brotandgames/ciao
51.3
Adequate · 19 September 2026
3.4k
lines of production code
JavaScript
with Ruby
1
measurement over time
What this system is
Ciao is a Ruby on Rails application designed to monitor HTTP endpoints and TLS certificate expiration. It schedules regular health checks, tracks status changes, and sends notifications via email or webhooks when issues arise. The system provides a web interface for managing checks and viewing health metrics, along with administrative tools for job management and debugging.
Features
Add CheckMailer for health status and TLS certificate notifications
Users will now receive email notifications for two specific events: when a health check's status changes (e.g., from 200 to 500) and when a TLS certificate is approaching expiration. A new \CheckMailer\ class has been introduced with \change\_status\_mail\ and \tls\_expires\_mail\ actions to handle these alerts, while the base \ApplicationMailer\ has been updated to use a consistent layout string.
app/mailers · high confidence
Add Helm chart CI/CD automation scripts
New shell scripts (ci.sh and cd.sh) have been added to the scripts/chart directory to automate the validation, packaging, and deployment of the Helm chart. The CI script validates the chart using helm lint and packages it, while the CD script updates the Helm repository index and uploads the packaged chart to the specified storage backend.
scripts · high confidence
Checks interface overhaul with TLS monitoring and admin tools
The checks views have been redesigned to provide a richer user experience and new operational capabilities. The index and show pages now display TLS certificate expiration details (days until expiry) for HTTPS checks, alongside last/next contact times and a history of status changes. A new Administration page allows users to recreate scheduled background jobs and trigger immediate TLS checks, while also exposing debugging information like configuration and database pool stats. The dashboard now offers a high-level overview of check health and status code distribution. Additionally, JSON representation links have been added to the index and show views, and the UI has been modernized with improved layout, icons, and confirmation dialogs for deletions.
app/views/checks · high confidence
Health check scheduling and TLS monitoring with status change tracking
The Check model now automatically manages background jobs using Rufus::Scheduler to perform regular HTTP health checks and daily TLS certificate expiration checks for HTTPS URLs. When a check's status changes, a new StatusChange record is created to track the history, and notifications are sent for both status transitions and TLS certificates expiring within 30 days. Jobs are automatically scheduled when a check is activated or its cron/URL changes, and unscheduled when a check is deactivated or destroyed.
app/models · high confidence
Initial release of the ciao Helm chart (v1.0.0)
This change introduces the first official Helm chart for the ciao HTTP monitoring application, allowing users to deploy it to Kubernetes via Helm. The chart includes standard Kubernetes resources (Deployment, Service, Ingress, PVC) and adds an initContainer to handle SQLite database file ownership, ensuring correct permissions for the application container. It supports configurable liveness and readiness probes, basic authentication headers in probes, and persistent storage via PersistentVolumeClaims.
helm-chart · high confidence
Introduces configurable webhook and email notification channels for TLS certificate expiration
This change adds the underlying infrastructure to send notifications when TLS/SSL certificates are nearing expiration. It introduces a new notification framework in \app/lib/ciao/notifications\ with base classes and specific implementations for sending emails via \CheckMailer\ (including a dedicated \tls\_expires\_mail\) and posting JSON payloads to configurable webhook endpoints. The system uses environment variables prefixed with \CIAO\_WEBHOOK\ENDPOINT\\ and \CIAO\_WEBHOOK\PAYLOAD\\ to define multiple webhook targets and their custom JSON templates, which are rendered using placeholders like \\_\_tls\_expires\at\\\ and \\\_tls\_expires\_in\days\\_\ via the new \ReplaceRenderer\.
app/lib · high confidence
New email notifications for status changes and TLS certificate expiration
Users will now receive email notifications for two specific events: when a monitored item's status changes (showing the previous and new status) and when a TLS/SSL certificate is approaching expiration (showing the expiry date and remaining days). These new mailer templates provide direct links to the relevant resources.
