apolloconfig/apollo
41.7
Weak · 24 September 2026
49.4k
lines of production code
Java
with JavaScript
4
measurements over time
What this system is
This system is Apollo, a distributed configuration management platform that provides a centralized interface for managing application configurations across multiple environments. It consists of an Admin Service for configuration CRUD operations and access control, a Config Service for efficient client-side configuration retrieval and synchronization, and a Portal for web-based administration, user management, and auditing. The system supports various service discovery mechanisms, enforces strict access permissions via access keys and consumer tokens, and facilitates safe configuration changes through features like namespace locking, gray releases, and comprehensive audit logging.
How it got here
2016 — Spring Boot 3 migration and OpenAPI v1 adoption
109 changes.
The project underwent a major infrastructure upgrade, migrating the backend to Spring Boot 3 and Java 17 while introducing Jakarta EE APIs and a unified assembly module. The Apollo Portal was refactored to communicate with the backend via a new OpenAPI v1 interface, replacing legacy internal contracts and enabling standardized consumer authentication and auditing. This period also established a robust data model using Spring Data JPA, implemented soft-delete patterns, and expanded the UI with comprehensive namespace management, gray release workflows, and role-based access control.
2017–2023 — Security hardening and audit logging
47 changes.
This period focused on strengthening Apollo's security posture by integrating Spring Security for authentication, implementing granular access controls, and enforcing stricter password policies. It also introduced comprehensive audit logging capabilities and enhanced the Open Platform with rate limiting and consumer management features. Underlying infrastructure improvements included caching optimizations, incremental sync support, and database-backed service discovery.
2024–2026 — OpenAPI security and database schema management
17 changes.
This period focused on enhancing OpenAPI security by introducing user access tokens, session validation filters, and comprehensive authentication tests. It also added features for custom SQL initialization and schema conversion, alongside manual migration scripts to purge retained release history. Extensive test coverage was added for portal UI, authentication flows, and static JSON validation to ensure system stability.
Features
Add Apollo Audit Log Spring Boot Starter
Introduces a new Spring Boot starter for Apollo audit logging, providing automatic configuration for audit log services, HTTP interceptors, and AOP aspects. The starter includes two auto-configuration classes: one that enables full audit logging when \apollo.audit.log.enabled=true\ (using JPA repositories and a default operator supplier), and a no-op fallback when the property is false or missing, ensuring the application runs without audit overhead by default. It registers beans for audit log APIs, trace contexts, and controllers, and is registered via both \spring.factories\ and the Spring Boot 3 \AutoConfiguration.imports\ mechanism.
apollo-audit/apollo-audit-spring-boot-starter · high confidence
Add Spring Boot auto-configuration for database-backed service registry and discovery
This change introduces new Spring Boot auto-configuration classes (\ApolloServiceRegistryAutoConfiguration\ and \ApolloServiceDiscoveryAutoConfiguration\) that enable Apollo servers to use the database as a service registry. It adds configuration properties (\apollo.service.registry\ and \apollo.service.discovery\) to control registration and discovery, and registers beans for database-based service registry and discovery clients. The configuration also includes support for heartbeat sending, deregistration on shutdown, and periodic cleanup of unhealthy instances, allowing users to opt-in to database-backed service registration and discovery by setting the respective enabled properties.
apollo-biz/src/main/java/com/ctrip/framework/apollo/biz/registry/configuration · high confidence
Add service discovery endpoints for non-Eureka environments
The config service now exposes REST endpoints to list available Apollo instances (Config and Admin) when using non-Eureka service discovery mechanisms. A new HomePageController provides a root endpoint (/) for profiles like Kubernetes, Nacos, Consul, Zookeeper, and database discovery, while the ServiceController exposes /services/config and /services/admin to return service instances. This allows clients and dashboards to discover service locations without relying on Eureka's home page.
apollo-configservice/src/main/java/com/ctrip/framework/apollo/metaservice/controller · high confidence
Added AOP aspect to trace Spring Data repository methods
A new aspect class, RepositoryAspect, has been introduced to automatically wrap all public methods in Spring Data repository interfaces with CAT transactions. This ensures that database operations performed through Spring Data repositories are now captured in application performance monitoring traces, aiding in debugging and performance analysis.
apollo-common/src/main/java/com/ctrip/framework/apollo/common/aop · high confidence
Added AngularJS v1.4.3 vendor libraries and i18n support
The Apollo Portal now includes several new AngularJS v1.4.3 vendor libraries to support enhanced functionality, specifically adding \angular-cookies\, \angular-resource\, \angular-route\, and \angular-sanitize\. Additionally, the \angular-translate\ library (v2.18.1) and its static file loader and cookie storage modules have been added to enable internationalization (i18n) support, while \angular-toastr\ (v1.4.1) has been included to provide toast notification capabilities for user feedback.
apollo-portal/src/main/resources/static/vendor/angular · high confidence
Added Eclipse and IntelliJ Java code style profiles and license template
The build tools now include standardized code formatting configurations for Java development, providing both Eclipse (eclipse-java-google-style.xml) and IntelliJ (intellij-java-google-style.xml) profiles based on Google Java Style. These profiles enforce consistent indentation, line wrapping, and brace placement rules. Additionally, a standard Apache 2.0 license header template (apollo-license) has been added to support automated license compliance checks in the CI pipeline.
apollo-buildtools/style · high confidence
Added Maven Wrapper for consistent builds
The project now includes the Maven Wrapper (\.mvn/wrapper\), which ensures that all developers and CI systems use the exact same Maven version (3.9.16) and build tooling, eliminating environment-specific build inconsistencies.
.mvn · high confidence
Added Windows and Unix build scripts for Apollo services
New build scripts (build.bat for Windows and build.sh for Unix/Linux) have been added to the scripts directory, providing users with standardized ways to package the Apollo config-service, admin-service, and portal. These scripts automate the Maven build process, allowing users to configure database connection details and meta server URLs for different environments (dev, fat, uat, pro) before building the services with specific profiles such as 'github' and 'auth'.
scripts · high confidence
Apollo Portal adds Spring Boot servlet initializer and assembly configuration
The Apollo Portal now includes a ServletInitializer class to support deployment as a traditional WAR file in external servlet containers, alongside a new PortalAssemblyConfiguration that configures the portal's database initialization specifically for the 'assembly' profile. These changes enable users to build and deploy the portal as a standalone web application archive while maintaining the existing embedded server startup path via the new PortalApplication entry point.
apollo-portal/src/main/java/com/ctrip/framework/apollo/portal · high confidence
ConfigService now enforces Access Key authentication for client requests
A new ClientAuthenticationFilter has been added to the ConfigService to validate incoming requests using Access Keys. The filter extracts the AppId and verifies the request's timestamp (checking against a configurable tolerance) and signature against available or observable secrets. If authentication fails, the request is rejected with an Unauthorized error; if it is a pre-check, invalid attempts are logged for observability without blocking the request.
apollo-configservice/src/main/java/com/ctrip/framework/apollo/configservice/filter · high confidence
Consumer API authentication and rate limiting
The Apollo Portal now enforces authentication and rate limiting for OpenAPI consumer requests via a new ConsumerAuthenticationFilter. Requests are validated using consumer tokens, and if a rate limit is configured for the consumer, requests exceeding the limit receive a 429 Too Many Requests response. This ensures that only authorized consumers can access the API and prevents abuse through rate limiting.
apollo-portal/src/main/java/com/ctrip/framework/apollo/openapi/filter · high confidence
Custom SQL initialization for Apollo data sources
Apollo now provides a dedicated mechanism to initialize database schemas and data via SQL scripts. This change introduces \ApolloSqlInitializationProperties\ to configure script locations, platform-specific filtering, and execution modes, alongside an \ApolloDataSourceScriptDatabaseInitializerFactory\ that resolves these settings and an \ApolloDataSourceScriptDatabaseInitializer\ that performs the actual initialization. This allows users to manage database setup through Apollo's configuration rather than relying solely on default Spring Boot behavior.
apollo-common/src/main/java/com/ctrip/framework/apollo/common/datasource · high confidence
Dynamic meta server configuration via database and environment sources
The Apollo Portal now supports dynamic configuration of meta server addresses for different environments. Administrators can define meta servers in the PortalDB.ServerConfig table (via the 'apollo.portal.meta.servers' key), which takes precedence over traditional configuration methods like system properties, OS environment variables, and the apollo-env.properties file. The system automatically loads these addresses, handles multiple comma-separated servers with random load balancing, and caches the results for performance. This change allows for runtime updates to meta server configurations without restarting the portal service.
apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/environment · high confidence
Enriched DTOs now include user display names
The portal now automatically populates display names for the creator, last modifier, and owner fields on application and base DTOs. This is achieved through a new \AdditionalUserInfoEnricher\ framework that maps user IDs from DTOs (such as \AppDTO\ and \OpenAppDTO\) to their corresponding display names using a provided user info map, ensuring that lists and views show human-readable names instead of just IDs.
apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/enricher · high confidence
Introduce backend audit log module with JPA persistence and REST API
This change adds the \apollo-audit-impl\ backend implementation, providing a new audit logging capability. It introduces JPA entities (\ApolloAuditLog\, \ApolloAuditLogDataInfluence\) and a REST controller (\/apollo/audit\) to query logs, trace details, and data influences. The module includes an AOP aspect (\ApolloAuditSpanAspect\) to intercept methods annotated with \@ApolloAuditLog\ and record operations, along with a tracer context to propagate trace IDs across HTTP requests. Audit logging is controlled via the \apollo.audit.log.enabled\ property and defaults to disabled.
