Skip to content
CAI
Software that uses CAICheck a score

bondy-io/bondy

68.5

Adequate · 2 October 2026

69k

lines of production code

Erlang

primary language

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Bondy is an Erlang-based event and service mesh platform that implements the WAMP protocol for real-time messaging and RPC. It provides capabilities for bridging internal events to external systems like Kafka and email services, while also proxying external HTTP APIs as WAMP procedures. The system includes built-in features for rate limiting, multiple serialization formats, and comprehensive security authentication.

How it got here

2016–2017 — Bondy application scaffolding and configuration

10 changes.

This period focused on establishing the Bondy event and service mesh platform by replacing legacy WAMP protocol implementations with a new core application structure. Significant work involved implementing a centralized configuration system using Cuttlefish and adding comprehensive test coverage for authentication and HTTP gateway components.

2018–2022 — Broker bridge and deployment infrastructure

13 changes.

This period focused on establishing the Bondy Broker Bridge application to route WAMP events to external systems like Kafka, AWS SNS, and email providers. It also introduced comprehensive configuration management, release hooks, and hardened Docker deployment images to support these new capabilities.

2023–2025 — Core OTP library and WAMP protocol expansion

10 changes.

This period focused on establishing foundational infrastructure by introducing the bondy\_stdlib OTP application with utility modules for error handling, UUIDs, and causality tracking. It also delivered the initial release of the bondy\_wamp application, expanding WAMP protocol support with multiple serialization formats and transport mechanisms, alongside a new rate-limiting component.

2026 — CBOR encoder and RPC gateway introduction

5 changes.

This period focused on introducing two new OTP applications: bondy\_cbor, a CBOR encoder/decoder with benchmarking support, and bondy\_rpc\_gateway, which bridges WAMP RPC calls to external HTTP services. The work included implementing core encoding/decoding logic, authentication strategies, and comprehensive test suites for both components.

Features

Add bondy\_stdlib OTP library

The new bondy\_stdlib application has been added to the project, providing a shared OTP library. It is configured to require Erlang/OTP R27.3.4 or later and depends on the resulto library.

_apps/bondy\stdlib · high confidence

Add custom configuration examples for Bondy security and platform settings

The \examples/custom\_config\ directory now includes a \bondy.conf.template\ file that sets the security configuration file path and platform data directory, alongside a \security\_config.json\ file. This JSON file provides a comprehensive example of security realms, defining authentication methods (such as password, WAMP-CRA, cryptosign, and OAuth2), user accounts with credentials or authorized keys, groups, and access control sources and grants for both a production-style realm and a test realm.

_examples/custom\config · high confidence

Added bondy\_regulator OTP application for rate limiting

The new bondy\_regulator application provides a rate-limiting capability for the Bondy platform. It introduces a token-bucket algorithm implementation (bondy\_regulator\_rate\_limit) that manages request throughput using atomic counters, exposing API functions to create limits, check allowance, and wait for capacity. The app includes a standard OTP supervision tree (bondy\_regulator\_sup) to manage the rate-limiting state and is configured to depend on the resulto library.

_apps/bondy\regulator · high confidence

Added certificate generation tool compatible with OTP 24-26

A new \config/make\_certs\ script has been added to generate SSL certificates, including root and intermediate CAs, client/server certificates, and revocation lists. This tool is updated to be compatible with Erlang/OTP versions 24, 25, and 26, ensuring that development and testing environments can generate valid TLS credentials across supported runtime versions.

config · high confidence

Bondy application source files added with version 1.0.0-rc.65

The Bondy application source files have been added to the repository, establishing the core application structure for version 1.0.0-rc.65. This includes the main application definition (\bondy.app.src\) which lists dependencies such as Cowboy, Prometheus, and telemetry, as well as core modules like \bondy.erl\ for message routing and administrative HTTP handlers for health checks (\bondy\_admin\_ready\_http\_handler\) and ping endpoints. These files provide the foundational components for the Bondy event and service mesh platform.

apps/bondy/src · high confidence

Expanded WAMP protocol support with new encodings and transports

The WAMP application now supports additional serialization formats and transport mechanisms. Users can utilize CBOR and batched variants of JSON, MessagePack, BERT, and Erlang terms for more efficient or specific payload encoding needs. Additionally, the system introduces support for Server-Sent Events (SSE) and HTTP long-polling as alternative transports to the standard WebSocket connection, enabling broader compatibility with different network environments and client capabilities.

