Skip to content
CAI
Software that uses CAICheck a score

apolloconfig/apollo

41.7

Weak · 24 September 2026

49.4k

lines of production code

Java

with JavaScript

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is Apollo, a distributed configuration management platform that provides a centralized interface for managing application configurations across multiple environments. It consists of an Admin Service for configuration CRUD operations and access control, a Config Service for efficient client-side configuration retrieval and synchronization, and a Portal for web-based administration, user management, and auditing. The system supports various service discovery mechanisms, enforces strict access permissions via access keys and consumer tokens, and facilitates safe configuration changes through features like namespace locking, gray releases, and comprehensive audit logging.

How it got here

2016 — Spring Boot 3 migration and OpenAPI v1 adoption

109 changes.

The project underwent a major infrastructure upgrade, migrating the backend to Spring Boot 3 and Java 17 while introducing Jakarta EE APIs and a unified assembly module. The Apollo Portal was refactored to communicate with the backend via a new OpenAPI v1 interface, replacing legacy internal contracts and enabling standardized consumer authentication and auditing. This period also established a robust data model using Spring Data JPA, implemented soft-delete patterns, and expanded the UI with comprehensive namespace management, gray release workflows, and role-based access control.

2017–2023 — Security hardening and audit logging

47 changes.

This period focused on strengthening Apollo's security posture by integrating Spring Security for authentication, implementing granular access controls, and enforcing stricter password policies. It also introduced comprehensive audit logging capabilities and enhanced the Open Platform with rate limiting and consumer management features. Underlying infrastructure improvements included caching optimizations, incremental sync support, and database-backed service discovery.

2024–2026 — OpenAPI security and database schema management

17 changes.

This period focused on enhancing OpenAPI security by introducing user access tokens, session validation filters, and comprehensive authentication tests. It also added features for custom SQL initialization and schema conversion, alongside manual migration scripts to purge retained release history. Extensive test coverage was added for portal UI, authentication flows, and static JSON validation to ensure system stability.

Features

Add Apollo Audit Log Spring Boot Starter

Introduces a new Spring Boot starter for Apollo audit logging, providing automatic configuration for audit log services, HTTP interceptors, and AOP aspects. The starter includes two auto-configuration classes: one that enables full audit logging when \apollo.audit.log.enabled=true\ (using JPA repositories and a default operator supplier), and a no-op fallback when the property is false or missing, ensuring the application runs without audit overhead by default. It registers beans for audit log APIs, trace contexts, and controllers, and is registered via both \spring.factories\ and the Spring Boot 3 \AutoConfiguration.imports\ mechanism.

apollo-audit/apollo-audit-spring-boot-starter · high confidence

Add Spring Boot auto-configuration for database-backed service registry and discovery

This change introduces new Spring Boot auto-configuration classes (\ApolloServiceRegistryAutoConfiguration\ and \ApolloServiceDiscoveryAutoConfiguration\) that enable Apollo servers to use the database as a service registry. It adds configuration properties (\apollo.service.registry\ and \apollo.service.discovery\) to control registration and discovery, and registers beans for database-based service registry and discovery clients. The configuration also includes support for heartbeat sending, deregistration on shutdown, and periodic cleanup of unhealthy instances, allowing users to opt-in to database-backed service registration and discovery by setting the respective enabled properties.

apollo-biz/src/main/java/com/ctrip/framework/apollo/biz/registry/configuration · high confidence

Add service discovery endpoints for non-Eureka environments

The config service now exposes REST endpoints to list available Apollo instances (Config and Admin) when using non-Eureka service discovery mechanisms. A new HomePageController provides a root endpoint (/) for profiles like Kubernetes, Nacos, Consul, Zookeeper, and database discovery, while the ServiceController exposes /services/config and /services/admin to return service instances. This allows clients and dashboards to discover service locations without relying on Eureka's home page.

apollo-configservice/src/main/java/com/ctrip/framework/apollo/metaservice/controller · high confidence

Added AOP aspect to trace Spring Data repository methods

A new aspect class, RepositoryAspect, has been introduced to automatically wrap all public methods in Spring Data repository interfaces with CAT transactions. This ensures that database operations performed through Spring Data repositories are now captured in application performance monitoring traces, aiding in debugging and performance analysis.

apollo-common/src/main/java/com/ctrip/framework/apollo/common/aop · high confidence

Added AngularJS v1.4.3 vendor libraries and i18n support

The Apollo Portal now includes several new AngularJS v1.4.3 vendor libraries to support enhanced functionality, specifically adding \angular-cookies\, \angular-resource\, \angular-route\, and \angular-sanitize\. Additionally, the \angular-translate\ library (v2.18.1) and its static file loader and cookie storage modules have been added to enable internationalization (i18n) support, while \angular-toastr\ (v1.4.1) has been included to provide toast notification capabilities for user feedback.

apollo-portal/src/main/resources/static/vendor/angular · high confidence

Added Eclipse and IntelliJ Java code style profiles and license template

The build tools now include standardized code formatting configurations for Java development, providing both Eclipse (eclipse-java-google-style.xml) and IntelliJ (intellij-java-google-style.xml) profiles based on Google Java Style. These profiles enforce consistent indentation, line wrapping, and brace placement rules. Additionally, a standard Apache 2.0 license header template (apollo-license) has been added to support automated license compliance checks in the CI pipeline.

apollo-buildtools/style · high confidence

Added Maven Wrapper for consistent builds

The project now includes the Maven Wrapper (\.mvn/wrapper\), which ensures that all developers and CI systems use the exact same Maven version (3.9.16) and build tooling, eliminating environment-specific build inconsistencies.

.mvn · high confidence

Added Windows and Unix build scripts for Apollo services

New build scripts (build.bat for Windows and build.sh for Unix/Linux) have been added to the scripts directory, providing users with standardized ways to package the Apollo config-service, admin-service, and portal. These scripts automate the Maven build process, allowing users to configure database connection details and meta server URLs for different environments (dev, fat, uat, pro) before building the services with specific profiles such as 'github' and 'auth'.

scripts · high confidence

Apollo Portal adds Spring Boot servlet initializer and assembly configuration

The Apollo Portal now includes a ServletInitializer class to support deployment as a traditional WAR file in external servlet containers, alongside a new PortalAssemblyConfiguration that configures the portal's database initialization specifically for the 'assembly' profile. These changes enable users to build and deploy the portal as a standalone web application archive while maintaining the existing embedded server startup path via the new PortalApplication entry point.

apollo-portal/src/main/java/com/ctrip/framework/apollo/portal · high confidence

ConfigService now enforces Access Key authentication for client requests

A new ClientAuthenticationFilter has been added to the ConfigService to validate incoming requests using Access Keys. The filter extracts the AppId and verifies the request's timestamp (checking against a configurable tolerance) and signature against available or observable secrets. If authentication fails, the request is rejected with an Unauthorized error; if it is a pre-check, invalid attempts are logged for observability without blocking the request.

apollo-configservice/src/main/java/com/ctrip/framework/apollo/configservice/filter · high confidence

Consumer API authentication and rate limiting

The Apollo Portal now enforces authentication and rate limiting for OpenAPI consumer requests via a new ConsumerAuthenticationFilter. Requests are validated using consumer tokens, and if a rate limit is configured for the consumer, requests exceeding the limit receive a 429 Too Many Requests response. This ensures that only authorized consumers can access the API and prevents abuse through rate limiting.

apollo-portal/src/main/java/com/ctrip/framework/apollo/openapi/filter · high confidence

Custom SQL initialization for Apollo data sources

Apollo now provides a dedicated mechanism to initialize database schemas and data via SQL scripts. This change introduces \ApolloSqlInitializationProperties\ to configure script locations, platform-specific filtering, and execution modes, alongside an \ApolloDataSourceScriptDatabaseInitializerFactory\ that resolves these settings and an \ApolloDataSourceScriptDatabaseInitializer\ that performs the actual initialization. This allows users to manage database setup through Apollo's configuration rather than relying solely on default Spring Boot behavior.

apollo-common/src/main/java/com/ctrip/framework/apollo/common/datasource · high confidence

Dynamic meta server configuration via database and environment sources

The Apollo Portal now supports dynamic configuration of meta server addresses for different environments. Administrators can define meta servers in the PortalDB.ServerConfig table (via the 'apollo.portal.meta.servers' key), which takes precedence over traditional configuration methods like system properties, OS environment variables, and the apollo-env.properties file. The system automatically loads these addresses, handles multiple comma-separated servers with random load balancing, and caches the results for performance. This change allows for runtime updates to meta server configurations without restarting the portal service.

apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/environment · high confidence

Enriched DTOs now include user display names

The portal now automatically populates display names for the creator, last modifier, and owner fields on application and base DTOs. This is achieved through a new \AdditionalUserInfoEnricher\ framework that maps user IDs from DTOs (such as \AppDTO\ and \OpenAppDTO\) to their corresponding display names using a provided user info map, ensuring that lists and views show human-readable names instead of just IDs.

apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/enricher · high confidence

Introduce backend audit log module with JPA persistence and REST API

This change adds the \apollo-audit-impl\ backend implementation, providing a new audit logging capability. It introduces JPA entities (\ApolloAuditLog\, \ApolloAuditLogDataInfluence\) and a REST controller (\/apollo/audit\) to query logs, trace details, and data influences. The module includes an AOP aspect (\ApolloAuditSpanAspect\) to intercept methods annotated with \@ApolloAuditLog\ and record operations, along with a tracer context to propagate trace IDs across HTTP requests. Audit logging is controlled via the \apollo.audit.log.enabled\ property and defaults to disabled.

apollo-audit/apollo-audit-impl/src/main · high confidence

Introduce database-backed release message scanning and sending

The apollo-biz module now includes a new message infrastructure centered on DatabaseMessageSender, ReleaseMessageScanner, and associated interfaces (MessageSender, ReleaseMessageListener). DatabaseMessageSender persists release messages to the database and manages a background thread to clean up old entries, while ReleaseMessageScanner periodically polls the database for new or missing release messages and notifies registered listeners. This provides a reliable, database-driven mechanism for propagating configuration release events, replacing or supplementing previous transport mechanisms.

apollo-biz/src/main/java/com/ctrip/framework/apollo/biz/message · high confidence

Introduce database-backed service registry and comprehensive entity model

This change adds a new database-based service registry implementation, allowing Apollo to discover server instances directly from the database without relying on external service discovery tools like Eureka or Zookeeper. It introduces the \ServiceRegistry\ entity and the \DatabaseDiscoveryClient\ interface with implementations that handle instance discovery, health checks, and caching. Additionally, the \entity\ package is populated with a complete set of JPA entities (including \AccessKey\, \Audit\, \Cluster\, \Commit\, \GrayReleaseRule\, \Instance\, \Item\, \Namespace\, \Release\, etc.) and a JSON converter, establishing the foundational data model for the application's business logic.

apollo-biz/src/main/java/com/ctrip/framework/apollo/biz/entity · high confidence

Introduce default SPI implementations for portal services

The portal now includes a set of default implementations for its Service Provider Interface (SPI) contracts within the \apollo-portal\ module. This adds concrete classes for email delivery (\DefaultEmailService\), message queue publishing (\DefaultMQService\), role and permission initialization (\DefaultRoleInitializationService\, \DefaultRolePermissionService\), user management (\DefaultUserService\), and session handling (\DefaultLogoutHandler\, \DefaultSsoHeartbeatHandler\, \DefaultUserInfoHolder\). These defaults provide baseline functionality—such as sending HTML emails, managing application and namespace roles, and handling basic user lookups—ensuring the portal operates correctly out-of-the-box without requiring custom service providers.

apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/spi/defaultimpl · high confidence

Introduce refreshable configuration property sources

Added two new classes, RefreshableConfig and RefreshablePropertySource, to the common configuration module. RefreshablePropertySource extends Spring's MapPropertySource to support dynamic updates, while RefreshableConfig provides a base implementation that registers these sources and schedules a background task to refresh configuration values every 60 seconds. This enables applications to automatically pick up changes to configuration properties without requiring a restart.

apollo-common/src/main/java/com/ctrip/framework/apollo/common/config · high confidence

Introduce text-based configuration resolution for properties and files

Added the ConfigTextResolver interface and its implementations (FileTextResolver, PropertyResolver) in the portal's txtresolver component. This enables the Apollo UI to parse raw text input for properties and file namespaces, correctly handling key-value pairs, comments, blank lines, and duplicate key detection when users submit configuration changes in text mode.

apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/component/txtresolver · high confidence

Introduce user access token support in the Apollo Portal

The Apollo Portal now supports user access tokens, enabling users to authenticate via tokens rather than just passwords. This change adds the core data models and authorization structures required for this feature, including a Spring Security authentication token (\UserTokenAuthenticationToken\), request and capability value objects for token creation and management (\UserTokenCreateRequest\, \UserTokenCapability\, \UserTokenInfo\), and scope definitions (\UserTokenScope\, \UserTokenNamespaceScope\, \UserTokenOpenApiAction\) that define granular permissions for operations, apps, environments, and namespaces.

apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/auth, apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/entity/vo/usertoken · high confidence

Introduces Apollo Audit Log API and annotation interfaces

This change adds the foundational API contracts and annotation definitions for the Apollo Audit Log feature. It introduces the \@ApolloAuditLog\ annotation for marking auditable methods, along with supporting annotations like \@ApolloAuditLogDataInfluence\ and \@ApolloAuditLogDataInfluenceTable\ to specify data change context. The \apollo-audit-api\ module exposes interfaces (\ApolloAuditLogRecordApi\, \ApolloAuditLogQueryApi\) and DTOs for recording audit events, querying logs, and tracking data influences, enabling developers to integrate audit logging into their applications.

apollo-audit/apollo-audit-annotation, apollo-audit/apollo-audit-api · high confidence

Introduces ApolloEurekaClientConfig for dynamic Eureka server URL configuration

A new ApolloEurekaClientConfig component has been added to the eureka package, extending EurekaClientConfigBean to allow Eureka server service URLs to be configured via the BizConfig. This component overrides getEurekaServerServiceUrls to return URLs from the application configuration, falling back to the default behavior if none are set. It also listens for the ApplicationReadyEvent to trigger a refresh of the Eureka client scope, ensuring that changes to the Eureka server configuration are picked up dynamically at runtime.

apollo-biz/src/main/java/com/ctrip/framework/apollo/biz/eureka · high confidence

Introduces SPI-based authentication configuration for LDAP, OIDC, and Spring Security

The portal now provides a new Service Provider Interface (SPI) in the \spi.configuration\ package to allow pluggable authentication backends. This change adds configuration classes for Spring Security (\AuthConfiguration\), LDAP (\LdapProperties\, \LdapExtendProperties\), and OIDC (\OidcExtendProperties\), enabling administrators to configure user identity claims, LDAP group mappings, and display name attributes. It also includes filter registration for user token and OpenAPI authentication (\AuthFilterConfiguration\) and default service beans for email and messaging (\EmailConfiguration\, \MQConfiguration\), establishing the foundation for flexible identity management without hardcoding specific providers.

apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/spi/configuration · high confidence

Introduces case-insensitive wrappers and deferred result handling for config notifications

The config service now includes new wrapper classes in the \wrapper\ package to support case-insensitive key lookups and improved long-polling response management. \CaseInsensitiveMapWrapper\ and \CaseInsensitiveMultimapWrapper\ normalize keys to lowercase, ensuring that namespace and configuration lookups are case-insensitive. \DeferredResultWrapper\ manages Spring MVC deferred results for long-polling, handling timeouts and ensuring that original namespace names are restored in responses when necessary, which supports the broader namespace name normalization feature.

apollo-configservice/src/main/java/com/ctrip/framework/apollo/configservice/wrapper · high confidence

Introduces in-memory caching for gray release rules

Adds GrayReleaseRuleCache and GrayReleaseRulesHolder to cache gray release rules in memory, enabling faster lookups for client requests. The holder periodically scans the database and listens for release messages to keep the cache synchronized, supporting case-insensitive matching for app IDs, IPs, and labels.

apollo-biz/src/main/java/com/ctrip/framework/apollo/biz/grayReleaseRule · high confidence

Introduces pluggable service discovery implementations for meta-service

The meta-service now supports multiple service discovery backends via a new \DiscoveryService\ interface and profile-based selection. Users can enable database-based discovery via the \database-discovery\ profile, use Spring Cloud-compatible registries (Consul, Zookeeper, Nacos) via the \consul-discovery\, \zookeeper-discovery\, or \nacos-discovery\ profiles, or bypass registry lookups entirely by providing direct URLs via configuration when using the \kubernetes\ or \custom-defined-discovery\ profiles. The default Eureka-based discovery remains active when none of these specific profiles are enabled.

apollo-configservice/src/main/java/com/ctrip/framework/apollo/metaservice/service · high confidence

Namespace-level role management UI added

A new 'role.html' page has been added to the namespace section of the Apollo Portal, providing a user interface for managing permissions at the namespace level. This page allows authorized users to assign 'ModifyNamespace' and 'ReleaseNamespace' roles to specific users, with the ability to scope these permissions to all environments or individual environments. The interface supports i18n and integrates with existing user selection and permission services.

apollo-portal/src/main/resources/static/namespace · high confidence

New Access Key and Cluster Management UI pages

The Apollo Portal adds two new static HTML pages to the client-side application: access\_key.html and manage\_cluster.html. The Access Key page provides a dedicated interface for application administrators to create, enable, disable, and remove access keys for specific environments, including UI support for 'Observed' mode. The Manage Cluster page displays a list of clusters per environment and provides a 'Grant' button to navigate to cluster-level role assignment. These pages rely on new Angular controllers (AccessKeyController, ManageClusterController) and services (AccessKeyService, ClusterService) to handle the respective backend interactions.

apollo-portal/src/main/resources/static/app · high confidence

New DTOs for access keys, gray release rules, and instance tracking

The apollo-common module introduces a suite of new data transfer objects to support expanded configuration management capabilities. AccessKeyDTO provides the data structure for managing application access keys, while GrayReleaseRuleDTO and GrayReleaseRuleItemDTO enable the definition and matching of gray release rules based on client IP and labels. InstanceDTO and InstanceConfigDTO expose instance-level configuration details, including the new releaseDeliveryTime field for tracking when configurations were delivered. Additionally, PageDTO adds pagination support for API responses, and several existing DTOs (AppDTO, ClusterDTO, NamespaceDTO) now include validation constraints for AppId and cluster/namespace formats.

apollo-common/src/main/java/com/ctrip/framework/apollo/common/dto · high confidence

New HTTP response entity models for multi-response, rich data, and search operations

Added three new classes to the \apollo-common\ HTTP package to standardize API responses: \MultiResponseEntity\ allows aggregating multiple \RichResponseEntity\ objects in a single response; \RichResponseEntity\ provides a structured wrapper for individual responses with status codes, messages, and typed bodies; and \SearchResponseEntity\ supports paginated search results by including a \hasMoreData\ flag alongside the body and status information.

apollo-common/src/main/java/com/ctrip/framework/apollo/common/http · high confidence

New JPA repositories for consumer management and auditing

The Apollo Open API layer now includes dedicated Spring Data JPA repositories to support consumer-centric features. ConsumerRepository enables lookups by application ID, while ConsumerRoleRepository manages role assignments and supports batch soft-deletion of roles. ConsumerTokenRepository handles token validation and retrieval for consumer authentication, and ConsumerAuditRepository provides the persistence layer for tracking consumer audit events.

apollo-portal/src/main/java/com/ctrip/framework/apollo/openapi/repository · high confidence

New Jenkins deployment script for Apollo applications

A new Jenkins deployment script (deploy\_jenkins.sh) has been added to the build tools. This script automates the deployment of specific Apollo applications (identified by IDs 100003171, 100003172, or 100003173) by shutting down the current instance, extracting the new release archive into a timestamped directory, and creating a symbolic link to the new version. It also includes a fix to prevent Jenkins from killing the newly started process by setting BUILD\_ID=dontKillMe before execution.

apollo-buildtools/src/main/scripts · high confidence

New LDAP authentication and user service implementation

The Apollo Portal now includes a new LDAP integration layer consisting of ApolloLdapAuthenticationProvider, FilterLdapByGroupUserSearch, and LdapUserService. The authentication provider overrides the standard Spring Security LDAP provider to map the login ID from the LDAP system rather than using the user-supplied username, ensuring consistent user identification. The user search component supports filtering users by group membership (using attributes like memberUid or member) and resolves user identities based on configurable LDAP attributes. The user service retrieves user details (ID, name, email, enabled status) from LDAP, supporting configuration for various LDAP schemas (OpenLDAP, Active Directory) via properties such as spring.ldap.base and ldap.mapping.\*.

apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/spi/ldap · high confidence

New Open Platform Consumer Management UI

The Apollo Portal now includes a dedicated interface for managing Open Platform consumers. This new page allows administrators to view a paginated list of consumers, create new consumer entries by specifying an App ID and selecting an organization, and delete existing consumers. It also supports retrieving consumer tokens by App ID and includes validation logic for optional rate limiting configurations.

apollo-portal/src/main/resources/static/scripts/controller/open · high confidence

New Open Platform consumer management UI with rate limiting and granular permissions

The Open Platform now includes a dedicated management interface (add-consumer.html, manage.html, grant-permission-modal.html) for root users to create and manage third-party consumer applications. This UI allows administrators to configure consumer capabilities, including whether the consumer can create applications or manage users, and introduces a configurable rate-limiting feature for API access. Additionally, it supports granular permission grants, allowing admins to assign specific roles (namespace or app level) and target specific environments to consumer tokens.

apollo-portal/src/main/resources/static/open · high confidence

New OpenAPI compatibility check script for v1 contract changes

A new Python script, \check\_openapi\_compatibility.py\, has been added to the \scripts/openapi\ directory to validate OpenAPI specifications against breaking changes. This tool ensures backward compatibility by detecting issues such as removed paths or HTTP methods, changed operation IDs, modified request/response schema references, and the addition of new required fields to existing schemas. It is designed to prevent accidental breaking changes to the Apollo OpenAPI v1 contract during migrations or updates.

scripts/openapi · high confidence

New OpenAPI consumer data model and audit entities

The portal now includes new JPA entity classes for OpenAPI consumers and their associated data: Consumer, ConsumerRole, ConsumerToken, and ConsumerAudit. These entities define the database schema for managing consumer identities, role assignments, authentication tokens (including rate limiting and expiration), and API usage audit logs, supporting the underlying OpenAPI consumer management and auditing capabilities.

apollo-portal/src/main/java/com/ctrip/framework/apollo/openapi/entity · high confidence

New OpenAPI consumer role and permission management services

Added ConsumerRolePermissionService and ConsumerService to the OpenAPI module, enabling programmatic management of consumer identities, tokens, and granular role-based permissions. ConsumerService handles consumer lifecycle (creation, token generation/lookup) and assigns specific namespace roles (modify/release) to consumers via API, while ConsumerRolePermissionService provides the underlying logic to verify if a consumer holds specific permissions by checking their assigned roles against the permission repository.

apollo-portal/src/main/java/com/ctrip/framework/apollo/openapi/service · high confidence

New OpenAPI utility components for consumer auditing, authentication, and model conversion

The portal now includes three new utility classes in the OpenAPI package to support the OpenAPI migration. ConsumerAuditUtil provides asynchronous, batched auditing of non-GET API requests, storing audit records in a queue for background processing. ConsumerAuthUtil centralizes the extraction and storage of consumer IDs from request tokens and context. OpenApiModelConverters supplies non-invasive conversion methods between internal portal DTOs/BOs and the generated OpenAPI model classes, ensuring consistent data formatting (such as date serialization) for API responses.

apollo-portal/src/main/java/com/ctrip/framework/apollo/openapi/util · high confidence

New SPI interfaces for extensible portal services

The Apollo portal now exposes a set of Service Provider Interface (SPI) definitions in the \com.ctrip.framework.apollo.portal.spi\ package, allowing organizations to replace default behaviors with custom implementations. New interfaces include \EmailService\ for sending notifications, \MQService\ for publishing messages to message queues, \LogoutHandler\ and \SsoHeartbeatHandler\ for customizing authentication and session management, and \UserService\ and \UserInfoHolder\ for managing user identity and lookup logic. This change enables users to integrate their own email providers, message brokers, and user directories without modifying core portal code.

apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/spi · high confidence

New SQL schema converter for MySQL and H2 profiles

The apollo-build-sql-converter module now includes a new tool that generates database schema scripts for different profiles (MySQL default, MySQL without database specification, and H2) from source templates. This converter processes SQL files to adapt them for specific database engines, such as converting MySQL-specific syntax like \ENGINE=InnoDB\ and \bit(1)\ types to H2-compatible formats, and renaming database references. It also includes tests to verify the generated SQL files are correct and consistent across profiles.

apollo-build-sql-converter · high confidence

New Spring profile-based conditional annotations

Added three new classes to the \apollo-common\ condition package: \ConditionalOnProfile\ and \ConditionalOnMissingProfile\ annotations, along with the \OnProfileCondition\ implementation. These allow developers to conditionally register Spring beans based on whether specific Spring profiles are active or inactive, extending the framework's existing conditional configuration capabilities.

apollo-common/src/main/java/com/ctrip/framework/apollo/common/condition · high confidence

New UI components for namespace management and grayscale publishing

The Apollo Portal adds a suite of new frontend components in the \views/component\ directory to support enhanced namespace and grayscale (gray release) workflows. These include templates for a 'back-to-top' button, a generic confirm dialog, and specific modals for deleting namespaces (with force-delete options for public/linked namespaces), importing namespaces, and managing config items (with type validation for strings, numbers, booleans, and JSON). Additionally, new views handle grayscale-specific logic: a branch-tab view for editing and publishing grayscale branches, a master-tab view for main namespace operations, a gray-release-rules modal for defining IP/label-based targeting, and a merge-and-publish modal for finalizing grayscale releases. An environment selector and entry point components are also introduced to support navigation and cluster selection.

apollo-portal/src/main/resources/static/views/component · high confidence

New admin service REST API controllers for configuration management

The Apollo admin service now exposes a comprehensive set of new REST controllers in the \com.ctrip.framework.apollo.adminservice.controller\ package, providing the backend API endpoints for managing the full configuration hierarchy. These include \AccessKeyController\ for application access key lifecycle management, \AppController\ for application CRUD operations (including auto-provisioning of access keys), \AppNamespaceController\ for managing application-level namespaces, \ClusterController\ for cluster management, \CommitController\ for viewing configuration change history, \ItemController\ for granular item creation, updates, and deletions, \ItemSetController\ for batch item updates, \NamespaceBranchController\ for gray release branch operations, \NamespaceController\ for namespace management and item-based search, and \InstanceConfigController\ for retrieving instance-specific configuration states. This establishes the core API surface for the admin service.

apollo-adminservice/src/main/java/com/ctrip/framework/apollo/adminservice/controller · high confidence

New assembly-mode configuration for Apollo Biz

The apollo-biz module now includes dedicated Spring Boot configuration classes for the 'assembly' profile. ApolloBizConfig enables auto-configuration and component scanning for the biz package, while ApolloBizAssemblyConfiguration provides a primary DataSourceProperties bean wired to the 'spring.config-datasource' prefix, allowing the service to operate with an externally configured database when running in assembly mode.

apollo-biz/src/main/java/com/ctrip/framework/apollo/biz · high confidence

New bash scripts for Apollo Open API automation

Added \openapi.sh\ and \openapi-usage-example.sh\ to the \scripts/openapi/bash\ directory. The library script provides bash functions to interact with the Apollo Open API (covering clusters, namespaces, items, and releases) via curl, while the example script demonstrates how to configure environment variables and execute common operations like creating and updating configuration items.

scripts/openapi/bash · high confidence

New business object models for portal configuration and user management

The Apollo Portal now includes a set of new business object (BO) classes in the \entity.bo\ package to structure internal data handling. These additions include \ConfigBO\ for representing namespace configurations, \ItemBO\ for tracking individual configuration item changes (added, modified, deleted), \NamespaceBO\ for namespace metadata and visibility controls, \ReleaseBO\ and \ReleaseHistoryBO\ for release details and history, \Email\ for email notification structures, \KVEntity\ for key-value pairs, and \UserInfo\ for user account details. These models provide the underlying data structures required for upcoming features such as configuration export/import, user management, and email notifications.

apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/entity/bo · high confidence

New config diff, history, and sync UI pages

The Apollo portal now includes dedicated static HTML templates for comparing configuration differences across clusters, viewing release history with rollback capabilities, and synchronizing configuration items between clusters. These new views provide users with enhanced visibility into configuration changes, allowing them to inspect diffs in both table and text modes, review past releases with change details, and selectively sync configuration keys to other environments.

