Skip to content
CAI
Software that uses CAICheck a score

andreapavoni/parabellum

41.7

Weak · 21 September 2026

57.2k

lines of production code

Rust

with TypeScript

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a Rust-based multiplayer game server that implements a CQRS and Event Sourcing architecture to manage complex game mechanics. It handles core gameplay loops including military combat, hero progression, resource trading, and village management through a structured application layer. The backend exposes a JSON API for a Preact single-page application, supporting user authentication, state hydration, and game actions.

How it got here

2024–2025 — Full-stack architecture and domain model overhaul

15 changes.

The project underwent a comprehensive architectural shift to a Rust/CQRS backend and a Preact frontend, introducing a modular workspace structure and event-sourced database schema. This period focused on implementing core gameplay mechanics, including hero progression, battle simulation, and marketplace systems, while establishing robust authentication and structured error handling across the stack.

2026 — CQRS/ES architecture and SPA migration

4 changes.

The codebase underwent a major architectural shift to CQRS and Event Sourcing, introducing new event consumers and an event store for village and report data. Simultaneously, the project migrated to a Preact-based single-page application with a comprehensive JSON API, supported by new CLI tools for data management and state reconstruction.

Features

Add project scaffolding and build configuration

The repository now includes essential configuration files to support the application's build and development workflow. A Dockerfile is introduced to define the multi-stage build process for the Rust backend and Bun-managed frontend, while docker-compose.yml and docker-compose-prod.yml provide containerized environments for development and production respectively. Additionally, a Justfile is added to streamline common development tasks such as running the server, starting the database, and executing tests. The project also includes a .gitignore to exclude build artifacts and environment files, a tsconfig.json for TypeScript configuration, and a vite.config.ts to manage the frontend build pipeline.

(repo-wide) · high confidence

Add token-based API authentication and HTTP routing

The web layer now implements a complete HTTP server using Axum, exposing a JSON API under /api/v1/\* and serving the SPA frontend. Authentication is handled via short-lived JWT access tokens and opaque refresh tokens, with session management stored in the database. The router registers endpoints for login, register, logout, and session management, alongside game-related actions like troop movement, building construction, and marketplace operations.

_parabellum\web · high confidence

Introduce CLI tools for event sourcing and data management

Added four new command-line utilities to the server binary directory: the main application entry point (parabellum.rs) which initializes the game application, event-sourcing worker, and web server; a backfill utility (parabellum\_backfill\_heroes.rs) that repairs missing hero and army links for existing players; a replay utility (parabellum\_replay.rs) that supports dry-run and full event replay, as well as snapshot rebuilding; and a seed utility (parabellum\_seed.rs) for generating test data. These tools support the new CQRS/ES architecture by providing operational commands for data migration, state reconstruction, and environment seeding.

_parabellum\server/bin · high confidence

Introduce JSON API for game actions, authentication, and building details

The \parabellum\_web/api\ module now exposes a comprehensive JSON API for the frontend. This includes endpoints for user authentication (login, register, refresh, logout), game state hydration (context, map, reports), and detailed building information. The API supports mutation actions such as building, training, sending troops, and managing the marketplace, all mapped to standardized error responses and DTOs.

_parabellum\web/api · high confidence

Introduced battle simulation and hero mechanics

Added a new battle simulation module that calculates combat outcomes, including attack/defense points, loyalty reduction, and building damage. The system now supports heroes, which provide offensive and defensive bonuses to armies and can gain experience or die in battle. Additionally, the codebase was reorganized, moving game models into a new \parabellum\_game\ crate and introducing factory utilities for testing.

_parabellum\game · high confidence

Introduces application-layer services for identity, map, and leaderboards

The \parabellum\_app\ crate now provides a structured application facade that orchestrates game use cases. This includes a \GameApplication\ service that composes identity, map, and leaderboard ports, alongside dedicated use-case modules for player registration, map reads, and player population leaderboards. The change also adds password hashing utilities and configuration loading for authentication and server settings.

_parabellum\app · high confidence

Introduces core game type definitions for units, buildings, and reports

The parabellum\_types module now defines the foundational data structures for the game's entities. This includes detailed definitions for military units (including Romans, Teutons, Gauls, Natar, and Nature tribes) with their specific stats, costs, and requirements. It also introduces building classifications, map topology structures, and comprehensive report payloads for battles, reinforcements, and market deliveries. These types enable the backend to model and serialize game state, unit compositions, and event logs.

