Skip to content
CAI
Software that uses CAICheck a score

alibaba/nacos

42.8

Weak · 5 August 2026

303.5k

lines of production code

Java

with JavaScript, TypeScript

3

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a comprehensive platform for managing AI-driven resources, including agents, skills, prompts, and MCP servers, alongside traditional service discovery and configuration management capabilities. It provides a robust framework for the full lifecycle management of AI assets, featuring versioning, import/export mechanisms, and a configurable publish pipeline for validation and auditing. The architecture supports both HTTP and gRPC communication, with dedicated APIs for querying, registering, and subscribing to changes in AI resources and standard Nacos services.

How it got here

2018–2020 — API and remote communication modernization

85 changes.

This period focused on modernizing the Nacos architecture by introducing a comprehensive gRPC-based remote communication layer and expanding the public API with new annotations, selectors, and configuration models. The work also established a modular plugin-based system for authentication and configuration changes, while introducing a new CMDB module and Istio integration to support service mesh and external data integration.

2021–2025 — AI module and plugin architecture

114 changes.

This period focused on introducing a comprehensive AI module supporting Model Context Protocol (MCP) servers, A2A agents, and skills, alongside a new plugin-based architecture for authentication, encryption, and tracing. The work also included significant refactoring of the API layer to support distributed locks, ability negotiation, and standardized error handling.

2026 — AI resource and pipeline management

70 changes.

This period focused on building a comprehensive AI resource management system, introducing support for Skills, Prompts, and AgentSpecs with full lifecycle, versioning, and caching. A pluggable pipeline framework was added to handle import, security scanning, and publishing workflows for these resources. Additionally, the codebase expanded database plugin support for MySQL, Oracle, and PostgreSQL, and modernized the frontend stack.

Features

AI module initialization and configuration infrastructure

The AI module now includes a suite of Spring configuration and initialization components that manage the module's lifecycle and data. An \AiEnabledFilter\ controls whether the AI module is active based on the \nacos.extension.ai.enabled\ property and the current function mode. A storage initializer registers \AiResourceStorage\ implementations via SPI. A new \PipelineConfiguration\ sets up the publish pipeline execution framework. Additionally, bootstrap initializers are added to automatically import built-in AgentSpecs and Skills on startup, and a migration task is introduced to move legacy prompt data into the new storage architecture.

ai/src/main/java/com/alibaba/nacos/ai/config · high confidence

Add A2A 1.0.0 agent card model classes

Added a new set of Java model classes in the \api/src/main/java/com/alibaba/nacos/api/ai/model/a2a\ package to support the A2A 1.0.0 protocol. This includes \AgentCard\ and its related components such as \AgentCapabilities\, \AgentEndpoint\, \AgentInterface\, \AgentProvider\, \AgentSkill\, and \SecurityScheme\. These models enable the system to handle agent registration, versioning, and interface definitions according to the updated A2A specification.

api/src/main/java/com/alibaba/nacos/api/ai/model/a2a · high confidence

Add AI pipeline and storage plugin providers

The Nacos AI module now exposes two new plugin providers that bridge internal AI services to the core plugin manager: AiPipelinePluginProvider, which registers PublishPipelineService instances for message publishing, and AiStoragePluginProvider, which registers AiResourceStorage implementations for AI skill and resource persistence. These providers enable the system to discover and manage AI pipeline and storage backends through the standard plugin mechanism.

ai/src/main/java/com/alibaba/nacos/ai/plugin · medium confidence

Add AI registry adaptor for MCP and Skills registry APIs

The ai-registry-adaptor module introduces new components to support the MCP (Model Context Protocol) and Skills registry APIs. This includes the NacosAiRegistry application entry point, startup phase, and package exclude filter. HTTP path configuration allows '/' in paths and enables URL-encoded slashes for the MCP community API. Controllers (McpRegistryController, SkillsRegistryController) expose endpoints for listing and retrieving MCP servers and skills, with conditional activation via nacos.ai.mcp.registry.enabled and nacos.ai.skill.registry.enabled properties. Form objects handle request parameters, and service classes (NacosMcpRegistryService, NacosSkillsRegistryService) implement the business logic for querying and returning data. Model classes define the response structures for both registries.

ai-registry-adaptor · high confidence

Add AI resource import manager APIs

Introduced new form classes in the \ai/form/importer\ package to support the AI resource import feature. This includes \AbstractAiResourceImportForm\ as a base class, along with specific forms for searching (\AiResourceImportSearchForm\), validating (\AiResourceImportValidateForm\), executing (\AiResourceImportExecuteForm\), and listing sources (\AiResourceImportSourceListForm\). These classes handle the data transfer and validation logic for importing external AI resources.

ai/src/main/java/com/alibaba/nacos/ai/form/importer · high confidence

Add AI resource trace logging for version operations

A new trace service and event initializer have been added to the AI module to log AI resource version operations (such as publish, review, and label updates) as structured JSON events. This enables auditing and ELK/Loki integration for tracking changes to AI resources.

ai/src/main/java/com/alibaba/nacos/ai/service/trace · high confidence

Add Closeable interface for resource shutdown

A new \Closeable\ interface is introduced in the \com.alibaba.nacos.common.lifecycle\ package, defining a \shutdown()\ method for managing resource cleanup such as IO connections and thread pools.

common/src/main/java/com/alibaba/nacos/common/lifecycle · high confidence

Add ConfigChangeClusterSyncResponse class

A new response class, ConfigChangeClusterSyncResponse, has been added to the API layer to handle cluster synchronization for configuration changes. This class extends the base Response type and is intended to support remote cluster communication for config updates.

api/src/main/java/com/alibaba/nacos/api/config/remote/response/cluster · medium confidence

Add Derby database implementation for Nacos data access

The Derby plugin module now includes full database mapper implementations for core Nacos entities, including ConfigInfo, ConfigInfoGray, ConfigInfoTagsRelation, GroupCapacity, HistoryConfigInfo, TenantCapacity, and TenantInfo. This adds support for using Apache Derby as the underlying data store for configuration and namespace isolation, with specific SQL generation for pagination, updates, and queries tailored to the Derby dialect.

plugin-default-impl/nacos-default-datasource-plugin/nacos-datasource-plugin-derby · high confidence

Add InstanceBuilder for constructing Instance objects

A new builder class, InstanceBuilder, has been added to the Nacos API. This class provides a fluent interface for constructing Instance objects, allowing users to set properties such as IP, port, weight, and metadata incrementally before calling build() to create the final Instance. This change supports building and handling requests from HTTP.

api/src/main/java/com/alibaba/nacos/api/naming/pojo/builder · high confidence

Add K8s Sync module to enable Kubernetes resource synchronization

The k8s-sync module is introduced to synchronize Kubernetes services and endpoints into Nacos. This includes a new configuration class (K8sSyncConfig) to manage feature flags, a filter (K8sSyncEnabledFilter) that gates the module based on the current function mode (Nacos naming or microservice) and the 'nacos.k8s.sync.enabled' property, and a server component (K8sSyncServer) that starts a Kubernetes informer to watch for service and endpoint changes. The module is disabled by default and only activates when the appropriate function mode is set and the feature is explicitly enabled.

k8s-sync · high confidence

Add Log4j2 logging adapter for Nacos client

Users can now use Log4j2 for Nacos client logging. This change introduces a new \log4j2-adapter\ module containing the \Log4J2NacosLoggingAdapter\ and supporting classes (configurator, properties holder, and lookup) that integrate Nacos logging configuration with the Log4j2 framework. The adapter loads a default \nacos-log4j2.xml\ configuration file and merges Nacos-specific loggers and appenders into the existing Log4j2 context, ensuring non-invasive logging setup. Tests are included to verify the adapter's behavior.

logger-adapter-impl/log4j2-adapter · high confidence

Add Logback 1.2.x logging adapter implementation

Added a new logging adapter for Logback versions 1.0.8 to 1.2.x, including the \LogbackNacosLoggingAdapter\ implementation, a builder, and a custom \NacosClientPropertyAction\ for parsing Nacos client properties in the XML configuration. The module also includes the \nacos-logback12.xml\ configuration file and the necessary \META-INF/services\ registrations to enable automatic discovery of the adapter. Tests were added to verify the adapter's configuration loading and property resolution.

logger-adapter-impl/logback-adapter-12 · high confidence

Add MCP registry model classes for server details, transport, and inputs

Added a new set of Java model classes in the \api/src/main/java/com/alibaba/nacos/api/ai/model/mcp/registry\ package to support the official MCP registry protocol. This includes data structures for server details (\McpRegistryServerDetail\, \McpRegistryServerList\), transport mechanisms (\StdioTransport\, \SseTransport\, \StreamableHttpTransport\), input handling (\Input\, \InputWithVariables\, \KeyValueInput\), and status enums (\McpServerStatusEnum\). These classes enable the Nacos API to serialize and deserialize MCP registry responses, supporting features like server listing, metadata retrieval, and argument parsing for AI model integration.

api/src/main/java/com/alibaba/nacos/api/ai/model/mcp/registry · high confidence

Add MCP server form objects for admin API

The change introduces new request form classes for managing Model Context Protocol (MCP) servers within the Nacos AI module. Specifically, it adds \McpForm\ as the base class, along with \McpDetailForm\ (for create/update details), \McpListForm\ (for listing with search options), and \McpImportForm\ (for importing server data). These forms define the structure and validation logic for MCP server operations, including support for override and namespace parameters.

ai/src/main/java/com/alibaba/nacos/ai/form/mcp · high confidence

Add Oracle database support for Nacos

This change introduces the Oracle database plugin for Nacos, providing Oracle-specific SQL dialects and mapper implementations. Users can now deploy Nacos on an Oracle database, with all core tables (config\_info, his\_config\_info, config\_info\_gray, etc.) and their corresponding Java mappers implemented for Oracle syntax and pagination.

plugin-default-impl/nacos-default-datasource-plugin/nacos-datasource-plugin-oracle · high confidence

Add PostgreSQL support for Nacos data source plugin

This change introduces full PostgreSQL support for the Nacos data source plugin. It adds a new \PostgresqlDatabaseDialect\ to handle PostgreSQL-specific SQL syntax, including pagination and function mapping. It also provides PostgreSQL-specific implementations for all core mappers (e.g., \ConfigInfoMapper\, \GroupCapacityMapper\, \TenantCapacityMapper\) and an enum for trusted SQL functions to prevent SQL injection. Additionally, it includes a PostgreSQL schema file (\pg-schema.sql\) for table creation, a service registration file to enable the dialect, and SQL scripts to handle schema upgrades and grant permissions.

plugin-default-impl/nacos-default-datasource-plugin/nacos-datasource-plugin-postgresql · high confidence

Add Prometheus service discovery API endpoints

Introduces a new Prometheus-compatible service discovery API that exposes Nacos service instances as targets for Prometheus scraping. The change adds a controller at /prometheus (and namespaced variants) that returns instance metadata in Prometheus SD format, along with security configurations to permit unauthenticated access to the metrics endpoint while enforcing basic authentication for other paths, and includes unit tests for the controller and exception handling.

prometheus · high confidence

Add ServerConfigChangeEvent for server configuration changes

A new event class, ServerConfigChangeEvent, has been added to the common module. This event is triggered when the Nacos server's configuration file (e.g., nacos/conf/application.properties) is modified, allowing subscribers to react to server-side configuration updates.

common/src/main/java/com/alibaba/nacos/common/event · high confidence

Add SkillQueryForm for client-side skill queries

A new SkillQueryForm class has been introduced in the AI module to handle client-side skill query parameters, including namespace, name, version, label, and an optional MD5 for cache validation.

ai/src/main/java/com/alibaba/nacos/ai/form/skills/client · high confidence

Add TLS configuration and connection type support for remote communication

Introduces new configuration and type definitions for remote connections, enabling TLS encryption for gRPC-based communication. The change adds a \ConnectionType\ enum to distinguish between different connection protocols, a \TlsConfig\ class to manage TLS settings such as certificate files, private keys, and mutual authentication options, and a \PayloadRegistry\ to handle payload registration via service loading. These components provide the foundational structure for securing remote client-server interactions.

common/src/main/java/com/alibaba/nacos/common/remote · high confidence

Add TLS/SSL support for Nacos client and server communication

Introduced new TLS/SSL utilities in the common module, including SelfHostnameVerifier, SelfTrustManager, TlsHelper, and TlsFileWatcher, enabling secure client-server communication with configurable certificate paths and authentication modes.

common/src/main/java/com/alibaba/nacos/common/tls · high confidence

Add address server cluster and server list controllers

The address module introduces two new REST controllers, \AddressServerClusterController\ and \ServerListController\, which enable the management and retrieval of address server nodes. The cluster controller allows users to register and delete IP lists associated with specific products and clusters, while the server list controller provides an endpoint to retrieve the current IP list for a given product and cluster. These endpoints facilitate the dynamic configuration of address servers within the Nacos ecosystem.

address/src/main/java/com/alibaba/nacos/address/controller · high confidence

Add admin forms for skill lifecycle and metadata management

Introduced a set of new Java form classes in the AI skills admin package to support skill operations. These include forms for updating business tags and labels, managing visibility scope, and handling the full skill lifecycle (create drafts, submit, publish, online/offline, and update). The forms also support versioning, commit messages, and legacy compatibility for the latest label.

ai/src/main/java/com/alibaba/nacos/ai/form/skills/admin · high confidence

Add built-in security scanning pipelines for AI Agent Skills

The nacos-default-ai-pipeline-plugin module now includes two new pipeline services: SkillScanner and SkillSpector. The SkillScanner service integrates Cisco AI Defense's skill-scanner to detect prompt injection, data exfiltration, and malicious code patterns, with optional LLM semantic analysis. The SkillSpector service integrates the SkillSpector tool for broader AI resource security scanning, supporting configurable risk score thresholds and LLM-based analysis. Both pipelines are configured via node properties and enforce security checks before publishing AI resources.

plugin-default-impl/nacos-default-ai-pipeline-plugin · high confidence

Add client-side forms for AgentSpec queries and searches

Introduced two new Java classes, AgentSpecQueryForm and AgentSpecSearchForm, to handle client-side data binding for AgentSpec operations. AgentSpecQueryForm supports retrieving a specific AgentSpec by name, version, and label, with validation ensuring the name is provided. AgentSpecSearchForm supports searching AgentSpecs by keyword and namespace. These forms standardize the input structure for the AgentSpec client runtime.

