Skip to content
CAI
Software that uses CAICheck a score

amazon-mq/rabbitmq-stream-s3

66.6

Adequate · 2 October 2026

22.2k

lines of production code

Erlang

with Clojure

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a RabbitMQ Stream plugin that implements tiered storage by offloading data to S3-compatible object stores. It manages the lifecycle of stream fragments and manifests, handling local retention, remote uploads, and garbage collection of dangling objects. The codebase includes extensive tooling for validation, such as Jepsen-based fault injection tests, formal verification models for concurrency and replication protocols, and integration benchmarks to ensure data durability and consistency under failure conditions.

Features

Add S3 remote reader benchmark harness

Adds a new set of shell scripts (\s3-bench-defaults.sh\, \s3-bench-env.sh\, \s3-bench-lib.sh\, \s3-bench-sweep.sh\, \s3-bench-validate.sh\) to benchmark the S3 remote reader. The harness provisions a MinIO instance via Podman/Docker, applies network latency shaping using \netem\, and runs stress tests to measure throughput against client connection ceilings and plugin defaults. It includes validation scenarios to ensure the benchmark results align with historical broker measurements.

scripts · high confidence

Added TLA+ formal models for Osiris and manifest replication protocols

Added formal TLA+ specifications and model-checking configurations for the Osiris replication protocol (including remote tier extensions) and the manifest edit replication protocol. These models allow users to verify protocol invariants—such as sequence bounds and replica consistency—under conditions like unreliable message delivery, node disconnects, and epoch transitions, primarily using simulation mode due to state-space size.

tla · high confidence

Automated Jepsen testing for S3 stream plugin in CI

A new CI entry point script (run-jepsen.sh) has been added to the jepsen/ci directory to orchestrate Jepsen tests for the stream\_s3 plugin. This script manages the cluster lifecycle by invoking up.sh, run.sh, and down.sh scripts located in the docker directory, ensuring the test environment is torn down regardless of the test outcome. It exposes configuration tunables such as time limits, rate, concurrency, and fault injection strategies (e.g., partition, s3-outage) via environment variables, allowing the test to be integrated into GitHub Actions workflows to validate consistency and fault tolerance.

jepsen/ci · high confidence

Formal verification of stream deletion and GC safety via P models

Added P formal models to verify critical concurrency invariants in the tiered-storage plugin. The \delete-stream-anchor\ model proves that reclaiming objects after queue deletion is safe only if the anchor node is written before the first fragment and read with strong consistency, preventing live-stream reaping. The \gc-decision\ model composes the entire orphan GC reap decision, verifying that the combination of epoch gates, live-floor re-reads, and live carve-out re-derivations prevents dangling-reference deletions across interleaved resets and sweeps.

p · high confidence

Introduce S3 remote tier manifest and fragment data structures

Added include headers defining the binary layout for the S3 remote tier, including records for fragments and manifests, macros for segment and index headers, and constants for manifest versions and entry sizes. These definitions establish the on-disk/on-remote format for storing stream data in S3, enabling the writer to construct and parse manifest trees and fragment references.

include · high confidence

New CLI commands for tiered storage management

Added CLI commands to manage the S3 tiered storage plugin: \evaluate\_local\_retention\ and \evaluate\_remote\_retention\ trigger retention evaluations for local and remote tiers respectively; \force\_fragment\_cut\ forces the current in-progress fragment to cut and upload immediately; \stream\_s3\_gc\ identifies or deletes dangling objects in the remote tier with \dry\_run\ and \delete\ modes; and \stream\_s3\_status\ displays detailed tiered storage status including bucket accessibility, stream info, remote tier offsets, upload pipeline state, and current fragment assembly details.

src · high confidence

New Docker-based Jepsen test harness for RabbitMQ Stream S3 storage

Added a complete local test environment for validating RabbitMQ's S3 storage tier using Jepsen. The change introduces Dockerfiles for control and node containers, a docker-compose topology including five RabbitMQ broker nodes, a MinIO S3-compatible store, and a Toxiproxy for fault injection. It also provides shell scripts (up.sh, down.sh, run.sh) to build the broker, generate test certificates, and execute Jepsen tests with configurable faults like partitions and S3 outages.

jepsen/docker · high confidence

New Jepsen test harness for RabbitMQ Stream S3 tiered storage

A new Jepsen test suite for the RabbitMQ Stream S3 plugin has been added to validate data durability and storage-tier behavior under fault conditions. The harness exercises the S3 tiering path by injecting faults such as S3 outages, S3 latency, leader moves, and member churn, while verifying that data is actually uploaded to and read from S3. It includes a durability checker to ensure no writes are lost or duplicated, a tiering checker to confirm S3 usage, and a replica consistency checker to detect cache divergence or stale floors.

