# str-ap-internal
Development repository used for

## Setup notes
To generate a local certificate use:

For testing the endpoints
* provided notebook
* [collection.http](collection.http)

### Swagger
Swagger ui: https://str.local/swagger/index.html
Update of the swagger documentation, can be done by running the following command from the project root:
swag fmt -g ./cmd/str/main.go
swag init -g ./cmd/str/main.go -o docs

### helm chart setup notes

cd chart/str
# Create a chart name sparse
helm create str
# Uninstall
helm uninstall str -n str
# Create or update
helm upgrade -i str . --namespace str --create-namespace --set image.password=ghp***
helm upgrade -i str . --namespace str --create-namespace \
--set image.password=ghp_*** \
--set tls.key=$(base64 -i ../../str.local-key.pem) \
--set tls.crt=$(base64 -i ../../str.local.pem) \
--set kafka.boostrapServers=pkc-***:9092 \
--set kafka.username=*** \
--set kafka.password=*** \
-f values-local.yaml
@@ -0,0 +1,21 @@
FROM alpine

# Create a new user 'str' with user ID 1001
RUN adduser -D -u 1001 str

# Copy files
# todo check the naming of the binary
COPY str-ap-internal /opt/str
COPY docs/ /opt/docs/

RUN touch /opt/.env

# Change ownership of the /opt directory to the new user
RUN chown -R str:str /opt


# Switch user
USER str

ENTRYPOINT ["/opt/str"]
@@ -0,0 +1,228 @@
## Setup
This notebook is a collection of `curl` commands that can be executed in the terminal to validate the API endpoints\.
Besides `curl` also `jq` is used for formatting purposes\.
### client credentials
The `bw` command is the Bitwarden password manager CLI command\.
Replace the CLIENT\_ID value\, with your personal CLIENT\_ID\. And provison your CLIENT\_SECRET
The client SECRET can also be captured via CLI read\:
Get an OAUTH token \( from the `/token` endpoint\)
# Compose the JSON string using jq
DATA=$(jq -n \
--arg client_id "$CLIENT_ID" \
--arg client_secret "$CLIENT_SECRET" \
--arg audience "" \
--arg grant_type "client_credentials" \
'{client_id: $client_id, client_secret: $client_secret, audience: $audience, grant_type: $grant_type}')
# Get the token
TOKEN=$(curl -s --request POST \
--url \
--header 'content-type: application/json' \
--data $DATA | jq -r .access_token )
### API host
## Test API
### Unauthenticated health endpoint
curl -s https://$HOST/api/v0/ping | jq -r .
This should return\:
"status": "ok"
## Activity data
### Submit of activity data
Multiple records can be posted at ounce\, but will be stored as individual records\.
For demo purposes\, we can set an invalid country code\.
curl -s -X POST https://$HOST/api/v0/str/activity-data \
--header "Authorization: Bearer $TOKEN" \
--header "Content-Type: application/json" \
--data '{
"data": [
"numberOfGuests": 10,
"countryOfGuests": [
"temporal": {
"startDateTime": "2024-07-21T17:32:28Z",
"endDateTime": "2024-07-25T17:32:28Z"
"address": {
"street": "123 Main St",
"city": "Brussels",
"postalCode": "1000",
"country": "BEL"
"hostId": "placeholder-host-id",
"unitId": "placeholder-unit-id",
"areaId": "placeholder-area-id"
"numberOfGuests": 2,
"countryOfGuests": [
"temporal": {
"startDateTime": "2024-07-21T17:32:28Z",
"endDateTime": "2024-07-25T17:32:28Z"
"address": {
"street": "123 Main St",
"city": "Brussels",
"postalCode": "1000",
"country": "BEL"
"hostId": "placeholder-host-id",
"unitId": "placeholder-unit-id",
"areaId": "placeholder-area-id"
"numberOfGuests": 3,
"countryOfGuests": [
"temporal": {
"startDateTime": "2024-07-21T17:32:28Z",
"endDateTime": "2024-07-25T17:32:28Z"
"address": {
"street": "123 Main St",
"city": "Brussels",
"postalCode": "1000",
"country": "BEL"
"hostId": "placeholder-host-id",
"unitId": "placeholder-unit-id",
"areaId": "placeholder-area-id"
"metadata": {
"platform": "",
"submissionDate": "2024-07-21T17:32:28Z",
"additionalProp1": {}
' \
| jq .
Data has been pushed to the Kafka topic\: `activity-data`

### Only for demonstration purposes\, and if you have an own deployment
We can use `kcat` to list kafka topics and kafka topics content
kcat -L
kcat -C -t activity-data -c 20 -f 'Headers: %h || Message value: %s\n'
Confluent Kafka also allows to views data in the topics\: [https\:\/\/confluent\.cloud\/environments\/env\-d19ry\/clusters\/lkc\-1dm6dj\/topics\/activity\-data\/message\-viewer](
Note also the header data contains the OAUTH2 app name\.

### Retrieve activity data submitted to the SDEP
curl -s https://$HOST/api/v0/ca/activity-data \
--header "Authorization: Bearer $TOKEN" \
| jq .
Note each consumer has it\'s offset and will only get \"new\" published data\.

