apache/openwhisk
41.4
Weak · 22 September 2026
48.4k
lines of production code
Scala
with JavaScript
4
measurements over time
What this system is
This system is the Apache OpenWhisk serverless platform, designed to deploy, manage, and execute serverless functions (actions) across various container runtimes. It provides a distributed architecture comprising a controller for API management, an invoker for action execution, and a scheduler for coordinating container lifecycle and load balancing. The platform supports multiple database backends for state storage and integrates with message brokers like Kafka for event-driven workflows, while offering extensive tooling for local development, CI/CD, and performance monitoring.
How it got here
2016 — Apache OpenWhisk initial release and cleanup
89 changes.
This period established the foundational structure for the Apache OpenWhisk project, including the Gradle build system, CI pipelines, and governance files. It involved a massive cleanup of legacy components, removing the Python CLI, Swift runtime, iOS SDK, and various Ant-based build scripts, while migrating the core infrastructure to Apache Pekko and Gradle.
2017–2018 — Pekko migration and infrastructure expansion
72 changes.
This period focused on migrating the core infrastructure from Akka to Apache Pekko, including the HTTP server, actor systems, and message connectors. It also introduced significant architectural changes such as API Gateway integration, Kubernetes container pool support, and new reactive invoker models backed by etcd. Extensive test coverage was added to validate these new components, database backends, and performance benchmarks.
2019–2022 — scheduler rewrite and infrastructure expansion
44 changes.
This period focused on a major architectural overhaul of the scheduler, introducing a new Pekko-based component with etcd coordination, gRPC APIs, and a function-pulling container model. Concurrently, the project expanded its backend support by adding ElasticSearch, MongoDB, and Azure Blob Storage, while also introducing a standalone server mode and YARN integration.
Features
Add Ansible role for deploying and managing local ElasticSearch
Users can now deploy a local ElasticSearch instance using the new ansible/roles/elasticsearch. The role handles setting system parameters, configuring cluster discovery and security, and managing the Docker container lifecycle (deploy and clean modes). It supports configurable ports, volumes, and Java options, allowing ElasticSearch to be used as a local database backend.
ansible/roles/elasticsearch · high confidence
Add actionProxy tool for testing OpenWhisk action containers
Introduces a new \tools/actionProxy\ directory containing a Dockerfile based on \openwhisk/dockerskeleton\, a README documenting the \ActionRunner\ proxy service (Flask-based \/init\ and \/run\ routes), and an \invoke.py\ script. This tool allows users to simulate invoker interactions by initializing action containers with source code or binaries and running them locally, facilitating the testing of custom action runtimes.
tools/actionProxy · high confidence
Add owperf performance evaluation tool for OpenWhisk
Introduces owperf, a new Node.js-based tool for benchmarking OpenWhisk deployments. It measures latency and throughput for both actions and rules (trigger-to-action), supporting concurrent worker clients and a 'master apart' mode to assess latency under load. The tool provides detailed metrics via CSV output and includes setup/teardown scripts to manage test assets.
tools/owperf · high confidence
Added git pre-commit hooks for automatic Scala formatting
Developers can now install pre-commit hooks in the tools/git directory to automatically format staged Scala source files before committing. Two options are provided: pre-commit-scalafmt-gradlew.sh, which uses the project's Gradle wrapper, and pre-commit-scalafmt-native.sh, which uses the native scalafmt command-line tool (requiring local installation). Both scripts detect staged .scala files, apply the project's formatting rules, and re-stage the changes, ensuring consistent code style without manual intervention.
tools/git · high confidence
Automated nightly Docker image publishing to Docker Hub
A new Jenkins pipeline script (tools/jenkins/apache/dockerhub.groovy) has been added to automatically build and publish OpenWhisk Docker images to Docker Hub. The job runs on Ubuntu nodes, authenticates using stored credentials, and utilizes Docker Buildx to create multi-architecture images for core components (controller, scheduler, invoker, standalone, monitoring/user-events, ow-utils, and cosmos/cache-invalidator). It tags and pushes these images to Docker Hub with both the 'nightly' tag and the short Git commit hash, then notifies the \#dev Slack channel upon completion.
tools/jenkins · high confidence
In-memory database stores for testing and local development
Added in-memory implementations of the artifact store (MemoryArtifactStore), attachment store (MemoryAttachmentStore), and activation store (NoopActivationStore) to allow running OpenWhisk without a CouchDB instance. These components provide full CRUD and query support (via MemoryViewMapper) for local performance testing and simplified test setups, replacing the need for a live database backend in those scenarios.
common/scala/src/main/scala/org/apache/openwhisk/core/database/memory · high confidence
Initial Apache OpenWhisk project structure and tooling
The repository is initialized with the foundational structure for the Apache OpenWhisk serverless platform. This includes the addition of standard Apache Software Foundation governance files such as .asf.yaml (configuring GitHub repository settings, labels, and branch protection), CODE\_OF\_CONDUCT.md, CONTRIBUTING.md, CREDITS.txt, and NOTICE.txt. The project build system is established with Gradle wrapper scripts (gradlew, gradlew.bat) and configuration files (.scalafmt.conf, .gitattributes) to ensure consistent code formatting and line endings. A Jenkinsfile is added to define the continuous integration pipeline for building and testing the platform, and a CHANGELOG.md is introduced to track version history starting from Apache 2.0.0.
(repo-wide) · high confidence
Initial Jenkins deployment environment configuration
Adds the Ansible configuration files required to deploy OpenWhisk within a Jenkins CI/CD environment. This includes the main Ansible settings, group variables for three distinct VMs (openwhisk-vm1, vm2, and vm3) defining Docker registries, Kafka retention policies, and action concurrency limits, as well as Jinja2 inventory templates that map specific host IPs to OpenWhisk components like controllers, invokers, and the API gateway.
ansible/environments/jenkins · high confidence
Initial configuration for the Invoker component
The Invoker now ships with a default \application.conf\ file that defines baseline settings for Docker and Kubernetes container management, including timeouts, parallel run limits, and prewarm pool behavior. This configuration also establishes default authentication credentials, sets the default protocol to HTTP, and includes initial settings for container health checks, logging of activation errors, and distributed tracing.
core/invoker/src/main/resources · high confidence
Initial deployment configuration and MongoDB management module
This change introduces the primary Ansible deployment configuration file (ansible/group\_vars/all) and a new custom Ansible module for MongoDB operations. The configuration file establishes default settings for the OpenWhisk environment, including runtime manifests, resource limits, controller and invoker parameters, and integration with Kafka and Zookeeper. The new MongoDB module enables Ansible playbooks to manage MongoDB users, documents, and indexes, supporting the deployment and initialization of MongoDB-backed components.
_ansible/group\vars · high confidence
Initial nginx reverse proxy configuration for OpenWhisk
Introduces a new Ansible role to deploy and configure an nginx reverse proxy that sits in front of the OpenWhisk controllers. The configuration enables HTTPS with strict TLS 1.2 settings, supports vanity URLs for web actions via namespace-based rewriting, and routes traffic to multiple controllers with keepalive connections. It also exposes the CLI download endpoint at /cli, mounts an optional static HTML directory for the UI, and generates transaction IDs for request tracing.
ansible/roles/nginx/templates · high confidence
Initial scheduler component with Pekko-based containerization
Introduces the new scheduler component, including its Dockerfile, coverage configuration, and initialization script. The scheduler now runs on Pekko (migrating from Akka) and exposes port 8080, with the init script configuring Pekko remote artery binding via environment variables.
core/scheduler · high confidence
Introduce OpenWhisk User Events service for Prometheus metrics
Adds the new user-events service, which connects to the events topic to publish metrics to Prometheus (exposed on port 9095) and other services via Kamon. The service allows users to ignore specific namespaces and rename Prometheus metric tags through configuration, and is distributed with Dockerfiles for both standard and Debian-based images.
core/monitoring/user-events · high confidence
Introduce dedicated user-events service for monitoring and metrics
A new standalone user-events service has been added to centralize the collection and exposure of OpenWhisk activation metrics. This service consumes Kafka events and records detailed metrics—including activation counts, cold starts, duration, wait time, response size, and status codes—using Kamon and Prometheus. It exposes these metrics via a configurable HTTP endpoint (default port 9095) and supports configuration for ignored namespaces and Prometheus tag relabeling, providing a unified interface for monitoring system performance.
core/monitoring/user-events/src/main · high confidence
Introduce new scheduler configuration defaults
Adds the initial configuration file for the new scheduler component, defining Pekko cluster settings (including Kryo serialization bindings for scheduler messages) and specific OpenWhisk scheduler parameters such as namespace over-provisioning ratios, queue retention limits, and throttling behavior.
core/scheduler/src/main/resources · high confidence
Introduce standalone CosmosDB Cache Invalidation Service
A new, independent service has been added to handle cache invalidation for Azure Cosmos DB. This service monitors the 'whisks' container via the Cosmos DB Change Feed and publishes invalidation events to Kafka. It is built on Apache Pekko (migrating from Akka) and uses the Azure Cosmos SDK v3, featuring configurable connection modes, consistency levels, and Kafka producer settings to ensure reliable, at-least-once delivery of cache updates.
