using Acl.Application; using Acl.Infrastructure; using OpenTelemetry.Metrics; using OpenTelemetry.Resources; using OpenTelemetry.Trace; var builder = WebApplication.CreateBuilder(args); // OpenTelemetry tracing (S-16b, ADR-0023): auto-instrument incoming ASP.NET Core requests and // outgoing HttpClient calls (the ACL → OpenZaak hop), exported over OTLP to Tempo. Service name + // OTLP endpoint come from OTEL_* env (compose); the exporter no-ops when Tempo is unreachable. builder.Services.AddOpenTelemetry() .ConfigureResource(r => r.AddService( builder.Configuration["OTEL_SERVICE_NAME"] ?? builder.Environment.ApplicationName)) .WithTracing(tracing => tracing .AddAspNetCoreInstrumentation(o => o.Filter = ctx => ctx.Request.Path != "/health") .AddHttpClientInstrumentation() .AddOtlpExporter()) // OpenTelemetry metrics (S-16c, ADR-0023): golden signals for the request path — // http.server.request.duration (traffic/errors/latency) + http.client.* for downstream hops, plus // the built-in System.Runtime meter for saturation (GC, CPU, thread pool). Prometheus scrapes these // from /metrics (mapped below); metrics aren't pushed over OTLP, so no collector hop (ADR-0023). .WithMetrics(metrics => metrics .AddAspNetCoreInstrumentation() .AddHttpClientInstrumentation() .AddMeter("System.Runtime") .AddPrometheusExporter()); builder.Services.AddSingleton(); builder.Services.AddSingleton(sp => sp.GetRequiredService() .GetSection("Acl:Defaults").Get() ?? throw new InvalidOperationException("Missing configuration section 'Acl:Defaults'")); builder.Services.AddSingleton(sp => sp.GetRequiredService() .GetSection("Acl:OpenZaak").Get() ?? throw new InvalidOperationException("Missing configuration section 'Acl:OpenZaak'")); // The default-fill values are held in a runtime-mutable store (S-15b, ADR-0026), seeded from the // configured Acl:Defaults. The beheer portal edits it; the worker reads it per zaak. The S-27 // resolution keys stay on AclDefaults (static) — see DefaultFillSettings. builder.Services.AddSingleton(sp => { var d = sp.GetRequiredService(); return new InMemoryDefaultFillStore( new DefaultFillSettings(d.Bronorganisatie, d.VerantwoordelijkeOrganisatie, d.Vertrouwelijkheidaanduiding)); }); builder.Services.AddSingleton(sp => sp.GetRequiredService() .GetSection("Acl:Objecten").Get() ?? throw new InvalidOperationException("Missing configuration section 'Acl:Objecten'")); builder.Services.AddHttpClient(); // The Objecten hop that writes the register record on approval (S-19a, ADR-0028). builder.Services.AddHttpClient(); // Singleton so the resolved zaaktype/informatieobjecttype URLs are cached across requests (S-27). builder.Services.AddSingleton(); builder.Services.AddScoped(); var app = builder.Build(); app.MapGet("/health", () => "Healthy"); // Prometheus scrape endpoint (S-16c): exposes the OTel metrics above in Prometheus text format. app.MapPrometheusScrapingEndpoint(); // The ACL's single operation, exposed as a service endpoint. app.MapPost("/zaken", async (OpenZaakRequest body, AclService acl, CancellationToken ct) => { var zaakUrl = await acl.OpenZaakAsync(new DomainRegistration(body.Bsn, body.Reference), ct); return Results.Ok(new { zaakUrl = zaakUrl.ToString() }); }); // Approve a zaak: set it to its zaaktype's eindstatus (S-09b). The domain hands over only the zaak // URL; the ACL owns the ZGW statustype resolution (§8.1). app.MapPost("/statussen", async (SetStatusRequest body, AclService acl, CancellationToken ct) => { await acl.ApproveZaakAsync(new Uri(body.ZaakUrl), ct); return Results.NoContent(); }); // Cancel a zaak on document-timeout expiry (S-10c): set