apollo-audit/apollo-audit-impl/src/main · high confidence
Introduce database-backed release message scanning and sending
The apollo-biz module now includes a new message infrastructure centered on DatabaseMessageSender, ReleaseMessageScanner, and associated interfaces (MessageSender, ReleaseMessageListener). DatabaseMessageSender persists release messages to the database and manages a background thread to clean up old entries, while ReleaseMessageScanner periodically polls the database for new or missing release messages and notifies registered listeners. This provides a reliable, database-driven mechanism for propagating configuration release events, replacing or supplementing previous transport mechanisms.
apollo-biz/src/main/java/com/ctrip/framework/apollo/biz/message · high confidence
Introduce database-backed service registry and comprehensive entity model
This change adds a new database-based service registry implementation, allowing Apollo to discover server instances directly from the database without relying on external service discovery tools like Eureka or Zookeeper. It introduces the \ServiceRegistry\ entity and the \DatabaseDiscoveryClient\ interface with implementations that handle instance discovery, health checks, and caching. Additionally, the \entity\ package is populated with a complete set of JPA entities (including \AccessKey\, \Audit\, \Cluster\, \Commit\, \GrayReleaseRule\, \Instance\, \Item\, \Namespace\, \Release\, etc.) and a JSON converter, establishing the foundational data model for the application's business logic.
apollo-biz/src/main/java/com/ctrip/framework/apollo/biz/entity · high confidence
Introduce default SPI implementations for portal services
The portal now includes a set of default implementations for its Service Provider Interface (SPI) contracts within the \apollo-portal\ module. This adds concrete classes for email delivery (\DefaultEmailService\), message queue publishing (\DefaultMQService\), role and permission initialization (\DefaultRoleInitializationService\, \DefaultRolePermissionService\), user management (\DefaultUserService\), and session handling (\DefaultLogoutHandler\, \DefaultSsoHeartbeatHandler\, \DefaultUserInfoHolder\). These defaults provide baseline functionality—such as sending HTML emails, managing application and namespace roles, and handling basic user lookups—ensuring the portal operates correctly out-of-the-box without requiring custom service providers.
apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/spi/defaultimpl · high confidence
Introduce refreshable configuration property sources
Added two new classes, RefreshableConfig and RefreshablePropertySource, to the common configuration module. RefreshablePropertySource extends Spring's MapPropertySource to support dynamic updates, while RefreshableConfig provides a base implementation that registers these sources and schedules a background task to refresh configuration values every 60 seconds. This enables applications to automatically pick up changes to configuration properties without requiring a restart.
apollo-common/src/main/java/com/ctrip/framework/apollo/common/config · high confidence
Introduce text-based configuration resolution for properties and files
Added the ConfigTextResolver interface and its implementations (FileTextResolver, PropertyResolver) in the portal's txtresolver component. This enables the Apollo UI to parse raw text input for properties and file namespaces, correctly handling key-value pairs, comments, blank lines, and duplicate key detection when users submit configuration changes in text mode.
apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/component/txtresolver · high confidence
Introduce user access token support in the Apollo Portal
The Apollo Portal now supports user access tokens, enabling users to authenticate via tokens rather than just passwords. This change adds the core data models and authorization structures required for this feature, including a Spring Security authentication token (\UserTokenAuthenticationToken\), request and capability value objects for token creation and management (\UserTokenCreateRequest\, \UserTokenCapability\, \UserTokenInfo\), and scope definitions (\UserTokenScope\, \UserTokenNamespaceScope\, \UserTokenOpenApiAction\) that define granular permissions for operations, apps, environments, and namespaces.
apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/auth, apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/entity/vo/usertoken · high confidence
Introduces Apollo Audit Log API and annotation interfaces
This change adds the foundational API contracts and annotation definitions for the Apollo Audit Log feature. It introduces the \@ApolloAuditLog\ annotation for marking auditable methods, along with supporting annotations like \@ApolloAuditLogDataInfluence\ and \@ApolloAuditLogDataInfluenceTable\ to specify data change context. The \apollo-audit-api\ module exposes interfaces (\ApolloAuditLogRecordApi\, \ApolloAuditLogQueryApi\) and DTOs for recording audit events, querying logs, and tracking data influences, enabling developers to integrate audit logging into their applications.
apollo-audit/apollo-audit-annotation, apollo-audit/apollo-audit-api · high confidence
Introduces ApolloEurekaClientConfig for dynamic Eureka server URL configuration
A new ApolloEurekaClientConfig component has been added to the eureka package, extending EurekaClientConfigBean to allow Eureka server service URLs to be configured via the BizConfig. This component overrides getEurekaServerServiceUrls to return URLs from the application configuration, falling back to the default behavior if none are set. It also listens for the ApplicationReadyEvent to trigger a refresh of the Eureka client scope, ensuring that changes to the Eureka server configuration are picked up dynamically at runtime.
apollo-biz/src/main/java/com/ctrip/framework/apollo/biz/eureka · high confidence
Introduces SPI-based authentication configuration for LDAP, OIDC, and Spring Security
The portal now provides a new Service Provider Interface (SPI) in the \spi.configuration\ package to allow pluggable authentication backends. This change adds configuration classes for Spring Security (\AuthConfiguration\), LDAP (\LdapProperties\, \LdapExtendProperties\), and OIDC (\OidcExtendProperties\), enabling administrators to configure user identity claims, LDAP group mappings, and display name attributes. It also includes filter registration for user token and OpenAPI authentication (\AuthFilterConfiguration\) and default service beans for email and messaging (\EmailConfiguration\, \MQConfiguration\), establishing the foundation for flexible identity management without hardcoding specific providers.
apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/spi/configuration · high confidence
Introduces case-insensitive wrappers and deferred result handling for config notifications
The config service now includes new wrapper classes in the \wrapper\ package to support case-insensitive key lookups and improved long-polling response management. \CaseInsensitiveMapWrapper\ and \CaseInsensitiveMultimapWrapper\ normalize keys to lowercase, ensuring that namespace and configuration lookups are case-insensitive. \DeferredResultWrapper\ manages Spring MVC deferred results for long-polling, handling timeouts and ensuring that original namespace names are restored in responses when necessary, which supports the broader namespace name normalization feature.
apollo-configservice/src/main/java/com/ctrip/framework/apollo/configservice/wrapper · high confidence
Introduces in-memory caching for gray release rules
Adds GrayReleaseRuleCache and GrayReleaseRulesHolder to cache gray release rules in memory, enabling faster lookups for client requests. The holder periodically scans the database and listens for release messages to keep the cache synchronized, supporting case-insensitive matching for app IDs, IPs, and labels.
apollo-biz/src/main/java/com/ctrip/framework/apollo/biz/grayReleaseRule · high confidence
Introduces pluggable service discovery implementations for meta-service
The meta-service now supports multiple service discovery backends via a new \DiscoveryService\ interface and profile-based selection. Users can enable database-based discovery via the \database-discovery\ profile, use Spring Cloud-compatible registries (Consul, Zookeeper, Nacos) via the \consul-discovery\, \zookeeper-discovery\, or \nacos-discovery\ profiles, or bypass registry lookups entirely by providing direct URLs via configuration when using the \kubernetes\ or \custom-defined-discovery\ profiles. The default Eureka-based discovery remains active when none of these specific profiles are enabled.
apollo-configservice/src/main/java/com/ctrip/framework/apollo/metaservice/service · high confidence
Namespace-level role management UI added
A new 'role.html' page has been added to the namespace section of the Apollo Portal, providing a user interface for managing permissions at the namespace level. This page allows authorized users to assign 'ModifyNamespace' and 'ReleaseNamespace' roles to specific users, with the ability to scope these permissions to all environments or individual environments. The interface supports i18n and integrates with existing user selection and permission services.
apollo-portal/src/main/resources/static/namespace · high confidence
New Access Key and Cluster Management UI pages
The Apollo Portal adds two new static HTML pages to the client-side application: access\_key.html and manage\_cluster.html. The Access Key page provides a dedicated interface for application administrators to create, enable, disable, and remove access keys for specific environments, including UI support for 'Observed' mode. The Manage Cluster page displays a list of clusters per environment and provides a 'Grant' button to navigate to cluster-level role assignment. These pages rely on new Angular controllers (AccessKeyController, ManageClusterController) and services (AccessKeyService, ClusterService) to handle the respective backend interactions.
apollo-portal/src/main/resources/static/app · high confidence
New DTOs for access keys, gray release rules, and instance tracking
The apollo-common module introduces a suite of new data transfer objects to support expanded configuration management capabilities. AccessKeyDTO provides the data structure for managing application access keys, while GrayReleaseRuleDTO and GrayReleaseRuleItemDTO enable the definition and matching of gray release rules based on client IP and labels. InstanceDTO and InstanceConfigDTO expose instance-level configuration details, including the new releaseDeliveryTime field for tracking when configurations were delivered. Additionally, PageDTO adds pagination support for API responses, and several existing DTOs (AppDTO, ClusterDTO, NamespaceDTO) now include validation constraints for AppId and cluster/namespace formats.
apollo-common/src/main/java/com/ctrip/framework/apollo/common/dto · high confidence
New HTTP response entity models for multi-response, rich data, and search operations
Added three new classes to the \apollo-common\ HTTP package to standardize API responses: \MultiResponseEntity\ allows aggregating multiple \RichResponseEntity\ objects in a single response; \RichResponseEntity\ provides a structured wrapper for individual responses with status codes, messages, and typed bodies; and \SearchResponseEntity\ supports paginated search results by including a \hasMoreData\ flag alongside the body and status information.