core/cosmosdb/cache-invalidator · high confidence
Introduce wskadmin-next, a Scala-based administrative tool with Pekko and namespace limits
The \tools/admin\ area now includes \wskadmin-next\, a new Scala-based implementation of the administrative CLI that replaces the legacy Python \wskadmin\ for core user and limit management. Built on Apache Pekko (migrating from Akka), \wskadmin-next\ provides database-agnostic commands for managing subjects (create, delete, block/unblock, key revocation) and setting namespace-specific throttles (invocations, allowed runtimes, activation storage). It reads configuration from \whisk.conf\ or a custom file via the \-c\ flag, supports a configurable async timeout, and includes tracing support. The legacy Python \wskadmin\ script remains available for database inspection and system log retrieval, but the new tool offers a modern, type-safe alternative for identity and limit administration.
tools/admin · high confidence
Introduces Pekko-based HTTP client for action container communication
The invoker now uses a new Pekko HTTP client implementation to communicate with action containers, providing an alternative to the existing Apache HTTP client. This change adds \PekkoContainerClient\ alongside the existing \ApacheBlockingContainerClient\, allowing the system to leverage Pekko's asynchronous HTTP capabilities for container interactions while maintaining compatibility with the current container pool architecture.
common/scala/src/main/scala/org/apache/openwhisk/core/containerpool · high confidence
Introduces core common utilities and infrastructure components
This change adds a suite of foundational classes to the common library, including configuration management (Config, ConfigMXBean, ConfigMapValue), logging and metrics integration (Logging, Prometheus), and concurrency primitives (Counter, ForcibleSemaphore, NestedSemaphore, ResizableSemaphore, Scheduler). It also introduces utility classes for handling HTTPS connections, transaction tracking (TransactionId), and ring buffers, establishing the basic building blocks for the system's operational behavior.
common/scala/src/main/scala/org/apache/openwhisk/common · high confidence
Introduction of entitlement privileges and SPI loader infrastructure
This change introduces the core entitlement model and the service-provider interface (SPI) loading mechanism. The \Privilege\ enum in \org.apache.openwhisk.core.entitlement\ defines specific access rights (READ, PUT, DELETE, ACTIVATE, REJECT) and includes JSON serialization support for configuration. Additionally, \SpiLoader\ in \org.apache.openwhisk.spi\ provides a generic mechanism to instantiate SPI implementations based on TypesafeConfig keys, enabling runtime resolution of service implementations without hardcoding them.
common/scala/src/main/scala/org/apache/openwhisk/core/entitlement, common/scala/src/main/scala/org/apache/openwhisk/spi · high confidence
Introduction of feature flags and warm-up infrastructure
This change introduces a new \FeatureFlags\ configuration object that allows administrators to toggle specific behaviors via configuration, such as requiring the \provide-api-key\ annotation for actions and controlling whether the API returns response payloads for created or deleted entities. It also adds a \WarmUp\ component that defines the system-level 'warmUp' action and associated messages, providing the foundational logic for pre-warming action containers to reduce cold-start latency.
common/scala/src/main/scala/org/apache/openwhisk/core · high confidence
Introduction of in-memory Lean messaging connector
A new lean messaging implementation has been added to the common Scala module, providing an in-memory alternative to external message brokers. This change introduces \LeanMessagingProvider\, \LeanConsumer\, and \LeanProducer\ classes that utilize Java \LinkedBlockingQueue\ instances to handle message production and consumption within the same process. This allows for a simplified, dependency-free messaging layer suitable for testing or lightweight configurations, replacing the need for external Kafka or similar infrastructure in these specific use cases.
common/scala/src/main/scala/org/apache/openwhisk/connector/lean · high confidence
MongoDB support for artifact storage and document views
This change introduces a new MongoDB-backed implementation for storing and retrieving artifacts (such as action code) using MongoDB GridFS, alongside the necessary view mappers and stream sinks/sources to handle document queries and large data transfers. Users can now leverage MongoDB as a backend for artifact storage and associated document views (whisks, activations, subjects) with specific indexing and filtering logic tailored for MongoDB's query model.
common/scala/src/main/scala/org/apache/openwhisk/core/database/mongodb · high confidence
New Ansible templates for database credentials, JMX, and Whisk configuration
This change introduces four new Jinja2 templates in the ansible/templates directory to manage deployment configuration. db\_local.ini.j2 generates database credential files, introducing separate usernames and passwords for the controller, invoker, and scheduler components instead of a single shared set. whisk.conf.j2 and whisk.properties.j2 provide the application configuration for the Whisk runtime, including support for MongoDB as an artifact store backend and configurable API host settings. Additionally, jmxremote.access.j2 and jmxremote.password.j2 are added to configure JMX remote access for monitoring.
ansible/templates · high confidence
New Azure Blob Storage backend for document attachments
Users can now store and retrieve document attachments in Azure Blob Storage via the new \AzureBlobAttachmentStore\. This implementation adds a new \az\ scheme, allowing attachments to be persisted to Azure containers with configurable retry policies and optional Azure CDN integration for content delivery.
common/scala/src/main/scala/org/apache/openwhisk/core/database/azblob · high confidence
New CosmosDB Cache Invalidator Service for Multi-Region Cache Propagation
A new standalone service has been added to handle cache invalidation in OpenWhisk clusters using Azure CosmosDB, enabling cache event propagation across multi-region setups. The service listens to CosmosDB ChangeFeed events on the \whisks\ and \subject\ collections and publishes corresponding messages to a local Kafka \cacheInvalidation\ topic, ensuring consistency when nodes do not share a common Kafka instance. The delivery includes Dockerfiles (standard and Debian-based), a docker-compose configuration, and an initialization script to run the service on port 8080.
core/cosmosdb · high confidence
New Eclipse code formatting profiles for Java and Scala
Added \tools/eclipse/java.xml\ and \tools/eclipse/scala.properties\ to provide default Eclipse IDE formatting configurations for the project. The Java profile enforces 4-space tab indentation and standard brace placement, while the Scala profile configures Scalariform to use 2-space indentation and specific alignment rules, ensuring consistent code style when developers import the project into Eclipse.
tools/eclipse · high confidence
New ElasticSearch-based activation store implementation
A new ElasticSearchActivationStore has been added to the common Scala module, providing a concrete implementation of the ActivationStore interface backed by ElasticSearch. This component handles storing and retrieving activation records using the Elastic4s client, featuring automatic batching of write operations, configurable retry logic for failed writes, and support for querying activations by binding package name. It also introduces configuration options for controlling success/failure levels for blocking and non-blocking database writes, and migrates the underlying actor system dependencies to Apache Pekko.
common/scala/src/main/scala/org/apache/openwhisk/core/database/elasticsearch · high confidence
New FPCSchedulerServer and Scheduler components introduce REST API and core scheduling logic
The scheduler module now includes a new FPCSchedulerServer that exposes a REST API for monitoring and control, including endpoints to retrieve queue state, activation counts, and queue size, as well as a route to disable the scheduler. This server implements basic HTTP authentication using credentials loaded via PureConfig and supports CORS headers. Additionally, the new Scheduler class provides the core scheduling logic, integrating with etcd for state management, using Pekko actors for container and queue management, and leveraging PureConfig for loading scheduling configurations. These changes represent a significant architectural shift in how the scheduler operates, moving towards a more modular and configurable system.
core/scheduler/src/main/scala/org/apache/openwhisk/core/scheduler · high confidence
New GitHub Actions CI tooling and scripts
This change introduces a comprehensive suite of shell scripts in the tools/github directory to support a new GitHub Actions-based CI pipeline. The collection includes setup and environment configuration (setup.sh, which upgrades to JDK 17 and configures Docker), distinct test runners for various scopes (unit, system, standalone, scheduler, multi-runtime, and lean system tests), and utility scripts for code scanning (flake8, scan.sh), log collection and S3 upload (checkAndUploadLogs.sh, s3-upload.sh), and debugging support via ngrok (debugAction.sh, waitIfDebug.sh). These scripts replace or supplement previous Travis CI infrastructure by handling build, test execution, and reporting directly within the GitHub Actions environment.
tools/github · high confidence
New OpenWhisk Standalone Server with Playground UI
A new standalone server mode is introduced, allowing OpenWhisk to run as a single runnable JAR for local development and testing without external dependencies like Kafka or CouchDB by default. This mode includes an embedded Playground UI for authoring and running functions directly in the browser, supports optional integration with CouchDB, API Gateway, and embedded Kafka, and provides a dedicated Dockerfile for containerized deployment.
core/standalone · high confidence
New Travis CI build scripts and tooling
The \tools/travis\ directory now contains a comprehensive set of shell and Python scripts to manage the CI pipeline. This includes dedicated runners for unit, system, standalone, scheduler, and lean system tests, alongside helper scripts for Docker setup, code scanning (flake8, scancode, scalafmt), and log uploads to Box. A new README documents the parallel job structure and script responsibilities.