it to its zaaktype's cancellation statustype // + resultaat. The domain hands over only the zaak URL; the ACL owns the ZGW resolution (§8.1). app.MapPost("/annuleringen", async (CancelZaakRequest body, AclService acl, CancellationToken ct) => { await acl.CancelZaakAsync(new Uri(body.ZaakUrl), ct); return Results.NoContent(); }); // Read a zaak's public-safe reference (its identificatie). The Event Subscriber calls this to enrich // the read projection without reading ZGW itself (§8.1, #78). app.MapPost("/zaken/reference", async (ZaakReferenceRequest body, AclService acl, CancellationToken ct) => { var reference = await acl.GetZaakReferenceAsync(new Uri(body.ZaakUrl), ct); return Results.Ok(new { reference }); }); // Read the register record an object in Objecten holds. The Event Subscriber projects a register // write from the notification NRC delivers, which carries only the object URL, and may not talk to // Objecten itself (§8.1, ADR-0028/ADR-0030). 404 when the object holds no record — the subscriber // treats that as "nothing to project" rather than an error (§8.6). app.MapPost("/register-records/read", async (RegisterRecordReadRequest body, AclService acl, CancellationToken ct) => { var record = await acl.GetRegisterRecordAsync(new Uri(body.ObjectUrl), ct); return record is null ? Results.NotFound() : Results.Ok(record); }); // Store an uploaded diploma against a zaak (S-10b): the domain sends the file as base64; the ACL // creates the ZGW enkelvoudiginformatieobject and relates it to the zaak (§8.1). Returns its URL. app.MapPost("/documenten", async (StoreDocumentRequest body, AclService acl, CancellationToken ct) => { var url = await acl.StoreDiplomaAsync( new Uri(body.ZaakUrl), Convert.FromBase64String(body.ContentBase64), body.FileName, body.ContentType, ct); return Results.Ok(new { informatieobjectUrl = url.ToString() }); }); // List the published zaaktypen — the read-only catalogus the beheer portal shows (S-15a). The BFF // proxies this behind medewerker-realm + beheerder authorization; the ACL trusts its callers (§8.3) // and is the only code allowed to read the ZGW Catalogi API (§8.1). app.MapGet("/catalogi/zaaktypen", async (AclService acl, CancellationToken ct) => Results.Ok(await acl.ListZaaktypenAsync(ct))); // Read the current default-fill settings (beheer config viewer, S-15b). app.MapGet("/default-fill", (AclService acl) => Results.Ok(acl.GetDefaultFill())); // Update the default-fill settings from the beheer portal (S-15b). Behind beheerder authorization at // the BFF; the ACL validates the values are present (the three ZGW-mandatory fields). app.MapPut("/default-fill", (DefaultFillSettings body, AclService acl) => { if (string.IsNullOrWhiteSpace(body.Bronorganisatie) || string.IsNullOrWhiteSpace(body.VerantwoordelijkeOrganisatie) || string.IsNullOrWhiteSpace(body.Vertrouwelijkheidaanduiding)) return Results.BadRequest(new { error = "bronorganisatie, verantwoordelijkeOrganisatie and vertrouwelijkheidaanduiding are all required." }); acl.UpdateDefaultFill(body); return Results.NoContent(); }); app.Run(); public sealed record OpenZaakRequest(string Bsn, string Reference); public sealed record SetStatusRequest(string ZaakUrl); public sealed record CancelZaakRequest(string ZaakUrl); public sealed record ZaakReferenceRequest(string ZaakUrl); /// The object whose register record the Event Subscriber wants read back (S-19b-2). public sealed record RegisterRecordReadRequest(string ObjectUrl); public sealed record StoreDocumentRequest(string ZaakUrl, string ContentBase64, string FileName, string ContentType); public partial class Program;