Skip to content
CAI
Software that uses CAICheck a score

abiosoft/colima

67.0

Adequate · 24 September 2026

11.3k

lines of production code

Go

primary language

5

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Colima is a Go-based CLI tool for macOS and Linux that manages lightweight Linux virtual machines to run container runtimes like Docker, containerd, and Incus. It supports multiple isolated instances with configurable networking, storage, and Kubernetes integration via K3s. The system also provides specialized capabilities for AI workloads through GPU-accelerated model runners and handles background processes for real-time volume synchronization.

How it got here

2021 — Colima rebrand and Go rewrite

18 changes.

The project was rebranded from Limakube to Colima and rewritten in Go to support multiple container runtimes and Kubernetes. This period established the core CLI structure, environment abstractions, and configuration systems necessary for managing Docker, containerd, and Incus instances.

2022 — daemon architecture and networking overhaul

10 changes.

The project refactored its core architecture by introducing a dedicated daemon process to manage background services like vmnet and inotify, replacing inline task execution. This period also involved migrating the virtual network implementation to socket\_vmnet with support for bridged modes and IPv6, while establishing new utility packages for Lima VM management, filesystem abstraction, and OS interactions to improve testability and configuration handling.

2023–2026 — Runtime expansion and AI support

9 changes.

This period focused on expanding supported container runtimes by adding Incus and updating embedded images to Ubuntu 24.04, while introducing a new inotify daemon for real-time volume synchronization. Significant effort was also directed toward AI capabilities by implementing support for Docker Model Runner and Ramalama backends, alongside robust configuration validation and persistent state management to ensure system stability.

Features

Add Incus container runtime support

Users can now run containers using the Incus runtime in addition to existing options. This change introduces a new Incus backend that provisions a ZFS storage pool, configures a dedicated bridge network (192.168.100.0/24), and sets up host routing on macOS to make container IPs directly reachable. It includes logic to handle storage pool recovery from existing data disks and ensures the Incus daemon is properly started via systemd socket activation.

environment/container/incus · high confidence

Added SHA utility package for hashing strings

A new \util/shautil\ package has been introduced to provide convenient functions for computing SHA-1 and SHA-256 hashes of strings. This utility exposes \SHA1\ and \SHA256\ functions that return a standardized interface, allowing other parts of the application to easily generate and access hash digests in both string and byte formats.

util/shautil · high confidence

Introduce YAML configuration utility for preserving structure and comments

A new \yamlutil\ package has been added to handle configuration file serialization. This utility reads the embedded default configuration, traverses its YAML node structure, and applies values from the application config struct while preserving the original file's formatting, comments, and structural integrity. This ensures that user edits to configuration files (such as comments or specific formatting) are retained when the configuration is saved, rather than being overwritten by a standard marshaling process.

util/yamlutil · high confidence

Introduce dedicated daemon process for background services

The daemon command now manages background processes like vmnet and inotify as distinct, daemonized services rather than inline tasks. This change introduces a new daemon lifecycle with start, stop, and status commands, allowing users to run network and filesystem monitoring components independently in the background. The implementation includes proper process isolation via pid files, signal handling for graceful shutdown, and configurable options for network modes (shared/bridged) and inotify directories.

cmd/daemon · high confidence

Introduce environment abstraction layer with container runtime and VM interfaces

This change introduces a new \environment\ package that defines the core abstractions for managing the system's runtime environment. It adds a \Container\ interface for managing container runtimes (supporting features like forced shutdown and external data disks) and a \VM\ interface for managing virtual machines, including architecture detection (x86\_64/aarch64) and default VM type selection (VZ on macOS 13+, QEMU otherwise). It also includes a \Systemctl\ wrapper for managing systemd services within the guest VM, along with the corresponding tests for this service management logic.

environment · high confidence

Introduce inotify daemon for real-time container volume synchronization

A new inotify background process has been added to the daemon to monitor changes in mounted container volumes and sync them to the guest VM in real time. The process detects volume changes for both Docker and containerd (scanning all namespaces) runtimes, filters out redundant child directories, and applies file permission changes inside the guest. It includes rate-limiting to handle high-frequency events and waits for the VM to be ready before starting.

