Skip to content
CAI
Software that uses CAICheck a score

CanineHQ/canine

40.6

Weak · 19 September 2026

22k

lines of production code

Ruby

with JavaScript

1

measurement over time

CAI band scale
CAI lens gauges

What this system is

Canine is a self-hosted Kubernetes deployment platform that enables users to manage clusters, deploy applications, and install add-ons through a comprehensive web interface and REST API. It supports multi-tenancy with team-based access control, integrates with major Git providers for automated builds, and offers flexible authentication via SSO, LDAP, and OIDC. The system handles the full lifecycle of cloud resources, including project deployments, service management, and billing, while providing developer tools like interactive pod shells and global search.

How it got here

2024 — Initial scaffolding and multi-tenancy foundation

86 changes.

The project established its foundational Rails 7.2 infrastructure, migrating the frontend to Tailwind CSS and implementing account-based multi-tenancy with Stripe billing. This period focused on building the core platform capabilities, including Kubernetes cluster management, project lifecycle automation, and a comprehensive UI for managing services, add-ons, and user authentication.

2025 — Async UI, SSO, and API v1

106 changes.

This period focused on enhancing perceived performance through asynchronous view models and skeleton loading across Kubernetes, Helm, and project dashboards. It introduced comprehensive Single Sign-On support for LDAP, OIDC, and SAML, alongside a new credentials management interface and Portainer integration. The release also established the foundational v1 REST API and migrated the admin panel to the Avo framework.

2026 — Platform expansion and operational maturity

53 changes.

This period focused on expanding the platform's core capabilities by introducing Model Context Protocol (MCP) integration, comprehensive notification systems, and automated DNS management. It also established foundational infrastructure for multi-cluster support, billing via Stripe, and secure user authentication with two-factor verification.

Features

Add Bitbucket support to the Git client abstraction

The Git service layer now supports Bitbucket alongside existing GitHub and GitLab integrations. A new \Git::Bitbucket::Client\ implementation handles Bitbucket-specific API interactions for commits, pull requests, webhooks, and file retrieval, while the central \Git::Client\ factory has been updated to instantiate the correct provider client based on the project's credential provider.

app/services/git · high confidence

Add Helm chart rendering utilities for search results and selection cards

A new JavaScript utility module has been introduced to handle the visual presentation of Helm chart data within the application. This module provides functions to generate HTML structures for displaying chart information, including logic to fetch and render chart logos (with a fallback placeholder), display version numbers, show verified publisher badges, and present star ratings. It supports two distinct UI contexts: a constrained header view for dropdown items and a full-width card view for selected charts, which includes a close button to clear the selection. These utilities enable consistent and detailed display of Helm chart metadata in the search interface.

_app/javascript/utils/helm\charts · high confidence

Add Project Webhook bulk delivery method

Users can now deliver notifications via webhooks for projects. A new \ProjectWebhook\ notifier class has been added to the \app/notifiers/bulk\_delivery\_methods\ directory, which iterates over enabled project notifiers (excluding email providers) and sends their configured webhook URLs with the built payload using HTTParty.

_app/notifiers/bulk\_delivery\methods · high confidence

Add TOTP two-factor authentication with recovery codes

Users can now enable Time-based One-Time Password (TOTP) two-factor authentication. The setup flow displays a QR code and secret key for scanning with an authenticator app, followed by a screen to save and copy/print/download a set of one-time recovery codes. During login, users can verify their identity using either the authenticator app code or a recovery code via a toggleable form.

_app/views/two\_factor\_authentication, app/views/two\_factor\verifications · high confidence

Add build cloud configuration and management UI

Users can now install, configure, and manage build clouds directly from the cluster settings. The new interface includes an install wizard, a status dashboard showing resource usage (replicas, CPU, memory) and health, and an edit form to adjust resource limits. Changes to configuration require a reinstall, and the UI provides clear feedback during installation, updates, and failure states.

_app/views/clusters/build\clouds · high confidence

Add cluster migration tool for projects and add-ons

New action classes have been introduced in the cluster migrations module to handle the migration of add-ons and projects to a target cluster. The MigrateAddOn action duplicates source add-on records, assigns them to the new cluster, generates unique names within the account, and sets an initial installation stage. The MigrateProject action orchestrates the migration process by delegating to CanineConfig services for definition creation, project restoration, and initialization.

_app/actions/cluster\migrations · high confidence

Add interactive pod shell via WebSocket channel

Users can now open an interactive shell inside Kubernetes pods through a new WebSocket-based channel. The system validates access using a temporary token, enforces a maximum number of concurrent sessions per user, and manages the shell lifecycle (including resizing, idle timeouts, and cleanup) over the connection. Session status is kept in sync with the UI via Turbo Stream broadcasts.

app/channels · high confidence

Add internal auth proxy and configurable ingress for add-ons

Users can now configure internal authentication and ingress routing for add-ons. An internal auth proxy service has been introduced to manage OIDC issuer URLs (derived from the app host) and OAuth credentials for add-ons, ensuring secure access. Additionally, an ingress service allows add-ons to be exposed via either Traefik or Nginx, automatically selecting the appropriate ingress class based on the cluster's installed packages.

_app/services/k8/add\ons · high confidence

Add project notifier management UI

Users can now configure and manage notification integrations for their projects through a new web interface. The system supports five provider types: Slack, Discord, Microsoft Teams, Google Chat, and Email. The notifier form allows users to set a name, select a provider, choose specific notification types (build, deployment, health), and enable or disable the notifier. A list view displays existing notifiers with their status and allows users to send test notifications, edit, or delete them.

app/views/projects/notifiers · high confidence

Add repository listing controllers for GitHub and GitLab integrations

New controllers have been added for the GitHub and GitLab integrations to handle repository listing. These controllers fetch repositories via their respective API clients and render the results using Turbo Streams, allowing users to view and paginate through their connected repositories without a full page reload. The GitHub controller includes client-side filtering for search queries, while the GitLab controller utilizes the API's search capabilities for the same purpose.

app/controllers/integrations · high confidence

Add version selector view model for add-ons

A new view model, Async::AddOns::VersionSelectorViewModel, has been introduced to handle the asynchronous loading of Helm chart versions for a specific add-on. When rendered, it fetches chart details from the add-on's configured repository URL and displays a list of available versions. If the chart is not found or the fetch fails, it renders an appropriate error message to the user.

_app/view\_models/async/add\ons · high confidence

Add-on creation now supports Artifact Hub, Helm repositories, and OCI registries

The add-on creation flow has been expanded to allow users to source Helm charts from three different origins: searching via Artifact Hub, browsing a custom Helm repository URL, or specifying an OCI registry URL. New JavaScript controllers handle the specific interaction patterns for each source—such as debounced search for Artifact Hub, repository index fetching for Helm repos, and OCI tag resolution—while a shared version selector controller manages the loading state and version dropdown for all three methods, ensuring the submit button is disabled while chart data is being fetched.

_app/javascript/controllers/add\ons · high confidence

Added ACME issuer service for shared Kubernetes configuration

A new service class \K8::Shared::AcmeIssuer\ has been introduced to manage ACME issuer settings. This component allows users to specify an email address, ingress class name, and namespace (defaulting to \Clusters::Install::DEFAULT\_NAMESPACE\) for configuring Let's Encrypt or similar certificate authorities within the shared Kubernetes context.

app/services/k8/shared · high confidence

Added Active Admin asset pipeline entry points

The application now includes specific asset pipeline files to integrate Active Admin. A JavaScript manifest explicitly requires the Active Admin base script, and a SCSS stylesheet imports Active Admin's mixins and base styles, allowing for variable overrides and custom styling of the admin interface.

vendor · high confidence

Added GitHub webhook status view model

A new view model has been introduced to display the connection status of a GitHub webhook for a specific project. This component asynchronously checks whether a webhook exists and renders a visual indicator (a green checkmark for connected, red cross for not found) to the user, providing immediate feedback on the integration state.

_app/view\models/async/github · high confidence

Added LDAP authentication strategy for Devise

Users can now authenticate against LDAP servers via a new \LDAPAuthenticatable\ strategy. This change enables LDAP-based login for accounts with SSO enabled and an LDAP provider configured, handling credential validation, optional group-based team provisioning, and user synchronization.

lib/devise · high confidence

Added Madmin admin dashboard routes

The application now includes a new admin interface powered by Madmin, accessible under the /madmin path. This change introduces a comprehensive set of routes for managing core resources such as projects, users, deployments, clusters, and services, as well as operational data like logs, metrics, and cron schedules. It also provides management capabilities for Active Storage assets (blobs, attachments, variant records) and notification events, culminating in a central dashboard view.

config/routes · high confidence

Added Rancher integration for cluster onboarding and synchronization

This change introduces a new integration with Rancher, enabling users to onboard Rancher-based stack managers and synchronize their associated Kubernetes clusters. The implementation includes a dedicated client for communicating with the Rancher API (handling authentication, cluster listing, and kubeconfig generation), data models for users and clusters, and a workflow for creating accounts and linking them to Rancher providers. It also includes logic to sync cluster states from Rancher and handle cluster installation jobs, while explicitly noting that centralized registry synchronization is not supported for Rancher.

lib/rancher · high confidence

Added RegistrySecret service for Kubernetes secret management

A new service class, K8::Secrets::RegistrySecret, has been introduced to handle registry-specific secrets. This component accepts a project identifier and a Docker configuration JSON object during initialization, providing the necessary structure to manage container registry credentials within the Kubernetes secrets framework.

app/services/k8/secrets · high confidence

Added SAML authentication service

Introduced a new SAML authentication implementation in app/services/saml/authenticator.rb. This service handles SAML response validation, extracts user attributes (email, name, UID, groups), and generates authorization URLs and metadata using the OneLogin RubySaml library, enabling users to authenticate via SAML identity providers.

app/services/saml · high confidence

Added SendTest action for sending test notifications

A new \Notifiers::SendTest\ action has been introduced to handle the sending of test notifications. This action supports both email and webhook-based notifiers: for email, it verifies SMTP configuration via \SmtpUtilities\ before sending a test email through \NotifierMailer\; for webhooks, it constructs a payload and posts it to the notifier's URL using HTTParty. The action integrates with the LightService framework and expects \notifier\, \project\, and \user\ context inputs, failing gracefully with descriptive messages if SMTP is unconfigured or if an error occurs during delivery.

app/actions/notifiers · high confidence

Added bin scripts for local development and Docker entrypoint

The repository now includes a set of executable scripts in the bin directory to streamline local development and containerized execution. bin/dev and bin/run bootstrap the application using Foreman, automatically installing the gem if missing and configuring Ruby debugging environment variables. bin/docker-entrypoint prepares the runtime by enabling jemalloc for memory efficiency and YJIT for performance, and automatically runs database creation and migration tasks when starting the Rails server, dev, or run scripts. bin/setup automates the initial environment setup by installing dependencies, preparing the database, and clearing logs. Additional binstubs for Rails, Rake, Rubocop, Brakeman, and Bundler are provided to ensure consistent tool execution.

bin · high confidence

Added build packs search input component

A new partial view for the build packs section introduces a search input field. This component allows users to filter build packs by name (e.g., ruby, node, python) using a styled text input with a placeholder hint.

_app/views/build\packs · high confidence

Added buildpack search and details actions

New action classes have been introduced in the app/actions/buildpacks directory to enable querying the Cloud Native Buildpacks registry. The Buildpacks::Search action allows users to search for buildpacks by query, returning a list of results including latest versions and version history. The Buildpacks::Details action fetches comprehensive information for a specific buildpack by namespace and name, including description, homepage, licenses, stacks, and verification status. Both actions parse responses from the buildpacks.io API and structure the data for downstream use.

app/actions/buildpacks · high confidence

Added cluster setup instructions for K3s, managed Kubernetes, and local K3s

The cluster creation flow now includes dedicated instruction views for three cluster types. For K3s, users are guided through entering a server IP, running an installation command (with UFW configuration hints), and pasting the resulting kubeconfig. For managed Kubernetes providers (DigitalOcean, Linode, or Other), users select their provider and upload a kubeconfig file. For local K3s setups, users select their operating system (macOS, Linux, or Windows) and paste the kubeconfig output.