_app/views/check\mailer · high confidence
Behavioural changes
Application startup, monitoring, and error handling improvements
The application now automatically schedules background jobs for active checks upon startup, ensuring monitoring tasks are ready immediately after launch. A new Prometheus metrics endpoint is available to expose check counts and status breakdowns, while TLS certificate expiration notifications can be configured via environment variables. Error handling is strengthened by catching SSLError in HTTP requests and logging detailed scheduler errors, and the asset pipeline has been modernized by removing legacy configuration files.
config/initializers · high confidence
Database schema updates for TLS monitoring and status history
The database schema has been updated to support TLS certificate monitoring and status change tracking. New columns have been added to the \checks\ table: \last\_contact\_at\ and \next\_contact\_at\ for scheduling visibility, and \tls\_expires\_at\, \tls\_expires\_in\_days\, and \tls\_job\ to track certificate expiration details and associated jobs. Additionally, a new \status\_changes\ table has been created to record the history of status updates for each check, including a foreign key link back to the \checks\ table.
db · high confidence
Enforce frozen string literals in core channel and job classes
The ApplicationCable::Channel, ApplicationCable::Connection, and ApplicationJob classes now include the \\# frozen\_string\_literal: true\ directive. This change optimizes string handling by preventing unnecessary string duplication, which can improve memory usage and performance for WebSocket connections and background jobs.
app/channels, app/jobs · high confidence
Enhanced status and health check visual indicators
The application now provides more granular visual feedback for check statuses and health metrics. The status display has been upgraded from a simple green/red binary to a five-tier color scheme (secondary, success, info, warning, danger) that maps to specific HTTP status code ranges. Additionally, new helper methods introduce visual indicators for TLS certificate expiration (using danger, warning, or neutral colors based on days remaining), active health check flags (displaying check or minus icons), and overall health percentages (green for 100%, red otherwise).
app/helpers · high confidence
Flash messages now auto-dismiss as toasts
Flash messages are now displayed as auto-dismissing toasts in the upper-right corner of the screen, disappearing after 4 seconds. This change also modernizes the JavaScript asset pipeline by removing the legacy Webpacker setup (including Action Cable consumer and Turbolinks integration) in favor of a simpler Turbo-based entry point.
app/javascript · high confidence
HTTP Basic Authentication and JSON API behavior updates
The application now supports optional HTTP Basic authentication, configurable via the BASIC\_AUTH\_USERNAME and BASIC\_AUTH\_PASSWORD environment variables, using secure string comparison to prevent timing attacks. For JSON API consumers, the controller no longer suppresses forgery protection, and error responses for failed create/update operations now explicitly return a 422 Unprocessable Entity status code. Additionally, new administrative endpoints have been added to view job details, recreate scheduled jobs, and perform on-demand TLS checks.
app/controllers · high confidence
Improved cron and HTTP URL validation with modernized Ruby APIs
The cron and HTTP URL validators have been updated to use more robust and modern Ruby standard library methods. The HTTP URL validator now uses \URI::DEFAULT\_PARSER.escape\ instead of the deprecated \URI.escape\, ensuring reliable URL encoding. The cron validator has been refactored to provide clearer error messaging by directing users to https://crontab.guru for help, and it now logs exceptions to the Rails logger for better debugging, while also adhering to Ruby style guidelines with frozen string literals.
app/validators · high confidence
Modernize Rails configuration and add SMTP mailer support
The application environment configurations have been updated to align with Rails 8.1 conventions, replacing deprecated settings like \cache\_classes\ with \enable\_reloading\ and removing obsolete asset pipeline options. In development, the mailer now uses \letter\_opener\ to display emails in the browser instead of sending them. Production now supports configurable SMTP delivery via environment variables (including SSL/TLS options), and the test environment sets explicit default mailer options and disables exception rendering.
config/environments · high confidence
Modernize development environment by removing Webpacker and Spring
The development workflow has been updated to remove the legacy Webpacker asset pipeline and the Spring application preloader. The \bin/webpack\, \bin/webpack-dev-server\, and \bin/spring\ scripts have been deleted, and \bin/dev\ now uses \foreman\ to manage processes via a \Procfile.dev\. Standard Rails binstubs (\bin/rails\, \bin/rake\) have been updated to use modern Ruby path resolution (\\_\dir\\_\) and include \frozen\_string\_literal\ comments, while \bin/bundle\ has been reformatted for style compliance.
bin · high confidence
Rails 8.1 upgrade, asset pipeline modernization, and new application features
The application has been upgraded to Rails 8.1, which includes a modernized asset pipeline that replaces Webpacker with jsbundling-rails and importmap. This change is accompanied by a shift in secret management from encrypted credentials to environment-variable-backed YAML secrets for better Docker compatibility. New user-facing capabilities include an Administration page, a minimal Dashboard, and on-demand TLS checks, accessible via new routes for jobs, job recreation, and admin actions. Configuration updates also include moving SQLite databases to a subfolder for Docker volume support, disabling Active Storage variants, setting a configurable default time zone, and increasing the default database connection pool size.
