Skip to content
CAI
Software that uses CAICheck a score

carverauto/serviceradar

67.5

Adequate · 24 September 2026

1530.6k

lines of production code

Elixir

with Rust, Go

3

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

ServiceRadar is a comprehensive network observability and security platform that ingests telemetry from edge agents to provide real-time topology visualization, anomaly detection, and endpoint inventory. The system features a high-performance query engine (SRQL) and a React-based web interface for dashboarding, remote access, and network flow analysis. It supports extensibility through a native add-on framework for capabilities like BGP monitoring, vulnerability scanning, and RF surveying, all managed via a unified, multi-language configuration and secret management system.

Features

Add Azure Storage authentication support to reqsign

The \reqsign-azure-storage\ crate now provides comprehensive signing support for Azure Storage services (Blob, File, Queue, and Table). It introduces a \Credential\ enum supporting Shared Key, SAS Token, and Bearer Token authentication, along with a \DefaultCredentialProvider\ that automatically chains multiple sources: environment variables, Azure CLI, client certificates, client secrets, Azure Pipelines workload identity, standard workload identity, and Azure Instance Metadata Service (IMDS). Additionally, it includes an \AccountSharedAccessSignature\ implementation for generating account-level SAS tokens.

_third\_party/rust\_patches/reqsign-azure-storage-1.0.0, third\_party/rust\_patches/reqsign-google-1.0.0, third\_party/rust\patches/rperf-0.1.25 · high confidence

Add example on-premises environment configuration for ServiceRadar

An example on-premises environment configuration for the 'untd' instance has been added to the ServiceRadar configuration system. This includes a Bazel build file that exposes the configuration and a textproto file defining default connection settings for PostgreSQL, NATS, the core service, and Dgraph. This change allows the on-premises deployment path to be validated by the same build-time tests as CI and SaaS environments, ensuring configuration integrity without exposing real customer data or secrets.

config/environments/onprem · high confidence

Add vendored Boombox audio/video streaming library

The \third\_party/hex\_vendored/boombox\ directory now contains a vendored copy of the Boombox library, providing capabilities for audio and video streaming. This includes a main API (\Boombox.run\) for handling various input and output protocols such as RTMP, RTSP, HLS, WebRTC, and RTP, as well as file-based formats like MP4 and AAC. The implementation features Membrane-based bins for pipeline construction, internal handling of Elixir endpoints for raw data streaming, and specific modules for HLS, RTMP, and RTP protocols. Notably, the \:player\ output is explicitly unsupported in this vendored build to remove SDL and PortAudio dependencies, allowing headless environment builds.

(repo-wide) · high confidence

Added Bazel project view configuration

A new .bazelproject file has been added to the .bazelbsp directory to configure the Bazel plugin. This configuration enables automatic target derivation from directories and sets the current directory as the project root, allowing the IDE to better understand the Bazel workspace structure.

.bazelbsp · high confidence

Added Elixir and Rust bindings for the ServiceRadar configuration schema

This change introduces the generated Elixir and Rust bindings for the ServiceRadar configuration schema, enabling the application to parse and validate configuration data using the unified protocol buffer definitions. The Elixir bindings (config.pb.ex and rules.pb.ex) expose types for environment kinds (including DEMO), TLS modes, security modes, and a comprehensive rule set for configuration validation (e.g., RequiredIf, ForbiddenIf). The Rust bindings provide a cross-language contract for these types, ensuring consistency with Go, and include tests to verify that unset fields are correctly reported as absent rather than defaulted, and that enum zero values serve as unspecified sentinels.