_app/views/clusters/cluster\types/instructions · high confidence

Added cluster setup instructions for Linux, macOS, Windows, DigitalOcean, and Linode

The cluster instructions view now includes dedicated setup guides for Linux (K3s/K3d), macOS (K3d), Windows (K3d with Docker Desktop or WSL2), and managed Kubernetes providers DigitalOcean and Linode. Users can select their environment to see step-by-step commands for installing the runtime, creating a cluster, and retrieving the kubeconfig, with copy-to-clipboard support for code snippets.

app/views/clusters/instructions · high confidence

Added email templates for account invitations and additions

Users now receive styled HTML and plain-text emails when invited to join an account or when added to an existing one. The invitation email provides the user's email address, a temporary password, and a login link, while the addition email confirms access to the new account with a direct login link.

_app/views/account\_invite\mailer · high confidence

Added example configuration for Canine service deployment

A new example configuration file (example\_1.yaml.erb) has been added to the resources/canine\_config directory. This file demonstrates a Canine service setup including a web service container on port 8080, environment variables for database connectivity (using a templated Redis URL), and a placeholder for cleanup scripts.

_resources/canine\config · high confidence

Added mobile demo recording and pricing data resources

The public resources directory now includes a mobile-optimized terminal demo recording (demo-mobile.cast) alongside the existing desktop demo (demo.cast), providing a tailored visual experience for mobile users. Additionally, a new prices.json file has been added to supply structured pricing data for Heroku, DigitalOcean, Hetzner, and Render tiers, enabling the frontend to display accurate cost comparisons for these cloud providers.

public/resources · high confidence

Added preview app management interface for project forks

Users can now manage preview apps directly from the project forks section. The new interface includes a form to configure pull request app settings, such as selecting a deployment cluster via a rich select component. It also displays a list of existing preview apps and open pull requests, allowing users to create new preview apps from pull requests and view details like the associated branch, author, and status.

_app/views/projects/project\forks · high confidence

Added shared error message partial for form validation

A new shared partial \\_error\_messages.html.erb\ has been added to the application views. This component provides a consistent, styled alert display for form validation errors, rendering the resource name and a list of full error messages using internationalization. This allows other views to easily include standardized error feedback without duplicating markup.

app/views/application · high confidence

Added skeleton loading components for fields and tables

New partials \\_field\_skeleton.html.erb\ and \\_table\_skeleton.html.erb\ have been added to the shared components directory to provide visual placeholders during data loading. The field skeleton supports small, medium, and large sizes, while the table skeleton renders rows with configurable column counts (defaulting to two), using CSS classes to display animated loading states.

app/views/shared/components · high confidence

Added storage volume usage view for Helm releases

A new partial view for displaying storage metrics in Helm releases has been added. This component iterates through available storage volumes, showing the volume name, the percentage of usage, the total available size, and a progress bar indicating current consumption. If no storage volumes are detected, it displays a 'No storage volumes found' message.

app/views/helm · high confidence

Added system installation script for Kubernetes tools and Telepresence

A new system installation script (resources/system\_install.sh) has been added to automate the setup of essential development tools on Linux servers. This script installs kubectl, Helm, and Telepresence (version 2.21.1), ensuring that the necessary CLI tools for Kubernetes management and traffic mirroring are available in the environment.

resources · high confidence

Added volume management interface for projects

Users can now create, view, and delete persistent storage volumes within a project. The new interface includes a form to specify volume name, size, and mount path, a list view displaying volume status (pending, deployed, failed) and details, and the ability to remove volumes with a confirmation prompt.

app/views/projects/volumes · high confidence

Added welcome email templates for new sign-ups

New HTML and plain-text email templates have been added for the sign-up mailer. Users will now receive a welcome message upon registration that addresses them by name or email and confirms they are set up to deploy applications.

_app/views/sign\_up\mailer · high confidence

Async cluster metrics view model

Added a new view model for asynchronously loading and displaying cluster metrics. This component handles the initial skeleton render and fetches live node metrics via the Kubernetes API to display in the cluster metrics view.

_app/view\models/async/clusters · high confidence

Async loading for Helm add-on details

The Helm add-on details page now loads specific sections asynchronously to improve perceived performance. Internal URLs, storage metrics, version information, and the values YAML configuration are now fetched in the background using dedicated view models. Users will see skeleton loaders or spinners while these components load, and the values YAML view now includes a toggle to reveal masked sensitive values.

_app/view\models/async/helm · high confidence

Async loading for project metrics and processes with skeleton UI

The project metrics and processes pages now use asynchronous view models to fetch data, displaying a skeleton table during the loading phase to improve perceived performance. For metrics, the view model fetches project details and renders live metrics, while for processes, it retrieves pods from the project's namespace via the Kubernetes client and displays them in a table, showing an empty state message if no pods are running.

_app/view\models/async/projects · high confidence

Asynchronous cluster lifecycle and package management jobs

Users can now manage cluster installations, deletions, and package operations asynchronously via background jobs. This includes dedicated jobs for installing and uninstalling the Build Cloud environment, destroying entire clusters (which cascades to destroy associated projects), and installing or uninstalling specific cluster packages. The package installation job includes logic to skip installation if a package is already present, while the Build Cloud destruction job handles teardown of the builder and updates the cluster status to 'uninstalled' upon completion, ensuring robust state tracking for cluster resources.

app/jobs/clusters · high confidence

Automated TODO tracking via pre-commit hook

A new pre-commit hook has been added to automatically detect TODO comments in staged Ruby (.rb) and ERB (.erb) files. When a commit includes new TODOs, the hook appends them to a dedicated TODO.md file and stages that file for inclusion in the commit, ensuring that pending tasks are consistently tracked without manual intervention.

.githooks · high confidence

Automated ingress creation for new service domains

A new job, Services::AddDomainJob, has been introduced to handle domain addition for services. When executed, it leverages the new K8::Connection abstraction to interact with the Kubernetes cluster, specifically generating and applying an ingress YAML configuration via the K8::Stateless::Ingress component.

app/jobs/services · high confidence

Automatic DNS record creation for managed domains

Users with domains marked as auto-managed can now have DNS records created automatically. When the \ENABLE\_AUTOMATIC\_DNS\_MAPPING\ environment variable is set to true and Cloudflare credentials are configured, the system detects new or updated domains and automatically creates the necessary A or CNAME records in Cloudflare to point the domain to the correct service IP or hostname. This removes the need for manual DNS configuration for supported domains.

app/services/dns · high confidence

Expanded Helm chart installation sources with Artifact Hub, custom repos, and OCI support

The Helm add-on creation interface now supports three distinct sources for installing charts: searching Artifact Hub's curated repository, providing a custom Helm repository URL, and installing from an OCI-compatible container registry. This change introduces new form fields and UI components for each source type, allowing users to select their preferred method and input the necessary details (such as repository URLs or search terms) to discover and install charts.

_app/views/add\ons/helm · high confidence

Expanded MCP toolset for full deployment workflow

The MCP server now exposes a comprehensive set of tools (11 new files) enabling end-to-end infrastructure and application management. Users can provision resources via create\_cluster, create\_project, create\_service, and create\_add\_on (installing Helm charts). Project lifecycle is managed through deploy\_project, restart\_project, and update\_project (covering settings like branch, autodeploy, and build configuration). Environment variables can be created or updated via update\_environment\_variable. For observability, get\_project\_logs and get\_add\_on\_logs provide pod logs and events, while get\_cluster\_kubeconfig retrieves sensitive cluster credentials. Discovery is supported by search\_add\_ons for Helm charts and get\_environment\_variable\_value for specific config lookups.

app/mcp/tools · high confidence

Initial Portainer integration library

Added a new library under lib/portainer that provides the core infrastructure for integrating with Portainer. This includes a client for authenticating via username/password or OAuth, retrieving Kubernetes configurations, and managing endpoints and registries. The update introduces stack management capabilities, allowing users to sync clusters and registries from their Portainer instance, and handles access token retrieval and authentication flows.

lib/portainer · high confidence

Initial Rails 7.2 application configuration and infrastructure setup

This change introduces the foundational configuration for the Canine application, upgrading the framework to Rails 7.2 and establishing the core environment settings. It configures the application to support three distinct deployment modes—local, cloud, and cluster—controlled via the BOOT\_MODE environment variable, and enables account-specific sign-in flows. The setup replaces Redis for Action Cable with an enhanced PostgreSQL adapter, configures Good Job as the background job queue, and defines the initial routing structure for API endpoints, OIDC/SAML authentication, and account management. Additionally, it sets up the Tailwind CSS theme with DaisyUI components, configures PostgreSQL database connections, and establishes security ignore rules for the Brakeman scanner.

config · high confidence

Initial configuration of core Rails application and integrations

This change introduces the initial set of configuration initializers for the application, establishing the foundational setup for authentication, background jobs, and external services. It configures Devise for user authentication with specific mailer and session settings, and sets up Doorkeeper with OpenID Connect support for OAuth2 and OIDC flows. Background processing is initialized via GoodJob, defining specific queues for builds and monitoring along with scheduled cron jobs for health checks, metrics, and cleanup tasks. The application also integrates Stripe for billing (gated by cloud mode), Sentry for error tracking, and Flipper for feature flags. Additional initializers configure asset management, content security policies, inflections for acronyms like SSO and LDAP, pagination via Pagy, and custom form error handling.

config/initializers · high confidence

Initial database schema and migration setup

This change introduces the foundational database schema for the application, establishing the core data models required for user management, multi-tenancy, and infrastructure orchestration. It creates tables for users, accounts, and teams to support organizational structures and role-based access control. It also defines the infrastructure layer with tables for clusters, projects, services, deployments, and add-ons, enabling the platform to manage Kubernetes resources and containerized workloads. Additionally, it includes migrations for authentication (Devise, OAuth via Doorkeeper, SSO providers), background job processing (GoodJob), feature flags (Flipper), and file storage (Active Storage), providing the necessary backend support for the platform's core features.

db/migrate · high confidence

Initial database schema and seed file added

The database schema is now defined in \db/schema.rb\ (version 2026\_09\_19\_152959) and a \db/seeds.rb\ file has been introduced to support idempotent data seeding. The schema establishes the core data model, including tables for accounts (with Stripe billing integration), users, clusters, add-ons, build configurations, and API tokens, alongside standard Active Storage and announcement tables.

db · high confidence

Initial deployment of Stimulus-based frontend controllers

This change introduces a comprehensive suite of new JavaScript controllers to the application's frontend, replacing or augmenting previous implementation methods with a structured Stimulus-based architecture. Key capabilities added include an asynchronous renderer for dynamic content, a buildpack search and selection interface with sortable lists, and a global search modal with keyboard navigation. The update also brings new interactive components for managing environment variables (including reveal/hide and storage type toggling), a pricing calculator with dynamic charting, and a Kubernetes manifest browser with YAML syntax highlighting. Additional controllers handle specific UI behaviors such as clipboard copying with tooltips, LDAP connection testing, log streaming, and mobile navigation, establishing a new foundation for client-side interactivity.

app/javascript/controllers · high confidence

Initial project scaffolding and local development environment

The repository is initialized with a complete Rails application structure, including Dockerfiles for production and development, docker-compose configurations for local PostgreSQL-backed runs, and standard Rails configuration files (Gemfile, Rakefile, config.ru). This establishes the foundational build and runtime environment for the Canine Kubernetes deployment platform, replacing the previous Jumpstart template scaffolding.