daemon/process/inotify · high confidence

Introduce limautil package for Lima VM management

A new limautil package has been added to centralize interactions with the Lima VM environment. This includes utilities for managing runtime disks (create, resize, delete, and check existence), downloading and caching disk images with optional mirror support, retrieving instance details and IP addresses, and handling SSH configuration generation. These changes provide a structured foundation for improved disk management and instance reporting within the Lima runtime.

environment/vm/lima/limautil · high confidence

Introduce new CLI commands for profile management, instance listing, and shell access

The command-line interface gains several new subcommands to improve workflow and manageability. Users can now clone existing profiles with \colima clone\, list all instances with \colima list\ (including JSON output support), and restart or delete profiles with dedicated \colima restart\ and \colima delete\ commands. Direct shell access is simplified via \colima ssh\, and SSH configuration details are exposed through \colima ssh-config\. Additionally, \colima prune\ allows users to clear cached assets, \colima update\ refreshes the container runtime, and \colima completion\ generates shell completion scripts for bash, zsh, fish, and PowerShell.

cmd · high confidence

Introduce persistent internal state store for VM configuration

A new store mechanism has been added to persist internal Colima instance configuration, specifically tracking whether the runtime disk has been formatted, which container runtime it is provisioned for, and whether Ramalama has been provisioned. This allows the system to maintain state across restarts regarding disk and AI model setup.

store · high confidence

Introduces structured command chaining and interactive command execution

The CLI now supports a new \CommandChain\ abstraction in \cli/chain.go\ that allows commands to be executed sequentially with stage logging, non-fatal error handling (warnings instead of termination), and built-in retry logic. Additionally, \cli/command.go\ provides a unified interface for running external commands, including an interactive mode that pipes stdin/stdout/stderr, and a \Prompt\ function for user input that ensures terminal formatting is reset after the question.

cli · high confidence

Introduction of daemon process management interfaces

The daemon now exposes a \Process\ interface and associated dependency management logic within the \daemon/process\ package. This change introduces the structural foundation for managing background processes, including methods to start processes, check their status, and handle their dependencies (including root access requirements). This allows the daemon to more robustly manage lifecycle and prerequisites for its internal background tasks.

daemon/process · high confidence

Introduction of host environment abstraction for command execution

The system now introduces a dedicated host environment implementation that standardizes how external commands are executed on the host machine. This change provides a structured interface for running commands with specific environment variables and working directories, supporting both standard output capture and interactive execution modes. Users benefit from more consistent command handling and better integration with the application's logging and terminal output systems.

environment/host · high confidence

Lima VM environment implementation and runtime disk management

This change introduces the Lima-specific implementation for the VM environment, including the new \environment/vm/lima\ package. It adds support for managing a dedicated runtime disk (separate from the root disk) for Docker, containerd, and Incus, ensuring data isolation and proper formatting. The implementation also handles certificate copying from the host to the guest (\/etc/docker/certs.d\ and \/etc/ssl/certs\), configures DNS via dnsmasq with custom gateway support, manages network daemon startup (vmnet/inotify), and provides file system operations for the guest. Additionally, it includes logic to determine the appropriate VM type (QEMU, VZ, or Krunkit) based on host architecture and OS version.

environment/vm/lima · high confidence

New OS utility helpers for environment variables and executable detection

A new \util/osutil\ package has been introduced to provide reusable utilities for interacting with the operating system. This includes an \EnvVar\ type that simplifies checking for the existence of environment variables, retrieving their string or boolean values, and appending paths to existing environment variables. Additionally, the package adds an \Executable\ function that robustly determines the path of the currently running binary, prioritizing the \COLIMA\_BINARY\ environment variable for nested processes and falling back to command-line arguments if detection fails. A \Socket\ helper is also included to manage Unix socket address formatting.

util/osutil · high confidence

New configurable downloader with resume support and curl option

The download utility has been refactored to support two download backends: the default Go native HTTP client and an optional curl-based downloader. Users can now switch to curl (which honors .curlrc settings) by setting the COLIMA\_DOWNLOADER environment variable to 'curl'. The new downloader implementation adds robust support for resuming interrupted downloads, handling HTTP 416 errors gracefully, and validating file integrity using SHA-256/SHA-512 checksums. It also includes improved error messages for network issues, DNS failures, and HTTP status codes, along with a progress bar for downloads.