apollo-portal/src/main/resources/static/config · high confidence

New configuration export, import, and user favorite capabilities

The Apollo Portal now supports exporting and importing configuration data, allowing administrators to back up or migrate settings for specific applications or entire environments via ZIP files. Additionally, users can now mark applications as favorites to quickly access their most-used projects, with the ability to reorder and manage these favorites directly within the portal.

apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/service · high confidence

New constants for access key modes, release operations, and server versioning

This change introduces several new constant interfaces and classes in the apollo-common module to support granular release operations and configuration management. Specifically, it adds AccessKeyMode to define FILTER and OBSERVER states, NamespaceBranchStatus for tracking branch lifecycle (DELETED, ACTIVE, MERGED), and ReleaseOperation to enumerate various release actions including NORMAL\_RELEASE, ROLLBACK, GRAY\_RELEASE, and their associated merge/abandon states. It also introduces ReleaseOperationContext keys for tracking branch and rule metadata during releases, GsonType definitions for serializing configuration and release rule data, and ApolloServer to expose the implementation version. These constants provide the foundational data structures for the new gray release and access key observation features.

apollo-common/src/main/java/com/ctrip/framework/apollo/common/constants · high confidence

New database profile configurations and application defaults

This change introduces dedicated configuration files for H2, MySQL, and PostgreSQL databases, allowing users to configure database settings via profiles without rebuilding the project. It also adds a new application.yaml with default settings for JPA, Tomcat, and management endpoints, along with a Spring Boot banner file.

apollo-common/src/main/resources · high confidence

New email notification builders for config releases, rollbacks, and gray releases

The portal now includes dedicated email builder components for different release scenarios: normal config publishes, rollbacks, full (merge) releases, and gray releases. These builders generate release notification emails with subjects and bodies tailored to the specific operation type, reusing a common base for shared fields (app ID, environment, operator, release time, etc.) while adding scenario-specific details like gray release rule IPs or rollback diffs. Users will receive more context-rich and operation-specific email notifications when configurations are published, rolled back, or released via gray/full strategies.

apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/component/emailbuilder · high confidence

New filters for portal user session validation and user access token authentication

The portal now includes three new servlet filters to enhance OpenAPI security and session handling. PortalUserSessionFilter validates portal user sessions for OpenAPI requests, redirecting expired sessions to the login page for auth/ldap modes or returning 401 for OIDC modes, while allowing authenticated users direct access. UserTokenAuthenticationFilter authenticates OpenAPI requests using portal-managed user access tokens (Bearer tokens), enforcing per-token rate limits and storing authentication context. UserTypeResolverFilter determines the current user type (user token, consumer, portal user, or anonymous) to support unified permission verification logic across the application.

apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/filter · high confidence

New namespace management and configuration editing directives

The Apollo portal now includes new AngularJS directives for managing namespaces and editing configuration items. Users can delete namespaces with permission checks and usage validation, import namespaces via file upload, and view diffs between configuration versions. The item modal directive supports creating and updating configuration items with validation for numbers and JSON, while the namespace panel directive provides the interface for managing branches, gray releases, and instance views.

apollo-portal/src/main/resources/static/scripts/directive · high confidence

New persistence models for user access tokens and audit logging

The portal now includes new entity classes to support user-managed access tokens and their associated audit trails. The \UserToken\ entity stores token details such as name, hash, scopes, rate limits, and expiration, while \UserTokenAudit\ records mutating OpenAPI requests authenticated by these tokens. These models enable the portal to manage user access tokens and track their usage for security and compliance purposes.

apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/entity/po · high confidence

New portal UI controllers for access keys, admin user tokens, app creation, audit logs, and config export

The Apollo Portal adds several new frontend controller modules to support recently introduced capabilities. AccessKeyController enables per-environment management (create, remove, enable, disable) of access keys for applications. AdminUserTokenController provides root users with a dashboard to list, filter, view details, revoke, and delete admin user tokens. CreateAppController (AppController) updates the application creation flow to require organization selection and respects the manage-app-master role limit setting. AuditLogMenuController and AuditLogTraceDetailController introduce a searchable audit log list and a detailed trace view with a span-based tree and data-influence entity navigation. ConfigExportController adds UI for exporting and importing configurations across environments and specific app/cluster paths, including conflict handling. ClusterController and DeleteAppClusterNamespaceController provide interfaces for creating clusters and deleting apps, clusters, and namespaces. BackTopController adds a scroll-to-top button to the dashboard.

apollo-portal/src/main/resources/static/scripts/controller · high confidence

New portal UI pages for app creation, cluster management, and audit logging

The Apollo Portal now includes dedicated frontend views for creating applications (app.html), managing clusters (cluster.html), and viewing audit logs (audit\_log\_menu.html, audit\_log\_trace\_detail.html). Users can create new apps with organization, app ID, name, owner, and admin details; define clusters with environment selections; and inspect system audit trails with search, date filtering, and detailed trace views showing field-level changes. These pages are part of the broader portal interface unification effort.

apollo-portal/src/main/resources/static · high confidence

New portal model classes for namespace operations and validation

The portal now includes a new set of model classes in the \entity.model\ package to support namespace creation, release, synchronization, and text editing workflows. Specifically, \NamespaceCreationModel\, \NamespaceReleaseModel\, \NamespaceSyncModel\, and \NamespaceTextModel\ provide structured data containers for these operations, while \NamespaceGrayDelReleaseModel\ extends release handling to support gray deletion of keys. A new \Verifiable\ interface and \AppModel\ (with validation constraints on fields like \appId\ and \orgId\) are also introduced to enforce data integrity and validation logic within the portal layer.

apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/entity/model · high confidence

New raw config file API and incremental config sync support

The Config Service now exposes a new \/configfiles\ endpoint that allows clients to retrieve configuration content directly as plain properties, JSON, YAML, or XML files, bypassing the standard Apollo JSON format. Additionally, the existing \/configs\ endpoint has been enhanced to support incremental configuration synchronization; when enabled, it returns only the specific configuration changes (additions, updates, deletions) since the client's last known release key, reducing payload size and improving efficiency for clients with large configuration sets.

apollo-configservice/src/main/java/com/ctrip/framework/apollo/configservice/controller · high confidence

New role management controllers for cluster, namespace, and system roles

The Apollo portal now includes dedicated Angular controllers for managing permissions at three new granular levels: Cluster, Namespace, and System. The new ClusterNamespaceRoleController allows administrators to assign and revoke 'ReleaseNamespacesInCluster' and 'ModifyNamespacesInCluster' roles to specific users within a given environment and cluster. The NamespaceRoleController extends this capability to the namespace level, supporting role assignments that can be scoped to specific environments or applied globally across all environments for a namespace. Additionally, the SystemRoleController introduces system-level roles, enabling root users to grant 'Create Application' permissions to users and manage 'App Master' assignment rights for specific applications. These controllers handle the UI logic for selecting users, confirming actions, and displaying success or error messages via the existing permission service infrastructure.

apollo-portal/src/main/resources/static/scripts/controller/role · high confidence

New utility classes for access key handling, instance config auditing, and namespace management

The config service introduces four new utility components in the \util\ package to support enhanced security and operational capabilities. \AccessKeyUtil\ centralizes logic for extracting app IDs from various request paths (configs, config files, notifications) and building request signatures, enabling stricter access key authentication. \InstanceConfigAuditUtil\ implements an asynchronous auditing mechanism that tracks instance configuration changes, optimizes database writes by caching release keys and skipping recent updates, and records release delivery times. \NamespaceUtil\ provides helpers to normalize namespace names and strip file extensions, while \WatchKeysUtil\ assembles the specific watch keys clients use for long-polling config changes, including support for public namespaces.

apollo-configservice/src/main/java/com/ctrip/framework/apollo/configservice/util · high confidence

New utility classes for config change building, JPA entity management, and release key generation

This change introduces four new utility classes in the apollo-biz module to support release and configuration management. ConfigChangeContentBuilder provides a builder pattern for assembling configuration change content (creates, updates, deletes) while cloning JPA entities to prevent unintended database writes during session persistence. EntityManagerUtil offers a controlled way to close JPA EntityManagers, specifically for async requests where Spring does not automatically close them. ReleaseKeyGenerator and ReleaseMessageKeyGenerator handle the generation and parsing of unique keys for releases and release messages, using formats like timestamp+appId+cluster+namespace and delimited strings respectively.

apollo-biz/src/main/java/com/ctrip/framework/apollo/biz/utils · high confidence

New utility classes for config file handling, namespace syntax validation, and user token auditing

The portal now includes several new utility classes in the \util\ package to support configuration export/import, namespace management, and user token operations. \ConfigFileUtils\ and \ConfigToFileUtils\ provide helpers for parsing and generating config file names and paths, while \NamespaceBOUtils\ converts namespace business objects into file content. \NamespaceTextSyntaxChecker\ adds fast, non-authoritative syntax validation for namespace text shared by Portal WebAPI and OpenAPI controllers. \RelativeDateFormat\ formats dates into relative strings (e.g., "2 hours ago"). \RoleUtils\ builds and extracts role names and target IDs for application and namespace permissions. Finally, \UserTokenAuditUtil\ asynchronously records audit rows for mutating OpenAPI requests made with user tokens, and \UserTokenAuthUtil\ stores and retrieves user tokens from the HTTP request context.

apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/util · high confidence

New utility classes for validation, data transformation, and request handling

The apollo-common module introduces a suite of new utility classes to standardize and improve core operations. InputValidator enforces stricter naming rules for clusters and namespaces, while NamespaceContentSyntaxValidator ensures JSON and YAML configuration files are strictly well-formed, preventing parsing errors. BeanUtils provides efficient object mapping and list-to-map transformations, and GrayReleaseRuleItemTransformer simplifies serialization for gray release rules. Additionally, RequestPrecondition centralizes argument validation, WebUtils standardizes client IP extraction, UniqueKeyGenerator creates unique identifiers, and ExceptionUtils formats HTTP error details for better debugging.

apollo-common/src/main/java/com/ctrip/framework/apollo/common/utils · high confidence

New value objects for portal configuration and authorization

The Apollo portal now includes a set of new value objects in the \entity.vo\ package to support enhanced configuration and authorization features. These include \SystemInfo\ and \EnvironmentInfo\ for exposing system and environment metadata, \PageSetting\ to control UI behaviors like private namespace creation, and \Organization\ for app organizational data. Additionally, several classes (\AppRolesAssignedUsers\, \NamespaceRolesAssignedUsers\, \ClusterNamespaceRolesAssignedUsers\, \NamespaceEnvRolesAssignedUsers\) are introduced to manage user permissions and role assignments at the app, namespace, and cluster levels. Supporting objects like \NamespaceIdentifier\, \ItemInfo\, \ItemDiffs\, \Change\, and \ReleaseCompareResult\ facilitate namespace identification, item tracking, and release comparison logic.

apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/entity/vo · high confidence

OIDC authentication now supports configurable user identity claims and local user provisioning

The Apollo Portal now allows administrators to configure which OIDC/JWT claim is used as the user identity (userId) and display name via the new \OidcExtendProperties\. When a custom claim is configured but missing or blank in the token, login is rejected to prevent duplicate local accounts. Upon successful authentication, the portal automatically creates or updates a local user record with the resolved identity and display name. Additionally, client registrations using the \client\_credentials\ grant type are now excluded from the available OIDC providers to prevent inappropriate usage in interactive flows.

apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/spi/oidc · high confidence

Architecture

New API client layer for Apollo Admin Service communication

The portal now uses a new \api\ package containing \AdminServiceAPI\ and its nested service classes (Health, App, Namespace, Item) to handle all HTTP interactions with the Apollo Admin Service. These classes wrap the \RetryableRestTemplate\ to provide structured, typed access to endpoints for managing apps, namespaces, and configuration items, and integrate audit logging via \@ApolloAuditLog\ annotations for remote operations.

apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/api · high confidence

Behavioural changes

Admin service configuration restructured with new discovery profiles and audit logging

The apollo-adminservice resource configuration has been reorganized to support multiple service discovery mechanisms and new operational features. Users can now choose between Eureka, Consul, Zookeeper, Nacos, or database-based service discovery by activating the corresponding profile (e.g., \consul-discovery\, \zookeeper-discovery\, \database-discovery\). The default configuration enables the \github\ profile with MySQL and turns on audit logging by default (\apollo.audit.log.enabled = true\). Additionally, the service now supports graceful shutdown and configures logging to write to \/opt/logs/apollo-adminservice.log\ by default, with console output controlled via the \LOG\_APPENDERS\ environment variable.

apollo-adminservice/src/main/resources · high confidence

AdminService migration to Spring Boot 3 with explicit servlet initialization and access control

The AdminService has been refactored to run on Spring Boot 3, introducing a new \AdminServiceApplication\ entry point and a \ServletInitializer\ to support both embedded and traditional WAR deployments. A new \AdminServiceAutoConfiguration\ explicitly registers the \AdminServiceAuthenticationFilter\ for specific API paths (such as \/apollo/audit/\\, \/apps/\\, and \/namespaces/\*\), ensuring that access control is applied only to the intended endpoints. Additionally, a dedicated \AdminServiceHealthIndicator\ has been added to monitor service health by verifying connectivity to the underlying app service.

apollo-adminservice/src/main/java/com/ctrip/framework/apollo/adminservice · high confidence

Apollo Config Service configuration files restructured for multi-discovery support

The configuration resources for the Apollo Config Service have been reorganized to support multiple service discovery mechanisms and simplified logging. New profile-specific property files have been added for Consul, Nacos, Zookeeper, custom-defined, and database-based discovery, allowing users to enable their preferred registry without modifying core settings. The main application configuration now groups the 'github' profile with MySQL by default and provides commented examples for activating other discovery profiles. Additionally, logging has been standardized to write to /opt/logs/ by default, with a new apollo-configservice.conf file and updated logback.xml to control console versus file appenders via the LOG\_APPENDERS environment variable.

apollo-configservice/src/main/resources · high confidence

Apollo Portal configuration files restructured and standardized

The Apollo Portal resource directory has been reorganized to provide a cleaner, more modular configuration structure. New default configuration files have been introduced, including \apollo-env.properties\ for environment metadata endpoints, \apollo-portal.conf\ for service mode and logging paths, and \portal.properties\ for basic application settings like port 8070. Database connectivity is now handled via \application-github.properties\ using environment variables. Sample configuration files for LDAP (Active Directory, ApacheDS, OpenLDAP) and OIDC have been added to simplify identity provider integration. Additionally, \application.yml\ and \application.properties\ now include settings for JDBC session storage, CSRF protection via SameSite cookies, and audit logging, while \logback.xml\ has been updated to support flexible log appender configuration.

apollo-portal/src/main/resources · high confidence

Apollo Portal frontend services migrated to OpenAPI v1

The Apollo Portal frontend JavaScript services (including AccessKey, App, AuditLog, Cluster, Config, Consumer, Env, Export, Favorite, Instance, and NamespaceBranch services) have been rewritten to communicate with the backend via the OpenAPI v1 endpoints (e.g., /openapi/v1/...). This change replaces the previous internal API contract with a standardized OpenAPI interface, affecting how the portal fetches, creates, updates, and deletes configuration data, manages access keys, handles audit logs, and performs namespace operations.

apollo-portal/src/main/resources/static/scripts/services · high confidence

Apollo biz service layer refactored to constructor injection and audit logging

The service classes in the apollo-biz module (including AccessKeyService, AdminService, AppNamespaceService, AppService, AuditService, BizDBPropertySource, ClusterService, CommitService, InstanceService, ItemService, ItemSetService, and NamespaceBranchService) have been refactored to use constructor-based dependency injection instead of field injection. Additionally, these services now integrate with the AuditService to record create, update, and delete operations, and enforce item count limits for namespaces.

apollo-biz/src/main/java/com/ctrip/framework/apollo/biz/service · high confidence

Audit log UI styling and common style foundation

The portal's visual presentation is updated with the addition of a dedicated audit-log.css file, which styles the audit log interface including the 'not enabled' prompt, menu, search bar, and data tables, alongside a new common-style.css that establishes base layout, typography, and component styles for the application.

apollo-portal/src/main/resources/static/styles · high confidence

Centralized configuration management for Apollo server limits and timeouts

The Apollo server now uses a new \BizConfig\ component to centralize and manage operational settings. This change introduces configurable limits for configuration item key and value lengths, as well as namespace and item counts, allowing administrators to enforce constraints on configuration sizes. It also standardizes timeout handling for long-polling connections and defines intervals for scanning and rebuilding caches for app namespaces, access keys, and release messages, ensuring consistent behavior across the service.

apollo-biz/src/main/java/com/ctrip/framework/apollo/biz/config · high confidence

ConfigService now supports configurable embedded Eureka security and modernized Spring Boot integration

The ConfigService module has been refactored to support Spring Boot 3/4 conventions, introducing a new \ConfigServerEurekaServerConfigure\ class that allows operators to enable HTTP Basic authentication for the embedded Eureka server via the \apollo.eureka.server.security.enabled\ property. This change adds a security filter chain protecting Eureka endpoints and configures an in-memory user for role-based access when security is active. Additionally, the application entry point and auto-configuration have been updated to use constructor injection, exclude default user details auto-configuration, and register a \ClientAuthenticationFilter\ for config and notification endpoints, ensuring that access key authentication is enforced on these paths.

apollo-configservice/src/main/java/com/ctrip/framework/apollo/configservice · high confidence

Configured HTTP firewall to allow URL-encoded slashes in meta service

The Apollo meta service now includes a configuration class that registers a custom HttpFirewall bean. This change allows the service to accept HTTP requests containing URL-encoded slashes, which were previously blocked by the default Spring Security firewall behavior.

apollo-configservice/src/main/java/com/ctrip/framework/apollo/metaservice · high confidence

Configures Spring Security firewall to return 400 Bad Request for denied requests

The Apollo Common module now includes a configuration class that registers a custom request rejected handler. When Spring Security's firewall rejects a request, the system will now respond with an HTTP 400 (Bad Request) status code instead of the default behavior, providing clearer feedback to clients regarding invalid requests.

apollo-common/src/main/java/com/ctrip/framework/apollo/common · high confidence

Consumer API request and response models now support rate limiting and user management permissions

The portal's consumer-facing value objects have been updated to include fields for rate limiting and user management capabilities. \ConsumerCreateRequestVO\ now accepts \rateLimitEnabled\ and \rateLimit\ parameters, as well as \allowManageUsers\, allowing consumers to configure these settings when creating or updating their API access. \ConsumerInfo\ exposes the current \rateLimit\ value and the \allowManageUsers\ permission status, enabling users to see their current rate limit configuration and whether they have permission to manage other users via the OpenAPI.

apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/entity/vo/consumer · high confidence

Enforce stronger password policies for user accounts

The Apollo portal now validates user passwords against stricter rules: passwords must be 8–20 characters long and contain at least one letter and one number. Additionally, passwords are rejected if they contain commonly used or predictable sequences (such as consecutive letters/numbers or regular patterns), with the list of disallowed fragments configurable via the portal configuration. This change introduces the \AuthUserPasswordChecker\ component, the \UserPasswordChecker\ interface, and the \CheckResult\ model to support this validation logic.

apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/util/checker · high confidence

Event-driven propagation of app and namespace lifecycle changes across environments

The portal now uses Spring ApplicationEvents to synchronize app and namespace creation, deletion, and information updates across all active environments. New event classes (AppCreationEvent, AppDeletionEvent, AppInfoChangedEvent, AppNamespaceCreationEvent, AppNamespaceDeletionEvent) are dispatched when these resources change, and dedicated listeners (CreationListener, DeletionListener, AppInfoChangedListener) receive them to invoke the AdminServiceAPI for the corresponding create, delete, or update operations in each environment. Additionally, a ConfigPublishListener reacts to ConfigPublishEvent to asynchronously send release notifications via email, message queue, and webhooks, supporting normal, gray, rollback, and merge release types.

apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/listener · high confidence

Frontend validation rules and utility scripts updated

The Apollo Portal's static scripts have been updated to enforce new input constraints and add utility functions. Validation rules now limit AppId to 64 characters, appName to 128, clusterName and namespaceName to 32, and item/release comments to 256 characters. A new AppUtil service includes a hasDuplicateKeys function to detect duplicate JSON keys, preventing silent data loss during parsing. Additional utilities include IPv4 validation, parameter parsing, and date formatting helpers.

apollo-portal/src/main/resources/static/scripts · high confidence

Introduce Spring Security-based user management and authentication in Apollo Portal

The Apollo Portal now includes a new Spring Security integration layer for user management and authentication. This change adds a delegating password encoder factory that supports multiple hashing algorithms (including BCrypt, Argon2, and others) and handles legacy password formats for backward compatibility. It introduces a Spring Security-aware user service that manages user creation, updates, and search operations using the new password encoding, and a user info holder that retrieves the current user context from the Spring Security authentication principal. This enables the portal to leverage Spring Security's standard authentication mechanisms while maintaining compatibility with existing user data.

apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/spi/springsecurity · high confidence

Introduce caching for access keys, app namespaces, and release messages

The config service now uses dedicated cached services (AccessKeyServiceWithCache, AppNamespaceServiceWithCache, ReleaseMessageServiceWithCache) to manage access keys, app namespaces, and release messages. These services load data from the database on startup and periodically scan for new or updated records, keeping an in-memory cache synchronized. This change improves performance by reducing database queries for frequently accessed configuration data and ensures consistent access to the latest configuration state.

apollo-configservice/src/main/java/com/ctrip/framework/apollo/configservice/service · high confidence

Introduce unified Apollo Assembly configuration and service discovery profiles

The apollo-assembly module now ships with a new set of resource files that consolidate the server configuration. A new \application-database-discovery.properties\ profile enables Apollo's native service registry and discovery (replacing Eureka/Zookeeper/Consul for this mode) with configurable heartbeat and health-check intervals. The \application-github.properties\ file provides a self-contained, embedded H2 database setup for the config and portal services, including H2 console access (restricted to local access by default) and embedded SQL schema initialization. The main \application.yml\ and \application.properties\ files configure the assembly to use these profiles, enable graceful shutdown, set session storage to none, and explicitly disable external service discovery mechanisms (Consul, Zookeeper, Eureka) by default, while also enabling the audit log feature.

apollo-assembly/src/main/resources · high confidence

Legacy portal WebAPI controllers marked deprecated in favor of OpenAPI

The controllers in the portal's legacy WebAPI package (AccessKey, App, Cluster, Commit, ConfigsExport, ConfigsImport, Consumer, Env, Favorite, GlobalSearch, Instance, and Item) are now annotated as @Deprecated. This signals that the portal UI has migrated to the /openapi/v1 endpoints, and these legacy REST endpoints are retained solely for backward compatibility. Users should transition their integrations to the OpenAPI v1 endpoints.

apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/controller · high confidence

Manual migration scripts to physically purge retained release history

A new manual migration suite in \scripts/sql/migration/release-history-retention\ allows administrators to repair and physically delete soft-deleted \Release\ and \ReleaseHistory\ rows that were previously retained by the old cleanup behavior. The four-step process (precheck, restore, precheck, purge) ensures that only rows belonging to the current active \Namespace\ incarnation are removed, safely restoring any releases still referenced by active release histories or gray release rules before purging the rest in batches of 1,000 rows.

scripts/sql · high confidence

Migrate Apollo repository layer to Spring Data JPA

The data access layer in the Apollo business module has been rewritten to use Spring Data JPA interfaces. All repository classes in the \apollo-biz\ package (such as \AppRepository\, \NamespaceRepository\, \ItemRepository\, and \ReleaseRepository\) now extend \JpaRepository\ and utilize Spring Data query derivation and JPQL for database operations, replacing the previous implementation.

apollo-biz/src/main/java/com/ctrip/framework/apollo/biz/repository · high confidence

Migrate portal OpenAPI controllers to v1 with unified permission validation

The Apollo Portal OpenAPI endpoints have been migrated to the v1 controller structure under the \com.ctrip.framework.apollo.openapi.v1.controller\ package. This change introduces new controller implementations for managing access keys, applications, clusters, environments, instances, configuration items, namespace branches, and namespaces. These controllers implement the corresponding OpenAPI management interfaces and enforce access control using a new \UnifiedPermissionValidator\ component, replacing previous permission-checking logic. The migration ensures consistent audit logging via \@ApolloAuditLog\ annotations and aligns the OpenAPI behavior with the portal's internal permission model.

apollo-portal/src/main/java/com/ctrip/framework/apollo/openapi/v1 · high confidence

Namespace configuration locking prevents concurrent edits

The admin service now enforces exclusive access to namespace configurations during modifications. A new \PreAcquireNamespaceLock\ annotation and corresponding AOP aspects (\NamespaceAcquireLockAspect\, \NamespaceUnlockAspect\) ensure that only one user can modify a namespace at a time. The system acquires a database lock before changes (create, update, delete) and releases it only if the configuration has been reverted to its last released state (redo operation), preventing conflicting edits and ensuring data integrity.

apollo-adminservice/src/main/java/com/ctrip/framework/apollo/adminservice/aop · high confidence

New ApolloInfoController and updated web configuration

The ApolloInfoController now exposes /apollo/net, /apollo/server, and /apollo/version endpoints to return network, server, and version information respectively. The GlobalDefaultExceptionHandler has been updated to include the root cause in error messages. WebMvcConfig now sets HTML mime type to UTF-8 and adjusts cache control for static resources.

apollo-common/src/main/java/com/ctrip/framework/apollo/common/controller · high confidence

New Spring Security configuration for Apollo Biz auth module

The Apollo Biz module now includes a new WebSecurityConfig class that configures HTTP basic authentication, disables CSRF protection, and allows same-origin frame options. It also retains legacy in-memory user details (user/apollo) for backward compatibility with older clients, despite being marked as useless for current functionality.

apollo-biz/src/main/java/com/ctrip/framework/apollo/biz/auth · high confidence

The Apollo Portal now uses new common layout components for the navigation bar and footer. The navigation bar includes a language switcher (English/Simplified Chinese), a Help link, and a user menu with logout and token management. For administrators, a new 'Admin Tools' dropdown provides direct access to user management, system roles, server configuration, app/cluster/namespace deletion, system info, config export, audit logs, and global value search. Non-admin users see a simplified 'Non-Admin Tools' menu with user management and config export. The footer displays the 2024 copyright and a GitHub link, and includes a hidden iframe for SSO session heartbeat maintenance.

apollo-portal/src/main/resources/static/views/common · high confidence

New config management UI controllers for Apollo Portal

The Apollo Portal config interface has been refactored into dedicated AngularJS controllers to improve modularity and user experience. The new ConfigBaseInfoController handles application overview, including missing environment/namespace detection and visited app tracking. ConfigNamespaceController manages the namespace list, item editing, and rollback operations. DiffConfigController and SyncConfigController provide new capabilities to compare configuration differences across clusters and selectively synchronize items between them. ReleaseHistoryController manages the release history view, supporting both diff and full configuration views while handling permissions and text-namespace constraints.

apollo-portal/src/main/resources/static/scripts/controller/config · high confidence

New consumer permission validator for OpenAPI

The Apollo OpenAPI now uses a dedicated ConsumerPermissionValidator to enforce access control for consumer tokens. This component grants modify and release namespace permissions automatically if the consumer already has create namespace permission, and it allows consumer tokens to manage users and create applications when the corresponding permissions are assigned, while explicitly preventing super-admin status and unsupported operations.

apollo-portal/src/main/java/com/ctrip/framework/apollo/openapi/auth · high confidence

New portal configuration class and JSON-based Spring session serialization

The portal now includes a centralized \PortalConfig\ class that manages runtime settings such as supported environments, meta servers, connection timeouts, and a new \configView.memberOnly.envs\ option to restrict config visibility to team members. Additionally, \SpringSessionConfig\ has been introduced to switch Spring session serialization to JSON mode, ensuring compatibility with newer Spring Security versions by registering security-specific Jackson modules.

apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/component/config · high confidence

New startup and shutdown scripts for Apollo Admin Service

The apollo-adminservice now uses new shell scripts (startup.sh and shutdown.sh) to manage the service lifecycle. These scripts allow users to configure the log directory, server port, and context path via environment variables, support running in Docker mode, and include logic to check for port conflicts and verify the service is healthy before completing startup. The shutdown script ensures graceful termination by waiting for the process to exit within a timeout period.