_parabellum\types · high confidence

Major domain model overhaul and new feature integrations

The game's domain models have been significantly restructured and expanded. The \parabellum\_game/models\ directory now includes new models for \Army\, \Hero\, \CulturePoints\, \Marketplace\, \Smithy\, \Trapper\, and \Village\, alongside a refactored \buildings\ module. These changes introduce core gameplay mechanics including hero progression (experience, health, and attribute points), a player-driven marketplace for resource trading, a trapper building for capturing enemy troops, and culture points for village expansion. The \Army\ model now supports hero integration, while \Village\ tracks culture points and merchant capacity. These changes reflect a shift towards a more complex, CQRS/Event-Sourced architecture with deeper simulation of military, economic, and cultural systems.

_parabellum\game/models · medium confidence

Preact frontend rewrite with new UI components and routing

The frontend has been rewritten in Preact, introducing a new client-side routing system that manages navigation between pages such as Village, Resources, Building, Stats, Player, Reports, and Map. The application now uses a centralized \App\ component to handle authentication sessions, global state invalidation, and route-based rendering. New UI components have been added, including \Layout\ for the main shell and navigation, \ArmyTable\ for displaying military units and hero status, \BuildingSprite\ and \UnitSprite\ for rendering building and unit icons, \QueueList\ for construction queues, and \VillageMap\ for visualizing the village layout. The \useAuthSession\ hook manages login, logout, and session refresh logic, while the \Link\ component enables client-side navigation. This change replaces the previous frontend implementation with a modern, component-based architecture.

frontend/src · high confidence

Removals

Removal of legacy game model structs

The legacy model structs for the game domain have been removed, including \Army\, \common\ types (such as \Tribe\, \Cost\, \ResourceGroup\, and \Player\), \map\ definitions (like \Valley\, \Oasis\, and \Position\), and \Village\ with its associated building and production logic. This cleanup eliminates outdated structures that were likely superseded by newer domain models.

src/game · high confidence

Removed empty lib.rs and main.rs files

The empty src/lib.rs and src/main.rs files have been removed from the project.

src · high confidence

Architecture

Migrate to CQRS/ES architecture for village and report projections

The infrastructure layer now implements a Command-Query Responsibility Segregation (CQRS) and Event Sourcing (ES) architecture. This introduces new event consumers (VillageProjector, ReportProjector) that process domain events to update read models and generate reports for battles, marketplaces, and reinforcements. It also adds a VillageEsAdapter to handle village data access via the new event store, and establishes database connection pools for the event store. This change shifts how village states and reports are persisted and queried, moving from direct database writes to event-driven projections.

_parabellum\infra · high confidence

Behavioural changes

Added .gitkeep file to frontend/assets

A .gitkeep file was added to the frontend/assets directory. This ensures the assets directory is tracked by version control, preventing it from being ignored or removed when the directory is empty.

frontend/assets · high confidence

Adds structured logging with daily log rotation

The application now initializes structured logging via the \tracing\_subscriber\ crate, configuring two output layers: a console layer for immediate feedback and a daily rotating file layer that writes to the \logs/\ directory. Log verbosity is controlled by the \RUST\_LOG\ environment variable, defaulting to \info\ for most crates and \debug\ for the \parabellum\ crate, while suppressing verbose output from \tower\_http\ and \sqlx\.

_parabellum\server/src · medium confidence

Database schema expanded to support CQRS, event sourcing, and game mechanics

The database schema has been significantly expanded to support a new CQRS/Event Sourcing architecture and various gameplay features. This includes the creation of tables for event streams (es\_events, es\_snapshots) and a comprehensive set of tables for the game world (rm\_village, rm\_armies, rm\_heroes, rm\_report\_reads, etc.), alongside infrastructure for authentication (auth\_refresh\_sessions). Specific game mechanics such as village loyalty tracking, scheduled action statuses, and trapper states have also been added to the schema.

migrations · medium confidence

Introduce structured error types for application, database, and game logic

The application now uses dedicated, strongly-typed error enums for handling failures across different layers. \AppError\ covers authentication, password hashing, and queue limits. \DbError\ handles database-specific failures such as missing villages, users, armies, heroes, and marketplace offers. \GameError\ encapsulates domain-specific rules, including resource shortages, building constraints, hero status, troop movement cancellations, and marketplace validity. These changes improve error handling clarity and allow users to receive specific, descriptive messages for each failure scenario.