tools/travis · high confidence
New build and CI helper utilities introduced
The \tools/build\ directory now includes a set of new helper scripts to streamline development and CI workflows. The \redo\ script serves as a unified wrapper for Ansible and Gradle, allowing users to build, deploy, and teardown OpenWhisk components with a single command while automatically detecting the deployment target (local, Docker Machine, or Docker for Mac). A new \citool\ script enables monitoring of Jenkins and Travis CI builds, supporting features like polling for completion, saving logs, and filtering output. Additionally, \checkLogs.py\ provides a CI/CD check to assert that log files and database dumps remain within expected size bounds, helping to catch runaway logs or excessive database growth during testing.
tools/build · high confidence
New centralized etcd watcher and data management services
Added three new actor-based services in the core service layer to manage etcd interactions: WatcherService, which centralizes etcd key watching and automatically restarts the watch stream on errors; DataManagementService, which handles data storage to etcd with leader election and retry logic to guarantee eventual delivery; and LeaseKeepAliveService, which manages etcd leases for instance keep-alive. These services introduce a new mechanism for handling etcd events and lease management, replacing previous ad-hoc implementations.
common/scala/src/main/scala/org/apache/openwhisk/core/service · high confidence
New createApi action for API Gateway configuration
Adds the createApi action, which allows users to add or update API configurations in the API Gateway. The action supports both API Gateway V1 (using username/password authentication) and V2 (using access tokens), handling tenant creation, API retrieval, and swagger validation. It accepts API documentation via either explicit gateway path/method/action parameters or a full swagger object, and returns the configured API details.
core/routemgmt/createApi · high confidence
New database maintenance and migration utilities
The \tools/db\ directory now includes several new Python scripts to help manage OpenWhisk's backing data stores. Administrators can use \cleanUpActivations.py\ and \deleteLogsFromActivations.py\ to remove old activation records or clear logs from them to save space. A new \moveCodeToAttachment.py\ script allows migration of existing action documents to a schema where code is stored as attachments rather than inline, reducing memory consumption in the controller. Additionally, \replicateDbs.py\ provides capabilities for creating snapshot and continuous backups, replaying those backups, and excluding specific databases, while \cosmosDbUtil.py\ offers a CLI for initializing, pruning, and dropping databases when using Azure Cosmos DB.
tools/db · high confidence
New development utility scripts for local debugging and module listing
The \tools/dev\ module now includes a suite of Gradle-integrated Groovy scripts to streamline local development. Developers can run \intellij\ to automatically generate IntelliJ run configurations for the Controller and Invoker by inspecting running Docker containers, allowing seamless switching between Docker and IDE debugging. The \couchdbViews\ task extracts and dumps CouchDB design document views into readable JavaScript files. Additionally, \listRepos\ fetches Apache OpenWhisk-related repositories from the GitHub API, and \renderModuleDetails\ generates a \docs/dev/modules.md\ page categorizing these repositories (e.g., Main, Clients, Runtimes) with their build statuses.
tools/dev · high confidence
New etcd-based data management and scheduler coordination layer
This change introduces a new set of components in the etcd package to support the new scheduler architecture. It adds an EtcdClient wrapper around the IBM etcd Java client, providing key-value operations, lease management, and watch capabilities with optional authentication. EtcdUtils defines configuration structures and key prefixes for scheduler states, queue management, throttling, and container lifecycle tracking. The EtcdWorker actor handles asynchronous interactions with etcd, managing lease lifecycles, leader election, data registration, and initial data storage with automatic retry logic on lease expiration or errors.
common/scala/src/main/scala/org/apache/openwhisk/core/etcd · high confidence
New file-based and ElasticSearch log store implementations
The logging subsystem in \common/scala\ now includes \DockerToActivationFileLogStore\, which writes container logs to rotating local files while also embedding them in the activation record, and \ElasticSearchLogStore\, which retrieves logs from an ElasticSearch backend. These new components rely on the \LogStore\ interface and \LogDriverLogStore\ base, and utilize Apache Pekko streams for log processing and file rotation.
common/scala/src/main/scala/org/apache/openwhisk/core/containerpool/logging · high confidence
New gRPC-based activation service implementation
The scheduler now exposes a new gRPC service (ActivationServiceImpl) that handles activation lifecycle requests via the Protobuf-defined ActivationService interface. Users interacting with the scheduler over gRPC will have their activation fetch and reschedule operations routed through this new implementation, which integrates with the existing memory queue pool and Pekko actor system for message handling.
core/scheduler/src/main/scala/org/apache/openwhisk/core/scheduler/grpc · high confidence
New log formatter callback for improved Ansible output readability
A new Ansible callback plugin, \logformatter\, has been added to the \ansible/callbacks\ directory. This plugin intercepts Ansible events (such as task failures, skips, and unreachable hosts) and formats the output to be more easily readable by highlighting specific fields like the command, reason, message, stdout, and stderr. It applies color coding (red for failures, bold for other statuses) when the terminal supports it, and wraps text to 80 characters to improve console display during playbook execution.
ansible/callbacks · high confidence
New macOS Docker-machine setup scripts and documentation
Added a new README and two shell scripts (\tweak-dockermachine.sh\ and \tweak-dockerhost.sh\) to facilitate running OpenWhisk on macOS using Docker-machine. The setup pins specific versions for stability: Docker 18.06.3 (required to address [CVE redacted]), Ansible 2.5.2, and Jinja2 2.9.6. The scripts configure the Docker-machine VM by disabling TLS, setting up port forwarding on port 4243, and installing necessary Python dependencies, while also adjusting host routes to ensure direct communication with Docker containers.
tools/macos/docker-machine · high confidence
New reactive invoker implementations with dedicated REST management endpoints
The invoker now supports new reactive execution models (InvokerReactive and FPCInvokerReactive) that replace the previous actor-based message handling with a message-consumer architecture backed by etcd for state management and gRPC for scheduler communication. These implementations expose new REST API endpoints on the invoker server: an enable/disable toggle for the invoker instance and a pool state endpoint (including a count of busy, paused, and in-progress containers) to support zero-downtime deployments and dynamic scaling. The invoker also introduces a namespace blacklist feature that periodically queries the database to block actions from throttled or blocked namespaces, and adds support for user-defined action instance concurrency limits and dedicated invoker assignment via Zookeeper or manual ID configuration.
core/invoker/src/main/scala/org/apache/openwhisk/core/invoker · high confidence
New scheduler deployment and management via Ansible
The ansible/roles/schedulers location now provides the infrastructure to deploy, configure, and clean up the new scheduler service. This includes tasks to pull the scheduler Docker image, create necessary log and configuration directories, and expose specific ports for HTTP, gRPC, and Pekko cluster communication. The role configures the scheduler environment with extensive settings for queue management, retention, throttling, Kafka connectivity, and JMX monitoring, while also handling the joining of the scheduler nodes to a Pekko cluster.
ansible/roles/schedulers · high confidence
New scheduler implementation with function-pulling container management
The invoker now uses a new scheduler architecture that manages containers via a function-pulling model. This introduces the FunctionPullingContainerPool to handle container lifecycle (prewarming, busy, paused states) and the FunctionPullingContainerProxy to manage individual container execution and state transitions. An ActivationClientProxy handles communication with the scheduler, including rescheduling and client recreation when scheduler endpoints change. Additionally, an InvokerHealthManager monitors invoker health by running test actions and publishing status to etcd, enabling better visibility into invoker availability.
core/invoker/src/main/scala/org/apache/openwhisk/core/containerpool/v2 · high confidence
Support for CloudFront-signed URLs in S3 attachment storage
The S3 attachment store now supports reading attachments via CloudFront signed URLs. A new CloudFrontSigner component handles the generation of signed URLs using AWS SDK for CloudFront, and the S3AttachmentStore uses this signer to fetch content when a CloudFront domain is configured, enabling faster and more secure delivery of attachment data through CloudFront's edge network.
common/scala/src/main/scala/org/apache/openwhisk/core/database/s3 · high confidence
Support for running OpenWhisk actions on Apache Hadoop YARN clusters
OpenWhisk can now deploy and manage action containers on Apache Hadoop YARN clusters. This change introduces a new YARN container factory and supporting actors that communicate with the YARN REST API to provision, monitor, and decommission containers. Users can configure the YARN master URL, authentication method (simple or Kerberos), service name, and resource limits (CPU and memory) to enable this runtime environment. Note that YARN containers do not support pause/resume operations, and log collection is currently limited to a static message directing users to the YARN UI.
common/scala/src/main/scala/org/apache/openwhisk/core/yarn · high confidence
Removals
Kafka service build and startup process removed
The local Dockerfile, Ant build script, and startup script for the Kafka service have been deleted. This removes the ability to build the Kafka image from source using the previous Ant-based workflow and eliminates the embedded Node.js monitor that previously initialized base topics upon startup.
services/kafka · high confidence
Registrator service build and deployment scripts removed
The Dockerfile, build.xml, and docker-run.sh scripts used to build and launch the registrator service have been deleted. This removes the legacy mechanism for compiling the Go-based registrator binary and starting it across multiple Docker hosts to register services with Consul, indicating a shift away from this specific deployment method.
