Skip to content

Supply-chain graph — Phase 6: graph-service + dashboard views - #185

Merged
toddysm merged 2 commits into
mainfrom
feat/supply-chain-graph-phase6
Aug 10, 2026
Merged

toddysm merged 2 commits into
mainfrom
feat/supply-chain-graph-phase6

Conversation

@toddysm

@toddysm toddysm commented Aug 10, 2026

Copy link
Copy Markdown
Owner

Implements Phase 6 of the supply-chain graph (epic #177): the FastAPI
graph-service, its Helm subchart, a dashboard graph view, and the deploy-stage
producer.

graph-service

apps/python-app/services/graph-service — FastAPI over the shared
cssc_graph.queries layer (the same code the cssc-graph CLI uses). It owns a
single LadybugDB writer, rebuilds the graph from the committed data root on
startup, and gates /readyz on a successful index (the pod stays not-ready, not
crash-looping, if the data is invalid).

Endpoints: resolve, path, bases, derived, show, tag history, search,
and a bounded GET /graph/neighborhood (json|cytoscape|mermaid) for the
dashboard, plus POST /index/rebuild. Every traversal depth is clamped by
MAX_DEPTH.

Helm

New subchart under the umbrella, consistent with the other services: single
replica (Recreate strategy — one writer), numeric UID 10001, startup /
readiness / liveness probes, ephemeral emptyDir database (rebuilt on start) or
an optional PVC, and an optional git-sync init container that clones the
supply-chain-graph-data branch into the indexed volume. git-sync is disabled by
default so a first deploy is green before the data branch exists; enable it once
events have been recorded. dashboard-web gains GRAPH_SERVICE_URL.

dashboard-web

A new Supply chain graph stage shows the index summary, and a
/graph/neighborhood htmx route renders a bounded neighborhood (nodes + edges)
for any reference — no new frontend dependency.

Deploy producer

build-graph-event gains an ArtifactDeployed kind (image occurrence +
environment cluster/namespace + optional chart). New deploy-cssc-dashboard.yml
(dispatch) resolves each service's published digest and stages ArtifactDeployed
per service; record-graph-events now also collects deploy / cssc-dashboard.
graph-service is added to the build matrix and the Makefile.

Validation (local)

  • Tests: 40 (cssc_graph) + 16 (graph-service) + 21
    (dashboard-web) pass, including transitive bases/derived, the
    neighborhood renders, depth capping, and the not-ready gate.
  • helm lint/template clean for the subchart (default, git-sync, and PVC
    variants) and the umbrella.
  • ArtifactDeployed records validate against the schema, keep
    filename == id == cssc-graph id, and index into RUNS edges.
  • actionlint + shellcheck -S warning clean on the new workflow and action.

ladybug publishes cp314 manylinux wheels, so the golden/python:3.14-slim
base builds the native engine cleanly.

Closes #175. Part of #177.

… deploy producers (#175)

Ship the FastAPI graph-service, its Helm subchart, a dashboard graph view, and
the deploy-stage producer.
- services/graph-service: FastAPI over the shared cssc_graph query layer. Owns a
  single LadybugDB writer, rebuilds the graph from the committed data root on
  startup, and gates /readyz on a successful index. Endpoints: resolve, path,
  bases, derived, show, tag history, search, and a bounded /graph/neighborhood
  (json|cytoscape|mermaid); POST /index/rebuild. Depth is capped by MAX_DEPTH.
- graph-service Helm subchart: single replica (Recreate), optional git-sync init
  container for the supply-chain-graph-data branch, ephemeral emptyDir DB or an
  optional PVC, numeric UID 10001, startup/readiness/liveness probes. Wired into
  the umbrella chart; dashboard-web gets GRAPH_SERVICE_URL.
- dashboard-web: new 'Supply chain graph' stage (index summary) + a
  /graph/neighborhood route that renders a bounded neighborhood (nodes + edges)
  for any reference via htmx.
- build-graph-event: add ArtifactDeployed kind (image occurrence + environment
  cluster/namespace + optional chart). New deploy-cssc-dashboard.yml producer
  resolves each service digest and stages ArtifactDeployed; record-graph-events
  now also collects it. graph-service added to the build matrix and Makefile.
Verified locally: 40 (cssc_graph) + 16 (graph-service) + 21 (dashboard-web) tests
pass; helm lint/template clean (incl. git-sync + PVC variants); ArtifactDeployed
records validate and index (RUNS edges); actionlint + shellcheck clean.
Part of #177; implements #175.
Copilot AI lite review requested due to automatic review settings August 10, 2026 21:03

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds Phase 6 of the supply-chain graph by introducing a new FastAPI graph-service (backed by the shared cssc_graph.queries layer), wiring it into Helm + build/deploy workflows, and surfacing a new dashboard “Supply chain graph” stage that renders a bounded neighborhood via htmx.

Changes:

  • Implement graph-service (index ownership + readiness gating + query endpoints) with Docker packaging and Helm subchart.
  • Add dashboard-web “observability” stage + neighborhood route/templates + GraphService client integration.
  • Extend graph event production to include deploy-stage ArtifactDeployed records and add a deploy workflow to stage those events.

Reviewed changes

Copilot reviewed 31 out of 31 changed files in this pull request and generated 7 comments.

