 5 years off
|
||||||
|
|
||||||
|
Assert.Empty(await new HerregistratieReminderSweep(store, new FixedClock(Now)).SweepAsync());
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -79,7 +79,7 @@ public class InMemoryRegistrationStoreTests
|
|||||||
switch (transition)
|
switch (transition)
|
||||||
{
|
{
|
||||||
case nameof(Registration.Withdraw): registration.Withdraw(); break;
|
case nameof(Registration.Withdraw): registration.Withdraw(); break;
|
||||||
case nameof(Registration.Approve): registration.Approve(); break;
|
case nameof(Registration.Approve): registration.Approve(DateTimeOffset.UtcNow); break;
|
||||||
case nameof(Registration.Reject): registration.Reject(); break;
|
case nameof(Registration.Reject): registration.Reject(); break;
|
||||||
case nameof(Registration.Expire): registration.Expire(); break;
|
case nameof(Registration.Expire): registration.Expire(); break;
|
||||||
}
|
}
|
||||||
@@ -96,4 +96,27 @@ public class InMemoryRegistrationStoreTests
|
|||||||
|
|
||||||
Assert.Null(await store.FindOpenByBsnAsync("123456782"));
|
Assert.Null(await store.FindOpenByBsnAsync("123456782"));
|
||||||
}
|
}
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
public async Task Finds_only_the_inscriptions_due_for_a_herregistratie_reminder()
|
||||||
|
{
|
||||||
|
var now = new DateTimeOffset(2026, 7, 23, 0, 0, 0, TimeSpan.Zero);
|
||||||
|
var store = new InMemoryRegistrationStore();
|
||||||
|
|
||||||
|
var due = Registration.Submit("123456782");
|
||||||
|
due.AttachZaak(new Uri("http://openzaak/zaken/api/v1/zaken/abc"));
|
||||||
|
due.Approve(now - Registration.HerregistratieGeldigheid + Registration.Herinneringstermijn);
|
||||||
|
await store.SaveAsync(due);
|
||||||
|
|
||||||
|
var freshlyInscribed = Registration.Submit("111111110");
|
||||||
|
freshlyInscribed.AttachZaak(new Uri("http://openzaak/zaken/api/v1/zaken/def"));
|
||||||
|
freshlyInscribed.Approve(now);
|
||||||
|
await store.SaveAsync(freshlyInscribed);
|
||||||
|
|
||||||
|
await store.SaveAsync(Registration.Submit("222222222")); // still INGEDIEND — never inscribed
|
||||||
|
|
||||||
|
var result = await store.FindDueForHerregistratieReminderAsync(now);
|
||||||
|
|
||||||
|
Assert.Equal([due.Id], result.Select(r => r.Id).ToArray());
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,90 @@
|
|||||||
|
using Big.Domain;
|
||||||
|
|
||||||
|
namespace Big.Tests;
|
||||||
|
|
||||||
|
// S-17 (#18): a BIG inscription is valid for a fixed term; before it lapses the zorgprofessional must
|
||||||
|
// herregistreren. The aggregate records when it was inscribed, derives the herregistratie deadline, and
|
||||||
|
// answers whether a reminder is due as of a given moment — the single rule the Quartz sweep and the
|
||||||
|
// store query both build on. All arithmetic is against an explicit "now" so it is wall-clock-free.
|
||||||
|
public class RegistrationHerregistratieTests
|
||||||
|
{
|
||||||
|
private static readonly DateTimeOffset Now = new(2026, 7, 23, 0, 0, 0, TimeSpan.Zero);
|
||||||
|
|
||||||
|
// The moment the reminder window opens: inscribed exactly (geldigheid - herinneringstermijn) ago.
