build-trust/ockam
58.2
Adequate · 30 September 2026
156.1k
lines of production code
Rust
with Elixir
2
measurements over time
What this system is
This system is a secure, decentralized networking framework implemented in Rust and Elixir that enables private, end-to-end encrypted communication between nodes. It provides core infrastructure for identity management, credential-based authorization, and secure channel establishment, allowing applications to route traffic over TCP, UDP, and custom transports without exposing them to the public internet. The platform supports complex service topologies through features like multi-hop routing, service discovery, and bidirectional streaming, while offering specialized integrations for tunneling legacy protocols such as Kafka and InfluxDB securely.
How it got here
2020–2021 — Core architecture and transport implementation
63 changes.
This period focused on establishing the foundational architecture for the Ockam node in both Rust and Elixir, introducing core components for routing, secure channels, and worker management. Significant effort was dedicated to implementing transport layers, including TCP, UDP, and WebSocket, alongside a pluggable messaging framework with reliable delivery and ordering guarantees. The work also included the initial release of the CLI, Kafka-backed streaming capabilities, and comprehensive test coverage to validate the new cryptographic and networking protocols.
2022 — CLI restructuring and service infrastructure
63 changes.
This period focused on restructuring the Ockam CLI into granular, dedicated command groups for managing nodes, identities, credentials, and TCP connections, while simultaneously introducing a centralized service infrastructure in the Elixir implementation. Significant work was also done to enhance identity and credential management across both Rust and Elixir, alongside the addition of new transports like UDP with NAT hole punching and the Portal TCP tunneling layer.
2023–2024 — Kafka integration and CLI modernization
85 changes.
This period focused on introducing comprehensive Kafka support through protocol-aware inlets, outlets, and dynamic broker discovery, alongside robust ABAC policy enforcement. The CLI was significantly modernized with declarative configuration via 'ockam run', persistent SQL state management, and standardized output formatting. Extensive test coverage was added for these new features, including BATS suites for orchestrator workflows and integration tests for encrypted Kafka topologies.
2025 — Orchestrator API and CLI expansion
16 changes.
This period focused on expanding the Ockam Orchestrator capabilities by introducing comprehensive APIs for managing projects, spaces, and share invitations, alongside a new Node Control API for programmatic node management. The CLI was significantly enhanced with new commands for status reporting, database migration, and cluster autonomy, while the underlying orchestrator module was restructured to support these features. Additionally, new Rust and Elixir examples were added to demonstrate core networking and security patterns.
Features
Add CRUD commands for managing Kafka Outlets
Users can now create, list, show, and delete Kafka Outlets using the \ockam kafka-outlet\ command group. The \create\ subcommand establishes a new outlet to a specified Kafka bootstrap server, supporting optional TLS and ABAC policy expressions, while \delete\ allows removing specific or all outlets. The \list\ and \show\ subcommands provide visibility into existing outlet configurations and their status on the local node.
_implementations/rust/ockam/ockam\command/src/kafka/outlet · high confidence
Add Elixir example workers for routing, echoing, and messaging
New example modules have been added to the Elixir library to demonstrate core Ockam worker patterns. These include an echoer that replies with the original payload, a hop worker that forwards and traces messages, a printer that logs incoming messages, and a ping-pong pair that demonstrates stateful message exchange with configurable delays. These examples illustrate the usage of the new \Worker.route/2\ function and message forwarding helpers.
implementations/elixir/ockam/ockam/lib/ockam/examples · high confidence
Add InfluxDB Outlet command with token management
The \ockam influxdb-outlet create\ command is now available, allowing users to create an InfluxDB Outlet that connects to a remote InfluxDB server. This command supports two authentication modes: using a fixed access token via the \--fixed-token\ argument, or managing token leases via the \--org-id\, \--all-access-token\, \--leased-token-permissions\, and \--leased-token-expires-in\ arguments. The outlet attaches the specified authentication information to HTTP requests before forwarding them to the InfluxDB server.
_implementations/rust/ockam/ockam\command/src/influxdb/outlet · high confidence
Add InfluxDB token lease management commands
The CLI now includes a new \lease\ command group for managing InfluxDB authentication tokens. Users can create, list, show, and revoke tokens via \lease create\, \lease list\, \lease show\, and \lease revoke\. These commands interact with the InfluxDB token lease service, supporting options for identity, trust context, and timeout, and provide output in plain text, machine-readable, and JSON formats.
_implementations/rust/ockam/ockam\command/src/lease · high confidence
Add Kafka storage backend for Ockam Stream
A new Kafka-based storage implementation has been added to the Ockam Stream service, enabling users to persist stream data using Kafka topics. This backend implements the standard storage interface, handling stream initialization, partition management, and message persistence via synchronous production, while fetching messages through leader connections with configurable wait times and byte limits.
_implementations/elixir/ockam/ockam\kafka/lib/storage · high confidence
Add TCP and UDP transport implementations
The Ockam Elixir library now includes new TCP and UDP transport modules. The TCP transport (\Ockam.Transport.TCP\) provides a configurable listener (using Ranch when available) and supports implicit client creation for routing messages to remote TCP addresses, with an option to disable implicit connections. The UDP transport (\Ockam.Transport.UDP\) offers a simple listener start function. Both transports are registered as OTP applications and integrate with the Ockam router for message handling.
implementations/elixir/ockam/ockam/lib/ockam/transport · high confidence
Add XX key establishment protocol for secure channels
The Elixir implementation of the secure channel now includes a new XX key establishment protocol. This change introduces a 3-packet handshake mechanism that establishes a secure session using static and ephemeral keypairs, deriving encryption keys via HKDF and ensuring message integrity through authenticated encryption (AES-256-GCM). Users connecting via this protocol will benefit from the specific security properties and handshake flow defined by the XX pattern, replacing or supplementing previous key exchange methods.
_implementations/elixir/ockam/ockam/lib/ockam/secure\_channel/key\_establishment\protocol · high confidence
Add \`ockam flow-control add-consumer\` command
Users can now associate an existing flow control policy with a new consumer address using the new \ockam flow-control add-consumer\ command. This command requires a flow control ID and the address of the consumer, allowing applications to dynamically update which endpoints are permitted to send data under a specific flow control rule.
_implementations/rust/ockam/ockam\_command/src/flow\control · high confidence
Add \`ockam message send\` command
Users can now send messages between Ockam nodes using the new \ockam message send\ subcommand. The command accepts a message payload and a destination route via \--to\, and optionally specifies a sender node via \--from\; if no sender is provided, an in-memory node is automatically created for the operation. It supports hex-encoded messages with the \--hex\ flag, configurable timeouts, and resolves project secure channels when the destination address includes project identifiers.
_implementations/rust/ockam/ockam\command/src/message · high confidence
Add \`ockam rendezvous get-my-address\` command
Users can now retrieve their public UDP address from the Rendezvous service using the new \ockam rendezvous get-my-address\ command. This command connects to the Rendezvous service (using a specified or default address), binds a UDP socket, and displays the assigned public address. The command is integrated into the existing \rendezvous\ subcommand structure alongside the \create\ command.
_implementations/rust/ockam/ockam\command/src/rendezvous · high confidence
Add command to list workers on a node
Users can now run \ockam worker list\ to view all available workers on a specified node. This new command queries the node for its current worker list and displays them in a standardized format, helping users verify which services or secure channels are active. The command supports an optional \--at\ flag to target a specific node by name.
_implementations/rust/ockam/ockam\command/src/worker · high confidence
Add project-admin and space-admin management commands
New CLI commands have been added to manage administrators for both Projects and Spaces. Users can now run \project-admin add\, \project-admin list\, and \project-admin delete\ to control project-level access, and \space-admin add\, \space-admin list\, and \space-admin delete\ for space-level access. The delete operations support bulk removal and confirmation flags, with space admin deletion specifically preventing the removal of admins attached to enrolled identities unless explicitly confirmed.
_implementations/rust/ockam/ockam\_command/src/project\admin · high confidence
Add shell completion generation command
Users can now generate shell completion scripts for the Ockam CLI by running the new \ockam completion\ command. This feature leverages the clap\_complete library to output syntax-highlighted completion scripts for supported shells (such as bash, zsh, fish, etc.), improving the interactive command-line experience by enabling auto-completion for commands and arguments.
_implementations/rust/ockam/ockam\command/src/completion · high confidence
Added BLE transport examples for routing and secure channels
New example files demonstrate how to initialize the BLE transport and send messages over it. The first example shows basic routing to an echoer worker via the BLE transport, while the second example demonstrates establishing a secure channel using the new Identity design before sending a message. Both examples utilize the new NodeBuilder for node initialization.
_implementations/rust/ockam/ockam\_transport\ble/examples · high confidence
Added Credo linting configuration and stream storage interface
The Ockam Elixir package now includes a Credo configuration file (.credo.exs) to enforce code quality and consistency checks, alongside a new .formatter.exs to standardize code formatting. Additionally, a new Stream.Storage module has been introduced, defining the callbacks for initializing streams/partitions and saving or fetching message data, serving as the interface for stream storage implementations.
implementations/elixir/ockam/ockam · high confidence
Added Elixir examples for local and TCP message routing
New example modules have been added to demonstrate Ockam routing capabilities in Elixir. The local routing example shows how to send a message through a hop to an echoer within a single node, while the TCP routing example illustrates establishing a connection to a remote TCP server, sending a message to an echoer, and receiving the response. These examples serve as reference implementations for users looking to integrate Ockam's routing and transport features in their Elixir applications.
implementations/elixir/ockam/ockam/lib/ockam/examples/routing · high confidence
Added TCP and UDP transport example modules
New example modules have been added to demonstrate how to use the TCP and UDP transports in Elixir. The TCP example shows how to start a server with a listener on port 4000 and a client that routes messages using various address formats (hostname, tuple IP, string IP). The UDP example illustrates starting transports on specific ports (4000 and 3000) and routing messages between them.
implementations/elixir/ockam/ockam/lib/ockam/examples/transport · high confidence
Added hidden command to migrate Postgres database schema
A new \migrate-database\ command has been added to the CLI, allowing users to migrate a shared Postgres database to the latest schema version. The command is currently hidden from help output and supports a \--dry-run\ flag to preview pending migrations without applying them. It validates that a Postgres configuration exists and that the user has admin privileges before executing the migration via the \NodeMigrationSet\.
_implementations/rust/ockam/ockam\_command/src/migrate\database · high confidence
Added node process registry for worker management
The Ockam node now includes a dedicated process registry (Ockam.Node.Registry) to manage worker lifecycle and routing. This new module enables workers to register themselves with unique addresses, allows the system to look up worker PIDs and associated metadata (such as the implementing module), and supports listing all registered worker names. This infrastructure is required for the new worker routing and address resolution capabilities within the Elixir implementation.
implementations/elixir/ockam/ockam/lib/ockam/node · high confidence
Customizable branded CLI binaries and improved error handling
Users can now generate custom-branded versions of the Ockam CLI by providing a YAML configuration file to the new \brand\ binary tool, which allows specifying unique command sets, support emails, home directories, and build arguments for each brand. The default \ockam\ binary now utilizes the mimalloc allocator to reduce memory fragmentation and displays detailed initialization errors to the user if startup fails, rather than exiting silently.
_implementations/rust/ockam/ockam\command/src/bin · high confidence
Direct authenticator client now supports listing and deleting members
The Elixir direct authenticator client has been extended with new API methods to manage credential authority members. Users can now retrieve a list of member identity IDs via \list\_member\_ids\, fetch detailed member attributes and metadata via \list\_members\, and remove members using \delete\_member\. These additions complement the existing \add\_member\ capability, providing a complete set of operations for member lifecycle management within the credential authority service.
implementations/elixir/ockam/ockam/lib/ockam/credential/authenticator · high confidence
Dynamic Kafka broker outlet creation via metadata interception
The Kafka API now automatically discovers and connects to Kafka brokers by intercepting Metadata responses. When a Metadata request is sent, the system tracks the correlation ID and, upon receiving the response, extracts the list of broker addresses. It then dynamically creates an outlet for each broker via the \KafkaOutletController\, allowing traffic to be routed through these newly established connections without manual configuration.
_implementations/rust/ockam/ockam\_api/src/kafka/protocol\aware/outlet · high confidence
InfluxDB portals now support automatic token management and HTTP header interception
InfluxDB inlet and outlet services now automatically attach authorization tokens to HTTP requests via new portal interceptors. The system supports two modes: 'PerClient', where each inlet instance manages its own token lease from a dedicated lease issuer service, and 'Shared', where a single outlet-side interceptor handles token attachment for multiple inlets. This change introduces a token lease refresher that automatically renews tokens before expiration, ensuring continuous connectivity to InfluxDB without manual token handling by the user.
_implementations/rust/ockam/ockam\api/src/influxdb · high confidence
Initial Kafka backend configuration for Ockam Stream
This change introduces the configuration file for the new Ockam Kafka backend, setting the default Kafka endpoint to localhost:9092 and registering the Kafka service provider within the ockam\_services application.