_config/proto\bindings/elixir · high confidence

Added daisyUI vendor bundle for CSS theming

The web client now includes the daisyUI component library as a vendored JavaScript bundle (\daisyui.js\ and \daisyui-theme.js\). This adds support for applying pre-built UI themes (such as light, dark, cupcake, and synthwave) to the application's interface via CSS variables, enabling consistent styling across components without requiring external CDN dependencies at runtime.

elixir/web-ng/assets/vendor · high confidence

Added wrappers.proto and Bazel build rules for primitive type wrappers

The google/protobuf location now includes the wrappers.proto definition and its corresponding Bazel build configuration. This adds support for wrapper messages (DoubleValue, FloatValue, Int64Value, UInt64Value, Int32Value, UInt32Value, BoolValue, StringValue, and BytesValue) that allow primitive types to be distinguished from their default values, which is useful for embedding in google.protobuf.Any or when presence detection is required.

google · high confidence

Config validation engine added in Elixir and Go alongside existing Rust implementation

The config/manager\_validator area now includes Elixir and Go implementations of the configuration validation engine, in addition to the existing Rust implementation. These new implementations validate configuration instances against the committed rule set (defined in //config/rules) and are verified for correctness through shared conformance vectors and property-based tests. This ensures that all three language implementations produce identical validation results for the same inputs, preventing drift between the different service components that rely on this validation logic.

_config/manager\validator · high confidence

Consolidated packaging infrastructure and native add-on delivery model

The build system has been consolidated into a single \setup-package.sh\ script and a \components.json\ configuration, replacing the previous scattered shell scripts to build both Debian and RPM packages for all ServiceRadar components. This change introduces a new \os-package\ delivery model for native agent add-ons, allowing them to be packaged as dormant \.deb\/\.rpm\ files that are activated by the agent rather than the package manager. The agent package itself has been updated to support ARM64 Linux and includes a new \srctl\ CLI binary with RFC 8628 authentication, while the macOS installer now supports signed builds with improved error reporting for signing failures.

build/packaging · high confidence

Edge OTLP relay with durable spooling and ingestion token authentication

The OTel collector now supports an edge deployment shape where telemetry is durably spooled to disk and relayed through the local ServiceRadar agent instead of publishing directly to NATS JetStream, ensuring data survives process crashes and network interruptions. This new agent-forward backend includes configurable disk-space floors, age/size-based eviction, and crash-safe relay ID management. Additionally, the OTLP listeners now support optional token-based ingestion authentication (SigNoz-style), allowing operators to require an ingestion key for external producers to secure data entry.

rust/otel · high confidence

Edge anomaly detection add-on with persistent state and CUSUM drift detection

The \rust/anomaly-addon\ introduces a new edge-based anomaly detection add-on that runs per-series detectors directly on the agent. It consumes the local metric feed, normalizes cumulative counters (handling resets, gaps, and 32-bit wraps), and applies rolling z-score scoring with optional hour-of-week seasonal deseasonalization baselines delivered from the core. The add-on now includes a CUSUM drift detector to identify sustained level shifts, configurable checkpoint persistence to survive restarts without cold-starting false positives, and health telemetry to report scoring liveness and dropped telemetry.

rust/anomaly-addon · high confidence

Experimental RDP connector integration via ironrdp

The RDP adapter now includes an experimental connector implementation backed by the ironrdp library. This adds a new backend module that handles the full RDP connection lifecycle, including TCP dialing, TLS verification (supporting both system roots and custom CA bundles), CredSSP authentication, and Kerberos integration. The implementation exposes a probe-gated feature (serviceradar\_rdp\_connector\_link\_probe) that enables live connection handoffs, media frame pumping, and input event mapping, allowing the adapter to establish and maintain active RDP sessions for remote desktop streaming.

rust/rdp-adapter · high confidence

Go source tree restructured with Bazel build system and new agent updater

The Go source tree has been reorganized under the /go/ directory, with all builds and tests now managed by Bazel. A new agent-updater binary has been introduced to handle add-on lifecycle management, including systemd unit installation, capability application, and release activation. The agent binary now supports cross-compilation for Windows (amd64, arm64) and macOS (darwin\_arm64), with version metadata embedded via Bazel x\_defs. Configuration is centralized in config.json, and the build system enforces pure Go mode for static binaries while allowing cgo for specific targets like the macOS installer.

go · high confidence

Initial configuration for the Elixir ServiceRadar Core application

This change introduces the foundational configuration files for the new \serviceradar\_core\_elx\ Elixir application. It defines the static configuration (\config.exs\) including Ash domain registrations (such as Camera, CompositeChecks, Identity, and Notifications), Spark formatter settings, and metrics endpoints. Environment-specific overrides are provided: \dev.exs\ enables debug logging, \prod.exs\ sets the default log level to info and configures the Swoosh email client to use the \Req\ library to avoid HTTP/2 conflicts, and \test.exs\ disables background jobs and the database for testing. The \runtime.exs\ file handles dynamic runtime configuration, including OpenTelemetry exporter setup with root sampling to prevent self-telemetry loops, log level tuning via environment variables, and automation callback deployment settings.