apollo-common/src/main/java/com/ctrip/framework/apollo/common/http · high confidence
New JPA repositories for consumer management and auditing
The Apollo Open API layer now includes dedicated Spring Data JPA repositories to support consumer-centric features. ConsumerRepository enables lookups by application ID, while ConsumerRoleRepository manages role assignments and supports batch soft-deletion of roles. ConsumerTokenRepository handles token validation and retrieval for consumer authentication, and ConsumerAuditRepository provides the persistence layer for tracking consumer audit events.
apollo-portal/src/main/java/com/ctrip/framework/apollo/openapi/repository · high confidence
New Jenkins deployment script for Apollo applications
A new Jenkins deployment script (deploy\_jenkins.sh) has been added to the build tools. This script automates the deployment of specific Apollo applications (identified by IDs 100003171, 100003172, or 100003173) by shutting down the current instance, extracting the new release archive into a timestamped directory, and creating a symbolic link to the new version. It also includes a fix to prevent Jenkins from killing the newly started process by setting BUILD\_ID=dontKillMe before execution.
apollo-buildtools/src/main/scripts · high confidence
New LDAP authentication and user service implementation
The Apollo Portal now includes a new LDAP integration layer consisting of ApolloLdapAuthenticationProvider, FilterLdapByGroupUserSearch, and LdapUserService. The authentication provider overrides the standard Spring Security LDAP provider to map the login ID from the LDAP system rather than using the user-supplied username, ensuring consistent user identification. The user search component supports filtering users by group membership (using attributes like memberUid or member) and resolves user identities based on configurable LDAP attributes. The user service retrieves user details (ID, name, email, enabled status) from LDAP, supporting configuration for various LDAP schemas (OpenLDAP, Active Directory) via properties such as spring.ldap.base and ldap.mapping.\*.
apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/spi/ldap · high confidence
New Open Platform Consumer Management UI
The Apollo Portal now includes a dedicated interface for managing Open Platform consumers. This new page allows administrators to view a paginated list of consumers, create new consumer entries by specifying an App ID and selecting an organization, and delete existing consumers. It also supports retrieving consumer tokens by App ID and includes validation logic for optional rate limiting configurations.
apollo-portal/src/main/resources/static/scripts/controller/open · high confidence
New Open Platform consumer management UI with rate limiting and granular permissions
The Open Platform now includes a dedicated management interface (add-consumer.html, manage.html, grant-permission-modal.html) for root users to create and manage third-party consumer applications. This UI allows administrators to configure consumer capabilities, including whether the consumer can create applications or manage users, and introduces a configurable rate-limiting feature for API access. Additionally, it supports granular permission grants, allowing admins to assign specific roles (namespace or app level) and target specific environments to consumer tokens.
apollo-portal/src/main/resources/static/open · high confidence
New OpenAPI compatibility check script for v1 contract changes
A new Python script, \check\_openapi\_compatibility.py\, has been added to the \scripts/openapi\ directory to validate OpenAPI specifications against breaking changes. This tool ensures backward compatibility by detecting issues such as removed paths or HTTP methods, changed operation IDs, modified request/response schema references, and the addition of new required fields to existing schemas. It is designed to prevent accidental breaking changes to the Apollo OpenAPI v1 contract during migrations or updates.
scripts/openapi · high confidence
New OpenAPI consumer data model and audit entities
The portal now includes new JPA entity classes for OpenAPI consumers and their associated data: Consumer, ConsumerRole, ConsumerToken, and ConsumerAudit. These entities define the database schema for managing consumer identities, role assignments, authentication tokens (including rate limiting and expiration), and API usage audit logs, supporting the underlying OpenAPI consumer management and auditing capabilities.
apollo-portal/src/main/java/com/ctrip/framework/apollo/openapi/entity · high confidence
New OpenAPI consumer role and permission management services
Added ConsumerRolePermissionService and ConsumerService to the OpenAPI module, enabling programmatic management of consumer identities, tokens, and granular role-based permissions. ConsumerService handles consumer lifecycle (creation, token generation/lookup) and assigns specific namespace roles (modify/release) to consumers via API, while ConsumerRolePermissionService provides the underlying logic to verify if a consumer holds specific permissions by checking their assigned roles against the permission repository.
apollo-portal/src/main/java/com/ctrip/framework/apollo/openapi/service · high confidence
New OpenAPI utility components for consumer auditing, authentication, and model conversion
The portal now includes three new utility classes in the OpenAPI package to support the OpenAPI migration. ConsumerAuditUtil provides asynchronous, batched auditing of non-GET API requests, storing audit records in a queue for background processing. ConsumerAuthUtil centralizes the extraction and storage of consumer IDs from request tokens and context. OpenApiModelConverters supplies non-invasive conversion methods between internal portal DTOs/BOs and the generated OpenAPI model classes, ensuring consistent data formatting (such as date serialization) for API responses.
apollo-portal/src/main/java/com/ctrip/framework/apollo/openapi/util · high confidence
New SPI interfaces for extensible portal services
The Apollo portal now exposes a set of Service Provider Interface (SPI) definitions in the \com.ctrip.framework.apollo.portal.spi\ package, allowing organizations to replace default behaviors with custom implementations. New interfaces include \EmailService\ for sending notifications, \MQService\ for publishing messages to message queues, \LogoutHandler\ and \SsoHeartbeatHandler\ for customizing authentication and session management, and \UserService\ and \UserInfoHolder\ for managing user identity and lookup logic. This change enables users to integrate their own email providers, message brokers, and user directories without modifying core portal code.
apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/spi · high confidence
New SQL schema converter for MySQL and H2 profiles
The apollo-build-sql-converter module now includes a new tool that generates database schema scripts for different profiles (MySQL default, MySQL without database specification, and H2) from source templates. This converter processes SQL files to adapt them for specific database engines, such as converting MySQL-specific syntax like \ENGINE=InnoDB\ and \bit(1)\ types to H2-compatible formats, and renaming database references. It also includes tests to verify the generated SQL files are correct and consistent across profiles.
apollo-build-sql-converter · high confidence
New Spring profile-based conditional annotations
Added three new classes to the \apollo-common\ condition package: \ConditionalOnProfile\ and \ConditionalOnMissingProfile\ annotations, along with the \OnProfileCondition\ implementation. These allow developers to conditionally register Spring beans based on whether specific Spring profiles are active or inactive, extending the framework's existing conditional configuration capabilities.
apollo-common/src/main/java/com/ctrip/framework/apollo/common/condition · high confidence
New UI components for namespace management and grayscale publishing
The Apollo Portal adds a suite of new frontend components in the \views/component\ directory to support enhanced namespace and grayscale (gray release) workflows. These include templates for a 'back-to-top' button, a generic confirm dialog, and specific modals for deleting namespaces (with force-delete options for public/linked namespaces), importing namespaces, and managing config items (with type validation for strings, numbers, booleans, and JSON). Additionally, new views handle grayscale-specific logic: a branch-tab view for editing and publishing grayscale branches, a master-tab view for main namespace operations, a gray-release-rules modal for defining IP/label-based targeting, and a merge-and-publish modal for finalizing grayscale releases. An environment selector and entry point components are also introduced to support navigation and cluster selection.
apollo-portal/src/main/resources/static/views/component · high confidence
New admin service REST API controllers for configuration management
The Apollo admin service now exposes a comprehensive set of new REST controllers in the \com.ctrip.framework.apollo.adminservice.controller\ package, providing the backend API endpoints for managing the full configuration hierarchy. These include \AccessKeyController\ for application access key lifecycle management, \AppController\ for application CRUD operations (including auto-provisioning of access keys), \AppNamespaceController\ for managing application-level namespaces, \ClusterController\ for cluster management, \CommitController\ for viewing configuration change history, \ItemController\ for granular item creation, updates, and deletions, \ItemSetController\ for batch item updates, \NamespaceBranchController\ for gray release branch operations, \NamespaceController\ for namespace management and item-based search, and \InstanceConfigController\ for retrieving instance-specific configuration states. This establishes the core API surface for the admin service.
apollo-adminservice/src/main/java/com/ctrip/framework/apollo/adminservice/controller · high confidence
New assembly-mode configuration for Apollo Biz
The apollo-biz module now includes dedicated Spring Boot configuration classes for the 'assembly' profile. ApolloBizConfig enables auto-configuration and component scanning for the biz package, while ApolloBizAssemblyConfiguration provides a primary DataSourceProperties bean wired to the 'spring.config-datasource' prefix, allowing the service to operate with an externally configured database when running in assembly mode.
apollo-biz/src/main/java/com/ctrip/framework/apollo/biz · high confidence
New bash scripts for Apollo Open API automation
Added \openapi.sh\ and \openapi-usage-example.sh\ to the \scripts/openapi/bash\ directory. The library script provides bash functions to interact with the Apollo Open API (covering clusters, namespaces, items, and releases) via curl, while the example script demonstrates how to configure environment variables and execute common operations like creating and updating configuration items.
scripts/openapi/bash · high confidence
New business object models for portal configuration and user management
The Apollo Portal now includes a set of new business object (BO) classes in the \entity.bo\ package to structure internal data handling. These additions include \ConfigBO\ for representing namespace configurations, \ItemBO\ for tracking individual configuration item changes (added, modified, deleted), \NamespaceBO\ for namespace metadata and visibility controls, \ReleaseBO\ and \ReleaseHistoryBO\ for release details and history, \Email\ for email notification structures, \KVEntity\ for key-value pairs, and \UserInfo\ for user account details. These models provide the underlying data structures required for upcoming features such as configuration export/import, user management, and email notifications.
apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/entity/bo · high confidence
New config diff, history, and sync UI pages
The Apollo portal now includes dedicated static HTML templates for comparing configuration differences across clusters, viewing release history with rollback capabilities, and synchronizing configuration items between clusters. These new views provide users with enhanced visibility into configuration changes, allowing them to inspect diffs in both table and text modes, review past releases with change details, and selectively sync configuration keys to other environments.