services/registrator · high confidence
Removal of Cloudant database management scripts
The shell scripts in tools/cloudant (createImmortalDBs.sh, loadTransientDBViews.sh, and wipeTransientDBs.sh) have been deleted. These scripts previously handled the creation, wiping, and view-loading for Cloudant databases, including the recreation of immortal auth keys and transient database views. Their removal means these database initialization and maintenance tasks are no longer performed by these specific utility scripts.
tools/cloudant · high confidence
Removal of Consul service build and configuration files
The build artifacts, configuration files, and startup scripts for the Consul service have been removed. This includes the Ant build file (build.xml), Eclipse project metadata (.classpath, .project), the Dockerfile, and various configuration and script files (config/\.json, scripts/\.sh, startconsul\*.sh). This change effectively removes the local build and deployment infrastructure for the Consul component from this directory.
services/consul · high confidence
Removal of ContainerPool unit tests
The unit tests for the ContainerPool component have been removed from the test suite. This deletion eliminates the test coverage for container lifecycle management, including operations such as retrieving containers by image name, managing idle/active limits, and enforcing garbage collection thresholds.
tests/src/whisk/core/container · high confidence
Removal of GitHub Webhook creation capability
The \catalog/github/webhook.js\ file has been deleted, removing the ability to create GitHub webhooks via this catalog entry. This eliminates the functionality that previously allowed users to register webhooks on GitHub repositories to trigger OpenWhisk actions, including the handling of repository names, authentication, and event configuration.
catalog/github · high confidence
Removal of Python-based JSON validation tooling
The Python-based JSON validation script (validate.py), its associated test script (test.sh), and the schema definition file (schema.json) located in the tools/json directory have been removed. This eliminates the legacy Python tooling used to validate JSON objects against a schema, aligning with the project's shift toward Java-based validation mechanisms.
tools/json · high confidence
Removal of Python-based deployment scripts
The \tools/deploy\ directory has removed the \deployInvoker\ script and the \dockerUtil.py\ utility module. This eliminates the Python-based tooling previously used to manage invoker deployment, container lifecycle, and Docker endpoint interactions, indicating a shift away from this specific Python deployment implementation.
tools/deploy · high confidence
Removal of Watson Language Identification and Translation actions
The catalog actions for language identification and text translation have been removed. Specifically, the \catalog/watson/languageId.js\ and \catalog/watson/translate.js\ files, which previously provided OpenWhisk actions to identify the language of text and translate strings between languages using the Watson Developer Cloud service, are no longer present in the catalog.
catalog/watson · high confidence
Removal of WhiskConfig.scala configuration class
The WhiskConfig.scala file, which previously managed core service configuration properties such as database credentials, host endpoints, and Docker settings, has been removed from the codebase. This change eliminates the centralized Scala-based configuration loader for the Whisk core module, implying that these configuration values are now handled by a different mechanism or component not present in this specific file diff.
common/scala/src/whisk/core · high confidence
Removal of catalog utility actions
The catalog utility actions \cat\, \date\, and \pipe\ have been removed from the system. This eliminates the ability to use these specific serverless functions for tasks such as reading file lines, retrieving the current date, or chaining multiple actions together.
catalog/utils · high confidence
Removal of legacy Ant-based build and Eclipse project files
The dispatcher module no longer includes the Ant build scripts (build.xml, Dockerfile) and Eclipse project metadata (.classpath, .project, .gitignore). This change removes the legacy build infrastructure for the dispatcher, indicating a migration to a different build system (likely Gradle, as suggested by commit messages) and eliminating the need for Eclipse-specific configuration files in this component.
core/dispatcher · high confidence
Removal of legacy CLI packaging and build artifacts
The \tools/cli/packagescripts\ directory has been removed, eliminating the legacy Python 2/3 setup scripts, Dockerfile, and documentation files that previously handled the distribution and building of the OpenWhisk CLI. This change removes support for older Python versions (2.6, 2.7, 3.2, 3.3) and the associated build infrastructure, streamlining the project by discarding outdated packaging mechanisms.
tools/cli/packagescripts · high confidence
Removal of legacy Cloudant and InMemoryCache database components
The Cloudant client wrapper, CloudantStore implementation, DocumentFactory, and InMemoryCache traits have been removed from the core database module. This cleanup eliminates the legacy Cloudant-specific storage layer and the associated in-memory caching mechanism, simplifying the database abstraction and removing unused code paths for document serialization and caching.
common/scala/src/whisk/core/database · high confidence
Removal of legacy Docker cleanup and utility scripts
The \tools/docker\ directory has been cleaned up by removing several obsolete shell scripts: \cleanAllDockers.sh\, \cleanDocker.sh\, \dockerWithRetry.sh\, \listAllDockerHosts.sh\, and \tools/logs/copyLogs.sh\. These scripts previously handled tasks such as killing and removing Docker containers, retrying Docker operations with timeouts, listing Docker hosts from configuration files, and copying log files. Their removal indicates a shift away from these manual or legacy operational workflows, likely as part of the broader post-ant cleanup and script modernization efforts.
tools/docker · high confidence
Removal of legacy Kafka connector implementations
The legacy Kafka consumer and producer connector classes have been removed from the codebase. This change eliminates the previous implementations that relied on older Kafka client libraries and manual configuration patterns, reflecting a shift in the underlying messaging infrastructure.
common/scala/src/whisk/connector · high confidence
Removal of legacy Python CLI implementation
The Python-based command-line interface (CLI) and its associated build infrastructure have been removed from the project. This change deletes the main \wsk\ executable, all supporting Python modules (such as \wskaction.py\, \wskactivation.py\, \wskitem.py\, and \wskprop.py\), the \wskadmin\ tool, and the Ant-based build scripts (\build.xml\, \generateDefaultProps.sh\) that were used to package and distribute the Python CLI. Users relying on this Python CLI will need to switch to the Go-based CLI or other supported interfaces.
tools/cli · high confidence
Removal of legacy Python health-check scripts
The \tools/health\ directory has been cleared of its previous Python-based diagnostic tools. Specifically, the \isAlive\ script (used to check component status via curl/nc), \killComponent\ (for stopping Docker containers), \kvstore\ (for Consul key-value store inspection), and the \monitorUtil\ helper library have all been deleted. This removes the ability to run these specific health checks and management commands from this location.
tools/health · high confidence
Removal of legacy Spray-based HTTP service infrastructure
The legacy HTTP service implementation based on the Spray framework has been removed from the common library. This change deletes the \BasicHttpService\ trait, which previously handled HTTP routing, transaction ID assignment, and request logging using Spray directives, as well as the \BasicRasService\ trait that provided a simple '/ping' endpoint on top of it. Additionally, the \ErrorResponse\ helper, which managed JSON serialization of error responses and status codes within the Spray ecosystem, has been deleted. Users relying on these specific base classes for building HTTP services in this module will need to migrate to the new HTTP implementation.
common/scala/src/whisk/http · high confidence
Removal of legacy Vagrant configuration
The legacy Vagrantfile for the OpenWhisk development environment has been removed. This file previously defined the virtual machine setup using the Ubuntu Trusty box, configured VirtualBox providers with specific CPU and memory limits, and executed shell provisioning scripts to install dependencies and set up the CLI environment. Its deletion indicates that this specific Vagrant-based provisioning method is no longer supported or maintained.
tools/vagrant · high confidence
Removal of legacy common Scala utilities and Consul integration
The \whisk/common\ module has removed a large set of legacy Scala files, including \Config.scala\, \ConsulKV.scala\, \ConsulKVReporter.scala\, \ConsulServiceCheck.scala\, \ConsulServiceHealth.scala\, \Counter.scala\, \Crypt.scala\, \Curl.scala\, \DateUtil.scala\, \HttpClient.scala\, \HttpUtils.scala\, \Logging.scala\, and \SimpleExec.scala\. This change eliminates the previous Consul-based configuration loading, service health reporting, and HTTP client implementations, as well as general-purpose utilities for encryption, command execution, and transaction logging that were previously housed in this common package.
common/scala/src/whisk/common · high confidence
Removal of legacy connector message and load balancer request components
The \LoadbalancerRequest.scala\, \Message.scala\, and \MessageConsumer.scala\ files have been removed from the \whisk.core.connector\ package. This eliminates the previous HTTP-based load balancer request handling, the generic \Message\ data structure used for serialization, and the \MessageConsumer\ trait, indicating a shift away from these specific legacy communication patterns within the connector module.
common/scala/src/whisk/core/connector · high confidence
Removal of legacy controller REST API implementation
The legacy REST API implementation for the controller has been removed. This change deletes the core source files that defined the HTTP routes and handlers for actions, activations, entities, namespaces, and packages, as well as the supporting authentication, authorization, and utility traits. This cleanup eliminates the old Spray-based API layer in favor of the refactored controller architecture.
core/controller/src/whisk/core/controller · high confidence
Removal of legacy entitlement and throttling subsystem
The legacy entitlement subsystem in the controller has been removed, deleting the files that defined the \Collection\, \EntitlementService\, \Privilege\, \RateThrottler\, and \RemoteEntitlementService\ components. This eliminates the previous implementation of namespace-based implicit rights, explicit privilege grants, and per-subject rate limiting (120 activations/minute) that relied on a remote entitlement service or local Consul KV store checks.