_elixir/serviceradar\_core\elx/config · high confidence

Initial database schema and observability infrastructure for ServiceRadar

This change introduces the foundational database schema for ServiceRadar, establishing the \platform\ schema and bootstroring essential PostgreSQL extensions (pgcrypto, pg\_trgm, citext, timescaledb, and AGE). It creates the core tables for network discovery and topology, including \mapper\_jobs\, \mapper\_topology\_links\, and \sweep\_host\_results\, while also setting up the initial AGE graph \serviceradar\ for graph-based topology queries. Additionally, it provisions the time-series infrastructure for observability by creating hypertables and tables for events, logs, traces, and metrics, and defines configuration profiles for system monitoring (sysmon) and Dusk blockchain node discovery.

_elixir/serviceradar\core/priv/repo/migrations · high confidence

Initial release configuration for ServiceRadar Agent Gateway

This change introduces the initial release environment files for the ServiceRadar Agent Gateway, including systemd service definitions, Erlang VM arguments, and shell environment scripts. The configuration enables mTLS for distributed Erlang node communication, applies specific BEAM performance tuning (such as scheduler capping and busy-wait prevention), and sets up security hardening and resource limits for the gateway service.

_elixir/serviceradar\_agent\gateway/rel · high confidence

Initialize ServiceRadar Agent Gateway configuration

The ServiceRadar Agent Gateway now includes a complete configuration structure (config.exs, dev.exs, prod.exs, runtime.exs, test.exs) to support its operation as a standalone component. This setup enables metrics publishing for various protocols (ICMP, MTR, SNMP, Sysmon, etc.) via NATS, configures OpenTelemetry export endpoints for traces and logs, and manages ERTS clustering for distributed process management. It also registers a comprehensive list of Ash domains for the core service and handles runtime secrets for edge crypto and plugin storage, while ensuring test environments run without database or clustering dependencies.

_elixir/serviceradar\_agent\gateway/config · high confidence

Initialize ServiceRadar release configuration with TLS and scheduler tuning

This change introduces the initial release environment files for ServiceRadar, enabling secure distributed node communication and optimized VM performance. It adds an environment script (env.sh.eex) that configures the release node name and enables mutual TLS for inter-node distribution when a cluster TLS configuration is present, alongside an example SSL configuration file (ssl\_dist.conf.example) detailing certificate requirements and generation steps. Additionally, it provides VM arguments (vm.args.eex) that cap Erlang schedulers to a 2-core cgroup quota to prevent busy-wait spinning and migration stalls, while increasing process, port, and atom limits to support large clusters.

elixir/web-ng/rel · high confidence

Introduce ARC custom GitHub Actions runner and Harden Demo GitOps Deployments

This change introduces a custom GitHub Actions Runner Controller (ARC) setup in the \k8s/arc\ directory, providing a dedicated \arc-systems\ namespace and Helm values for a custom runner image (\ghcr.io/carverauto/arc-runner\) that includes essential build tools (cmake, protoc, etc.) missing from the stock GitHub runner. Additionally, it establishes ArgoCD Application manifests for the demo environment: \demo-prod.yaml\ is configured to deploy from the immutable \demo/prod-release\ branch with auto-sync enabled but pruning and self-healing disabled to prevent accidental drift, while \demo-staging.yaml\ is switched to use a pinned Helm chart version (\1.2.11\) from the Harbor registry instead of a moving branch, ensuring reproducible staging deployments.

k8s · high confidence

Introduce Bazel build system for WASM plugins

The build system for WASM plugins has been migrated to Bazel, introducing a new \build/wasm\_plugins\ directory that manages the entire lifecycle of plugin artifacts. This change adds a declarative inventory of plugins (including AWX, Proxmox, NetBox, and OTX) and defines build targets that compile Go and TinyGo sources into WASM binaries. It also introduces a Python-based bundle assembler that packages plugins into signed ZIP archives with metadata, and a publishing script that pushes these bundles to OCI registries using \oras\. The build infrastructure includes platform-specific TinyGo toolchain selection (supporting macOS and Linux on amd64/arm64) and comprehensive test coverage for the bundle assembly, publishing logic, and AWX runtime behavior.

_build/wasm\plugins · high confidence

Introduce Bumblebee Exposure Scanner add-on

Adds the Bumblebee native add-on, which deploys a root-owned local exposure scanner for developer and package-manager artifacts. The add-on installs a systemd timer that runs the scanner periodically, writing sanitized findings to a spool directory for ingestion by the non-root agent. Configuration is managed via a JSON schema and runtime profile, with the service hardened using strict systemd protections and SELinux relabeling to ensure execution under strict security policies.

addons/bumblebee-scan · high confidence

Introduce Dgraph topology persistence and migration tooling

The rust/dgraph-topology crate now provides the schema, typed mutations, and a one-shot migrator for persisting network topology in Dgraph. A new \dgraph-migrate\ binary applies the namespaced schema (covering devices, interfaces, hops, prefixes, and reified topology edges) and supports MIGRATE, STATUS, and DEPROVISION modes via environment variables. The \TopologyClient\ exposes typed upserts for devices, interfaces, prefixes, and canonical/MTR edges, while \downstream.rs\ adds a BFS utility to determine if one set of nodes is reachable downstream of another on the canonical topology. Integration tests in \cutover\_tests.rs\ verify idempotent rebuilds and stale-path pruning against a Dgraph fixture.

rust/dgraph-topology · high confidence

Introduce Elixir datasvc client for NATS JetStream KV operations

The datasvc location now provides an Elixir library that acts as a gRPC client for the ServiceRadar datasvc service, enabling access to a NATS JetStream key-value store. Consumers can use the new Datasvc module to establish connections (with optional mTLS) and perform KV operations such as listing keys, retrieving values, and fetching store metadata via the Datasvc.KV module. The change also includes the necessary protobuf definitions for the KV service and configures the Bazel build to compile the app as a production release while excluding dev-only tooling from the final artifact.

elixir/datasvc · high confidence

Introduce FieldSurvey iOS app for RF and spatial mapping

The FieldSurvey iOS application is introduced, enabling users to conduct Wi-Fi and Bluetooth RF surveys alongside 3D spatial mapping. The app leverages LiDAR and the RoomPlan framework to capture room meshes and floorplans, while simultaneously collecting Wi-Fi signal strength and access point location data. It supports backend integration for uploading survey artifacts, including USDZ meshes, point clouds, and GeoJSON floorplans, and provides a live heatmap visualization of signal coverage.

swift · high confidence

Introduce OTLP Collector Add-on with Agent-Forward Spooling

Added the \serviceradar-otel-addon\, a new native agent add-on that packages the ServiceRadar OTLP collector. This add-on enforces an agent-forward output backend by default, using a durable spool to buffer telemetry frames before relaying them to the agent via the \otlp-relay:v1\ capability. It includes a spool monitor that tracks utilization and emits OCSF usage events (native-telemetry:v1) when thresholds are crossed, and reports degraded health if the spool exceeds 90% capacity or if listeners fail to start.

rust/otel-addon · high confidence

Introduce Palisade: shared SSRF defense primitives for Elixir

The \elixir/palisade\ library has been extracted as the canonical home for shared trust-boundary primitives previously duplicated across ServiceRadar and CRM codebases. It provides \Palisade.NetworkAddressPolicy\ to reject loopback, link-local, and private CIDR addresses (including DNS rebinding protection), \Palisade.OutboundURLPolicy\ to enforce HTTPS-only, public-host URL validation with configurable port allowlists, and \Palisade.OutboundFetch\ to execute HTTP requests bound to pre-validated IPs while preserving TLS hostname verification. The library is published to hex.pm and includes comprehensive test coverage for these security policies.