apollo-adminservice/src/main/scripts · high confidence

New startup and shutdown scripts for Apollo Config Service

The apollo-configservice now uses new startup.sh and shutdown.sh scripts to manage the service lifecycle. The startup script supports configurable logging directories, server ports, and context paths via environment variables, and automatically adjusts JVM garbage collection options based on the detected Java version (supporting JDK 9+ log formats). It also includes checks to prevent starting if the port is already in use by another process and ensures the service is healthy before completing startup. The shutdown script provides a graceful shutdown mechanism by reading the PID file, sending SIGTERM, and waiting for the process to exit with a timeout, falling back to killing processes matching the service pattern if the PID file is missing or stale.

apollo-configservice/src/main/scripts · high confidence

New startup and shutdown scripts for Apollo Portal

The Apollo Portal now uses new \startup.sh\ and \shutdown.sh\ scripts to manage the service lifecycle. The startup script externalizes configuration via environment variables (e.g., \SERVER\_PORT\, \LOG\_DIR\, \JAVA\_OPTS\), supports JDK 9+ GC logging, checks for port conflicts before starting, and handles Docker-specific foreground execution. The shutdown script ensures graceful termination by waiting for the process to exit within a timeout period.

apollo-portal/src/main/scripts · high confidence

Portal OpenAPI service layer migrated to generated contracts

The portal's OpenAPI server-side implementation has been refactored to use a new set of service interfaces and implementations (e.g., \AccessKeyOpenApiService\, \AppOpenApiService\, \ItemOpenApiService\) backed by generated OpenAPI model contracts. This change standardizes the data transfer objects and service signatures for managing apps, namespaces, items, permissions, and access keys, ensuring the portal's internal logic aligns with the external OpenAPI specification.

apollo-portal/src/main/java/com/ctrip/framework/apollo/openapi/server · high confidence

Refactored HTTP exception hierarchy to support string templates and HTTP status codes

The exception classes in the \apollo-common\ module have been refactored to use a new base class, \AbstractApolloHttpException\, which supports message string templates (e.g., \"item not found for itemId:%s"\) and explicitly exposes the associated \HttpStatus\. Specific exceptions like \BadRequestException\, \NotFoundException\, and \ServiceException\ now automatically set their respective HTTP status codes (BAD\_REQUEST, NOT\_FOUND, INTERNAL\_SERVER\_ERROR) and utilize the new templating constructor, allowing for more consistent and parameterized error messages across the application.

apollo-common/src/main/java/com/ctrip/framework/apollo/common/exception · high confidence

Refactored config service with cache-aware loading and incremental sync support

The config service in apollo-configservice has been refactored to introduce a new \AbstractConfigService\ base class and a \ConfigServiceWithCache\ implementation that uses Guava caches for configuration lookups. This change adds case-insensitive matching for cache keys when the \configServiceCacheKeyIgnoreCase\ configuration is enabled, fixing potential cache misses due to case sensitivity. Additionally, a new \IncrementalSyncService\ interface and \DefaultIncrementalSyncService\ implementation have been added to support incremental configuration synchronization, allowing clients to receive only the changes (added, modified, deleted keys) since their last known release key rather than the full configuration.

apollo-configservice/src/main/java/com/ctrip/framework/apollo/configservice/service/config · high confidence

Refactored entity model to support soft deletes and audit logging

The entity classes in the common module have been updated to implement a soft-delete pattern, where deleting an entity sets an IsDeleted flag and a DeletedAt timestamp rather than removing the row from the database. This change introduces a BaseEntity superclass that manages these fields and audit metadata (created/modified by and times), and applies Hibernate SQL restrictions to automatically filter out deleted records. Additionally, the entities now integrate with the Apollo audit log system via annotations to track data influence, and input validation constraints have been added to fields like App name and AppId to ensure data integrity.

apollo-common/src/main/java/com/ctrip/framework/apollo/common/entity · high confidence

Renamed H2 initialization script to prevent incorrect loading in quick start mode

The H2 database initialization script has been renamed from init.h2.sql to portaldb.init.h2.sql. This change ensures that the correct schema and seed data are loaded during quick start mode, preventing potential conflicts or errors caused by loading the wrong initialization file.

apollo-portal/src/main/resources/jpa · high confidence

Repository layer refactored to support soft deletes and unified permission queries

The repository layer in the Apollo Portal has been restructured to introduce soft-delete capabilities across core entities (App, AppNamespace, Favorite, Permission, Role, RolePermission, and UserRole) and to centralize permission lookup logic. New repository interfaces define batch soft-delete operations that mark records as deleted rather than removing them, and the PermissionRepository now provides specific queries to retrieve user and consumer permissions by joining UserRole and RolePermission tables. This change supports the broader permission management and soft-delete design updates, ensuring that access control checks and role-based data filtering operate on logically deleted records appropriately.

apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/repository · high confidence

Unified permission validation and audit logging for the Apollo Portal

The portal now enforces a unified permission validation layer that delegates checks to specific validators based on the authentication source (user, user token, or consumer), ensuring consistent access control across all operations. This change introduces environment name normalization in permission checks to prevent bypasses and adds a member-only configuration view setting for environments. Additionally, audit logging is enabled for the portal's query APIs, restricted to super admins, and the portal's HTTP client is now configured with connection pooling and timeouts via a dedicated factory.

apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/component · high confidence

Unified startup entry point for Apollo services

A new \ApolloApplication\ class has been introduced in the \com.ctrip.framework.apollo.assembly\ package to serve as the single entry point for launching the Apollo server. This class orchestrates the startup of the ConfigService, AdminService, and Portal components within a shared Spring Boot context, excluding specific auto-configurations for data sources, JPA, and Eureka to optimize the assembly build.

apollo-assembly/src/main/java · high confidence

Updated H2 initialization script with new server configuration defaults

The H2 database initialization script (configdb.init.h2.sql) has been updated to include new default entries for the ServerConfig table. Specifically, it now initializes the 'config-service.incremental.change.enabled' setting to false, alongside existing configurations for Eureka URLs, namespace locking, and key/value length limits. This change ensures that the incremental configuration synchronization feature is disabled by default in fresh H2 database setups.

apollo-configservice/src/main/resources/jpa · high confidence

Fixes

Relaxed URL character validation for Open API connectors

The Open API module now allows special characters (including \<, \>, \[, \], \\, ^, \`, {, \|, }) in URL paths and query parameters. This change prevents 400 Bad Request errors when API keys or parameters contain these previously restricted characters, ensuring smoother integration for users with complex key formats.

apollo-portal/src/main/java/com/ctrip/framework/apollo/openapi · high confidence

Test coverage

Add test resources for Apollo Portal; Added SQL cleanup script for test database teardown; Added SQL fixtures for Open API consumer authorization tests; Added SQL fixtures for config service integration tests; Added SQL fixtures for controller integration tests; Added SQL test fixtures for Apollo business logic; Added SQL test fixtures for permission service scenarios; Added integration tests for Apollo Config Service controllers; Added integration tests for Apollo repository layer; Added local one-click start application for testing; Added service-layer tests for Apollo Portal; Added static tests for JSON duplicate-key detection, non-properties namespace revocation, and text modal display; Added test configuration and local application entry point for apollo-configservice; Added test configuration resources for local environment; Added test coverage for Apollo Admin Service; Added test coverage for Apollo biz service layer; Added test data for AppNamespace service; Added test data for admin service access control scenarios; Added test for OffsetDateTime serialization in HttpMessageConverterConfiguration; Added test for OpenAppDTO user info enrichment; Added test infrastructure and unit tests for Apollo Portal; Added test infrastructure for authorization scenarios; Added test resource configuration and sample data for apollo-configservice; Added test resources for Apollo AdminService; Added test resources for Apollo biz module; Added tests for ClientAuthenticationFilter; Added tests for ConditionalOnProfile and ConditionalOnMissingProfile annotations; Added tests for ConsumerAuthenticationFilter; Added tests for PortalConfig environment alias normalization; Added tests for config service auto-configuration and graceful shutdown settings; Added tests for config service caching, case-insensitive keys, and incremental sync; Added tests for configurable OIDC username claim resolution; Added tests for database-backed service registry and discovery; Added tests for portal authentication and user-type resolution filters; Added tests for portal environment and meta server configuration; Added unit and integration tests for Apollo Portal controller endpoints; Added unit and integration tests for OpenAPI consumer services; Added unit and integration tests for OpenAPI v1 controller and service layers; Added unit and integration tests for role initialization and permission services; Added unit tests for BadRequestException and NotFoundException; Added unit tests for BizConfig configuration properties; Added unit tests for ConfigChangeContentBuilder and ReleaseKeyGenerator; Added unit tests for FileTextResolver and PropertyResolver; Added unit tests for GrayReleaseRulesHolder; Added unit tests for ItemInfoDTO and SearchResponseEntity; Added unit tests for JpaMapFieldJsonConverter; Added unit tests for PortalConfig property retrieval; Added unit tests for cached service classes; Added unit tests for config service controllers; Added unit tests for config service utility classes; Added unit tests for message sending and scanning components; Added unit tests for meta-service discovery and controller components; Added unit tests for portal authentication filter configuration and LDAP user service; Added unit tests for portal permission and HTTP client components; Added unit tests for portal utility classes; Added unit tests for the Apollo Audit Log implementation; Added unit tests for wrapper components; New E2E test infrastructure for Portal UI and external discovery; New test infrastructure and mock utilities for Apollo biz module.