_apps/bondy\wamp/include · high confidence

Initial Fly.io deployment configuration for Bondy

Added a complete set of configuration files to deploy the Bondy application on Fly.io. This includes the \fly.toml\ app definition specifying the container image, regions, and service ports; a \bondy.conf.template\ for Erlang/Elixir runtime and cluster settings; a \security\_config.json\ defining authentication methods and access controls; and a \setup.sh\ script for environment initialization. A Makefile and README are also provided to streamline deployment, scaling, and verification tasks.

deployment/fly · high confidence

Initial project scaffolding and documentation

Added foundational repository files including a Docker ignore list, EditorConfig for consistent code formatting, the Apache 2.0 License, a Code of Conduct, and initial documentation (README, CHANGELOG, MIGRATION guide).

(repo-wide) · high confidence

Initial release of bondy\_cbor CBOR encoder/decoder

The bondy\_cbor OTP application is introduced, providing an implementation of the Concise Binary Object Representation (CBOR) data format as specified in RFC 8949. The core module exposes public API functions for encoding Erlang terms to CBOR (including a deterministic mode for sorted keys) and decoding CBOR binaries back to Erlang terms. This location also includes a comprehensive EUnit test suite validating the implementation against RFC 8949 Appendix A test vectors, as well as a benchmarking suite for comparing performance against MsgPack and Erlang's built-in JSON module.

_apps/bondy\cbor · high confidence

Initial release of bondy\_wamp OTP application

Adds the new bondy\_wamp OTP application, providing WAMP (Web Application Messaging Protocol) capabilities. The app is configured to require Erlang/OTP R27.0 or later and includes dependencies on utils (1.4.3), bert (0.2.0), app\_config (1.1.2), and msgpack (0.8.1).

_apps/bondy\wamp · high confidence

Introduce Bondy Broker Bridge for external event forwarding

The new \bondy\_broker\_bridge\ application provides a framework for forwarding WAMP events to external systems. It includes a manager that orchestrates subscriptions and a \mops\-based template engine for transforming event data. Shipped bridge implementations allow forwarding to Apache Kafka (\bondy\_kafka\_bridge\), sending SMS via AWS SNS (\bondy\_aws\_sns\_bridge\), and sending emails via SendGrid (\bondy\_sendgrid\_bridge\) and Mailgun (\bondy\_mailgun\_bridge\).

_apps/bondy\_broker\bridge/src · high confidence

Introduce bondy\_rpc\_gateway application

Added the bondy\_rpc\_gateway OTP application, which translates WAMP RPC calls into upstream HTTP requests and maps HTTP responses back to WAMP results. The app includes configuration files (rebar.config, LICENSE, .gitignore) and documentation detailing its architecture, supervision tree, and service configuration.

_apps/bondy\_rpc\gateway · high confidence

Introduction of WAMP library with CBOR and partial payload support

The new bondy\_wamp OTP library (v1.3.0) provides WAMP message encoding and decoding, adding support for the CBOR binary format alongside existing JSON, MessagePack, BERT, and Erlang terms. It introduces partial encoding and decoding capabilities for JSON and CBOR, allowing large payloads to be handled efficiently by encoding only the message control elements while preserving the rest. The library also includes configuration management for serialization options, URI validation with strictness rules, and feature flag support for capability negotiation.