elixir/palisade · high confidence

Introduce PowerDNS native telemetry addon

A new PowerDNS addon has been added to the ServiceRadar platform, enabling native telemetry ingestion for DNS activity. This component listens for PowerDNS events, processes them into structured telemetry batches, and exposes health and configuration endpoints via the addon SDK, allowing users to monitor PowerDNS infrastructure directly within the platform.

rust/powerdns · high confidence

Introduce Rust SecretManager with strict declaration enforcement and redaction

The Rust configuration library now includes a SecretManager that resolves secrets via a provider selected by the SERVICAR\_ENV environment variable (EnvProvider for non-local environments, FileProvider for localhost). Secrets are wrapped in a Secret type that redacts values in Debug/Display output and requires explicit exposure. A Manifest enforces least-privilege by refusing any secret name not explicitly declared, returning clear errors for undeclared, unresolvable, or provider-failure cases. An in-memory MapProvider is available for testing.

_config/manager\secret/rust · high confidence

Introduce SRQL shared library with Rust NIF bindings

Added the \serviceradar\_srql\ Elixir application, which exposes Rust-based Native Implemented Functions (NIFs) for parsing SRQL (ServiceRadar Query Language) queries into abstract syntax trees, translating them to SQL, and encoding/decoding data in Arrow IPC and Cap'n Proto formats. This library serves as a shared component for both the backend (\serviceradar\_core\) and the web layer (\web-ng\), enabling consistent query parsing and data handling across the system.

_elixir/serviceradar\srql · high confidence

Introduce ScaLibr Endpoint Software Inventory scanner addon

Adds the ScaLibr Endpoint Software Inventory addon, which deploys an OSV ScaLibr-backed scanner to generate endpoint software SBOMs and inventory metadata. The addon installs a systemd timer that triggers the scanner hourly, writing results to a shared spool directory for ingestion by the base agent. Configuration allows operators to define scan roots, specific package plugins (dpkg, rpm, apk), and directories to skip, with sensible defaults for security and performance.

addons/scalibr-endpoint-inventory · high confidence

Introduce ServiceRadar BMP collector for BGP monitoring

Adds a new BMP (BGP Monitoring Protocol) collector service that listens for incoming BMP frames, parses them using the arancini-lib library, and publishes structured routing updates to a NATS JetStream stream. The collector normalizes IPv4-mapped IPv6 addresses to standard IPv4 format in its JSON output and supports configurable NATS TLS, credentials, and stream settings.

rust/bmp-collector · high confidence

Introduce ServiceRadar Core configuration and test database safeguards

This change establishes the default configuration for the ServiceRadar Core library, defining baseline settings for Ash, Oban job queues (including cron schedules for maintenance, anomaly, and retention workers), rate-limiting buckets, and observability components like NetFlow and GeoIP. It also introduces a strict test database guard that enforces secure, isolated connections for database-backed tests by validating TLS requirements, restricting allowed database names, and preventing unsafe URL overrides.

_elixir/serviceradar\core/config · high confidence

Introduce ServiceRadar Core-ELX as a dedicated Elixir runtime boundary

A new Elixir application, serviceradar\_core\_elx, has been added to serve as the primary coordination node for the ServiceRadar cluster. This component acts as a thin wrapper that enables cluster mode and AshOban schedulers for the core library, while introducing new ERTS-native ingress boundaries for camera relay sessions and remote desktop media. It also manages the lifecycle of external analysis workers and provides a hermetic Bazel build path for the Elixir release, replacing the previous non-hermetic mix\_release approach.

_elixir/serviceradar\_core\elx · high confidence

Introduce ServiceRadar React component library with dashboard and remote access UIs

This change introduces a new \serviceradar-react-components\ library (located in \elixir/web-ng/assets/component\) that bundles a set of React components for the ServiceRadar product. The library pins React to version 19.2.8 and includes a \bun.lock\ dependency manifest. It exports several new UI components: a \JdmEditor\ for visual decision model editing, a \DashboardBuilderCanvas\ for grid-based dashboard authoring, and \DashboardPanelChart\ for rendering charts using Recharts. Additionally, it provides a suite of remote access components, including \RemoteAccessSSHConsole\, \RemoteAccessApplication\, \RemoteAccessDesktopSession\, \RemoteAccessTCPText\, and \RemoteAccessTerminal\, enabling SSH, RDP, and TCP-based remote sessions directly in the browser.