ai/src/main/java/com/alibaba/nacos/ai/form/agentspecs/client · high confidence

Add default Nacos control plugin implementation

The default Nacos control plugin is introduced, providing the default implementations for connection and TPS (transactions per second) control. This includes \NacosConnectionControlManager\ and \NacosTpsControlManager\, along with the \NacosControlManagerBuilder\ and its SPI registration, enabling Nacos to use these specific control logic implementations by default.

plugin-default-impl/nacos-default-control-plugin · high confidence

Add distributed lock manager with reentrant and non-reentrant lock implementations

The lock module now includes a new distributed lock manager that supports both reentrant and non-reentrant locking. The implementation includes a \LockManager\ interface and \NacosLockManager\ service that manages lock states, including owner tracking, reentrant counting, and wait queues. The system provides \MutexAtomicLock\ (legacy/non-reentrant), \ReentrantAtomicLock\, and \NonReentrantAtomicLock\ implementations, each with distinct locking behaviors. A \RequestLockAspect\ aspect is added to monitor lock acquisition and release metrics, while snapshot operations handle serialization and deserialization of lock states for persistence.

lock · high confidence

Add event classes for tracking prompt and skill download counts

New event classes, PromptDownloadEvent and SkillDownloadEvent, have been added to the Nacos AI module. These events are published when a prompt version or a skill version is downloaded, respectively. They carry the namespace ID, name, and version (and type for skills) to allow downstream consumers to track download metrics.

ai/src/main/java/com/alibaba/nacos/ai/event · high confidence

Add form objects for pipeline query and list operations

Introduced new form classes, PipelineDetailForm and PipelineListForm, to handle input validation for the pipeline query and list APIs. PipelineDetailForm validates the required 'pipelineId' parameter, while PipelineListForm validates the required 'resourceType' parameter and supports optional filtering by resource name, namespace ID, and version.

ai/src/main/java/com/alibaba/nacos/ai/form/pipeline · high confidence

Add gRPC service definitions for Nacos

A new gRPC service definition file (nacos\_grpc\_service.proto) has been added, introducing the 'Request' and 'BiRequestStream' services along with 'Metadata' and 'Payload' message types. This establishes the protocol buffer contracts for client-server and bidirectional streaming communication, enabling gRPC-based interactions for Nacos.

api/src/main/proto · high confidence

Add path encoding for Windows file system restrictions

A new path encoding mechanism has been introduced to handle illegal characters on Windows systems. The \PathEncoder\ interface and \PathEncoderManager\ singleton manage the encoding and decoding of paths, automatically detecting the operating system and applying the appropriate encoder. For Windows, the \WindowsEncoder\ implementation encodes characters that are invalid in file paths (such as / : ? " \< \> \| and backslashes) into safe string representations, ensuring compatibility with Windows file system constraints.

common/src/main/java/com/alibaba/nacos/common/pathencoder · high confidence

Add pipeline execution persistence layer

Introduced the \PipelineExecutionRepository\ interface and its \PipelineExecutionRepositoryImpl\ JDBC implementation to persist pipeline execution records. This new repository supports saving, updating, and querying pipeline executions by ID or by resource attributes (resource type, name, namespace, version) with pagination, enabling the system to track and retrieve the state and results of AI pipeline runs.

ai/src/main/java/com/alibaba/nacos/ai/pipeline/repository · high confidence

Add remote ability models for client and server

Introduced new \ClientRemoteAbility\ and \ServerRemoteAbility\ classes in the \api/src/main/java/com/alibaba/nacos/api/remote/ability\ package. These models define the remote capabilities for the Nacos client and server respectively, including properties for remote connection support and gRPC report status, enabling serialization and equality checks for these capability objects.

api/src/main/java/com/alibaba/nacos/api/remote/ability · high confidence

Add remote request handlers for AI module

Added new remote request handlers for the AI module, including McpServerEndpoint, QueryMcpServer, ReleaseMcpServer, QueryPrompt, AgentEndpoint, BatchAgentEndpoint, QueryAgentCard, and ReleaseAgentCard. These handlers enable MCP server and agent endpoint registration, deregistration, and querying, as well as agent card release and query functionality within the Nacos AI module.

ai/src/main/java/com/alibaba/nacos/ai/remote · high confidence

Added AI coding agent guidance and standardized build/test workflows

The repository now includes \AGENTS.md\ to provide AI coding agents with specific guidelines for contributing, including mandatory spec-first coding and API/SDK impact analysis. A \Makefile\ was added to standardize build, test, and run commands for various modes (config, naming, microservice, AI). The \mvnw\ wrapper and \.gitignore\ were updated to support the new build system and ignore generated files. Additionally, the \BUILDING\ and \CONTRIBUTING\ documentation were updated to reflect the new JDK 17+ requirement and the use of the Makefile for development workflows.

(repo-wide) · high confidence

Added AI resource import SPI models

Added new API models for the AI resource import feature, including request and response classes for searching, validating, and executing imports, as well as supporting types for status and validation results.

api/src/main/java/com/alibaba/nacos/api/ai/model/importer · high confidence

Added Base64 codec implementation

A new Base64 encoding and decoding class has been added to the common codec module, providing standard and URL-safe Base64 support for the Nacos platform.

common/src/main/java/com/alibaba/nacos/common/codec · high confidence

Added Java annotations for beta status and thread-safety warnings

The Nacos common module now includes new Java annotations: \@Beta\ to mark classes or methods as being in a beta version, and \@NotThreadSafe\ to indicate that a method or class is not thread-safe. These annotations can be used by developers to understand the stability and concurrency guarantees of the API. Additionally, an unused license-appending utility class was removed, and a test marker annotation was moved to the common module.

common/src/main/java/com/alibaba/nacos/common · high confidence

Added NacosConfigConverter interface for config type conversion

A new NacosConfigConverter interface has been introduced in the Nacos API module, providing a generic mechanism to convert Nacos configuration data into specific target types. This addition enables users to define custom conversion logic for configuration data, supporting type-safe access to configuration values through the canConvert and convert methods.

api/src/main/java/com/alibaba/nacos/api/config/convert · high confidence

Added TraceEvent class for unified tracing

A new TraceEvent class has been added to the common module, providing a standardized event structure for tracing. This class encapsulates key metadata including event type, timestamp, namespace, group, and name, enabling consistent trace data collection across the system.

common/src/main/java/com/alibaba/nacos/common/trace/event · high confidence

Added application.properties for the address module

A new application.properties file was added to the address module's resources, configuring the embedded server to listen on port 8080 with a context path of '/'.

address/src/main/resources · high confidence

Added client-side selector and result interfaces

Introduced new API interfaces for client-side selection logic. The \Selector\<C, E\>\ interface defines a generic contract for selecting a result \E\ from a context \C\, while \SelectResult\<T\>\ provides a generic container for a select result. These additions establish the foundation for client-side selector implementations within the Nacos API.

api/src/main/java/com/alibaba/nacos/api/selector/client · high confidence

Added gRPC API stubs and protobuf-generated classes for Nacos RPC

The API module now includes auto-generated gRPC stubs and message classes for the Nacos RPC service. This adds support for bidirectional streaming via \BiRequestStreamGrpc\ and unary requests via \RequestGrpc\, along with the associated \Payload\ and \Metadata\ message types. These classes enable clients to communicate with Nacos servers over gRPC, supporting both blocking and asynchronous call patterns for service discovery and configuration updates.

api/src/main/java/com/alibaba/nacos/api/grpc · high confidence

Added naming selector interfaces for service instance selection

New interfaces have been introduced in the Nacos API to support service instance selection. The \NamingContext\ interface provides access to service name, group, clusters, and the current list of instances. The \NamingResult\ interface wraps the selected instances as a \SelectResult\. The \NamingSelector\ interface extends the generic \Selector\ interface, defining the contract for selecting instances. These changes establish the API-side foundation for the selector feature, allowing implementations to define how instances are chosen based on context.

api/src/main/java/com/alibaba/nacos/api/naming/selector · high confidence

Added package scanning capability to discover classes by package and annotation

The \common\ module now includes a new \com.alibaba.nacos.common.packagescan\ package containing a \PackageScan\ interface and \DefaultPackageScan\ implementation, along with supporting classes for resource resolution and class reading (including \ClassReader\ and \Symbol\ copied from ASM, and resource classes like \ClassPathResource\ and \AntPathMatcher\ from Spring). This provides a new mechanism for scanning classes within a package that match specific annotations.

common/src/main/java/com/alibaba/nacos/common/packagescan · high confidence

Added response model classes for connection, server metrics, and namespaces

The \api\ module now includes several new response model classes to support server-side APIs and client connection tracking. Specifically, \ConnectionInfo\ and \ConnectionMetaInfo\ provide data structures for tracking client connection details and metadata. \ServerLoaderMetric\ and \ServerLoaderMetrics\ are introduced to expose server load indicators such as CPU, load average, and connection counts. Additionally, \Namespace\, \NacosMember\, and \IdGeneratorInfo\ are added to support namespace management, cluster member information, and ID generation responses. The legacy \JSONUtils\ utility class from the \config\ module has been removed and replaced by these specific model classes in the \api\ module.

api/src/main/java/com/alibaba/nacos/api/model/response · high confidence

Added serializable config ability classes

Introduced new Java classes, ClientConfigAbility and ServerConfigAbility, which implement the Serializable interface. These classes encapsulate configuration capabilities for the Nacos client and server respectively, each including a serialVersionUID to ensure stable serialization across versions.

api/src/main/java/com/alibaba/nacos/api/config/ability · high confidence

Added service for querying pipeline execution history

Users can now retrieve and list pipeline execution records through a new query service. The \PipelineQueryService\ provides methods to fetch a single pipeline execution by its ID or to list executions with pagination support, filtering by resource type, resource name, namespace, and version. This enables users to inspect the status and details of past pipeline runs.

ai/src/main/java/com/alibaba/nacos/ai/service/pipeline · medium confidence

Added support for Jackson 3 JSON adapter

Nacos now supports Jackson 3 as an alternative JSON serialization provider alongside the existing Jackson 2 implementation. The \Jackson2JsonAdapter\ and \Jackson3JsonAdapter\ classes are introduced, allowing the runtime to select between the two Jackson versions based on classpath availability or explicit configuration. Additionally, diagnostic logging has been added to the \JsonAdapterLogUtils\ to record which adapter is ultimately selected, helping users verify the active JSON provider.

common/src/main/java/com/alibaba/nacos/common/json · high confidence

Added trace event publishing infrastructure

The Nacos common module now includes a new trace event publishing system, introducing \TraceEventPublisher\ and \TraceEventPublisherFactory\. This adds the core components for handling and distributing trace events, enabling unified trace capacity building across the application.

common/src/main/java/com/alibaba/nacos/common/trace/publisher · high confidence

Added trace events for Nacos naming operations

Added new trace event classes for Nacos naming operations, including batch register, register, update, and deregister for both instances and services, as well as subscribe, unsubscribe, push, and health state change events. These events capture details such as client IP, service namespace/group/name, instance IP/port, metadata, and performance metrics like push cost time, enabling users to trace and monitor the lifecycle of naming-related operations.

common/src/main/java/com/alibaba/nacos/common/trace/event/naming · high confidence

Adds common utility classes for arrays, bytes, classes, collections, and more

The \nacos-common\ module introduces a suite of new utility classes to the \com.alibaba.nacos.common.utils\ package, including \ArrayUtils\, \ByteBufferInputStream\, \ByteUtils\, \ClassUtils\, \CollectionUtils\, \ConcurrentHashSet\, \ConnLabelsUtils\, \ConvertUtils\, \DateFormatUtils\, \ExceptionUtil\, \FuzzyGroupKeyPattern\, \HttpMethod\, and \InetAddressValidator\. These additions provide standardized helper methods for array and byte operations, object conversion, date formatting, exception handling, HTTP method constants, and IP address validation, consolidating common functionality within the common module.

common/src/main/java/com/alibaba/nacos/common/utils · high confidence

Centralized task execution and scheduling infrastructure

The task execution and scheduling infrastructure has been consolidated into the Nacos common module. This introduces a new NacosTask interface and abstract base classes (AbstractExecuteTask, AbstractDelayTask) to standardize how tasks are processed and scheduled. Additionally, a BatchTaskCounter utility was added to track the completion status of batch operations, and the NacosTaskProcessor interface was introduced to handle task processing logic.

common/src/main/java/com/alibaba/nacos/common/task · high confidence

Common model classes moved to nacos-common

The \RestResult\ class has been moved from the \config\ module to \nacos-common\, and a new \RequestHttpEntity\ class has been added to the common model package. \RestResult\ now includes a builder pattern for constructing results and utility methods (\ok()\, \isNoRight()\) to check status codes, while \RequestHttpEntity\ provides a unified structure for HTTP requests containing headers, query parameters, and a body.

common/src/main/java/com/alibaba/nacos/common/model · high confidence

Introduce AI constants for MCP and A2A protocols

Added AiConstants class defining configuration keys and protocol constants for AI services, including Model Context Protocol (MCP) transport modes (stdio, SSE, HTTP, Dubbo), endpoint types, and cache update intervals, as well as A2A agent discovery and transport settings.

api/src/main/java/com/alibaba/nacos/api/ai/constant · high confidence

Introduce AI module client components and native-image configuration

The client module now includes a new AI service implementation (NacosAiService) that supports HTTP and gRPC transport modes for AI-related operations, including agent cards, agent specs, MCP servers, prompts, and skills. Each AI resource type has a corresponding cache holder (e.g., NacosAgentCardCacheHolder, NacosAgentSpecCacheHolder, NacosMcpServerCacheHolder) that manages local caching, periodic polling, and event notification. Additionally, a new filter-config.json file is added to configure reflection and resource rules for GraalVM native-image packaging.