core/controller/src/whisk/core/entitlement · high confidence
Removal of legacy entity model classes
The core entity model classes in \whisk.core.entity\ (including \ActivationId\, \ActivationLogs\, \ActivationResult\, \AuthKey\, \Exec\, \Limits\, \MemoryLimit\, \Namespace\, \Parameter\, \TimeLimit\, \UUID\, \WhiskAction\, and \WhiskActivation\) have been removed. This change eliminates the legacy data structures and serialization logic that previously handled action metadata, activation records, and entity identification, indicating a migration to a new entity representation or storage schema.
common/scala/src/whisk/core/entity · high confidence
Removal of legacy load balancer implementation
The legacy load balancer module in core/loadBalancer has been removed. This deletes the previous implementation files (ActivationThrottle, InvokerHealth, LoadBalancer, LoadBalancerService, and LoadBalancerToKafka) which handled invoker health monitoring, activation throttling, and message publishing via Kafka and Consul. This change eliminates the old HTTP-based routing and health-checking logic in favor of the new architecture.
core/loadBalancer/src/whisk · high confidence
Removal of legacy test infrastructure utilities
Deleted obsolete test support files in \tests/src/common\, including the Java process launcher (\BasicLauncher\, \Launcher\), utility classes (\TestUtils\, \Util\, \Pair\), and Scala/Java CLI wrappers (\Wsk\, \WskCli\). This cleanup removes unused test helpers and dead code from the test suite.
tests/src/common · high confidence
Removal of legacy utility modules for execution contexts, JSON conversion, and retries
The \ExecutionContextFactory\, \JsonUtils\, and \Retry\ utility objects in \whisk.utils\ have been removed. This eliminates the previous implementation of custom thread-pool execution contexts, the bidirectional conversion between GSON and Spray JSON, and the synchronous retry logic that relied on \Thread.sleep\. Users relying on these specific utilities will need to adopt the project's new equivalents for thread management, JSON serialization, and asynchronous retry mechanisms.
common/scala/src/whisk/utils · high confidence
Removal of legacy weather forecast action
The weather forecast action in the catalog has been removed. This eliminates the previous implementation that fetched 10-day daily forecasts from the Weather.com API using an API key, latitude/longitude, or ZIP code parameters.
catalog/weather · high confidence
Removal of loadBalancer configuration file
The application configuration file for the load balancer module (application.conf) has been removed. This file previously contained logging includes and a specific timeout setting for the spray server. Its removal aligns with the broader refactoring that moved the load balancer code into the controller project, indicating that these specific configuration settings are no longer managed in this location.
core/loadBalancer/src/resources · high confidence
Removal of obsolete common JavaScript build artifacts
The common JavaScript build configuration and Dockerfile have been removed, eliminating the legacy Ubuntu 14.04-based image that bundled a specific set of Node.js packages (such as Express 4.12.2, Socket.io 1.3.5, and Mustache 2.1.3). This cleanup also removes the associated Eclipse project metadata files, reflecting a shift away from this centralized common image approach.
common/js · high confidence
Removal of sample action scripts from catalog
The sample action scripts located in the catalog/samples directory have been removed. This deletion eliminates several example implementations, including countdown.js, curl.js, echo.js, greeting.js, hello.js, and wcbin.js, which previously demonstrated various invocation patterns and utility functions.
catalog/samples · high confidence
Removal of the Kafka Monitor service
The dedicated Kafka monitor service, previously provided by \services/kafka/monitor/app.js\, has been removed. This service previously exposed HTTP endpoints (\/ping\ and \/ready\) and performed background checks against Zookeeper to verify Kafka topic availability and consumer group offsets. Its removal eliminates this specific health-check mechanism and the associated Express server.
services/kafka/monitor · high confidence
Removal of the OpenWhisk iOS SDK
The OpenWhisk iOS SDK, including the main framework, the WatchKit extension, and associated build configurations, has been removed from the repository. This change eliminates the ability to build and integrate the OpenWhisk client library for iOS and watchOS applications.
mobile/iOS/sdk · high confidence
Removal of the legacy Node.js action runner
The entire legacy Node.js action runner implementation has been removed from the \core/nodejsAction\ directory. This change deletes the \Dockerfile\, \app.js\, \runner.js\, and supporting source files (\src/service.js\, \src/whisk.js\, \src/logger.js\) that previously handled action initialization and execution via an Express-based HTTP service. Consequently, the old mechanism for running Node.js actions, including the specific SDK methods and runtime environment defined in these files, is no longer available.
core/nodejsAction · high confidence
Removal of the standard action catalog installation scripts
The deployment process no longer automatically installs the standard set of OpenWhisk actions and packages. The shell scripts responsible for provisioning the \system\, \util\, \samples\, \github\, \slack\, \watson\, and \weather\ packages (including \installCatalog.sh\ and its dependencies) have been deleted, meaning these default actions are no longer created during deployment.
catalog · high confidence
Swift action runtime removed
The Swift action runtime support has been removed from the system. The Dockerfile, build scripts, and all associated Python proxy and helper files (including epilogue.swift, proxy.py, and run.py) that previously handled Swift action initialization, execution, and JSON serialization have been deleted.
core/swiftAction · high confidence
iOS starter app project files removed
The Xcode project configuration, workspace, and scheme files for the OpenWhiskStarterApp have been deleted from the repository. This change removes the local build artifacts and project structure for the iOS starter application, consistent with the migration of the Swift client code to a separate repository.
mobile/iOS/starterapp/OpenWhiskStarterApp.xcodeproj · high confidence
iOS starter app removed from repository
The OpenWhisk iOS starter application has been deleted from this location. The diff shows the removal of all application source files, including the app delegate, view controllers, storyboards, assets, and configuration files, indicating the project has been moved to a separate Swift client repository.
mobile/iOS/starterapp/OpenWhiskStarterApp · high confidence
API
New ActivationService gRPC API for fetching and rescheduling activations
A new protobuf definition introduces the ActivationService, exposing two RPCs: FetchActivation, which retrieves activation details based on transaction ID and invocation context, and RescheduleActivation, which allows the scheduler to re-queue an activation. This defines the contract for the new scheduler's activation management capabilities.
core/scheduler/src/main/protobuf · high confidence
Architecture
Active acknowledgement logic moved to common package
The implementation for sending active acknowledgements (including health checks and messaging to Kafka) has been relocated to the \common\ package. This change centralizes the \ActiveAck\ trait and its concrete implementations (\HealthActionAck\, \MessagingActiveAck\), making the acknowledgement mechanism available as a shared component rather than being tied to a specific module.
common/scala/src/main/scala/org/apache/openwhisk/core/ack · high confidence
Behavioural changes
Activation storage now supports file-based logging and configurable result retention
Users can now store activation logs and metadata to local files in addition to the database via the new \ArtifactWithFileStorageActivationStore\, which rotates log files based on size and allows including or excluding the action result payload. The system also introduces granular control over database storage through \storeBlockingResultLevel\ and \storeNonBlockingResultLevel\ configuration options, enabling administrators to prevent successful blocking activations from being stored to reduce database load.
common/scala/src/main/scala/org/apache/openwhisk/core/database · high confidence
Ansible deployment files restructured with new CouchDB design documents and runtime configurations
The ansible/files directory has been restructured to support the separation of the activations database from the main whisks database. This includes adding new CouchDB design documents for the activations database (activations\_design\_document, logCleanup\_design\_document) and updated design documents for the whisks database (v2.1.0, v2.1.1) that handle activation summaries and path filtering, including support for binding annotations. The runtimes.json and runtimes-nodeonly.json files have been updated to reflect current supported runtimes (e.g., nodejs:20, python:3.10/3.11, swift:5.3/5.7, go:1.20, dotnet:3.1, php:8.1, ruby:2.5) with nightly image tags. Additionally, a new genssl.sh script for generating SSL certificates and keystores has been added, and authentication keys (auth.guest, auth.whisk.system) have been moved from config/keys to ansible/files.
ansible/files · high confidence
Consolidated ow-utils Docker image with multi-architecture support
The \tools/ow-utils\ directory now provides a unified utility image for OpenWhisk tasks, replacing previous separate builds. The new Dockerfiles support both x86\_64 and ARM64 architectures, bundling JDK 8, Python, Node.js, Ansible, and standard CLI tools like \wsk\, \wskadmin\, \kubectl\, and \docker\. This consolidation ensures consistent tooling availability across different hardware platforms for deployment and management tasks.
tools/ow-utils · high confidence
Controller Docker image rebuilt with security, tooling, and build-system improvements
The controller container image has been significantly updated to improve security, reliability, and build hygiene. The image now installs a specific Docker client version (23.0.6) and verifies the integrity of downloaded software (like Swagger UI) using SHA-256 checksums. It also switches to a non-root user for better security practices and includes Swagger UI 3.6.0. Additionally, the build system has migrated from Ant to Gradle, removing obsolete Ant build files and Eclipse project metadata, while adding a .dockerignore file to optimize the build context.