util/downloader · high confidence

New debutil package for managing Debian package updates

Added a new \debutil\ package that provides utilities for managing Debian-based package updates within the guest environment. It includes functions to check for upgradable packages and install them using \apt\, integrated into a command chain that refreshes the package manager, checks for updates, and applies them if available.

util/debutil · high confidence

New filesystem abstraction utility for testable file operations

Added a new \fsutil\ package that provides a \FileSystem\ interface wrapping standard \os\ operations like \MkdirAll\ and \Open\. This abstraction allows the application to swap the underlying filesystem implementation, specifically enabling the use of a \FakeFS\ mock for testing purposes without relying on the real disk.

util/fsutil · high confidence

New utility functions for macOS detection, port management, and network validation

The util package introduces several new helper functions to support platform-specific logic and network operations. On macOS, it adds robust version and chip detection (including M-series chip identification and macOS 13/15 checks) via \system\_profiler\ and \sw\_vers\, along with a check for Rosetta availability. It also provides utilities for finding available TCP ports (including a range search starting from a specific port), retrieving host IPv4 addresses, validating subnet availability against existing routes, and parsing shell command strings. Additionally, it includes helpers to verify the presence of \qemu-img\ and \krunkit\ binaries, and a template rendering function.

util · high confidence

New verbose terminal output with scrollable header support

The terminal utility now includes a new verbose writer that displays command output in a scrollable view with a fixed header, improving readability for long subprocess outputs. This change introduces a new \output.go\ module that handles ANSI control sequence stripping, line wrapping, and screen updates, along with a \terminal.go\ module providing alternate screen buffer management and signal handling for clean terminal restoration. Tests have been added to verify line counting and text normalization logic.

util/terminal · high confidence

Project renamed from Limakube to Colima with comprehensive documentation and build infrastructure

The project has been rebranded from Limakube to Colima, shifting its focus from a specific Lima-based Kubernetes setup to a broader container runtime manager supporting Docker, Containerd, and Incus on macOS and Linux. The legacy \limakube\ bash script has been removed and replaced with a Go-based CLI tool, accompanied by a new Makefile for building and installing the binary, a Nix flake for declarative package management, and a \.golangci.yml\ configuration enabling gocritic linting. The README has been completely rewritten to document the new features, including multiple instance support, GPU-accelerated AI workloads via krunkit, and installation via Homebrew, MacPorts, Nix, and Mise.

(repo-wide) · high confidence

Support for Docker Model Runner and Ramalama AI model backends

The model layer now supports two distinct AI model runners: Docker Model Runner and Ramalama. A new \Runner\ interface and \runner.go\ dispatcher allow users to select between these backends, with Docker Model Runner serving as the default. The \docker.go\ file implements logic to inspect, pull, and serve models via the \docker model\ CLI, including handling GGUF file paths within the VM. The \ramalama.go\ file adds support for the Ramalama runner, enabling installation via pipx, model listing, and pulling models using the \ramalama\ CLI. Common prerequisites, such as requiring the Docker runtime and Krunkit VM type for GPU access, are validated in the runner setup.

model · high confidence

Behavioural changes

Automated host network permission setup via embedded sudoers

The application now automatically configures host-level network permissions by installing a sudoers file located in the embedded assets. This change introduces a mechanism to read the embedded sudoers configuration and apply it to the host system, ensuring the necessary privileges are granted for network operations without manual intervention.

embedded · high confidence

Colima application core refactored to support multiple container runtimes and Kubernetes

The application entry point has been rewritten to support Docker, containerd, and Incus as container runtimes, with Kubernetes (k3s) integration available for Docker and containerd. The startup sequence now explicitly provisions and starts the selected container runtime and Kubernetes before running provision scripts, while the shutdown process checks VM responsiveness before stopping containers. The app also persists runtime and Kubernetes configuration and auto-generates SSH config upon start.

app · high confidence

Config validation rejects invalid network and mount settings

The configuration manager now validates user settings before applying them, preventing silent failures or runtime errors. It rejects mount paths containing spaces, enforces that the network gateway address ends in octet 2, restricts custom subnets to shared mode and non-vz VM types, and validates that NAT66 prefixes are proper IPv6 ULA addresses. These checks ensure that only supported and correctly formatted configurations are accepted.

config/configmanager · high confidence

Daemon process management refactored to support network and inotify configurations

