Gabriel Radureau e1af61e1ea feat(server): add per-IP rate limit middleware on /api/v1/greet
Implements Phase 1 of ADR-0022 (Rate Limiting and Cache Strategy):
in-memory per-IP rate limiter using golang.org/x/time/rate. Returns
HTTP 429 with JSON body and Retry-After header when exceeded.

Changes:
- New: pkg/middleware/ratelimit.go (153 lines, 7 unit tests in ratelimit_test.go)
- Modified: pkg/config/config.go (RateLimit struct + 3 SetDefaults + 3 BindEnv + 3 getters)
- Modified: pkg/server/server.go (wire on /api/v1/greet, conditional on Enabled)
- Modified: pkg/bdd/testserver/server.go (env-var support for rate limit config)
- New: pkg/bdd/steps/ratelimit_steps.go (step definitions)
- Added: features/greet/greet.feature scenario (currently @skip @bdd-deferred — see note below)

Known limitation:
The BDD scenario is tagged @skip @bdd-deferred because the testserver
loads its config once at startup; env vars set inside a step do not
reach the already-running server. The middleware itself is fully
covered by unit tests. To re-enable BDD, the testserver needs either
an admin endpoint or a per-scenario fresh-server pattern.

Closes #13 (Phase 1 only — Phase 2 Redis + cache service deferred).

Generated ~95% in autonomy by Mistral Vibe via ICM workspace
~/Work/Vibe/workspaces/rate-limit-middleware/.
Trainer (Claude) finalized the commit/PR step (Mistral hit max-turns).

🤖 Co-Authored-By: Mistral Vibe (devstral-2 / mistral-medium-3.5)
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-03 13:16:13 +02:00

dance-lessons-coach

Build Status Go Report Card Version License BDD Coverage UNIT Coverage

Go web service demonstrating idiomatic package structure, versioned JSON API, and production-ready features.

Features

  • Versioned JSON API (/api/v1, /api/v2)
  • Chi router with graceful shutdown
  • Zerolog structured logging (console and JSON modes)
  • Viper configuration (file + env vars)
  • Readiness endpoint for Kubernetes / service mesh
  • OpenTelemetry / Jaeger distributed tracing
  • OpenAPI / Swagger UI (embedded in binary)
  • PostgreSQL user service with JWT auth
  • BDD + unit tests

Quick Start

git clone https://gitea.arcodange.lab/arcodange/dance-lessons-coach.git
cd dance-lessons-coach
./scripts/build.sh          # produces ./bin/server and ./bin/greet
./scripts/start-server.sh start
curl http://localhost:8080/api/health
curl http://localhost:8080/api/v1/greet/Alice

Stop: ./scripts/start-server.sh stop

Greet CLI

go run ./cmd/greet           # Hello world!
go run ./cmd/greet Alice     # Hello Alice!

Configuration

All options are available via config.yaml or DLC_* environment variables.

Env var Default Description
DLC_SERVER_PORT 8080 Listening port
DLC_SERVER_HOST 0.0.0.0 Bind address
DLC_LOGGING_JSON false JSON log format
DLC_LOGGING_OUTPUT stderr Log file path
DLC_SHUTDOWN_TIMEOUT 30s Graceful shutdown window
DLC_API_V2_ENABLED false Enable /api/v2 routes
DLC_CONFIG_FILE ./config.yaml Override config path

See config.example.yaml for a full template.

API

Method Path Description
GET /api/health Liveness check
GET /api/ready Readiness check (503 during shutdown)
GET /api/version Version info (?format=plain|full|json)
GET /api/v1/greet/ Default greeting
GET /api/v1/greet/{name} Named greeting
POST /api/v2/greet V2 greeting with validation
GET /swagger/ Swagger UI

Testing

go test ./...                          # unit + integration tests
./scripts/test-graceful-shutdown.sh    # lifecycle + JSON logging validation
./scripts/test-opentelemetry.sh        # tracing end-to-end

Gitea Client

AI agent helper script at .vibe/skills/gitea-client/scripts/gitea-client.sh.

Auth setup:

echo "your_token" > ~/.gitea_token
chmod 600 ~/.gitea_token
export GITEA_API_TOKEN_FILE="$HOME/.gitea_token"

Get a token at https://gitea.arcodange.lab → Profile → Settings → Applications.

Architecture

Key decisions are documented in adr/. See AGENTS.md for the full development reference (commands, config, ADR index, commit conventions).

License

MIT

Description
No description provided
Readme 57 MiB
Languages
Go 71.2%
Shell 21.7%
Gherkin 3.9%
TypeScript 1.4%
Vue 0.5%
Other 1.2%