|
||||||
|
private static DateTimeOffset InscribedSoDueAt(DateTimeOffset asOf)
|
||||||
|
=> asOf - Registration.HerregistratieGeldigheid + Registration.Herinneringstermijn;
|
||||||
|
|
||||||
|
private static Registration Inscribed(DateTimeOffset ingeschrevenOp)
|
||||||
|
{
|
||||||
|
var registration = Registration.Submit("123456782");
|
||||||
|
registration.AttachZaak(FakeAclClient.DefaultZaakUrl);
|
||||||
|
registration.Approve(ingeschrevenOp);
|
||||||
|
return registration;
|
||||||
|
}
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
public void Approving_records_the_inscription_moment_and_the_herregistratie_deadline()
|
||||||
|
{
|
||||||
|
var registration = Inscribed(Now);
|
||||||
|
|
||||||
|
Assert.Equal(Now, registration.IngeschrevenOp);
|
||||||
|
Assert.Equal(Now + Registration.HerregistratieGeldigheid, registration.HerregistratieVoor);
|
||||||
|
}
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
public void A_reminder_is_due_the_moment_the_window_before_the_deadline_opens()
|
||||||
|
{
|
||||||
|
var registration = Inscribed(InscribedSoDueAt(Now));
|
||||||
|
|
||||||
|
Assert.True(registration.HerregistratieReminderDue(Now));
|
||||||
|
}
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
public void A_reminder_is_not_yet_due_one_day_before_the_window_opens()
|
||||||
|
{
|
||||||
|
var registration = Inscribed(InscribedSoDueAt(Now) + TimeSpan.FromDays(1));
|
||||||
|
|
||||||
|
Assert.False(registration.HerregistratieReminderDue(Now));
|
||||||
|
}
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
public void A_registration_that_is_not_ingeschreven_is_never_due_and_has_no_deadline()
|
||||||
|
{
|
||||||
|
var registration = Registration.Submit("123456782"); // INGEDIEND, never inscribed
|
||||||
|
|
||||||
|
Assert.Null(registration.IngeschrevenOp);
|
||||||
|
Assert.Null(registration.HerregistratieVoor);
|
||||||
|
Assert.False(registration.HerregistratieReminderDue(Now));
|
||||||
|
}
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
public void A_reminded_registration_is_no_longer_due()
|
||||||
|
{
|
||||||
|
var registration = Inscribed(InscribedSoDueAt(Now));
|
||||||
|
|
||||||
|
registration.MarkHerregistratieReminderVerstuurd();
|
||||||
|
|
||||||
|
Assert.True(registration.HerregistratieReminderVerstuurd);
|
||||||
|
Assert.False(registration.HerregistratieReminderDue(Now));
|
||||||
|
}
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
public void Marking_the_reminder_sent_twice_is_idempotent()
|
||||||
|
{
|
||||||
|
var registration = Inscribed(InscribedSoDueAt(Now));
|
||||||
|
|
||||||
|
registration.MarkHerregistratieReminderVerstuurd();
|
||||||
|
registration.MarkHerregistratieReminderVerstuurd();
|
||||||
|
|
||||||
|
Assert.True(registration.HerregistratieReminderVerstuurd);
|
||||||
|
}
|
||||||
|
|
||||||
|
[Fact]
|
||||||
|
public void Marking_a_reminder_on_a_registration_that_is_not_ingeschreven_is_rejected()
|
||||||
|
{
|
||||||
|
var registration = Registration.Submit("123456782");
|
||||||
|
|
||||||
|
var ex = Assert.Throws<InvalidOperationException>(() => registration.MarkHerregistratieReminderVerstuurd());
|
||||||
|
Assert.Contains("INGESCHREVEN", ex.Message);
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -4,6 +4,9 @@ namespace Big.Tests;
|
|||||||
|
|
||||||
public class RegistrationTests
|
public class RegistrationTests
|
||||||
{
|
{
|
||||||
|
// A fixed inscription moment for the approval tests; its exact value is irrelevant to them.
