# ai-compliance-sdk Go/Gin service providing AI-Act compliance analysis: iACE impact assessments, UCCA rules engine, hazard library, training/academy, audit, escalation, portfolio, RBAC, RAG, whistleblower, workshop. **Port:** `8090` → exposed `8093` (container: `bp-compliance-ai-sdk`) **Stack:** Go 1.24, Gin, pgx, Postgres. ## Architecture (target — Phase 2) ``` cmd/server/main.go # Thin entrypoint (<50 LOC) internal/ ├── app/ # Wiring + lifecycle ├── domain// # Types, interfaces, errors ├── service// # Business logic ├── repository/postgres/ # Repo implementations ├── transport/http/ # Gin handlers + middleware + router └── platform/ # DB pool, logger, config, httperr ``` See `../AGENTS.go.md` for the full convention. ## Run locally ```bash cd ai-compliance-sdk go mod download export COMPLIANCE_DATABASE_URL=... go run ./cmd/server ``` ## Tests ```bash go test -race -cover ./... golangci-lint run --timeout 5m ./... ``` Co-located `*_test.go`, table-driven. Repo layer uses testcontainers-go (or the compose Postgres) — no SQL mocks. ## Public API surface Handlers under `internal/api/handlers/` (Phase 2 moves to `internal/transport/http/handler/`). Health at `GET /health`. iACE, UCCA, training, academy, portfolio, escalation, audit, rag, whistleblower, workshop subresources. Every route is a contract. ## Environment | Var | Purpose | |-----|---------| | `COMPLIANCE_DATABASE_URL` | Postgres DSN | | `LLM_GATEWAY_URL` | LLM router for rag/iACE | | `QDRANT_URL` | Vector search | ## Don't touch DB schema. Hand-rolled migrations elsewhere own it.