Lightweight full-stack Golang boilerplate
Build apps in Go the light, clean and fast way. Gin, Vue 3 and strict rules under which people and AI write equally good code.
Clone the repo and let AI do the work
What Gin GoKick does
01–05
Getting started
-
01
Go and Gin
One binary serves the templates and the frontend build.
-
02
Config from .env
Variables are checked. A typo stops the start, not production.
-
03
Rules in AGENTS.md
People and AI write by the same rules, and tools enforce them.
-
04
Pre-commit gate
One block runs the lint, types and tests of CI before a commit.
-
05
Pre-push hook
Lefthook checks the branch name and commit messages before a push.
06–09
Database
-
06
PostgreSQL 18
The app connects through pgx, one command starts the database.
-
07
goose migrations
They run at start under a lock, so instances never collide.
-
08
sqlc instead of an ORM
You write SQL, and typed Go functions are generated from it.
-
09
Tests with a database
Each test gets an empty migrated schema, in CI and locally.
10–13
Deployment
-
10
Docker image
The image runs on Alpine without root and checks the database.
-
11
Dokploy guide
Guides the first deploy with Postgres, Cloudflare and Grafana.
-
12
Graceful restart
On shutdown, requests in progress finish within five seconds.
-
13
Emails over SMTP
Mailpit catches them locally, Amazon SES sends them live.
14–17
Frontend
-
14
Vite the Laravel way
HMR runs through Go, so development gets the production CSP.
-
15
Vue 3 and Tailwind 4
The SPA with vue-router and the Go pages share one style.
-
16
Go types and guards
tsgen writes types and guards, so API changes fail to compile.
-
17
Routes by sign-in
Every route says who may open it, and tabs share the sign-in.
18–20
Go templates
-
18
SSR with html/template
The server renders the home page, the 404 and the app entry in each language.
-
19
Guarded templates
Checks catch missing files, untranslated text and unknown keys in templates.
-
20
Mail templates
Mails come from Go templates and reach users in their own language.
21–24
Components
-
21
Shared elements
Icons, dropdowns and tooltips look the same in Vue and Go.
-
22
Data grid
The URL keeps the filters, and a selection runs bulk actions.
-
23
Forms
Text and number fields show the API error right below them.
-
24
Toasts and dialogs
Toasts survive navigation, and a modal confirms risky actions.
25–28
Languages and SEO
-
25
Languages in the URL
Languages live in the URL with hreflang, accounts keep theirs.
-
26
Translation checks
tools/i18n catches missing keys, unused texts and bad plurals.
-
27
ICU in Go and Vue
Plurals and numbers look the same in Go and in the browser.
-
28
Titles and sharing
A missing title, description or share image fails the checks.
29–33
Security
-
29
Sign-in
Passwords use argon2id, the attempt limit spans all instances.
-
30
Signed-in devices
Users see every device with its last IP and can sign it out.
-
31
CSP with a nonce
A nonce and Trusted Types keep injected scripts from running.
-
32
CSRF without tokens
http.CrossOriginProtection refuses requests from other sites.
-
33
A+ headers
HSTS, COOP, CORP and Permissions-Policy come from the server.
34–36
Sentry and telemetry
-
34
Sentry for Go and Vue
Links browser errors to the backend, releases are commit SHAs.
-
35
Prometheus metrics
Prometheus gets the metrics and Grafana a ready dashboard.
-
36
JSON logs
slog writes trace_id and user_id, never an email or a name.
37–40
Analytics and consent
-
37
Cookie banner
Refusing is as easy as accepting, and the choice can change any time.
-
38
Analytics and conversions
GA4, Ads and Meta measure and count conversions only after consent.
-
39
Hashed email
Only Ads and Meta get the email, and only as SHA-256.
-
40
Events from Go
Go defines the events, and typecheck lets none go unmapped.