Skip to content

How gStack works

gStack is the Republic of Moldova’s shared, sovereign government technology stack — a common foundation of reusable government building blocks plus the domain applications built on top of them. The guiding idea: build a public-service capability once and reuse it everywhere, hosted on national infrastructure, with a full append-only audit trail, delivered trilingually (RO / RU / EN).

gStack follows the GovStack building-block model: a new service is mostly the composition of existing blocks (identity, signing, interoperability, audit, notifications, storage) plus its own domain logic.

  • Sovereign by default — every component is self-hostable on national (on-prem / govcloud) infrastructure; no mandatory external dependencies.
  • Build once, reuse — services compose from shared platform blocks instead of re-implementing plumbing.
  • Auditable & compliant — an append-only event log records every state change, built for contestation, investigation and data-protection compliance.
  • Trilingual — every service ships in Română, Русский and English from day one.

gStack reads top-to-bottom: citizen channels rest on applications, applications rest on platform blocks, and everything runs on shared infrastructure.

LayerWhat it isIn gStack
ChannelsHow people reach servicesPublic-service portal, mobile, single sign-on
SaaS — ApplicationsThe domain services we deliverRegistrul Interdicțiilor, SI RDP (Drumuri), Cancelarie, GRegistry, GDocs, …
PaaS — Building blocksReusable platform capabilities every app composes fromgSSO, GLog, GNotify, GStorage, GDocs, GRegistry, GDS
Framework & IaaSThe base + where it all runsGDS design system, the shared edge, Keycloak, Kubernetes / compose, PostgreSQL, Elasticsearch, object storage

A new application is mostly: its own domain logic (SaaS) + configuration of existing building blocks (PaaS) + deployment onto existing infrastructure (IaaS).

Within a single service the layering is the standard JHipster shape: Angular SPA → (HTTPS + OIDC/JWT) → web.rest.*Resource (DTOs only) → service.*Service (+ QueryService filtering, MapStruct mappers) → repository → PostgreSQL / Elasticsearch.

The building blocks (PaaS) — and how they map

Section titled “The building blocks (PaaS) — and how they map”

gStack uses GovStack-standard capability names for the abstract block, and each is implemented by a concrete gStack service, which in turn aligns with the Republic of Moldova’s national eIntegritate government services. This is the single mapping to keep in mind:

GovStack capabilitygStack implementationMoldova gov serviceWhat it provides
Identity / SSO (GPass)gSSO (governance control-plane over Keycloak)MPassLogin, tokens, roles, per-platform access grants
e-Signature (GSign)MSign integrationMSignSign an act; store signature + SHA-256 hash
Interoperability (GConnect)MConnect integrationMConnectResolve IDNP→population register, IDNO→fiscal; data exchange
Notifications (GNotify)GNotifyMNotifyMulti-channel notify (email/SMS/Viber/WebPush), templates
Audit & logging (GLog)GLogMLogImmutable WORM audit (hash-chained), cross-service investigation
Object storageGStorage—Buckets/objects (MinIO/S3), open-data catalog, SDK
DocumentsGDocs—Government documents: access levels, signing, OCR, archive
Registry of systemsGRegistry—Catalog of every information system + dependencies (RSI)
Design systemGDS—One visual language for every gStack SPA

Each block is explained in Building Blocks and under Platforms (PaaS); the integration libraries (MPass/MSign/MConnect/MNotify/MLog) ship as reusable Spring Boot starters, each with a mock mode for local development, mTLS, and retry.

GDocs vs GStorage: GStorage is the generic object-store beneath GDocs. GDocs is a document domain app (access levels, e-signature, OCR, archive) that stores its blobs through GStorage. GStorage never signs or OCRs.

A typical gStack application:

  1. Authenticates operators through gSSO (OIDC single sign-on) — no app mints its own tokens.
  2. Attaches signed acts via GSign / MSign (signature + hash stored on the act).
  3. Verifies subject identity (IDNP for persons, IDNO for legal entities) over GConnect / MConnect before persisting.
  4. Records lifecycle changes in an append-only audit trail — locally and forwarded to GLog.
  5. Notifies the right people/systems via GNotify.
  6. Publishes a public consultation API with GDPR field-masking.
  7. Looks and behaves consistently because every SPA is built on GDS, and the system itself is catalogued in GRegistry.

Creating and consulting an interdiction (Registrul Interdicțiilor):

  • An operator fills a form in the Angular SPA → POST /api/interdictii with an OIDC bearer.
  • InterdictieResource (authorized) → the service validates the lifecycle transition → MapStruct maps the DTO → the repository saves to PostgreSQL (auditing columns auto-stamped) → the record is mirrored to Elasticsearch → one row is appended to the write-only event log → GNotify alerts the approving officer.
  • On approval the status moves to ACTIV, another event is appended, and the record becomes publicly consultable.
  • A bank later calls GET /public/api/interdictii?idnp=… with an API key → the gateway rate-limits + validates → the service searches Elasticsearch for ACTIV records → applies a GDPR mask → logs the consultation to the audit trail → returns JSON.

The cross-cutting invariant across every app: the audit event log is append-only — no UPDATE, no DELETE, enforced by a Hibernate guard and a database trigger, and forwarded to GLog. It is built for forensic contestation.

  • Reference stack: JHipster (Spring Boot 3 + Angular), PostgreSQL (prod) / H2 (dev), Elasticsearch, Keycloak OIDC, Liquibase (append-only changelogs), MapStruct. The JDL file is the source of truth for each app’s entities — regenerate from it, then re-apply hand-written logic kept in separately-named classes.
  • Deliberately bilingual domain: Romanian legal terms are never translated (Interdictie, Entitate, statut); framework plumbing stays English.
  • Shared runtime glue: a single edge nginx (TLS + per-app vhosts on *.gstack.esempla.systems), Keycloak at sso.gstack.esempla.systems, a shared gstack-web Docker network, and the GitLab container/package registry for images and SDKs.
  • Where it runs: docker-compose on the shared hosts, plus a Kubernetes cluster for SI RDP; the docs portal you’re reading (Astro/Starlight + a local RAG assistant) is itself a gStack component.
SystemLayerStatus
Registrul Interdicțiilor · GRegistry · GDocs · CancelarieSaaSLive
SI RDP (Drumuri)SaaS (GovTech)Live (Kubernetes)
gSSO · GLog · GNotify · GStoragePaaSLive
Keycloak (identity runtime) · GDS + ConstructorFrameworkLive
gStack docs portal + assistantFrameworkLive
Portal Servicii Publice · CRM · Arhivă · GPaySaaS / PaaSDemo
GPower · GEvents · gAI · gInsight · gScheduler · gFlowPaaSPlanned
Generic multi-registry platform—Design

Explore each building block under Platforms (PaaS), each application under Softwares (SaaS), and the live estate on the System map.