_parabellum\types/errors · high confidence

Migrated to a Preact-based single-page application with a JSON API

The application now serves a Preact frontend, rendering the main layout via a new SPA shell template that dynamically injects CSS and script tags from the Vite manifest. A new health check endpoint has been added to the web layer, and the server now handles client-side routing by falling back to the SPA shell for non-static, non-asset requests.

_parabellum\_web/templates, parabellum\web/web · medium confidence

Test coverage

Added integration tests for web API authentication and context endpoints

New integration tests were added in the parabellum\_server/tests directory, including test\_utils.rs and web\_api\_contract\_test.rs. These tests verify the behavior of the /api/v1/auth/token/login and /api/v1/auth/refresh endpoints, ensuring that login returns access and refresh tokens, that refresh token rotation works correctly, and that validation errors are properly returned for missing fields.

_parabellum\server/tests · high confidence

Dependencies

Rust edition and workspace restructuring

The project has been restructured into a Cargo workspace containing six crates: parabellum\_game, parabellum\_app, parabellum\_infra, parabellum\_server, parabellum\_types, and parabellum\_web. The Rust edition has been updated to 2024, and the workspace root now defines shared dependencies for the sub-crates. Additionally, the root package's metadata has been updated to version 0.5.0, and the Cargo.lock file has been removed.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 42 → 42 (-0.1)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 69 → 72 (+3.0)
  • Architecture 100 → 93 (-6.9)
  • Maturity 64 → 68 (+4.4)
  • Readiness 22 → 23 (+1.6)
  • Security 65 → 72 (+6.6)
  • Domain Modelling 78 → 57 (-20.4)
  • Event Sourcing 100 → 100 (+0.0)
  • Accessibility 47 → 47 (+0.1)

Resolved (16)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • LLM evaluation failed
  • Medium IaC: CKV_DOCKER_2 (Dockerfile)
  • No exposed public API
  • Off-boarding risk: anonymized user #1
  • Scanner failed to run — not a clean result
  • Test reliability not included
  • TooManyFunctions: crate::api::actions (parabellum_web/api/actions.rs)

New (161)

  • App.App (cognitive 35) (frontend/src/app/App.tsx)
  • App.App (cyclomatic 39) (frontend/src/app/App.tsx)
  • ArmyTable.ArmyTable (cognitive 20) (frontend/src/components/ArmyTable.tsx)
  • ArmyTable.ArmyTable (cyclomatic 18) (frontend/src/components/ArmyTable.tsx)
  • BuildingPage.BuildingPage (cognitive 32) (frontend/src/pages/BuildingPage.tsx)
  • BuildingPage.BuildingPage (cyclomatic 32) (frontend/src/pages/BuildingPage.tsx)
  • ClassTooLong: GameApplication (parabellum_app/application/game.rs)
  • ClassTooLong: RallyPointBuilding (frontend/src/components/buildings/RallyPointBuilding.tsx)
  • ClassTooLong: Village (parabellum_game/models/village.rs)
  • ClassTooLong: VillageEsAdapter (parabellum_infra/adapters/village_es_adapter.rs)
  • ClassTooLong: VillageEvent (parabellum_app/villages/events.rs)
  • ClassTooLong: VillageState (parabellum_app/villages/state.rs)
  • Dependency hygiene PARTLY measured — Cargo dependencies read, no committed lock to grade for currency
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (10 lines × 2) (parabellum_app/villages/commands/resolve_attack_battle.rs)
  • Duplicated block (10 lines × 2) (parabellum_app/villages/commands/resolve_attack_battle.rs)
  • Duplicated block (10 lines × 2) (parabellum_infra/es/repositories/armies/queries.rs)
  • Duplicated block (10 lines × 2) (parabellum_infra/es/village_service/queries/movements.rs)
  • Duplicated block (10 lines × 2) (parabellum_web/auth_tokens.rs)
  • …and 141 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

andreapavoni/parabellum was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 0f92b4c06f5c57832f52311a034752afd0e16b8f — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.