config · high confidence
Redesigned navigation, toast notifications, and modernized asset pipeline
The application layout has been updated to use the Tabler CSS framework, replacing the previous styling with styled buttons for navigation links (Checks, New Check, Admin) and adding a footer that displays the application version. Flash messages are now rendered as auto-dismissing toast notifications in the top-right corner instead of plain text. Additionally, the asset pipeline has been modernized by switching from Webpacker to importmap for JavaScript and using a specific Tabler stylesheet, while also enabling Turbo tracking for assets.
app/views/layouts · high confidence
Updated UI styling to match Tabler 1.4.0 and Bootstrap 5
The application's visual appearance has been updated to align with the new Tabler 1.4.0 design system and Bootstrap 5 components. This change introduces tighter table rows, adjusted icon sizing, and compact count badges to restore previous styling nuances. It also fixes form layout gaps, ensures badges display white text correctly, and restores proper spacing between sibling cards, ensuring the interface looks consistent with the latest framework updates.
app/assets · high confidence
Updated application version to 1.10.1
The public version file has been updated to reflect the current release version 1.10.1, ensuring that any client-side version checks or footer displays accurately report the latest deployed build.
public · high confidence
Upgrade to Ruby 4.0.6 and Rails 8.1 with modernized asset pipeline
The application runtime has been upgraded from Ruby 2.5.5 to 4.0.6, and the framework has been upgraded to Rails 8.1. This change replaces the legacy Webpacker/Babel/PostCSS asset pipeline with the modern \jsbundling-rails\ approach, removing \babel.config.js\, \postcss.config.js\, and \.browserslistrc\. The Dockerfile has been refactored to use a multi-stage build with a non-root user for improved security and smaller image size, and the startup process now uses a dedicated \start.sh\ script that handles secret key generation and database migrations. Additionally, a Prometheus metrics endpoint is now available at \/metrics\ when the \PROMETHEUS\_ENABLED\ environment variable is set to true.
(repo-wide) · high confidence
Test coverage
Added comprehensive test suite for checks, mailers, and notifications
Added tests for the Check model (validations, scopes, and job scheduling callbacks), the ChecksController (CRUD operations and JSON API responses), the CheckMailer (status change and TLS expiration emails), and the notification system (mail and webhook notifications, including environment variable parsing and payload rendering). Also updated test fixtures and configuration to support these tests, including enabling SimpleCov for coverage reporting.
test · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Baseline
- First survey — no prior run to compare against. CAI 51.
Lenses
- Code Health 100
- Architecture 66
- Maturity 55
- Readiness 53
- Security 67
- Domain Modelling 43
- Accessibility 66
Changes since last survey
- 300 commits — 292 feature/other, 8 fixes
By area
- (root) — 209 commits
- public/version — 36 commits
- .github/workflows — 8 commits
- app/views — 8 commits
- app/models — 5 commits
- chart/templates — 4 commits
- config/initializers — 4 commits
- app/helpers — 3 commits
- helm-chart/ciao — 3 commits
- .github/ISSUE_TEMPLATE — 2 commits
- app/controllers — 2 commits
- app/lib — 2 commits
- chart/Chart.yaml — 2 commits
- chart/values.yaml — 2 commits
- config/environments — 2 commits
- scripts/chart — 2 commits
- (repo) — 1 commit
- app/mailers — 1 commit
- app/validators — 1 commit
- chart/README.md — 1 commit
Notable commits
- fix: Add comprehensive test suite and fix SMTP TLS configuration conflict
- fix: Fix pesky 'A server is already running' error when restarting docker container (#81)
- fix: Fix standardrb
- fix: Fix timing attack on Basic Auth
- fix: Revert 'Force bundler to avoid pre-compiled gems.'
- fix: Revert sassc upgrade (2.2.1 => 2.0.1).
- fix: Update README: Fix last PR - travis-ci.org URL.
- fix: Upheave common HTTP status codes and fix err.
- change: Add .editorconfig.
- change: Add Backup & Restore and Upgrade instructions.
- change: Add CIAO_LOG_LEVEL environment variable
- change: Add Docker build and push to GitHub Actions (#119)
- change: Add ENV variable to disable TLS expiration notifications via E-Mail
- change: Add Features section to README.
- change: Add Gitter chat (https://gitter.im/brotandgames/ciao).
- change: Add Guestbook ;)
- change: Add Helm Chart.
- change: Add Helm chart support for Ingress apiVersion networking.k8s.io/v1
- change: Add LICENSE.
- change: Add PVC (optional) and minimal README to Helm Chart (#33)
- …and 280 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
brotandgames/ciao was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 19 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 14b79d6d2b753075fbeb881b726d71eb2849d71d — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-13a154b7f5d1.