(repo-wide) · high confidence

Initial release of the v1 REST API

This change introduces the foundational v1 API controllers, enabling programmatic access to core platform resources. Users can now authenticate via API tokens and interact with endpoints for listing and managing projects (including deploying, restarting, and running diagnostics), viewing and killing builds, listing clusters and downloading kubeconfigs, and managing add-ons (including restarting them). The API enforces account-level scoping and authorization via Pundit.

app/controllers/api/v1 · high confidence

Introduce API Token management interface

Adds a new UI for managing API tokens, allowing users to create tokens with a custom name and select an expiration period (7, 30, 60, or 90 days, or no expiration). The interface includes a list view displaying token names, masked access keys, last-used dates, and expiration dates, along with the ability to delete tokens and copy the full access key upon initial creation.

_app/views/api\tokens · high confidence

Introduce Helm-based add-on management for Redis, PostgreSQL, and ClickHouse

The application now supports installing and managing add-ons via Helm charts, starting with Redis, PostgreSQL, and ClickHouse. This change introduces a new service layer (\K8::Helm\) that handles chart building, installation, and configuration via \values.yaml\ files. Users can now deploy these specific data services as add-ons, with the system automatically handling secret retrieval for credentials (e.g., \postgres-password\, \redis-password\) and constructing internal service URLs. The implementation includes a \ChartBuilder\ for generating temporary Helm charts and a \Client\ for executing Helm commands like \install\, \upgrade\, and \uninstall\ against the Kubernetes cluster.

app/services/k8/helm · high confidence

Introduce Stack Manager configuration UI for Portainer integration

The Stack Manager settings page now provides a complete interface for configuring and managing Portainer connections. Users can select a stack manager type, enter the Portainer URL and access token, and optionally enable Role Based Access Control (RBAC) to restrict cluster access to the user's session while using the token for async Git deployments. The interface includes real-time connection verification (showing success, unauthorized, or error states), a dedicated section to display the current configuration (including RBAC status and provider URL), and a button to sync clusters with Portainer. An empty state guides new users to configure their first manager, and the form includes a warning about potential cluster connectivity impacts when changes are made.

_app/views/accounts/stack\managers · high confidence

Introduce account-based multi-tenancy and Pundit authorization

Users can now create and switch between multiple accounts, with all resources (clusters, projects, add-ons) scoped to the active account. This change introduces Pundit for authorization, requiring users to have admin or owner roles to manage accounts, and adds a new \AccountsController\ to handle account creation, editing, and switching. The \ApplicationController\ now enforces account context via \current\_account\ and \current\_account\_user\, ensuring that all subsequent resource controllers operate within the correct account boundary.

app/controllers · high confidence

Introduce cloud-based Docker build infrastructure with automatic build arguments

The build system now supports executing Docker builds on a remote cloud cluster via the new \Builders::BuildCloud\ service, which constructs \docker buildx\ commands to push images directly to the registry while injecting automatic build arguments (\GIT\_SHA\ and \BUILD\_TIMESTAMP\) into every build. This cloud builder leverages a \BuildCloudManager\ to provision local builders and parse image digests from metadata files, providing an alternative to the existing local \Builders::Docker\ implementation that delegates to buildpack or Dockerfile frontends. Additionally, a \Workbench::Status\ service has been added to track environment provisioning stages, specifically detecting and reporting errors during the git clone phase.

app/services/builders · high confidence

Introduce email notification system for account, service health, and event alerts

Users can now receive email notifications for account invitations, service health status changes (down/restored), and general application events. This change adds dedicated mailers (AccountInvite, ServiceHealth, Notifier, SignUp) that send styled emails with project context, inline logos, and specific details like commit SHAs or deployment versions. The system supports configurable SMTP settings and includes a test notification feature for verification.

app/mailers · high confidence

Introduce structured notification system for builds, deployments, and health checks

Users can now receive notifications for build status changes, deployment events, and service health alerts via email and webhooks. This change adds a new notification framework (Noticed) with specific notifiers for builds, deployments, and service health, allowing users to configure email delivery and webhook integrations (Slack, Discord, Microsoft Teams, Google Chat) for these events.

app/notifiers · high confidence

Introduce user favorites for projects, clusters, and add-ons

Users can now mark and unmark projects, clusters, and add-ons as favorites via a new toggle button in the UI. The system persists these preferences per user and account, and the favorites list is displayed in a dedicated view, allowing users to quickly access their most important resources. A development seed task is also included to generate sample data for testing this feature.

app/actions/favorites, app/views/favorites, lib/tasks/development · high confidence

Introduces a new Kubernetes integration service layer

The application now includes a new \app/services/k8\ module that provides a structured, connection-based approach to interacting with Kubernetes clusters. This change introduces core components including \K8::Connection\ for managing cluster access and kubeconfig handling (including in-cluster detection and localhost remapping), \K8::Client\ for direct API interactions via Kubeclient, and \K8::Kubectl\ for executing CLI commands. It also adds \K8::BuildCloudManager\ to handle the lifecycle of BuildKit builders on Kubernetes, including installation, verification, and image building, alongside supporting classes like \K8::Base\ for YAML templating and \K8::Namespace\ for resource management. This refactors the previous ad-hoc kubectl usage into a reusable, object-oriented service layer.

app/services/k8 · high confidence

Introduces internal auth proxy for projects, services, and add-ons

An internal authentication proxy has been added to secure communication between projects, services, and add-ons within the Kubernetes cluster. This change introduces a new \K8::Stateless::AuthProxy\ service that manages OIDC configuration, deriving the issuer URL from the \AppHost.url\ and retrieving client credentials from the associated OAuth application. This proxy works alongside a comprehensive set of new Kubernetes resource wrappers (including Deployment, Ingress, CronJob, and Secrets) to standardize how these internal components are managed and secured.

app/services/k8/stateless · high confidence

Introduction of account-based multi-tenancy and billing infrastructure

This change introduces a new Account model that serves as the root of the multi-tenant hierarchy, replacing the previous flat user-centric structure. Users are now members of Accounts via a new AccountUser model, which supports role-based access (owner, admin, member). The Account model includes billing logic (Billable concern) to manage subscription statuses and enforce plan limits for clusters and team members. This new structure is propagated through the domain: Clusters, Projects, and Add-ons are now associated with Accounts, enabling account-level resource management, unique naming constraints, and billing tracking.

app/models · high confidence

Introduction of asynchronous view model base class

A new base class for asynchronous view models has been added to provide a standardized foundation for handling async rendering. This class manages common parameters like the current user and request params, validates that expected parameters are present, and provides a helper method to render partials within the application's controller context. This change supports the broader effort to load storage and render versions asynchronously, improving perceived performance by allowing skeleton animations during data fetching.

_app/view\models/async · high confidence

Introduction of background job infrastructure for health monitoring and billing

This change introduces the core background job framework and specific workers for service health monitoring, cluster metrics collection, and Stripe billing synchronization. Users will now benefit from automated health checks that detect service outages and trigger email notifications via the new ServiceHealthNotifier, ensuring timely alerts when services go down or recover. Additionally, the system now periodically syncs usage data with Stripe for Pro accounts to manage per-cluster pricing, and fetches cluster metrics to support monitoring dashboards. The job architecture includes dedicated queues (monitoring, default) and timeout protections to ensure reliable execution.

app/jobs · high confidence

LDAP SSO provider configuration form with test connection

The LDAP Single Sign-On provider setup now includes a dedicated configuration form allowing users to specify the server host, port, base DN, encryption method, and bind credentials, along with optional advanced settings for user attribute mapping (UID, email, name) and search filters. A "Test Connection" button is provided within the form to validate the LDAP server settings before saving, displaying success or failure status directly on the page.

_app/views/accounts/sso\providers/ldap · high confidence

LDAP authentication service implementation

Added a new LDAP authenticator service that enables user login via LDAP directories. The service supports testing connection configurations, binding with service accounts or anonymous reads, searching for user entries, verifying passwords, and optionally fetching group memberships. It handles various encryption methods including plain, StartTLS, and SimpleTLS connections.

app/services/ldap · high confidence

MCP server exposes account-scoped resources via URI routing

The MCP server now exposes account-scoped resources (accounts, clusters, projects, builds, environment variables, and add-ons) through a URI-based routing system. Users can access these resources via URIs like \canine://accounts/{account\_id}/projects\ or \canine://accounts/{account\_id}/add\_ons/{add\_on\_id}\. The router validates account access and returns JSON data through view models, with environment variables exposing only names and storage types (not values) for security.

app/mcp/resources · high confidence

New API endpoint for managing project pods

A new controller has been added to expose pod management capabilities within the project API. Users can now list the first 50 pods in a project, retrieve details for a specific pod, create new pods via YAML definitions, and terminate existing pods through dedicated API endpoints.

app/controllers/api/v1/projects · high confidence

New Avo admin dashboard with real-time statistics and activity feeds

A new dashboard view has been added to the Avo admin interface, providing a centralized overview of system health and recent activity. Administrators can filter statistics by time period (7, 30, 90, or 365 days) to view counts for users, accounts, clusters, projects, services, and add-ons, including new additions within the selected window. The dashboard displays performance metrics such as build and deployment success rates, service health percentages, and cluster availability. It also includes status breakdowns for clusters and add-ons, along with feeds of the five most recent builds and deployments, allowing admins to quickly monitor operational status and recent changes.

app/views/avo/tools · high confidence

New Avo admin dashboard with statistics cards

The Avo admin interface now includes a dedicated Dashboard page, accessible via the sidebar. This page displays a set of statistical cards showing key metrics: build success rate, deployment success rate, counts of running and failed clusters, deployed projects, new apps, and new users. The dashboard uses custom partials to render these metrics with specific styling and icons.

app/views/avo/custom · high confidence

New CLI execution, Docker registry, favicon, analytics, and schema inference services

Added five new service classes in app/services to support core platform capabilities. Cli::RunAndLog enables interactive command execution with user-initiated process termination, while DockerCli handles authentication for custom container registries. FaviconService fetches site icons using DuckDuckGo (replacing Google), GoogleAnalytics tracks events via GA4, and InferJsonSchemaService generates JSON schemas from data structures.

app/services · high confidence

New Helm-based deployment strategy with automatic DNS and auth proxy support

The platform now supports a new Helm-based deployment path alongside the existing legacy method. When using Helm deployments, the system installs charts with atomic and wait flags disabled by default, automatically configures DNS mappings for services with auto-managed domains, and provisions an internal authentication proxy for services marked as protected. This change introduces a new base deployment service and specific implementations for Helm and legacy deployments, allowing users to benefit from improved deployment reliability and automatic infrastructure setup for protected web services.

app/services/deployments · high confidence

New Kubernetes node and pod metrics collection for compute and memory

The system now collects and stores detailed CPU and memory metrics for Kubernetes nodes and their associated pods. This change introduces a new metrics module that queries node capacity and usage via kubectl, aggregates data by node, namespace, and pod, and persists these metrics to the cluster's storage. Users will see granular resource utilization data for their Kubernetes infrastructure, including total and used CPU cores and memory for each node and pod.

app/services/k8/metrics · high confidence

New MCP prompts for project lifecycle and troubleshooting

Added five new MCP prompt templates in app/mcp/prompts to guide users through key Canine operations: deploying a new project (deploy\_new\_project), adding background workers or cron jobs (add\_worker\_or\_cron), installing Helm chart add-ons (install\_add\_on), troubleshooting failing deployments (troubleshoot\_deployment), and handling destructive actions like resource deletion (destroy\_resource). These prompts provide step-by-step instructions for using MCP tools such as create\_project, create\_service, create\_add\_on, and deploy\_project, while explicitly directing users to the Canine web app for any delete operations.

app/mcp/prompts · high confidence

New OIDC authentication service implementation

A new OIDC authenticator service has been added to handle user authentication via OpenID Connect. This service manages the full authentication flow, including exchanging authorization codes for tokens, validating JWTs using JWKS, and extracting user claims such as email, name, and group memberships. It supports multiple signing algorithms and includes fallback mechanisms for fetching user information if the ID token does not contain all necessary claims.

app/services/oidc · high confidence

New Pod view model for status and navigation

A new PodViewModel class has been introduced to handle the display logic for Kubernetes pods. It provides methods to determine the pod's current status (such as running, pending, failed, or waiting) and generates the correct URL paths for viewing logs and accessing an online shell, adapting the links based on whether the pod belongs to a Project or an AddOn.

