How gStack works
Acest conținut nu este încă disponibil în limba selectată.
gStack is the Republic of Moldova’s shared, sovereign government technology stack — a common foundation of reusable government building blocks plus the domain applications built on top of them. The guiding idea: build a public-service capability once and reuse it everywhere, hosted on national infrastructure, with a full append-only audit trail, delivered trilingually (RO / RU / EN).
gStack follows the GovStack building-block model: a new service is mostly the composition of existing blocks (identity, signing, interoperability, audit, notifications, storage) plus its own domain logic.
Principles
Section titled “Principles”- Sovereign by default — every component is self-hostable on national (on-prem / govcloud) infrastructure; no mandatory external dependencies.
- Build once, reuse — services compose from shared platform blocks instead of re-implementing plumbing.
- Auditable & compliant — an append-only event log records every state change, built for contestation, investigation and data-protection compliance.
- Trilingual — every service ships in Română, Русский and English from day one.
The layered architecture
Section titled “The layered architecture”gStack reads top-to-bottom: citizen channels rest on applications, applications rest on platform blocks, and everything runs on shared infrastructure.
| Layer | What it is | In gStack |
|---|---|---|
| Channels | How people reach services | Public-service portal, mobile, single sign-on |
| SaaS — Applications | The domain services we deliver | Registrul Interdicțiilor, SI RDP (Drumuri), Cancelarie, GRegistry, GDocs, … |
| PaaS — Building blocks | Reusable platform capabilities every app composes from | gSSO, GLog, GNotify, GStorage, GDocs, GRegistry, GDS |
| Framework & IaaS | The base + where it all runs | GDS design system, the shared edge, Keycloak, Kubernetes / compose, PostgreSQL, Elasticsearch, object storage |
A new application is mostly: its own domain logic (SaaS) + configuration of existing building blocks (PaaS) + deployment onto existing infrastructure (IaaS).
Within a single service the layering is the standard JHipster shape:
Angular SPA → (HTTPS + OIDC/JWT) → web.rest.*Resource (DTOs only) → service.*Service (+ QueryService filtering, MapStruct mappers) → repository → PostgreSQL / Elasticsearch.
The building blocks (PaaS) — and how they map
Section titled “The building blocks (PaaS) — and how they map”gStack uses GovStack-standard capability names for the abstract block, and each is implemented by a concrete gStack service, which in turn aligns with the Republic of Moldova’s national eIntegritate government services. This is the single mapping to keep in mind:
| GovStack capability | gStack implementation | Moldova gov service | What it provides |
|---|---|---|---|
| Identity / SSO (GPass) | gSSO (governance control-plane over Keycloak) | MPass | Login, tokens, roles, per-platform access grants |
| e-Signature (GSign) | MSign integration | MSign | Sign an act; store signature + SHA-256 hash |
| Interoperability (GConnect) | MConnect integration | MConnect | Resolve IDNP→population register, IDNO→fiscal; data exchange |
| Notifications (GNotify) | GNotify | MNotify | Multi-channel notify (email/SMS/Viber/WebPush), templates |
| Audit & logging (GLog) | GLog | MLog | Immutable WORM audit (hash-chained), cross-service investigation |
| Object storage | GStorage | — | Buckets/objects (MinIO/S3), open-data catalog, SDK |
| Documents | GDocs | — | Government documents: access levels, signing, OCR, archive |
| Registry of systems | GRegistry | — | Catalog of every information system + dependencies (RSI) |
| Design system | GDS | — | One visual language for every gStack SPA |
Each block is explained in Building Blocks and under Platforms (PaaS); the integration libraries (MPass/MSign/MConnect/MNotify/MLog) ship as reusable Spring Boot starters, each with a mock mode for local development, mTLS, and retry.
GDocs vs GStorage: GStorage is the generic object-store beneath GDocs. GDocs is a document domain app (access levels, e-signature, OCR, archive) that stores its blobs through GStorage. GStorage never signs or OCRs.
How a service composes the blocks
Section titled “How a service composes the blocks”A typical gStack application:
- Authenticates operators through gSSO (OIDC single sign-on) — no app mints its own tokens.
- Attaches signed acts via GSign / MSign (signature + hash stored on the act).
- Verifies subject identity (IDNP for persons, IDNO for legal entities) over GConnect / MConnect before persisting.
- Records lifecycle changes in an append-only audit trail — locally and forwarded to GLog.
- Notifies the right people/systems via GNotify.
- Publishes a public consultation API with GDPR field-masking.
- Looks and behaves consistently because every SPA is built on GDS, and the system itself is catalogued in GRegistry.
A request, end to end
Section titled “A request, end to end”Creating and consulting an interdiction (Registrul Interdicțiilor):
- An operator fills a form in the Angular SPA →
POST /api/interdictiiwith an OIDC bearer. InterdictieResource(authorized) → the service validates the lifecycle transition → MapStruct maps the DTO → the repository saves to PostgreSQL (auditing columns auto-stamped) → the record is mirrored to Elasticsearch → one row is appended to the write-only event log → GNotify alerts the approving officer.- On approval the status moves to ACTIV, another event is appended, and the record becomes publicly consultable.
- A bank later calls
GET /public/api/interdictii?idnp=…with an API key → the gateway rate-limits + validates → the service searches Elasticsearch forACTIVrecords → applies a GDPR mask → logs the consultation to the audit trail → returns JSON.
The cross-cutting invariant across every app: the audit event log is append-only — no UPDATE, no DELETE, enforced by a Hibernate guard and a database trigger, and forwarded to GLog. It is built for forensic contestation.
How it’s built and run
Section titled “How it’s built and run”- Reference stack: JHipster (Spring Boot 3 + Angular), PostgreSQL (prod) / H2 (dev), Elasticsearch, Keycloak OIDC, Liquibase (append-only changelogs), MapStruct. The JDL file is the source of truth for each app’s entities — regenerate from it, then re-apply hand-written logic kept in separately-named classes.
- Deliberately bilingual domain: Romanian legal terms are never translated (
Interdictie,Entitate,statut); framework plumbing stays English. - Shared runtime glue: a single edge nginx (TLS + per-app vhosts on
*.gstack.esempla.systems), Keycloak atsso.gstack.esempla.systems, a sharedgstack-webDocker network, and the GitLab container/package registry for images and SDKs. - Where it runs: docker-compose on the shared hosts, plus a Kubernetes cluster for SI RDP; the docs portal you’re reading (Astro/Starlight + a local RAG assistant) is itself a gStack component.
Status at a glance
Section titled “Status at a glance”| System | Layer | Status |
|---|---|---|
| Registrul Interdicțiilor · GRegistry · GDocs · Cancelarie | SaaS | Live |
| SI RDP (Drumuri) | SaaS (GovTech) | Live (Kubernetes) |
| gSSO · GLog · GNotify · GStorage | PaaS | Live |
| Keycloak (identity runtime) · GDS + Constructor | Framework | Live |
| gStack docs portal + assistant | Framework | Live |
| Portal Servicii Publice · CRM · Arhivă · GPay | SaaS / PaaS | Demo |
| GPower · GEvents · gAI · gInsight · gScheduler · gFlow | PaaS | Planned |
| Generic multi-registry platform | — | Design |
Explore each building block under Platforms (PaaS), each application under Softwares (SaaS), and the live estate on the System map.