_implementations/elixir/ockam/ockam\kafka/config · high confidence
Initial Kafka backend implementation for Ockam streams
This change introduces the core Elixir modules for the new Kafka backend, enabling Ockam streams to use Kafka as a transport layer. The \Ockam.Kafka.Config\ module handles configuration parsing, including SASL authentication, SSL settings, and endpoint resolution from environment variables. The \Ockam.Kafka\ module provides the client logic for interacting with Kafka via the \:brod\ library, supporting operations such as creating and deleting topics, fetching messages, and resolving offsets.
_implementations/elixir/ockam/ockam\kafka/lib · high confidence
Initial UDP transport implementation
Adds the initial UDP transport layer for the Ockam node, introducing a new \Ockam.Transport.UDPAddress\ module for handling IP/port address serialization and a \Ockam.Transport.UDP.Listener\ GenServer that manages the UDP socket lifecycle. The listener registers a message handler for the UDP address type, decodes incoming packets via the \Wire\ module, routes them to the internal router, and encodes outgoing messages to send back over UDP, including basic telemetry emission for successful operations.
implementations/elixir/ockam/ockam/lib/ockam/transport/udp · high confidence
Initial release of OckamKafka library
This change introduces the OckamKafka library, providing a Kafka backend for Ockam streams. The commit adds the foundational project structure, including configuration for code formatting (.formatter.exs), linting (.credo.exs), and build artifacts (.gitignore), along with a README outlining installation via Hex. This establishes the package as a dependency for integrating Kafka messaging within the Ockam ecosystem.
_implementations/elixir/ockam/ockam\kafka · high confidence
Initial release of the WebSocket transport for Ockam
The \ockam\_transport\_websocket\ crate is introduced, providing a WebSocket transport implementation for Ockam's routing protocol. This enables nodes to establish bidirectional communication over WebSocket connections, supporting both server-side listening (via \WebSocketTransport::listen\) and client-side connecting (via \WebSocketTransport::connect\). The implementation handles connection lifecycle management, message serialization/deserialization, and routing through dedicated workers and processors, allowing Ockam applications to communicate with remote peers over standard WebSocket infrastructure.
_implementations/rust/ockam/ockam\_transport\websocket · high confidence
Initial release of the main ockam Rust crate
The \ockam\ crate is now available as a unified entry point for the library, exposing core types, macros, and services. Users can now import the \ockam\ crate to access the \Node\ builder for managing identities and secure channels, the \Context\ for worker and processor management, and re-exports for \ockam\_identity\, \ockam\_node\, and transport modules like TCP and UDP. The crate also includes the \RelayService\ for remote communication and provides access control and flow control APIs.
implementations/rust/ockam/ockam/src · high confidence
Initial release of the ockam\_command crate with build-time branding and configuration
The ockam\_command crate is introduced as the new home for the Ockam CLI, providing commands to start nodes and manage projects on the Ockam Orchestrator. The crate includes a build script that embeds compile-time configuration, allowing users to customize the binary's name, brand, support email, and the set of visible commands (defaulting to 'cluster' and 'zone') via environment variables. It also embeds the current Git hash for versioning and sets up basic project scaffolding including a changelog and README.
_implementations/rust/ockam/ockam\command · high confidence
Initial release of the ockam\_executor crate
The ockam\_executor crate is introduced as a new component providing an async executor implementation designed for no\_std environments. It exposes a runtime API compatible with Tokio's surface (re-exported under ockam\_executor::tokio), including task spawning, join handles, and a channel implementation (ockam\_executor::tokio::sync::mpsc) that uses a fixed-size, statically allocated queue. The executor also provides time utilities such as timeout and sleep wrappers, enabling asynchronous operations in constrained environments without requiring a full std library.
(repo-wide) · high confidence
Introduce 'cluster' command group for autonomy management
A new 'cluster' command group has been added to the CLI to manage clusters in autonomy. This includes the 'cluster enroll' command, which allows users to enroll their machine's identity with their cluster (creating a new vault and identity if none exists), and the 'cluster show' command, which displays the current cluster ID and its associated zones. The implementation introduces shared argument structures for cluster identification and HTTP API configuration, along with utility functions to retrieve the cluster ID and API clients.
_implementations/rust/ockam/ockam\command/src/cluster · high confidence
Introduce AWS KMS-backed signing vault
The \ockam\_vault\_aws\ crate now provides an AWS KMS implementation of the Ockam signing vault. Users can initialize an \AwsSigningVault\ that manages NIST P-256 key pairs in AWS KMS, supporting key creation, signing, public key retrieval, and scheduled deletion. The vault allows configuring initial key discovery (listing all accessible keys or providing explicit key IDs) and supports multi-region keys. This change extracts the AWS-specific vault logic into a dedicated crate, replacing previous inline implementations.
_implementations/rust/ockam/ockam\_vault\aws · high confidence
Introduce Elixir ABAC policy engine with attribute-based rule evaluation
This location adds the core Elixir implementation of the Ockam ABAC (Attribute-Based Access Control) system. It provides a policy engine that evaluates access requests by matching attribute rules against subject, resource, and action attributes. The implementation includes a PEG-based grammar parser for defining rules (supporting equality, comparison, membership, and logical operators), a policy storage abstraction with in-memory ETS and persistent DETS backends, and an authorization module that acts as a Policy Enforcement Point to intercept and validate message routing based on configured policies.
_implementations/elixir/ockam/ockam\abac · high confidence
Introduce Elixir credential attribute storage and authorization
This change adds three new Elixir modules to the credential subsystem: AttributeSet defines the data structure for credential attributes with expiration metadata; AttributeStorageETS provides an ETS-backed store to save, retrieve, and list these attribute sets while automatically filtering out expired entries; and Authorization implements attribute-based access control by matching required attributes against the stored identity attributes. This enables the Elixir layer to manage credential attributes locally and enforce access policies based on them.
implementations/elixir/ockam/ockam/lib/ockam/credential · high confidence
Introduce InfluxDB Inlet command for secure data forwarding
Users can now create InfluxDB inlets using the \ockam influxdb-inlet create\ command, which establishes a secure portal to forward HTTP traffic to an InfluxDB outlet. This new capability allows users to specify the listening address, the target outlet route, and an optional relay via the \--via\ flag. The inlet automatically attaches authorization tokens to requests and supports access control policies, with options to configure lease token strategies and connection timeouts.
_implementations/rust/ockam/ockam\command/src/influxdb/inlet · high confidence
Introduce InfluxDB Token Lease Issuer service
A new InfluxDB Token Lease Issuer service has been added to the Ockam API, enabling nodes to manage temporary InfluxDB API tokens. This component exposes a node service and worker that handle creating, listing, retrieving, and revoking lease tokens with configurable expiration times and permissions. It integrates with the InfluxDB API client to issue tokens on behalf of users and includes a background processor to automatically revoke expired tokens, ensuring secure and automated token lifecycle management.
_implementations/rust/ockam/ockam\_api/src/influxdb/lease\issuer · high confidence
Introduce Kafka Inlet and Outlet services with policy-based access control
The \ockam\_api\ crate now includes a new Kafka service module that allows users to create Kafka inlets and outlets as background node services. This change introduces \KafkaInletController\ and \KafkaOutletController\ to manage dynamic broker connections, supporting features like TLS for outlets, content encryption for inlets, and configurable port ranges. Access to these services is governed by ABAC policy expressions, which can be specified for inlets, consumers, and producers, enabling fine-grained authorization for Kafka traffic through Ockam portals.
_implementations/rust/ockam/ockam\api/src/kafka · high confidence
Introduce Ockam Node Control API with HTTP frontend and OpenAPI documentation
This change introduces the Node Control API, allowing users to manage Ockam nodes programmatically via HTTP requests rather than using the CLI or library directly. The implementation in this location provides the HTTP server frontend (frontend.rs) that listens for requests, routes them to the node manager, and handles authentication via a bearer token, as well as the OpenAPI schema generation (openapi.rs) which documents the available endpoints for managing TCP Inlets, Outlets, Relays, Tickets, and Authority Members. A dedicated error handling module (http.rs) ensures consistent JSON error responses, and an exporter utility (exporter.rs) is added to print the generated schema for documentation purposes.
_implementations/rust/ockam/ockam\_api/src/control\api · high confidence
Introduce RemoteRelay for cloud-based message forwarding
Users can now register a local node with the Ockam Orchestrator to allow other nodes to forward messages to local workers via a static or ephemeral alias. This new \RemoteRelay\ component handles the registration handshake, manages flow control and access control for forwarded traffic, and routes incoming messages from the cloud back to the appropriate local worker addresses.
implementations/rust/ockam/ockam/src/remote · high confidence
Introduce TypedCBOR module for schema-based CBOR encoding and decoding
Added the \Ockam.TypedCBOR\ module, which provides helpers to encode and decode Elixir structs to/from CBOR format with strict type validation. This implementation is designed for compatibility with the minicbor Rust library, supporting schemas for integers, strings, booleans, binaries, enums, variant enums, lists, and structs (including required fields and constant values). It enables reliable serialization for identity services and secure channel protocols by ensuring data integrity during CBOR message processing.
_implementations/elixir/ockam/ockam\_typed\cbor/lib · high confidence
Introduce Unix Domain Socket (UDS) transport for local inter-process communication
This change adds a new \ockam\_transport\_uds\ crate that provides a Unix Domain Socket transport for Ockam's Routing Protocol. It introduces a \UdsTransport\ API allowing applications to listen on and connect to local socket paths, handling the underlying router registration, connection lifecycle, and message serialization. This enables secure, private communication between Ockam nodes running on the same host via local sockets.
_implementations/rust/ockam/ockam\_transport\uds · high confidence
Introduce \`kafka-inlet\` command for managing Kafka connections
The CLI now includes a new \kafka-inlet\ command group with subcommands to create, show, list, and delete Kafka Inlets. This replaces the previous \kafka direct\ and \kafka consumer/producer\ services with a unified inlet service model. Users can configure inlet details such as the bind address, broker port range, and routing to the Kafka outlet. The create command supports advanced features like selective field encryption for JSON records, disabling end-to-end content encryption, and defining specific access control policies for the inlet, consumer, and producer via ABAC expressions. It also introduces concepts for consumer resolution (direct node or relay) and publishing (relay or none) to manage how consumers are discovered and made available to producers.
_implementations/rust/ockam/ockam\command/src/kafka/inlet · high confidence
Introduce \`ockam relay\` command group with create, list, show, and delete subcommands
The CLI now provides a dedicated \ockam relay\ command group to manage relays, replacing the previous \forwarder\ terminology. This includes \relay create\ to establish a relay connection (supporting project and node targets, with options for non-blocking creation and JSON output), \relay list\ to display available relays on a node, \relay show\ to view detailed status and addresses of a specific relay, and \relay delete\ to remove a relay with optional confirmation. The commands use a TUI for interactive operations and support both plain text and JSON output formats.
_implementations/rust/ockam/ockam\command/src/relay · high confidence
Introduce \`ockam run\` command for declarative node configuration
Users can now define and launch multiple Ockam resources (nodes, identities, vaults, TCP/Kafka inlets/outlets, policies, and relays) using a single declarative configuration file (YAML) or inline text via the new \ockam run\ command. The command automatically resolves dependencies between resources (e.g., creating nodes before inlets) and supports optional resource naming, allowing users to bootstrap complex network topologies with a single invocation.
_implementations/rust/ockam/ockam\command/src/run · high confidence
Introduce \`ockam space\` commands for managing Orchestrator spaces
The CLI now includes a new \ockam space\ command group with subcommands for creating, listing, showing, and deleting spaces in Ockam Orchestrator. The \create\ command accepts an optional identity name and validates space names, while \delete\ supports confirmation prompts and JSON output. \list\ and \show\ commands retrieve space details from the orchestrator, with \show\ defaulting to the current space if no name is provided. All commands require an enrolled identity and use the new \InMemoryNode\ architecture for execution.
_implementations/rust/ockam/ockam\command/src/space · high confidence
Introduce bi-directional stream client with publisher proxy and subscription handling
This change adds a new bi-directional streaming capability to the Ockam Elixir implementation. It introduces a PublisherProxy worker that encodes messages and routes them to a publisher stream, a PublisherRegistry (using ETS) to manage and cache publisher addresses, and a Subscribe service that exposes protocols for creating remote stream subscriptions and ensuring publishers exist. This enables clients to send and receive data over bi-directional streams with automatic publisher management.
_implementations/elixir/ockam/ockam/lib/ockam/stream/client/bi\directional · high confidence
Introduce branded CLI binary support with compile-time configuration
The command-line interface now supports custom branding for white-label or partner distributions. By setting specific compile-time environment variables (such as \COMPILE\_OCKAM\_COMMAND\_BIN\_NAME\ and \COMPILE\_OCKAM\_COMMAND\_BRAND\_NAME\), distributors can customize the binary name, brand name, home directory, support email, and the set of available commands. This configuration is loaded at startup via \load\_compile\_time\_vars\ and applied to help text, error reporting, and output branding, allowing the CLI to present a tailored user experience while maintaining the core Ockam functionality.