_apps/bondy\wamp/src · high confidence

Introduction of the Bondy Broker Bridge application

A new application, bondy\_broker\_bridge, has been added to the system to serve as a bridge between the Bondy platform and external message brokers. This component is configured to require Erlang/OTP R27.3.4 or later and integrates several dependencies to support specific bridging capabilities: 'brod' for Kafka connectivity, 'erlcloud' for AWS SNS, and 'email' for Sendgrid and Mailgun integrations. The inclusion of this app establishes the foundational infrastructure for routing events to these external services.

_apps/bondy\_broker\bridge · high confidence

New Docker configuration files for Bondy

Added three new configuration files for the Docker deployment: sys.config, which sets up SASL, Partisan, and OS Mon settings and includes user-defined configuration; vars.config, which defines platform directory paths under /bondy; and vm.args, which configures the Erlang VM node name and distributed cookie using environment variables, and loads additional arguments generated by cuttlefish and user-defined extra arguments.

config/docker · high confidence

New Dockerfiles for Bondy with hardened runtime and explicit port exposure

The deployment directory now includes two new Dockerfiles (Dockerfile and alpine.Dockerfile) that define the build and runtime environment for Bondy. The images are built using Erlang 27.3.4 and target Debian trixie-slim or Alpine 3.20. The runtime images are hardened by removing unnecessary packages like sudo and dnsutils to reduce the CVE attack surface, and they run as a dedicated non-root 'bondy' user. The configuration explicitly exposes ports 18080 through 18086 for API, admin, WAMP, and cluster services, and mounts /bondy/etc, /bondy/data, /bondy/log, and /bondy/tmp as volumes. Environment variables for node naming and distributed cookies are set with defaults, and the entrypoint runs Bondy in the foreground.

deployment · high confidence

New RPC Gateway bridges WAMP procedures to external HTTP/REST services

The \bondy\_rpc\_gateway\ application is introduced to expose upstream HTTP APIs as WAMP procedures, allowing clients to call external services transparently. It handles authentication (with pluggable strategies like OAuth2 client-credentials and API keys via \bondy\_rpc\_gateway\_auth\_generic\), token caching, and automatic retries with exponential backoff. The gateway supports per-service configuration for timeouts, retries, and TLS settings, and includes resilient secret resolution from providers like AWS Secrets Manager to ensure services are ready before accepting calls.

_apps/bondy\_rpc\gateway/src · high confidence

New bondy\_stdlib OTP application with utility modules

The new \bondy\_stdlib\ OTP application introduces several utility modules to the platform. It provides \bondy\_humanized\ for converting lists of items into human-readable, quoted strings (e.g., for error messages), and \bondy\_itc\ implementing Interval Tree Clocks for causality tracking in dynamic distributed systems. The core \bondy\_stdlib\ module adds functional helpers like \and\_then\ and \or\_else\ for handling optional values, along with exponential backoff and jitter-based retry logic. Additionally, it includes \bondy\_stdlib\_error\ for structured error handling with typed codes and messages, and \bondy\_uuidv7\ for generating and parsing UUIDv7s based on timestamps.

_apps/bondy\stdlib/src · high confidence

New configurable Erlang VM arguments schema

A new schema file (vm\_args.schema) has been added to define and expose Erlang VM configuration options, allowing users to tune settings such as async thread stack sizes, IO poll threads, process and port limits, and CPU scheduler counts via the application's configuration interface.

schema/hidden · high confidence

New configuration files for the Bondy bridge component

This change introduces the initial configuration set for the Bondy bridge, including a comprehensive bondy.conf.template (covering startup, admin API, API gateway, and security settings), a sys.config for Partisan and OS monitoring, a vars.config defining default ports and paths, and a vm.args file for Erlang VM tuning. These files establish the baseline configuration structure for the bridge, replacing or supplementing previous ad-hoc configuration methods.