apollo-portal/src/main/resources/static/config · high confidence
New configuration export, import, and user favorite capabilities
The Apollo Portal now supports exporting and importing configuration data, allowing administrators to back up or migrate settings for specific applications or entire environments via ZIP files. Additionally, users can now mark applications as favorites to quickly access their most-used projects, with the ability to reorder and manage these favorites directly within the portal.
apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/service · high confidence
New constants for access key modes, release operations, and server versioning
This change introduces several new constant interfaces and classes in the apollo-common module to support granular release operations and configuration management. Specifically, it adds AccessKeyMode to define FILTER and OBSERVER states, NamespaceBranchStatus for tracking branch lifecycle (DELETED, ACTIVE, MERGED), and ReleaseOperation to enumerate various release actions including NORMAL\_RELEASE, ROLLBACK, GRAY\_RELEASE, and their associated merge/abandon states. It also introduces ReleaseOperationContext keys for tracking branch and rule metadata during releases, GsonType definitions for serializing configuration and release rule data, and ApolloServer to expose the implementation version. These constants provide the foundational data structures for the new gray release and access key observation features.
apollo-common/src/main/java/com/ctrip/framework/apollo/common/constants · high confidence
New database profile configurations and application defaults
This change introduces dedicated configuration files for H2, MySQL, and PostgreSQL databases, allowing users to configure database settings via profiles without rebuilding the project. It also adds a new application.yaml with default settings for JPA, Tomcat, and management endpoints, along with a Spring Boot banner file.
apollo-common/src/main/resources · high confidence
New email notification builders for config releases, rollbacks, and gray releases
The portal now includes dedicated email builder components for different release scenarios: normal config publishes, rollbacks, full (merge) releases, and gray releases. These builders generate release notification emails with subjects and bodies tailored to the specific operation type, reusing a common base for shared fields (app ID, environment, operator, release time, etc.) while adding scenario-specific details like gray release rule IPs or rollback diffs. Users will receive more context-rich and operation-specific email notifications when configurations are published, rolled back, or released via gray/full strategies.
apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/component/emailbuilder · high confidence
New filters for portal user session validation and user access token authentication
The portal now includes three new servlet filters to enhance OpenAPI security and session handling. PortalUserSessionFilter validates portal user sessions for OpenAPI requests, redirecting expired sessions to the login page for auth/ldap modes or returning 401 for OIDC modes, while allowing authenticated users direct access. UserTokenAuthenticationFilter authenticates OpenAPI requests using portal-managed user access tokens (Bearer tokens), enforcing per-token rate limits and storing authentication context. UserTypeResolverFilter determines the current user type (user token, consumer, portal user, or anonymous) to support unified permission verification logic across the application.
apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/filter · high confidence
New namespace management and configuration editing directives
The Apollo portal now includes new AngularJS directives for managing namespaces and editing configuration items. Users can delete namespaces with permission checks and usage validation, import namespaces via file upload, and view diffs between configuration versions. The item modal directive supports creating and updating configuration items with validation for numbers and JSON, while the namespace panel directive provides the interface for managing branches, gray releases, and instance views.
apollo-portal/src/main/resources/static/scripts/directive · high confidence
New persistence models for user access tokens and audit logging
The portal now includes new entity classes to support user-managed access tokens and their associated audit trails. The \UserToken\ entity stores token details such as name, hash, scopes, rate limits, and expiration, while \UserTokenAudit\ records mutating OpenAPI requests authenticated by these tokens. These models enable the portal to manage user access tokens and track their usage for security and compliance purposes.
apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/entity/po · high confidence
New portal UI controllers for access keys, admin user tokens, app creation, audit logs, and config export
The Apollo Portal adds several new frontend controller modules to support recently introduced capabilities. AccessKeyController enables per-environment management (create, remove, enable, disable) of access keys for applications. AdminUserTokenController provides root users with a dashboard to list, filter, view details, revoke, and delete admin user tokens. CreateAppController (AppController) updates the application creation flow to require organization selection and respects the manage-app-master role limit setting. AuditLogMenuController and AuditLogTraceDetailController introduce a searchable audit log list and a detailed trace view with a span-based tree and data-influence entity navigation. ConfigExportController adds UI for exporting and importing configurations across environments and specific app/cluster paths, including conflict handling. ClusterController and DeleteAppClusterNamespaceController provide interfaces for creating clusters and deleting apps, clusters, and namespaces. BackTopController adds a scroll-to-top button to the dashboard.
apollo-portal/src/main/resources/static/scripts/controller · high confidence
New portal UI pages for app creation, cluster management, and audit logging
The Apollo Portal now includes dedicated frontend views for creating applications (app.html), managing clusters (cluster.html), and viewing audit logs (audit\_log\_menu.html, audit\_log\_trace\_detail.html). Users can create new apps with organization, app ID, name, owner, and admin details; define clusters with environment selections; and inspect system audit trails with search, date filtering, and detailed trace views showing field-level changes. These pages are part of the broader portal interface unification effort.
apollo-portal/src/main/resources/static · high confidence
New portal model classes for namespace operations and validation
The portal now includes a new set of model classes in the \entity.model\ package to support namespace creation, release, synchronization, and text editing workflows. Specifically, \NamespaceCreationModel\, \NamespaceReleaseModel\, \NamespaceSyncModel\, and \NamespaceTextModel\ provide structured data containers for these operations, while \NamespaceGrayDelReleaseModel\ extends release handling to support gray deletion of keys. A new \Verifiable\ interface and \AppModel\ (with validation constraints on fields like \appId\ and \orgId\) are also introduced to enforce data integrity and validation logic within the portal layer.
apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/entity/model · high confidence
New raw config file API and incremental config sync support
The Config Service now exposes a new \/configfiles\ endpoint that allows clients to retrieve configuration content directly as plain properties, JSON, YAML, or XML files, bypassing the standard Apollo JSON format. Additionally, the existing \/configs\ endpoint has been enhanced to support incremental configuration synchronization; when enabled, it returns only the specific configuration changes (additions, updates, deletions) since the client's last known release key, reducing payload size and improving efficiency for clients with large configuration sets.
apollo-configservice/src/main/java/com/ctrip/framework/apollo/configservice/controller · high confidence
New role management controllers for cluster, namespace, and system roles
The Apollo portal now includes dedicated Angular controllers for managing permissions at three new granular levels: Cluster, Namespace, and System. The new ClusterNamespaceRoleController allows administrators to assign and revoke 'ReleaseNamespacesInCluster' and 'ModifyNamespacesInCluster' roles to specific users within a given environment and cluster. The NamespaceRoleController extends this capability to the namespace level, supporting role assignments that can be scoped to specific environments or applied globally across all environments for a namespace. Additionally, the SystemRoleController introduces system-level roles, enabling root users to grant 'Create Application' permissions to users and manage 'App Master' assignment rights for specific applications. These controllers handle the UI logic for selecting users, confirming actions, and displaying success or error messages via the existing permission service infrastructure.
apollo-portal/src/main/resources/static/scripts/controller/role · high confidence
New utility classes for access key handling, instance config auditing, and namespace management
The config service introduces four new utility components in the \util\ package to support enhanced security and operational capabilities. \AccessKeyUtil\ centralizes logic for extracting app IDs from various request paths (configs, config files, notifications) and building request signatures, enabling stricter access key authentication. \InstanceConfigAuditUtil\ implements an asynchronous auditing mechanism that tracks instance configuration changes, optimizes database writes by caching release keys and skipping recent updates, and records release delivery times. \NamespaceUtil\ provides helpers to normalize namespace names and strip file extensions, while \WatchKeysUtil\ assembles the specific watch keys clients use for long-polling config changes, including support for public namespaces.
apollo-configservice/src/main/java/com/ctrip/framework/apollo/configservice/util · high confidence
New utility classes for config change building, JPA entity management, and release key generation
This change introduces four new utility classes in the apollo-biz module to support release and configuration management. ConfigChangeContentBuilder provides a builder pattern for assembling configuration change content (creates, updates, deletes) while cloning JPA entities to prevent unintended database writes during session persistence. EntityManagerUtil offers a controlled way to close JPA EntityManagers, specifically for async requests where Spring does not automatically close them. ReleaseKeyGenerator and ReleaseMessageKeyGenerator handle the generation and parsing of unique keys for releases and release messages, using formats like timestamp+appId+cluster+namespace and delimited strings respectively.
apollo-biz/src/main/java/com/ctrip/framework/apollo/biz/utils · high confidence
New utility classes for config file handling, namespace syntax validation, and user token auditing
The portal now includes several new utility classes in the \util\ package to support configuration export/import, namespace management, and user token operations. \ConfigFileUtils\ and \ConfigToFileUtils\ provide helpers for parsing and generating config file names and paths, while \NamespaceBOUtils\ converts namespace business objects into file content. \NamespaceTextSyntaxChecker\ adds fast, non-authoritative syntax validation for namespace text shared by Portal WebAPI and OpenAPI controllers. \RelativeDateFormat\ formats dates into relative strings (e.g., "2 hours ago"). \RoleUtils\ builds and extracts role names and target IDs for application and namespace permissions. Finally, \UserTokenAuditUtil\ asynchronously records audit rows for mutating OpenAPI requests made with user tokens, and \UserTokenAuthUtil\ stores and retrieves user tokens from the HTTP request context.
apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/util · high confidence
New utility classes for validation, data transformation, and request handling
The apollo-common module introduces a suite of new utility classes to standardize and improve core operations. InputValidator enforces stricter naming rules for clusters and namespaces, while NamespaceContentSyntaxValidator ensures JSON and YAML configuration files are strictly well-formed, preventing parsing errors. BeanUtils provides efficient object mapping and list-to-map transformations, and GrayReleaseRuleItemTransformer simplifies serialization for gray release rules. Additionally, RequestPrecondition centralizes argument validation, WebUtils standardizes client IP extraction, UniqueKeyGenerator creates unique identifiers, and ExceptionUtils formats HTTP error details for better debugging.
apollo-common/src/main/java/com/ctrip/framework/apollo/common/utils · high confidence
New value objects for portal configuration and authorization
The Apollo portal now includes a set of new value objects in the \entity.vo\ package to support enhanced configuration and authorization features. These include \SystemInfo\ and \EnvironmentInfo\ for exposing system and environment metadata, \PageSetting\ to control UI behaviors like private namespace creation, and \Organization\ for app organizational data. Additionally, several classes (\AppRolesAssignedUsers\, \NamespaceRolesAssignedUsers\, \ClusterNamespaceRolesAssignedUsers\, \NamespaceEnvRolesAssignedUsers\) are introduced to manage user permissions and role assignments at the app, namespace, and cluster levels. Supporting objects like \NamespaceIdentifier\, \ItemInfo\, \ItemDiffs\, \Change\, and \ReleaseCompareResult\ facilitate namespace identification, item tracking, and release comparison logic.
apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/entity/vo · high confidence
OIDC authentication now supports configurable user identity claims and local user provisioning
The Apollo Portal now allows administrators to configure which OIDC/JWT claim is used as the user identity (userId) and display name via the new \OidcExtendProperties\. When a custom claim is configured but missing or blank in the token, login is rejected to prevent duplicate local accounts. Upon successful authentication, the portal automatically creates or updates a local user record with the resolved identity and display name. Additionally, client registrations using the \client\_credentials\ grant type are now excluded from the available OIDC providers to prevent inappropriate usage in interactive flows.
apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/spi/oidc · high confidence
Architecture
New API client layer for Apollo Admin Service communication
The portal now uses a new \api\ package containing \AdminServiceAPI\ and its nested service classes (Health, App, Namespace, Item) to handle all HTTP interactions with the Apollo Admin Service. These classes wrap the \RetryableRestTemplate\ to provide structured, typed access to endpoints for managing apps, namespaces, and configuration items, and integrate audit logging via \@ApolloAuditLog\ annotations for remote operations.
apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/api · high confidence
Behavioural changes
Admin service configuration restructured with new discovery profiles and audit logging
The apollo-adminservice resource configuration has been reorganized to support multiple service discovery mechanisms and new operational features. Users can now choose between Eureka, Consul, Zookeeper, Nacos, or database-based service discovery by activating the corresponding profile (e.g., \consul-discovery\, \zookeeper-discovery\, \database-discovery\). The default configuration enables the \github\ profile with MySQL and turns on audit logging by default (\apollo.audit.log.enabled = true\). Additionally, the service now supports graceful shutdown and configures logging to write to \/opt/logs/apollo-adminservice.log\ by default, with console output controlled via the \LOG\_APPENDERS\ environment variable.
apollo-adminservice/src/main/resources · high confidence
AdminService migration to Spring Boot 3 with explicit servlet initialization and access control
The AdminService has been refactored to run on Spring Boot 3, introducing a new \AdminServiceApplication\ entry point and a \ServletInitializer\ to support both embedded and traditional WAR deployments. A new \AdminServiceAutoConfiguration\ explicitly registers the \AdminServiceAuthenticationFilter\ for specific API paths (such as \/apollo/audit/\\, \/apps/\\, and \/namespaces/\*\), ensuring that access control is applied only to the intended endpoints. Additionally, a dedicated \AdminServiceHealthIndicator\ has been added to monitor service health by verifying connectivity to the underlying app service.
apollo-adminservice/src/main/java/com/ctrip/framework/apollo/adminservice · high confidence
Apollo Config Service configuration files restructured for multi-discovery support
The configuration resources for the Apollo Config Service have been reorganized to support multiple service discovery mechanisms and simplified logging. New profile-specific property files have been added for Consul, Nacos, Zookeeper, custom-defined, and database-based discovery, allowing users to enable their preferred registry without modifying core settings. The main application configuration now groups the 'github' profile with MySQL by default and provides commented examples for activating other discovery profiles. Additionally, logging has been standardized to write to /opt/logs/ by default, with a new apollo-configservice.conf file and updated logback.xml to control console versus file appenders via the LOG\_APPENDERS environment variable.
apollo-configservice/src/main/resources · high confidence
Apollo Portal configuration files restructured and standardized
The Apollo Portal resource directory has been reorganized to provide a cleaner, more modular configuration structure. New default configuration files have been introduced, including \apollo-env.properties\ for environment metadata endpoints, \apollo-portal.conf\ for service mode and logging paths, and \portal.properties\ for basic application settings like port 8070. Database connectivity is now handled via \application-github.properties\ using environment variables. Sample configuration files for LDAP (Active Directory, ApacheDS, OpenLDAP) and OIDC have been added to simplify identity provider integration. Additionally, \application.yml\ and \application.properties\ now include settings for JDBC session storage, CSRF protection via SameSite cookies, and audit logging, while \logback.xml\ has been updated to support flexible log appender configuration.
apollo-portal/src/main/resources · high confidence
Apollo Portal frontend services migrated to OpenAPI v1
The Apollo Portal frontend JavaScript services (including AccessKey, App, AuditLog, Cluster, Config, Consumer, Env, Export, Favorite, Instance, and NamespaceBranch services) have been rewritten to communicate with the backend via the OpenAPI v1 endpoints (e.g., /openapi/v1/...). This change replaces the previous internal API contract with a standardized OpenAPI interface, affecting how the portal fetches, creates, updates, and deletes configuration data, manages access keys, handles audit logs, and performs namespace operations.
apollo-portal/src/main/resources/static/scripts/services · high confidence
Apollo biz service layer refactored to constructor injection and audit logging
The service classes in the apollo-biz module (including AccessKeyService, AdminService, AppNamespaceService, AppService, AuditService, BizDBPropertySource, ClusterService, CommitService, InstanceService, ItemService, ItemSetService, and NamespaceBranchService) have been refactored to use constructor-based dependency injection instead of field injection. Additionally, these services now integrate with the AuditService to record create, update, and delete operations, and enforce item count limits for namespaces.
apollo-biz/src/main/java/com/ctrip/framework/apollo/biz/service · high confidence
Audit log UI styling and common style foundation
The portal's visual presentation is updated with the addition of a dedicated audit-log.css file, which styles the audit log interface including the 'not enabled' prompt, menu, search bar, and data tables, alongside a new common-style.css that establishes base layout, typography, and component styles for the application.
apollo-portal/src/main/resources/static/styles · high confidence
Centralized configuration management for Apollo server limits and timeouts
The Apollo server now uses a new \BizConfig\ component to centralize and manage operational settings. This change introduces configurable limits for configuration item key and value lengths, as well as namespace and item counts, allowing administrators to enforce constraints on configuration sizes. It also standardizes timeout handling for long-polling connections and defines intervals for scanning and rebuilding caches for app namespaces, access keys, and release messages, ensuring consistent behavior across the service.
apollo-biz/src/main/java/com/ctrip/framework/apollo/biz/config · high confidence
ConfigService now supports configurable embedded Eureka security and modernized Spring Boot integration
The ConfigService module has been refactored to support Spring Boot 3/4 conventions, introducing a new \ConfigServerEurekaServerConfigure\ class that allows operators to enable HTTP Basic authentication for the embedded Eureka server via the \apollo.eureka.server.security.enabled\ property. This change adds a security filter chain protecting Eureka endpoints and configures an in-memory user for role-based access when security is active. Additionally, the application entry point and auto-configuration have been updated to use constructor injection, exclude default user details auto-configuration, and register a \ClientAuthenticationFilter\ for config and notification endpoints, ensuring that access key authentication is enforced on these paths.
apollo-configservice/src/main/java/com/ctrip/framework/apollo/configservice · high confidence
Configured HTTP firewall to allow URL-encoded slashes in meta service
The Apollo meta service now includes a configuration class that registers a custom HttpFirewall bean. This change allows the service to accept HTTP requests containing URL-encoded slashes, which were previously blocked by the default Spring Security firewall behavior.
apollo-configservice/src/main/java/com/ctrip/framework/apollo/metaservice · high confidence
Configures Spring Security firewall to return 400 Bad Request for denied requests
The Apollo Common module now includes a configuration class that registers a custom request rejected handler. When Spring Security's firewall rejects a request, the system will now respond with an HTTP 400 (Bad Request) status code instead of the default behavior, providing clearer feedback to clients regarding invalid requests.
apollo-common/src/main/java/com/ctrip/framework/apollo/common · high confidence
Consumer API request and response models now support rate limiting and user management permissions
The portal's consumer-facing value objects have been updated to include fields for rate limiting and user management capabilities. \ConsumerCreateRequestVO\ now accepts \rateLimitEnabled\ and \rateLimit\ parameters, as well as \allowManageUsers\, allowing consumers to configure these settings when creating or updating their API access. \ConsumerInfo\ exposes the current \rateLimit\ value and the \allowManageUsers\ permission status, enabling users to see their current rate limit configuration and whether they have permission to manage other users via the OpenAPI.
apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/entity/vo/consumer · high confidence
Enforce stronger password policies for user accounts
The Apollo portal now validates user passwords against stricter rules: passwords must be 8–20 characters long and contain at least one letter and one number. Additionally, passwords are rejected if they contain commonly used or predictable sequences (such as consecutive letters/numbers or regular patterns), with the list of disallowed fragments configurable via the portal configuration. This change introduces the \AuthUserPasswordChecker\ component, the \UserPasswordChecker\ interface, and the \CheckResult\ model to support this validation logic.
apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/util/checker · high confidence
Event-driven propagation of app and namespace lifecycle changes across environments
The portal now uses Spring ApplicationEvents to synchronize app and namespace creation, deletion, and information updates across all active environments. New event classes (AppCreationEvent, AppDeletionEvent, AppInfoChangedEvent, AppNamespaceCreationEvent, AppNamespaceDeletionEvent) are dispatched when these resources change, and dedicated listeners (CreationListener, DeletionListener, AppInfoChangedListener) receive them to invoke the AdminServiceAPI for the corresponding create, delete, or update operations in each environment. Additionally, a ConfigPublishListener reacts to ConfigPublishEvent to asynchronously send release notifications via email, message queue, and webhooks, supporting normal, gray, rollback, and merge release types.
apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/listener · high confidence
Frontend validation rules and utility scripts updated
The Apollo Portal's static scripts have been updated to enforce new input constraints and add utility functions. Validation rules now limit AppId to 64 characters, appName to 128, clusterName and namespaceName to 32, and item/release comments to 256 characters. A new AppUtil service includes a hasDuplicateKeys function to detect duplicate JSON keys, preventing silent data loss during parsing. Additional utilities include IPv4 validation, parameter parsing, and date formatting helpers.
apollo-portal/src/main/resources/static/scripts · high confidence
Introduce Spring Security-based user management and authentication in Apollo Portal
The Apollo Portal now includes a new Spring Security integration layer for user management and authentication. This change adds a delegating password encoder factory that supports multiple hashing algorithms (including BCrypt, Argon2, and others) and handles legacy password formats for backward compatibility. It introduces a Spring Security-aware user service that manages user creation, updates, and search operations using the new password encoding, and a user info holder that retrieves the current user context from the Spring Security authentication principal. This enables the portal to leverage Spring Security's standard authentication mechanisms while maintaining compatibility with existing user data.
apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/spi/springsecurity · high confidence
Introduce caching for access keys, app namespaces, and release messages
The config service now uses dedicated cached services (AccessKeyServiceWithCache, AppNamespaceServiceWithCache, ReleaseMessageServiceWithCache) to manage access keys, app namespaces, and release messages. These services load data from the database on startup and periodically scan for new or updated records, keeping an in-memory cache synchronized. This change improves performance by reducing database queries for frequently accessed configuration data and ensures consistent access to the latest configuration state.
apollo-configservice/src/main/java/com/ctrip/framework/apollo/configservice/service · high confidence
Introduce unified Apollo Assembly configuration and service discovery profiles
The apollo-assembly module now ships with a new set of resource files that consolidate the server configuration. A new \application-database-discovery.properties\ profile enables Apollo's native service registry and discovery (replacing Eureka/Zookeeper/Consul for this mode) with configurable heartbeat and health-check intervals. The \application-github.properties\ file provides a self-contained, embedded H2 database setup for the config and portal services, including H2 console access (restricted to local access by default) and embedded SQL schema initialization. The main \application.yml\ and \application.properties\ files configure the assembly to use these profiles, enable graceful shutdown, set session storage to none, and explicitly disable external service discovery mechanisms (Consul, Zookeeper, Eureka) by default, while also enabling the audit log feature.
apollo-assembly/src/main/resources · high confidence
Legacy portal WebAPI controllers marked deprecated in favor of OpenAPI
The controllers in the portal's legacy WebAPI package (AccessKey, App, Cluster, Commit, ConfigsExport, ConfigsImport, Consumer, Env, Favorite, GlobalSearch, Instance, and Item) are now annotated as @Deprecated. This signals that the portal UI has migrated to the /openapi/v1 endpoints, and these legacy REST endpoints are retained solely for backward compatibility. Users should transition their integrations to the OpenAPI v1 endpoints.
apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/controller · high confidence
Manual migration scripts to physically purge retained release history
A new manual migration suite in \scripts/sql/migration/release-history-retention\ allows administrators to repair and physically delete soft-deleted \Release\ and \ReleaseHistory\ rows that were previously retained by the old cleanup behavior. The four-step process (precheck, restore, precheck, purge) ensures that only rows belonging to the current active \Namespace\ incarnation are removed, safely restoring any releases still referenced by active release histories or gray release rules before purging the rest in batches of 1,000 rows.
scripts/sql · high confidence
Migrate Apollo repository layer to Spring Data JPA
The data access layer in the Apollo business module has been rewritten to use Spring Data JPA interfaces. All repository classes in the \apollo-biz\ package (such as \AppRepository\, \NamespaceRepository\, \ItemRepository\, and \ReleaseRepository\) now extend \JpaRepository\ and utilize Spring Data query derivation and JPQL for database operations, replacing the previous implementation.
apollo-biz/src/main/java/com/ctrip/framework/apollo/biz/repository · high confidence
Migrate portal OpenAPI controllers to v1 with unified permission validation
The Apollo Portal OpenAPI endpoints have been migrated to the v1 controller structure under the \com.ctrip.framework.apollo.openapi.v1.controller\ package. This change introduces new controller implementations for managing access keys, applications, clusters, environments, instances, configuration items, namespace branches, and namespaces. These controllers implement the corresponding OpenAPI management interfaces and enforce access control using a new \UnifiedPermissionValidator\ component, replacing previous permission-checking logic. The migration ensures consistent audit logging via \@ApolloAuditLog\ annotations and aligns the OpenAPI behavior with the portal's internal permission model.
apollo-portal/src/main/java/com/ctrip/framework/apollo/openapi/v1 · high confidence
Namespace configuration locking prevents concurrent edits
The admin service now enforces exclusive access to namespace configurations during modifications. A new \PreAcquireNamespaceLock\ annotation and corresponding AOP aspects (\NamespaceAcquireLockAspect\, \NamespaceUnlockAspect\) ensure that only one user can modify a namespace at a time. The system acquires a database lock before changes (create, update, delete) and releases it only if the configuration has been reverted to its last released state (redo operation), preventing conflicting edits and ensuring data integrity.
apollo-adminservice/src/main/java/com/ctrip/framework/apollo/adminservice/aop · high confidence
New ApolloInfoController and updated web configuration
The ApolloInfoController now exposes /apollo/net, /apollo/server, and /apollo/version endpoints to return network, server, and version information respectively. The GlobalDefaultExceptionHandler has been updated to include the root cause in error messages. WebMvcConfig now sets HTML mime type to UTF-8 and adjusts cache control for static resources.
apollo-common/src/main/java/com/ctrip/framework/apollo/common/controller · high confidence
New Spring Security configuration for Apollo Biz auth module
The Apollo Biz module now includes a new WebSecurityConfig class that configures HTTP basic authentication, disables CSRF protection, and allows same-origin frame options. It also retains legacy in-memory user details (user/apollo) for backward compatibility with older clients, despite being marked as useless for current functionality.
apollo-biz/src/main/java/com/ctrip/framework/apollo/biz/auth · high confidence
New common navigation and footer components with admin tools and SSO heartbeat
The Apollo Portal now uses new common layout components for the navigation bar and footer. The navigation bar includes a language switcher (English/Simplified Chinese), a Help link, and a user menu with logout and token management. For administrators, a new 'Admin Tools' dropdown provides direct access to user management, system roles, server configuration, app/cluster/namespace deletion, system info, config export, audit logs, and global value search. Non-admin users see a simplified 'Non-Admin Tools' menu with user management and config export. The footer displays the 2024 copyright and a GitHub link, and includes a hidden iframe for SSO session heartbeat maintenance.
apollo-portal/src/main/resources/static/views/common · high confidence
New config management UI controllers for Apollo Portal
The Apollo Portal config interface has been refactored into dedicated AngularJS controllers to improve modularity and user experience. The new ConfigBaseInfoController handles application overview, including missing environment/namespace detection and visited app tracking. ConfigNamespaceController manages the namespace list, item editing, and rollback operations. DiffConfigController and SyncConfigController provide new capabilities to compare configuration differences across clusters and selectively synchronize items between them. ReleaseHistoryController manages the release history view, supporting both diff and full configuration views while handling permissions and text-namespace constraints.
apollo-portal/src/main/resources/static/scripts/controller/config · high confidence
New consumer permission validator for OpenAPI
The Apollo OpenAPI now uses a dedicated ConsumerPermissionValidator to enforce access control for consumer tokens. This component grants modify and release namespace permissions automatically if the consumer already has create namespace permission, and it allows consumer tokens to manage users and create applications when the corresponding permissions are assigned, while explicitly preventing super-admin status and unsupported operations.
apollo-portal/src/main/java/com/ctrip/framework/apollo/openapi/auth · high confidence
New portal configuration class and JSON-based Spring session serialization
The portal now includes a centralized \PortalConfig\ class that manages runtime settings such as supported environments, meta servers, connection timeouts, and a new \configView.memberOnly.envs\ option to restrict config visibility to team members. Additionally, \SpringSessionConfig\ has been introduced to switch Spring session serialization to JSON mode, ensuring compatibility with newer Spring Security versions by registering security-specific Jackson modules.
apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/component/config · high confidence
New startup and shutdown scripts for Apollo Admin Service
The apollo-adminservice now uses new shell scripts (startup.sh and shutdown.sh) to manage the service lifecycle. These scripts allow users to configure the log directory, server port, and context path via environment variables, support running in Docker mode, and include logic to check for port conflicts and verify the service is healthy before completing startup. The shutdown script ensures graceful termination by waiting for the process to exit within a timeout period.