client · high confidence

Introduce AI publish pipeline execution framework

Added the core execution engine (PublishPipelineExecutor) and plugin manager (PublishPipelineManager) for the AI publish pipeline. The executor runs configured pipeline nodes asynchronously in a serial order, persisting each node's result and the overall execution status (APPROVED/REJECTED) to the database. The manager discovers and loads pipeline services via SPI, caching them for runtime lookup and ordering. This provides the foundational framework for executing AI-driven publish pipelines.

ai/src/main/java/com/alibaba/nacos/ai/pipeline · high confidence

Introduce AI resource import framework and operators

Added a new AI resource import subsystem that allows importing external resources into Nacos. This includes configuration classes (AiResourceImportProperties, AiResourceImportSourceConfig) to define import sources and runtime settings, managers (AiResourceImportManager, AiResourceImportPluginManager, AiResourceImportSourceManager) to orchestrate search, validation, and execution of imports, and specific operators (McpResourceOperator, SkillResourceOperator) that apply imported artifacts to the MCP and Skill domains respectively. The framework supports listing sources, searching external candidates, validating selected items, and executing imports, with built-in security guards and traceability.

ai/src/main/java/com/alibaba/nacos/ai/importer · high confidence

Introduce AgentSpec and NacosAiConfigKeyCodec for AI resource management

Added new model classes for AI agent specifications (AgentSpec, AgentSpecBase, AgentSpecBasicInfo, AgentSpecMeta, AgentSpecSummary) and a utility class (AgentSpecUtils) to support managing AI resources in Nacos. The new NacosAiConfigKeyCodec class provides reversible encoding for Nacos Config dataId and group segments, ensuring that special characters in names and versions are safely stored in Nacos configuration keys. The AgentSpecResource class, refactored from the previous Service class, now represents individual files within an AI worker package, including type, content, and metadata. These changes enable the storage and retrieval of AI agent specifications and their associated resources through Nacos Config.

api/src/main/java/com/alibaba/nacos/api/ai/model/agentspecs · high confidence

Introduce AgentSpec operation service with HTTP 304 caching and versioned metadata

Added the AgentSpec operation service interface and implementation, providing full lifecycle management for AgentSpecs including upload, bootstrap, and deletion. The service introduces HTTP 304 caching support via the new AgentSpecQueryResult wrapper, which allows clients to skip content loading when the MD5 hash matches. It also exposes versioned metadata queries, supporting both admin and client-facing search and list operations with optional ordering and filtering.

ai/src/main/java/com/alibaba/nacos/ai/service/agentspecs · high confidence

Introduce CMDB POJOs for entity management

The api module now includes new POJOs for the CMDB module: Label, Entity, EntityEvent, EntityEventType, and PreservedEntityTypes. These classes provide the data structures for representing CMDB entities, their events, and preserved types (such as 'ip' and 'service'), enabling the integration with third-party CMDBs to filter service providers by their labels.

api/src/main/java/com/alibaba/nacos/api/cmdb/pojo · high confidence

Introduce CMDB Service SPI for external data integration

Added the CmdbService interface, which defines a set of methods for retrieving label names, entity types, and entity data from a CMDB store. This new SPI allows external systems to query and dump CMDB data, including deprecated methods for backward compatibility.

api/src/main/java/com/alibaba/nacos/api/cmdb/spi · high confidence

Introduce Copilot feature with AI-powered prompt and skill generation/optimization

The Copilot feature is now available, providing AI-driven capabilities to generate and optimize prompts and Agent Skills. This includes new Java classes for managing the Copilot agent lifecycle, configuration storage via Nacos Config, and form objects for user inputs. The system includes hardcoded system prompts for optimizing and generating skills and prompts, along with a stream response callback interface. The feature is controlled by the \nacos.copilot.enabled\ property and is conditionally loaded for non-server deployments.

copilot · high confidence

Introduce Istio module with MCP and XDS service support

Added the Istio module to Nacos, introducing a new application entry point (IstioApp) and a suite of components to support Istio's Model Control Protocol (MCP) and xDS protocols. This includes an event processor to handle configuration and service changes, a resource snapshot manager, and generators to convert Nacos service data into MCP and xDS formats for service mesh integration.

istio · high confidence

Introduce MCP server import and management services

Added new services in the AI module to support importing and managing Model Context Protocol (MCP) servers. This includes \McpServerImportService\ for handling import logic, \McpExternalDataAdaptor\ for adapting external data formats, \McpLegacyImportAdapter\ for backward compatibility, \McpServerOperationService\ for CRUD operations, \McpResourceOperationService\ for resource specifications, \McpEndpointOperationService\ for endpoint management, \McpServerValidationService\ for validation, and \McpServerCacheInvalidateService\ for cache invalidation.

ai/src/main/java/com/alibaba/nacos/ai/service · high confidence

Introduce Nacos Config-based AI resource storage

Added NacosConfigAiResourceStorage and its builder to enable storing AI resources (Skills, AgentSpecs, and Prompts) as Nacos Config configurations. This new storage implementation supports both legacy 4-part and new 5-part key formats, allowing users to persist and manage AI model resources directly within Nacos Config, with automatic handling of data IDs, groups, and namespaces.

ai/src/main/java/com/alibaba/nacos/ai/storage · high confidence

Introduce Nacos Console UI (Next) with modernized frontend stack and new AI resource management

The \console-ui-next\ directory introduces a new frontend for the Nacos console, built with React 18, TypeScript, Vite 7, and Tailwind CSS 4. This new UI provides a modernized user experience for managing configuration, services, and AI resources (Agents, AgentSpecs, Prompts, and MCP servers). The implementation includes dedicated API clients for these resources, state management via Zustand, and comprehensive unit tests for API base paths and wire field names. Additionally, supply chain security is improved by configuring \.npmrc\ to restrict package installation to those released more than three days ago.

console-ui-next · high confidence

Added new classes in the common module to support a pluggable logging adapter mechanism. The new \NacosLoggingAdapter\ interface allows different logging frameworks to be adapted, while \NacosLoggingAdapterBuilder\ provides a safe way to construct these adapters. Additionally, \NacosLoggingProperties\ is introduced to manage logging configuration properties, including the config file location, default config enablement, and reload interval settings.

common/src/main/java/com/alibaba/nacos/common/logging · high confidence

Introduce NacosServiceLoader for SPI-based service discovery

A new NacosServiceLoader utility class has been added to the common module to handle Service Provider Interface (SPI) loading with internal caching. This replaces direct usage of Java's standard ServiceLoader, providing a cached mechanism to load and instantiate service implementations. A corresponding ServiceLoaderException has been introduced to wrap loading failures, ensuring that service discovery errors are handled consistently within the Nacos framework.

common/src/main/java/com/alibaba/nacos/common/spi · high confidence

Introduce RPC client abstraction and TLS configuration

Added a new \RpcClient\ abstraction in the \common\ module to manage remote connections, including the \Connection\ class to track connection state and capabilities, and a \RpcClientTlsConfig\ to handle TLS settings for secure communication. This change introduces the foundational classes for gRPC-based client-server communication, enabling features like connection status tracking, server list management, and secure transport configuration.

common/src/main/java/com/alibaba/nacos/common/remote/client · high confidence

Introduce SPI-based encryption plugin architecture

Added a new \plugin/encryption\ module that provides a plugin-based encryption and decryption mechanism. This includes an \EncryptionPluginService\ SPI interface, an \EncryptionPluginManager\ for managing and discovering encryption algorithms, and an \EncryptionHandler\ that routes requests based on dataId prefixes (e.g., \cipher-\). The implementation leverages Java SPI for extensibility, allowing users to register custom encryption algorithms. Unit tests are included to verify the manager, provider, and handler logic.

plugin/encryption · high confidence

Introduce a neutral JSON adapter API for pluggable JSON providers

The Nacos Java SDK now includes a neutral JSON utility facade (JsonUtils) and a pluggable adapter selection mechanism (JsonAdapterSelector) that automatically detects and uses an available JSON provider (Jackson 2 or 3) via the system property nacos.client.json.adapter. This allows users to swap or upgrade their JSON library without changing SDK code, as the SDK delegates serialization and deserialization to the selected adapter.

api/src/main/java/com/alibaba/nacos/api/utils/json · high confidence

Introduce ability constants for server and client feature negotiation

Added new constants to define supported capabilities for the server, SDK client, and cluster client. The \AbilityKey\ enum enumerates specific features such as persistent instance registration via gRPC, fuzzy watch, distributed locks, and AI module registries (MCP, Agent, A2A), each tagged with its corresponding \AbilityMode\ (SERVER, SDK\_CLIENT, or CLUSTER\_CLIENT). This structure allows the system to negotiate and verify feature support between components before executing requests.

api/src/main/java/com/alibaba/nacos/api/ability/constant · high confidence

Introduce ability model classes for Nacos naming

Added new Java classes, ClientNamingAbility and ServerNamingAbility, to represent the capabilities of the Nacos client and server respectively. These classes, which implement Serializable, encapsulate specific feature flags (such as support for delta push, remote metrics, and SOFA-Jraft) to allow the system to query and exchange capability information between client and server.

api/src/main/java/com/alibaba/nacos/api/naming/ability · medium confidence

Introduce auth configuration model and SPI holder

Added new classes to model authentication configuration and manage plugin loading. AuthErrorCode defines error codes for invalid or empty identity. NacosAuthConfig is a new interface defining methods to retrieve auth scope, enabled status, system type, and server identity details. NacosAuthConfigHolder is a new SPI-based holder that loads all NacosAuthConfig implementations via NacosServiceLoader, providing methods to retrieve configs by scope, check if any auth is enabled, and get the global auth system type.

auth/src/main/java/com/alibaba/nacos/auth/config · high confidence

Introduce centralized application.properties for Nacos 3.0 configuration

A new \application.properties\ file has been added to the bootstrap resources, consolidating configuration for Nacos 3.0. This file defines core server settings, including the main port (8848), database connection templates for MySQL and PostgreSQL, and metrics exporters for Prometheus, ElasticSearch, and Influx. It also introduces specific configuration keys for the new AI module, allowing users to enable or disable the MCP and skill registries, set the AI registry port (9080), and configure upload limits for skill ZIP files.

bootstrap/src/main/resources · high confidence

Introduce centralized parameter validation framework

A new parameter validation framework has been added to the Nacos common module, introducing a structured way to validate inputs such as namespace IDs, data IDs, service names, and MCP names. The change adds a set of classes in the \com.alibaba.nacos.common.paramcheck\ package, including \AbstractParamChecker\, \DefaultParamChecker\, \ParamCheckRule\, \ParamInfo\, \ParamCheckResponse\, and \ParamCheckerManager\. This provides a unified mechanism for checking and validating various Nacos parameters, ensuring that inputs meet specific format and length requirements before processing.

common/src/main/java/com/alibaba/nacos/common/paramcheck · high confidence

Introduce centralized thread pool lifecycle management

Added a new \ThreadPoolManager\ singleton and an \ExecutorFactory\ in the \common\ module to provide unified lifecycle management for \ExecutorService\ instances. The \ThreadPoolManager\ registers, tracks, and destroys thread pools by namespace and group, while the \ExecutorFactory\ provides static methods to create managed executors. Additionally, the \TimerTaskService\ from the config module was refactored and moved to \common\ as \NameThreadFactory\, enabling consistent thread naming and daemon configuration across the application.

common/src/main/java/com/alibaba/nacos/common/executor · high confidence

Introduce config change plugin framework and SPI-based plugin management

Added a new plugin module for config change events, including the \ConfigChangePluginManager\ to load and manage plugins via SPI, the \ConfigChangePluginProvider\ to expose them through the plugin API, and supporting models (\ConfigChangeRequest\, \ConfigChangeResponse\) and constants. This establishes the foundation for intercepting and processing configuration changes through a pluggable architecture.

plugin/config · high confidence

Introduce config change tracking and query result models

Added new API classes to support configuration change events and structured query results. The new \ConfigChangeEvent\ and \ConfigChangeItem\ classes allow clients to inspect individual configuration changes (key, old value, new value, and change type). A new \ConfigQueryResult\ class wraps configuration content with its MD5 hash and type, enabling CAS (Compare-And-Swap) operations. The \ConfigService\ interface now includes a \getConfigWithResult\ method to retrieve this structured result. Additionally, the \ConfigType\ enum was expanded to include 'toml' and 'unset' types, and the \ConfigFactory\ was refactored to use reflection for creating \NacosConfigService\ instances.

api/src/main/java/com/alibaba/nacos/api/config · high confidence

Introduce configurable gRPC client settings for Nacos remote communication

The Nacos common module now exposes a new \DefaultGrpcClientConfig\ and \GrpcClientConfig\ interface that allow users to configure gRPC client behavior. This includes thread pool sizing (core/max/queue), keep-alive intervals, health check parameters, and TLS encryption settings. These configuration options enable users to optimize network performance and secure their gRPC connections between the Nacos client and server.

common/src/main/java/com/alibaba/nacos/common/remote/client/grpc · high confidence

Introduce custom environment plugin support

Adds a new plugin architecture for environment configuration, allowing third-party providers to supply custom environment properties via the \CustomEnvironmentPluginService\ SPI. The \CustomEnvironmentPluginManager\ loads these services, sorts them by priority, and merges their key-value pairs into the application's property source. This enables modular extension of environment variable handling.

plugin/environment · high confidence

Introduce dedicated prompt lifecycle and client operation services

The prompt module now includes a new \PromptOperationService\ that manages the full lifecycle of prompts (create, update, submit, publish, online/offline, and delete) and a \PromptClientOperationService\ that handles runtime queries with MD5-based conditional fetch for SDK long-polling. Additionally, a \PromptDownloadCountManager\ is added to track and flush download counts to the database.

ai/src/main/java/com/alibaba/nacos/ai/service/prompt · high confidence

Introduce distributed lock API for acquiring and releasing locks

Added the Nacos distributed lock API, including the \LockService\ interface with methods for acquiring, releasing, and renewing locks, alongside the \NacosLockFactory\ for instantiation. The change introduces the \LockInstance\ model to represent lock state, a \LockResult\ to convey reentrant counts and wait queue positions, and remote request/response classes (\LockOperationRequest\, \LockOperationResponse\) to support the underlying gRPC communication.