_implementations/rust/ockam/ockam\command/src · high confidence
Introduce dedicated Ockam Metrics application for Prometheus monitoring
A new \ockam\_metrics\ application has been added to centralize and expose Ockam telemetry data via a Prometheus endpoint. This module defines base metrics for VM resources, worker counts, secure channel states (initiator/responder, handshake/data stages), and message handling durations. It includes a configurable telemetry poller to periodically emit these metrics and a Prometheus exporter that supports shared tags and dynamic metric configuration, allowing users to monitor system health and worker activity through standard Prometheus scraping.
_implementations/elixir/ockam/ockam\metrics · high confidence
Introduce dedicated TCP connection management commands
The CLI now includes a new \tcp-connection\ command group with subcommands for creating, listing, showing, and deleting TCP connections. The \create\ command accepts a target address and an optional source node (\--from\), returning the worker address in plain, JSON, and machine-readable formats. The \delete\ command supports deletion by worker or socket address, allows deleting all connections (\--all\), and includes a confirmation prompt (bypassed with \--yes\). The \list\ command displays all active TCP connections on a specified node, while the \show\ command provides detailed status for a specific connection. These commands replace the previous monolithic transport handling, offering more granular control over TCP connectivity.
_implementations/rust/ockam/ockam\command/src/tcp/connection · high confidence
Introduce dedicated node lifecycle management commands
The CLI now provides a structured \ockam node\ subcommand group to manage node states, replacing the previous implicit or monolithic creation flow. Users can explicitly create, start, stop, delete, and list nodes, as well as view their logs and details. A new \node default\ command allows setting and querying the default node, while \node show\ and \node list\ provide status information including process IDs and default status. The \node start\ command enables restarting previously stopped nodes, and \node delete\ supports removing nodes with optional force and confirmation flags. These commands interact with the CLI state to manage node configurations and processes.
_implementations/rust/ockam/ockam\command/src/node · high confidence
Introduce direct authenticator for authority member management
The direct authenticator module now provides a dedicated worker and client interface for managing authority members. This change adds the ability to add, list, show, and delete members, as well as create enrollment tokens with explicit TTLs, all handled via the new DirectAuthenticatorWorker. Users can now interact with these member management operations through the AuthorityNodeClient, which sends requests to the direct authenticator endpoint.
_implementations/rust/ockam/ockam\api/src/authenticator/direct · high confidence
Introduce extensible BARE schema encoding and protocol mapping layer
The protocol layer now supports advanced BARE schema types including union, variant, and tuple structures, enabling more complex message definitions. A new protocol mapping system allows developers to declaratively define request and response schemas for multiple protocols, handling automatic encoding and decoding of payloads based on protocol name. This infrastructure supports the new stream protocols (stream\_index, stream\_create, stream\_push, stream\_pull) and their partitioned variants, which define specific message structures for stream management and data transfer.
implementations/elixir/ockam/ockam/lib/ockam/protocol · high confidence
Introduce in-memory internal storage implementation for streams
The stream storage layer now includes an internal, in-memory implementation (\Ockam.Stream.Storage.Internal\) that manages stream data using Elixir maps. This change allows the stream service to operate without external persistent storage dependencies during development or testing, providing a lightweight backend that supports basic save and fetch operations via index-based lookups.
implementations/elixir/ockam/ockam/lib/ockam/stream/storage · high confidence
Introduce new project management commands
The CLI now includes a comprehensive set of commands for managing projects within the Ockam Orchestrator. Users can create new projects (\project create\), delete them (\project delete\), and list available projects (\project list\). Enrollment is handled via \project enroll\ (supporting both enrollment tickets and Okta authentication) and \project ticket\ for generating enrollment tickets with configurable attributes, expiration, and usage limits. Additional commands allow importing project configurations (\project import\), viewing detailed project information (\project show\, \project information\), listing project relays (\project relays\), and checking the orchestrator version (\project version\).
_implementations/rust/ockam/ockam\command/src/project · high confidence
Introduce policy-based access control for incoming and outgoing messages
The \ockam\_abac\ policy module now enforces access decisions using configurable policy expressions. New \PolicyAccessControl\, \IncomingPolicyAccessControl\, and \OutgoingPolicyAccessControl\ components evaluate policies against the resource, action, and message context (including sender/receiver identifiers and locality) to authorize or deny traffic. The system supports granular policy storage for both specific resource names and resource types, allowing administrators to define and manage access rules that apply to individual resources or broader categories.
_implementations/rust/ockam/ockam\abac/src/policy · high confidence
Introduce secure-channel CLI commands (create, delete, list, show)
Users can now manage secure channels directly from the command line with four new subcommands: \secure-channel create\ initiates a secure channel to a specified route (supporting optional credentials and authorized identifiers); \secure-channel delete\ removes a channel by address with a confirmation prompt; \secure-channel list\ displays all secure channels on a node; and \secure-channel show\ displays details for a specific channel, including peer identifiers and change history. All commands support structured JSON output and standard terminal formatting.
_implementations/rust/ockam/ockam\_command/src/secure\channel · high confidence
Introduce share invitation API types and client interface
This change adds the core data structures and client interface for the new share invitation system in the orchestrator API. It defines CBOR-serializable message types for creating invitations (including specific service invitations with enrollment tickets and project details), accepting invitations, and listing invitations by kind (sent, received, accepted). It also introduces the \Invitations\ trait and its \ControllerClient\ implementation, which exposes API endpoints for managing these invitations, and defines enums for share scopes (Project, Service, Space) and roles (Admin, Guest, Service).
_implementations/rust/ockam/ockam\api/src/orchestrator/share · high confidence
Introduce sidecar commands for secure relay inlet and outlet
Users can now use the new \ockam sidecar secure-relay-inlet\ and \ockam sidecar secure-relay-outlet\ commands to quickly generate and run configuration recipes for secure TCP relay portals. These commands accept a service name, a socket address (for the inlet's listen port or the outlet's destination), and an enrollment ticket (or Okta flag) to authenticate. By default, they print a generated YAML recipe and immediately execute it via \ockam run\; the \--dry-run\ flag allows users to preview and customize the recipe before execution.
_implementations/rust/ockam/ockam\command/src/sidecar · high confidence
Introduce stream creation service and partitioned worker implementation
Added a new \Ockam.Stream.Workers.Service\ that acts as a server-side coordinator for creating streams, handling \StreamProtocol.Create\ and \StreamProtocol.Partitioned.Create\ requests by validating stream names (rejecting empty strings) and spawning individual \Ockam.Stream.Workers.Stream\ workers for each partition. The new \Stream\ worker manages the lifecycle of a single stream partition, initializing storage via a configurable storage module, and handling \Push\ and \Pull\ protocol messages to save and retrieve data. This change establishes the core infrastructure for managing stream partitions and their underlying storage interactions.
implementations/elixir/ockam/ockam/lib/ockam/stream/workers · high confidence
Introduce stress-test tool for load testing Ockam projects
A new stress-test utility has been added to the \tools/stress-test\ directory to help users evaluate the performance and stability of their Ockam projects under load. The tool allows users to define a configuration file (in TOML) specifying parameters such as the number of peak portals and relays, ramp-up duration, and throughput limits (e.g., '10 mbits'). It simulates portal traffic by creating and managing relays and portals, measuring metrics like bytes sent/received, message throughput, and out-of-order messages. The tool uses \mimalloc\ for memory management and provides a real-time summary display of performance statistics.
tools/stress-test · high confidence
Introduces Kafka protocol interceptor for dynamic portal management
Adds a new Kafka protocol interceptor that automatically manages Ockam inlets and outlets based on Kafka metadata responses. The implementation includes an \InletManager\ and \OutletManager\ to dynamically create and clean up portal connections for Kafka brokers, and a \MetadataHandler\ that intercepts metadata requests and responses to update these connections. It also provides a full parser and formatter for Kafka metadata API versions 0–12, allowing the system to transparently route Kafka traffic through secure Ockam tunnels without manual configuration of broker endpoints.
_implementations/elixir/ockam/ockam\kafka/lib/interceptor · high confidence
Introduces Portal transport for TCP tunneling with packet ordering
Adds the core components for the Portal transport layer, including Inlet and Outlet workers, an Interceptor for routing, and a TunnelProtocol for message encoding. This enables TCP connections to be tunneled through the Ockam network with a handshake mechanism (ping/pong) and packet counters to ensure message ordering and detect mismatches.
implementations/elixir/ockam/ockam/lib/ockam/transport/portal · high confidence
Introduces binary wire protocol with optional tracing context support
The Elixir implementation now includes a new binary wire format that supports two message versions. Version 1 messages are encoded without a tracing context, while version 2 messages include an optional tracing context field. The decoder handles both versions, storing the tracing context in local metadata when present. This change enables the Elixir side to encode and decode messages with tracing information, aligning with the Rust implementation's capabilities.
implementations/elixir/ockam/ockam/lib/ockam/wire · high confidence
Introduces core Ockam framework components for messaging, routing, and security
This change adds the foundational building blocks for the Ockam node architecture, including the \Ockam.Address\ and \Ockam.Message\ data structures for typed routing, a \Ockam.Router\ with pluggable message handlers, and a \Ockam.Worker\ behavior for implementing node services. It also introduces \Ockam.Pipeline\ for composing worker steps, \Ockam.SecureChannel\ for end-to-end encrypted communication, and a \Ockam.Telemetry\ module for emitting metrics and logs. Additionally, it provides \Ockam.Wire\ for encoding/decoding messages, \MiniCBOR\ for optimized serialization, and a \Ockam.Topic\ implementation for publish-subscribe semantics.
implementations/elixir/ockam/ockam/lib/ockam · high confidence
Introduces pluggable session architecture with separate handshake and data stages
The session module now supports a pluggable architecture that explicitly separates the session handshake phase from the data transmission phase. This change introduces \Ockam.Session.Handshake\ as a behavior for defining handshake logic, \Ockam.Session.Pluggable\ to manage the state transitions between handshake and data stages, and \Ockam.Session.Spawner\ to dynamically spawn data workers based on handshake results. Users can now implement custom handshake protocols by adhering to the \Handshake\ behavior, allowing for more flexible and modular session management within the Ockam framework.
implementations/elixir/ockam/ockam/lib/ockam/session · high confidence
Introduction of ABAC access control for incoming and outgoing messages
The \ockam\_abac\ module now provides \IncomingAbac\ and \OutgoingAbac\ access controls that evaluate boolean policy expressions against message and subject attributes. These components allow you to authorize communication based on authenticated identity attributes, credential presence, and whether a message is local, enabling fine-grained, expression-based authorization for both inbound and outbound traffic.
_implementations/rust/ockam/ockam\abac/src/abac · high confidence
Introduction of Ockam Cloud Node with automated resource cleanup
The Ockam Cloud Node application has been introduced (renamed from ockam\_hub\_node) to manage cloud-side operations, featuring a new scheduled cleanup system. This system automatically terminates idle forwarding and stream workers, cleans up idle stream index shards, and optionally removes idle Kafka topics based on configurable timeouts and cron schedules. The node also includes a custom log formatter to ensure log messages are single-line for easier parsing.
_implementations/elixir/ockam/ockam\_cloud\node · high confidence
Introduction of Ockam Healthcheck Application
A new healthcheck application has been added to the Ockam Elixir implementation. This application initializes a supervisor that starts the TCP transport and manages a schedule of health checks. It parses configuration from a JSON list of targets, validates them using a ScheduledTarget parser, and schedules each target to be checked periodically via SchedEx based on a specified crontab expression.
_implementations/elixir/ockam/ockam\healthcheck/lib · high confidence
Introduction of persistent CLI state management with SQLite/PostgreSQL
The local CLI state is now persisted in a database (SQLite or PostgreSQL) instead of flat files, introducing a \CliState\ struct that manages nodes, identities, vaults, projects, spaces, and enrollments. This change enables reliable state recovery, supports multiple named identities and vaults, and allows the \ockam reset\ command to safely clear local data without affecting PostgreSQL tenant data. Users benefit from improved data integrity, better concurrency via WAL mode, and the ability to manage multiple local nodes and identities with distinct configurations.
_implementations/rust/ockam/ockam\_api/src/cli\state · high confidence
Introduction of the ockam\_api crate with core node and address utilities
The \ockam\_api\ crate has been introduced to centralize core node management and API logic. This change adds new modules for handling address resolution (including converting node aliases to multiaddresses), managing port ranges, and parsing dates. It also introduces foundational worker implementations such as \Echoer\, \Hop\, and \Uppercase\, alongside utility services like \RendezvousHealthcheck\ for monitoring node connectivity. Additionally, the crate provides common API components for TCP inlet creation and standardized error handling via \ApiError\ and \ParseError\ types, forming the basis for the node's internal and external communication interfaces.
_implementations/rust/ockam/ockam\api/src · high confidence
Introduction of the ockam\_services application with core service infrastructure
The \ockam\_services\ application has been introduced to centralize the management and execution of Ockam services. This change adds a new application structure including configuration files (\.credo.exs\, \.formatter.exs\) and a core \Ockam.Services\ module that acts as a supervisor for starting, stopping, and listing services based on configuration. It includes a provider-based architecture (\Ockam.Services.Provider\) to register and instantiate various service types such as echo, forwarding, discovery, ABAC policies, and secure channels. Additionally, it introduces a request-response API framework (\Ockam.Services.API\) with specific API workers for node info, discovery, and ABAC policies, along with supporting modules for metrics, telemetry, and gRPC forwarding.
_implementations/elixir/ockam/ockam\services · high confidence
Kafka inlet interceptor now supports selective field encryption
The Kafka inlet interceptor has been refactored to support encrypting specific fields within Kafka JSON records. The new \InletInterceptorImpl\ and \KafkaInletInterceptorFactory\ accept \encrypt\_content\ and \encrypted\_fields\ parameters, allowing users to configure which fields in Produce requests and Fetch responses are encrypted. This change also includes logic to reduce Kafka API versions to a supported range to ensure compatibility and security, and moves the portal interceptor implementation from the \api\ crate to the \tcp\ crate.
_implementations/rust/ockam/ockam\_api/src/kafka/protocol\aware/inlet · high confidence
Kafka message encryption now uses dedicated key-exchange secure channels
The Kafka API now supports encrypting specific fields within JSON records by establishing secure channels specifically for key exchange. This change introduces a new \KafkaKeyExchangeController\ in the \ockam\_api\ crate that manages these channels per topic and partition, allowing producers to encrypt content and consumers to decrypt it using separate secure channel endpoints. The implementation handles both direct and relay-based consumer resolution, ensuring that credentials are validated against policy access controls before encryption or decryption operations proceed.
_implementations/rust/ockam/ockam\_api/src/kafka/key\exchange · high confidence
Kafka-backed offset storage for Ockam Streams
The Ockam Stream index service now supports a Kafka storage backend via the new \KafkaOffset\ module. This change allows stream offsets to be persisted and retrieved directly from Kafka consumer group commits, replacing or supplementing previous storage mechanisms. Users can now leverage Kafka's native offset management for stream state, ensuring that stream progress is tracked within the Kafka cluster itself.
_implementations/elixir/ockam/ockam\kafka/lib/index · high confidence
New ABAC policy expression language and REPL tool
The \ockam\_abac\ crate now includes a new small language for defining ABAC policies, supporting both simple boolean expressions (using \and\, \or\, \not\ on attributes) and full expressions with operators like \=\, \\<\, \\>\, \!=\, \member?\, and \exists?\. This change introduces a new \BooleanExpr\ type and a \PolicyExpression\ enum that can parse either format, along with a new \repl\ binary that provides an interactive command-line interface for testing and debugging these policy expressions.
_implementations/rust/ockam/ockam\abac/src · high confidence
New AI Platform API interface and client implementations
The \ockam\_api\ crate now exposes a new \AiPlatformApi\ trait and its implementations (\ControllerClient\ and \InMemoryNode\) within the \orchestrator/ai\_platform\ module. This adds the ability to manage AI infrastructure zones (create, list, delete, deploy), manage secrets, provision ECR credentials, and handle authentication via enrollment tickets, gateway tokens, and new development tokens. The change includes CBOR-serializable request and response structs for these operations, enabling the orchestrator to interact with external AI platform services.
_implementations/rust/ockam/ockam\_api/src/orchestrator/ai\platform · high confidence
New API clients for service discovery and static forwarding
Added two new API client modules to the Ockam Elixir implementation: \DiscoveryClient\ and \StaticForwardingClient\. The \DiscoveryClient\ provides functions to register service information and list available services, handling route extension with access routes. The \StaticForwardingClient\ allows workers to subscribe to the static forwarding service, returning the forwarder's address and route upon successful subscription. These clients interact with the underlying API via synchronous requests and handle standard response parsing and error mapping.
implementations/elixir/ockam/ockam/lib/ockam/api/client · high confidence
New API endpoint healthcheck target and metrics
The healthcheck module now supports checking HTTP API endpoints in addition to basic TCP connectivity. A new \APIEndpointTarget\ struct allows specifying HTTP method, path, and optional body for checks, while \ScheduledTarget\ parses these configurations. The core \Healthcheck\ module routes checks to either simple TCP pings or full API requests via secure channels, and \Metrics\ exposes detailed telemetry including status, success duration, and error duration with granular tags (target name, host, port, method, path, etc.) for monitoring.
_implementations/elixir/ockam/ockam\healthcheck/lib/healthcheck · high confidence
New API models for node resources, portals, and secure channels
The node API now exposes structured request and response types for managing node resources, secure channels, portals (inlets/outlets), relays, and services. Users can now interact with a unified \NodeResources\ model that aggregates transport, secure channel listener, inlet, outlet, and service statuses, and the API supports detailed configuration for inlets (including TLS, MPTCP, and policy expressions) and relays (with connection status and forwarding routes). Secure channel operations are now modeled with explicit create, delete, and show requests, and policy management is supported via typed \SetPolicyRequest\ and \PoliciesList\ responses.
_implementations/rust/ockam/ockam\api/src/nodes/models · high confidence
New CLI subcommands for managing share invitations
The \ockam share\ command group now includes subcommands to create, accept, list, show, and create service-specific sharing invitations. Users can generate invitations for Spaces or Projects (\create\), accept received invitations (\accept\), view their sent and received invitations (\list\), inspect details of a specific invitation (\show\), and create invitations that grant access to a specific service (\service\). These commands interact with the Ockam Orchestrator via the \InMemoryNode\ controller and support both plain-text and JSON output formats.
_implementations/rust/ockam/ockam\command/src/share · high confidence
New CLI utility modules for API requests, argument parsing, and validation
The \ockam\_command\ utility module now includes dedicated helpers for constructing API requests (such as listing secure channels, workers, and services), parsing user inputs (including hostnames, identifiers, and human-readable durations), and validating resource names. It also introduces a \ForegroundArgs\ struct to manage foreground node execution with signal handling and a standardized exit code system, improving the robustness and consistency of command-line interactions.
_implementations/rust/ockam/ockam\command/src/util · high confidence
New ContextRouter API for starting workers and processors
The ockam\_node crate now exposes a ContextRouter type that allows starting and stopping workers and processors without requiring a full Context instance with its own mailbox. This new API provides methods like start\_worker, start\_worker\_with\_access\_control, start\_processor, and start\_processor\_with\_access\_control, enabling more flexible node management and reduced resource overhead for scenarios where a dedicated worker context is not needed.
_implementations/rust/ockam/ockam\node · high confidence
New Elixir TCP transport implementation
This change introduces a new TCP transport layer for the Elixir implementation, adding core components including a listener (using Ranch), a client with heartbeat support, a recoverable client wrapper for automatic reconnection, and CBOR-based message serialization. It also defines address parsing, a configurable TCP wrapper behavior for telemetry, and a handler for incoming connections, enabling reliable TCP-based communication within the Ockam network.
implementations/elixir/ockam/ockam/lib/ockam/transport/tcp · high confidence
New Elixir examples for routing, secure channels, and TCP portals
The \implementations/elixir/examples\ directory now contains a comprehensive set of Elixir scripts demonstrating core Ockam capabilities. The \get\_started\ subdirectory provides progressive tutorials covering basic worker communication, multi-hop routing, TCP transport integration, and secure channel establishment with authenticated key exchange. Additionally, the \tcp\_inlet\_and\_outlet\ subdirectory includes examples for creating TCP inlets and outlets, both with and without secure channel encryption, allowing users to tunnel TCP traffic through the Ockam network.
implementations/elixir/examples · high confidence
New Elixir forwarding example demonstrating service registration and message routing
Added a new example module, Ockam.Examples.Forwarding, which demonstrates how to use the forwarding service on Ockam Services. This example includes a ServiceApi helper to register a local process with a remote forwarder and illustrates sending and receiving messages through a forwarding route between an initiator and a responder, either on the same node or across remote nodes.
implementations/elixir/ockam/ockam/lib/ockam/examples/forwarding · high confidence
New Kafka service provider with configurable interceptor and stream support
A new \Ockam.Services.Kafka.Provider\ module has been added to manage Kafka-related services, including \stream\_kafka\, \stream\_kafka\_index\, and a \kafka\_interceptor\. This provider allows users to configure Kafka stream connections with options for SASL authentication, SSL, and topic prefixes. It also introduces a customizable TCP portal interceptor that can spawn dynamic inlets and outlets, enabling flexible routing and authorization for Kafka traffic through Ockam portals.
_implementations/elixir/ockam/ockam\kafka/lib/services · high confidence
New Node Control API for managing relays, tickets, and authority members
The Node Control API now exposes HTTP endpoints to manage relays, tickets, and authority members. Users can create, list, and delete relays; generate enrollment tickets for project access; and add, update, list, or remove authority members. These capabilities are implemented in the new \control\_api/backend\ module, which routes requests to the appropriate handlers for each resource type.
_implementations/rust/ockam/ockam\_api/src/control\api/backend · high confidence
New Node Control API protocol definitions for relays, tickets, and authority members
The Node Control API now exposes structured request and response types for managing relays, tickets, and authority members, alongside updated schemas for TCP inlets and outlets. Users can now create, list, get, and remove authority members, create and manage enrollment tickets, and configure relays with specific routing and authorization constraints. The inlet and outlet protocols have been refined to support new fields such as the 'via' relay selector for inlets, optional 'kind' fields for outlet creation, and distinct TLS configuration options, all standardized through a common HostPort type that accepts both string and object formats.
_implementations/rust/ockam/ockam\_api/src/control\api/protocol · high confidence
New OIDC enrollment service with configurable authenticator endpoint
The enrollment module now includes a new \OidcService\ that manages OIDC authentication flows (PKCE and device code) to obtain tokens for connecting to the Orchestrator. This service supports pluggable OIDC providers, including a default \OckamOidcProvider\ and an \OktaOidcProvider\. The authenticator endpoint is now configurable via the \OCKAM\_AUTHENTICATOR\_ENDPOINT\ environment variable, defaulting to \https://account.autonomy.computer\, and the \OCKAM\_AUTH0\_CLIENT\_ID\ is required when using non-default endpoints. This change introduces a new mechanism for user authentication during enrollment, replacing previous hardcoded or less flexible approaches.
_implementations/rust/ockam/ockam\api/src/enroll · high confidence
New Ockam Healthcheck application with configurable targets and metrics reporting
A new Ockam healthcheck application has been added to the Elixir implementation. It periodically sends ping messages or API requests to configured Ockam nodes to verify their status, reporting results via Prometheus metrics and logs. Users can configure targets (including host, port, API paths, and schedules) and identity sources through application environment variables or environment variables like HEALTHCHECK\_TARGETS and HEALTHCHECK\_IDENTITY\_SOURCE.
_implementations/elixir/ockam/ockam\healthcheck · high confidence
New OpenTelemetry tracing and logging infrastructure
The API layer now includes a comprehensive module for configuring and exporting OpenTelemetry traces and logs. This introduces new environment variables (such as OCKAM\_TELEMETRY\_EXPORT and OCKAM\_LOGGING) to control whether telemetry is enabled, along with configuration for the collector endpoint, export timeouts, and queue sizes. The system supports exporting data via secure channels to project or authority nodes, and provides custom log formats for user-facing terminal output.
_implementations/rust/ockam/ockam\api/src/logs · high confidence
New Rust examples for file transfer and getting started
The Rust examples directory now includes a 'get\_started' project demonstrating core Ockam concepts such as node creation, worker messaging, multi-hop routing, TCP/UDP/Unix domain socket transports, secure channels, and credential exchange with attribute-based access control. Additionally, a 'file\_transfer' example has been added, showing how to implement secure file transfers between nodes using relays and secure channels, complete with integration tests.
implementations/rust/examples · high confidence
New Rust examples for file transfer, TCP MITM, and UDP rendezvous
This change introduces several new Rust example applications to the repository. The \file\_transfer\ example provides message types for serializing file descriptions and data chunks. The \get\_started\ example includes reusable worker components (echoer, hop, logger, relay) and utilities for managing Ockam project identities and enrollment tokens. A new \mitm\_node\ example demonstrates a TCP man-in-the-middle interceptor that listens on local ports and forwards traffic to a target. The \no\_std\ example provides embedded-friendly echo and hop workers with a custom tracing subscriber for logging on constrained targets. Finally, the \rendezvous\ example shows how to use UDP transport to connect to a remote echo server.
(repo-wide) · high confidence
New SQL-backed storage for resource and resource-type policies
The policy storage module now includes SQL repository implementations for resource policies, resource-type policies, and resource definitions, enabling persistent storage of ABAC policies in PostgreSQL and SQLite. These repositories scope data by node name and tenant ID, and support auto-retry for database operations. This change introduces the storage layer for these new policy types but does not include the schema migration scripts or the higher-level policy evaluation logic.
