// the find
tx7do/go-wind-admin
Enterprise admin platform in Go on go-kratos (Ent): Protobuf as the single API contract with full-stack codegen (Go APIs + TypeScript clients, one-click CRUD scaffolds), multi-tenant RBAC (Casbin / OPA / Zanzibar), TOTP MFA, 180-day audit logging aligned with China MLPS 2.0 (等保) — with Vue3 (Vben / Element Plus) and React 19 (Antd) frontends.
GoWind Admin is a Go admin platform built on go-kratos, with Ent as the ORM and Protobuf as the single API contract that generates the Go services and TypeScript clients. It ships three alternative frontends (Vue Vben, Element Plus, and React 19 with Ant Design), and the docs and most inline comments are in Chinese. It suits a team that wants a self-hosted back office with multi-tenant RBAC and can read Chinese documentation.
The Protobuf pipeline is the real asset: one .proto drives the Go HTTP and gRPC code, the validators, and TypeScript clients for all three frontends, and the generated code is checked in under api/gen. Tenant isolation is enforced in the data layer rather than in handlers: Ent Privacy policies inject read filters, reject forged tenant IDs on create, and add tenant predicates to update and delete, backed by a fail-closed (path, method) check against the API table. The audit design is more considered than most admin templates, with six log categories, a 180-day retention window that exports JSONL archives before pruning, and IP geolocation on login and operation logs. The authorization engine can be swapped between Casbin and OPA, and every decision is written to an evaluation log with a trace ID.
Three frontends is a real maintenance cost, and the README tells adopters to keep one and delete the other two. The repo already carries parity and mirror workflows, which suggests drift is a live problem, and the feature table shows it: position import resolves the org-unit column only in the Element Plus frontend, while the other two omit that field with a comment calling it future work. The compliance section is a checklist mapped to technical controls, and it correctly says it does not replace an MLPS 2.0 assessment, so treat it as a head start rather than a finished answer. The scope is wide for one project: pgvector RAG, a Lua and JavaScript scripting engine, a notification system with webhook signing styles, online session management, and a build-tag switch between Ent and GORM, which doubles the persistence surface to keep tested. The compose file pulls bitnami/redis:latest with no pinned version, which will eventually break a reproducible deploy.