apollo-adminservice/src/main/scripts · high confidence
New startup and shutdown scripts for Apollo Config Service
The apollo-configservice now uses new startup.sh and shutdown.sh scripts to manage the service lifecycle. The startup script supports configurable logging directories, server ports, and context paths via environment variables, and automatically adjusts JVM garbage collection options based on the detected Java version (supporting JDK 9+ log formats). It also includes checks to prevent starting if the port is already in use by another process and ensures the service is healthy before completing startup. The shutdown script provides a graceful shutdown mechanism by reading the PID file, sending SIGTERM, and waiting for the process to exit with a timeout, falling back to killing processes matching the service pattern if the PID file is missing or stale.
apollo-configservice/src/main/scripts · high confidence
New startup and shutdown scripts for Apollo Portal
The Apollo Portal now uses new \startup.sh\ and \shutdown.sh\ scripts to manage the service lifecycle. The startup script externalizes configuration via environment variables (e.g., \SERVER\_PORT\, \LOG\_DIR\, \JAVA\_OPTS\), supports JDK 9+ GC logging, checks for port conflicts before starting, and handles Docker-specific foreground execution. The shutdown script ensures graceful termination by waiting for the process to exit within a timeout period.
apollo-portal/src/main/scripts · high confidence
Portal OpenAPI service layer migrated to generated contracts
The portal's OpenAPI server-side implementation has been refactored to use a new set of service interfaces and implementations (e.g., \AccessKeyOpenApiService\, \AppOpenApiService\, \ItemOpenApiService\) backed by generated OpenAPI model contracts. This change standardizes the data transfer objects and service signatures for managing apps, namespaces, items, permissions, and access keys, ensuring the portal's internal logic aligns with the external OpenAPI specification.
apollo-portal/src/main/java/com/ctrip/framework/apollo/openapi/server · high confidence
Refactored HTTP exception hierarchy to support string templates and HTTP status codes
The exception classes in the \apollo-common\ module have been refactored to use a new base class, \AbstractApolloHttpException\, which supports message string templates (e.g., \"item not found for itemId:%s"\) and explicitly exposes the associated \HttpStatus\. Specific exceptions like \BadRequestException\, \NotFoundException\, and \ServiceException\ now automatically set their respective HTTP status codes (BAD\_REQUEST, NOT\_FOUND, INTERNAL\_SERVER\_ERROR) and utilize the new templating constructor, allowing for more consistent and parameterized error messages across the application.
apollo-common/src/main/java/com/ctrip/framework/apollo/common/exception · high confidence
Refactored config service with cache-aware loading and incremental sync support
The config service in apollo-configservice has been refactored to introduce a new \AbstractConfigService\ base class and a \ConfigServiceWithCache\ implementation that uses Guava caches for configuration lookups. This change adds case-insensitive matching for cache keys when the \configServiceCacheKeyIgnoreCase\ configuration is enabled, fixing potential cache misses due to case sensitivity. Additionally, a new \IncrementalSyncService\ interface and \DefaultIncrementalSyncService\ implementation have been added to support incremental configuration synchronization, allowing clients to receive only the changes (added, modified, deleted keys) since their last known release key rather than the full configuration.
apollo-configservice/src/main/java/com/ctrip/framework/apollo/configservice/service/config · high confidence
Refactored entity model to support soft deletes and audit logging
The entity classes in the common module have been updated to implement a soft-delete pattern, where deleting an entity sets an IsDeleted flag and a DeletedAt timestamp rather than removing the row from the database. This change introduces a BaseEntity superclass that manages these fields and audit metadata (created/modified by and times), and applies Hibernate SQL restrictions to automatically filter out deleted records. Additionally, the entities now integrate with the Apollo audit log system via annotations to track data influence, and input validation constraints have been added to fields like App name and AppId to ensure data integrity.
apollo-common/src/main/java/com/ctrip/framework/apollo/common/entity · high confidence
Renamed H2 initialization script to prevent incorrect loading in quick start mode
The H2 database initialization script has been renamed from init.h2.sql to portaldb.init.h2.sql. This change ensures that the correct schema and seed data are loaded during quick start mode, preventing potential conflicts or errors caused by loading the wrong initialization file.
apollo-portal/src/main/resources/jpa · high confidence
Repository layer refactored to support soft deletes and unified permission queries
The repository layer in the Apollo Portal has been restructured to introduce soft-delete capabilities across core entities (App, AppNamespace, Favorite, Permission, Role, RolePermission, and UserRole) and to centralize permission lookup logic. New repository interfaces define batch soft-delete operations that mark records as deleted rather than removing them, and the PermissionRepository now provides specific queries to retrieve user and consumer permissions by joining UserRole and RolePermission tables. This change supports the broader permission management and soft-delete design updates, ensuring that access control checks and role-based data filtering operate on logically deleted records appropriately.
apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/repository · high confidence
Unified permission validation and audit logging for the Apollo Portal
The portal now enforces a unified permission validation layer that delegates checks to specific validators based on the authentication source (user, user token, or consumer), ensuring consistent access control across all operations. This change introduces environment name normalization in permission checks to prevent bypasses and adds a member-only configuration view setting for environments. Additionally, audit logging is enabled for the portal's query APIs, restricted to super admins, and the portal's HTTP client is now configured with connection pooling and timeouts via a dedicated factory.
apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/component · high confidence
Unified startup entry point for Apollo services
A new \ApolloApplication\ class has been introduced in the \com.ctrip.framework.apollo.assembly\ package to serve as the single entry point for launching the Apollo server. This class orchestrates the startup of the ConfigService, AdminService, and Portal components within a shared Spring Boot context, excluding specific auto-configurations for data sources, JPA, and Eureka to optimize the assembly build.
apollo-assembly/src/main/java · high confidence
Updated H2 initialization script with new server configuration defaults
The H2 database initialization script (configdb.init.h2.sql) has been updated to include new default entries for the ServerConfig table. Specifically, it now initializes the 'config-service.incremental.change.enabled' setting to false, alongside existing configurations for Eureka URLs, namespace locking, and key/value length limits. This change ensures that the incremental configuration synchronization feature is disabled by default in fresh H2 database setups.
apollo-configservice/src/main/resources/jpa · high confidence
Fixes
Relaxed URL character validation for Open API connectors
The Open API module now allows special characters (including \<, \>, \[, \], \\, ^, \`, {, \|, }) in URL paths and query parameters. This change prevents 400 Bad Request errors when API keys or parameters contain these previously restricted characters, ensuring smoother integration for users with complex key formats.
apollo-portal/src/main/java/com/ctrip/framework/apollo/openapi · high confidence
Test coverage
Add test resources for Apollo Portal; Added SQL cleanup script for test database teardown; Added SQL fixtures for Open API consumer authorization tests; Added SQL fixtures for config service integration tests; Added SQL fixtures for controller integration tests; Added SQL test fixtures for Apollo business logic; Added SQL test fixtures for permission service scenarios; Added integration tests for Apollo Config Service controllers; Added integration tests for Apollo repository layer; Added local one-click start application for testing; Added service-layer tests for Apollo Portal; Added static tests for JSON duplicate-key detection, non-properties namespace revocation, and text modal display; Added test configuration and local application entry point for apollo-configservice; Added test configuration resources for local environment; Added test coverage for Apollo Admin Service; Added test coverage for Apollo biz service layer; Added test data for AppNamespace service; Added test data for admin service access control scenarios; Added test for OffsetDateTime serialization in HttpMessageConverterConfiguration; Added test for OpenAppDTO user info enrichment; Added test infrastructure and unit tests for Apollo Portal; Added test infrastructure for authorization scenarios; Added test resource configuration and sample data for apollo-configservice; Added test resources for Apollo AdminService; Added test resources for Apollo biz module; Added tests for ClientAuthenticationFilter; Added tests for ConditionalOnProfile and ConditionalOnMissingProfile annotations; Added tests for ConsumerAuthenticationFilter; Added tests for PortalConfig environment alias normalization; Added tests for config service auto-configuration and graceful shutdown settings; Added tests for config service caching, case-insensitive keys, and incremental sync; Added tests for configurable OIDC username claim resolution; Added tests for database-backed service registry and discovery; Added tests for portal authentication and user-type resolution filters; Added tests for portal environment and meta server configuration; Added unit and integration tests for Apollo Portal controller endpoints; Added unit and integration tests for OpenAPI consumer services; Added unit and integration tests for OpenAPI v1 controller and service layers; Added unit and integration tests for role initialization and permission services; Added unit tests for BadRequestException and NotFoundException; Added unit tests for BizConfig configuration properties; Added unit tests for ConfigChangeContentBuilder and ReleaseKeyGenerator; Added unit tests for FileTextResolver and PropertyResolver; Added unit tests for GrayReleaseRulesHolder; Added unit tests for ItemInfoDTO and SearchResponseEntity; Added unit tests for JpaMapFieldJsonConverter; Added unit tests for PortalConfig property retrieval; Added unit tests for cached service classes; Added unit tests for config service controllers; Added unit tests for config service utility classes; Added unit tests for message sending and scanning components; Added unit tests for meta-service discovery and controller components; Added unit tests for portal authentication filter configuration and LDAP user service; Added unit tests for portal permission and HTTP client components; Added unit tests for portal utility classes; Added unit tests for the Apollo Audit Log implementation; Added unit tests for wrapper components; New E2E test infrastructure for Portal UI and external discovery; New test infrastructure and mock utilities for Apollo biz module.