api/src/main/java/com/alibaba/nacos/api/lock · high confidence

Introduce file-based AI pipeline configuration via new config provider

A new file-based configuration provider for the AI pipeline has been added, allowing users to enable and configure pipeline plugins through application.properties. The provider reads keys such as nacos.plugin.ai-pipeline.enabled to toggle the feature, nacos.plugin.ai-pipeline.type to specify which plugins (e.g., skill-scanner) to run, and nacos.plugin.ai-pipeline.{type}.order to control execution order. This change shifts pipeline configuration from hardcoded or memory defaults to a flexible, file-driven approach.

ai/src/main/java/com/alibaba/nacos/ai/pipeline/config · high confidence

Introduce in-memory CMDB provider for entity and label management

Added CmdbProvider, a new Spring component that maintains an in-memory cache of CMDB entities and labels. It initializes by loading data from a configured CmdbService implementation and schedules periodic tasks to dump and update label and entity information, enabling the system to query and manage CMDB data locally.

cmdb/src/main/java/com/alibaba/nacos/cmdb/memory · high confidence

Introduce in-memory caching for MCP server index lookups

The AI module now supports an in-memory cache for MCP server index lookups, implemented via the new \MemoryMcpCacheIndex\ backed by a Guava cache. This change introduces a \CachedMcpServerIndex\ that prioritizes fast memory-based lookups before falling back to database queries, while also providing a \PlainMcpServerIndex\ for non-cached scenarios. The update includes a new \McpCacheIndex\ interface and an \AbstractMcpServerIndex\ base class to standardize search and retrieval operations across different index implementations.

ai/src/main/java/com/alibaba/nacos/ai/index · high confidence

Introduce legacy console-ui build system and reusable UI components

The console-ui directory is established as a standalone React frontend project, complete with a Webpack 4 build pipeline (webpack.base.conf.js, webpack.dev.conf.js, webpack.prod.conf.js) and configuration files (.babelrc, .eslintrc, .prettierrc). This adds a new build process that compiles and copies the legacy console assets to the backend static resources directory. Additionally, the change introduces several reusable UI components for the console, including BatchHandle, CloneDialog, Copy, DeleteDialog, DiffEditorDialog, EditorNameSpace, and ExportDialog, which provide functionality for batch operations, cloning configurations, copying text, deleting items, comparing diffs, editing namespaces, and exporting configurations.

console-ui · high confidence

Introduce listener-style skill queries with MD5-based cache validation

Added a new client-side query path for skills that supports HTTP 304 (Not Modified) responses when the client's cached version matches the server's content MD5. This optimization reduces bandwidth and latency for skill listeners by avoiding full payload transfers when the client cache is fresh. The implementation includes a new \SkillClientOperationService\ and \SkillIndexManifestService\ to resolve versions and read stored MD5s, while \SkillQueryResult\ and \SkillUploadRequest\ support the new query and upload workflows.

ai/src/main/java/com/alibaba/nacos/ai/service/skills · high confidence

Introduce new API model classes for AI Prompt management

Added new Java model classes in the \api/src/main/java/com/alibaba/nacos/api/ai/model/prompt\ package to support the AI Prompt feature. This includes \Prompt\ for core entity data, \PromptVariable\ for template variables with default values, and several metadata/summary classes (\PromptMetaInfo\, \PromptMetaSummary\, \PromptVersionInfo\, \PromptVersionSummary\) that expose versioning, status, and lifecycle information. A \PromptUtils\ class was also added to handle Nacos Config group naming conventions for prompts.

api/src/main/java/com/alibaba/nacos/api/ai/model/prompt · high confidence

Introduce new HTTP client abstractions and templates

The common module adds a new HTTP client architecture, introducing \AbstractNacosRestTemplate\ as a base class that manages a registry of response handlers (for String, RestResult, byte\[\], and Bean types). New concrete implementations \NacosRestTemplate\ (sync) and \NacosAsyncRestTemplate\ (async) are added to handle HTTP requests. The change also introduces an \HttpClientRequestInterceptor\ interface and an \InterceptingHttpClientRequest\ wrapper to support request interception, allowing clients to hook into HTTP requests before execution.

common/src/main/java/com/alibaba/nacos/common/http/client · high confidence

Introduce new auth plugin API and SPI interfaces

Added new classes to the \plugin/auth\ module to support the plugin-based authentication architecture. This includes the \AuthResult\ class for standardizing authentication responses, context classes (\IdentityContext\, \LoginIdentityContext\) for carrying identity data, and domain models (\Resource\, \Permission\, \RequestResource\) for authorization checks. Additionally, SPI interfaces (\AuthPluginService\, \ClientAuthService\) and their managers (\AuthPluginManager\, \ClientAuthPluginManager\) are introduced to enable dynamic loading and management of server-side and client-side authentication plugins, along with associated constants and exception classes.

plugin/auth · high confidence

Introduce new data models for MCP server management

Added three new Java classes in the \com.alibaba.nacos.ai.model.mcp\ package to support the MCP (Model Context Protocol) registry and API features. \McpServerIndexData\ provides a lightweight index structure containing server ID and namespace ID. \McpServerStorageInfo\ extends \McpServerBasicInfo\ to include description references for tools, prompts, and resources. \UrlPageResult\ serves as a paginated container for \McpServerDetailInfo\ objects, supporting cursor-based pagination. These models form the internal data layer for the new MCP admin API.

ai/src/main/java/com/alibaba/nacos/ai/model/mcp · high confidence

Introduce new event notification system in common module

The common module now includes a new event notification system, featuring a \NotifyCenter\ singleton that manages event publishers. This includes a \DefaultPublisher\ for general events and a \DefaultSharePublisher\ for slow events, both implementing the \EventPublisher\ interface. The \Event\ class provides a sequence number for event ordering, and the \ShardedEventPublisher\ interface supports multiple event types. The \SlowEvent\ class has been moved from the client module to the common module.

common/src/main/java/com/alibaba/nacos/common/notify · high confidence

Introduce new health check implementations for HTTP, MySQL, and TCP

The Nacos API module now includes new POJO classes for health checking: Http, Mysql, and Tcp. The Http class allows configuration of HTTP health checks with a path, headers, and expected response code. The Mysql class supports MySQL health checks with user, password, and command configuration. The Tcp class provides a basic TCP health check implementation. These classes extend AbstractHealthChecker and implement standard Java methods like equals, hashCode, and clone.

api/src/main/java/com/alibaba/nacos/api/naming/pojo/healthcheck/impl · high confidence

Introduce new selector API for service filtering

The api module now includes a new selector framework in the com.alibaba.nacos.api.selector package, providing a standardized way to filter and select services. This includes the Selector interface, abstract base classes (AbstractSelector, AbstractCmdbSelector), and concrete implementations like ExpressionSelector and NoneSelector, along with a SelectorFactory for registration. This change replaces the previous selector mechanism, enabling more flexible service selection based on labels, clusters, health states, and other criteria.

api/src/main/java/com/alibaba/nacos/api/selector · high confidence

Introduce pipeline execution model classes

Added new model classes to support the AI pipeline execution framework: PipelineCallback for handling execution completion notifications, PipelineConfig for global pipeline settings (enabled status and ordered node list), and PipelineNodeConfig for individual node settings (ID, properties, and execution order). These classes provide the data structures required to configure and monitor pipeline runs.

ai/src/main/java/com/alibaba/nacos/ai/pipeline/model · medium confidence

Introduce plugin configuration and management API

Added new API classes in the \com.alibaba.nacos.api.plugin\ package to support plugin configuration and management. This includes \ConfigItemDefinition\ and \PluginConfigSpec\ for defining and applying plugin configuration items, \PluginProvider\ for SPI-based plugin discovery, \PluginStateChecker\ and \PluginStateCheckerHolder\ for checking plugin states, and \PluginType\ to enumerate supported plugin types such as AUTH, TRACE, and AI\_Vanilla pipeline/storage/import. These changes provide the foundation for managing plugin configurations and discovering plugins via SPI.

api/src/main/java/com/alibaba/nacos/api/plugin · high confidence

Introduce plugin-based AI resource import and publish pipeline frameworks

The AI plugin module now provides a plugin-based architecture for importing external AI resources and reviewing them before publishing. For imports, new SPIs (AiResourceImportService, AiResourceImportServiceBuilder, AiResourceImportSourceProvider) and model classes (e.g., AiResourceImportArtifact, AiResourceImportCandidate) allow external sources to be discovered and fetched as import artifacts. For publishing, a new pipeline framework (PublishPipelineService, PublishPipelineServiceBuilder) enables configurable review/interception steps (e.g., security checks, manual confirmation) before AI resources are published. Additionally, a storage router (AiResourceStorageRouter) and model (StorageKey) are introduced to route AI resource storage operations to pluggable storage providers.

plugin/ai · high confidence

Introduce plugin-based datasource architecture with dialect support

The datasource module is refactored to use a plugin-based architecture, introducing a \DatabaseDialect\ interface and SPI-driven discovery for database-specific SQL generation (e.g., pagination, limit clauses). A new \MapperManager\ and \AbstractMapper\ provide a unified, extensible way to map configuration data to different database schemas. This enables Nacos to support multiple database backends (such as PostgreSQL, Oracle, and MySQL) through pluggable dialects, improving compatibility and maintainability.

plugin/datasource · high confidence

Introduce repository layer for AI resource and version persistence

Added the \AiResourcePersistService\ and \AiResourceVersionPersistService\ interfaces and their implementations (\AiResourcePersistServiceImpl\, \EmbeddedAiResourcePersistServiceImpl\, etc.) to handle database operations for AI resources and their versions. This includes row mappers, query condition models, and support for both external and embedded storage backends, enabling the system to store, retrieve, and manage AI resource metadata and versioning.

ai/src/main/java/com/alibaba/nacos/ai/service/repository · high confidence

Introduce server status management and readiness checks for the naming module

The naming module now includes a new \ServerStatus\ enum and a \ServerStatusManager\ to track and control the working status of the local server (e.g., UP, DOWN, STARTING, PAUSED, WRITE\_ONLY, READ\_ONLY). A \NamingReadinessCheckService\ has been added to perform readiness checks based on the server status. Additionally, a \NamingAbilityInitializer\ initializes naming-specific server abilities, and new distro-related classes (\DistroDataRequest\, \DistroDataResponse\, \DistroClientComponentRegistry\, \DistroClientDataProcessor\) are introduced to handle client data synchronization and consistency for the v2 naming model.

naming · high confidence

Introduce skill index manifest for client-side caching

A new SkillIndexManifest class has been added to the AI module to support client-side caching of skill index data. This manifest stores skill metadata, including label-to-version mappings and version-to-file mappings, which are persisted in Nacos Config under the group 'skill\_{name}' and dataId 'skill\_index.json'.

ai/src/main/java/com/alibaba/nacos/ai/model/skills · medium confidence

Introduce standalone console mode for Nacos

The console module now supports a standalone deployment mode, allowing the Nacos console to run independently of the server. This is achieved through new startup classes (NacosConsole, NacosConsoleStartUp) and configuration beans (ConsoleWebConfig, ConsoleCorsConfig, NacosConsoleAuthConfig) that configure web filters, CORS, and authentication specifically for the console. Additionally, AOT runtime hints and native library loaders are added to support GraalVM compilation, and a remote server member manager is introduced to handle cluster node discovery in this mode.

console · high confidence

Introduce trace plugin infrastructure and SPI

Added the trace plugin module, including the NacosTracePluginManager to load and manage trace subscribers, a TracePluginProvider implementing the plugin API, and the NacosTraceSubscriber SPI interface. This enables users to register and discover trace event subscribers via the service loader, with optional filtering by plugin state.

plugin/trace · high confidence

Introduce visibility plugin with SPI-based service loading and query advising

The visibility plugin now provides a plugin-based architecture for managing resource visibility. It introduces a new \VisibilityService\ SPI that allows implementations to validate access and advise on query filtering. The \VisibilityPluginManager\ loads and manages these services via Java SPI, supporting a global \nacos.plugin.visibility.enabled\ property to enable or disable the plugin, as well as per-service configuration. The plugin also introduces model classes like \VisibilityResource\, \QueryAdvisor\, and \ValidationResult\ to support visibility planning and validation. Tests have been added to verify the plugin's behavior, including handling of broken SPI providers and property resolution.

plugin/visibility · high confidence

Introduces CMDB utility classes for execution and logging

The CMDB module now includes new utility classes to support its operation. A dedicated scheduled executor service is provided via CmdbExecutor, which manages background tasks using a managed thread pool. Additionally, a centralized logger (Loggers) is introduced for the CMDB component, and a constants class (UtilsAndCommons) defines the Nacos server version and CMDB context path.

cmdb/src/main/java/com/alibaba/nacos/cmdb/utils · high confidence

Introduces NamingUtils for service and instance validation

Adds the new NamingUtils class to the API module, providing utility methods for constructing and parsing service keys, validating service name formats (including enforcing non-empty group names), and checking instance parameters such as heartbeat and IP delete timeouts.

api/src/main/java/com/alibaba/nacos/api/naming/utils · high confidence

Introduces a new ability control framework for Nacos nodes

A new capability control system has been added to the common module, allowing the runtime enablement or disablement of specific features on the current node. The change introduces an abstract \AbstractAbilityControlManager\ that manages a table of supported abilities, supporting both client and server modes. The system uses SPI to discover and prioritize different ability managers, ensuring that the highest priority implementation is used. This provides a centralized way to manage feature flags and capabilities across the Nacos application.

common/src/main/java/com/alibaba/nacos/common/ability · high confidence

Introduces new default authentication and visibility services for Nacos

The default auth plugin now includes new core components: \AbstractNacosAuthPluginService\ and \DefaultAiVisibilityService\ to handle authentication and AI resource visibility checks. A new \SafeBcryptPasswordEncoder\ is added to fix a password length vulnerability in BCrypt. Additionally, \AnonymousAccessInitializer\ and \NacosAuthPluginService\ manage the initialization and configuration of anonymous access and token settings.

plugin-default-impl/nacos-default-auth-plugin · high confidence

Introduces server identity check mechanism for Nacos admin APIs

A new server identity validation framework has been added to the authentication module. This includes a \ServerIdentity\ model, a \ServerIdentityChecker\ interface, and a \DefaultChecker\ implementation that validates server identity against configured values. The \ServerIdentityCheckerHolder\ uses SPI to load custom checker implementations, falling back to the default if none are found. This change enhances the security of internal/administrative APIs by ensuring requests originate from trusted Nacos servers.