The daemon entry point has been restructured to explicitly manage background processes based on configuration. It now passes network settings (subnet, mode, bridge interface, NAT66 prefix) to the vmnet process when a network address is configured, and passes mount paths and runtime details to the inotify process when filesystem monitoring is enabled. This change centralizes the wiring of these specific daemon capabilities within the daemon package.

daemon · high confidence

Docker runtime reimplementation with context isolation and systemd-based host-gateway configuration

The Docker container runtime implementation has been rewritten to improve stability and multi-profile support. It now creates a dedicated Docker context for each profile to prevent clashes with other Docker servers, automatically activating it if configured. The daemon configuration is managed via a systemd drop-in unit, which sets the host-gateway IP to the loopback interface to resolve proxy connectivity issues, while also enforcing cgroupfs driver settings for k3s compatibility. Additionally, the runtime provisions a custom containerd configuration, respects the DOCKER\_CONFIG environment variable, and ensures the user is added to the docker group to allow non-root access.

environment/container/docker · high confidence

Enforce minimum Lima version and support development builds

The core module now validates the installed Lima version against a minimum supported release (v0.18.0) to prevent compatibility issues. It also explicitly allows Lima development versions (indicated by 'HEAD'), issuing a warning if the dev version is lower than the minimum supported release, ensuring users are aware of potential risks when using non-stable Lima builds.

core · high confidence

Introduce structured configuration model and XDG-compliant directory resolution

This change introduces a new, structured configuration system for Colima, replacing the previous implicit or flat configuration approach. The \config\ package now defines explicit Go structs for all settings, including CPU, memory, disk, architecture, network (with support for custom subnets, gateways, and DNS hosts), VM type, mounts, and runtime options. Additionally, the application's directory resolution logic has been updated to respect the \XDG\_CONFIG\_HOME\ and \XDG\_CACHE\_HOME\ environment variables on non-macOS systems, while maintaining backward compatibility with \\~/.colima\ on macOS. This provides users with a more robust and standard-compliant way to manage Colima's configuration and cache files.

config · high confidence

Kubernetes runtime rewritten in Go with K3s and customizable ports

The Kubernetes integration has been rewritten in Go, replacing the previous Minikube-based implementation with K3s (defaulting to v1.35.0+k3s1). This change introduces a customizable K3s listen port, allowing users to override the default API server port via configuration. The new implementation handles CNI configuration installation, kubeconfig provisioning with profile-aware context switching, and OCI image caching for both containerd and Docker runtimes, ensuring a more robust and configurable Kubernetes environment.

environment/container/kubernetes · high confidence

Lima VM configuration schema updated to support new features

The Lima VM configuration structure has been updated to include support for additional disks, nested virtualization, and UDP port forwarding. The configuration now allows specifying additional disk images with formatting options, enables nested virtualization settings, and supports UDP protocol in port forwarding rules. The schema also introduces support for the Krunkit VM type and updated network configuration options.

environment/vm/lima/limaconfig · high confidence

Refactor root command to dedicated package with profile and verbose flags

The root CLI command has been moved into its own \root\ package. This change introduces persistent flags for managing multiple instances via the \--profile\ (or \-p\) option, which respects the \COLIMA\_PROFILE\ environment variable and positional arguments. It also adds \--verbose\ and \--very-verbose\ flags to control logging levels (Debug and Trace) via the logrus library.

cmd/root · high confidence

Refactored CLI entry point to use root command execution

The main entry point for the Colima CLI has been refactored to explicitly import and execute the root command via \root.Execute()\. This change consolidates the initialization of subcommands (including the daemon and embedded assets) into the root command structure, ensuring a cleaner and more modular startup sequence for the application.

cmd/colima · high confidence

Switch to socket\_vmnet with bridged mode and configurable networking

The virtual network daemon now uses the socket\_vmnet binary (installed to /opt/colima/bin) instead of the previous implementation. This change introduces support for bridged networking mode, allows configuration of the shared network subnet, and adds support for a configurable NAT66 prefix for IPv6. Users benefit from more flexible network configurations and potentially improved stability with the new underlying daemon.

daemon/process/vmnet · high confidence

Updated embedded disk images to Ubuntu 24.04 with Incus support

The embedded disk images have been updated to Ubuntu 24.04 minimal cloud images (v0.10.4) for both arm64 and amd64 architectures. This update adds support for the Incus container runtime alongside the existing none, docker, and containerd runtimes. The system now uses a new automated script to download these images and verify their integrity via SHA512 checksums.