|
||||||
|
private static readonly DateTimeOffset Ingeschreven = new(2026, 1, 1, 0, 0, 0, TimeSpan.Zero);
|
||||||
|
|
||||||
[Fact]
|
[Fact]
|
||||||
public void Submitting_a_registration_starts_in_ingediend()
|
public void Submitting_a_registration_starts_in_ingediend()
|
||||||
{
|
{
|
||||||
@@ -103,7 +106,7 @@ public class RegistrationTests
|
|||||||
var registration = Registration.Submit("123456782");
|
var registration = Registration.Submit("123456782");
|
||||||
registration.AttachZaak(new Uri("http://openzaak/zaken/api/v1/zaken/abc"));
|
registration.AttachZaak(new Uri("http://openzaak/zaken/api/v1/zaken/abc"));
|
||||||
|
|
||||||
registration.Approve();
|
registration.Approve(Ingeschreven);
|
||||||
|
|
||||||
Assert.Equal(RegistrationStatus.Ingeschreven, registration.Status);
|
Assert.Equal(RegistrationStatus.Ingeschreven, registration.Status);
|
||||||
}
|
}
|
||||||
@@ -113,7 +116,7 @@ public class RegistrationTests
|
|||||||
{
|
{
|
||||||
var registration = Registration.Submit("123456782");
|
var registration = Registration.Submit("123456782");
|
||||||
|
|
||||||
var ex = Assert.Throws<InvalidOperationException>(() => registration.Approve());
|
var ex = Assert.Throws<InvalidOperationException>(() => registration.Approve(Ingeschreven));
|
||||||
|
|
||||||
Assert.Contains("no zaak", ex.Message, StringComparison.OrdinalIgnoreCase);
|
Assert.Contains("no zaak", ex.Message, StringComparison.OrdinalIgnoreCase);
|
||||||
Assert.Equal(RegistrationStatus.Ingediend, registration.Status);
|
Assert.Equal(RegistrationStatus.Ingediend, registration.Status);
|
||||||
@@ -124,9 +127,9 @@ public class RegistrationTests
|
|||||||
{
|
{
|
||||||
var registration = Registration.Submit("123456782");
|
var registration = Registration.Submit("123456782");
|
||||||
registration.AttachZaak(new Uri("http://openzaak/zaken/api/v1/zaken/abc"));
|
registration.AttachZaak(new Uri("http://openzaak/zaken/api/v1/zaken/abc"));
|
||||||
registration.Approve();
|
registration.Approve(Ingeschreven);
|
||||||
|
|
||||||
var ex = Assert.Throws<InvalidOperationException>(() => registration.Approve());
|
var ex = Assert.Throws<InvalidOperationException>(() => registration.Approve(Ingeschreven));
|
||||||
Assert.Contains("only an INGEDIEND", ex.Message);
|
Assert.Contains("only an INGEDIEND", ex.Message);
|
||||||
Assert.Equal(RegistrationStatus.Ingeschreven, registration.Status);
|
Assert.Equal(RegistrationStatus.Ingeschreven, registration.Status);
|
||||||
}
|
}
|
||||||
@@ -157,7 +160,7 @@ public class RegistrationTests
|
|||||||
{
|
{
|
||||||
var registration = Registration.Submit("123456782");
|
var registration = Registration.Submit("123456782");
|
||||||
registration.AttachZaak(new Uri("http://openzaak/zaken/api/v1/zaken/abc"));
|
registration.AttachZaak(new Uri("http://openzaak/zaken/api/v1/zaken/abc"));
|
||||||
registration.Approve();
|
registration.Approve(Ingeschreven);
|
||||||
|
|
||||||
var ex = Assert.Throws<InvalidOperationException>(() => registration.TakeIntoBehandeling());
|
var ex = Assert.Throws<InvalidOperationException>(() => registration.TakeIntoBehandeling());
|
||||||
Assert.Contains("only an INGEDIEND", ex.Message);
|
Assert.Contains("only an INGEDIEND", ex.Message);
|