elixir/web-ng/assets/component · high confidence

Introduce ServiceRadar backend components and native libraries

This change initializes the ServiceRadar feature by adding the core backend infrastructure for the web-ng application. It includes a Rust-based NIF (srql\_nif) that allows Elixir to parse SRQL queries and translate them into database requests, as well as a WebAssembly module (god\_view\_exec) providing native functions for memory management, state masking, graph traversal, and coordinate interpolation. Additionally, it adds database seeding scripts to create a default admin user and establishes the initial gettext localization files for error messages.

(repo-wide) · high confidence

Introduce ServiceRadar developer CLI with dashboard, plugin, and auth capabilities

This change introduces the \@carverauto/serviceradar-cli\ package, providing a unified command-line interface for ServiceRadar development. The CLI enables developers to authenticate via OAuth 2.0 Device Authorization (with manual token fallback), author and publish dashboard packages (including manifest validation, Vite-based builds, and HMR dev servers), and publish Wasm check plugins. It also includes a \doctor\ command for environment diagnostics, a Python utility for ensuring Kubernetes node alert routes, and a browser-side harness for testing dashboard renderers locally. The CLI is structured with TypeScript source, JSON Schema validation for dashboard configs, and Bazel build support.

js · high confidence

Introduce ServiceRadar flow collector with multi-protocol support and host-slice attribution

The flow-collector component has been rewritten to support NetFlow (v5, v9, IPFIX) and sFlow ingestion, enabling per-listener bounded channels to isolate noisy protocols and prevent starvation. It now supports host-slice flow attribution, allowing flows to be routed to specific agent subjects based on IP matching and an allowlist. A shared NATS KV template store is available for multi-pod template sharing, and sampling rates are persisted with configurable defaults and per-exporter overrides.

rust/flow-collector · high confidence

Introduce ServiceRadar rperf gRPC checker for network performance testing

The rperf-client component is introduced as a new gRPC service that orchestrates network performance tests against configured targets. It supports mTLS and SPIFFE-based security modes, allowing users to define test targets with specific protocols (TCP/UDP), bandwidth, and duration parameters. The service runs scheduled tests via a poller, parses rperf output to report metrics like throughput and packet loss, and exposes these results through a gRPC interface for integration with the ServiceRadar monitoring system.

rust/rperf-client · high confidence

Introduce ServiceRadar secret management library for Elixir

Added a new Elixir library (ServiceradarSecret) that manages component secrets through a provider-based system. The library enforces least-privilege access by requiring components to declare their required secrets in a manifest before resolution; any attempt to access an undeclared secret is refused immediately to prevent information leakage. It supports two provider backends: EnvProvider, which reads secrets from environment variables (the primary method for Kubernetes and CI environments), and FileProvider, which reads from mounted files (used for local development). The library includes utilities for defining secret names, resolving values securely using closures to prevent accidental logging, and handling errors with clear, specific messages.

_config/manager\secret/elixir · high confidence

Introduce ServiceRadar trapd with configurable security and NATS integration

The trapd component is introduced as a new SNMP trap receiver that parses incoming traps and publishes them to a NATS JetStream stream. It supports configurable security modes (mTLS, SPIFFE, or none) for both its NATS connection and an optional gRPC management interface, including validation of required certificates and trust domains. The service initializes the \ring\ TLS provider by default and handles NATS stream creation with wildcard-aware subject logic to prevent overlap errors.

rust/trapd · high confidence

Introduce adaptive RF scanning and secure API for FieldSurvey Sidekick

The FieldSurvey Sidekick service now supports adaptive channel hopping, which dynamically prioritizes frequencies based on real-time spectrum and RF observations to improve scan efficiency. This capability is exposed via a new REST API (powered by axum) that includes endpoints for observation and spectrum streaming, configuration management, and device pairing. Access to these endpoints is secured using bearer tokens, supporting both a static setup token and dynamically generated pairing tokens for paired devices.

rust/fieldsurvey-sidekick · high confidence

Introduce correlation-engine as the new deterministic dependency and expert-reasoning service

