Skip to content

feat(host): expose JWKS and monitoring services over gRPC - #46

Merged
rian-be merged 7 commits into
developmentfrom
fix/grpc
Sep 15, 2026
Merged

rian-be merged 7 commits into
developmentfrom
fix/grpc

Conversation

@rian-be

@rian-be rian-be commented Sep 15, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Replaces the placeholder GreeterService with real gRPC surfaces for the host's public key store and monitoring, backs both the REST and gRPC monitoring endpoints with single shared aggregation layer (no duplicated health logic), fixes two DevTools gRPC UI issues (TLS less target resolution and empty request bodies), and lands the full ExamplePlugin reference plugin that exercises every hook in the plugin contract.

Host gRPC: JWKS and Monitoring services

  • protos/jwks.proto - Jwks service exposing GetJwks, GetKeyByKid, GetJwksHealth, and GetJwksStats (mirrors the REST JwksController)
  • protos/monitoring.proto - Monitoring service exposing GetHealth (key store + per plugin health) and GetMetrics (process uptime/start)
  • JwksService and MonitoringService implementations; GreeterService and greet.proto removed
  • generated types namespaced as Host.Grpc to avoid shadowing the REST DTOs in Host.KeyManagement.Restful.DTO.Response

Shared monitoring layer (Host.Monitoring)

  • HealthReportService aggregates key store health and every loaded plugin's health check into one transport-agnostic HealthResponse
  • the REST /health and /metrics endpoints (EndpointConfiguration) and the gRPC Monitoring service now consume the same reports instead of re-implementing the same aggregation twice
  • MetricsReportService produces the process metrics surfaced by both transports

DevTools gRPC UI fixes

  • ResolveGrpcTarget() now selects https only when the Kestrel certificate exists (falls back to plain HTTP/2, h2c), so the in-process gRPC UI can reach the host without TLS
  • GrpcDynamicInvoker treats empty request bodies as {} for google.protobuf.Empty inputs instead of failing with InvalidProtocolBufferException

ExamplePlugin (living reference)

  • src/Plugins/Solutions/ExamplePlugin - small, dependency free plugin implementing the complete IAuthKitPlugin contract: [PluginMetadata], context scoped configuration (ExampleOptions), middleware, endpoints, an API key authentication scheme, structured health checks, a hosted service, and plugin owned gRPC service
  • wired into AuthKit.slnx, appsettings.json (Plugins:authkit.example), and the Docker build ships its generated manifest.json

Validation

  • dotnet build AuthKit.slnx completes with zero errors
  • 94/94 Host unit tests and 10/10 integration tests pass
  • task generate-manifest produces the ExamplePlugin manifest; AuthKit.PluginContractValidator passes all plugins

Result

The host's key management and health surfaces are reachable over gRPC (and browsable in the DevTools UI under GRPC_UI_TARGET), monitoring logic lives in one place shared by REST and gRPC, the DevTools gRPC UI works in HTTP and HTTPS setups, and plugin authors have complete reference to copy from.

@rian-be rian-be added area/host Host-side runtime (DI, OpenAPI, health exec) additive Additive, non-breaking change area/devtools DevTools plugin labels Sep 15, 2026
return Task.CompletedTask;
});

logger.LogDebug("ExamplePlugin middleware handling {Method} {Path}.", context.Request.Method, context.Request.Path);
return Task.CompletedTask;
});

logger.LogDebug("ExamplePlugin middleware handling {Method} {Path}.", context.Request.Method, context.Request.Path);
@rian-be
rian-be merged commit a1ea6a7 into development Sep 15, 2026
9 checks passed
@rian-be
rian-be deleted the fix/grpc branch September 15, 2026 18:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

additive Additive, non-breaking change area/devtools DevTools plugin area/host Host-side runtime (DI, OpenAPI, health exec)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants