Skip to content

Feat: plugin based architecture and DevTokens solution - #1

Merged
sean6224 merged 26 commits into
mainfrom
ref
Aug 25, 2026
Merged

sean6224 merged 26 commits into
mainfrom
ref

Conversation

@rian-be

@rian-be rian-be commented Aug 24, 2026

Copy link
Copy Markdown
Contributor

This PR establishes AuthKit as plugin based service and delivers the first solution on top of it.

  • introduces the IAuthKitPlugin contract and dynamic plugin loading from plugins/ directory
  • adds the DevTokens plugin for issuing, validating, listing, and revoking developer tokens
  • restructures the codebase under src/ (Core / Host / Plugins) and migrates the solution, CI, and Docker layout
  • moves Keycloak realm configuration into the Deploy/ folder

Plugin Architecture

  • adds AuthKit.Plugins.Abstractions with IAuthKitPlugin, AuthKitSecuritySchemeDescriptor, AuthKitSecuritySchemeType, and AuthKitApiKeyLocation
  • IAuthKitPlugin lets plugin contribute services, middleware, health checks, and OpenAPI security schemes without being referenced by the host
  • adds PluginLoader and LoadedPlugin that discover and load plugin assemblies from AuthKit:PluginsPath at startup
  • the host calls ConfigureServices, inserts contributed middleware, exposes security schemes, and reports plugin health

DevTokens Plugin

  • adds DevTokensPlugin registered as an IAuthKitPlugin (issues and validates developer tokens for SDK access)
  • adds services IDeveloperTokenService, IDeveloperTokenManager, IDeveloperTokenValidator, and IDeveloperTokenRepository
  • adds CQRS handlers (Wolverine) for create, delete, get-by-id, and list developer tokens with FluentValidation validators
  • adds REST controllers: DeveloperTokensController, TokenLifecycleController, and VirtualMachineController
  • adds DeveloperTokenMiddleware and scope based authorization (DeveloperScopeRequirement, DeveloperScopePolicyProvider, DeveloperScopeHandler)
  • exposes the X-Developer-Token API key security scheme in OpenAPI
  • adds value objects TokenName, TokenLifetime, and TokenScope, plus DeveloperTokenLimitExceededException

Core & Key Management

  • moves the Core project under src/Core (domain, key management, token key bindings, options)
  • key management provides RSA signing key generation, AES encrypted on disk key storage, JWT key store, and JWKS discovery
  • token key bindings associate issued tokens with their signing key

Solution Layout & CI

  • migrates from the legacy RyzeSDK.AuthKit.sln to AuthKit.slnx and adds Directory.Packages.props
  • updates Dockerfile and docker-compose.yml to the new layout (host build/publish, plugin publish into plugins/, PostgreSQL + Keycloak services)
  • updates .github/workflows/main.yml to build/test the new solution layout

Keycloak Configuration

  • moves Keycloak realm definitions (realm-authz.json, workspace-authz-authz-config.json) into Deploy/Keycloak/realms

Result

  • AuthKit is now an extensible host where new SDK solutions ship as plugins instead of changing the host
  • developer token lifecycle (create, verify, list, get, delete, revoke-rotate) is served over REST
  • the repository builds, containers, and runs from a single src/ based layout

rian-be added 25 commits August 23, 2026 14:42
@rian-be
rian-be requested a review from RX-J August 24, 2026 21:02
@rian-be rian-be self-assigned this Aug 24, 2026
@sean6224
sean6224 merged commit 41741b0 into main Aug 25, 2026
4 checks passed
@sean6224
sean6224 deleted the ref branch August 25, 2026 20:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants