Skip to content
CAI
Software that uses CAICheck a score

bsideup/liiklus

60.0

Adequate · 22 September 2026

3.8k

lines of production code

Java

primary language

7

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Liiklus is a distributed event streaming and offset management system that ingests, stores, and tracks consumer group positions across multiple backends. It provides a pluggable architecture supporting various storage implementations, including Kafka, Pulsar, DynamoDB, Redis, and in-memory stores, alongside gRPC and RSocket transport layers. The system enables modular record processing through pre- and post-processors and ensures data integrity via JSON Schema validation.

How it got here

2018 — Plugin architecture and storage abstraction

28 changes.

The project established a modular plugin architecture and abstracted storage backends, introducing interfaces for records and positions storage. This enabled the implementation of diverse storage options, including in-memory, DynamoDB, and Kafka, alongside a new client API supporting gRPC and RSocket transports.

2019–2020 — Plugin-based storage and transport extensibility

7 changes.

This period focused on expanding Liiklus's architecture through a plugin-based approach, introducing new backends for records and positions storage as well as additional transport protocols. The team implemented support for Apache Pulsar and Redis for data persistence, while also adding RSocket transport and enhancing gRPC with JWT authentication and TLS encryption. These changes collectively broadened the system's integration capabilities and security options.

Features

Add Apache Pulsar as a records storage backend

Users can now configure Liiklus to store records in an Apache Pulsar cluster. This introduces a new \PulsarRecordsStorage\ implementation that supports publishing CloudEvents, handling partitioned and non-partitioned topics, and reading end offsets. The implementation includes TLS and authentication support via configurable trust certificates and auth plugin classes, and uses \publishTime\ as a fallback when \eventTime\ is not set. The storage is registered via Spring Boot auto-configuration when \storage.records.type\ is set to \PULSAR\.

plugins/pulsar-records-storage/src/main · high confidence

Add DynamoDB positions storage with automatic table creation

A new DynamoDB-based positions storage implementation is introduced, allowing the system to persist positions in a DynamoDB table. The configuration class registers the storage bean and, if enabled via the new \dynamodb.auto-create-table\ property, automatically creates the required table with a hash key, range key, and provisioned throughput settings.

plugins/dynamodb-positions-storage/src/main/java/com/github/bsideup/liiklus/dynamodb/config · high confidence

Add GRPC and RSocket client implementations

The client module now includes two new implementations of the LiiklusClient interface: GRPCLiiklusClient, which wraps the gRPC generated stubs, and RSocketLiiklusClient, which provides an RSocket-based transport. Both classes implement the full client API including publish, subscribe, receive, ack, getOffsets, and getEndOffsets, giving users the choice of transport protocol for interacting with the service.

client · high confidence

Add JSON Schema validation for incoming events

The schema plugin now supports validating incoming events against a JSON Schema. When enabled, the system will reject events that do not conform to the specified schema, including checks for required fields, data types, and deprecated properties. This applies to both standard events and CloudEvents, ensuring data integrity at the ingestion point.

plugins/schema · high confidence

Add JWT-based authentication and TLS encryption for gRPC transport

The gRPC transport now supports securing the transport layer with TLS (including mutual TLS) and authenticating requests via JWT. Users can enable authentication by setting \grpc.auth.alg\ to \HMAC512\ or \RSA512\ (with corresponding secret or public keys), and can enable TLS encryption by providing the necessary certificate and key files via \grpc.tls\ properties. This introduces new configuration properties for both authentication and transport security, allowing users to enforce secure communication channels for their gRPC services.

plugins/grpc-transport-auth · high confidence

Add Java example for Liiklus integration

A new Java example was added to the codebase, providing a complete consumer implementation that demonstrates how to publish and subscribe to events using the Liiklus protocol. The example includes the necessary configuration files (logback.xml) and a symbolic link to the protocol definitions, serving as a reference for integrating with the system.

examples/java · high confidence

Add Kafka-based records storage implementation

Introduces a new Kafka-backed implementation of the records storage interface, enabling the system to publish and subscribe to events via Apache Kafka. The new \KafkaRecordsStorage\ class handles producing messages to Kafka topics and consuming them using reactive streams, supporting CloudEvents and standard headers. This adds a new backend option for event storage and retrieval, allowing users to configure Kafka connection details and properties to route event data through a Kafka cluster.

plugins/dynamodb-positions-storage/src/main/java/com/github/bsideup/liiklus/dynamodb, plugins/kafka-records-storage/src/main/java/com/github/bsideup/liiklus/kafka · high confidence

Add Prometheus metrics endpoint for topic positions

The metrics plugin now exposes a Prometheus-compatible endpoint at /prometheus that reports the current position of each topic partition as a gauge metric named 'liiklus\_topic\_position'. This endpoint is only active when the 'exporter' Spring profile is enabled, and includes labels for topic, group name, group version, whether the position is the latest, and partition number. Tests verify that the metrics collector is not registered by default and requires the exporter profile to be active.

plugins/metrics · high confidence

Add RSocket transport support for the gateway profile

A new RSocket transport plugin has been added to the gateway profile, exposing the core Liiklus service methods (publish, subscribe, receive, ack, getOffsets, getEndOffsets) over RSocket. The configuration is controlled via the 'rsocket' properties (host, port, enabled), and the transport is only activated when the 'gateway' Spring profile is active. Tests have been added to verify profile activation, disable-ability, and parameter validation.

plugins/rsocket-transport · high confidence

Add Redis-backed positions storage plugin

A new plugin for storing consumer group positions in Redis has been added. The implementation includes the core storage class (RedisPositionsStorage) and its Spring Boot configuration (RedisPositionsConfiguration), which registers the bean when the 'storage.positions.type' is set to 'REDIS'. The plugin is configured via 'redis.host' and 'redis.port' properties, with a default key prefix of 'liiklus:positions:'. Unit tests have been added to verify configuration validation and storage behavior.

plugins/redis-positions-storage · high confidence

Add example plugin with record pre/post processors

An example plugin is introduced that demonstrates how to implement record processing in the system. It includes an \ExampleRecordPreProcessor\ that reverses the value of each record's envelope, and an \ExampleRecordPostProcessor\ that masks records with the key "maskMe". The plugin is registered via Spring's \ApplicationContextInitializer\ mechanism, making it available for use as a reference implementation.

examples/plugin/src/main/java/com/github/bsideup/liiklus/plugins/example · high confidence

Add in-memory records storage for testing

A new in-memory implementation of the records storage interface has been introduced, allowing the system to store and retrieve records in memory rather than a persistent backend. This component, located in the 'inmemory-records-storage' plugin, implements the 'FiniteRecordsStorage' interface and supports features such as publishing cloud events, retrieving end offsets, and subscribing to topic partitions. As noted in the code, this storage type is intended for testing purposes and should not be used in production.

plugins/inmemory-positions-storage, plugins/inmemory-records-storage/src/main/java/com/github/bsideup/liiklus/records/inmemory, plugins/inmemory-records-storage/src/main/java/com/github/bsideup/liiklus/records/inmemory/config · medium confidence

Initial project scaffolding and build configuration

The project is initialized with essential build and deployment artifacts, including a Dockerfile for containerized execution, a .dockerignore to exclude unnecessary files from the image, and a .travis.yml for CI integration. The Gradle wrapper scripts (gradlew, gradlew.bat) are updated to include memory allocation settings and license headers, and the .gitignore is adjusted to exclude generated files. Additionally, a LICENSE file (MIT) and a jitpack.yml for package publishing are added, establishing the project's operational and legal baseline.

(repo-wide) · high confidence

Introduce CloudEvents support and record processing pipeline

The records storage layer now supports CloudEvents, allowing messages to be wrapped in a structured envelope that carries headers and metadata. A new processing pipeline has been added with pre-processors and post-processors that can transform records as they enter or leave the storage system. Additionally, the storage interface now exposes methods to retrieve end offsets for partitions, enabling consumers to track their position in the stream.

api/src/main/java/com/github/bsideup/liiklus/records · high confidence

Modularizes the application into plugins and client modules

The project structure has been refactored to support a plugin-based architecture. The build configuration now includes new modules for various transport and storage implementations, including gRPC, RSocket, Kafka, Pulsar, Redis, DynamoDB, and schema validation. Additionally, a new 'client' module has been introduced to provide a unified API for interacting with the system, while the main 'app' module has been updated to depend on these new plugin implementations.