auth/src/main/java/com/alibaba/nacos/auth/serveridentity · high confidence

Introduces standardized v2 API response models and error codes

The API module now includes new v2 model classes: \ErrorCode\ defines a comprehensive set of error codes and messages for various failure scenarios (e.g., parameter missing, access denied, config/namespace specific errors), and \Result\<T\>\ provides a generic wrapper for API responses containing a status code, message, and optional data payload. Additionally, \SupportedLanguage\ is added to manage supported language codes (zh-CN, en-US) for features like announcements. These changes standardize how the Nacos v2 API communicates status and errors to clients.

api/src/main/java/com/alibaba/nacos/api/model/v2 · high confidence

Introduction of CMDB module with new service interfaces

The CMDB module is introduced to support integration with third-party CMDBs, enabling filtering of service providers by their labels. This change adds a new application entry point (CmdbApp) and a CmdbReader interface for querying entities and labels. Additionally, the existing Datum class is refactored and moved to the CMDB package, becoming the CmdbWriter interface to support writing to the CMDB.

cmdb/src/main/java/com/alibaba/nacos/cmdb/service · high confidence

MCP server model and import support

Added new data models for the Model Context Protocol (MCP) in the Nacos API, including classes for server details, tool and resource specifications, and endpoint configurations. The update also introduces request and response structures for importing MCP servers from external sources, enabling users to bulk-import server configurations.

api/src/main/java/com/alibaba/nacos/api/ai/model/mcp · high confidence

MySQL plugin implementation and schema for Nacos datasource

The MySQL implementation of the Nacos datasource plugin has been introduced, providing the concrete SQL mappings and database schema for MySQL. This includes the \DefaultDatabaseDialect\ and \MysqlDatabaseDialect\ classes that handle database-specific function mappings, as well as a comprehensive set of mapper classes (e.g., \ConfigInfoMapperByMySql\, \GroupCapacityMapperByMysql\) that translate Nacos's internal data models into MySQL queries. Additionally, the \TrustedMysqlFunctionEnum\ enum is added to whitelist trusted SQL functions, and the \mysql-schema.sql\ file defines the necessary database tables (such as \config\_info\ and \config\_info\_gray\) using the \utf8mb4\ charset to support full Unicode characters.

plugin-default-impl/nacos-default-datasource-plugin/nacos-datasource-plugin-mysql · high confidence

Nacos client API expands with new configuration keys and factory methods

The Nacos client API now exposes a broader set of configuration constants in the new \PropertyKeyConst\ class, including parameters for endpoint parsing rules, RAM role/namespace parsing, client metrics, and thread counts for naming and config services. The \NacosFactory\ class has been moved to the \api\ module and now provides factory methods to create \LockService\ and \NamingMaintainService\ instances, while also deprecating the \createMaintainService\ methods in favor of the \nacos-maintainer-client\ artifact.

api/src/main/java/com/alibaba/nacos/api · medium confidence

New @Secured annotation for request authorization

A new @Secured annotation has been introduced in the auth module to mark requests that require authorization. This annotation allows developers to specify the action type, resource name, module (signType), custom resource parser, tags, and API type (ADMIN\_API or OPEN\_API) for fine-grained access control.

auth/src/main/java/com/alibaba/nacos/auth/annotation · high confidence

New A2aServerOperationService for agent registration and deletion

The A2aServerOperationService was added to handle agent lifecycle operations. It provides methods to register an agent by publishing its card and version information to the configuration system, and to delete an agent by removing its associated configuration data, including handling version-specific deletions and updating the latest published version.

ai/src/main/java/com/alibaba/nacos/ai/service/a2a · high confidence

New AI client API for agent cards, MCP servers, and endpoints

The Nacos AI client now exposes a comprehensive set of APIs for managing AI resources. Users can retrieve and release agent cards, as well as subscribe to changes for agent specifications. The API also supports registering, deregistering, and subscribing to changes for MCP (Model Context Protocol) servers and their associated endpoints, enabling dynamic discovery and management of AI services and tools.

api/src/main/java/com/alibaba/nacos/api/ai · high confidence

New AI event listener framework for agents, skills, prompts, and MCP servers

The Nacos API module now includes a new event-driven listener framework for the AI module. This adds a generic \NacosAiListener\ interface and a \NacosAiEvent\ marker interface to the \api/src/main/java/com/alibaba/nacos/api/ai/listener\ package. Specific event classes—\NacosAgentCardEvent\, \NacosAgentSpecEvent\, \NacosMcpServerEvent\, \NacosPromptEvent\, and \NacosSkillEvent\—are introduced to carry data about changes to agent cards, agent specs, MCP servers, prompts, and skills. Corresponding abstract listener classes (\AbstractNacosAgentCardListener\, \AbstractNacosAgentSpecListener\, \AbstractNacosMcpServerListener\, \AbstractNacosPromptListener\, and \AbstractNacosSkillListener\) are provided to simplify implementation. The \AbstractNacosAgentSpecListener\ and \NacosAiEvent\ interfaces were migrated from the legacy \naming\ module (\Message.java\ and \OperatorController.java\), while the remaining new files are entirely new additions.

api/src/main/java/com/alibaba/nacos/api/ai/listener · high confidence

New AI resource management APIs for agents, prompts, skills, and MCP servers

The AI module now exposes a comprehensive set of admin and client-side REST APIs for managing AI resources. Administrators can now manage the full lifecycle of AgentSpecs, Prompts, and Skills—including creating, updating, publishing, and deleting these resources, as well as managing drafts, versions, and metadata. The update also introduces dedicated controllers for A2A agent registration and updates, MCP server CRUD operations, and pipeline execution history queries. Additionally, a new import manager API allows administrators to search, validate, and execute imports of external AI resources. These endpoints are annotated with @Since version markers (3.0.1, 3.1.0, 3.2.0, 3.2.1, 3.2.2, 3.2.3) to indicate their introduction.

ai/src/main/java/com/alibaba/nacos/ai/controller · high confidence

New AI utility classes for AgentCard, AgentSpec, and MCP configuration

Added several new utility classes in the AI module to support AgentCard, AgentSpec, and MCP (Model Context Protocol) features. AgentCardUtil and AgentEndpointUtil handle the construction and transformation of A2A agent card and endpoint data. AgentRequestUtil and AgentSpecRequestUtil manage parsing and validation of agent card and agent spec requests. AgentSpecContentDigestUtils computes content hashes for agent specs. AgentSpecSeedArchiveReader and AgentSpecZipParser handle reading and parsing of agent spec ZIP archives with security hardening. ExecutorUtils provides thread pools for async storage IO. McpConfigUtils formats configuration data IDs for MCP servers. These utilities support the broader AI/AgentSpec and A2A capabilities.

ai/src/main/java/com/alibaba/nacos/ai/utils · high confidence

New API type, constants, and response code definitions

Added new types and constants to the Nacos API layer to standardize API classification, client configuration, and error handling. The \ApiType\ enum introduces four API categories: ADMIN\_API, CONSOLE\_API, OPEN\_API, and INNER\_API. The \Constants\ class defines key configuration parameters including the client version (3.0.0), default group and namespace IDs, HTTP header names, timeout values, and retry settings. Additionally, \ResponseCode\ provides structured error codes, starting with 10200 for general success, with a structure designed to separate module-specific codes (Naming, Config, Core) from global ones.

api/src/main/java/com/alibaba/nacos/api/common · high confidence

New CMDB operation controller and configuration component

A new REST controller at /nacos/v1/cmdb/ops/label is added, exposing a GET endpoint that accepts 'entry' and 'label' query parameters to query label information via the CmdbProvider. Additionally, a new Spring component SwitchAndOptions is introduced to manage CMDB-related configuration properties, including dumpTaskInterval, eventTaskInterval, labelTaskInterval, and loadDataAtStart, allowing users to configure CMDB task intervals and startup loading behavior.

cmdb/src/main/java/com/alibaba/nacos/cmdb/controllers · high confidence

New ConfigChangeClusterSyncRequest for cluster-wide config change propagation

A new remote request class, ConfigChangeClusterSyncRequest, has been added to handle synchronization of configuration changes across clusters. This class extends AbstractConfigRequest and includes fields for lastModified timestamp, grayName, and deprecated beta and tag properties, enabling the system to propagate and manage configuration updates in a clustered environment.

api/src/main/java/com/alibaba/nacos/api/config/remote/request/cluster · high confidence

New HTTP client response handlers for structured, string, and byte-array responses

The HTTP client package now includes a set of new response handlers that provide explicit support for deserializing HTTP responses into Java beans, raw strings, and byte arrays. The \BeanResponseHandler\ converts JSON responses into typed Java objects, \StringResponseHandler\ returns the raw body as a string, and \ByteArrayResponseHandler\ provides direct access to the response body as a byte array, addressing previous issues with byte\[\] deserialization. These handlers implement the new \ResponseHandler\ interface and extend \AbstractResponseHandler\, allowing callers to choose the most appropriate conversion strategy for their use case.

common/src/main/java/com/alibaba/nacos/common/http/client/handler · high confidence

New HTTP parameter extractors for AI resources

Added new HTTP parameter extractor classes for Nacos AI resources, including Agent, AgentSpec, MCP, Prompt, and Skill. These extractors handle the extraction of request parameters such as namespaceId, agentName, mcpName, and skillName, enabling the system to properly parse and validate incoming requests for these AI-related endpoints.

ai/src/main/java/com/alibaba/nacos/ai/param · high confidence

New HTTP parameter model classes for headers, media types, and query strings

The Nacos common module introduces three new classes to standardize HTTP interactions: Header, MediaType, and Query. The Header class now supports case-insensitive header key matching and preserves original response headers, addressing previous issues with header case sensitivity and charset handling. The MediaType class provides a structured representation of content types with explicit charset support (defaulting to UTF-8), ensuring consistent content-type headers across the client. The Query class offers a fluent API for building URL-encoded query strings with UTF-8 encoding. These changes improve reliability in HTTP communication by standardizing how headers, media types, and query parameters are constructed and encoded.

common/src/main/java/com/alibaba/nacos/common/http/param · high confidence

New HTTP resource parsers for AI, Config, and Naming services

Added new HTTP resource parsers (AbstractHttpResourceParser, AiHttpResourceParser, ConfigHttpResourceParser, NamingHttpResourceParser) to handle authentication for AI, Config, and Naming HTTP endpoints. The AI parser extracts resource names and namespaces from request parameters for MCP, A2A, Skill, Prompt, and AgentSpec paths. The Config parser handles namespace and group extraction for configuration services. The Naming parser extracts service names and groups for naming services. These changes enable fine-grained access control for these specific HTTP API paths.

auth/src/main/java/com/alibaba/nacos/auth/parser/grpc, auth/src/main/java/com/alibaba/nacos/auth/parser/http · high confidence

New InstanceIdGenerator SPI for custom instance ID generation

A new Service Provider Interface (SPI) named InstanceIdGenerator has been introduced in the Nacos API. This interface allows users to provide custom implementations for generating instance IDs, exposing a generateInstanceId method and a type identifier. This change enables users to replace the default instance ID generation logic with their own strategy.

api/src/main/java/com/alibaba/nacos/api/naming/spi · high confidence

New Java annotations for Nacos API configuration and versioning

Added four new Java annotations in the Nacos API module to support configuration injection and API versioning. The \@NacosApi\ annotation marks controllers for the Nacos API v2. The \@NacosInjected\ annotation enables automatic injection of \ConfigService\ or \NamingService\ instances into Spring beans, with a \properties\ attribute to specify \NacosProperties\. The \@NacosProperties\ annotation defines constants and placeholders for Nacos configuration keys (such as endpoint, namespace, server-addr, username, and password). Additionally, the \@Since\ annotation was introduced to mark the first Nacos version that supports a specific API.

api/src/main/java/com/alibaba/nacos/api/annotation · high confidence

New RPC response types for remote communication

Added a new set of response classes in the \api/src/main/java/com/alibaba/nacos/api/remote/response\ package to support remote procedure call (RPC) interactions. This includes a base \Response\ abstract class and specific response types such as \ClientDetectionResponse\, \ConnectResetResponse\, \ErrorResponse\, \HealthCheckResponse\, \ServerCheckResponse\, \ServerLoaderInfoResponse\, \ServerReloadResponse\, and \SetupAckResponse\. These classes provide the necessary structures for handling server checks, health checks, error states, and connection setup acknowledgments within the Nacos API.

api/src/main/java/com/alibaba/nacos/api/remote/response · high confidence

New annotations for Nacos config binding and listeners

The API module introduces five new annotations to support binding Java objects to Nacos configuration and handling config changes. \@NacosConfigurationProperties\ allows POJOs to be bound to Nacos properties with options for prefix, group, data ID, config type, and auto-refresh. \@NacosConfigListener\ marks methods as listeners for Nacos config changes, supporting group, data ID, config type, timeout, and custom converters. \@NacosProperty\ and \@NacosIgnore\ enable fine-grained control over which fields are bound or skipped during the binding process. \@NacosValue\ extends the standard \@Value\ annotation with an \autoRefreshed\ flag to support dynamic config updates. These annotations provide a declarative way to integrate with Nacos configuration management.

api/src/main/java/com/alibaba/nacos/api/config/annotation · high confidence

New base mapper and dialect classes for database plugin implementation

Added new base implementation classes for database mappers, including BaseConfigInfoMapper, BaseConfigTagsRelationMapper, BaseGroupCapacityMapper, BaseTenantCapacityMapper, and BaseTenantInfoMapper, which provide default SQL generation and pagination logic. Introduced the AbstractDatabaseDialect class to handle database-specific SQL transformations and limit clauses. Added a TrustedPostgresqFunctionEnum to manage and validate trusted SQL functions. Included corresponding unit tests for the mapper manager and dialect classes.

plugin-default-impl/nacos-default-datasource-plugin/nacos-datasource-plugin-base · high confidence