_implementations/rust/ockam/ockam\abac/src/policy/storage · high confidence
New TCP Inlet management commands (create, delete, list, show)
The CLI now includes a dedicated \tcp-inlet\ command group with subcommands to create, delete, list, and show TCP Inlets. The \create\ command allows users to configure the inlet's bind address, target route, relay, identity, and access policies, with support for TLS, MPTCP, and HTTP header injection. The \delete\ command supports deleting specific inlets by alias or all inlets at once, with optional confirmation. The \list\ and \show\ commands provide status and details of existing inlets. These commands interact with the node's background client to manage inlet state.
_implementations/rust/ockam/ockam\_command/src/tcp/inlet, implementations/rust/ockam/ockam\command/src/tcp/outlet · high confidence
New TCP listener management commands
The CLI now includes a dedicated \tcp-listener\ command group with subcommands to create, delete, list, and show TCP listeners. Users can create a listener at a specific address, list all active listeners on a node, view details of a specific listener, and delete a listener (with an optional confirmation prompt). These commands allow direct management of TCP listener resources on specified or default nodes.
_implementations/rust/ockam/ockam\command/src/tcp/listener · high confidence
New \`generate markdown\` command to export CLI documentation
A new \generate markdown\ command has been added to the Ockam CLI, allowing users to automatically export documentation for all existing commands into Markdown files. By default, these files are saved in a directory named after the binary (e.g., \ockam\_markdown\_pages\) in the current working directory, though a custom output path can be specified via the \--dir\ flag. The generated output includes a \SUMMARY.md\ index file and individual Markdown pages for each command, capturing usage instructions, arguments, options, and help text.
_implementations/rust/ockam/ockam\command/src/markdown · high confidence
New \`ockam admin\` command for managing subscriptions
A new \ockam admin\ command group has been introduced to centralize administrative operations, specifically focusing on subscription management. This command exposes subcommands to attach subscriptions via JSON configuration, list all current subscriptions, unsubscribe by ID or space, and update subscription contact information or move subscriptions between spaces. These administrative capabilities are now distinct from standard user-facing node commands, providing a dedicated interface for managing cloud orchestrator subscriptions.
_implementations/rust/ockam/ockam\command/src/admin · high confidence
New \`ockam authority create\` command to provision authority nodes
Users can now run \ockam authority create\ to start a new authority node, which issues and verifies cryptographically signed credentials, creates enrollment tokens, and authenticates identities as project members. The command accepts options to configure the TCP listener address, specify the project identifier, preload trusted identities with attributes, and manage enrollment policies (such as disabling direct authentication or token enrollment). It also supports Okta integration for attribute retrieval and allows administrators to enforce distinctions between admin and enroller roles.
_implementations/rust/ockam/ockam\command/src/authority · high confidence
New \`ockam status\` command displays Orchestrator resources and project details
A new \status\ command has been added to the CLI, providing a comprehensive overview of your Ockam instance. It now displays the Ockam and Orchestrator versions, lists your Spaces and Projects, shows cryptographic Identities and their enrollment status, and provides details on available Nodes such as routes, protocols, and listeners.
_implementations/rust/ockam/ockam\command/src/status · high confidence
New \`project-member\` command for managing project membership
A new \project-member\ subcommand has been added to the CLI, providing a dedicated interface for managing members on a Project Membership Authority node. This command includes five subcommands: \add\ to enroll new members with optional relay and enroller attributes, \delete\ to remove specific members or all members (except the current identity) using the \--all\ flag, \list\ to display member details and attributes, \list-ids\ to output only member identifiers, and \show\ to view the details of a specific member. This centralizes project membership operations that were previously handled by other commands or APIs.
_implementations/rust/ockam/ockam\_command/src/project\member · high confidence
New \`rendezvous create\` command to start a foreground Rendezvous server
Users can now start a local Rendezvous server directly from the command line using the new \rendezvous create\ command. This command launches the server in the foreground, binding a UDP listener (defaulting to 0.0.0.0:4000) for rendezvous services and a TCP listener (defaulting to 0.0.0.0:4001) for health checks. The process runs until interrupted (e.g., via Ctrl+C), ensuring the server and its health check components are cleanly stopped upon exit.
_implementations/rust/ockam/ockam\command/src/rendezvous/create · high confidence
New background node client and HTTP status server
The node service layer now includes a \BackgroundNodeClient\ to send requests to running background nodes, and an HTTP server that exposes a \/show\ endpoint to return node resources for health checks and monitoring.
_implementations/rust/ockam/ockam\api/src/nodes/service · high confidence
New bi-directional stream examples for local and secure channel communication
Added two new example modules, \local.ex\ and \secure\_channel.ex\, demonstrating bi-directional stream communication between 'ping' and 'pong' nodes. The local example shows how to use local subscriptions and publishers to exchange messages via the stream service. The secure channel example extends this by establishing an ordered channel over the stream and creating a secure channel for encrypted message exchange, illustrating the integration of \PipeChannel\, \IndexPipe\, and \SecureChannel\ components.
_implementations/elixir/ockam/ockam/lib/ockam/examples/stream/bi\directional · high confidence
New centralized tooling and build infrastructure
This change introduces a comprehensive suite of new configuration files and scripts under the \tools/\ directory to standardize development and release workflows. It adds a Nix flake for reproducible, multi-language development environments (Rust, Elixir, Python), a \cargo-deny\ configuration to enforce license and dependency security policies, and a \commitlint\ configuration to enforce conventional commit message standards. Additionally, it provides Dockerfiles and Chainguard/Wolfi YAML definitions for building distroless images for the Ockam command, cloud node, healthcheck, and rendezvous services, alongside scripts for documentation verification and profiling.
tools · high confidence
New configuration modules for address lookup and URL parsing
The \ockam\_api\ configuration module has been expanded with new components to handle address resolution and environment variable parsing. A new \lookup\ module introduces an \InternetAddress\ abstraction that standardizes DNS, IPv4, and IPv6 addresses, automatically converting them to multiaddresses and tracking project names during lookups. Additionally, a \url\_var\ module provides a \UrlVar\ type for safely parsing URL strings from environment variables, ensuring robust configuration handling for network endpoints.
_implementations/rust/ockam/ockam\api/src/config · high confidence
New credential issuer worker for project members and admins
A new credential issuer worker has been added to the authenticator module, enabling the system to issue credentials specifically for project members and administrators. The worker exposes a POST endpoint at /credential that validates requests via secure channels and delegates issuance to a core issuer logic. This logic distinguishes between admin users (identified by the 'ockam-tls-certificate' attribute) and regular members, applying appropriate attributes and TTLs (defaulting to 30 days) to the issued credentials. It also supports a legacy trust context ID for backward compatibility, which can be disabled via configuration.
_implementations/rust/ockam/ockam\_api/src/authenticator/credential\issuer · high confidence
New credential management commands (issue, list, store, verify)
The CLI now includes a dedicated \credential\ command group with four subcommands: \issue\ to create credentials with configurable TTL and attributes, \list\ to display stored credentials filtered by subject or issuer, \store\ to persist verified credentials into the local node database, and \verify\ to validate credential signatures. These commands replace previous ad-hoc credential handling, providing structured output (plain, JSON, machine-readable) and integrating with the new CLI state abstraction for vault and identity resolution.
_implementations/rust/ockam/ockam\command/src/credential · high confidence
New enrollment token issuer and acceptor workers
The authenticator module now includes dedicated workers for issuing and accepting enrollment tokens. The issuer worker handles requests to create one-time codes with configurable duration and usage limits, while the acceptor worker validates and consumes these tokens to add new members to an authority. This introduces a new, reusable token-based enrollment mechanism alongside the existing direct authentication methods.
_implementations/rust/ockam/ockam\_api/src/authenticator/enrollment\tokens · high confidence
New environment command to display CLI configuration
The Ockam CLI now includes an \environment\ command that outputs information about the environment variables used by the CLI. When run, it displays a static informational message followed by a list of runtime environment variables containing 'OCKAM' in their name, as well as compile-time branding variables. This allows users to easily inspect the current configuration and environment state of their Ockam CLI installation.
_implementations/rust/ockam/ockam\command/src/environment · high confidence
New identity management commands (create, list, show, delete, import, export)
The CLI now provides a comprehensive set of commands for managing local identities. Users can create new identities (optionally importing from hex or using a specific key ID), list all stored identities with JSON output support, view detailed identity information including change history, set a default identity, delete identities (with confirmation prompts), and export/import identities for portability. These commands replace the previous implicit identity handling, giving users explicit control over their identity lifecycle and storage.
_implementations/rust/ockam/ockam\command/src/identity · high confidence
New interactive enrollment flow with OIDC and email verification
The \ockam enroll\ command now implements a complete interactive enrollment workflow using OpenID Connect (OIDC). Users authenticate via a device code flow that opens their browser, with the one-time code automatically copied to the clipboard for convenience. The command now supports PKCE authorization and waits for email verification before completing the process. New flags allow users to force re-enrollment (\--force\) or bypass the interactive browser step if they already have an authorization code (\--authorization-code-flow\). The command also provides a \--skip-resource-creation\ flag to check enrollment status without creating new Orchestrator resources, and it correctly handles cases where the identity is already enrolled by displaying a status message instead of failing.
_implementations/rust/ockam/ockam\command/src/enroll · high confidence
New messaging examples demonstrating reliable delivery, ordering, and deduplication
Added example modules in the messaging directory that showcase how to use delivery pipes, ordering pipes, and reliable deduplication channels. The new \Delivery\ example illustrates reliable message delivery by comparing it against an unreliable path using a filter worker that randomly drops messages. The \Ordering\ example demonstrates how to maintain message sequence integrity using strict and monotonic ordering pipes, contrasting them with a shuffle worker that reorders messages. Additionally, the \ReliableDeduplication\ example shows how to combine resend pipes with index-ordering pipes to achieve low message loss and high uniqueness, supporting both local and cloud-based scenarios via TCP recoverable clients.
implementations/elixir/ockam/ockam/lib/ockam/examples/messaging · high confidence
New modular access control system with caching and composition
The \ockam\_core\ crate now provides a structured access control framework, splitting authorization into distinct \IncomingAccessControl\ and \OutgoingAccessControl\ traits. This allows developers to define granular policies, such as \AllowSourceAddress\ for incoming messages or \AllowOnwardAddress\ for outgoing routes, and combine them using logical \All\ (AND) or \Any\ (OR) wrappers. To improve performance, the system also includes a \CachedIncomingAccessControl\ and \CachedOutgoingAccessControl\ that memoize successful authorizations for one second, reducing redundant checks for repeated message patterns.
_implementations/rust/ockam/ockam\core · high confidence
New node management API module with secure channel and service registries
The \ockam\_api\ crate now exposes a dedicated \nodes\ module that centralizes the Node Manager service and its supporting registries. This change introduces a \SecureChannelRegistry\ for tracking active secure channels and a general \Registry\ to manage various node services (such as TCP inlets/outlets, Kafka services, and relay information). The module also defines the internal node manager address (\\_internal.nodemanager\) and re-exports the core \NodeManager\ and \NodeManagerWorker\ types, providing a structured foundation for node lifecycle and service management within the API layer.
_implementations/rust/ockam/ockam\api/src/nodes · high confidence
New pluggable messaging pipe and channel framework
The messaging layer now supports pluggable delivery pipes and channels, allowing users to select specific delivery guarantees for their sessions. This change introduces a \Pipe\ behavior and several implementations: \ResendPipe\ for reliable delivery with automatic retransmission on timeout, and \IndexPipe\ variants (Monotonic and Strict) for enforcing message ordering via sequence indices. These pipes are integrated into the \PipeChannel\ framework, which manages the session handshake and data forwarding, enabling users to configure channels with different reliability and ordering properties.
implementations/elixir/ockam/ockam/lib/ockam/messaging · high confidence
New project addon management commands and integrations
Users can now manage cloud addons for Ockam projects via new CLI subcommands: \project addon list\ to view enabled addons, \project addon disable\ to remove them, and \project addon configure\ to set up specific integrations. The configuration command supports InfluxDB Cloud (for automated token lease management), Okta (for enterprise OIDC credential issuance with user profile attributes), and multiple Apache Kafka providers including Confluent, Aiven, Instaclustr, Redpanda, and WarpStream (for end-to-end encrypted data in motion).
_implementations/rust/ockam/ockam\command/src/project/addon · high confidence
New project management API and client implementation
The orchestrator module now includes a complete set of files to manage projects, including models, client logic, and API definitions. Users can now create, retrieve, and delete projects, as well as manage space and project administrators. The implementation also introduces support for listing project relays and exposes orchestrator version information through the new API surface.
_implementations/rust/ockam/ockam\api/src/orchestrator/project · high confidence
New relay service with authority-based access control and aliasing
The relay service now supports creating named relay aliases with configurable access controls and optional authority validation. Users can configure incoming access for both the service and its spawned relays, set service prefixes, and define aliases. When an authority is configured, relay creation requests are validated against the requester's identity attributes (specifically the 'ockam-relay' attribute), allowing or denying relay names based on policy. Existing relays with the same name are automatically stopped and replaced before creating the new one.
_implementations/rust/ockam/ockam/src/relay\service · high confidence
New request-response API client and protocol structures
The Ockam API layer now includes a dedicated request-response client (\Ockam.API.Client\) that sends synchronous HTTP-style requests (GET, POST, PUT, DELETE, PATCH) over Ockam routes. This change introduces new \Ockam.API.Request\ and \Ockam.API.Response\ modules that define the protocol schema using minicbor bare encoding, supporting request IDs, paths, methods, optional bodies, and tracing context. The client handles encoding/decoding of these structures and manages routing via \Ockam.Workers.Call\, enabling structured request-response communication patterns previously handled by lower-level message passing.
implementations/elixir/ockam/ockam/lib/ockam/api · high confidence
New secure-channel-listener CLI commands (create, delete, list, show)
The CLI now includes a dedicated \secure-channel-listener\ command group with four subcommands: \create\ (accepts an address, optional authorized identifiers, and an optional identity name), \delete\ (removes a listener by address), \list\ (displays all listeners on a node), and \show\ (displays details for a specific listener). These commands interact with the node via the background node client and use the new \NodeOpts\ for node targeting, providing a consistent interface for managing secure channel listeners.
_implementations/rust/ockam/ockam\_command/src/secure\channel/listener · high confidence
New service management commands for listing and starting services
Users can now manage node services via the new \ockam service\ command group, which includes \service list\ to display the status of services running on a node and \service start\ to initiate services like the Hop service. The \service start\ command also displays a security warning when starting the Hop service in production. Additionally, a new configuration file format (\service/config.rs\) allows users to define startup services, including secure-channel listeners and control API settings, supporting both YAML and JSON formats.
_implementations/rust/ockam/ockam\command/src/service · high confidence
New session-based example applications for routing and piped channels
Added example applications in the session module that demonstrate the new framework for separating session handshake and data stages. The \count\_to\ example implements a multi-message handshake protocol to initialize a data worker, while the \routing\ and \pipe\_channel\ examples showcase session establishment with simple forwarding and reliable piped messaging respectively, providing concrete usage patterns for the updated session architecture.
implementations/elixir/ockam/ockam/lib/ockam/examples/session · high confidence
New stream example demonstrating Kafka-backed streaming with index management
Added new example code in the stream module that demonstrates a Kafka-backed streaming service. This includes an index API for managing stream offsets (get/save index), a main stream API for creating streams and pushing/pulling messages, and a full end-to-end example showing how to initialize a publisher and consumer, route messages, and handle incoming data via a receiver worker.
implementations/elixir/ockam/ockam/lib/ockam/examples/stream · high confidence
New synchronous call, pub/sub subscriber, and remote forwarding workers
This change introduces three new worker implementations in the Elixir library to expand communication patterns. The new \Ockam.Workers.Call\ module enables synchronous request-response interactions by routing a payload to a target worker and waiting for a reply within a specified timeout. \Ockam.Workers.PubSubSubscriber\ provides a resilient way to subscribe to topics via the pub/sub service, automatically refreshing the subscription at configurable intervals to handle service restarts or connection drops. Finally, \Ockam.Workers.RemoteForwarder\ allows nodes to register with a central forwarding service, enabling messages sent to a specific cloud address to be routed through the service and delivered to a local route on the target node.
implementations/elixir/ockam/ockam/lib/ockam/workers · high confidence
New tcp-test tool for measuring portal network properties
A new Rust-based CLI tool (\tcp-test\) has been added to the \tools/tcp-test\ directory to help measure and validate portal network performance. It provides subcommands to run TCP echo and null servers, measure connection latency, test connection flood resilience, and benchmark TCP throughput. The tool supports both plain TCP and TLS connections (using \rustls\ with a custom no-validation verifier for testing), allows configuration of buffer sizes and pool counts, and includes options to run throughput tests for a specific duration or count.
tools/tcp-test · high confidence
New user journey tracking with time-limited traces
The CLI state now records user actions (such as identity creation, node setup, and command execution) as OpenTelemetry spans within structured 'journeys'. These journeys are split into host-level and project-level traces, with trace IDs generated from machine identifiers or project IDs and rotated every five days to keep traces time-limited. Each event is a fixed-duration span enriched with attributes like Ockam version, git hash, and node name, providing better observability into user workflows.
_implementations/rust/ockam/ockam\_api/src/cli\state/journeys · high confidence
New worker message authorization module
A new \Ockam.Worker.Authorization\ module has been added to provide helper functions for configuring how workers authorize incoming messages. This module introduces a composable pipeline of authorization steps, allowing developers to define rules such as allowing or denying all messages, restricting access by source or destination addresses, validating message metadata, and enforcing secure channel or identity-based checks. This enables more granular control over which messages a worker is permitted to process.
implementations/elixir/ockam/ockam/lib/ockam/worker · high confidence
Node configuration now supports declarative resource definitions
Users can now define Ockam resources directly within node configuration files, allowing the system to automatically create and configure identities, vaults, nodes, policies, relays, TCP and InfluxDB inlets/outlets, Kafka inlets/outlets, and project enrollments. This new parser layer in the command runner interprets YAML resource blocks (such as \identities\, \nodes\, \tcp\_inlets\, \kafka\_inlet\, etc.) and translates them into the corresponding CLI commands, enabling fully declarative node setup without manual command invocation.
_implementations/rust/ockam/ockam\command/src/run/parser/resource · high confidence
Node creation now supports configuration files and inline configurations
The \ockam node create\ command now accepts a \--configuration\ argument (and treats the first positional argument as a configuration source) to define node settings via YAML or JSON files, or inline strings. This allows users to declaratively specify node names, TCP listeners, relays, inlets, outlets, and other services in a single configuration block. Command-line arguments take precedence over configuration file values, and the command supports both foreground and background execution modes when using configurations. Demo configuration files are provided to illustrate common setups.
_implementations/rust/ockam/ockam\command/src/node/create · high confidence
Okta identity provider integration with certificate pinning
The Okta API module now implements an identity provider that authenticates users via Okta's Device Flow. Upon successful token validation, the system retrieves user information from the Okta tenant and persists custom attributes (such as email or name) into the authority's member table. To enhance security, the integration enforces certificate pinning by validating the Okta tenant's TLS certificate against a provided root certificate, rejecting connections that do not match.
_implementations/rust/ockam/ockam\api/src/okta · high confidence
Persistent local storage for CLI state via SQL repositories
The CLI state management has been migrated from file-based storage to a structured SQL database (supporting SQLite and PostgreSQL). This change introduces a new \storage\ module containing repository traits and SQL implementations for persisting identities, enrollments, nodes, projects, spaces, journeys, and vaults. Users benefit from more robust state persistence, including automatic retry handling for database deadlocks, tenant-based data isolation, and the ability to store additional metadata such as enrollment emails and OpenTelemetry tracing contexts for project journeys.
_implementations/rust/ockam/ockam\_api/src/cli\state/storage · high confidence
Protocol-aware Kafka message interception and decoding
The Kafka service now includes a protocol-aware layer that intercepts, decodes, and re-encodes Kafka messages passing through inlets and outlets. This change introduces a \KafkaMessageDecoder\ to handle length-delimited message framing and a \KafkaMessageInterceptorWrapper\ that implements the \PortalInterceptor\ trait to process requests and responses. The implementation supports multiple Kafka API versions (tested up to version 13) and allows for future extensibility, such as field-level encryption, by intercepting messages at the protocol level rather than just forwarding raw bytes.
_implementations/rust/ockam/ockam\_api/src/kafka/protocol\aware · high confidence
Service discovery now supports CBOR-encoded service info
The discovery API introduces a new \ServiceInfo\ structure that enables encoding and decoding service metadata using CBOR (via minicbor). This change allows the discovery service to serialize and deserialize service details—including ID, route, and metadata—into a compact binary format, facilitating more efficient network communication for service discovery and forwarding.
implementations/elixir/ockam/ockam/lib/ockam/api/discovery · high confidence
Software Vault implementation restructured with modular traits and configurable crypto backends
The \ockam\_vault\ crate now provides a concrete software implementation of the Vault traits, organized into distinct modules for secure channels, signing, and signature verification. This change introduces a modular architecture where the underlying cryptographic library for secure channels can be selected via feature flags (\aws-lc\ or \rust-crypto\), allowing users to choose between \aws-lc-rs\ and \aes-gcm\ for AES operations. The implementation also defines specific secret types (such as \X25519SecretKey\ and \SigningSecret\) and error handling (\VaultError\) tailored for software-based cryptographic operations, replacing previous generic or hardware-coupled approaches with a standardized, configurable software vault.
_implementations/rust/ockam/ockam\vault · high confidence
Support for UDP and MPTCP in multiaddress resolution
The multiaddress resolver now supports UDP and Multipath TCP (MPTCP) transport protocols in addition to TCP. This allows nodes and portals to establish connections using these protocols, enabling more flexible and resilient networking paths. The resolver handles both local and remote multiaddresses, ensuring that UDP and MPTCP hops are correctly interpreted and routed.
_implementations/rust/ockam/ockam\_api/src/multiaddr\resolver · high confidence
TCP transport now supports Multipath TCP (MPTCP)
The \ockam\_transport\_tcp\ crate now includes MPTCP support, allowing TCP connections to utilize multiple network paths for improved reliability and throughput. This feature is exposed via new \enable\_mptcp()\ methods on \TcpConnectionOptions\, \TcpListenerOptions\, \TcpInletOptions\, and \TcpOutletOptions\, as well as dedicated \mptcp\ module exports (\connect\_mptcp\, \bind\_mptcp\). The implementation includes platform-specific socket builders for Linux and macOS/Darwin, with runtime checks to verify if the OS supports MPTCP.
_implementations/rust/ockam/ockam\_transport\tcp · high confidence
TypedStruct plugin for automatic CBOR encoding and decoding
The ockam\_typed\_cbor library now includes a TypedStruct plugin that automatically generates encode and decode functions for structs. By annotating struct fields with a :minicbor option, developers can seamlessly serialize and deserialize data to/from CBOR format without writing manual conversion logic. The plugin supports various data types, including lists, maps, and enums, and validates that field keys are sequential integers when encoding as a list.
_implementations/elixir/ockam/ockam\_typed\_cbor/lib/typed\cbor · high confidence
UDP transport now supports NAT hole punching and message segmentation
The UDP transport crate now includes a full implementation of UDP puncturing (NAT hole punching) via a rendezvous service, allowing direct peer-to-peer connections through firewalls. It also introduces message segmentation, enabling routing messages larger than a single UDP datagram to be split into multiple transport messages and reassembled by the receiver. These changes are supported by new error types for segmentation issues and negotiation failures, as well as updated flow control and access control mechanisms for the new workers.
_implementations/rust/ockam/ockam\_transport\udp · high confidence
ockam\_api crate documentation and build configuration added
The ockam\_api crate now includes a CHANGELOG.md documenting changes from version 0.93.0 through 0.100.0, a README.md providing usage instructions and configuration details for the NodeManager, and a build.rs script that sets the GIT\_HASH environment variable and defines the privileged\_portals\_support configuration flag for Linux targets with the privileged\_portals feature enabled.
_implementations/rust/ockam/ockam\api · high confidence
Behavioural changes
68 commits (14 fixes) modifying implementations/rust/ockam/ockam\_command/src/zone
A change to existing behaviour in implementations/rust/ockam/ockam\_command/src/zone — 68 commits (14 fixs), 48 files.
_implementations/rust/ockam/ockam\command/src/zone · medium confidence · unverified
Authority node service startup and configuration
The authority node now explicitly manages the lifecycle of its core services through a dedicated \start\_node\ function in \node.rs\, which initializes the secure channel listener, direct authenticator, enrollment services, credential issuer, optional Okta integration, echo service, and gRPC telemetry forwarder. The \Configuration\ struct in \configuration.rs\ defines the necessary parameters for these services, including database settings, listener addresses, and optional Okta configuration, while \authority.rs\ implements the \Authority\ struct that holds the identity, secure channels, and repositories for members and tokens, providing methods to create the authority and start individual services.
_implementations/rust/ockam/ockam\_api/src/authority\node · high confidence
Authority storage now isolates data by tenant
The Authority node's storage layer for enrollment tokens and project members has been updated to include a \tenant\_id\ column in the underlying database schemas. This change ensures that data for different tenants is fully separated, preventing cross-tenant data leakage. The SQL implementations for \AuthorityEnrollmentTokenRepository\ and \AuthorityMembersRepository\ now bind the current database tenant ID to all insert and update operations, and use it in conflict resolution strategies.
_implementations/rust/ockam/ockam\api/src/authenticator/storage · high confidence
Bidirectional streaming support with reliable message handling
The stream client now supports bidirectional communication, allowing consumers to send messages back through a return stream. This is implemented via new \BiDirectional\, \Consumer\, and \Publisher\ modules that manage subscription, message routing, and encoding. To ensure reliability, the client now handles timeouts on synchronous requests; if a push request times out, unconfirmed messages are tracked and resent, and the stream route is re-established upon timeout.
implementations/elixir/ockam/ockam/lib/ockam/stream/client · high confidence
Configurable healthcheck targets and identity sources via environment variables
The Ockam Healthcheck application now supports runtime configuration through environment variables, allowing users to define which services are monitored and how identity is managed without code changes. Users can set \HEALTHCHECK\_TARGETS\ to specify the list of targets to check, and \HEALTHCHECK\_IDENTITY\_SOURCE\ to switch between \function\ (default) and \file\ modes for identity retrieval. When using file-based identity, \HEALTHCHECK\_IDENTITY\_FILE\ and \HEALTHCHECK\_IDENTITY\_SIGNING\_KEY\_FILE\ can be provided. Additionally, Prometheus metrics are enabled by setting \PROMETHEUS\_PORT\, and the application includes improved error handling for invalid configuration inputs.
_implementations/elixir/ockam/ockam\healthcheck/config · high confidence
Default service configuration and test isolation for Ockam Services
The Ockam Services application now includes explicit configuration files that define default runtime behavior. In production and development environments, the service starts with a standard set of providers including Routing, Stream, Token Lease Manager, Secure Channel, Discovery, Node Info, and Sidecar, listening on TCP port 4000 and UDP port 7000. For testing, the configuration explicitly disables all services and transports by default, ensuring that tests do not inadvertently start background services unless specifically configured otherwise.
_implementations/elixir/ockam/ockam\services/config · high confidence
Improved human-readable output for cryptographic keys and credentials
The \ockam\_command\ tool now provides clearer, structured text output for identity-related commands. A new output module formats X25519, Ed25519, and P-256 public keys with explicit prefixes (e.g., "X25519:") and displays purpose-specific keys (Secure Channel vs. Credential Signing) with descriptive labels. Additionally, credentials and purpose key attestations are now rendered with detailed fields including version, subject, change hashes, creation/expiry times, and attributes, replacing previous less informative formats.
_implementations/rust/ockam/ockam\command/src/output · high confidence
Introduce TUI traits for interactive Show and Delete commands
The terminal module now exposes \ShowCommandTui\ and \DeleteCommandTui\ traits, enabling commands to render interactive user interfaces. For \Show\ commands, users can now select multiple items from a list via a terminal prompt when no specific item is requested. For \Delete\ commands, the system supports confirmation prompts and bulk deletion operations, allowing users to review and confirm actions before items are removed.
_implementations/rust/ockam/ockam\command/src/terminal · high confidence
Introduce ockam\_rust\_elixir\_nifs library with AWS-LC and credential schema support
The \ockam\_rust\_elixir\_nifs\ library (renamed from \ockly\) is now available as a standalone Elixir package (v0.117.0) that wraps Rust NIFs for identity management, secure channels, and credential handling. This update enables the \aws-lc\ cryptographic feature for the underlying Rust crate and exposes the credential schema ID in credential-related NIF calls, allowing applications to explicitly specify and verify credential schemas. The library includes precompiled binaries for macOS and Linux, configurable via the \OCKAM\_VAULT\_AWS\ environment variable to enable AWS KMS integration.
_implementations/elixir/ockam/ockam\_rust\_elixir\nifs · high confidence
Introduce sharded in-memory storage for stream index operations
The stream index service now uses a sharded architecture to manage index data, replacing the previous monolithic approach. A new \Ockam.Stream.Index.Service\ coordinates multiple \Shard\ workers, each handling storage for a specific client and stream combination. These shards delegate to an in-memory storage implementation (\Ockam.Stream.Index.Storage.Internal\) that persists index values in process state, allowing for concurrent, partitioned access to stream metadata without external dependencies.
implementations/elixir/ockam/ockam/lib/ockam/stream/index · high confidence
Introduce structured vault management commands
The vault subcommand is restructured into distinct operations: create, delete, list, show, and move. Users can now create named vaults (optionally using AWS KMS), list all available vaults, view details of a specific or default vault, delete vaults (with confirmation), and move a vault's storage path. Output is standardized across commands, supporting plain text, machine-readable, and JSON formats.
_implementations/rust/ockam/ockam\command/src/vault · high confidence
Introduction of environment-specific configuration files
The application now uses dedicated configuration files for development, production, and test environments (dev.exs, prod.exs, test.exs), imported via a central config.exs. The main config file sets up console logging metadata (module, line, pid) and conditionally loads the environment-specific file, ensuring that configuration is applied correctly during releases and mix runs while remaining isolated when the app is used as a dependency.
implementations/elixir/ockam/ockam/config · high confidence
Kafka command module initialization with safe broker port range calculation
The Kafka command module has been initialized in the ockam\_command crate, introducing the core structure for Kafka-related CLI operations. A key addition is the \make\_brokers\_port\_range\ function, which calculates a safe range of ports for Kafka brokers based on the bootstrap server's port, explicitly preventing arithmetic overflows by capping the range at the maximum 16-bit unsigned integer value (u16::MAX). This ensures that users connecting to Kafka services with high port numbers do not encounter errors due to port range calculation failures.
_implementations/rust/ockam/ockam\command/src/kafka · high confidence
Kafka producer and consumer commands are deprecated in favor of kafka-inlet
The \kafka-producer\ and \kafka-consumer\ command groups (including create, delete, and list subcommands) are now hidden and marked as deprecated. When users run these commands, they will receive a warning directing them to use the \kafka-inlet\ command instead. The deprecated commands now act as thin wrappers that delegate their logic to the corresponding \kafka-inlet\ implementations, ensuring existing workflows continue to function while encouraging migration to the unified inlet service.
_implementations/rust/ockam/ockam\command/src/kafka/producer · high confidence
New Elixir Secure Channel implementation with identity-based handshake and CBOR serialization
The Elixir secure channel has been replaced with a new implementation that establishes connections using a 3-packet handshake involving identity proofs and credential exchange. This change introduces CBOR-based serialization for secure channel messages, including support for message padding and credential refresh, and integrates with the updated identity design to allow users to specify trust policies and authorities during channel creation.
_implementations/elixir/ockam/ockam/lib/ockam/secure\channel · high confidence
New credential management and retrieval services in ockam\_identity
The \ockam\_identity\ crate now exposes structured services for issuing, verifying, and retrieving credentials. A new \Credentials\ service aggregates creation and verification logic, while the \credentials\ module introduces three distinct retriever implementations: \CachedCredentialRetriever\ for local storage, \MemoryCredentialRetriever\ for in-memory access, and \RemoteCredentialRetriever\ for fetching credentials from external authorities via secure channels. This refactors credential handling into a modular system that supports proactive refresh, clock-skew tolerance, and subscriber notifications for credential updates.
_implementations/rust/ockam/ockam\identity · high confidence
New identity, identifier, and trust policy abstractions
The identity module now introduces a dedicated \Identifier\ type for representing identity keys, alongside a refactored \Identity\ struct that exposes methods for creation, import, and credential operations (issuing and verifying). A new \TrustPolicy\ module provides configurable trust rules, including specific policies for \known\_identity\ and \cached\_identity\ checks against a \KnownIdentities\ storage backend (currently implemented via ETS). These changes establish the foundational data structures and trust logic for identity management within the Ockam Elixir library.
implementations/elixir/ockam/ockam/lib/ockam/identity · high confidence
New pluggable session architecture with separate handshake and data stages
The session layer now uses a new pluggable architecture that explicitly separates the connection handshake phase from the data transfer phase. New \Ockam.Session.Pluggable.Initiator\ and \Responder\ modules manage this lifecycle, allowing developers to inject custom handshake logic via the \handshake\_mod\ option while delegating all subsequent message processing to a configurable \data\_worker\_mod\. This change provides a structured way to handle secure channel establishment and credential exchange before switching to the data stage.
implementations/elixir/ockam/ockam/lib/ockam/session/pluggable · high confidence
New session monitoring and replacement infrastructure
The session management layer has been restructured to include a dedicated monitoring system that tracks connection health via periodic pings and automatically handles session failures. This change introduces a \SessionReplacer\ mechanism that detects when a session goes down and attempts to recreate it, ensuring more reliable connectivity for inlets and relays. The new architecture separates the core session logic into distinct modules for status tracking, ping collection, and replacement coordination, providing a robust foundation for maintaining persistent connections in the node manager.
_implementations/rust/ockam/ockam\api/src/session · high confidence
New terminal UI subsystem with optional full-feature support
The terminal output layer has been restructured into a new \ui/terminal\ module within \ockam\_api\. This introduces a \Terminal\ abstraction that standardizes command output formatting, including colored icons for success, warning, and error states, and dynamic separator lines that adapt to the terminal width. A new \NotificationHandler\ manages asynchronous progress bars and status messages. The system supports a \ui\ feature flag: when enabled, it utilizes the \r3bl\_tuify\ library for advanced terminal sizing and interaction; when disabled, it falls back to a lightweight implementation using \dialoguer\ and \syntect\ for syntax highlighting, ensuring the CLI remains functional without the heavier UI dependencies.
_implementations/rust/ockam/ockam\api/src/ui/terminal · high confidence
New transport model definitions and CBOR serialization
The transport API models have been restructured into a new module under \ockam\_api/src/nodes/models/transport\. This introduces explicit data structures for transport requests (\CreateTcpConnection\, \CreateTcpListener\, \DeleteTransport\) and responses (\TransportStatus\, \TransportStatusList\), all serialized using CBOR. It also adds a \BindAddress\ helper that supports binding to an explicit port or automatically falling back to a random port if the specified one is in use, and defines \TransportType\ and \TransportMode\ enums to standardize how transport directions and types are encoded and displayed.
_implementations/rust/ockam/ockam\api/src/nodes/models/transport · high confidence
Ockam Cloud Node configuration is now environment-driven
The Ockam Cloud Node (formerly Ockam Hub Node) now relies on runtime environment variables for its configuration, replacing static config files. Users can now control TCP/UDP ports, Kafka endpoints and authentication (including reading credentials from /mnt/secrets), identity implementation (sidecar vs. stub), enabled services, cleanup schedules, ABAC policy storage, and Prometheus metrics via environment variables. This change supports flexible deployment and sidecar integration without requiring code or config-file changes.
_implementations/elixir/ockam/ockam\_cloud\node/config · high confidence
Ockam application now conditionally starts telemetry
The Ockam application's startup logic has been updated to conditionally ensure the \:telemetry\ application is started only if the \:telemetry\ module is loaded. This change allows the core Ockam functionality (starting the Router and Node supervisors) to proceed without requiring telemetry, making telemetry an optional dependency for users who do not need it.
implementations/elixir/ockam/ockam/lib · high confidence
Orchestrator module reorganization and new API models
The \orchestrator\ module has been restructured, introducing new data models and API client implementations for managing spaces, subscriptions, addons, and enrollment tokens. Users will see updated command outputs including project details in the status command and proper formatting for Platinum subscriptions. The module now exposes methods to retrieve subject attributes directly from an authority and supports MPTCP between nodes and inside portals. Additionally, the orchestrator UI URL can be controlled via an environment variable, and AI-related commands for enrollment and ticketing are now available.
_implementations/rust/ockam/ockam\api/src/orchestrator · high confidence
Policy management commands renamed and restructured
The policy management CLI interface has been reorganized: the previous \ockam policy set\ and \ockam policy get\ commands are now \ockam policy create\ and \ockam policy show\, respectively, with new dedicated subcommands for \list\ and \delete\. The \--node\ argument has been renamed to \--at\ across all policy commands. The \policy create\ command now accepts a boolean policy expression via the \--allow\ (or \--expression\) flag and supports both specific resources and resource types. The \policy delete\ command now includes a confirmation prompt (overridable with \-y\) to prevent accidental deletions. Output formatting has been standardized, with \policy list\ and \policy show\ providing both plain text and JSON output.
_implementations/rust/ockam/ockam\command/src/policy · high confidence
Refactored 'ockam run' configuration parsing with variable expansion and flexible resource naming
The parsing logic for the \ockam run\ command has been rewritten to support a new \variables\ section in configuration files, allowing users to define custom variables that are expanded into environment variables before parsing. The parser now supports defining resources (such as nodes) without explicit names, automatically assigning them random identifiers, and allows multiple values in configuration entries. Additionally, the parser handles JSON comments and ensures that command-line arguments take precedence over configuration file values.
_implementations/rust/ockam/ockam\command/src/run/parser · high confidence
Reset command now supports deleting Orchestrator spaces
The \reset\ command has been updated to optionally remove spaces from the Orchestrator when the \--all\ flag is used. This action is restricted to developer builds (controlled by the \OCKAM\_DEVELOPER\ environment variable) to prevent accidental data loss. When enabled, the command prompts for confirmation, displays progress while deleting spaces, and allows the user to proceed with clearing local state even if the remote deletion fails.
_implementations/rust/ockam/ockam\command/src/reset · high confidence
Restructured authenticator module with new access control and identity types
The authenticator module has been reorganized into distinct components, introducing a new \common.rs\ file that defines \EnrollerAccessControlChecks\ for verifying member, enroller, and admin roles based on identity attributes and authority configuration. New types have been added: \OneTimeCode\ for enrollment tokens with optimized CBOR encoding and debug masking, \PreTrustedIdentity\ and \PreTrustedIdentities\ to manage pre-trusted identity records with attributes and expiration, and a \mod.rs\ that exposes these new modules while hiding internal implementation details.