config/bridge · high confidence

New example configurations for API specs, broker bridge, OIDC, and security

Added example configuration files to demonstrate new capabilities: api\_spec.json defines a WAMP call API with OAuth2 and OIDC security defaults; broker\_bridge\_config.json configures a Kafka bridge subscription with metadata and deduplication support; oidc\_api\_spec.json provides a template for OIDC-based authentication; and security\_config.json.template sets up realm security with multiple auth methods (including cookie and OIDC RP) and user/group definitions.

examples/config · high confidence

New operational and configuration management tools

Added four new utility scripts to the \priv/tools\ directory to assist with deployment and maintenance: \console\_clean\ provides a shell interface to a running node for cleanup tasks; \db-repair.escript\ allows manual repair of specific EleveldB partitions; \replace-env-vars\ processes template files by substituting \${VARNAME}\ placeholders with actual environment variable values; and \validate-config\ ensures required configuration files like \bondy.conf\ and \vm.extra.args\ are present, automatically generating defaults or handling conflicts (such as moving duplicate config files to a \disabled\ directory) and sanitizing prohibited Erlang VM arguments.

priv/tools · high confidence

New production configuration files for Bondy release

Added three new configuration files for the production environment: sys.config defines core application settings for SASL, Partisan (including channel and peer service manager configuration), and OS Mon; vars.config establishes standard platform directory paths (bin, data, etc, lib, log, share, tmp); and vm.args configures the Erlang VM with distributed node naming and cookie settings via environment variables, while loading generated arguments from cuttlefish and user-defined extra arguments. These files collectively establish the baseline runtime configuration for the Bondy production release.

config/prod · high confidence

New release hooks for remote console, pre-start configuration, and status checks

Added three new shell scripts in the release hooks directory: \bondy\_remote\_console\ enables interactive remote shell access with configurable Erlang node names and distributed cookies; \pre\_start\ handles environment variable setup, exporting defaults for release directories and data/log/tmp paths (with hardcoded paths for Docker environments), and runs configuration validation and variable replacement before the application starts; \status\ provides a simple command to check the Bondy application status.

priv/hooks · high confidence

Removals

Removal of legacy Erlang header definitions

The \include/ramp.hrl\ file has been deleted, removing all previously defined Erlang type aliases (such as \uri()\, \id()\, \payload()\), message type constants (e.g., \HELLO\, \WELCOME\, \ERROR\), and record structures for the protocol's message types. This change eliminates the legacy header definitions from the codebase, requiring any remaining code to rely on alternative definitions or updated includes.

include · high confidence

Removal of legacy WAMP protocol implementation modules

The \src\ directory has had its core WAMP protocol implementation files deleted, including \ramp.erl\, \ramp\_app.erl\, \ramp\_id.erl\, \ramp\_packing.erl\, \ramp\_router.erl\, \ramp\_sup.erl\, and \ramp\_uri.erl\. This removes the previous session management, message packing/unpacking, ID generation, and URI validation logic from the application.

src · high confidence

Behavioural changes

2 commits (0 fixes) modifying ebin

A change to existing behaviour in ebin — 2 commits, 2 files.

ebin · medium confidence · unverified

Centralized include headers for Bondy configuration, security, and API definitions

The Bondy application now provides a unified set of Erlang header files in the \apps/bondy/include\ directory to standardize internal configuration and API contracts. These headers define core WAMP realm URIs, router/broker feature flags (such as pattern-based registration and payload passthru mode), and PlumDB table mappings for security and registry data. They also consolidate security authentication method definitions (including OAuth2, OIDC, and ticket-based auth), expose the complete set of Bondy WAMP procedure and topic URIs, and provide HTTP status code macros for the API gateway, ensuring consistent behavior across the router, dealer, and broker components.

apps/bondy/include · high confidence

Client-side rendering of Mermaid diagrams in documentation

The documentation now renders Mermaid diagrams directly in the browser using the mermaid.js library loaded from a CDN. This change adds a new JavaScript file that initializes the Mermaid library and processes code blocks marked with the 'mermaid' class to generate SVG visualizations, replacing the previous behavior where these diagrams were likely static images or required server-side processing.

