BuildNot yet confirmed elsewhere1 publisher3 min readPublished
The compiler checks three of the seven things your coding agent had to get right
A Go admin framework changed its module pattern; the models still write the old one, because the old one was public for longer. The permission wiring fails with no error at all.
The Engineer · Build desk
What happened
- go-admin's earlier module style needed hand-written Api and Service files, at least seven functions per Api, and that style was public for years.
- Current guidance for single-table CRUD is three files, with binding, data-scope filtering and pagination handled by the framework's Actions.
- A usable module also needs seed rows in four tables, and missing any one produces the same silent symptom with no error logged.
- Adding a business module is now an invocable Skill whose every step points at a runnable reference file instead of a description.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- cost Style divergence bills late and in labour: it passes every automated gate, and the reunification work lands on whoever inherits the mixed codebase.
- constraint "It compiles and the endpoint responds" cannot serve as an acceptance gate here, because most of the artifacts a working module depends on are not code.
- decision Maintainers now have to rule on what counts as a hard rule versus documentation, since the convention file only works while it stays short enough to stay true.
- precedent Naming a reference implementation as the source of truth promotes it to a build dependency: it has to fail loudly when the recommended pattern moves, or agents inherit a stale one.
The corpus a model sampled is a repository's history, not its head commit. go-admin has been public for several years [3], and the hand-written Api-and-Service style was the only style for most of them [4]. The Actions pattern is what the codebase recommends now [5], which means it is thinner in the public record purely as a function of calendar time. The project's own writeup argues the retired style is a large share of what is visible on GitHub and is therefore overrepresented in training [14]. That is an assertion, not a measurement, and no numbers are offered. It is still the right shape of claim, and it applies to any repository whose current convention is younger than its git log.
Both styles compile, and nothing warns you [6]. Worth sitting with: a module that a user can actually reach spans at least seven artifacts, three code files plus rows across four tables, and only the three files are validated by anything that runs automatically [13]. Route registration, menu mounting, the menu-to-API relationship and the casbin policy all have to be seeded [7], and if one is missing the result is a sidebar with no menu item or a button that does nothing, with no error emitted [8]. The compiler and Postman both report success [16]. Debugging that means checking four candidates against one indistinguishable symptom, across two repositories.
The layering in the mitigation is ordered by decay rate, which is the part that generalises. The AGENTS.md files in both repos are kept deliberately short, restricted to rules that break something when ignored, with stack versions and commands left to go.mod and package.json so the file cannot fall out of sync with the code [9]. Underneath that is a reference implementation at app/demo/ that compiles, has tests, and runs in CI [1]. The stated reasoning is that prose goes stale and CI-exercised code does not [2]. A reference implementation has a failure mode that a document lacks: it can go red. A convention file is only ever as current as the last person who remembered to edit it.
The Skill layer turns adding a module into one invocable procedure covering table design, migration, scaffolding and the seed-data step, with each step pointing at a runnable file rather than asking the model to reconstruct one [10]. The frontend has a matching skill for list and form pages, and the coupling between them is a single string, the permission identifier [11]. The framework's deterministic generator still handles standard CRUD from a table definition, with generation reserved for business logic, refactors and tests [12].
The cost that gets underpriced is not the 403. It is that two weeks later nobody can tell which parts of the module were written by a person [17]. Review depends on being able to distinguish, and a model that writes your codebase's past writes something that reads like it belonged there.
What to watch
- Whether AGENTS.md stays short as edge cases accumulate, or grows back into a spec that drifts from go.mod and package.json.
- Whether app/demo actually breaks the build when the recommended pattern changes, since a stale reference is worse than none.
- Whether the project ever publishes a measurement of how often an agent still emits the retired Api-and-Service style with the Skill installed.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence28
- Adoption18
- Hype gap+18
- Incentives76
- Confidence42
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
The second layer is a reference implementation at app/demo/ that compiles, has tests, and runs in CI.
- [2]
The project's stated reasoning is that prose goes stale while code that CI keeps exercising does not, making it a more reliable source of truth than any spec document.
ReportedSupportedSource: go-admin project writeup on dev.to2 sources— create a free account to open themView cited source - [3]
go-admin is an open-source admin framework built on Gin and Vue 3, and has been public for several years.
- [4]
In earlier versions of go-admin, every business module required hand-written Api and Service files, at least seven functions per Api.
- [5]
The current go-admin codebase recommends an Actions-based pattern for single-table CRUD: a module needs only model, dto and router files, with parameter binding, data-scope filtering and pagination handled by the framework's built-in Actions.
- [6]
Both the old and new module styles compile, and the model will not warn you either way; the divergence is not noticed immediately.
- [7]
For a module to be usable in the UI, correct seed data is required across four tables: sys_api, sys_menu, sys_menu_api_rule and casbin_rule, covering route registration, menu mounting, the menu-to-API relationship and the permission policy.
- [8]
Miss any one of the four seed-data steps and the symptom is identical: the menu does not show up or the button does nothing, with no error anywhere.
- [9]
The first layer is AGENTS.md, a convention file for AI coding tools, one in the root of go-admin and one in go-admin-ui, kept deliberately short to rules that cause a real failure if ignored, with stack versions and commands left to go.mod and package.json so the file does not drift out of sync with the code.
- [10]
"Add a new business module" was turned from a paragraph of prose into a structured, invocable Skill: one end-to-end procedure covering table design, migration, Actions-mode scaffolding and the menu/permission seed data step, with every step pointing at a real runnable reference file rather than asking the model to reconstruct it from memory.
- [11]
The frontend has a matching skill for scaffolding a standard list plus form page, and the two skills are kept in sync by one shared string: the permission identifier.
- [12]
go-admin's built-in code generator handles the deterministic, reproducible part, standard CRUD from a table definition, while AI generation covers business logic, refactors and tests.
- [13]
A usable go-admin module spans at least seven artifacts: three code files plus rows in four tables, of which only the three code files are checked by compilation.
- [14]
According to the go-admin writeup, the older hand-written Api style makes up a large share of what is publicly visible on GitHub and is almost certainly overrepresented in what any model has seen during training.
ReportedInsufficientSource: go-admin project writeup on dev.to2 sources— create a free account to open themView cited source - [15]
By the time the two styles are mixed across a real codebase, unifying them again costs real engineering time.
- [16]
Generated modules usually compile and the endpoints respond, and can be hit from Postman, while the frontend menu item is missing or clicking into it returns a 403.
- [17]
Generated code written in a different style from the rest of the codebase leaves the team unable, two weeks later, to tell which parts were AI-written and which were not.
Sources
1 independent publisher whose own reporting we read for this story.
- dev.toWhy AI-Generated Code for Your Go Project Compiles But Still Needs a Rewrite
1 article · August 23, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- RBAC And Permission WiringFollow
- Deterministic Generators vs AI GenerationFollow
- AI Coding AgentsFollow
- Silent Failure ModesFollow
- Go Web And Admin FrameworksFollow
- Agent context engineeringFollow