||||||
@@ -171,7 +174,7 @@ public class RegistrationTests
|
|||||||
registration.AttachZaak(new Uri("http://openzaak/zaken/api/v1/zaken/abc"));
|
registration.AttachZaak(new Uri("http://openzaak/zaken/api/v1/zaken/abc"));
|
||||||
registration.TakeIntoBehandeling();
|
registration.TakeIntoBehandeling();
|
||||||
|
|
||||||
registration.Approve();
|
registration.Approve(Ingeschreven);
|
||||||
|
|
||||||
Assert.Equal(RegistrationStatus.Ingeschreven, registration.Status);
|
Assert.Equal(RegistrationStatus.Ingeschreven, registration.Status);
|
||||||
}
|
}
|
||||||
@@ -218,7 +221,7 @@ public class RegistrationTests
|
|||||||
var approveEx = Assert.Throws<InvalidOperationException>(() =>
|
var approveEx = Assert.Throws<InvalidOperationException>(() =>
|
||||||
{
|
{
|
||||||
registration.AttachZaak(new Uri("http://openzaak/zaken/api/v1/zaken/abc"));
|
registration.AttachZaak(new Uri("http://openzaak/zaken/api/v1/zaken/abc"));
|
||||||
registration.Approve();
|
registration.Approve(Ingeschreven);
|
||||||
});
|
});
|
||||||
Assert.Contains("IN_BEHANDELING", approveEx.Message);
|
Assert.Contains("IN_BEHANDELING", approveEx.Message);
|
||||||
|
|
||||||
@@ -277,7 +280,7 @@ public class RegistrationTests
|
|||||||
{
|
{
|
||||||
var registration = Registration.Submit("123456782");
|
var registration = Registration.Submit("123456782");
|
||||||
registration.AttachZaak(new Uri("http://openzaak/zaken/api/v1/zaken/abc"));
|
registration.AttachZaak(new Uri("http://openzaak/zaken/api/v1/zaken/abc"));
|
||||||
registration.Approve();
|
registration.Approve(Ingeschreven);
|
||||||
|
|
||||||
var ex = Assert.Throws<InvalidOperationException>(() => registration.Withdraw());
|
var ex = Assert.Throws<InvalidOperationException>(() => registration.Withdraw());
|
||||||
Assert.Contains("only an INGEDIEND", ex.Message);
|
Assert.Contains("only an INGEDIEND", ex.Message);
|
||||||
@@ -336,7 +339,7 @@ public class RegistrationTests
|
|||||||
{
|
{
|
||||||
var registration = Registration.Submit("123456782");
|
var registration = Registration.Submit("123456782");
|
||||||
registration.AttachZaak(new Uri("http://openzaak/zaken/api/v1/zaken/abc"));
|
registration.AttachZaak(new Uri("http://openzaak/zaken/api/v1/zaken/abc"));
|
||||||
registration.Approve();
|
registration.Approve(Ingeschreven);
|
||||||
|
|
||||||
var ex = Assert.Throws<InvalidOperationException>(() => registration.Expire());
|
var ex = Assert.Throws<InvalidOperationException>(() => registration.Expire());
|
||||||
Assert.Contains("only an INGEDIEND", ex.Message);
|
Assert.Contains("only an INGEDIEND", ex.Message);
|
||||||
|
|||||||
@@ -6,7 +6,8 @@
|
|||||||
"mutate": [
|
"mutate": [
|
||||||
"!**/OpenZaakJobPump.cs",
|
"!**/OpenZaakJobPump.cs",
|
||||||
"!**/BeoordelingEscalatiePump.cs",
|
"!**/BeoordelingEscalatiePump.cs",
|
||||||
"!**/RegistratieVerlopenPump.cs"
|
"!**/RegistratieVerlopenPump.cs",
|
||||||
|
"!**/HerregistratieReminderJob.cs"
|
||||||
],
|
],
|
||||||
"thresholds": {
|
"thresholds": {
|
||||||
"high": 95,
|
"high": 95,
|
||||||
|
|||||||
@@ -5,6 +5,13 @@
|
|||||||
<ProjectReference Include="..\..\projection-api\Projection.ReadModel\Projection.ReadModel.csproj" />
|
<ProjectReference Include="..\..\projection-api\Projection.ReadModel\Projection.ReadModel.csproj" />