Show a summary per file
File Description
apps/python-app/services/graph-service/tests/test_app.py End-to-end app tests that build a temporary data root and exercise API journeys + readiness gating.
apps/python-app/services/graph-service/src/graph_service/indexing.py Implements the single-writer index owner and rebuild logic around LadybugDB.
apps/python-app/services/graph-service/src/graph_service/config.py Adds environment-driven settings for data root, DB path, rebuild behavior, and depth cap.
apps/python-app/services/graph-service/src/graph_service/app.py FastAPI routes for resolve/path/bases/derived/show/search + neighborhood and rebuild endpoint.
apps/python-app/services/graph-service/src/graph_service/init.py Introduces package version exported to FastAPI app metadata.
apps/python-app/services/graph-service/requirements.txt Runtime deps for running the service with uvicorn.
apps/python-app/services/graph-service/pyproject.toml Package metadata and test dependencies for graph-service.
apps/python-app/services/graph-service/Dockerfile Container build for graph-service, including shared cssc_graph install.
apps/python-app/services/graph-service/deploy/helm/graph-service/values.yaml Chart values including git-sync and optional PVC support.
apps/python-app/services/graph-service/deploy/helm/graph-service/templates/service.yaml Kubernetes Service for graph-service.
apps/python-app/services/graph-service/deploy/helm/graph-service/templates/pvc.yaml Optional PVC template for persisting the graph DB.
apps/python-app/services/graph-service/deploy/helm/graph-service/templates/deployment.yaml Deployment with single-replica writer semantics + probes + init git-sync option.
apps/python-app/services/graph-service/deploy/helm/graph-service/templates/configmap.yaml ConfigMap for non-secret runtime settings.
apps/python-app/services/graph-service/deploy/helm/graph-service/templates/_helpers.tpl Standard Helm naming/labels helpers for the subchart.
apps/python-app/services/graph-service/deploy/helm/graph-service/Chart.yaml Helm chart metadata for graph-service.
apps/python-app/services/graph-service/deploy/helm/graph-service/.helmignore Helm ignore rules for packaging.
apps/python-app/services/dashboard-web/tests/test_graph.py Tests for the new dashboard stage + neighborhood route and GraphService client.
apps/python-app/services/dashboard-web/src/dashboard_web/web/routes.py Adds optional graph neighborhood HTML route when a graph client is provided.
apps/python-app/services/dashboard-web/src/dashboard_web/templates/stages/observability.html New stage template that shows readiness summary and graph explore form.
apps/python-app/services/dashboard-web/src/dashboard_web/templates/stages/_graph_neighborhood.html Fragment template rendering nodes/edges (or empty/error prompts).
apps/python-app/services/dashboard-web/src/dashboard_web/stages/observability.py Adds GraphProvider stage that sources readiness data from graph-service.
apps/python-app/services/dashboard-web/src/dashboard_web/config.py Adds GRAPH_SERVICE_URL to dashboard settings.
apps/python-app/services/dashboard-web/src/dashboard_web/clients.py Adds GraphService HTTP client for readiness + neighborhood calls.
apps/python-app/services/dashboard-web/src/dashboard_web/app.py Wires GraphProvider + GraphServiceClient into app construction and routes.
apps/python-app/Makefile Adds graph-service to build/test targets and includes cssc_graph tests.
apps/python-app/deploy/helm/cssc-dashboard/values.yaml Adds graph-service subchart values + passes GRAPH_SERVICE_URL to dashboard-web.
apps/python-app/deploy/helm/cssc-dashboard/Chart.yaml Adds graph-service as an umbrella chart dependency and updates description.
.github/workflows/record-graph-events.yml Extends collection triggers to include deploy workflow completions.
.github/workflows/deploy-cssc-dashboard.yml New workflow_dispatch producer that resolves image digests and stages ArtifactDeployed events.
.github/workflows/build-cssc-dashboard.yml Adds graph-service to the build matrix.
.github/actions/build-graph-event/action.yml Extends event builder to support ArtifactDeployed record staging.
Suppressed comments (1)

apps/python-app/services/dashboard-web/src/dashboard_web/app.py:52

  • Similarly, create_app types graph as GraphServiceClient, but the parameter is used as an injectable dependency and only needs to satisfy the GraphClient protocol. Keeping the signature protocol-typed makes tests and alternate implementations type-safe.
def create_app(
    registry: StageRegistry | None = None,
    settings: DashboardSettings | None = None,
    graph: GraphServiceClient | None = None,
) -> FastAPI:
    settings = settings or dashboard_settings()
    graph = graph or GraphServiceClient(settings.graph_service_url)
    registry = registry or build_registry(settings, graph)

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread apps/python-app/services/graph-service/src/graph_service/app.py Outdated
Comment thread apps/python-app/services/graph-service/src/graph_service/app.py
Comment thread .github/actions/build-graph-event/action.yml
Comment thread apps/python-app/services/dashboard-web/src/dashboard_web/web/routes.py Outdated
Comment thread apps/python-app/services/dashboard-web/src/dashboard_web/app.py Outdated
Comment thread apps/python-app/services/graph-service/pyproject.toml
…ias, chart guard, shared protocol

- graph-service: run every query inside GraphIndex.reading() (holds the writer
  lock) so /index/rebuild can't close the store mid-request.
- graph-service /search: keep the public 'type' query param via alias, use a
  non-shadowing local name.
- build-graph-event: ArtifactDeployed now errors when chart-name is given without
  chart-version (no more chart.version:"").
- dashboard-web: define GraphClient Protocol once in clients.py and reuse it from
  observability + routes; type build_registry/create_app against the protocol.
@toddysm
toddysm merged commit 4250b4e into main Aug 10, 2026
3 checks passed
@toddysm
toddysm deleted the feat/supply-chain-graph-phase6 branch August 10, 2026 21:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Supply-chain graph — Phase 6: graph-service + dashboard views

2 participants