_app/view\models · high confidence

New Processes interface for managing one-off pods

Users can now access a dedicated Processes section within a project to create and manage one-off pods. The new index page provides a button to launch single-instance pods for testing or temporary commands, while the show view displays pod logs and events. A new shell view enables interactive terminal access to pods, and a connect modal assists users in configuring their local environment by providing a downloadable Kubeconfig file and a copyable connection command.

app/views/projects/processes · high confidence

New Rake tasks for metrics, health checks, and Docker build management

Added new Rake tasks to support operational monitoring and maintenance. The \metrics\ namespace provides tasks to check service health (\check\_health\), fetch Kubernetes cluster metrics (\fetch\), and flush metrics older than a week (\flush\). The \monitoring\ namespace includes a task to check for and kill Docker builds that have been running for more than one hour, helping to prevent resource exhaustion from hanging builds. Additionally, an auto-annotation task is configured for development to keep model files annotated.

lib/tasks · high confidence

New UI components for cluster summary, form fields, and selection controls

This change introduces several new ViewComponent classes to enhance the user interface for cluster management and form interactions. The ClusterSummaryCardComponent displays key cluster metrics (node count, version, CPU, RAM) and status alerts. FormFieldComponent provides a standardized layout for form inputs with labels and optional descriptions. RadioSelectCardComponent offers a styled radio button selection interface, supporting both clickable cards and optional hyperlinks. RichSelectComponent replaces standard HTML selects with a customizable, accessible dropdown that supports custom rendering via partials, placeholder text, and disabled options.

app/components · high confidence

New UI for installing and managing cluster system packages

This change introduces the user interface components for the cluster packages feature, allowing users to select, configure, and install system packages (such as the Fluent Bit log drain) on their clusters. The new views include a collapsible list of recommended and optional packages, with support for template variables (strings, booleans, integers, passwords, enums) that can include pattern validation and placeholders. Users can now install, uninstall, retry failed installations, and view the status of packages directly from the cluster management interface.

_app/views/clusters/cluster\packages · high confidence

New account management capabilities: SSO, billing, teams, and stack managers

This change introduces several new controllers for account-level management. Users can now configure Single Sign-On (SSO) via OIDC, SAML, or LDAP through the SSO providers controller, including testing LDAP connections. Account administrators can manage team members (adding, updating roles, removing) and create/edit teams. Billing functionality is added via a Stripe-backed controller for checkout and portal access, gated by cloud mode. Additionally, stack managers (Portainer/Rancher) can be configured, verified, and synced for clusters and registries.

app/controllers/accounts · high confidence

New account settings page with MCP access control

A new account edit view has been introduced, allowing users to update their account name and manage Model Context Protocol (MCP) access. The interface includes a toggle to enable or disable MCP access for the account and provides a link to open a modal with instructions on how to add an MCP server.

app/views/accounts · high confidence

New action for creating stack managers

A new StackManagers::Create action has been added to handle the creation of stack managers. This action manages the transactional logic for assigning attributes to a stack manager, saving it, and linking or initializing a user provider with the corresponding access token.

_app/actions/stack\managers · high confidence

New async search dropdown component with floating UI positioning

A new base controller for async search dropdowns has been added to the application, providing a reusable component for search interfaces. This controller integrates the @floating-ui/dom library to handle precise positioning of the dropdown menu relative to the input field, ensuring it stays visible during scrolling and resizing. It includes built-in support for debounced search queries, loading states, and click-outside dismissal, offering a more robust and consistent user experience for search interactions compared to previous implementations.

app/javascript/controllers/components · high confidence

New background jobs for add-on lifecycle management

This change introduces four new background jobs to handle the installation, uninstallation, demo reset, and cleanup of add-on resources. The InstallJob manages Helm chart deployment and triggers a service restart only when updating an existing installation. The UninstallJob handles the removal of Helm releases. The ResetDemoJob allows for reinstalling an add-on from scratch while preserving the namespace and record, gated by a feature flag. Finally, the CleanupAuthProxyJob removes associated Kubernetes deployments and services labeled as auth-proxy components when an add-on is removed.

_app/jobs/add\ons · high confidence

New billing page with per-cluster pricing and Stripe integration

A new billing page has been added to the account settings, allowing users to view their current plan, subscription status, and cluster usage. The page implements per-cluster pricing, showing that the first cluster is free and additional clusters cost $20/month each. For Pro users with a Stripe customer ID, a button is provided to manage billing details via Stripe's portal. Free users are presented with an upgrade path to Pro, highlighting benefits like unlimited clusters, team members, priority support, and SSO/SAML authentication.

app/views/accounts/billing · high confidence

New branded error pages and developer documentation assets

The public site now includes custom-styled error pages for 404, 406 (unsupported browser), 422, and 500 status codes, featuring a consistent dark theme, responsive layouts, and unique illustrations. Additionally, an \llms.txt\ file has been added to provide a structured overview of the Canine platform's architecture and features for AI agents, alongside a new SVG icon and terminal recording assets.

public · high confidence

New build configuration form with Buildpacks and Kubernetes build cloud support

The project build configuration interface has been redesigned to offer more granular control over how applications are built. Users can now choose between Dockerfile and Cloud Native Buildpacks as the build method; the Buildpacks option includes a dedicated UI for selecting a base builder and managing a list of buildpacks via a modal dialog. Additionally, the form introduces a 'Build driver' selection allowing users to switch between Local Docker, the platform's managed 'Canine Cloud', or a 'Kubernetes Build Cloud' that lets users select a specific active cluster for distributed builds. The form also features a rich select component for choosing container registry credentials and an expandable section for specifying a custom image repository.

_app/views/projects/build\configurations · high confidence

New buildpack and Dockerfile builder implementations for frontend services

Added two new builder classes, BuildpackBuilder and DockerfileBuilder, to the frontend service location. BuildpackBuilder enables building images using Cloud Native Buildpacks via the 'pack' CLI, supporting ordered buildpacks, automatic build arguments (GIT\_SHA, BUILD\_TIMESTAMP), and digest extraction from build reports. DockerfileBuilder enables building images using Docker Buildx, supporting custom Dockerfiles, platform specification (linux/amd64), automatic build arguments, environment variable injection, and digest extraction from metadata files. Both builders integrate with the existing build infrastructure to provide alternative image building strategies for frontend projects.

app/services/builders/frontends · high confidence

New cluster management actions and team-based access control

This change introduces a suite of new action classes in app/actions/clusters to handle cluster lifecycle operations, including creation, installation, YAML export, and filtering. It implements team-based visibility for clusters, restricting access based on team resources rather than showing all clusters to all account members. The installation process now uses a modular recipe system that syncs package statuses before installing components, and includes logic to skip already-installed components like cert-manager and traefik. Additionally, it adds support for exporting cluster YAML with sensitive data sanitization and validates kubeconfig structures before attempting connections.

app/actions/clusters · high confidence

New cluster management capabilities for build clouds, packages, and metrics

Users can now manage cluster resources directly through the UI. A new Build Clouds controller allows installing, updating, refreshing, and destroying build clouds on clusters, including handling status checks and error states. A Cluster Packages controller enables installing, uninstalling, and syncing Helm-like packages on clusters. Additionally, a Metrics controller provides node-level CPU and memory metrics over configurable time ranges, supporting async loading and time-range searches.

app/controllers/clusters · high confidence

New cluster metrics dashboard with live and historical views

Users can now view cluster resource usage through a new metrics page that displays both live and historical data. The live view provides a real-time table of node-level CPU and memory usage, as well as per-pod resource consumption within namespaces, with automatic updates every 30 seconds. The historical view allows users to select a time range (from 2 hours up to 288 hours ago) and toggle between percentage and total metric displays for CPU and memory usage charts.

app/views/clusters/metrics · high confidence

New cluster type selection cards for K3s, Managed Kubernetes, and Local K3s

The cluster selection interface now includes dedicated cards for three distinct cluster types: External K3s (highlighting Hetzner VPS options starting at $4/month), Managed Kubernetes (covering providers like Digital Ocean, Linode, and Vultr with Linode starting at $12/month), and Local K3s or K3d for local development via kubeconfig upload. These new UI components allow users to easily identify and select their preferred cluster environment based on infrastructure needs and budget.

_app/views/clusters/cluster\types/cards · high confidence

New credentials management interface for Git and container registries

The application now provides a dedicated credentials page where users can add, view, and manage access tokens for GitHub, GitLab, Bitbucket, and custom container registries (including Docker Hub, GitHub Container Registry, Google, AWS, and Azure). The new interface supports configuring Enterprise server URLs for Git providers and allows users to update their Portainer access token directly within the settings. Users can also view which projects are currently using each credential and manage API tokens in a separate section.

app/views/providers · high confidence

New custom domain management interface for services

Users can now add, view, and remove custom domains directly from the service page. The new interface includes a form to register domains, a table listing existing domains with their associated ingress controller (Traefik or Nginx), and asynchronous rendering for cluster IP and certificate status. Domain names are clickable to copy to the clipboard, and a dedicated button allows users to manually refresh DNS verification status.

app/views/projects/services/domains · high confidence

New email notification template for user alerts

A new HTML email template has been added for the notifier mailer, providing a structured layout for alert notifications. The template displays a main title, a table of key-value fields for detailed information, and a prominent call-to-action button linking to a specified URL, ensuring users receive clear and actionable email updates.

_app/views/notifier\mailer · high confidence

New endpoint management UI with SSO protection and ingress support

Users can now view and edit add-on endpoint configurations through a dedicated interface. The new endpoint list displays internal cluster URLs (with copy-to-clipboard functionality) and external URLs derived from ingress rules. The edit page allows users to configure domains for an endpoint, with clear instructions on creating the necessary DNS A or CNAME records pointing to the provided IP or target. Additionally, this view includes controls to enable or disable Canine SSO protection for the endpoint, requiring login before access.

_app/views/add\ons/endpoints · high confidence

New generic chart component with Stimulus controller

A new shared partial \\_chart.html.erb\ has been introduced to render metric charts. This component provides a standardized UI structure featuring a title and a 400px high container that integrates with a \chart\ Stimulus controller. The controller receives chart configuration via a \data-chart-config-value\ attribute, allowing views to pass specific chart data and settings dynamically.

app/views/shared/charts · high confidence

New global search action aggregating projects, clusters, and add-ons

A new \GlobalSearch::Search\ action has been introduced to handle global search queries. When invoked with a query string, it concurrently retrieves matching projects, clusters, and add-ons by delegating to their respective list services, applying the specified limit to each result set. If the query is empty, it returns empty arrays for all categories, ensuring a consistent response structure for the global search interface.

_app/actions/global\search · high confidence

New interface for managing cloud development environments

Users can now view and create managed cloud development environments directly from the project settings page. The new Development Environments index displays the project's template configuration (including target cluster, Dockerfile path, and workspace mount) and lists all active environments with their status, branch, and creator. A modal dialog allows users to create a new environment by selecting an existing Git credential, with an option to add new credentials if none are available.