(dependencies) · high confidence

Behavioural changes

Gradle wrapper updated to 7.1.1

The Gradle wrapper has been upgraded from version 4.5.1 to 7.1.1. This change updates the build tooling used to compile and package the application, which may affect build performance and compatibility with newer Java or Android Gradle Plugin versions.

gradle · high confidence

Introduce GroupId and PositionsStorage interface for offset management

A new GroupId class is introduced to represent a group with an optional version, supporting parsing, comparison, and string representation. Alongside it, a new PositionsStorage interface is added, defining methods to update and retrieve position data for topics and groups. This change shifts the handling of offsets and positions into a dedicated storage abstraction, enabling modular storage implementations.

api/src/main/java/com/github/bsideup/liiklus/positions · high confidence

Introduce custom plugin loading and extension discovery

Added four new classes (LiiklusExtensionFinder, LiiklusPluginLoader, LiiklusPluginManager, LiiklusPluginRepository) to customize how the application discovers and loads plugins. The custom extension finder filters out classes not on the classpath to avoid exceptions, while the custom plugin loader explicitly loads JARs from a 'lib' folder within the plugin archive. The plugin manager overrides default behaviors to use these custom components, enabling a more robust plugin architecture.

app/src/main/java/com/github/bsideup/liiklus/plugins · high confidence

Introduce pluggable configuration for the gRPC transport layer

The gRPC transport is now configurable via a new \GRPCLiiklusTransportConfigurer\ interface, allowing users to apply customizations to the underlying \NettyServerBuilder\. This change enables advanced gRPC server tuning and service registration through the \GRPCConfiguration\ initializer, which also introduces validation for server properties like the port and enabled status.

plugins/grpc-transport · medium confidence

Kafka records storage configuration via Spring Boot properties

The application now supports configuring the Kafka-based records storage through standard Spring Boot properties. Users can set the 'storage.records.type' to 'KAFKA' and provide Kafka connection details (bootstrap servers and additional properties) to enable the Kafka storage plugin.

plugins/kafka-records-storage/src/main/java/com/github/bsideup/liiklus/kafka/config · high confidence

Migrate to Spring Fu Jafu and add plugin system support

The application startup has been refactored to use Spring Fu's Jafu functional API instead of the traditional SpringApplication, enabling a more declarative configuration style. This change introduces a plugin system that dynamically loads and starts plugins from a specified directory, allowing for extensibility through the PluginManager. Additionally, the codebase now includes a new PropertiesUtil class to handle configuration binding with validation, and the application initializes with specific Netty memory leak fixes via system properties.

app/src/main/java/com/github/bsideup/liiklus · medium confidence

New APIs for offset management and event publishing

The protocol now supports publishing events via a new \Publish\ RPC and querying offsets with \GetOffsets\ and \GetEndOffsets\ RPCs. The \LiiklusEvent\ message structure is introduced to carry CloudEvents-compatible data, and the \ReceiveReply\ now includes a \LiiklusEventRecord\ alongside the existing \Record\ type. Additionally, the \SubscribeRequest\ and \AckRequest\ messages are updated to include \group\_version\ and \Assignment\-based identification, replacing the previous string-based session and partition identifiers.

protocol · medium confidence

Refactored configuration for record processing and transport layers

The application's configuration has been restructured to support a plugin-based architecture for record processing. New \RecordPreProcessorChain\ and \RecordPostProcessorChain\ classes manage the ordering of pre- and post-processing steps for records, orchestrated by a new \GatewayConfiguration\ that activates when the 'gateway' profile is active. Additionally, legacy configuration classes for gRPC (\GRPCConfiguration\) and Kafka (\KafkaConfiguration\) have been removed, indicating a shift away from hardcoded bean definitions toward a more modular, profile-driven setup.

app/src/main/java/com/github/bsideup/liiklus/config · high confidence

Removed DefaultKafkaReceiverAccessor utility class

The DefaultKafkaReceiverAccessor class, which previously provided static helper methods for updating Kafka offsets and closing receivers, has been removed from the application codebase.