|
||||||
</ItemGroup>
|
</ItemGroup>
|
||||||
|
|
||||||
|
<ItemGroup>
|
||||||
|
<PackageReference Include="OpenTelemetry.Exporter.OpenTelemetryProtocol" Version="1.17.0" />
|
||||||
|
<PackageReference Include="OpenTelemetry.Extensions.Hosting" Version="1.17.0" />
|
||||||
|
<PackageReference Include="OpenTelemetry.Instrumentation.AspNetCore" Version="1.17.0" />
|
||||||
|
<PackageReference Include="OpenTelemetry.Instrumentation.Http" Version="1.17.0" />
|
||||||
|
</ItemGroup>
|
||||||
|
|
||||||
<PropertyGroup>
|
<PropertyGroup>
|
||||||
<TargetFramework>net10.0</TargetFramework>
|
<TargetFramework>net10.0</TargetFramework>
|
||||||
<Nullable>enable</Nullable>
|
<Nullable>enable</Nullable>
|
||||||
|
|||||||
@@ -1,9 +1,22 @@
|
|||||||
using System.Text.Json;
|
using System.Text.Json;
|
||||||
using EventSubscriber.Application;
|
using EventSubscriber.Application;
|
||||||
|
using OpenTelemetry.Resources;
|
||||||
|
using OpenTelemetry.Trace;
|
||||||
using Projection.ReadModel;
|
using Projection.ReadModel;
|
||||||
|
|
||||||
var builder = WebApplication.CreateBuilder(args);
|
var builder = WebApplication.CreateBuilder(args);
|
||||||
|
|
||||||
|
// OpenTelemetry tracing (S-16b, ADR-0023): auto-instrument the incoming NRC notification callback and
|
||||||
|
// the outgoing ACL enrichment call, exported over OTLP to Tempo. Service name + OTLP endpoint come
|
||||||
|
// from OTEL_* env (compose); the exporter no-ops when Tempo is unreachable.
|
||||||
|
builder.Services.AddOpenTelemetry()
|
||||||
|
.ConfigureResource(r => r.AddService(
|
||||||
|
builder.Configuration["OTEL_SERVICE_NAME"] ?? builder.Environment.ApplicationName))
|
||||||
|
.WithTracing(tracing => tracing
|
||||||
|
.AddAspNetCoreInstrumentation(o => o.Filter = ctx => ctx.Request.Path != "/health")
|
||||||
|
.AddHttpClientInstrumentation()
|
||||||
|
.AddOtlpExporter());
|
||||||
|
|
||||||
var connectionString = builder.Configuration.GetConnectionString("Projection")
|
var connectionString = builder.Configuration.GetConnectionString("Projection")
|
||||||
?? throw new InvalidOperationException("Missing connection string 'ConnectionStrings:Projection'");
|
?? throw new InvalidOperationException("Missing connection string 'ConnectionStrings:Projection'");
|
||||||
// The exact Authorization header value Open Notificaties sends on each abonnement callback.
|
// The exact Authorization header value Open Notificaties sends on each abonnement callback.
|
||||||
|
|||||||
@@ -1,8 +1,21 @@
|
|||||||
using Microsoft.EntityFrameworkCore;
|
using Microsoft.EntityFrameworkCore;
|
||||||
|
using OpenTelemetry.Resources;
|
||||||
|
using OpenTelemetry.Trace;
|
||||||
using Projection.ReadModel;
|
using Projection.ReadModel;
|
||||||
|
|
||||||
var builder = WebApplication.CreateBuilder(args);
|
var builder = WebApplication.CreateBuilder(args);
|
||||||
|
|
||||||
|
// OpenTelemetry tracing (S-16b, ADR-0023): auto-instrument incoming ASP.NET Core requests, exported
|
||||||
|
// over OTLP to Tempo, so a BFF → projection-api read is one connected trace. Service name + OTLP
|
||||||
|
// endpoint come from OTEL_* env (compose); the exporter no-ops when Tempo is unreachable.