_app/views/projects/development\environments · high confidence

New interface for managing project environment variables

Users can now manage environment variables for a project through a dedicated view that supports both individual creation and bulk import via .env file paste. The interface includes an 'Add new environment variable' button for single entries, a text area for pasting multiple key-value pairs, and a 'Download as .env' link to export current variables. The view utilizes a JavaScript controller to handle the dynamic addition of variables and form submission states.

_app/views/projects/environment\variables · high confidence

New onboarding flow supporting in-cluster installation and build cloud setup

The onboarding process now supports both standard and in-cluster installation modes. When a user opts to connect an in-cluster environment, the system automatically creates an 'in-cluster' cluster record, installs default or specified system packages, and triggers the build cloud installation if requested. The flow begins by creating or updating the user account and setting them as an admin owner, then conditionally proceeds with cluster setup based on user selection.

app/actions/onboarding · high confidence

New onboarding flow with account selection and multi-provider support

The local onboarding experience has been restructured to begin with an account selection screen, allowing users to choose an existing account or create a new one. The main onboarding index now presents three installation methods: Normal (standard installation), Portainer (integration with existing Portainer instances), and Rancher (integration with existing Rancher instances). Each method provides a dedicated configuration form, including fields for account details, admin user credentials, and provider-specific settings such as URLs, API keys, and cluster connection options.

app/views/local · high confidence

New pod listing view model for add-on processes

A new PodsViewModel has been introduced for the Async Add-Ons Processes area, enabling users to view pods associated with a specific add-on. This component initializes a Kubernetes client using a connection-based integration (passing the add-on's cluster and current user) to fetch pods within the add-on's namespace. It provides a skeleton loading state during initial render and displays the retrieved pods in a table, showing an empty message if no pods are found in the namespace.

_app/view\_models/async/add\ons/processes · high confidence

New process management views for pods and interactive shells

This change introduces two new view templates in the processes area: a pod listing table and an interactive terminal interface. The pod list displays key metadata (name, status, message, creation time) and provides action buttons to view logs, open a shell (only for running pods), or delete pods, with appropriate warnings for running instances. The terminal view establishes a live shell session UI with file upload support via drag-and-drop, connection status indicators, and a modal dialog offering instructions for connecting via the Canine CLI or kubectl.

app/views/processes · high confidence

New processes view for add-ons

Users can now view and manage processes within an add-on. The index page lists processes using an asynchronous renderer, while dedicated views allow users to open an interactive shell in a pod and view pod logs along with associated events.

_app/views/add\ons/processes · high confidence

New project fork and development environment creation workflows

Users can now create project forks and development environments through new action classes that orchestrate the process. Fork creation (\ProjectForks::Create\) builds a definition from the parent project, overrides project attributes with pull request details, and merges configuration from the PR's \.canine.yml\ file (scripts, services, variables, volumes, notifiers) before initializing the fork record. Development environment creation (\ProjectForks::CreateDevelopmentEnvironment\) similarly starts from the parent's config but applies dev-specific overrides: it generates a unique name suffix, switches to a custom Dockerfile if configured, strips parent domains, injects git credentials and user info as environment variables, and adds a workspace volume based on the project's development environment configuration.

_app/actions/project\forks · high confidence

New project lifecycle jobs for builds, deployments, and destruction

This change introduces a new set of background jobs to manage the project lifecycle. Projects::BuildJob handles building Docker images using Kubernetes, Docker, or Cloud drivers, cloning repositories, and triggering deployments. Projects::CheckForNewCommitsJob automatically detects new commits and queues builds. Projects::DeploymentJob manages deployments via Helm or a legacy method. Projects::DestroyJob handles project teardown with retry logic for uninstallation, domain cleanup, and webhook removal. Projects::DoctorJob runs diagnostics with concurrency limits to prevent overlapping runs. Projects::ResetDemoJob supports demo mode by resetting projects via Flipper feature flags.

app/jobs/projects · high confidence

New project management controllers for deployments, environments, and services

This change introduces a comprehensive set of new controllers under app/controllers/projects to manage project lifecycle and configuration. Users can now trigger deployments and redeployments, kill in-progress builds or deployments, and migrate projects between clusters via the new Deployments and ClusterMigrations controllers. Development environments are managed through dedicated controllers for configuration, creation, and forking (preview apps). Additional controllers provide interfaces for managing environment variables, project metrics, notifiers, volumes, services, and workbenches (including shell access and log streaming). These controllers rely on a new BaseController that establishes a K8::Connection for the project, centralizing Kubernetes interaction for these features.

app/controllers/projects · high confidence

New project uninstall services for Helm and legacy deployments

Added new service classes to handle project uninstallation, introducing a base service that manages connection setup, pre/post-destroy commands, and namespace deletion. Two specific implementations are provided: HelmUninstallService, which uses the Helm client to uninstall releases, and LegacyUninstallService, which deletes specific Kubernetes resources (ConfigMap, Secrets, Deployment, CronJob, Service, Ingress, Pvc) labeled with 'caninemanaged=true'.

app/services/projects · high confidence

New scheduled jobs for system maintenance and demo management

This change introduces a suite of new background jobs in the scheduled namespace to handle routine maintenance and demo environment management. Specifically, it adds jobs to cancel hanging builds and deploys that have been in progress for over an hour, sweep stale DNS records for auto-managed domains, and clean up expired shell sessions. It also includes jobs to reset demo projects and add-ons based on a configurable interval (defaulting to 24 hours) when demo mode is enabled via Flipper, as well as jobs to fetch cluster metrics, check service health, and monitor for new commits in autodeploy-enabled projects.

app/jobs/scheduled · high confidence

New service-level management controllers for domains, jobs, OAuth, and resources

Users can now manage specific aspects of individual services directly from the service context. This change introduces dedicated controllers that allow creating and deleting service domains (with DNS status checks), manually triggering and deleting Kubernetes jobs based on cron schedules, enabling/disabling internal SSO and service proxies, and configuring resource constraints (CPU, memory, GPU requests/limits). These capabilities are now handled via a new base controller that ensures the correct service context is set for each action.

app/controllers/projects/services · high confidence

New shared UI components for forms, wizards, and async rendering

Added several new shared view partials to support enhanced form interactions and wizard-style workflows. The new \_radio\_selector.html.erb provides a card-based selection interface with optional dynamic partials, while \_namespace\_input\_group.html.erb and \_namespace\_show.html.erb handle namespace configuration and display with managed namespace logic. The \_markdown\_editor.html.erb introduces a live-preview markdown input, and \_async\_renderer.html.erb enables deferred content rendering via Stimulus controllers. Additional utilities include \_progress\_stages.html.erb for multi-step progress indicators and \_wizard\_animation.html.erb for visual wizard transitions.

app/views/shared/partials · high confidence

New shell-based installation and management scripts for Dockerized deployment

The installation process now relies on two new shell scripts: \install/install.sh\ handles the initial setup by cloning the repository, verifying Docker and docker-compose availability, generating a secret key, and launching the service; \install/canine\ provides a CLI interface to start, stop, or destroy the running environment. Users can now install and manage the application via these scripts instead of previous methods.

install · high confidence

New static marketing pages and interactive pricing calculator

The site now includes dedicated landing pages for Dev Environments, MCP Tools, and Self-Hosted deployment, along with a new interactive Cloud Provider Pricing Calculator. These pages provide detailed feature breakdowns, installation guides, and SEO-optimized metadata, while the calculator allows users to compare infrastructure costs based on team size, CPU, memory, and replica counts.

app/views/static · high confidence

New user management tools in Avo admin panel

Administrators can now manage individual users directly from the Avo interface with four new capabilities: impersonate a user to view their experience, generate and securely copy temporary login credentials (URL, email, and password) after a password reset, disable two-factor authentication for specific users, and promote or demote users to site admin status. These features are presented in a dedicated user tool panel with dark-mode styling consistent with the core app theme.

_app/views/avo/resource\tools · high confidence

New utility functions for URL reachability and Portainer connectivity checks

Added a new \debounce\ utility function to \app/javascript/utils/index.js\ for delaying function execution. Introduced a \PortainerChecker\ class in \app/javascript/utils/portainer.js\ that provides methods to check URL reachability via \/stack\_manager/check\_reachable\, verify general connectivity via \/stack\_manager/verify\_connectivity\, and validate Portainer URLs with access tokens via \/stack\_manager/verify\_url\, returning standardized status results (ok, unauthorized, error).

app/javascript/utils · high confidence

OIDC SSO provider configuration form added

The account settings interface now includes a new form for configuring OpenID Connect (OIDC) Single Sign-On providers. Users can input the Issuer URL, Client ID, and Client Secret, along with optional scopes. An advanced settings section allows manual specification of authorization, token, and userinfo endpoints, as well as the JWKS URI, for providers that do not support automatic discovery. Additionally, users can map specific claims for the user ID, email, and display name. The form also displays the specific redirect URI that must be configured in the external OIDC provider.

_app/views/accounts/sso\providers/oidc · high confidence

Portainer onboarding flow for self-hosted accounts

Users can now onboard a self-hosted Portainer instance directly through the application. This new flow validates that the system is not in cloud mode, authenticates with the Portainer provider using credentials, and automatically creates a new account and user (promoting the user to admin if new). It also configures a StackManager linked to the Portainer instance and triggers the initial synchronization of clusters and registries.

lib/portainer/onboarding · high confidence

Project metrics dashboard now displays live pod resource usage and historical charts

Users can now view a dedicated metrics page for their projects, featuring a live-updating table that shows current CPU and memory consumption for each pod, alongside historical usage charts for both metrics. The interface includes a live status indicator and refreshes automatically every 30 seconds to reflect real-time cluster data.

app/views/projects/metrics · high confidence

Redesigned layout with new sidebar, email preferences, and PWA support

The application interface has been significantly restructured: the main layout now features a collapsible sidebar with an account switcher, a dedicated homepage layout with a dark theme, and a new email preferences page for managing notifications. Email templates have been updated to include a branded header and a link to these preferences. Additionally, Progressive Web App (PWA) capabilities are introduced via a manifest and service worker, and the application now supports dynamic theme switching.

app/views/layouts · high confidence

Repository selection modal and list view added

Users can now select repositories via a new modal interface that includes a searchable list of available repositories and a dedicated section for entering public repository URLs. The list view displays repository names with a 'Connect' button for each, while the modal provides a search input to filter the list and an input field for manual URL entry, enabling users to back services with either private or public repositories.

app/views/integrations · high confidence

Resource constraints can now be created and updated for namespaces

Users can now define and modify resource constraints (such as CPU requests and limits) associated with namespaces. The system automatically converts CPU values from cores to millicores and normalizes blank string inputs to nil before saving the configuration.

_app/actions/resource\constraints · high confidence

SAML Single Sign-On configuration form

The SSO provider setup interface now includes a dedicated form for configuring SAML-based identity providers. Users can input essential connection details such as the IdP Entity ID, SSO Service URL, and X.509 certificate, along with optional advanced settings like Single Logout URLs, custom Service Provider Entity IDs, Name Identifier formats, and request signing preferences. The form also provides fields for mapping SAML attributes to user identifiers, emails, names, and group memberships, and displays the account-specific ACS and Metadata URLs required to complete the IdP configuration.

_app/views/accounts/sso\providers/saml · high confidence

SSO provider management UI now supports LDAP, OIDC, and SAML

The SSO provider settings interface has been updated to allow users to create, view, edit, and delete Single Sign-On providers for LDAP, OpenID Connect (OIDC), and SAML 2.0. The new views include a unified form for configuring provider details (name, enabled status, team provisioning mode) and type-specific configuration fields, as well as a dashboard view that displays provider status, user counts, and key configuration details like LDAP host/base DN, OIDC issuer/client ID, or SAML IdP metadata.