app/src/main/java/reactor · high confidence

Replaced Kafka source implementation with a new service architecture

The \ReactorLiiklusServiceImpl\ and \KafkaSource\/\ReactorKafkaSource\ implementations have been removed and replaced with a new \LiiklusService\ that manages subscriptions and records storage directly. This change removes the dependency on \reactor-kafka\ for source handling, likely addressing the NPE and memory leak issues mentioned in the commit history, and introduces a more modular structure for handling message offsets and processing.

app/src/main/java/com/github/bsideup/liiklus/service · medium confidence

Test coverage

Add Liiklus test container and associated tests; Add integration test infrastructure for Liiklus; Added integration and configuration tests for Kafka records storage; Added integration tests for core messaging and configuration features; Added integration tests for the example plugin; Added tests for DynamoDB positions storage and configuration; Added tests for GroupId parsing and CloudEvents serialization; Added tests for Pulsar records storage; Added tests for in-memory records storage and its configuration; Introduce TCK for validating record and positions storage implementations.

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 61 → 60 (-0.9)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 99 → 97 (-2.3)
  • Architecture 100 → 82 (-18.1)
  • Maturity 43 → 43 (+0.0)
  • Readiness 62 → 63 (+1.5)
  • Security 85 → 90 (+5.1)

Resolved (11)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (8 lines × 2) (plugins/inmemory-positions-storage/src/main/java/com/github/bsideup/liiklus/positions/inmemory/config/InMemoryPositionsConfiguration.java)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium IaC: CKV_DOCKER_3 (Dockerfile)
  • No exposed public API
  • Test reliability not included
  • The quick-start assumes a Kafka bootstrap host and MEMORY storage for testing, but the README does not mention how to configure or verify the actual event-storage backend (e.g. Pulsar/Kafka) when running locally. (README.md)
  • This README is a Pulsar example reference and adds nothing new about Liiklus; it does not explain how to run the gateway with Pulsar or link back to the main docs. (plugins/pulsar-records-storage/src/test/resources/certs/README.md)
  • dormant codebase — no living knowledge left to concentrate

New (45)

  • Dependency hygiene PARTLY measured — Maven/Gradle declarations read, no dependency graph resolved
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no licence statement (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (5 lines × 2) (plugins/inmemory-positions-storage/src/main/java/com/github/bsideup/liiklus/positions/inmemory/config/InMemoryPositionsConfiguration.java)
  • Duplicated block (7 lines × 2) (plugins/inmemory-positions-storage/src/main/java/com/github/bsideup/liiklus/positions/inmemory/config/InMemoryPositionsConfiguration.java)
  • Duplicated block (8 lines × 3) (plugins/grpc-transport/src/main/java/com/github/bsideup/liiklus/transport/grpc/config/GRPCConfiguration.java)
  • Edited copy of a member (15 corresponding lines) (plugins/inmemory-records-storage/src/main/java/com/github/bsideup/liiklus/records/inmemory/config/InMemoryRecordsConfiguration.java)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Medium IaC: WD-DOCKER-0003 (Dockerfile)
  • Medium IaC: WD-DOCKER-0003 (Dockerfile)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • No ADRs found
  • No assertions: mTLS (plugins/grpc-transport-auth/src/test/java/com/github/bsideup/liiklus/transport/grpc/GRPCTLSTest.java)
  • No assertions: shouldAlwaysUseEarliestOffsetOnEmptyOffsetsInTheInitialProvider (plugins/pulsar-records-storage/src/test/java/com/github/bsideup/liiklus/pulsar/AbstractPulsarRecordsStorageTest.java)
  • No assertions: shouldConnectWithTLS (plugins/grpc-transport-auth/src/test/java/com/github/bsideup/liiklus/transport/grpc/GRPCTLSTest.java)
  • No assertions: shouldCreateProviderInstance (plugins/grpc-transport-auth/src/test/java/com/github/bsideup/liiklus/transport/grpc/StaticRSAKeyProviderTest.java)
  • No assertions: shouldPublishWithAuthRsa512 (plugins/grpc-transport-auth/src/test/java/com/github/bsideup/liiklus/transport/grpc/GRPCAuthTest.java)
  • …and 25 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

bsideup/liiklus was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 22 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 9a5bb00fa8c4d35e9985fe535a6dc84d41420f41 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-90d5d2fe38ee.