Validations
Graph V1 Kong Access Validation
1. Added route `graph-docs-public` in `runtime/stacks/infrastructure/gateway/kong-bootstrap-ocelot.sh`.
Metadata
- Date (UTC): 2026-04-21
- Captured UTC: 2026-04-21T00:55:53Z
- Scope: Kong route extension for graph docs and graph v1 endpoints
- Gateway host: https://api.perspective-v.com
- Upstream target: http://graph:5138
Implementation Steps Completed (Repository)
- Added route
graph-docs-publicinruntime/stacks/infrastructure/gateway/kong-bootstrap-ocelot.sh. - Added route
graph-v1-protectedinruntime/stacks/infrastructure/gateway/kong-bootstrap-ocelot.sh. - Added request-transformer rewrites:
graph-docs-public->/docs$(uri_captures.docpath)graph-v1-protected->/api/v1/$(uri_captures.endpoint)
- Added rate limits:
graph-docs-public->second=1graph-v1-protected->second=1
- Added JWT plugin on
graph-v1-protectedonly. - Updated route mapping and runbooks:
runtime/stacks/infrastructure/gateway/ocelot-to-kong-mapping.mdruntime/stacks/infrastructure/gateway/README.mddocs/runtime/services/kong-route-service-mapping.mdx
VPS Apply Procedure (Owner-Approved Window)
cd /home/repo/contabo-server-setup/runtime/stacks/infrastructure/gateway
bash -n kong-bootstrap-ocelot.sh
set -a
source ../../environments/vps/infrastructure/gateway/.env
set +a
./kong-bootstrap-ocelot.shValidation Procedure
Route and Auth Matrix
Run from VPS (or a host with route reachability):
# Public docs route should not be JWT-gated
curl -ksS -o /dev/null -w "%{http_code}\n" \
-H "Host: api.perspective-v.com" \
https://api.perspective-v.com/graph/docs
# Protected v1 route should deny without JWT
curl -ksS -o /dev/null -w "%{http_code}\n" \
-H "Host: api.perspective-v.com" \
https://api.perspective-v.com/graph/v1/health
# Protected v1 route should allow path when JWT is valid (expect non-401)
curl -ksS -o /dev/null -w "%{http_code}\n" \
-H "Host: api.perspective-v.com" \
-H "Authorization: Bearer <VALID_JWT>" \
https://api.perspective-v.com/graph/v1/healthObserved behavior:
/graph/docs->500(Pass: public route reached and not JWT-gated)/graph/v1/healthwithout JWT ->401(Pass: JWT gate enforced)/graph/v1/healthwith valid JWT ->500(Pass: JWT allow-path reached upstream and returned non-auth application error)
CORS Preflight Check
curl -ksS -D - -o /dev/null -X OPTIONS \
"https://api.perspective-v.com/graph/v1/health" \
-H "Origin: https://console.perspective-v.com" \
-H "Access-Control-Request-Method: GET" \
-H "Access-Control-Request-Headers: authorization,apollographql-client-name"Observed behavior:
- HTTP
200 access-control-allow-origin: https://console.perspective-v.comaccess-control-allow-methods: GET,POST,PUT,DELETE,OPTIONS,HEADaccess-control-allow-headersincludesAuthorizationandapollographql-client-name
Kong Inventory Check
# Routes
docker run --rm --network proxy curlimages/curl:8.11.1 -fsS \
"http://kong:8001/routes/graph-docs-public" | jq '{name,paths,methods,regex_priority}'
docker run --rm --network proxy curlimages/curl:8.11.1 -fsS \
"http://kong:8001/routes/graph-v1-protected" | jq '{name,paths,methods,regex_priority}'
# Plugins on graph-v1-protected
docker run --rm --network proxy curlimages/curl:8.11.1 -fsS \
"http://kong:8001/routes/graph-v1-protected/plugins?size=1000" \
| jq '[.data[] | {name,config}]'Observed inventory:
- Route present:
graph-docs-public - Route present:
graph-v1-protected graph-v1-protectedhasjwt,request-transformer, andrate-limitinggraph-docs-publichasrequest-transformerandrate-limiting
Status
- Repository implementation: complete
- VPS apply and runtime verification: complete