New classes for fuzzy watch configuration changes

The \api\ module now includes new classes to support fuzzy watch functionality: \AbstractFuzzyWatchEventWatcher\ and \FuzzyWatchEventWatcher\ define the listener interface for fuzzy watch events, \ConfigFuzzyWatchChangeEvent\ represents the event payload, and \ConfigChangeParser\ provides a parsing interface. Additionally, several listener-related classes (\AbstractListener\, \AbstractSharedListener\, \Listener\, and \FuzzyWatchLoadWatcher\) have been moved from the \client\ module to the \api\ module, with code style and formatting improvements applied.

api/src/main/java/com/alibaba/nacos/api/config/listener · high confidence

New configuration model classes for API responses

The API module now includes a set of new model classes for configuration data: ConfigBasicInfo, ConfigCloneInfo, ConfigDetailInfo, ConfigGrayInfo, ConfigHistoryBasicInfo, ConfigHistoryDetailInfo, and ConfigListenerInfo. These classes define the structure for configuration information, including basic details, cloning, detailed views, gray release states, and history. Additionally, the previous AppTest.java file was removed and replaced with a new SameConfigPolicy enum in the same package, defining policies for handling duplicate configurations (ABORT, SKIP, OVERWRITE).

api/src/main/java/com/alibaba/nacos/api/config/model · high confidence

New consistency module interfaces and serialization support

The consistency module introduces a new set of core interfaces and utilities to support data consistency protocols. This includes the \ConsistencyProtocol\ interface for managing cluster state and data operations, along with specific protocol implementations for AP and CP models. The update also adds a \Serializer\ interface with \HessianSerializer\ and \JacksonSerializer\ implementations to handle data serialization, alongside utility classes for protocol metadata and snapshot operations.

consistency · high confidence

New event subscriber abstraction in the common module

The Nacos common module now provides a new event notification infrastructure with two new abstract classes: \Subscriber\<T extends Event\>\ and \SmartSubscriber\. The \Subscriber\ class introduces a standard interface for handling events, including methods for specifying the event type, configuring an executor for asynchronous handling, and filtering expired or out-of-scope events. The \SmartSubscriber\ extends this to support listening to multiple event types simultaneously. This change refactors how components subscribe to and process internal Nacos events, offering a more flexible and typed approach to event handling.

common/src/main/java/com/alibaba/nacos/common/notify/listener · high confidence

New examples for AgentSpec, Skill, and Fuzzy Watch features

The example module now includes new demonstration code for recently added capabilities. AgentSpecExample and SkillExample showcase HTTP polling with 304 conditional queries for AI-related resources. ConfigFuzzyWatchExample and NamingFuzzyWatchExample demonstrate fuzzy listening for configuration and service discovery, respectively. Existing examples (App, Config, Naming) have been updated to use the default port 8848, include structured logging, and provide clearer output for users testing these features.

example · high confidence

New form classes for A2A agent registration and management

Added new Java form classes (AgentForm, AgentCardForm, AgentCardUpdateForm, AgentListForm) in the ai module to support agent registration, updates, and listing. These classes introduce validation for the 'registrationType' parameter (accepting 'URL' or 'SERVICE' values) and handle default namespace and search type logic, enabling the backend to process agent card data for the A2A admin API.

ai/src/main/java/com/alibaba/nacos/ai/form/a2a · high confidence

New form classes for AgentSpec management

The \ai/src/main/java/com/alibaba/nacos/ai/form/agentspecs/admin\ directory now contains a set of new form classes that define the input structures for managing AgentSpec resources. These include \AgentSpecForm\ as the base class, along with specific forms for listing (\AgentSpecListForm\), creating drafts (\AgentSpecDraftCreateForm\), updating details (\AgentSpecUpdateForm\), publishing (\AgentSpecPublishForm\), submitting (\AgentSpecSubmitForm\), managing labels (\AgentSpecLabelsUpdateForm\), managing business tags (\AgentSpecBizTagsUpdateForm\), and controlling online status (\AgentSpecOnlineForm\). This change introduces the backend data transfer objects required to support the new AgentSpec lifecycle and configuration capabilities.

ai/src/main/java/com/alibaba/nacos/ai/form/agentspecs/admin · high confidence

New labels collection framework for client connections

A new labels collection framework has been introduced to the common module, providing a pluggable system for gathering and managing key-value labels from multiple sources. The \LabelsCollector\ interface and \LabelsCollectorManager\ define the contract for collecting labels, while \DefaultLabelsCollector\ implements the default logic to aggregate labels from properties, JVM system properties, and environment variables. The manager loads all registered \LabelsCollector\ implementations via ServiceLoader, sorts them by priority, and merges their outputs, with validation ensuring keys and values are well-formed. This enables users to attach custom metadata to client connections through a structured, extensible mechanism.

common/src/main/java/com/alibaba/nacos/common/labels · high confidence

New maintainer API data models for naming service

Added new Java classes in the \api\ module under \com.alibaba.nacos.api.naming.pojo.maintainer\ to support the independent console calling remote Nacos servers. This includes \ClientServiceInfo\, \ClientSubscriberInfo\, \ClientSummaryInfo\, \ClusterInfo\, \InstanceMetadataBatchResult\, \MetricsInfo\, \ServiceDetailInfo\, \ServiceView\, and \SubscriberInfo\. Additionally, \ClientPublisherInfo\ was moved from the \client\ module to the \api\ module, with its package updated to \com.alibaba.nacos.api.naming.pojo.maintainer\ and its fields adjusted (e.g., \dom\ and \cluster\ replaced by \clientId\ and \clusterName\).

api/src/main/java/com/alibaba/nacos/api/naming/pojo/maintainer · medium confidence

New maintainer-client SDK for AI, MCP, and AgentSpec management

The maintainer-client module now includes a comprehensive SDK for managing AI resources, including AgentSpecs, MCP servers, and A2A agents. This introduces new interfaces and implementations (e.g., \AiMaintainerService\, \AgentSpecMaintainerService\, \McpMaintainerService\) that allow developers to programmatically register, update, delete, and list these AI resources via HTTP calls. The SDK provides a unified entry point through \AiMaintainerFactory\ and \NacosMaintainerFactory\, enabling direct client-side interaction with the Nacos server for AI-related administrative tasks.

maintainer-client · high confidence

New naming remote request types for gRPC and fuzzy watch

The Nacos API module introduces a new set of remote request classes to support gRPC-based naming operations and fuzzy watch subscriptions. This includes base classes like AbstractNamingRequest and AbstractFuzzyWatchNotifyRequest, alongside specific requests for service queries, subscriptions, instance registration, and fuzzy watch synchronization and notifications. These changes enable the client to communicate with the server via gRPC for operations such as registering instances, subscribing to service changes, and receiving fuzzy watch updates.

api/src/main/java/com/alibaba/nacos/api/naming/remote/request · high confidence

New pipeline execution data models for AI features

The API module now includes new data transfer objects for the AI pipeline system: \Checkpoint\ (audit criteria), \PipelineExecution\ (execution records), \PipelineExecutionResult\ (callback results), \PipelineExecutionStatus\ (IN\_PROGRESS, APPROVED, REJECTED), and \PipelineNodeResult\ (node-level details). These classes provide the structured data structures required for tracking and reporting on AI pipeline execution states and results.

api/src/main/java/com/alibaba/nacos/api/ai/model/pipeline · high confidence

New prompt form classes for versioning, labels, and metadata updates

The ai module introduces a comprehensive set of new form classes in the com.alibaba.nacos.ai.form.prompt package to support prompt lifecycle management. These include PromptForm as the base class, along with specialized forms for listing (PromptListForm), querying (PromptQueryForm), publishing (PromptPublishForm, PromptVersionPublishForm), updating drafts (PromptDraftCreateForm, PromptDraftUpdateForm), and managing metadata, labels, and business tags (PromptMetadataForm, PromptLabelForm, PromptLabelsUpdateForm, PromptBizTagsUpdateForm, PromptLabelBindForm). This structure enables users to create, version, publish, and manage attributes of AI prompts through the API.

ai/src/main/java/com/alibaba/nacos/ai/form/prompt · high confidence

New remote API abstractions and scheduling infrastructure

The \api/src/main/java/com/alibaba/nacos/api/remote\ package now includes new interfaces and abstract classes to support remote request handling and push callbacks. Specifically, \Requester\ defines the core request, future, and async request methods; \RequestFuture\ and \DefaultRequestFuture\ manage asynchronous request states and timeouts; \RequestCallBack\ and \PushCallBack\ (along with their abstract implementations \AbstractRequestCallBack\ and \AbstractPushCallBack\) provide callback mechanisms for requests and pushes. Additionally, \RpcScheduledExecutor\ introduces a dedicated scheduled thread pool for RPC operations, and \RemoteConstants\ provides label constants. The \Payload\ interface has been moved from the naming module to this remote package.

api/src/main/java/com/alibaba/nacos/api/remote · high confidence

New remote request and response classes for AI module endpoints

The Nacos API module introduces a new set of remote request and response classes to support the AI module's communication protocol. This includes base request classes for agents, MCP servers, and prompts, as well as specific request and response types for registering/deregistering endpoints, querying cards and servers, and releasing new versions of agent cards and MCP servers. These classes enable the client to interact with the AI module's remote interfaces for managing agent endpoints, MCP server registrations, and prompt versions.

api/src/main/java/com/alibaba/nacos/api/ai/remote · high confidence

New remote request types for config module

The Nacos API module introduces several new remote request classes to support config management over RPC. These include \ConfigFuzzyWatchRequest\ and \ConfigFuzzyWatchSyncRequest\ for batch fuzzy listening and synchronization, \ConfigFuzzyWatchChangeNotifyRequest\ for change notifications, \ConfigQueryRequest\ for querying config content, \ConfigPublishRequest\ for publishing configs, and \ConfigRemoveRequest\ for removing configs. The existing \NotifyTask\ and \ConfigInfo4Tag\ classes have been refactored into \AbstractConfigRequest\ and \ConfigRemoveRequest\ respectively, moving them from the server-side model/task packages to the remote request API layer to support the new RPC-based communication.

api/src/main/java/com/alibaba/nacos/api/config/remote/request · high confidence

New remote request types for connection management and health checks

The Nacos API module introduces several new remote request classes in the \com.alibaba.nacos.api.remote.request\ package to support a new remote communication model. These include \ClientDetectionRequest\ and \HealthCheckRequest\ for active client and server health checks, \ConnectResetRequest\ to handle connection resets, and \ConnectionSetupRequest\ to manage connection setup with client version, labels, and an ability table. Additionally, \PushAckRequest\ is added to acknowledge server pushes, while \RequestMeta\ is introduced to carry metadata such as connection ID, client IP, version, and capability status. These changes provide the foundational request types for the new remote channel and server push/retry mechanisms.

api/src/main/java/com/alibaba/nacos/api/remote/request · high confidence

New remote response models for config operations

Added new remote response classes to support the gRPC-based config channel: ConfigQueryResponse, ConfigPublishResponse, ConfigRemoveResponse, ConfigChangeNotifyResponse, ConfigChangeBatchListenResponse, ConfigFuzzyWatchResponse, ConfigFuzzyWatchSyncResponse, and ClientConfigMetricResponse. These classes define the data structures for config query, publish, remove, change notifications, batch listen, fuzzy watch, and client metrics, enabling the client and server to exchange configuration data and status updates over the new remote protocol.

api/src/main/java/com/alibaba/nacos/api/config/remote/response · high confidence

New response types for naming service remote calls

Added new API response classes for the naming service's remote communication layer, including \NamingFuzzyWatchResponse\, \NamingFuzzyWatchSyncResponse\, \NotifySubscriberResponse\, \QueryServiceResponse\, \ServiceListResponse\, \SubscribeServiceResponse\, and \BatchInstanceResponse\. These classes provide structured responses for operations such as fuzzy watching, service subscription, and instance querying. Additionally, \InstanceResponse\ was moved from the config module to the API module to support naming service instance operations.

api/src/main/java/com/alibaba/nacos/api/naming/remote/response · high confidence

New runtime exception types for serialization and loading errors

The Nacos API module introduces four new unchecked runtime exceptions in the \com.alibaba.nacos.api.exception.runtime\ package: \NacosRuntimeException\ (a base class with error codes), \NacosDeserializationException\, \NacosSerializationException\, and \NacosLoadException\. These provide structured error handling for serialization, deserialization, and loading failures, allowing callers to catch specific failure modes rather than generic runtime exceptions.

api/src/main/java/com/alibaba/nacos/api/exception/runtime · high confidence

New skill model classes for upload precheck and batch results

The API module now includes a new set of model classes for managing AI skills, including \SkillBase\, \Skill\, \SkillBasicInfo\, \SkillMeta\, \SkillResource\, \SkillSummary\, and \SkillUtils\. These classes define the structure for skill metadata, version summaries, and resource handling. Additionally, \BatchUploadResult\ and \SkillUploadPrecheckRequest\/\SkillUploadPrecheckResult\ are introduced to support pre-checking skill uploads and reporting batch upload outcomes. These changes enable the system to validate and process skill uploads with better error handling and metadata tracking.

api/src/main/java/com/alibaba/nacos/api/ai/model/skills · high confidence

New task execution engine architecture in the common module

The common module now introduces a new task execution engine framework, including the NacosTaskExecuteEngine interface and its implementations: AbstractNacosTaskExecuteEngine, NacosDelayTaskExecuteEngine, NacosExecuteTaskExecuteEngine, and TaskExecuteWorker. This replaces the previous task dispatcher with a more robust engine that supports both delayed and immediate task execution, featuring dedicated workers for handling tasks and improved logging and error handling.

common/src/main/java/com/alibaba/nacos/common/task/engine · high confidence

New trace enums for instance deregistration and health checks

Added two new trace enums to the common module: DeregisterInstanceReason, which defines the reasons for instance deregistration (such as client request, native disconnection, synced disconnection, and heartbeat expiration), and HealthCheckType, which defines health check types including client beat, HTTP, MySQL, and TCP super sense. These additions support the unified trace capacity building for tracking instance status and health check events.