jepsen/jepsen.streams3 · high confidence

New configuration schema for RabbitMQ Stream S3 plugin

The plugin now includes a formal configuration schema (rabbitmq\_stream\_s3.schema) that defines and validates settings for S3 integration. This schema maps user-facing options such as AWS region, bucket name, and static credentials to internal configuration keys, while explicitly defaulting static credentials to be ignored unless explicitly enabled. It also introduces configuration for remote read prefetch bounds, manifest persistence thresholds, and S3 account ownership verification.

priv · high confidence

Test coverage

Added config schema tests for RabbitMQ Stream S3 settings; Expanded test coverage for core storage and API components; New Java-based integration test suite for S3 tiered storage.

Dependencies

Add Java integration test harness for tiered storage

Added a new Maven-based Java test harness (\stream-s3-integration-test\) in \test/integration\ to support end-to-end testing of the RabbitMQ Stream S3 tiered storage plugin. The harness uses the RabbitMQ Stream Java client (v1.5.0) for precise control over consumer offsets and message counts, and switches the Management API client to the Hop client (v5.5.0). It also includes dependencies for AWS SDK S3 (v2.46.2), Jackson Databind (v2.22.2), SLF4J/Logback, Picocli, and Guava, and builds a shaded JAR with the main class \com.amazon.mq.rabbitmq.stream.s3.Main\.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 59 → 67 (+7.6)
  • Rubric changed (rubric-2026.09.12 → rubric-2026.09.18) — scores are not directly comparable.

Lenses

  • Code Health 94 → 94 (+0.0)
  • Architecture 100 → 100 (+0.0)
  • Maturity 73 → 74 (+0.1)
  • Readiness 30 → 45 (+14.8)
  • Security 89 → 95 (+5.5)
  • Event Sourcing 100 → 100 (+0.0)

Resolved (9)

  • Coverage not measured — no coverage collector is wired up
  • Documentation: no installation or build instructions (p/read-resolution/README.md)
  • Hotspot: src/rabbitmq_stream_s3_api_aws.erl (src/rabbitmq_stream_s3_api_aws.erl)
  • Hotspot: src/rabbitmq_stream_s3_log_reader.erl (src/rabbitmq_stream_s3_log_reader.erl)
  • Hotspot: src/rabbitmq_stream_s3_replica_reader.erl (src/rabbitmq_stream_s3_replica_reader.erl)
  • Hotspot: src/rabbitmq_stream_s3_replica_reader_tasks.erl (src/rabbitmq_stream_s3_replica_reader_tasks.erl)
  • Off-boarding risk: anonymized user #1
  • Scanner failed to run — not a clean result
  • Scanner failed to run — not a clean result

New (1)

  • Off-boarding risk: anonymized user #1

Changes since last survey

  • 11 commits — 9 feature/other, 2 fixes

By area

  • (repo) — 4 commits
  • docs/operations.md — 2 commits
  • src/rabbitmq_stream_s3_log_reader.erl — 2 commits
  • .github/workflows — 1 commit
  • src/rabbitmq_stream_s3_remote_reader_core.erl — 1 commit
  • test/integration — 1 commit

Notable commits

  • fix: Merge pull request #375 from amazon-mq/fix/374-close-stops-remote-reader
  • fix: Merge pull request #378 from amazon-mq/fix/373-clamp-search-to-budget
  • change: Bump aws-actions/configure-aws-credentials in the github-actions group
  • change: Bump com.fasterxml.jackson.core:jackson-databind in /test/integration
  • change: Clamp the concurrency search to what the fetch budget can spend
  • change: Close a reader that has served a consumer in the close test
  • change: Cover the ramp's hold arm, and correct what it claims
  • change: Merge pull request #377 from amazon-mq/dependabot/github_actions/github-actions-ae05891aa2
  • change: Merge pull request #379 from amazon-mq/dependabot/maven/test/integration/com.fasterxml.jackson.core-jackson-databind-2.22.2
  • change: Round the expressible target up, and hold the ramp at it
  • change: Stop the remote reader when the log reader is closed

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

amazon-mq/rabbitmq-stream-s3 was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 2 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit f3de67fe372d28ab71f33871fb368937f6343263 — the exact code this score is about.
  • Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.