|
||||||
|
builder.Services.AddOpenTelemetry()
|
||||||
|
.ConfigureResource(r => r.AddService(
|
||||||
|
builder.Configuration["OTEL_SERVICE_NAME"] ?? builder.Environment.ApplicationName))
|
||||||
|
.WithTracing(tracing => tracing
|
||||||
|
.AddAspNetCoreInstrumentation(o => o.Filter = ctx => ctx.Request.Path != "/health")
|
||||||
|
.AddHttpClientInstrumentation()
|
||||||
|
.AddOtlpExporter());
|
||||||
|
|
||||||
var connectionString = builder.Configuration.GetConnectionString("Projection")
|
var connectionString = builder.Configuration.GetConnectionString("Projection")
|
||||||
?? throw new InvalidOperationException("Missing connection string 'ConnectionStrings:Projection'");
|
?? throw new InvalidOperationException("Missing connection string 'ConnectionStrings:Projection'");
|
||||||
|
|
||||||
|
|||||||
@@ -4,6 +4,13 @@
|
|||||||
<ProjectReference Include="..\Projection.ReadModel\Projection.ReadModel.csproj" />
|
<ProjectReference Include="..\Projection.ReadModel\Projection.ReadModel.csproj" />
|
||||||
</ItemGroup>
|
</ItemGroup>
|
||||||
|
|
||||||
|
<ItemGroup>
|
||||||
|
<PackageReference Include="OpenTelemetry.Exporter.OpenTelemetryProtocol" Version="1.17.0" />
|
||||||
|
<PackageReference Include="OpenTelemetry.Extensions.Hosting" Version="1.17.0" />
|
||||||
|
<PackageReference Include="OpenTelemetry.Instrumentation.AspNetCore" Version="1.17.0" />
|
||||||
|
<PackageReference Include="OpenTelemetry.Instrumentation.Http" Version="1.17.0" />
|
||||||
|
</ItemGroup>
|
||||||
|
|
||||||
<PropertyGroup>
|
<PropertyGroup>
|
||||||
<TargetFramework>net10.0</TargetFramework>
|
<TargetFramework>net10.0</TargetFramework>
|
||||||
<Nullable>enable</Nullable>
|
<Nullable>enable</Nullable>
|
||||||
|
|||||||
@@ -40,7 +40,7 @@ public sealed class EenRegistratieBeoordelenSteps
|
|||||||
|
|
||||||
[When("the behandelaar decides \"(.*)\"")]
|
[When("the behandelaar decides \"(.*)\"")]
|
||||||
public async Task WhenTheBehandelaarDecides(string besluit)
|
public async Task WhenTheBehandelaarDecides(string besluit)
|
||||||
=> await new BeoordeelRegistratie(_store, _acl, _tasks).HandleAsync(
|
=> await new BeoordeelRegistratie(_store, _acl, _tasks, TimeProvider.System).HandleAsync(
|
||||||
new BeoordeelRegistratieCommand(_id, Enum.Parse<BeoordelingsBesluit>(besluit, ignoreCase: true)));
|
new BeoordeelRegistratieCommand(_id, Enum.Parse<BeoordelingsBesluit>(besluit, ignoreCase: true)));
|
||||||
|
|
||||||
[Then("the registration has status \"(.*)\"")]
|
[Then("the registration has status \"(.*)\"")]
|
||||||
|
|||||||
@@ -221,4 +221,9 @@ public sealed class InMemoryRegistrationStore : IRegistrationStore
|
|||||||
public Task<Registration?> FindOpenByBsnAsync(string bsn, CancellationToken ct = default)
|
public Task<Registration?> FindOpenByBsnAsync(string bsn, CancellationToken ct = default)
|
||||||
=> Task.FromResult(_byId.Values.FirstOrDefault(r =>
|
=> Task.FromResult(_byId.Values.FirstOrDefault(r =>
|
||||||
r.Bsn == bsn && r.Status is RegistrationStatus.Ingediend or RegistrationStatus.InBehandeling));
|
r.Bsn == bsn && r.Status is RegistrationStatus.Ingediend or RegistrationStatus.InBehandeling));
|
||||||
|
|
||||||
|
public Task<IReadOnlyList<Registration>> FindDueForHerregistratieReminderAsync(
|
||||||
|
DateTimeOffset asOf, CancellationToken ct = default)
|
||||||
|
=> Task.FromResult<IReadOnlyList<Registration>>(
|
||||||
|
_byId.Values.Where(r => r.HerregistratieReminderDue(asOf)).ToList());
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user