embedded/images · high confidence

User-configurable containerd and BuildKit settings

The containerd runtime now supports user-provided configuration for both containerd and BuildKit. Users can override default settings by placing custom \config.toml\ and \buildkitd.toml\ files in their profile directory (\\~/.colima/\<profile\>/containerd/\) or in the central XDG config directory (\\~/.config/containerd/\ and \\~/.config/buildkit/\). The system resolves these in order of priority: per-profile overrides take precedence, followed by central configs, with embedded defaults used only if no user configuration is found. This allows users to customize runtime behavior without modifying internal code.

environment/container/containerd · high confidence

Test coverage

Automated build and integration testing for socket\_vmnet

Added build\_vmnet.sh to automate the compilation and packaging of socket\_vmnet (v1.1.5) for x86\_64 and arm64 architectures, ensuring the binaries are correctly embedded. Added integration.sh to validate Colima's runtime (Docker and containerd) and Kubernetes functionality across both architectures, including DNS resolution and image building.

scripts · high confidence

Dependencies

Updated Go module dependencies

The project's Go dependencies have been updated to their latest versions, including github.com/spf13/cobra (v1.10.2), github.com/fatih/color (v1.19.0), github.com/sirupsen/logrus (v1.9.4), and golang.org/x/term (v0.45.0).

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 70 → 67 (-3.4)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 84 → 89 (+4.8)
  • Architecture 100 → 95 (-5.4)
  • Maturity 57 → 57 (+0.2)
  • Readiness 81 → 73 (-8.1)
  • Security 80 → 70 (-9.7)

Resolved (11)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (7 lines × 2) (environment/host/host.go)
  • Duplicated block (7 lines × 2) (environment/host/host.go)
  • Duplicated block (8 lines × 2) (environment/container/kubernetes/k3s.go)
  • Duplicated block (8 lines × 2) (environment/vm/lima/disk.go)
  • Medium IaC: CKV_DOCKER_3 (integration/Dockerfile)
  • No exposed public API
  • Off-boarding risk: anonymized user #1
  • Scanner failed to run — not a clean result
  • Test reliability not included

New (36)

  • CI runs a third-party container image from a mutable tag (.github/workflows/_docker.yml)
  • Dependency pinned to a stale untagged commit: github.com/google/shlex
  • Duplicated block (11 lines × 2) (cmd/kubernetes.go)
  • Duplicated block (11 lines × 2) (cmd/model.go)
  • Duplicated block (8 lines × 2) (environment/container/kubernetes/k3s.go)
  • Duplicated block (8 lines × 2) (environment/host/host.go)
  • Duplicated block (8 lines × 2) (environment/host/host.go)
  • Duplicated block (8 lines × 2) (environment/vm/lima/disk.go)
  • Duplicated block (8 lines × 2) (environment/vm/lima/limautil/disk.go)
  • Duplicated block (8 lines × 3) (cmd/model.go)
  • Duplicated block (8 lines × 4) (environment/container/containerd/containerd.go)
  • FunctionTooLong: cmd.prepareConfig (cmd/start.go)
  • FunctionTooLong: lima.newConf (environment/vm/lima/yaml.go)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Hotspot: config/configmanager/configmanager.go (config/configmanager/configmanager.go)
  • Medium IaC: WD-DOCKER-0010 (integration/Dockerfile)
  • …and 16 more

Changes since last survey

  • 7 commits — 6 feature/other, 1 fixes

By area

  • cmd/start.go — 2 commits
  • environment/vm — 2 commits
  • cmd/daemon — 1 commit
  • config/configmanager — 1 commit
  • util/downloader — 1 commit

Notable commits

  • fix: net: fix missing network address when emulating a foreign arch (#1638)
  • change: cli: make mount writable suffix case insensitive (#1618)
  • change: cli: trim whitespace and reject empty dns-host entries (#1616)
  • change: core: recover from HTTP 416 when resuming a cached download (#1642)
  • change: dns: detect installed dnsmasq with dpkg-query (#1640)
  • change: net: add configurable nat66Prefix for shared networking (#1639)
  • change: net: add configurable subnet for shared networking (#1628)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

abiosoft/colima was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 24 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit bba803d3d6fa9372a60f747e5dad4c8e80db7cde — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-5f8d0eb43fd7.