A new \correlation-engine\ crate has been added to replace the legacy \causal-engine\ (renamed via \refactor(de-causal)\). This service implements a deterministic expert system (rules C1–C13) that reasons over topology and state to identify root causes and affected services. It hydrates a shared \Context\ from CNPG via \EmbeddedSrql\ and live NATS \signals.state\ deltas, evaluates structural graph algorithms (centrality, reachability, articulation points) and rule-based logic, and emits verdicts to \signals.analytics.predictions\. The engine supports both AGE and Dgraph for topology reads, persists context snapshots for fast restarts, and publishes OCSF-compatible prediction envelopes.

rust/correlation-engine · high confidence

Introduce immutable schema template manifest generation

Added a new Bazel build target that generates a deterministic manifest of schema inputs (migrations, baseline SQL, helpers, and construction dependencies) using cryptographic hashes. This ensures that schema template generations are reproducible and immutable, with identity changes triggered by any modification to the declared inputs, and includes a policy configuration for controlling generation constraints.

_build/schema\template · high confidence

Introduce in-kernel network flow attribution and L2 device census via eBPF

The netprobe now performs network flow attribution and Layer 2 device discovery directly in the kernel using eBPF programs. This change adds support for tracking TCP, UDP, and ICMP/ICMPv6 flows, including passive L2 device census via ARP and NDP (Neighbor Discovery Protocol). It also introduces p0f signature detection for TCP SYN packets and captures mDNS announcements at the kernel level, reducing reliance on userspace tools like avahi. These in-kernel observations are attributed to local processes and sent to userspace via ring buffers for correlation and reporting.

rust/netprobe/ebpf · high confidence

Introduce native Workload Identity add-on for node-local container metadata enrichment

A new standalone Rust-based add-on has been introduced to collect and enrich node-local workload identity metadata. This component replaces the previous integration within the netprobe, providing a dedicated binary that discovers container runtimes (including Docker, containerd, and CRI-O) via Unix sockets and periodically collects identity snapshots (pod name, namespace, labels, etc.) into a spool directory. A separate validation utility is also included to verify CRI connectivity and identity resolution on the node.

rust/workload-identity · high confidence

Introduce native add-on framework for agent extensibility

The system now supports a native add-on framework that allows agents to load and manage external plugins (such as netprobe and Bumblebee) as first-class components. This change introduces a manifest-driven schema for add-on definitions, a build-hygiene gate to validate add-on artifacts, and a lifecycle manager that handles add-on installation, configuration, and status reporting. Users can now extend agent capabilities through signed, versioned add-on packages that are managed via the agent's capability status and configuration dispatch, replacing previous ad-hoc plugin delivery mechanisms.

openspec · high confidence

Introduce new timeseries dashboard plugin components

The timeseries dashboard plugin has been refactored into a modular structure, introducing dedicated modules for chart rendering (ChartCard, CombinedChartCard), data processing (Metrics, SeriesData, Points, Paths), and specification parsing (Spec). This change adds support for series encodings (shapes like circles, squares, triangles), annotation markers, chart overlays (anomaly windows, capacity confidence bands), and reference lines. It also implements counter rate calculations, unit formatting, and optimized path generation for timeseries visualization.

_elixir/web-ng/lib/serviceradar\_web\_ng\web/dashboard/plugins/timeseries · high confidence

Introduce shared AF\_PACKET capture crate

The \rust/afpacket\ crate provides a unified, Linux-only \AF\_PACKET\ capture engine using \PACKET\_MMAP\ (TPACKET\_V3) rings, replacing the separate ring walkers previously maintained by \serviceradar-netprobe\ and \serviceradar-fieldsurvey-sidekick\. It enforces a strict setup sequence to prevent silent failures—such as building a V1 ring or capturing traffic from unauthorized interfaces—and ensures accurate, monotonic drop statistics by accumulating kernel counters. On non-Linux platforms, the crate fails loudly at runtime rather than returning empty successes, ensuring that capture paths are never indistinguishable from idle interfaces.

rust/afpacket · high confidence

Introduce standalone Elixir agent gateway with mTLS authentication and media relay support

The ServiceRadar Agent Gateway is now a standalone Elixir release that receives status pushes and camera media streams from Go agents via gRPC over mTLS. It enforces strict payload size limits, maintains an in-memory certificate revocation denylist, and tracks camera relay sessions with automatic expiration and capacity enforcement. The gateway forwards monitoring data and media to the core cluster while ensuring agents only connect outbound, requiring no inbound firewall rules in customer networks.