_app/views/accounts/sso\providers · high confidence

SSO user and team synchronization logic

The application now includes specific action classes to handle user and team synchronization via SSO. When a user authenticates, the system attempts to link them to an existing account via their SSO provider identity or creates a new user account if none exists, updating their name on every login. Additionally, the system can automatically create local teams based on remote team names and synchronize team memberships, adding the user to relevant teams and removing them from any local teams they are no longer part of in the remote source.

app/actions/sso · high confidence

Stripe billing webhook integration for per-cluster pricing

A new Stripe webhook controller has been added to handle billing events for per-cluster pricing. This controller processes checkout completions, subscription updates, and deletions to automatically update account plans and subscription statuses. The feature is gated behind the \cloud\_mode\ configuration, ensuring it only activates in cloud environments.

app/controllers/webhooks · high confidence

Support for Bitbucket, GitHub, and GitLab webhook-driven builds

Users can now trigger automatic Docker builds and deployments via webhooks from Bitbucket, GitHub, and GitLab. New job classes (BitbucketJob, GithubJob, GitlabJob) parse platform-specific push events to identify the repository and branch, then create a build record and enqueue a build job for any matching project configured with auto-deploy. An IncinerationJob is also introduced to handle the cleanup of processed inbound webhook records.

_app/jobs/inbound\webhooks · high confidence

Support for GitHub, GitLab, and Bitbucket webhook integrations

The application now accepts inbound webhooks from GitHub, GitLab, and Bitbucket. Each provider has a dedicated controller that validates the incoming event signature (using HMAC-SHA256 for GitHub and Bitbucket, and token comparison for GitLab) before persisting the payload and queuing it for asynchronous processing. This allows users to connect their repositories from these three major Git platforms to trigger automated workflows.

_app/controllers/inbound\webhooks · high confidence

Support for bulk updating and pasting environment variables

Users can now update multiple environment variables at once via a bulk update action, which handles creating, updating, and deleting variables in a single transaction. This includes a new feature to paste text content (key=value pairs) to automatically parse and apply changes, streamlining the management of environment configurations.

_app/actions/environment\variables · high confidence

Support for creating GitHub, GitLab, Bitbucket, and custom container registry providers

Users can now configure and validate credentials for GitHub, GitLab, Bitbucket, and custom container registries. The system validates access tokens and scopes (skipping strict scope checks for enterprise instances), retrieves user information, and generates the necessary Docker configuration JSON for authenticated registry access.

app/actions/providers · high confidence

Team member and resource access management

Users can now manage team composition and permissions through new backend endpoints. The system supports searching for account users to add as team members, handling the addition and removal of team memberships, and granting or revoking access to specific resources such as clusters, projects, and add-ons within the team context.

app/controllers/accounts/teams · high confidence

Team member management and invitation interface

The Team Members settings page now allows administrators to view, manage, and invite users to the account. The member list displays each user's name, email, role, and 2FA status, and enables admins to change roles or remove non-owner members. A new modal facilitates inviting new members by email, providing a temporary password and login credentials that can be copied or sent via email if SMTP is configured.

_app/views/accounts/account\users · high confidence

Teams management interface for resource access control

The Teams settings page now provides a complete interface for organizing account members and controlling resource access. Users can create and edit teams, view a list of all teams with member and resource counts, and manage individual team details. Within a team, users can add or remove members via a search-based modal and assign specific resources—Clusters, Projects, and Add-ons—through dedicated tabs and search modals. An empty-state landing page explains the benefits of teams and guides users to create their first one.

app/views/accounts/teams · high confidence

Workbench session management and setup progress UI

The workbench view now includes a modal for managing active shell sessions, displaying a count of connected sessions and a list where users can identify and terminate individual sessions. Additionally, a setup progress component provides real-time feedback on the workbench initialization status, showing stages of cloning, errors, or warnings if the environment is not running.

app/views/projects/workbenches · high confidence

Removals

Removal of Madmin impersonation controller

The Madmin impersonation functionality has been removed from the application. The \app/controllers/madmin/impersonates\_controller.rb\ file, which previously allowed administrators to impersonate users via the Madmin dashboard, has been deleted. Users can no longer switch identities to act as other users through this interface.

app/controllers/madmin · high confidence

Security

Secure YAML configuration parsing with restricted templating

The \app/services/canine\_config\ service now parses \canine.yml\ files using a dedicated \Definition\ class that replaces ERB-based template processing with a safe, restricted variable substitution mechanism. This change prevents arbitrary code execution by only allowing simple variable replacements (e.g., \\<%= variable\_name %\>\) and ignoring complex expressions or method calls. The service also introduces new actions to initialize project resources (services, environment variables, volumes, notifiers) and restore project definitions from serialized configurations, ensuring that configuration data is handled securely and consistently during project creation and migration flows.

_app/services/canine\config · high confidence

Behavioural changes

API response structure refactored to use view models and partials

The JSON serialization for the Projects and Clusters API endpoints has been refactored to use dedicated view models and partials. Project list and show responses now delegate to \Api::Projects::ListViewModel\ and \Api::Projects::ShowViewModel\ respectively, while cluster responses use \Api::Clusters::ShowViewModel\. Additionally, pod details in the processes API are now rendered via a shared partial, standardizing the output format for pod metadata, status, and labels.

app/views/api/v1/projects · high confidence

Account-centric authentication and self-hosted registration controls

The user registration and login flows now automatically create a default account for new users, linking them as owners. Sign-up is disabled for self-hosted deployments, redirecting users to the login page instead. The login process now supports account-specific authentication via slugs, allowing users to log in directly to a specific organization's context. Additionally, the system now enforces TOTP two-factor authentication for logins when enabled, and the legacy Service model for social logins has been replaced by a Provider model to better support multiple SSO types like LDAP, OIDC, and SAML.

app/controllers/users · high confidence

Add-on management refactored into dedicated action classes with OCI and Artifact Hub support

The add-on installation and configuration logic has been restructured into a suite of dedicated action classes (e.g., \AddOns::Create\, \AddOns::InstallHelmChart\, \AddOns::ApplyEndpointIngress\) to improve maintainability and separation of concerns. This change introduces native support for Helm charts hosted in OCI registries (via \oci://\ URLs) alongside traditional HTTP repositories, and integrates with Artifact Hub for fetching chart metadata, versions, and values schemas. Additionally, the system now supports templated add-on values, allowing users to define dynamic configuration parameters that are processed during installation, and enforces namespace management rules to ensure add-ons are deployed to valid, isolated Kubernetes namespaces.

_app/actions/add\ons · high confidence

Add-on management refactored into dedicated controllers with new capabilities

The add-on management interface has been restructured into specific controllers (Endpoints, Metrics, OAuth Applications, Processes, Cluster Migrations) inheriting from a new base controller that standardizes Kubernetes connection handling. This change introduces several new user-facing capabilities: users can now migrate add-ons to different clusters via a dedicated migration flow, enable or disable internal SSO protection for add-ons, view historical metrics even if the cluster is temporarily unreachable, and access pod logs and events with improved error handling for missing resources. Additionally, an online shell feature has been added for debugging pod processes, and endpoint configuration now includes validation for domain formats and port mappings.

_app/controllers/add\ons · high confidence

Add-ons API now uses view models for JSON serialization

The API responses for listing and showing add-ons have been refactored to use dedicated view models (Api::AddOns::ListViewModel and Api::AddOns::ShowViewModel) instead of direct object serialization. This change centralizes the JSON structure logic for the add-ons index and show endpoints, ensuring consistent data formatting for API consumers.

_app/views/api/v1/add\ons · high confidence

Add-ons management UI overhaul with install tracking and migration

The add-ons interface has been rebuilt to provide a comprehensive management experience. Users can now install add-ons via a new creation flow that supports chart selection, versioning, and YAML configuration with autocomplete. During installation, a dedicated layout displays a multi-stage progress tracker and allows users to view real-time logs. The edit page now includes a cluster migration tool to copy an add-on to a different cluster, alongside standard configuration and deletion options. The main index view presents add-ons in a sortable table, and the show view features a tabbed sidebar for navigating Info, Processes, Metrics, and Settings.

_app/views/add\ons · high confidence

Added DNS verification for ingress domains

Users can now automatically verify the DNS status of domains associated with their ingress resources. A new \Networks::CheckDns\ action performs live DNS lookups (A or CNAME records) to confirm that the domain points to the expected IP address or hostname, updating the domain status to either 'dns\_verified' or 'dns\_incorrect' with a specific reason if the record does not match.

app/actions/networks · high confidence

Admin panel migrated to Avo with comprehensive resource definitions

The admin interface has been switched to the Avo framework, introducing a complete set of resource definitions for managing system entities. Administrators can now view and search Accounts, Projects, Clusters, Teams, and Users, with detailed views for Build logs, Deployments, and Services. The update also adds configuration resources for SSO providers (OIDC, SAML, LDAP), allowing admins to manage authentication settings, alongside resources for Add-ons, Domains, and Development Environments.

app/avo · high confidence

Admin panel migration to Avo with new management capabilities

The admin interface has switched from Active Admin to Avo, introducing a new dashboard and resource controllers for managing accounts, builds, clusters, projects, teams, and users. Administrators can now impersonate users, reset user passwords with temporary credentials, disable two-factor authentication, and promote or demote users to site admin status directly from the panel.

app/controllers/avo · high confidence

Async loading and dual metric support for cluster metrics

The cluster metrics view now loads asynchronously using Turbo Frames to improve page responsiveness, and displays both CPU and Memory usage charts. The view utilizes a dedicated view model to handle data preparation and includes a search partial to allow users to filter or configure the metric display.

_app/views/add\ons/metrics · high confidence

Async rendering of Kubernetes cluster and service details

The Kubernetes dashboard now loads cluster information (server version, server address), node metrics (CPU and memory usage for nodes and pods), service cluster IPs, and certificate status asynchronously. This change improves perceived performance by showing loading spinners immediately and fetching data in the background, while also introducing a new view for certificate issuance status and refining the node metrics table to display both node-level and per-namespace pod-level resource usage.

_app/view\models/async/k8 · high confidence

Automatic HTTPS prefix for APP\_HOST configuration

The application now normalizes the APP\_HOST environment variable to ensure it always includes a protocol scheme. If the provided value does not start with 'http', the system automatically prepends 'https://', allowing users to configure the host using either a bare hostname or a full URL without manual protocol specification.

app/lib · high confidence

Custom OAuth authorization UI with PKCE support

The application now provides custom views for the Doorkeeper OAuth flow, replacing the default interface with a styled card-based layout. Users will see a new authorization screen that clearly displays the requesting client's name and the specific scopes being requested, along with explicit 'Authorize' and 'Deny' buttons. The flow now supports PKCE (Proof Key for Code Exchange) by passing code challenge parameters in the authorization request. Upon successful authorization, a dedicated success page displays the generated authorization code for the client to use.

app/views/doorkeeper · high confidence

Custom Turbo confirmation modals and removal of Bootstrap UI components

The application now uses a custom HTML dialog for form confirmations via Turbo, replacing the previous default browser alerts with a styled modal that supports dynamic titles and button types. This change is accompanied by the removal of Bootstrap's tooltip and popover initialization logic from the main application entry point, while adding Chartkick integration for data visualization.

app/javascript · high confidence

Customized Avo admin panel styling and branding

The Avo admin panel now features a dark mode theme with colors matched to the core application, uses the DM Sans font family for consistency, and displays a 'Site Admin' label in the header. The footer has been updated to show 'Canine, Inc.' branding instead of the default Avo attribution, and link colors have been adjusted to use a subtle indigo accent.

app/views/avo/partials · high confidence

Display historical metrics when cluster is unreachable

The metrics view now renders historical data even if the cluster is unreachable, ensuring users can still see past metrics instead of being blocked by connectivity issues.