Dependencies

Apollo 3.0 baseline: Spring Boot 4.1, Jakarta EE, and audit logging

The project has been upgraded to a Spring Boot 4.1.1 baseline (with Spring Cloud 2025.1.3), requiring Java 17 and introducing Jakarta EE APIs (e.g., \jakarta.xml.bind-api\, \jakarta.activation-api\, \jakarta.mail\) across the AdminService, ConfigService, and Portal. The Portal now uses the OpenAPI Generator to produce Spring interfaces from the Apollo OpenAPI spec (v0.3.12) and adds Spring Session (Core, Redis, JDBC) for shared sessions. A new Apollo Audit module (annotation, API, implementation, and Spring Boot starter) is added to the build, and the Portal integrates it alongside OAuth2 client/resource-server support. The assembly module now bundles ConfigService, AdminService, and Portal, copying SQL profiles for H2 and MySQL. E2E testing for the Portal is introduced via Playwright (v1.58.2).

(dependencies) · high confidence

Updated Bootstrap vendor assets to v3.3.5

The Apollo portal now uses Bootstrap v3.3.5 for its frontend styling and icons. This update replaces the previous vendor files with the latest minified CSS (bootstrap.min.css and bootstrap-theme.min.css) and the SVG glyph icon font (glyphicons-halflings-regular.svg), ensuring the interface benefits from the latest bug fixes and styling improvements in the Bootstrap framework.

apollo-portal/src/main/resources/static/vendor/bootstrap · high confidence

Updated frontend vendor libraries for Apollo Portal

The Apollo Portal's static vendor assets have been updated to newer versions of key frontend libraries: jQuery has been upgraded to version 2.2.4, Font Awesome to 4.5.0, and the text diffing library (jsdiff) to 2.2.3. Additionally, a new clipboard.js library (v1.5.12) has been added to support copy-to-clipboard functionality in the UI.

apollo-portal/src/main/resources/static/vendor · high confidence

Housekeeping

Repository governance, CI, and documentation overhaul

The repository has been restructured with new governance and contribution guidelines (GOVERNANCE.md, CONTRIBUTING.md, CODE\_OF\_CONDUCT.md, SECURITY.md) and a formal changelog (CHANGES.md). CI automation is now managed via Mergify with approval-based merge queues, and license compliance is enforced through a new .licenserc.yaml configuration. The project also introduces a Maven wrapper (mvnw/mvnw.cmd) for consistent builds, updates .gitattributes and .gitignore for better file handling, and significantly expands the README with comprehensive documentation, screenshots, and community information.

(repo-wide) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 49 → 42 (-7.5)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 59 → 60 (+0.8)
  • Architecture 100 → 95 (-4.9)
  • Maturity 70 → 69 (-0.2)
  • Readiness 80 → 58 (-22.0)
  • Security 67 → 42 (-25.0)
  • Accessibility 29 → 28 (-1.2)

Resolved (98)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (10 lines × 2) (apollo-assembly/src/main/java/com/ctrip/framework/apollo/assembly/ApolloApplication.java)
  • Duplicated block (10 lines × 2) (apollo-biz/src/main/java/com/ctrip/framework/apollo/biz/service/AppService.java)
  • Duplicated block (10 lines × 2) (apollo-biz/src/main/java/com/ctrip/framework/apollo/biz/service/ItemService.java)
  • Duplicated block (10 lines × 2) (apollo-build-sql-converter/src/main/java/com/ctrip/framework/apollo/build/sql/converter/ApolloSqlConverterUtil.java)
  • Duplicated block (10 lines × 2) (apollo-portal/src/main/java/com/ctrip/framework/apollo/openapi/v1/controller/PortalManagementController.java)
  • Duplicated block (10 lines × 2) (apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/service/ConfigsImportService.java)
  • Duplicated block (10 lines × 2) (apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/spi/oidc/OidcLocalUserServiceImpl.java)
  • Duplicated block (10 lines × 3) (apollo-common/src/main/java/com/ctrip/framework/apollo/common/utils/BeanUtils.java)
  • Duplicated block (10 lines × 4) (apollo-biz/src/main/java/com/ctrip/framework/apollo/biz/service/NamespaceService.java)
  • Duplicated block (10 lines × 4) (apollo-portal/src/main/java/com/ctrip/framework/apollo/openapi/v1/controller/ItemController.java)
  • Duplicated block (11 lines × 2) (apollo-portal/src/main/java/com/ctrip/framework/apollo/openapi/server/service/ServerNamespaceManagementOpenApiService.java)
  • Duplicated block (11 lines × 2) (apollo-portal/src/main/java/com/ctrip/framework/apollo/openapi/v1/controller/AppController.java)
  • Duplicated block (11 lines × 2) (apollo-portal/src/main/java/com/ctrip/framework/apollo/openapi/v1/controller/PortalManagementController.java)
  • Duplicated block (11 lines × 2) (apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/component/config/PortalConfig.java)
  • Duplicated block (11 lines × 3) (apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/service/ConfigsImportService.java)
  • Duplicated block (13 lines × 2) (apollo-adminservice/src/main/java/com/ctrip/framework/apollo/adminservice/controller/ReleaseController.java)
  • Duplicated block (13 lines × 2) (apollo-portal/src/main/java/com/ctrip/framework/apollo/openapi/service/ConsumerRolePermissionService.java)
  • Duplicated block (13 lines × 2) (apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/service/AppNamespaceService.java)
  • …and 78 more

New (338)

  • AuditLogMenuController.auditLogMenuController (cognitive 23) (apollo-portal/src/main/resources/static/scripts/controller/AuditLogMenuController.js)
  • AuditLogMenuController.auditLogMenuController (cyclomatic 19) (apollo-portal/src/main/resources/static/scripts/controller/AuditLogMenuController.js)
  • ClassTooLong: PortalManagementController (apollo-portal/src/main/java/com/ctrip/framework/apollo/openapi/v1/controller/PortalManagementController.java)
  • ConfigBaseInfoController.ConfigBaseInfoController (cognitive 36) (apollo-portal/src/main/resources/static/scripts/controller/config/ConfigBaseInfoController.js)
  • ConfigBaseInfoController.ConfigBaseInfoController (cyclomatic 39) (apollo-portal/src/main/resources/static/scripts/controller/config/ConfigBaseInfoController.js)
  • ConfigNamespaceController.controller (cognitive 35) (apollo-portal/src/main/resources/static/scripts/controller/config/ConfigNamespaceController.js)
  • ConfigNamespaceController.controller (cyclomatic 29) (apollo-portal/src/main/resources/static/scripts/controller/config/ConfigNamespaceController.js)
  • DeleteAppClusterNamespaceController.DeleteAppClusterNamespaceController (cyclomatic 17) (apollo-portal/src/main/resources/static/scripts/controller/DeleteAppClusterNamespaceController.js)
  • Dependency hygiene PARTLY measured — Maven/Gradle declarations read, no dependency graph resolved
  • Documentation: contradicts the code (docs/zh/misc/apollo-benchmark.md)
  • Documentation: no architecture or design documentation (docs/zh/portal/apollo-open-api-platform.md)
  • Duplicated block (10 lines × 2) (apollo-biz/src/main/java/com/ctrip/framework/apollo/biz/service/AppService.java)
  • Duplicated block (10 lines × 2) (apollo-build-sql-converter/src/main/java/com/ctrip/framework/apollo/build/sql/converter/ApolloSqlConverterUtil.java)
  • Duplicated block (10 lines × 2) (apollo-portal/src/main/java/com/ctrip/framework/apollo/openapi/v1/controller/InstanceController.java)
  • Duplicated block (10 lines × 2) (apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/service/ConfigsImportService.java)
  • Duplicated block (106 lines × 2) (apollo-common/src/main/java/com/ctrip/framework/apollo/common/entity/App.java)
  • Duplicated block (11 lines × 2) (apollo-portal/src/main/java/com/ctrip/framework/apollo/openapi/v1/controller/ItemController.java)
  • Duplicated block (11 lines × 3) (apollo-common/src/main/java/com/ctrip/framework/apollo/common/utils/BeanUtils.java)
  • Duplicated block (11–12 lines × 2) (apollo-biz/src/main/java/com/ctrip/framework/apollo/biz/service/ReleaseService.java)
  • Duplicated block (11–12 lines × 3) (apollo-portal/src/main/java/com/ctrip/framework/apollo/portal/service/ConfigsImportService.java)
  • …and 318 more

Changes since last survey

  • 17 commits — 13 feature/other, 4 fixes

By area

  • apollo-portal/src — 8 commits
  • docs/en — 3 commits
  • (root) — 2 commits
  • .github/workflows — 1 commit
  • apollo-biz/src — 1 commit
  • apollo-configservice/src — 1 commit
  • docs/zh — 1 commit

Notable commits

  • fix: fix(openapi): support user-token deletion of encoded keys (#5676)
  • fix: fix(portal): do not update unchanged items when revoking changes (#5672)
  • fix: fix(portal): preserve OpenAPI fields and optional item types (#5677)
  • fix: fix: strict JSON/YAML well-formedness validation at the authoritative save path (#5660)
  • change: Merge commit from fork
  • change: Merge commit from fork
  • change: Merge commit from fork
  • change: chore: upgrade to Spring Boot 4.1.1 (#5671)
  • change: ci: enable manual Portal E2E runs
  • change: docs(openapi): fix Chinese API reference link rendering
  • change: docs(openapi): link to the full auto-generated API reference site (#5673)
  • change: docs: document User and Permission Management Open APIs (#5654)
  • change: docs: use canonical OpenAPI reference domain (#5679)
  • change: feat(openapi): add batch create/update/delete for namespace items (#5665)
  • change: feat(portal): add formatted and raw JSON views (#5657)
  • change: feat(portal): support configurable OIDC username claim for user identity (#5655)
  • change: feat(portal): support revoking non-properties namespace changes (#5656)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

apolloconfig/apollo was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 24 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit bb0725d3a42f749bbb14eb8fc12ca9700e24a932 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-ae95d6cad036.