core/controller · high confidence
Controller REST API implementation migrated to Apache Pekko HTTP
The core controller REST API implementation in \core/controller/src/main/scala/org/apache/openwhisk/core/controller\ has been updated to use Apache Pekko HTTP instead of the previous Akka HTTP framework. This migration involves replacing Akka imports and types with their Pekko equivalents (e.g., \org.apache.pekko.http\), ensuring the controller service continues to handle action, activation, and entity operations using the new underlying HTTP server library.
core/controller/src/main/scala/org/apache/openwhisk/core/controller · high confidence
Controller configuration migration to Pekko and API security hardening
The controller's configuration has been migrated from Akka to Apache Pekko, introducing a new application.conf with Pekko HTTP settings (such as request timeouts and connection limits) and updating reference.conf for cluster and load-balancer behavior. Concurrently, the main API specification (apiv1swagger.json) has been updated to enforce basic authentication on all endpoints, and a new info endpoint has been added to expose deployment configuration, supported runtimes, and namespace throttle limits to users.
core/controller/src/main/resources · high confidence
CosmosDB backend refactored with soft delete, usage metrics, and connection pooling
The CosmosDB database backend has been significantly restructured to improve reliability, observability, and data safety. The new implementation introduces soft delete support, allowing documents to be marked for deletion with a configurable TTL rather than being immediately removed, which prevents accidental data loss. It also adds detailed resource usage tracking, collecting metrics on document size, index size, and request unit (RU) consumption to help monitor performance and quota usage. Additionally, the client connection management has been refactored to use a reference-counted pool, ensuring that multiple store instances share a single underlying connection to optimize resource usage.
common/scala/src/main/scala/org/apache/openwhisk/core/database/cosmosdb · high confidence
Docker invoker refactored to Pekko and enhanced with runc and file-based access
The Docker container pool implementation in the invoker has been rewritten to use the Apache Pekko actor system, replacing the previous Akka dependencies. This change introduces a new Docker client architecture that supports file-based log and configuration access (DockerClientWithFileAccess) for more efficient log collection and IP resolution, and adds optional support for using runc to pause and resume containers for better performance. The refactoring also includes platform-specific client implementations for Docker for Mac and Windows, configurable timeouts for Docker CLI commands, and the ability to mask Docker run arguments in logs for security.
core/invoker/src/main/scala/org/apache/openwhisk/core/containerpool/docker · high confidence
Entitlement system refactored for Apache Pekko and per-minute throttling
The entitlement logic in the controller has been migrated from the Akka HTTP stack to Apache Pekko, updating imports and actor system dependencies throughout the entitlement providers. Additionally, a new per-minute throttling mechanism has been introduced for the FPC entitlement provider, allowing administrators to enable rate limits on actions and triggers per minute via configuration, alongside the existing concurrent activation limits. The entitlement provider interface has also been standardized to use the new \Identity\ type instead of the legacy \Subject\ type, and package binding circular references are now explicitly detected and rejected during entitlement checks.
core/controller/src/main/scala/org/apache/openwhisk/core/entitlement · high confidence
Initialize docker-machine environment configuration with local defaults
A new \group\_vars/all\ file is introduced for the \docker-machine\ environment, establishing baseline configuration variables for local deployments. This includes setting the configuration and log directories to \/Users/Shared\, enabling the bypass of Docker image pulls for local images, configuring the API gateway connection, and allowing multiple invoker instances. It also defines Kafka heap and retention settings and sets a hardcoded database prefix specific to the docker-machine setup.
_ansible/environments/docker-machine/group\vars · high confidence
Introduce new in-memory scheduler queue with advanced capacity management
The scheduler queue implementation has been replaced with a new in-memory architecture that provides finer-grained control over container provisioning and namespace throttling. This change introduces a dedicated ContainerCounter to track existing and in-progress containers via etcd, and a DurationChecker (backed by Elasticsearch or a no-op fallback) to monitor action execution times for smarter scaling decisions. The new MemoryQueue and SchedulingDecisionMaker components allow for over-provisioning new actions before namespace throttling kicks in, handle stale activations more efficiently, and support user-defined action instance concurrency limits, resulting in improved responsiveness and reduced latency for action invocations.
core/scheduler/src/main/scala/org/apache/openwhisk/core/scheduler/queue · high confidence
Introduction of an abstract Clock interface for time abstraction
A new \Clock\ trait and its \SystemClock\ implementation have been added to the common time utilities. This change introduces an abstraction layer for retrieving the current time, replacing direct calls to \java.time.Instant.now()\ with a configurable interface. While primarily designed to facilitate testing by allowing fake clocks to be injected, this architectural shift enables more predictable time handling within the application.
common/scala/src/main/scala/org/apache/openwhisk/common/time · high confidence
Introduction of new load balancer implementations and refactoring
The load balancer module has been significantly refactored to support new scheduling models and improved observability. A new \FPCPoolBalancer\ has been added to support per-minute throttling and integration with the new scheduler via etcd, while a \LeanBalancer\ implementation provides a lightweight, in-memory mode for single-instance deployments. The core logic has been extracted into a shared \CommonLoadBalancer\ base class, and the \ShardingContainerPoolBalancer\ now emits separate metrics for managed and blackbox invokers. Additionally, the underlying actor system has been migrated from Akka to Apache Pekko.
core/controller/src/main/scala/org/apache/openwhisk/core/loadBalancer · high confidence
Invoker container now runs as a non-root user with Docker 23.0.6
The invoker Docker images have been updated to install Docker client version 23.0.6 and switch to running the invoker process as a non-root user (owuser) instead of root. This change improves security by reducing the container's privileges and aligns the Docker client version with the server version to ensure proper runc support. The entry also includes the necessary Dockerfiles (standard, Debian, and coverage variants) and an init script to handle JMX configuration and environment transformation before starting the service.
core/invoker · high confidence
Load balancer build system migrated from Ant to Gradle
The load balancer module has switched its build infrastructure from Ant to Gradle. This change removes the legacy Ant build script (build.xml), associated Eclipse project configuration files (.classpath, .project), and the previous Dockerfile and startup shell script, as these are no longer managed by the old build toolchain. Users should note that the local build and deployment processes for this component now rely on the new Gradle configuration.
core/loadBalancer · high confidence
Local environment defaults for OpenWhisk configuration and concurrency
The local environment now defines default configuration variables for the OpenWhisk deployment, including temporary directories, database prefixes, and API Gateway connection settings. It enables the reactive container pool (Pekko client) and action concurrency by default, setting a maximum concurrency limit of 500 actions per namespace. Additionally, it configures Kafka heap size and topic retention policies, and allows multiple invoker instances to run locally.
_ansible/environments/local/group\vars · high confidence
Migrate HTTP infrastructure from Akka to Apache Pekko
The core HTTP service layer in the common module has been migrated from Akka HTTP to Apache Pekko. This change updates the underlying actor system and HTTP server/client implementations (including BasicHttpService, PoolingRestClient, and CORS settings) to use the Pekko libraries, ensuring compatibility with the platform's broader migration to Apache Pekko while maintaining existing REST API and monitoring endpoints.
common/scala/src/main/scala/org/apache/openwhisk/http · high confidence
Migrate Scala common image to JDK 21 and add configuration helper scripts
The common/scala Docker image has been upgraded from Ubuntu 14.04 with Oracle Java 8 to a multi-arch image based on Eclipse Temurin JDK 21 (JRE). To support this environment, the build now installs curl, bash, sed, and openssl, and copies two new helper scripts: transformEnvironment.sh, which converts environment variables into JVM system properties, and copyJMXFiles.sh, which handles JMX configuration files for Kubernetes compatibility. Additionally, legacy Eclipse project files (.classpath, .project) and the old .gitignore have been removed.
common/scala · high confidence
Migrate configuration and logging to Apache Pekko and Logback
The application configuration and logging infrastructure have been updated to align with the Apache Pekko migration. The main configuration file (application.conf) now uses Pekko-specific settings for HTTP client limits (50 MB content length, 128 max connections) and Kamon metrics integration. Logging has switched from the legacy log4j system to Logback, with a new logback.xml entry point that delegates to whisk-specific configurations and sets default log levels. Additionally, reference.conf defines default SPI providers for core components (such as CouchDB, Kafka, and Docker) and configures dedicated thread-pool dispatchers for CouchDB and Kafka clients to improve concurrency handling.
common/scala/src/main/resources · high confidence
Migrate core entity models to Apache Pekko
The entity model classes in the core package (including ActivationId, ActivationResult, Attachments, and BasicAuthenticationAuthKey) have been updated to use Apache Pekko HTTP types instead of the previous Akka HTTP implementation. This change aligns the entity layer with the broader Apache Pekko migration, ensuring that serialization, deserialization, and status code handling within these core data structures are consistent with the new Pekko-based runtime.
common/scala/src/main/scala/org/apache/openwhisk/core/entity · high confidence
Migrate invoker container pool actors to Apache Pekko
The ContainerPool and ContainerProxy components in the OpenWhisk invoker now use the Apache Pekko actor library instead of Akka. This migration updates the underlying actor system imports and references (e.g., \org.apache.pekko.actor\), ensuring the invoker's container lifecycle management and proxy logic operate on the Pekko runtime.