doc/js · high confidence

Hardcoded Erlang VM configuration for named-node deployments

A new \vm.args\ file has been added to the \config/prod\_named\ profile, configuring the Erlang VM to use a hardcoded nodename (\bondy\) and cookie (\bondy\). This profile enforces strict distributed Erlang settings, such as disabling automatic connection and EPMD, to support deployments where node identity is fixed rather than dynamic. The configuration also sets specific VM flags for process limits, kernel polling, and async I/O, while deferring additional arguments to generated files.

_config/prod\named · high confidence

Introduction of Cuttlefish-based configuration schema

Bondy now uses a new Cuttlefish configuration schema (bondy.schema) to manage settings, replacing the previous configuration approach. This change introduces structured configuration for core components including the router, security realms, and startup behavior, while also adding dedicated schema files for new or enhanced features: Bridge Relay (bondy\_bridge\_relay.schema) for edge-to-core connections with TLS and keepalive controls, Broker Bridge (bondy\_broker\_bridge.schema) for Kafka integration, RPC Gateway (bondy\_rpc\_gateway.schema) for upstream service proxying with authentication and connection pooling, Logger (logger.schema) for detailed log handler and burst-control tuning, and OAuth2 (oauth2.schema) for token duration and grant settings. Users should review their bondy.conf files to align with the new option names and defaults, as some parameters have been renamed or reorganized.

schema · high confidence

New development configuration files for Bondy

The development environment now includes a new set of configuration files: bondy.conf.template, sys.config, vars.config, and vm.args. These files define the default settings for the Bondy application in development mode, including network ports, cluster settings, logging, and Erlang VM parameters. This change provides a structured way to configure the application for development, replacing or supplementing previous configuration methods.

config/dev · high confidence

Test coverage

Added Common Test suites for the RPC Gateway authentication and routing components; Added comprehensive test suites for WAMP encoding, message handling, and URI validation; Added property-based tests for bondy\_itc and bondy\_uuidv7; Added test environment configuration files; Expanded Common Test coverage for authentication, HTTP gateway, and CORS.

Dependencies

Added benchmarking environment for CBOR implementation

A new benchmarking project (bondy\_cbor\_bench) has been introduced to evaluate the performance of the CBOR coder. This setup includes dependencies for the Benchee benchmarking framework (v1.5.0) along with its HTML and Markdown reporters, as well as the Msgpack library (v0.8.1) for comparative analysis. The configuration is currently inactive but provides the necessary tooling to run performance tests against the bondy\_cbor application.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 72 → 68 (-4.0)
  • Rubric changed (rubric-2026.09.12 → rubric-2026.09.18) — scores are not directly comparable.

Lenses

  • Code Health 89 → 89 (+0.0)
  • Architecture 98 → 95 (-3.5)
  • Maturity 67 → 67 (+0.0)
  • Readiness 73 → 62 (-10.8)
  • Security 69 → 66 (-2.7)
  • Event-Driven 100 → 100 (+0.0)
  • Event Sourcing 100 → 100 (+0.0)

Resolved (1)

  • Coverage not measured — no coverage collector is wired up

New (19)

  • Documentation: no contributor guidance (README.md)
  • Documentation: no licence statement (README.md)
  • Documentation: no project overview (README.md)
  • High CVE: [GHSA redacted] (rebar.lock)
  • High CVE: [GHSA redacted] (rebar.lock)
  • High CVE: [GHSA redacted] (rebar.lock)
  • Medium CVE: EEF-[CVE redacted] (rebar.lock)
  • Medium CVE: [GHSA redacted] (rebar.lock)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • Off the main sequence: bondy_stdlib
  • Projects may be oversized for their cohesion

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

bondy-io/bondy was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 2 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit b3748a19ee15f7dd61740ceea109efa1d69aa9a9 — the exact code this score is about.
  • Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.