Dependencies
Apollo 3.0 baseline: Spring Boot 4.1, Jakarta EE, and audit logging
The project has been upgraded to a Spring Boot 4.1.1 baseline (with Spring Cloud 2025.1.3), requiring Java 17 and introducing Jakarta EE APIs (e.g., \jakarta.xml.bind-api\, \jakarta.activation-api\, \jakarta.mail\) across the AdminService, ConfigService, and Portal. The Portal now uses the OpenAPI Generator to produce Spring interfaces from the Apollo OpenAPI spec (v0.3.12) and adds Spring Session (Core, Redis, JDBC) for shared sessions. A new Apollo Audit module (annotation, API, implementation, and Spring Boot starter) is added to the build, and the Portal integrates it alongside OAuth2 client/resource-server support. The assembly module now bundles ConfigService, AdminService, and Portal, copying SQL profiles for H2 and MySQL. E2E testing for the Portal is introduced via Playwright (v1.58.2).
(dependencies) · high confidence
Updated Bootstrap vendor assets to v3.3.5
The Apollo portal now uses Bootstrap v3.3.5 for its frontend styling and icons. This update replaces the previous vendor files with the latest minified CSS (bootstrap.min.css and bootstrap-theme.min.css) and the SVG glyph icon font (glyphicons-halflings-regular.svg), ensuring the interface benefits from the latest bug fixes and styling improvements in the Bootstrap framework.
apollo-portal/src/main/resources/static/vendor/bootstrap · high confidence
Updated frontend vendor libraries for Apollo Portal
The Apollo Portal's static vendor assets have been updated to newer versions of key frontend libraries: jQuery has been upgraded to version 2.2.4, Font Awesome to 4.5.0, and the text diffing library (jsdiff) to 2.2.3. Additionally, a new clipboard.js library (v1.5.12) has been added to support copy-to-clipboard functionality in the UI.
apollo-portal/src/main/resources/static/vendor · high confidence
Housekeeping
Repository governance, CI, and documentation overhaul
The repository has been restructured with new governance and contribution guidelines (GOVERNANCE.md, CONTRIBUTING.md, CODE\_OF\_CONDUCT.md, SECURITY.md) and a formal changelog (CHANGES.md). CI automation is now managed via Mergify with approval-based merge queues, and license compliance is enforced through a new .licenserc.yaml configuration. The project also introduces a Maven wrapper (mvnw/mvnw.cmd) for consistent builds, updates .gitattributes and .gitignore for better file handling, and significantly expands the README with comprehensive documentation, screenshots, and community information.
(repo-wide) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 49 → 42 (-7.5)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 59 → 60 (+0.8)
- Architecture 100 → 95 (-4.9)
- Maturity 70 → 69 (-0.2)
- Readiness 80 → 58 (-22.0)
- Security 67 → 42 (-25.0)
- Accessibility 29 → 28 (-1.2)
Resolved (98)
- Coverage not included — suite not readable by the collector
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Duplicated block (10 lines × 2) (apollo-assembly/src/main/java/com/ctrip/framework/apollo/assembly/ApolloApplication.java)
- Duplicated block (10 lines × 2) (apollo-biz/src/main/java/com/ctrip/framework/apollo/biz/service/AppService.java)
- Duplicated block (10 lines × 2) (apollo-biz/src/main/java/com/ctrip/framework/apollo/biz/service/ItemService.java)
- Duplicated block (10 lines × 2) (apollo-build-sql-converter/src/main/java/com/ctrip/framework/apollo/build/sql/converter/ApolloSqlConverterUtil.java)
- Duplicated block (10 lines × 2) (apollo-portal/src/main/java/com/ctrip/framework/apollo/openapi/v1/controller/PortalManagementController.java)
- Duplicated block (10 lines × 2) (apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/service/ConfigsImportService.java)
- Duplicated block (10 lines × 2) (apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/spi/oidc/OidcLocalUserServiceImpl.java)
- Duplicated block (10 lines × 3) (apollo-common/src/main/java/com/ctrip/framework/apollo/common/utils/BeanUtils.java)
- Duplicated block (10 lines × 4) (apollo-biz/src/main/java/com/ctrip/framework/apollo/biz/service/NamespaceService.java)
- Duplicated block (10 lines × 4) (apollo-portal/src/main/java/com/ctrip/framework/apollo/openapi/v1/controller/ItemController.java)
- Duplicated block (11 lines × 2) (apollo-portal/src/main/java/com/ctrip/framework/apollo/openapi/server/service/ServerNamespaceManagementOpenApiService.java)
- Duplicated block (11 lines × 2) (apollo-portal/src/main/java/com/ctrip/framework/apollo/openapi/v1/controller/AppController.java)
- Duplicated block (11 lines × 2) (apollo-portal/src/main/java/com/ctrip/framework/apollo/openapi/v1/controller/PortalManagementController.java)
- Duplicated block (11 lines × 2) (apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/component/config/PortalConfig.java)
- Duplicated block (11 lines × 3) (apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/service/ConfigsImportService.java)
- Duplicated block (13 lines × 2) (apollo-adminservice/src/main/java/com/ctrip/framework/apollo/adminservice/controller/ReleaseController.java)
- Duplicated block (13 lines × 2) (apollo-portal/src/main/java/com/ctrip/framework/apollo/openapi/service/ConsumerRolePermissionService.java)
- Duplicated block (13 lines × 2) (apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/service/AppNamespaceService.java)
- …and 78 more
New (338)
- AuditLogMenuController.auditLogMenuController (cognitive 23) (apollo-portal/src/main/resources/static/scripts/controller/AuditLogMenuController.js)
- AuditLogMenuController.auditLogMenuController (cyclomatic 19) (apollo-portal/src/main/resources/static/scripts/controller/AuditLogMenuController.js)
- ClassTooLong: PortalManagementController (apollo-portal/src/main/java/com/ctrip/framework/apollo/openapi/v1/controller/PortalManagementController.java)
- ConfigBaseInfoController.ConfigBaseInfoController (cognitive 36) (apollo-portal/src/main/resources/static/scripts/controller/config/ConfigBaseInfoController.js)
- ConfigBaseInfoController.ConfigBaseInfoController (cyclomatic 39) (apollo-portal/src/main/resources/static/scripts/controller/config/ConfigBaseInfoController.js)
- ConfigNamespaceController.controller (cognitive 35) (apollo-portal/src/main/resources/static/scripts/controller/config/ConfigNamespaceController.js)
- ConfigNamespaceController.controller (cyclomatic 29) (apollo-portal/src/main/resources/static/scripts/controller/config/ConfigNamespaceController.js)
- DeleteAppClusterNamespaceController.DeleteAppClusterNamespaceController (cyclomatic 17) (apollo-portal/src/main/resources/static/scripts/controller/DeleteAppClusterNamespaceController.js)
- Dependency hygiene PARTLY measured — Maven/Gradle declarations read, no dependency graph resolved
- Documentation: contradicts the code (docs/zh/misc/apollo-benchmark.md)
- Documentation: no architecture or design documentation (docs/zh/portal/apollo-open-api-platform.md)
- Duplicated block (10 lines × 2) (apollo-biz/src/main/java/com/ctrip/framework/apollo/biz/service/AppService.java)
- Duplicated block (10 lines × 2) (apollo-build-sql-converter/src/main/java/com/ctrip/framework/apollo/build/sql/converter/ApolloSqlConverterUtil.java)
- Duplicated block (10 lines × 2) (apollo-portal/src/main/java/com/ctrip/framework/apollo/openapi/v1/controller/InstanceController.java)
- Duplicated block (10 lines × 2) (apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/service/ConfigsImportService.java)
- Duplicated block (106 lines × 2) (apollo-common/src/main/java/com/ctrip/framework/apollo/common/entity/App.java)
- Duplicated block (11 lines × 2) (apollo-portal/src/main/java/com/ctrip/framework/apollo/openapi/v1/controller/ItemController.java)
- Duplicated block (11 lines × 3) (apollo-common/src/main/java/com/ctrip/framework/apollo/common/utils/BeanUtils.java)
- Duplicated block (11–12 lines × 2) (apollo-biz/src/main/java/com/ctrip/framework/apollo/biz/service/ReleaseService.java)
- Duplicated block (11–12 lines × 3) (apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/service/ConfigsImportService.java)
- …and 318 more
Changes since last survey
- 17 commits — 13 feature/other, 4 fixes
By area
- apollo-portal/src — 8 commits
- docs/en — 3 commits
- (root) — 2 commits
- .github/workflows — 1 commit
- apollo-biz/src — 1 commit
- apollo-configservice/src — 1 commit
- docs/zh — 1 commit
Notable commits
- fix: fix(openapi): support user-token deletion of encoded keys (#5676)
- fix: fix(portal): do not update unchanged items when revoking changes (#5672)
- fix: fix(portal): preserve OpenAPI fields and optional item types (#5677)
- fix: fix: strict JSON/YAML well-formedness validation at the authoritative save path (#5660)
- change: Merge commit from fork
- change: Merge commit from fork
- change: Merge commit from fork
- change: chore: upgrade to Spring Boot 4.1.1 (#5671)
- change: ci: enable manual Portal E2E runs
- change: docs(openapi): fix Chinese API reference link rendering
- change: docs(openapi): link to the full auto-generated API reference site (#5673)
- change: docs: document User and Permission Management Open APIs (#5654)
- change: docs: use canonical OpenAPI reference domain (#5679)
- change: feat(openapi): add batch create/update/delete for namespace items (#5665)
- change: feat(portal): add formatted and raw JSON views (#5657)
- change: feat(portal): support configurable OIDC username claim for user identity (#5655)
- change: feat(portal): support revoking non-properties namespace changes (#5656)
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
apolloconfig/apollo was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 24 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit bb0725d3a42f749bbb14eb8fc12ca9700e24a932 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-ae95d6cad036.