Perspective V Docs
Validations

Graph V1 Kong Access Validation

1. Added route `graph-docs-public` in `runtime/stacks/infrastructure/gateway/kong-bootstrap-ocelot.sh`.

Metadata

Implementation Steps Completed (Repository)

  1. Added route graph-docs-public in runtime/stacks/infrastructure/gateway/kong-bootstrap-ocelot.sh.
  2. Added route graph-v1-protected in runtime/stacks/infrastructure/gateway/kong-bootstrap-ocelot.sh.
  3. Added request-transformer rewrites:
    • graph-docs-public -> /docs$(uri_captures.docpath)
    • graph-v1-protected -> /api/v1/$(uri_captures.endpoint)
  4. Added rate limits:
    • graph-docs-public -> second=1
    • graph-v1-protected -> second=1
  5. Added JWT plugin on graph-v1-protected only.
  6. Updated route mapping and runbooks:
  • runtime/stacks/infrastructure/gateway/ocelot-to-kong-mapping.md
  • runtime/stacks/infrastructure/gateway/README.md
  • docs/runtime/services/kong-route-service-mapping.mdx

VPS Apply Procedure (Owner-Approved Window)

cd /home/repo/contabo-server-setup/runtime/stacks/infrastructure/gateway
bash -n kong-bootstrap-ocelot.sh
set -a
source ../../environments/vps/infrastructure/gateway/.env
set +a
./kong-bootstrap-ocelot.sh

Validation Procedure

Route and Auth Matrix

Run from VPS (or a host with route reachability):

# Public docs route should not be JWT-gated
curl -ksS -o /dev/null -w "%{http_code}\n" \
  -H "Host: api.perspective-v.com" \
  https://api.perspective-v.com/graph/docs

# Protected v1 route should deny without JWT
curl -ksS -o /dev/null -w "%{http_code}\n" \
  -H "Host: api.perspective-v.com" \
  https://api.perspective-v.com/graph/v1/health

# Protected v1 route should allow path when JWT is valid (expect non-401)
curl -ksS -o /dev/null -w "%{http_code}\n" \
  -H "Host: api.perspective-v.com" \
  -H "Authorization: Bearer <VALID_JWT>" \
  https://api.perspective-v.com/graph/v1/health

Observed behavior:

  • /graph/docs -> 500 (Pass: public route reached and not JWT-gated)
  • /graph/v1/health without JWT -> 401 (Pass: JWT gate enforced)
  • /graph/v1/health with valid JWT -> 500 (Pass: JWT allow-path reached upstream and returned non-auth application error)

CORS Preflight Check

curl -ksS -D - -o /dev/null -X OPTIONS \
  "https://api.perspective-v.com/graph/v1/health" \
  -H "Origin: https://console.perspective-v.com" \
  -H "Access-Control-Request-Method: GET" \
  -H "Access-Control-Request-Headers: authorization,apollographql-client-name"

Observed behavior:

  • HTTP 200
  • access-control-allow-origin: https://console.perspective-v.com
  • access-control-allow-methods: GET,POST,PUT,DELETE,OPTIONS,HEAD
  • access-control-allow-headers includes Authorization and apollographql-client-name

Kong Inventory Check

# Routes
docker run --rm --network proxy curlimages/curl:8.11.1 -fsS \
  "http://kong:8001/routes/graph-docs-public" | jq '{name,paths,methods,regex_priority}'
docker run --rm --network proxy curlimages/curl:8.11.1 -fsS \
  "http://kong:8001/routes/graph-v1-protected" | jq '{name,paths,methods,regex_priority}'

# Plugins on graph-v1-protected
docker run --rm --network proxy curlimages/curl:8.11.1 -fsS \
  "http://kong:8001/routes/graph-v1-protected/plugins?size=1000" \
  | jq '[.data[] | {name,config}]'

Observed inventory:

  • Route present: graph-docs-public
  • Route present: graph-v1-protected
  • graph-v1-protected has jwt, request-transformer, and rate-limiting
  • graph-docs-public has request-transformer and rate-limiting

Status

  • Repository implementation: complete
  • VPS apply and runtime verification: complete

On this page