## Listings
### Submit of listings data
curl -s -X POST https://$HOST/api/v0/str/listings \
--header "Authorization: Bearer $TOKEN" \
--header "Content-Type: application/json" \
--data '
"data": [
"registrationNumber": "1234",
"Unit": {
"description": "string",
"floorLevel": "string",
"address": {
"street": "Culliganlaan 5",
"city": "Diegem",
"postalCode": "1831",
"country": "BEL"
"obtainedAuth": true,
"subjectToAuth": true,
"numberOfRooms": 0,
"occupancy": 0,
"purpose": "string",
"type": "string",
"url": ""
"metadata": {
"platform": "STR-Platform"
| jq .
### Only for demonstration purposes\, and if you have an own deployment
Consuming data from the kafka topic `listings`
kcat -C -t listings -c 20 -f 'Headers: %h || Message value: %s\n'
### Retrieving listing data
The limit parameter is optional\.
This data retrieval is also incremental and will only return \"new\" data\.
curl -s https://$HOST/api/v0/ca/listings \
--header "Authorization: Bearer $TOKEN" \
| jq .
## Area
### Shape file upload
curl -s -X POST https://$HOST/api/v0/ca/area \
--header "Authorization: Bearer $TOKEN" \
-F "file=@/Users/thierryturpin/GolandProjects/str-ap-internal/BELGIUM_-_Regions.shp"
### List shape files
curl -s https://$HOST/api/v0/str/area \
--header "Authorization: Bearer $TOKEN" \
| jq .
### Download of a shape file
Set the ID returned by the previous command
curl -s https://$HOST/api/v0/str/area/01J0R0GC700000000000000000 \
--header "Authorization: Bearer $TOKEN" \
-o downloaded_shape_file.shp
Verify the downloaded file
file downloaded_shape_file.shp
### Verify SSL certificate
Only relevant for own deployments\:
export PORT=443
openssl s_client -servername $SERVER_NAME -connect $SERVER_NAME:$PORT | openssl x509 -noout -dates
@@ -0,0 +1,24 @@
apiVersion: v2
name: str
description: A Helm chart for Kubernetes

# A chart can be either an 'application' or a 'library' chart.
# Application charts are a collection of templates that can be packaged into versioned archives
# to be deployed.
# Library charts provide useful utilities or functions for the chart developer. They're included as
# a dependency of application charts to inject those utilities and functions into the rendering
# pipeline. Library charts do not define any templates and therefore cannot be deployed.
type: application

# This is the chart version. This version number should be incremented each time you make changes
# to the chart and its templates, including the app version.
# Versions are expected to follow Semantic Versioning (
version: 0.1.0

# This is the version number of the application being deployed. This version number should be
# incremented each time you make changes to the application. Versions are not expected to
# follow Semantic Versioning. They should reflect the version the application is using.
# It is recommended to use it with quotes.
appVersion: "v0.0.27"
@@ -0,0 +1,8 @@
{{- if .Values.ingress.enabled }}
{{- range $host := .Values.ingress.hosts }}
{{- range .paths }}
Application is exposed via ingress on:
http{{ if $.Values.ingress.tls }}s{{ end }}://{{ $ }}{{ .path }}
{{- end }}
{{- end }}
{{- end }}
@@ -0,0 +1,62 @@
Expand the name of the chart.
{{- define "" -}}
{{- default .Chart.Name .Values.nameOverride | trunc 63 | trimSuffix "-" }}
{{- end }}

Create a default fully qualified app name.
We truncate at 63 chars because some Kubernetes name fields are limited to this (by the DNS naming spec).
If release name contains chart name it will be used as a full name.
{{- define "str.fullname" -}}
{{- if .Values.fullnameOverride }}
{{- .Values.fullnameOverride | trunc 63 | trimSuffix "-" }}
{{- else }}
{{- $name := default .Chart.Name .Values.nameOverride }}
{{- if contains $name .Release.Name }}
{{- .Release.Name | trunc 63 | trimSuffix "-" }}
{{- else }}
{{- printf "%s-%s" .Release.Name $name | trunc 63 | trimSuffix "-" }}
{{- end }}
{{- end }}
{{- end }}

Create chart name and version as used by the chart label.
{{- define "str.chart" -}}
{{- printf "%s-%s" .Chart.Name .Chart.Version | replace "+" "_" | trunc 63 | trimSuffix "-" }}
{{- end }}

Common labels
{{- define "str.labels" -}} {{ include "str.chart" . }}
{{ include "str.selectorLabels" . }}
{{- if .Chart.AppVersion }} {{ .Chart.AppVersion | quote }}
{{- end }} {{ .Release.Service }}
{{- end }}

Selector labels
{{- define "str.selectorLabels" -}} {{ include "" . }} {{ .Release.Name }}
{{- end }}

Create the name of the service account to use
{{- define "str.serviceAccountName" -}}
{{- if .Values.serviceAccount.create }}
{{- default (include "str.fullname" .) }}
{{- else }}
{{- default "default" }}
{{- end }}
{{- end }}