core/invoker/src/main/scala/org/apache/openwhisk/core/containerpool · high confidence
New Kafka connector implementation with Pekko migration and metrics
The Kafka connector module has been replaced with a new implementation that migrates the underlying actor system from Akka to Apache Pekko. This change introduces a new consumer connector that handles partition lag monitoring and includes robust error handling for consumer recreation on exceptions. Topic provisioning is now managed by a messaging provider that checks for topic existence before creation and supports configurable partition counts. Additionally, the connector now exposes Kafka client-side metrics via Kamon and provides a JSON endpoint at /metrics/kafka for monitoring consumer and producer performance.
common/scala/src/main/scala/org/apache/openwhisk/connector/kafka · high confidence
New Kubernetes container pool implementation with resource scaling and security hardening
The Kubernetes container pool has been replaced with a new implementation that allows users to configure optional CPU limits and ephemeral storage limits scaled based on action memory, enforce node affinity for invoker placement, and apply security contexts that drop NET\_RAW and NET\_ADMIN capabilities. The new system also supports custom pod templates, configurable Pod Disruption Budgets, and field reference environment injection, while ensuring failed pods are cleaned up and providing more robust error handling for API server failures and image pull issues.
core/invoker/src/main/scala/org/apache/openwhisk/core/containerpool/kubernetes · high confidence
New container creation and management architecture in the scheduler
The scheduler now uses a new \ContainerManager\ and \CreationJobManager\ to handle container lifecycle. \ContainerManager\ coordinates invoker selection and tracks warmed containers via etcd, while \CreationJobManager\ manages the creation job pool, handling retries with exponential backoff and timeouts (with extended retention for blackbox actions). This replaces the previous inline scheduling logic with a structured job-based approach for both cold and warm container creation.
core/scheduler/src/main/scala/org/apache/openwhisk/core/scheduler/container · high confidence
New macOS unit test runner and updated Docker for Mac setup documentation
A new script, tools/macos/runUnitTests.sh, has been added to streamline running unit tests on macOS by executing the necessary Ansible playbooks (setup, prereq, couchdb, initdb, wipe, elasticsearch, etcd, properties) before invoking the Gradle test task. The legacy scripts for configuring Docker Machine (tweak-dockerhost.sh and tweak-dockermachine.sh) have been removed, and the README.md has been updated to provide instructions for setting up OpenWhisk with Docker for Mac, including specific version requirements for Docker (18.06.3+), OpenJDK 11, and Ansible 4.1.0.
tools/macos · high confidence
Redesign of Controller Ansible deployment role
The controller deployment role has been restructured into a modular set of task files (deploy, clean, join\_pekko\_cluster, lean) to support flexible configuration modes. This change introduces native support for joining a Pekko cluster, enables a 'lean' deployment mode that shares invoker resources, and adds configurable JMX monitoring and SSL/TLS certificate handling for secure communication.
ansible/roles/controller · high confidence
Refactored action invocation logic into dedicated controller traits
The action invocation logic in the controller has been reorganized into three new Scala traits: PostActionActivation, PrimitiveActions, and SequenceActions. PostActionActivation serves as the entry point for invoking actions, routing requests to either sequence or primitive handlers. PrimitiveActions contains the core logic for invoking single actions, including support for conductor-based compositions and handling of init-time parameters. SequenceActions manages the execution of action sequences, ensuring proper activation tracking and database storage for sequence components. This refactoring improves code modularity and separation of concerns within the action controller layer.
core/controller/src/main/scala/org/apache/openwhisk/core/controller/actions · high confidence
Refactored invoker Ansible role into modular deploy and clean tasks
The invoker deployment logic has been restructured into distinct task files: \deploy.yml\ handles pulling images, configuring SSL, and starting the container, while \clean.yml\ manages graceful shutdown, container removal, and cleanup of logs and configuration directories. This separation enables zero-downtime deployments by allowing the system to disable the invoker and wait for active containers to finish before removal, and it improves maintainability by isolating the installation and teardown processes.
ansible/roles/invoker · high confidence
Refactored message bus interfaces to use common metadata and support retries
The connector module's message bus interfaces have been updated to decouple from Kafka-specific types and improve reliability. The \MessageProducer\ interface now returns a generic \ResultMetadata\ object instead of Kafka's \RecordMetadata\, and its \send\ method accepts an optional \retry\ parameter to handle transient failures. Additionally, the \MessageProducer.sentCount\ return type has been changed from \Int\ to \Long\ to prevent overflow during high-volume usage. New abstractions including \MessagingProvider\ and \MessageConsumer\ have been introduced to standardize how message producers and consumers are instantiated and managed across the system.
common/scala/src/main/scala/org/apache/openwhisk/core/connector · high confidence
Removal of Ant-based build and configuration generation for Nginx
The Ant build script (build.xml) and the shell script used to generate the Nginx reverse proxy configuration (generateProxyConf.sh) have been removed from the services/nginx directory. This eliminates the legacy build targets responsible for generating proxy configuration files and starting the Nginx container via Docker, aligning with the project's migration away from Ant.
services/nginx · high confidence
Removal of legacy Akka and Spray configuration files
The default configuration files for the Akka actor system and the Spray HTTP toolkit have been removed from the project. Specifically, \common/scala/src/application.conf\, \common/scala/src/logging.conf\, and \core/controller/src/resources/application.conf\ are no longer present. This eliminates the default DEBUG-level logging setup via SLF4J and the infinite request/idle timeouts previously configured for the Spray server, indicating a shift away from these specific legacy frameworks or their default configuration strategies.
common/scala/src, core/controller/src/resources · high confidence
Removal of legacy Cloudant and Ant-based configuration scripts
The deployment configuration system has been cleaned up by removing the Ant build configuration (\config.xml\) and several shell scripts responsible for local environment setup and property generation (\localEnv.sh\, \cloudantSetup.sh\, \setupProps.sh\, \writePropertyFile.sh\). This change eliminates the hardcoded dependency on Cloudant for local development and removes the self-signed SSL certificate (\openwhisk-self-cert.pem\) that was previously bundled in the config keys directory, simplifying the configuration structure.
config · high confidence
Removal of local Kafka and Zookeeper configuration files
The local configuration files for Kafka (consumer, producer, server, and log4j settings) and Zookeeper have been removed from the services/kafka/config directory. This change aligns with the switch to the ches/kafka image, indicating that these services are no longer managed via these local property files but are instead configured through the new container image or external infrastructure.
services/kafka/config · high confidence
Removes precompiled OpenWhisk binary framework from iOS starter app
The precompiled OpenWhisk.framework binary, including its headers, module map, and code signature, has been removed from the iOS starter app. This change shifts the dependency management from a static binary to source-based resolution via Carthage (Cartfile) and CocoaPods (Podfile), requiring users to build the framework from source during their own project setup.
mobile/iOS/starterapp/OpenWhisk.framework, mobile/iOS/starterapp/OpenWhisk.framework/Modules/OpenWhisk.swiftmodule · high confidence
Restructuring of CLI entry points and tool locations
The bin directory has been reorganized to reflect a shift in tooling and structure. The wskdev command is now a symlink to the build redo script, while the wsk CLI entry point has been removed entirely. Additionally, the wskadmin tool has been moved from the CLI tools directory to a dedicated admin tools directory, indicating a separation of administrative utilities from the main client interface.
bin · high confidence
Route management actions refactored to use API Gateway as the configuration store
The route management actions (create, get, delete) have been restructured to no longer store API configuration in a separate database. Instead, they now use the API Gateway as the single source of truth for API configuration data. This change introduces a new common utilities module (apigw-utils.js and utils.js) that handles tenant management, API CRUD operations, and Swagger validation directly against the API Gateway. The actions now support both V1 and V2 API Gateway endpoints, with V2 using access tokens and space GUIDs for tenant isolation. The refactoring also adds proper User-Agent headers to API Gateway requests and improves error handling for API creation, deletion, and retrieval operations.
core/routemgmt/common · high confidence
Route management scripts now install actions into the apimgmt package
The install and uninstall scripts for route management have been updated to deploy and manage API gateway actions within the apimgmt package instead of the routemgmt package. The install script now creates the apimgmt package and installs getApi, createApi, and deleteApi actions into it, while the uninstall script targets the apimgmt package for deletion. This change aligns the deployment location of these actions with the API configuration data store.
ansible/roles/routemgmt/files · high confidence
Ubuntu setup tooling modernized for Ubuntu 18.04+ with Docker 27 and Ansible 2.5
The Ubuntu setup scripts have been updated to support Ubuntu 18.04 (Xenial) and later releases, replacing legacy installation methods with modern equivalents. Docker installation now targets version 27.3.1 via the official Docker CE repository for Ubuntu Jammy, replacing the deprecated lxc-docker package, and includes a new experimental script for Xenial+ that installs the latest stable Docker CE. Ansible has been upgraded to version 2.5.2, and the setup now installs Python dependencies (argcomplete, couchdb) via pip instead of older package managers. Legacy tools such as Ant, Gradle, Eclipse, Emacs, and Tmux have been removed from the automated setup, and the default timezone has been changed from America/New\_York to UTC.
tools/ubuntu-setup · high confidence
Vagrant environment defaults updated for CLI remote mode and runc usage
The Vagrant environment configuration now sets the CLI installation mode to 'remote' and explicitly disables the use of runc for the invoker (setting invoker\_use\_runc to false). These changes streamline the local development setup by relying on remote CLI execution and standard container runtimes, while also centralizing database prefix and Kafka retention settings.
