Skip to content

Server REST API

Gabor Galazzo edited this page Jul 25, 2026 · 1 revision

Server REST API

All controllers live under com.evento.server.web.* and depend on BusFacade. This is the surface the Evento GUI is built on; it is served on the HTTP port (3000).


1. Controllers

Controller Prefix Key endpoints
DashboardController /api/dashboard Cluster status snapshot
ClusterStatusController /api/cluster Connected nodes, availability
BundleController /api/bundle Bundle list, update, delete
HandlerController /api/handler Handler graph, invocation graph
CatalogController /api/catalog Payload catalog
ConsumerController /api/consumer Consumer status, dead queue, retry
PerformanceController /api/performance Performance model, time series
ArtifactController /api/artifact Bundle artifact upload
FlowsController /api/flows Handler flow visualisation
SystemStateStoreController /api/system-state-store Aggregate snapshots

2. Authentication

HTTP Basic against the static Spring Boot in-memory user. WebConfig requires authentication on /api/** plus the actuator endpoints (except health and info), and returns a plain 401 without a WWW-Authenticate header so the GUI's own login page handles failures rather than the browser's native dialog.

Per-endpoint enforcement is @Secured("ROLE_WEB") / @Secured("ROLE_ADMIN").

There is no JWT stack — AuthFilter, AuthService, TokenRole and AuthController were removed with the explorative read-only pivot. See Security Model.

curl -u evento:secret http://localhost:3000/api/cluster

3. How the data gets there

Nothing here is a separate reporting pipeline — these controllers read the same bus state the broker routes on:

  • Cluster and bundle views come from ConnectionRegistry and ClusterRegistry via BusFacade.
  • Handler graph, catalog and flows come from the rich evento:bundle-discovery notification each bundle sends after enable — including source paths, line numbers, repositoryUrl and linePrefix for clickable source links, and @EventoDescription text.
  • Consumer status, dead queue and retry round-trip to the bundle over the wire as evento:server-admin-request, handled by BundleAdminRequestHandler.
  • Performance data comes from PerformanceStoreService.

If a bundle appears in the cluster but its handlers are missing from the catalog, its discovery notification was rejected rather than never sent. Check for event=listener_error … decode failed for BundleDiscoveryInfo — see Wire Protocol § 8.

Since 2.0, discovery carries full self-description metadata, which is what allowed the static-analysis publish step (evento-cli) to be deleted. Since 2.4.0 it also carries each handler's executor, so the GUI can mark parallel handlers.


4. What is not here

Deploy-by-upload and the autoscaling protocol were removed in 2.0: no JAR upload for deployment, no /spawn, no /kill, no per-bundle env or VM options, no autorun / deployable flags. Deployment and scaling belong to the external orchestrator.


5. Actuator

Separate from /api/**, on the same port:

Endpoint Notes
/actuator/health Bus port + node counts; liveness and readiness probes enabled
/actuator/prometheus All Micrometer meters
/actuator/metrics Browsable meter list
/actuator/info

See Observability.


See also

Clone this wiki locally