_implementations/rust/ockam/ockam\api/src/authenticator · high confidence
Secure channel encryption now supports automatic key rotation and out-of-order message decryption
The AEAD AES-GCM implementation for secure channels has been updated to automatically rotate encryption keys every 32 messages, enhancing forward secrecy. Additionally, the decryptor now supports processing messages out of order by maintaining a sliding window of seen nonces across current, previous, and next key windows, ensuring compatibility with the Rust implementation's handling of network latency and reordering.
_implementations/elixir/ockam/ockam/lib/ockam/secure\_channel/encrypted\_transport\protocol · high confidence
Standardized command output formatting with JSON and jq support
The command-line interface now provides a unified, standardized output system for all commands. Users can choose between plain text and JSON formats, with JSON output optionally supporting jq queries for filtering. The system also supports hex-encoded CBOR serialization for binary data and applies consistent branding replacements (e.g., custom binary names) across all outputs. This change improves consistency and usability when parsing or viewing command results.
_implementations/rust/ockam/ockam\api/src/ui/output · high confidence
Standardized user feedback for long-running project and operation tasks
The command-line interface now provides clearer, standardized status messages when waiting for asynchronous tasks like project creation or other background operations to complete. Users will see a spinner with specific instructions (e.g., "Configuring project...") and warnings not to interrupt the process, replacing previous generic or absent feedback. This improves the user experience by setting expectations for wait times and reducing confusion during long-running orchestrator operations.
_implementations/rust/ockam/ockam\command/src/operation · high confidence
Switch credential signing to software vault and expose schema IDs
The Rust NIFs now use a software-based vault for credential signing keys instead of the previous default, and credential-related NIF calls now expose the schema ID. This change affects how identities and credentials are managed within the Elixir integration layer, providing more explicit control over key storage and schema identification.
_implementations/rust/ockam/ockam\_rust\_elixir\nifs · high confidence
TCP command module restructured into dedicated sub-modules
The TCP command implementation has been reorganized into a modular structure, splitting the previous monolithic transport logic into distinct components for connections, listeners, inlets, and outlets. This change introduces a new utility module for argument parsing, specifically adding validation to ensure TCP aliases do not contain colon characters, which improves input handling for users creating or managing TCP connections.
_implementations/rust/ockam/ockam\command/src/tcp · high confidence
TCP inlets now support optional handshakes, mptcp, and TLS certificate providers
The TCP inlet creation API has been extended with new configuration options that allow users to skip the initial handshake (skip\_handshake), enable Multipath TCP (enable\_mptcp), and specify a custom TLS certificate provider (tls\_certificate\_provider). These changes are implemented across the inlet service layer, including the background node client, in-memory node, and session replacer, enabling more flexible connection setups and integration with external certificate authorities.
_implementations/rust/ockam/ockam\_api/src/nodes/service/tcp\inlets · high confidence
Unified connection instantiation with TCP, UDP, and secure channel support
The connection module has been refactored to use a modular instantiator pattern, introducing dedicated handlers for plain TCP, plain UDP, project-based secure connections, and generic secure channels. This change enables nodes to establish connections over both TCP and UDP transports (including MPTCP) and simplifies the creation of secure channels by unifying the logic for project and direct secure connections. Users benefit from a more consistent and robust connection lifecycle, with improved flow control integration and cleaner resource management for both transport types.
_implementations/rust/ockam/ockam\api/src/nodes/connection · high confidence
Updated static controller identity identifier
The static controller identity file has been updated to use a new specific identity ID (I84502ce0d9a0a91bae29026b84e19be69fb4203a6bdd1424c85a43c812772a00). This change ensures that the local API component uses the correct identity for authentication and secure channel creation, aligning with the broader updates to the controller's identity design.
_implementations/rust/ockam/ockam\api/static · high confidence
Test coverage
Add test utilities for managing node lifecycles and TCP echo servers; Added Kafka integration tests for end-to-end encrypted topologies; Added argument validation tests for CLI commands; Added benchmarking and property-based tests for MultiAddr; Added compile-time validation tests for the \\#\[ockam::node\]\ macro; Added comprehensive test coverage for macros, node behavior, and relay services; Added initial test suite for Ockam Kafka; Added integration and interceptor tests for the Kafka API; Added integration test for WebSocket send/receive functionality; Added integration tests for AWS signing vault operations; Added integration tests for TCP transport features; Added integration tests for UDP transport reliability and NAT traversal; Added integration tests for authority, portals, sessions, and tracing; Added integration tests for ockam\_node worker/processor lifecycle and metadata; Added integration tests for orchestrator-enrolled scenarios; Added local BATS test suites for Ockam CLI commands; Added orchestrator BATS test suite; Added orchestrator enrollment test suite; Added serial test suite for project addons and use cases; Added test coverage for Ockam protocol encoding and mapping; Added test coverage for core Ockam services; Added test helper modules for Elixir messaging and session testing; Added test infrastructure and helper scripts for ockam\_cloud\_node; Added test infrastructure for authority nodes, session replacers, and tracing spans; Added test suite for TypedCBOR plugin and core encoding; Added test utilities for identity and secure channel validation; Added tests for AEAD AES-GCM encrypted transport protocol; Added tests for Ockam API client, request, and response modules; Added tests for Ockam session handshake and data stages; Added tests for Ockam wire binary message encoding and decoding; Added tests for Secure Channel message parsing; Added tests for TCP address encoding and idle connection termination; Added tests for UDP address creation and encoding; Added tests for credential attribute storage and service authorization; Added tests for messaging delivery and ordering pipes; Added tests for portal tunnel protocol and outlet worker behavior; Added tests for stream index and service APIs; Added tests for the Kafka interceptor inlet/outlet management and protocol handling; Added tests for the Noise XX key establishment protocol; Added tests for the Ockam Healthcheck application; Added unit tests for Ockam router storage and application startup; Added unit tests for UDP transport listener initialization; Added user enrollment ticket fixture for tests; Expanded test coverage for identity, secure channels, and credentials; Initial test coverage for Ockam core modules; New BATS test infrastructure for load, docs, and orchestrator scenarios; New BATS test runner and documentation.
Dependencies
Routine dependency updates across Rust and Elixir crates
This release includes routine updates to dependencies across the Rust and Elixir codebases, including bumps to core libraries such as tokio, clap, serde, and aws-sdk-kms, as well as maintenance updates to build tools and internal crates. These changes ensure the platform stays current with upstream security patches and performance improvements without introducing new user-facing features.
(dependencies) · high confidence
ockam\_macros v0.39.0: New SQL log level and dependency updates
The ockam\_macros crate has been updated to version 0.39.0. This release introduces the \OCKAM\_SQL\_LOG\_LEVEL\ environment variable, allowing users to control SQL logging verbosity. Additionally, the crate's dependencies have been updated.
_implementations/rust/ockam/ockam\macros · high confidence
Housekeeping
Added Credo linting and Elixir formatter configuration
The ockam\_typed\_cbor package now includes configuration files for the Credo static analysis tool and the Elixir code formatter. This ensures consistent code style and enables automated linting checks for the library's source and test files.
_implementations/elixir/ockam/ockam\_typed\cbor · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 51 → 58 (+7.1)
- Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.
Lenses
- Code Health 86 → 86 (-0.1)
- Architecture 99 → 94 (-5.6)
- Maturity 53 → 53 (-0.1)
- Readiness 85 → 85 (+0.0)
- Security 27 → 42 (+15.3)
- Domain Modelling 92 → 91 (-1.4)
- Event Sourcing 100 → 100 (+0.0)
- Performance 100 (new)
Resolved (14)
- Change coupling: delete.rs ↔ list.rs (implementations/rust/ockam/ockam_command/src/tcp/outlet/delete.rs)
- Change coupling: project.rs ↔ util.rs (implementations/rust/ockam/ockam_api/src/nodes/connection/project.rs)
- Change coupling: util.rs ↔ util.rs (implementations/rust/ockam/ockam_command/src/operation/util.rs)
- Change-coupling hub: enroll.rs → addon.rs, space.rs, subscription.rs (implementations/rust/ockam/ockam_api/src/orchestrator/enroll.rs)
- Documentation: written for insiders (implementations/rust/examples/mitm_node/README.md)
- Edited copy of a member (18 corresponding lines) (implementations/rust/ockam/ockam_api/src/multiaddr_resolver/local_resolver.rs)
- Edited copy of a member (22 corresponding lines) (implementations/rust/ockam/ockam_api/src/control_api/backend/entrypoint.rs)
- Members sharing a duplicated core (12 members, 50+ identical tokens) (implementations/rust/ockam/ockam_api/src/orchestrator/ai_platform/node_service_client.rs)
- Members sharing a duplicated core (4 members, 50+ identical tokens) (implementations/rust/ockam/ockam_abac/src/policy/storage/resource_policy_repository_sql.rs)
- Members sharing a duplicated core (4 members, 50+ identical tokens) (implementations/rust/ockam/ockam_api/src/authenticator/credential_issuer/credential_issuer_worker.rs)
- Members sharing a duplicated core (4 members, 50+ identical tokens) (implementations/rust/ockam/ockam_command/src/secure_channel/listener/list.rs)
- Members sharing a duplicated core (4 members, 50+ identical tokens) (implementations/rust/ockam/ockam_transport_ble/src/router/mod.rs)
- Members sharing a duplicated core (9 members, 50+ identical tokens) (implementations/rust/ockam/ockam_node/src/storage/database/migrations/node_migrations/rust/postgres/migration_20250407100000_sqlite_initialization.rs)
- Off-boarding risk: anonymized user #1
New (60)
- Change coupling: addon.rs ↔ enroll.rs (implementations/rust/ockam/ockam_api/src/orchestrator/addon.rs)
- Change coupling: enroll.rs ↔ space.rs (implementations/rust/ockam/ockam_api/src/orchestrator/enroll.rs)
- Confusingly similar methods for retrieving identity information. get_named_identity vs get_named_identity_or_default vs get_identity_by_optional_name vs get_identifier_by_optional_name. It is unclear when to use 'optional' vs 'default' vs direct lookup, and whether the return type is the full Identity, just the Identifier, or a NamedIdentity struct.
- Duplicate functionality for creating relays. Node has create_relay and create_static_relay, while the RemoteRelay type also exposes create and create_static with nearly identical signatures (except RemoteRelay takes Context explicitly). This creates confusion about whether to use the Node method or the RemoteRelay static method.
- Duplicated block (10–11 lines × 3) (implementations/elixir/ockam/ockam_kafka/lib/interceptor/protocol/metadata/response/parser.ex)
- Duplicated block (12 lines × 2) (implementations/elixir/ockam/ockam_kafka/lib/interceptor/protocol/metadata/response/parser.ex)
- Duplicated block (13 lines × 2) (implementations/elixir/ockam/ockam_kafka/lib/interceptor/protocol/parser.ex)
- Duplicated block (13 lines × 3) (implementations/elixir/ockam/ockam/lib/ockam/examples/session/count_to.ex)
- Duplicated block (15 lines × 2) (implementations/elixir/ockam/ockam/lib/ockam/stream/client/consumer.ex)
- Duplicated block (16–17 lines × 2) (implementations/elixir/ockam/ockam_kafka/lib/interceptor/protocol/metadata/request/parser.ex)
- Duplicated block (24 lines × 2) (implementations/elixir/ockam/ockam/lib/ockam/examples/messaging/ordering.ex)
- Duplicated block (25 lines × 2) (implementations/elixir/ockam/ockam/lib/ockam/examples/messaging/reliable_deduplication.ex)
- Duplicated block (3–10 lines × 3) (implementations/elixir/ockam/ockam_kafka/lib/interceptor/protocol/metadata/response/parser.ex)
- Duplicated block (5 lines × 2) (implementations/elixir/ockam/ockam/lib/ockam/mini_cbor.ex)
- Duplicated block (5 lines × 2) (implementations/elixir/ockam/ockam_kafka/lib/interceptor/kafka_interceptor.ex)
- Duplicated block (5 lines × 2) (implementations/elixir/ockam/ockam_kafka/lib/interceptor/protocol/metadata/response/formatter.ex)
- Duplicated block (5 lines × 2) (implementations/elixir/ockam/ockam_kafka/lib/interceptor/protocol/metadata/response/parser.ex)
- Duplicated block (6 lines × 2) (implementations/elixir/ockam/ockam/lib/ockam/protocol/stream.ex)
- Duplicated block (6 lines × 2) (implementations/elixir/ockam/ockam_kafka/lib/interceptor/protocol/metadata/response/formatter.ex)
- Duplicated block (7 lines × 2) (implementations/elixir/ockam/ockam/lib/ockam/transport/tcp/address.ex)
- …and 40 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
build-trust/ockam was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 30 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 0435d8d73dc2bd3bdd56675021b27c76b1116d91 — the exact code this score is about.
- Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-cb25ca4feafa.