common/src/main/java/com/alibaba/nacos/common/trace · high confidence

New utility classes for authentication header management and logging

Added AuthHeaderUtil, a utility class that injects server identity information into HTTP and gRPC headers based on the NacosAuthConfig, and Loggers, which provides a dedicated logger for the auth module with a method to dynamically set its log level.

auth/src/main/java/com/alibaba/nacos/auth/util · high confidence

OIDC authentication plugin for Nacos

Nacos now supports authentication via OpenID Connect (OIDC). Administrators can configure an OIDC provider (issuer, client ID, secret, scopes, etc.) to enable user login and authorization through an external identity provider. The plugin handles the authorization code flow, validates JWT tokens, and delegates fine-grained authorization decisions to the IdP's authorization endpoint. This allows Nacos to integrate with modern identity providers for both authentication and access control.

plugin-default-impl/nacos-oidc-auth-plugin · high confidence

Refactor client address and authentication into the client-basic module

The client-basic module now contains the core abstractions and implementations for server list management and client authentication. For server discovery, new classes (AbstractServerListManager, AbstractServerListProvider, EndpointServerListProvider, PropertiesListProvider) provide a pluggable, SPI-based mechanism to fetch and refresh the list of Nacos server addresses. For authentication, the module now includes the NacosClientAuthServiceImpl for standard username/password login and the OidcClientAuthServiceImpl for OIDC Client Credentials Flow, both of which manage token lifecycle and provide identity context to downstream components.

client-basic/src/main/java · high confidence

Refactored server authentication and authorization into a modular, plugin-based system

The core module's authentication and authorization logic has been refactored to support a plugin-based architecture. The previous monolithic \AuthManager\ has been replaced with a modular system where authentication is handled by pluggable \AuthFilter\ and \AuthAdminFilter\ components. This change introduces a new \AbstractWebAuthFilter\ that standardizes request processing, identity parsing, and permission validation. Additionally, the system now supports dynamic ability negotiation between clients and servers, allowing for more flexible feature activation and compatibility with older Nacos versions during upgrades. The refactoring also includes a new \InnerApiAuthEnabled\ component that manages the transition period for inner API authentication during the 2.x to 3.x upgrade, ensuring that internal cluster communication remains secure once all nodes are upgraded.

core · high confidence

Register AI service implementations via Java SPI

New Service Provider Interface (SPI) configuration files have been added to enable automatic discovery of AI-related components. Specifically, the system now registers the McpServerOperationService, AiPipelinePluginProvider, AiStoragePluginProvider, and various HttpParamExtractors (Mcp, Agent, Skill, SkillList) as well as the NacosConfigAiResourceStorageBuilder and AiEnabledFilter. This allows the application to dynamically load these AI capabilities at runtime.

ai/src/main/resources · high confidence

Register new remote payload types for fuzzy watch, distributed locks, and AI services

The Nacos API now registers a new set of remote payload classes via the Java SPI mechanism (META-INF/services/com.alibaba.nacos.api.remote.Payload). This includes support for config and naming 'fuzzy watch' requests and responses, distributed lock operation and notification requests/responses, and AI-related requests for querying and releasing MCP servers, querying and releasing agent cards, and batch agent endpoints. This change enables the remote communication layer to handle these new message types.

api/src/main/resources · high confidence

Service loader registrations for client authentication and server list providers

New META-INF/services files register the concrete implementations for client-side authentication (NacosClientAuthServiceImpl, RamClientAuthServiceImpl, OidcClientAuthServiceImpl) and server list providers (EndpointServerListProvider, PropertiesListProvider) via Java's ServiceLoader mechanism, enabling automatic discovery of these components at runtime.

client-basic/src/main/resources · high confidence

Removals

Removal of common utility classes

The \IoUtils\ and \UuidUtil\ utility classes have been removed from the \common\ module. This eliminates the built-in methods for reading streams, copying data, cleaning directories, and generating UUIDs, which may require users to adopt alternative implementations or third-party libraries for these operations.

common/src/main/java/com/alibaba/nacos/common/util · high confidence

Architecture

Centralized AI resource management and shared data structures

The AI module refactors duplicated logic from Skill and AgentSpec operation services into a new shared manager, AiResourceManager, which handles common operations like CAS updates, version resolution, and pipeline callbacks. Additionally, two new shared data structures, PublishPipelineInfo and ResourceVersionInfo, are introduced to replace duplicated inner classes, consolidating pipeline execution and version state management for all AI resources.

ai/src/main/java/com/alibaba/nacos/ai/service/resource · high confidence

Centralized constants and enums for AI resources, MCP, and A2A

The AI module now consolidates shared configuration and status definitions into dedicated constant and enum classes. New files include AiResourceConstants for resource and version lifecycle states (enable, disable, online, draft, reviewing, reviewed, offline), McpServerValidationConstants for MCP server validation statuses (valid, invalid, duplicate), and ExternalDataTypeEnum/McpImportResultStatusEnum for import operations. The Constants class defines API paths and metadata keys for MCP servers, A2A agents, and Skills, including endpoint groups, data ID templates, and header names. This refactoring extracts duplicated logic and constants from service implementations into a centralized location, improving maintainability and consistency across the AI feature set.

ai/src/main/java/com/alibaba/nacos/ai/constant · high confidence

Introduces a plugin-based architecture for configuration change operations

The config module now uses a plugin-based architecture for configuration change operations, allowing for extensible and modular handling of config publish, update, and delete actions. This change introduces new components such as \ConfigChangeAspect\, \ConfigOpFailureAspect\, and \ConfigChangeConfigs\ to manage and configure these plugins. The \ConfigChangeConfigs\ class, now marked as deprecated, is replaced by a more flexible plugin system that supports dynamic configuration and better separation of concerns. This architectural shift enables easier integration of custom logic into config change workflows, improving maintainability and extensibility.

config · high confidence

Nacos API naming POJOs migrated to api module

The naming data transfer objects (Instance, Service, ServiceInfo, ListView, and Cluster) have been moved from the client module to the api module. This change consolidates the public API layer, making these core naming structures available to all consumers of the Nacos API without requiring the full client dependency.

api/src/main/java/com/alibaba/nacos/api/naming/pojo · high confidence

Behavioural changes

AI resource model entities gain download tracking and versioning support

The AI module introduces new data models for AI resources and their versions, enabling download count tracking and version history. The \AiResource\ entity now includes a \downloadCount\ field and a \from\ field in its metadata, while a new \AiResourceVersion\ entity is added to track version details such as author, version string, and download count. These changes support the broader skill and resource lifecycle management capabilities.

ai/src/main/java/com/alibaba/nacos/ai/model · high confidence

Add AI resource trace logging

AI resource trace logs are now routed through trace events, with a new \AiResourceTraceEvent\ and a corresponding \AiResourceTraceLogSubscriber\ that outputs structured JSON logs for AI resource operations.

common/src/main/java/com/alibaba/nacos/common/trace/event/ai, plugin-default-impl/nacos-default-ai-trace-plugin · high confidence

Add Maven Wrapper for consistent builds

The project now includes a Maven Wrapper (mvnw) configured to use Maven version 3.9.9. This allows developers to build the project with a consistent, pre-configured version of Maven without needing to install it globally.

.mvn · high confidence

Added Apache 2.0 license header template

A new file, resources/copyright, was added containing the Apache 2.0 license header template. This change supports the unification of copyright headers across the project, specifically for nacos-common, by providing a standard license text for use in source files.

resources · high confidence

Added local IP address resolution and string utility classes to the API module

The api module now includes new utility classes: NetUtils, which provides methods to retrieve the local IP address by scanning network interfaces and respecting system properties for IP version and hostname preference, and StringUtils, which implements string manipulation methods (isEmpty, isBlank, trim, equals) copied from Apache Commons Lang3 to remove external dependencies. These additions allow the API layer to handle network address resolution and common string operations independently.

api/src/main/java/com/alibaba/nacos/api/utils · high confidence

Added protocol-specific identity context builders for authentication

The authentication module now uses dedicated builders to extract identity context from HTTP and gRPC requests. New classes—HttpIdentityContextBuilder and GrpcIdentityContextBuilder—implement the IdentityContextBuilder interface to parse headers and parameters (for HTTP) or request headers (for gRPC) into a unified IdentityContext, enabling the auth system to correctly identify users across different transport protocols.

auth/src/main/java/com/alibaba/nacos/auth/context · high confidence

Added security configuration for Nacos address server endpoints

A new Spring Security configuration class, AddressServerSecurityConfiguration, has been introduced to secure the Nacos address server. This configuration enforces HTTP Basic authentication for requests to the /nacos/v1/as/\\ endpoints, while explicitly disabling CSRF protection for this specific filter chain.

address/src/main/java/com/alibaba/nacos/address/config · high confidence

Built-in AI importers for MCP registry and skills.sh are now enabled by default

The default AI importer plugin now includes built-in importers for the official MCP registry and skills.sh, and these sources are enabled by default. A secure HTTP client enforces HTTPS-only connections and blocks requests to private or local network targets unless explicitly allowed via source properties. Users can disable the MCP or skills.sh importers or adjust security settings through the new configuration prefixes (e.g., nacos.plugin.ai.importer.mcp.official.enabled, nacos.plugin.ai.importer.skills.sh.enabled, and allow-http/allow-private-network on each source).

plugin-default-impl/nacos-default-ai-importer-plugin · high confidence

Centralized HTTP and request constants into the common module

The Nacos codebase has been refactored to centralize shared constants into the common module. HTTP header names (e.g., Client-Version, User-Agent) are now defined in a new HttpHeaderConsts interface. Response handling types (String, RestResult, byte\[\], default bean) are grouped in a new ResponseHandlerType class. URL prefixes (http/https) are moved to a new RequestUrlConstants interface. Additionally, the AuthType enum has been renamed and moved to the common module as Symbols, which now defines shared string constants like COMMA. These changes consolidate previously scattered constant definitions, making them easier to maintain and reuse across different Nacos modules.

common/src/main/java/com/alibaba/nacos/common/constant · high confidence

Centralized persistence configuration and datasource management

The persistence module now owns the complete lifecycle of database connectivity. A new DatasourceConfiguration class and associated condition classes (ConditionOnEmbeddedStorage, ConditionOnExternalStorage, etc.) centralize the logic for selecting between embedded (Derby) and external databases. This is supported by new classes for managing connection pools (DataSourcePoolProperties), dynamic datasource routing (DynamicDataSource), and external datasource properties (ExternalDataSourceProperties). Additionally, shared utilities like RowMapperManager and PaginationHelper have been moved into the persistence module to consolidate database access logic.

persistence · high confidence

Config filter interfaces moved to api module

The config filter interfaces (IConfigRequest, IConfigResponse, IConfigContext, IConfigFilter, IConfigFilterChain) and the abstract base class (AbstractConfigFilter) have been moved from the client and naming modules into the api module. This reorganization centralizes the config filter API, making these interfaces more accessible for developers building custom config filters.

api/src/main/java/com/alibaba/nacos/api/config/filter · high confidence

Deprecated ability initialization mechanism and introduced a new post-processing hook

The legacy \AbilityInitializer\ interface has been marked as deprecated, signaling that the old method of initializing abilities is no longer the recommended approach. To replace it, a new \AbilityPostProcessor\ interface has been introduced, which allows for post-processing of abilities based on the execution mode (SDK client, server, or cluster client). This change alters how ability configurations are processed during startup, moving from a direct initialization model to a post-processing model that can adapt to different runtime contexts.

api/src/main/java/com/alibaba/nacos/api/ability/initializer · high confidence

Deprecated old version ability API classes

The \ClientAbilities\ and \ServerAbilities\ classes in the \com.alibaba.nacos.api.ability\ package have been marked as \@Deprecated\. These classes, which previously managed client and server capabilities for remote, config, and naming features, are now superseded by newer ability structures. Users relying on these classes should migrate to the updated API to ensure compatibility with future releases.

api/src/main/java/com/alibaba/nacos/api/ability · medium confidence

Improved memory usage and startup performance via bean reuse and module state tracking

The sys module introduces a new bean post-processing mechanism that reuses Spring beans from the parent context to reduce duplicate rebuilds, thereby lowering memory usage. Additionally, the module now tracks and exposes module states (such as standalone/cluster mode, function mode, and version) to support independent deployment of the Nacos console and server.

sys · high confidence

Introduce NacosApiException for API v2.0 error handling

A new exception class, NacosApiException, has been added to the API module to support the v2.0 API error model. This exception extends the existing NacosException and introduces fields for a detailed error code and an abstract error message, allowing clients to receive more granular error information for API v2.0 requests.

api/src/main/java/com/alibaba/nacos/api/exception/api · high confidence

Introduce agent identity encoding for AI module

Added the AgentIdCodec interface and its default implementation, AsciiAgentIdCodec, to handle the encoding and decoding of agent names for storage and search. This change ensures that agent names are safely encoded, preventing unexpected search results and controlling character limits for storage. The AgentIdCodecHolder component provides access to this encoding logic, supporting both standard encoding and a specific encoding path for blur search operations.

ai/src/main/java/com/alibaba/nacos/ai/service/a2a/identity · medium confidence

Introduce protocol-specific auth services for HTTP and gRPC requests

The authentication logic for HTTP and gRPC requests is now handled by dedicated \HttpProtocolAuthService\ and \GrpcProtocolAuthService\ classes, which implement the new \ProtocolAuthService\ interface. This refactors the previous monolithic \AuthManager\ approach into a protocol-aware structure where each protocol can parse identity context and resources via specific parsers, while sharing a common abstract base \AbstractProtocolAuthService\ for server identity checks.

auth/src/main/java/com/alibaba/nacos/auth · medium confidence

Nacos address server refactored into dedicated components

The Nacos address server logic has been restructured into dedicated components within the \address\ module. A new \AddressServerGeneratorManager\ handles the generation of product names, instance lists, and response strings, while \AddressServerManager\ manages raw product and cluster names, IP splitting, and default values. These components are supported by new constants in \AddressServerConstants\ and logging utilities in \Loggers\. The main application entry point has been renamed from \Nacos\ to \AddressServer\ and moved to \com.alibaba.nacos.address\, with the \@ServletComponentScan\ annotation removed.

address/src/main/java/com/alibaba/nacos/address/component · high confidence

NacosException refactored to support exception chaining and improved error message resolution