_app/view\_models/async/add\ons/metrics · medium confidence

Fluent Bit log drain output switched to S3

The Fluent Bit configuration has been updated to send container logs to an S3 bucket instead of CloudWatch. Users can now configure the target S3 bucket and AWS region via Helm values, with logs organized by date and tag in the specified bucket path.

resources/helm/values · high confidence

Global search results UI for projects, clusters, and add-ons

The search interface now displays results for projects, clusters, and add-ons using a consistent, styled list layout. Each result type includes a relevant icon or logo, the item name with query highlighting, and contextual metadata such as the cluster name, project repository URL, or associated project/add-on counts. Results are grouped by type with section headers and updated dynamically via Turbo Streams.

app/views/search · high confidence

Improved mobile keyboard experience for email input fields

The email input fields on the confirmation and unlock pages now include the inputmode attribute set to 'email'. This change ensures that mobile devices present the optimized email keyboard layout when users type their email addresses, improving usability and reducing typing errors on touchscreens.

app/views/devise/confirmations, app/views/devise/unlocks · high confidence

Initial Rails 8 environment configuration files added

The application now includes explicit configuration files for development, production, and test environments, marking the completion of the Rails 8 upgrade in this area. In development, code reloading is enabled, mailers use the letter\_opener delivery method for local previewing, and ngrok hostnames are permitted for tunneling. Production mode enforces SSL by default (with exceptions for local or cluster modes), logs to STDOUT, and dynamically configures allowed hosts based on the ALLOWED\_HOSTNAME environment variable to support Kubernetes deployments. The test environment isolates storage and jobs, disables forgery protection, and configures GoodJob to avoid persisting job records.

config/environments · high confidence

Internal SSO proxy configuration now enforces HTTPS redirect URIs

The internal SSO logic has been refactored into dedicated actions that manage OAuth application creation and proxy deployment. A key behavioral change is that redirect URIs for both services and add-ons are now explicitly constructed with the 'https://' scheme (e.g., 'https://{domain}/oauth2/callback'), ensuring secure callback endpoints. Additionally, the system now normalizes the base application host to handle both bare hostnames and full URLs when generating these URIs.

_app/actions/internal\sso · high confidence

Introduce dedicated controller for managing Portainer API tokens

Users can now explicitly manage their Portainer API access tokens through a new dedicated controller. This change introduces a specific workflow for updating and removing individual Portainer credentials, replacing the previous stack-manager-based authentication approach. The new flow validates the token against the Portainer API, stores the access token and associated username, and clears any cached token state upon update or removal, ensuring that only accounts with Role-Based Access Control (RBAC) enabled can utilize this individual credential management feature.

app/controllers/providers · high confidence

Introduces passwordless local authentication and multi-method onboarding

Users can now log in to local instances without a password if the feature is enabled, with the system automatically signing in the owner when only one user exists. The onboarding process has been refactored to support multiple cluster integration methods, including Portainer, Rancher, and standard in-cluster setups, while protecting routes to prevent re-onboarding once a user account is established.

app/controllers/local · high confidence

Introduces structured project lifecycle actions and a live diagnostic system

This change replaces ad-hoc project logic with a suite of dedicated action classes (using LightService) that manage the project creation, update, and deployment workflows. Key additions include \Projects::Create\ and \Projects::Update\ which orchestrate source configuration, build configuration, and namespace setup; \Projects::DeployLatestCommit\ which supports skipping builds to reuse previous deployment digests; and \Projects::Doctor\, which provides a live, Turbo Stream-based diagnostic modal to check cluster connectivity, source repository access, registry authentication, and build cloud status. The diff also introduces \Projects::VisibleToUser\ to enforce team-based project visibility and \Projects::Filter\ for search functionality.

app/actions/projects · high confidence

Introduction of comprehensive view helpers and removal of Bootstrap styling

The application introduces a wide range of new helper modules to support UI rendering and data processing, including \AddOnsHelper\ for add-on layouts and logo URLs, \ApplicationHelper\ for custom Pagy pagination and color generation, \AvoDashboardHelper\ for status-based color styling, \ClustersHelper\ for cluster-specific icons, \LogColorsHelper\ for converting ANSI codes to Tailwind classes, \MetricsHelper\ and \NamespaceMetricsHelper\ for sampling and parsing CPU/memory metrics, and \StorageHelper\ for converting between integer and human-readable compute/memory units. Additionally, \TurboStreamActionsHelper\ adds custom Turbo Stream actions, while \Eventable\ and \Loggable\ concerns provide event tracking and structured logging capabilities. As part of this shift, the legacy \BootstrapHelper\ has been removed, indicating a migration away from Bootstrap CSS classes in favor of the new Tailwind-based styling infrastructure.

app/helpers · high confidence

Landing page redesigned with new sections and interactive demos

The landing page has been completely rebuilt with a new dark-themed layout, featuring a hero section, a CLI demo using Asciinema, and dedicated sections for features, Kubernetes self-hosting, and pricing. The page now includes an interactive MCP terminal animation, a cost comparison chart, and a swipeable card stack for mobile. Navigation has been updated with dropdowns for Product and Resources, and the footer now links to a Cost Calculator, Privacy, and Terms pages.

_app/views/static/landing\page · high confidence

MCP tool authentication and account scoping logic

Added a new authentication concern for MCP tools that enforces account-level access control and feature flags. This module handles user identification, resolves the correct account user context, and blocks tool execution if the account does not have MCP enabled or if the user lacks access to the specified account.

app/mcp/tools/concerns · high confidence

Migrate styling to Tailwind CSS and add component assets

The application's styling system has been replaced with Tailwind CSS, introducing a new \application.tailwind.css\ entry point that imports base, component, and utility layers alongside specific libraries like Tippy.js and xterm.js. This change adds comprehensive styles for UI components, including navigation, pagination, forms, tables, and custom alerts/badges, while removing legacy SCSS files such as \jumpstart/announcements.scss\. Additionally, new asset directories for builds and images have been created, and specific styles for ApexCharts and a Pacman loading animation have been added to support new visual features.

app/assets · high confidence

New API view models for structured JSON serialization

This change introduces a comprehensive set of new view models in the \app/view\_models/api\ directory to standardize how API responses are serialized. These view models cover key resources including accounts, add-ons, builds, clusters, deployments, environment variables, helm charts, pods, projects, and providers. By centralizing the \as\_json\ logic, the API now provides consistent, structured responses for listing and showing details of these resources, such as including build logs for builds, endpoint and connection data for add-ons, and deployment history for projects.

_app/view\models/api · high confidence

New actions for saving development environment configurations and destroying development environments

This change introduces two new action classes to handle specific lifecycle operations for development environments. The \DevelopmentEnvironmentConfigurations::Save\ action now encapsulates the logic for persisting configuration changes, ensuring that save failures are properly reported. Additionally, the \DevelopmentEnvironments::Destroy\ action provides a dedicated mechanism for removing development environments, which includes disconnecting parent-child fork relationships by destroying associated records. These actions streamline the backend logic for managing the creation and deletion of development environments.

_app/actions/development\_environment\configurations · high confidence

New log viewing interface with live streaming and error handling

The log output views have been replaced with new partials that provide a structured, styled interface for viewing logs. Users can now see logs for general resources via a paginated list (limited to the most recent 100 entries) and for pods via a dedicated view that includes a 'LIVE' indicator for real-time updates. This new pod view also displays startup logs derived from pod events, shows error alerts if log retrieval fails, and offers a link to add an MCP server for debugging assistance.

_app/views/log\outputs · high confidence

New project update forms for Git and Container Registry configurations

The project update interface now uses dedicated form templates for configuring Git repositories and container registries. The Git form allows users to select credentials via a rich select component, specify a branch, enable autodeploy, and optionally configure build settings when the feature is enabled. The Container Registry form provides fields for the repository path, image tag, and predeploy command, while automatically indicating whether credentials are required based on the image's public status. Both forms include submission feedback and consistent error handling.

app/views/projects/update · high confidence

New settings layout with SSO login URL and conditional billing access

The settings interface now uses a new shared layout that displays a copyable Account Login URL for users with an SSO provider and organizes navigation into User and Account sections. The menu includes links to Profile, Credentials, Notifications, General settings, Team Members, Authentication, and Stack Manager. Billing access is now gated behind the cloud\_mode configuration flag, meaning it only appears for users in cloud mode.

app/views/settings · high confidence

Redesigned account management UI with integrated two-factor authentication

The account settings and authentication views have been completely restyled using a modern card-based layout with Tailwind CSS and DaisyUI components, replacing the previous Bootstrap structure. The account edit page now features distinct sections for Profile, Authentication, and a Danger zone, and explicitly hides password change fields for users who signed in via GitHub OmniAuth. A new two-factor authentication setup and management interface has been added, allowing users to enable, disable, and view the status of 2FA directly within the account settings. The sign-up and password reset pages have also been updated to match this new visual design.

app/views/devise/registrations · high confidence

The shared authentication links component now prominently features social sign-in buttons for configured OmniAuth providers (such as GitHub) instead of simple text links, and includes an expandable section explaining why GitHub OAuth permissions are required for container registry access. Additionally, password recovery and confirmation links have been updated to use internationalized text keys and styled as block-level elements for better visual hierarchy.

app/views/devise/shared · high confidence

Redesigned cluster management interface with new lifecycle and configuration features

The clusters section has been completely rewritten with a new layout, sidebar navigation, and status indicators. Users can now create clusters with support for local K3s, K3s, and standard Kubernetes providers, and manage them via a unified dashboard. Key additions include the ability to download kubeconfig files and export Kubernetes YAML manifests (with options to include ConfigMaps and masked Secrets), transfer cluster ownership between accounts, and rerun or retry cluster installations. The edit view allows updating cluster names, skipping TLS verification, and editing kubeconfig credentials directly. The interface also displays system packages (recommended and optional), project and add-on grids, and install logs, while the index page supports pagination and Portainer syncing.

app/views/clusters · high confidence

Redesigned deployment tracking with real-time updates and Kubernetes manifest inspection

The deployments interface has been rebuilt to provide a comprehensive, real-time view of build and deployment events. The index page now lists events with commit details, status badges (including a pending spinner), and timestamps, updating live via Turbo Streams. The show page offers deeper visibility: it displays build and release logs, allows users to kill in-progress builds or deployments, and provides a 'Run Diagnostics' button for failed events. Additionally, a new manifest browser lets users view the Kubernetes manifests associated with a deployment, enhancing transparency into what was actually deployed.

app/views/projects/deployments · high confidence

Redesigned login interface with multi-provider support and account selection

The login experience has been completely overhauled to support multiple authentication methods and account management. The main sign-in page now features a modern card-based layout with Tailwind CSS styling, includes a link to sign up, and conditionally displays a Portainer stack manager badge. New dedicated views have been added for LDAP, OIDC, and SAML authentication, allowing users to sign in via their organization's identity provider. Additionally, a new account selector component enables users to choose between different accounts, displaying specific login options such as passwordless access, SSO providers, or standard password login based on the account's configuration.

app/views/devise/sessions · high confidence

Redesigned project creation flow with Git and Container Registry options

The project creation interface has been restructured into two distinct paths: deploying from a Git repository (supporting GitHub and GitLab) and deploying from a container registry (public or private). The new forms introduce a 'RichSelectComponent' for cluster selection, explicit credential selection via a new 'select\_credentials' partial, and specific fields for image sources, predeploy commands, and build settings. Users are now guided through dedicated views for missing Git or registry credentials, with clear navigation links to switch between deployment types or add necessary integrations.

app/views/projects/create · high confidence

Redesigned project management interface with real-time updates and new capabilities

The project views have been completely overhauled to provide a modern, responsive interface. The project index now displays a table with real-time status updates via Turbo Streams, showing the latest commit SHA and deployment details. The main project layout includes a new header that distinguishes between standard projects, forked preview apps, and development environments, along with a favicon that fetches the site icon via DuckDuckGo. Users can now manage development environment configurations directly from the edit page, including setting target clusters and Dockerfile paths. The interface also supports cluster migration, allowing users to move projects to different clusters, and includes a 'Run Diagnostics' button for troubleshooting. The sidebar has been reorganized to include tabs for Workbench, Deployments, Services, Environment, Processes, Metrics, and Preview Apps, with conditional visibility based on project type and feature flags.

app/views/projects · high confidence

Redesigned resource constraints UI with sliders and enable toggles

The resource constraints interface for services has been replaced with a new form layout featuring dedicated CPU and Memory sections. Each resource type now includes a checkbox to enable/disable the constraint and a range slider (0.1–16 cores for CPU, 128–32768 MB for Memory) alongside a numeric input for precise values. The form supports both creating new constraints and updating existing ones, with appropriate submit buttons and a delete option for persisted constraints.