_ansible/environments/vagrant/group\vars · high confidence
Vagrant environment now includes etcd in the inventory
The Vagrant environment configuration has been updated to explicitly define an etcd host group. This change adds an 'etcd' section to the Ansible inventory file, allowing the orchestration system to target and manage etcd nodes within the Vagrant setup, which is necessary for the new scheduler implementation.
ansible/environments/vagrant · high confidence
Test coverage
Add action container test utilities and base test suites; Add test configuration and logging resources; Added API Gateway end-to-end tests using REST operations; Added API Gateway test data for path parameters and YAML import validation; Added Android and Java build templates for Swagger code generation tests; Added Gradle compatibility workaround in test sources; Added OpenWhisk Gatling performance test simulations and DSL; Added REST API validation and test operations; Added REST system tests for API schema validation and CLI download endpoints; Added REST-based CLI test suites for API Gateway, actions, and entitlements; Added Unicode action test fixtures for multiple runtimes; Added behavior tests for Activation and Artifact stores; Added build script for Gatling performance tests; Added high-availability tests for controller cache invalidation and failover; Added integration tests for Whisk action invocation and copying; Added integration tests for action limits and concurrency; Added integration tests for the ElasticSearch activation store; Added performance test preparation scripts and sample actions; Added standalone mode integration tests for API Gateway, CouchDB, Kafka, and Kubernetes; Added test action data files and build script; Added test coverage for MongoDB database components; Added test coverage for configuration, SPI, execution context, and API gateway actions; Added test coverage for core entity serialization and runtime configuration; Added test data assets for Gatling performance tests; Added test data for Python zip-based actions; Added test documentation and cleaned up legacy IDE/build files; Added test fixtures for blackbox and zipped actions; Added test suite for CosmosDB store implementation; Added tests for Azure Blob attachment store and database utilities; Added tests for CORS headers and Kafka connector resilience; Added tests for CosmosDB cache invalidation and change event observation; Added tests for Docker log collection and activation logging; Added tests for FPC Scheduler flows and server API; Added tests for Kafka metrics JSON endpoint; Added tests for S3 attachment store and CloudFront signing; Added tests for YARN container pool integration; Added tests for acknowledgement message serialization; Added tests for action and trigger rate throttling; Added tests for common infrastructure components; Added tests for container log store implementations; Added tests for container pool configuration and runtime behavior; Added tests for core service components; Added tests for database store implementations and CLI commands; Added tests for invoker container message consumption and server management; Added tests for the FPC Pool Balancer, Invoker Supervision, and Sharding Container Pool Balancer; Added tests for the Pooling REST Client; Added tests for the new scheduler queue components; Added tests for the user-events monitoring service; Added tests for wskadmin user management operations; Added unit tests for ContainerManager and CreationJobManager; Added unit tests for Docker container pool components; Added unit tests for Etcd configuration, key-value operations, and worker actor behavior; Added unit tests for Kubernetes container pool client and pod builder; Added unit tests for the connector module; Added unit tests for the gRPC ActivationService implementation; Added unit tests for the v2 container pool scheduler components; Added wrk-based performance test scripts for latency and throughput; Expanded test coverage for OpenWhisk controller components; New system tests for REST API operations; New test infrastructure and helper utilities; Removal of Activator unit tests; Removal of legacy Cloudant-based entity tests; Removal of legacy Java CLI test suites; Removal of legacy REST system tests; Removal of legacy Scala controller unit tests; Removal of legacy action container integration tests; Removal of legacy dispatcher test suite; Removal of obsolete ConsulKV test suite; Removal of obsolete DbUtils test helper; Removal of obsolete service integration tests; Removal of obsolete test suite in tests/src/whisk/common; Removed InvokerTests.scala integration test; Removed Java-based integration tests for Samples and Slack packages; Removed ParallelRunner test utility; Removed defunct LoadBalancer unit tests.
Dependencies
Initialize Gradle wrapper with version 7.6.2
The project now includes a Gradle wrapper configuration file that pins the build tool to version 7.6.2. This ensures that all developers and CI systems use a consistent, reproducible Gradle environment by automatically downloading the specified distribution, rather than relying on a globally installed version.
gradle/wrapper · high confidence
Migrate build system from Ant to Gradle and switch runtime from Akka to Apache Pekko
The project build system has been migrated from Ant to Gradle, introducing a new multi-module structure with build definitions for core components (controller, invoker, scheduler, standalone) and common libraries. As part of this migration, the underlying actor framework has been switched from Akka to Apache Pekko, with Pekko libraries (actor, HTTP, Kafka connectors, management, and gRPC) now explicitly versioned and constrained across all Scala modules to ensure consistency. The Gradle configuration also enforces strict dependency resolution for transitive libraries like Netty, gRPC, and Jackson to address security vulnerabilities, while maintaining support for both Scala 2.12 and 2.13.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 37 → 41 (+3.9)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 25 → 36 (+11.0)
- Architecture 61 → 61 (+0.5)
- Maturity 46 → 49 (+3.2)
- Readiness 45 → 54 (+9.5)
- Security 59 → 57 (-1.6)
- Domain Modelling 70 → 60 (-9.7)
- Accessibility 49 → 38 (-11.2)
Resolved (79)
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- …and 59 more
New (261)
- ActivationResponse.processRunResponseContent (cognitive 16) (common/scala/src/main/scala/org/apache/openwhisk/core/entity/ActivationResult.scala)
- ActivationServiceImpl.fetchActivation (cognitive 18) (core/scheduler/src/main/scala/org/apache/openwhisk/core/scheduler/grpc/ActivationServiceImpl.scala)
- AttachmentSupport.attachToExternalStore (cognitive 17) (common/scala/src/main/scala/org/apache/openwhisk/core/database/AttachmentSupport.scala)
- CallbackModule.emit (cognitive 21) (ansible/callbacks/logformatter.py)
- Change coupling: Packages.scala ↔ PackageCollection.scala (core/controller/src/main/scala/org/apache/openwhisk/core/controller/Packages.scala)
- CommonLoadBalancer.processCompletion (cognitive 22) (core/controller/src/main/scala/org/apache/openwhisk/core/loadBalancer/CommonLoadBalancer.scala)
- ContainerManager.schedule (cognitive 24) (core/scheduler/src/main/scala/org/apache/openwhisk/core/scheduler/container/ContainerManager.scala)
- ContainerPool.receive (cognitive 57) (core/invoker/src/main/scala/org/apache/openwhisk/core/containerpool/ContainerPool.scala)
- ContainerPool.receive (cyclomatic 26) (core/invoker/src/main/scala/org/apache/openwhisk/core/containerpool/ContainerPool.scala)
- ContainerProxy.initializeAndRun (cognitive 33) (core/invoker/src/main/scala/org/apache/openwhisk/core/containerpool/ContainerProxy.scala)
- ContainerProxy.initializeAndRun (cyclomatic 24) (core/invoker/src/main/scala/org/apache/openwhisk/core/containerpool/ContainerProxy.scala)
- CouchDBLauncher.run (cognitive 30) (core/standalone/src/main/scala/org/apache/openwhisk/standalone/CouchDBLauncher.scala)
- CouchDbRestStore.attachToCouch (cognitive 33) (common/scala/src/main/scala/org/apache/openwhisk/core/database/CouchDbRestStore.scala)
- DataManagementService.receive (cognitive 31) (common/scala/src/main/scala/org/apache/openwhisk/core/service/DataManagementService.scala)
- DataManagementService.receive (cyclomatic 23) (common/scala/src/main/scala/org/apache/openwhisk/core/service/DataManagementService.scala)
- Dependency hygiene PARTLY measured — Maven/Gradle declarations read, no dependency graph resolved
- DockerContainer.create (cognitive 17) (core/invoker/src/main/scala/org/apache/openwhisk/core/containerpool/docker/DockerContainer.scala)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Duplicated block (10 lines × 2) (core/controller/src/main/scala/org/apache/openwhisk/core/controller/ApiUtils.scala)
- …and 241 more
Changes since last survey
- 4 commits — 3 feature/other, 1 fixes
By area
- (root) — 3 commits
- ansible/roles — 1 commit
Notable commits
- fix: Bump zookeeper version to fix apache/openwhisk#5564 (#5565)
- change: Address vulns for netty, logback, httpclient, and jackson (#5585)
- change: Upgrade netty to 4.2.16.Final and micrometer to 1.17.0 for vulns (#5581)
- change: Upgrade netty to 4.2.17.Final and awssdk to 2.54.2 (#5584)
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
apache/openwhisk was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 22 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit a67aba60ce68e0583962cb51cf6726c2a5f3795e — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-be726e82e277.