The NacosException class has been moved from the client module to the api module. The exception now supports exception chaining via a new constructor that accepts a Throwable cause, and the getErrMsg() method has been updated to fall back to the underlying cause's message if the primary error message is blank. Additionally, a new error code for client disconnect has been added.

api/src/main/java/com/alibaba/nacos/api/exception · high confidence

New HTTP client request implementations

The Nacos common module introduces new HTTP client request implementations: an interface and default implementations for both synchronous (DefaultHttpClientRequest) and asynchronous (DefaultAsyncHttpClientRequest) HTTP requests using Apache HTTP Client 5, alongside a JDK-based implementation (JdkHttpClientRequest). These classes provide the concrete execution logic for HTTP requests within the common library.

common/src/main/java/com/alibaba/nacos/common/http/client/request · high confidence

New HTTP client response abstractions for Apache and JDK clients

The HTTP client layer now introduces a common \HttpClientResponse\ interface and concrete implementations (\DefaultClientHttpResponse\ for Apache HttpComponents 5 and \JdkHttpClientResponse\ for the JDK HTTP client). These classes standardize how HTTP responses (status code, headers, and body stream) are accessed and closed, ensuring consistent handling of response streams and header parsing across different HTTP client implementations.

common/src/main/java/com/alibaba/nacos/common/http/client/response · high confidence

New resource parsing infrastructure for authentication

The auth module now includes a new resource parsing framework consisting of a ResourceParser interface and an AbstractResourceParser base class that extracts namespace, group, name, and custom properties from requests. A default implementation (DefaultResourceParser) is also provided. This change introduces the core mechanism for parsing security metadata from incoming requests, which is essential for the system's authorization logic.

auth/src/main/java/com/alibaba/nacos/auth/parser · high confidence

Redesigned startup scripts and configuration for native and Java modes

The distribution package's startup scripts (startup.sh, startup.cmd, startup-native.sh) have been significantly refactored to support both Java and native (GraalVM) server modes, with improved environment detection and JVM configuration. The system now enforces a secure, Base64-encoded token secret key, prompting users to set it if missing. Additionally, the default server port has been changed from 8080 to 8848, and the console UI is disabled by default, requiring explicit configuration to enable. The logback configuration has been updated to use a configurable log path and includes new appenders for CMDB and async logging.

distribution · high confidence

Refactor health check serialization to use Jackson

The health check serialization mechanism has been replaced from Fastjson to Jackson. The \AbstractHealthChecker\ class now uses Jackson annotations (\@JsonTypeInfo\, \@JsonSubTypes\) for polymorphic type handling, and the \HealthCheckerFactory\ delegates serialization and deserialization to \JsonUtils\ (Jackson-based). This change affects how health check objects are serialized to and deserialized from JSON, ensuring compatibility with the new Jackson-based serialization path.

api/src/main/java/com/alibaba/nacos/api/naming/pojo/healthcheck · high confidence

Refactored Nacos naming API with new factory classes and constants

The naming API module has been refactored to improve structure and maintainability. New factory classes, NamingFactory and NamingMaintainFactory, have been introduced to create NamingService and NamingMaintainService instances, replacing previous instantiation patterns. A new CommonParams class defines shared parameter constants for service discovery, and a PreservedMetadataKeys class centralizes reserved metadata keys. The NamingResponseCode class was added to handle naming-specific response codes. These changes streamline the API's public surface and prepare for future enhancements in service registration and management.

api/src/main/java/com/alibaba/nacos/api/naming · high confidence

Refactored control plugin architecture with new manager center and rule storage

The control plugin has been refactored to introduce a centralized \ControlManagerCenter\ that manages both TPS and connection control managers. This change introduces a new \ControlConfigs\ for configuration, a \RuleStorageProxy\ to handle local and external rule storage, and a \ControlRuleChangeActivator\ to listen for rule changes. The refactoring also includes new SPI interfaces like \ControlManagerBuilder\ and \ExternalRuleStorageBuilder\ to support pluggable control implementations, and a \DefaultConnectionControlManager\ that provides a no-limit fallback. These changes improve the modularity and extensibility of the control plugin.

plugin/control · high confidence

Refactored naming event listener architecture with new fuzzy watch support

The naming event listener package has been restructured: core interfaces (Event, EventListener) and the concrete NamingEvent class have been moved from the client module to the api module. NamingEvent now exposes groupName and clusters fields, allowing users to identify the specific service group and cluster in event callbacks. Additionally, new classes have been introduced to support fuzzy watch functionality: the FuzzyWatchChangeEvent event, the FuzzyWatchEventWatcher and FuzzyWatchLoadWatcher interfaces, and their respective abstract base classes (AbstractEventListener, AbstractFuzzyWatchEventWatcher) that allow users to provide custom executors for event handling.

api/src/main/java/com/alibaba/nacos/api/naming/listener · high confidence

Separate client and server ability registration

The ability registration mechanism has been refactored to distinguish between client-side and server-side capabilities. New classes have been introduced: \AbstractAbilityRegistry\ provides the base registry logic, while \ClusterClientAbilities\ and \SdkClientAbilities\ now handle client-side ability declarations, and \ServerAbilities\ handles server-side ones. This separation allows the system to negotiate capabilities more precisely, ensuring that features like persistent instance registration via gRPC, fuzzy watch, distributed locks, and agent registry are only used if both the client and server support them.

api/src/main/java/com/alibaba/nacos/api/ability/register · medium confidence

Server startup split into web and non-web application contexts

The server startup logic has been refactored to separate web and non-web bean loading into two distinct Spring Boot application contexts: NacosServerWebApplication and NacosServerBasicApplication. This change introduces new type filters (NacosWebBeanTypeFilter, NacosNormalBeanTypeFilter) to exclude web-specific beans from the basic application and vice versa, allowing the server to start with different web containers and ports. Additionally, the server properties now explicitly enable servlet encoding and configure the main server port and context path.

server · high confidence

Service provider files added for JSON adapters, labels, param checking, and path encoding

The project now registers concrete implementations for several core interfaces via Java SPI (Service Provider Interface) files in META-INF/services. Specifically, Jackson 2 and Jackson 3 JSON adapters are registered, a default labels collector is registered, a default parameter checker is registered, and a Windows path encoder is registered. Additionally, the version file has been moved from client/src/main/resources/application.properties to common/src/main/resources/nacos-version.txt.

common/src/main/resources · medium confidence

Shared model classes moved to the API module

The \Page\ class, previously located in the config server module, has been moved to the shared \api\ module, making it available for all Nacos clients and servers. Additionally, a new \NacosForm\ interface has been added to the \api\ module to support HTTP form validation for remote calls.

api/src/main/java/com/alibaba/nacos/api/model · high confidence

Support independent deployment of Nacos Console and Server

The Nacos bootstrap entry point has been refactored to support independent deployment of the Nacos Console and the Nacos Server. The application now starts different Spring Boot contexts based on a deployment type (MERGED, SERVER, or CONSOLE), allowing users to run just the server, just the console, or both together. Additionally, the startup process now conditionally initializes the AI registry context if the MCP or skill registry features are enabled.

bootstrap/src/main/java · high confidence

Unified HTTP client implementation with Apache HTTP Components 5

The common module's HTTP client layer has been refactored to use Apache HTTP Components 5. This change introduces new factory classes (AbstractHttpClientFactory, AbstractApacheHttpClientFactory, DefaultHttpClientFactory) and a centralized bean holder (HttpClientBeanHolder) to manage NacosRestTemplate and NacosAsyncRestTemplate instances. The update ensures proper lifecycle management, including shutdown hooks and connection manager cleanup, which improves stability and resource management for HTTP operations.

common/src/main/java/com/alibaba/nacos/common/http · medium confidence

Test coverage

Add Java SDK integration test module with scenario coverage registry; Add unit tests for AI resource constants; Add unit tests for server identity authentication components; Add unit tests for the Page model serialization; Added integration tests for the distributed lock feature; Added integration tests for the maintainer SDK; Added mock auth plugin service for testing; Added mock authentication and resource parsing utilities for unit testing; Added test resources for Spas authentication and server list provider; Added test resources for unit testing; Added tests for AI pipeline model consistency and serialization; Added tests for AI publish pipeline execution and routing; Added tests for AI resource import configuration; Added tests for AI resource trace service; Added tests for AgentSpec visibility, deletion, label updates, list filtering, and pipeline completion; Added tests for AgentSpecScopeForm validation; Added tests for pipeline execution repository; Added tests for pipeline query service and consistency; Added tests for skill form validation; Added tests for the AI resource import manager; Added tests for the JSON adapter selection and utility classes; Added unit and integration tests for the address module; Added unit tests for A2A identity codec components; Added unit tests for A2aServerOperationService; Added unit tests for AI controller endpoints; Added unit tests for AI module MCP server index components; Added unit tests for AI module configuration components; Added unit tests for AI module form validation; Added unit tests for AI module parameter extractors; Added unit tests for AI module utility classes; Added unit tests for AI prompt management and download counting; Added unit tests for AI remote request handlers; Added unit tests for AI resource import operators; Added unit tests for AI resource persistence services; Added unit tests for AI resource storage key generation and parsing; Added unit tests for AI skill management services; Added unit tests for API response models; Added unit tests for AiResource model; Added unit tests for AiResourceManager; Added unit tests for CMDB POJOs and exception classes; Added unit tests for ClientAbilities and ServerAbilities serialization and equality; Added unit tests for HTTP resource parsers; Added unit tests for InstanceBuilder; Added unit tests for MCP server service layer; Added unit tests for Nacos API ability registration; Added unit tests for Nacos API and client services; Added unit tests for Nacos API naming pojo classes; Added unit tests for Nacos API naming remote request and response classes; Added unit tests for Nacos API utility classes; Added unit tests for NacosProperties placeholder resolution; Added unit tests for NamingUtils; Added unit tests for auth configuration and utilities; Added unit tests for client and server remote ability serialization; Added unit tests for client-basic authentication and server list providers; Added unit tests for common module components; Added unit tests for health check serialization and deserialization; Added unit tests for identity context builders; Added unit tests for maintainer POJOs; Added unit tests for prompt form validation; Added unit tests for the Nacos AI service client; Added unit tests for the Nacos API config module; Added unit tests for the Nacos lock API and client components; Added unit tests for the new gRPC and HTTP protocol auth services; Added validation tests for pipeline form objects; Expanded integration test coverage for AI admin OpenAPI endpoints.

Dependencies

Introduce new modular Nacos components and next-generation console UI

The project structure is reorganized into new modules: nacos-address, nacos-ai, nacos-ai-registry-adaptor, nacos-api, nacos-auth, nacos-bootstrap, nacos-client-basic, nacos-cmdb, nacos-consistency, and nacos-console-ui-next. These new Maven modules define the build and dependency graph for the address, AI, API, authentication, bootstrap, client, CMDB, and consistency layers. Additionally, the next-generation console UI (console-ui-next) is introduced with its own package.json and package-lock.json, establishing the frontend dependency tree for the modernized console interface.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 43.

Lenses

  • Code Health 51
  • Architecture 99
  • Maturity 73
  • Readiness 37
  • Security 38
  • Domain Modelling 100
  • Accessibility 43

Changes since last survey

  • 300 commits — 220 feature/other, 80 fixes

By area

  • ai/src — 37 commits
  • console/src — 32 commits
  • console-ui-next/src — 20 commits
  • client/src — 18 commits
  • config/src — 18 commits
  • common/src — 15 commits
  • (root) — 14 commits
  • core/src — 14 commits
  • naming/src — 11 commits
  • api/src — 10 commits
  • specs/en — 10 commits
  • test/maintainer-sdk-test — 9 commits
  • .github/workflows — 8 commits
  • plugin-default-impl/nacos-default-auth-plugin — 8 commits
  • test/openapi-test — 8 commits
  • test/java-sdk-test — 7 commits
  • maintainer-client/src — 6 commits
  • (repo) — 5 commits
  • plugin-default-impl/nacos-default-ai-importer-plugin — 5 commits
  • distribution/bin — 4 commits

Notable commits

  • fix: Apply the #14751 check-then-act fix to remaining naming index readers (#15182)
  • fix: Fix config namespace isolation for ID-based operations (#15498)
  • fix: Fix equals and hashCode contract violation in ManagerListenerWrap (#14959)
  • fix: Fix flaky prompt cache, task manager, and fuzzy watch tests (#15187)
  • fix: Fix off-by-one page count in PageUtil for divisible totals (#15446)
  • fix: Fix prompt get default scope problem (#14919)
  • fix: Fix skill meta description sync on upload (#15204)
  • fix: Fix trailing separator in StringUtils.join when collection has null elements (#15410)
  • fix: For #15240, Fix skill download filename overflow (#15241)
  • fix: Merge pull request #14928 from LiyunZhang10/fix-remove-subscriber-indexes-race
  • fix: Potential fix for pull request finding 'CodeQL / Workflow does not contain permissions'
  • fix: [AI] Fix missing writeLock in MemoryMcpCacheIndex#removeIndex (data race) (#15067)
  • fix: [BUG] Fix cross-thread visibility and race conditions for ManagerListenerWrap inNotifying (#14960)
  • fix: [Bug] Fix TOCTOU race condition and thread leak in ClientWorker.ensureSyncExecutor() (#14927)
  • fix: [Bug] Fix TOCTOU race condition and unsafe lazy init in CacheItem.initConfigGrayIfEmpty() (#14934)
  • fix: [ISSUE #12585] Fix pagination parameter binding (#15407)
  • fix: [ISSUE #14693] Fix MCP service selector pagination (#15413)
  • fix: [ISSUE #14774] fix(plugin/oidc): shade Caffeine into plugin jar to avoid NoClassDefFoundError (#15001)
  • fix: [ISSUE #14815] fix(style): change continuation_indentation from 2 to 1 (#15092)
  • fix: [ISSUE #14908] fix(ai): SkillRemoteHandler#createDraft passes skillCard as targetVersion and loses targetVersion (#14909)
  • …and 280 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

alibaba/nacos was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 5 August 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 41b6c5ad5870da2f6b5c86a1af776803cf8f1f35 — the exact code this score is about.
  • Scored under rubric-2026.08.19 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer latest.