_app/views/projects/services/resource\constraints · high confidence

Redesigned service management interface with tabbed navigation and SSO protection

The service management UI has been restructured into a tabbed layout (Overview, Networking, Cron Job History, Advanced) to organize configuration options. Users can now enable Canine Single Sign-On (SSO) protection for web services via the Networking tab, which deploys an OAuth2 proxy. The Advanced tab allows editing resource constraints and custom pod template YAML, while the Overview tab consolidates settings for container ports, health checks, replicas, and descriptions. A new Cron Job History tab displays run logs, durations, and statuses, and the service index now includes a Telepresence guide for connecting to private services.

app/views/projects/services · high confidence

Redesigned user interface with Tailwind CSS and new diagnostic tools

The application's user interface has been completely overhauled, migrating from Bootstrap to Tailwind CSS and replacing Font Awesome icons with Iconify. This update introduces a new global search modal, a redesigned navigation bar, and a new password change flow. Additionally, a project 'doctor' system has been added to provide live diagnostic checks and resolution hints during builds, alongside a new MCP modal for AI tool integration and an admin right navigation for managing feature flags and jobs.

app/views/shared · high confidence

Refactor service creation and updates into dedicated action classes

Service creation and update logic has been moved from model callbacks to dedicated action classes (Services::Create, Services::Update, etc.) using the LightService library. This change centralizes the handling of service associations, cron schedule updates, and auto-managed domain attachment, ensuring that these side effects are executed explicitly during service lifecycle operations rather than implicitly through model callbacks.

app/actions/services · high confidence

Refactored API build views to use view models

The JSON serialization logic for the builds API has been refactored to use dedicated view models. The show and index endpoints now delegate to a shared partial, which in turn utilizes the \Api::Builds::ShowViewModel\ to structure the build data, replacing the previous inline serialization logic.

app/views/api/v1/builds · high confidence

Refactored cluster package installers with skip logic and new package support

The cluster package installation logic has been refactored to use a base installer class that handles Helm and manifest deployments, with specific installers for Cert Manager, Cloudflared, Fluent Bit, Metrics Server, Nginx Ingress, and Telepresence. Cert Manager and Traefik Ingress installers now check for existing installations and skip if already present. Fluent Bit installer now uses an ERB template for Helm values and supports AWS S3 log drain configuration. The base installer also checks for installed packages across all namespaces.

_app/models/cluster\package · high confidence

SSO provider configuration logic refactored into dedicated action classes

The logic for creating and updating SSO provider configurations has been restructured into a set of dedicated action classes within the \app/actions/sso\_providers\ directory. This change introduces \BuildSSOConfiguration\ to handle the instantiation of specific configuration objects (LDAP, OIDC, SAML) based on the provider type, and \SaveConfiguration\ to persist both the configuration and the provider record. Additionally, \Create\ and \Update\ organizers orchestrate these steps, while \UpdateConfiguration\ handles the specific logic for modifying existing configurations. This refactoring centralizes the behavior for managing SSO provider settings.

_app/actions/sso\providers · high confidence

The service down and restored email templates have been updated to clearly display the associated project and service names, along with the specific health check URL when available. Each notification now includes a direct "View Service" button that links to the service's detail page, allowing users to quickly investigate the status without navigating manually.

_app/views/service\_health\mailer · high confidence

The sidebar layout has been refactored to support two distinct views controlled by the SCALE\_MODE environment variable. When SCALE\_MODE is enabled, the sidebar displays a 'favorites' view showing only favorited projects, clusters, and add-ons. In standard mode, it displays a 'full' view that lists both favorited items and all visible resources for the user. This change introduces new partials to handle these views and updates the project item rendering to optionally show a favorite icon.

app/views/layouts/sidebars · high confidence

Simplified auto-managed domain naming for single-service projects

The system now generates simpler domain names for projects containing only one public web service, using the format {project\_slug}.oncanine.run instead of {service\_name}-{project\_slug}.oncanine.run. This change is implemented via the new Domains::AttachAutoManagedDomain action, which checks the count of public web services in a project to determine the naming convention, and includes corresponding cleanup logic in Domains::Destroy to remove associated DNS records when auto-managed domains are deleted.

app/actions/domains · high confidence

Stack manager now verifies Portainer connectivity with RBAC-aware status feedback

The stack manager UI now actively validates Portainer instance connectivity when configuring stacks. A new badge controller automatically checks reachability on load, distinguishing between general URL reachability and authenticated access when RBAC is enabled, displaying specific success, error, or unauthorized states. Additionally, a new URL input controller allows users to manually verify their Portainer URL and access token, providing immediate feedback on whether the instance is reachable and if the provided credentials are valid, helping users troubleshoot connection issues before deploying stacks.

_app/javascript/controllers/stack\manager · high confidence

Fixes

Added development credential key

A new development key file (development.key) has been added to the config/credentials directory, containing a specific hexadecimal value for local environment authentication or configuration.

config/credentials · low confidence

Test coverage

Added RSpec test framework and Swagger schema validation; Added integration test schemas for API models; Added model specifications for core platform entities; Added request specs for Stripe webhook controller; Added request specs for development environment configuration and environment creation; Added request specs for inbound webhook signature verification; Added request specs for local onboarding redirect protection; Added request specs for shell sessions and two-factor authentication; Added request specs for the Stack Managers controller; Added system test for initial install page; Added system test support infrastructure; Added system tests for core application workflows; Added test coverage for Add-Ons view models; Added test coverage for Helm and legacy deployment services; Added test coverage for K8 stateless services; Added test coverage for MCP resource routing and data retrieval; Added test coverage for Portainer integration components; Added test coverage for SSO user and team synchronization actions; Added test coverage for add-on lifecycle and namespace management actions; Added test coverage for auto-managed domain attachment and destruction; Added test coverage for cluster management actions; Added test coverage for health check, PR cleanup, and metrics jobs; Added test coverage for project fork and development environment creation actions; Added test coverage for project lifecycle jobs; Added test coverage for provider creation and configuration; Added test coverage for scheduled background jobs; Added test coverage for service creation and update actions; Added test coverage for the Cloudflare DNS service client; Added test factories and specs for core domain models; Added test fixtures for canine configuration scenarios; Added test support contexts for buildpacks, MCP, and Portainer; Added tests for CanineConfig YAML parsing and project initialization; Added tests for DNS hostname inference logic; Added tests for FaviconService and InferJsonSchemaService; Added tests for GitLab client webhook and file operations; Added tests for Hash\#to\_yaml\_raw initializer; Added tests for Helm chart building and client command generation; Added tests for InboundWebhooks::GitlabJob; Added tests for K8 connection and kubeconfig utilities; Added tests for K8 metrics collection and parsing; Added tests for LDAP authentication service; Added tests for Portainer onboarding creation logic; Added tests for SAML authenticator; Added tests for buildpacks details and search actions; Added tests for cluster migration actions; Added tests for environment variable bulk update and text parsing; Added tests for favorites actions; Added tests for onboarding cluster creation logic; Added tests for resource constraint saving logic; Added tests for the Billable concern; Integration test coverage for API v1 endpoints; Removed template integration test.

Dependencies

Initial dependency configuration for Rails 7.2 and modern frontend tooling

The application establishes its foundational dependency stack by introducing a Gemfile and package.json. On the backend, it adopts Rails 7.2.2 alongside Puma, PostgreSQL, and Avo 3.25 for the admin interface, while integrating Good Job for background processing, Stripe for billing, and various authentication providers (Devise, OmniAuth, SAML, LDAP). On the frontend, it configures Tailwind CSS, esbuild, and a suite of JavaScript libraries including CodeMirror, ApexCharts, and Hotwire (Turbo/Stimulus) to support the user interface.

(dependencies) · high confidence

Housekeeping

Added placeholder files for standard directories

Placeholder \.keep\ files have been added to the \lib/assets\, \log\, \storage\, \tmp\, \tmp/pids\, and \tmp/storage\ directories. This ensures these directories are tracked by version control and exist in the repository structure, which is typically done to support local development environments or deployment processes that expect these paths to be present.

(repo-wide) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 41.

Lenses

  • Code Health 46
  • Architecture 83
  • Maturity 53
  • Readiness 34
  • Security 60
  • Domain Modelling 53
  • Accessibility 40

Changes since last survey

  • 300 commits — 207 feature/other, 93 fixes

By area

  • (repo) — 78 commits
  • app/views — 76 commits
  • app/actions — 31 commits
  • app/controllers — 19 commits
  • app/jobs — 15 commits
  • app/models — 14 commits
  • app/services — 13 commits
  • (root) — 10 commits
  • spec/requests — 7 commits
  • .github/workflows — 4 commits
  • config/initializers — 4 commits
  • app/javascript — 3 commits
  • spec/models — 3 commits
  • db/migrate — 2 commits
  • resources/k8 — 2 commits
  • spec/actions — 2 commits
  • spec/jobs — 2 commits
  • spec/services — 2 commits
  • app/avo — 1 commit
  • app/mailers — 1 commit

Notable commits

  • fix: Fix AddOns::Update call to use execute with context hash
  • fix: Fix Helm 4 empty values file parse error
  • fix: Fix InternalSso -> InternalSSO to match acronym inflection
  • fix: Fix MCP OAuth flow and support public clients
  • fix: Fix OAuth redirect URI and OIDC config improvements
  • fix: Fix SSO redirect_uri to always prepend https to APP_HOST
  • fix: Fix add-on uninstall hanging due to TypeError
  • fix: Fix oauth-authorization-server route being intercepted by Doorkeeper
  • fix: Fix predeploy command namespace mismatch and false statuses crash
  • fix: Fix rubocop array bracket spacing
  • fix: Fix rubocop lint offense
  • fix: Fix webhook signature verification and scope cluster access
  • fix: Force date-fns resolution to v3 to fix esbuild errors
  • fix: Merge pull request #658 from CanineHQ/fix/remove-extra-quotes-from-build-args
  • fix: Merge pull request #659 from CanineHQ/fix/ingress-discovery-across-namespaces
  • fix: Merge pull request #660 from CanineHQ/fix/domain-copy-and-external-link
  • fix: Merge pull request #661 from CanineHQ/fix/destroy-job-retry-uninstall
  • fix: Merge pull request #667 from CanineHQ/fix/container-registry-project-link
  • fix: Merge pull request #669 from CanineHQ/fix/health-check-fan-out
  • fix: Merge pull request #670 from CanineHQ/fix/fetch-metrics-fan-out
  • …and 280 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

CanineHQ/canine was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 19 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 04c85cdb3ea30d003cfd295ad147e699d8d1038f — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-13a154b7f5d1.