_elixir/serviceradar\_agent\gateway · high confidence

Introduce standalone Workload Identity add-on for node-local container metadata collection

A new native add-on has been added to collect and enrich Kubernetes pod, namespace, container, image, and runtime identity data directly on the node. This standalone Rust service runs as root to access CRI/Docker sockets, writes bounded identity snapshots to a local spool directory for the agent to ingest, and includes a systemd unit with strict security hardening (ProtectSystem=strict, SELinux chcon support, no CAP\_DAC\_OVERRIDE). Configuration allows enabling/disabling the collector, specifying CRI or Docker endpoints, setting context/cluster labels, and tuning refresh intervals and snapshot sizes.

addons/workload-identity · high confidence

Introduce unified configuration schema and validation rules for ServiceRadar

ServiceRadar now uses a centralized, language-agnostic configuration system. A new protobuf-based schema (config.proto) defines environment kinds (including a new DEMO mode) and typed TLS settings for PostgreSQL and Dgraph, replacing ambiguous string-based configurations. A corresponding rule set (ruleset.textproto) enforces validation constraints—such as required fields, value ranges, and TLS posture—across Go and Rust implementations, ensuring consistent behavior and preventing silent defaulting errors.

_config/proto\bindings, config/rules · high confidence

Introduce web-ng Elixir application configuration

The web-ng application now includes its own dedicated Elixir configuration files (config.exs, dev.exs, prod.exs, runtime.exs, test.exs). This establishes the web-ng app as a distinct OTP application with its own Phoenix endpoint, Ash domain registrations, and Oban job processing settings. The configuration enforces that web-ng joins the ERTS cluster for distributed reads but explicitly disables hosting distributed processes and joining the Horde CRDT mesh to prevent state bloat during frequent rollouts. It also configures the React build tooling (esbuild), Guardian JWT token lifetimes, and runtime environment variable loading for database connections, OpenTelemetry, and automation callbacks.

elixir/web-ng/config · high confidence

Introduce zero-touch SPIRE deployment for Docker Compose

The \docker/compose/spire\ directory now provides a complete, self-managed SPIRE runtime for local development and testing. Running \docker compose up\ automatically launches a dedicated SPIRE server (backed by SQLite) and a shared SPIRE agent, which exposes the Workload API via a Unix socket. A new bootstrap script (\bootstrap-compose-spire.sh\) handles idempotent registration of all ServiceRadar workload identities (core, datasvc, agent, log-collector, etc.) and manages join tokens. The setup intentionally requires vetted SPIRE binaries to be present on the host, refusing to download or execute them from the network without explicit integrity verification, thereby ensuring a secure, zero-touch identity bootstrap for all containers in the stack.

docker/compose/spire · high confidence

Introduces AF\_XDP-based packet capture and DPI classification pipeline

netprobe now supports high-performance packet capture and Deep Packet Inspection (DPI) using the AF\_XDP kernel interface. This change adds the core runtime plumbing for AF\_XDP, including consumer threads, ring buffer management, and socket registration with eBPF maps. It introduces a new classifier that processes packets from the AF\_XDP stream, performing DPI analysis and updating the eBPF flow table for attribution. This replaces or supplements the previous libpcap-based capture path, enabling lower-latency, high-throughput network visibility for supported Linux kernels.

rust/netprobe · high confidence

Introduces God View renderer and camera relay player with packet flow visualization

The application now includes a new God View renderer that manages layout, rendering, and lifecycle for the topology visualization, along with a camera relay player supporting WebRTC, WebCodecs, and MSE playback transports. Additionally, a PacketFlowLayer has been added to visualize bidirectional packet flows on the topology map using deck.gl.

elixir/web-ng/assets/js · high confidence

Introduces Rust config-bootstrap library for unified configuration loading

The new \rust/config-bootstrap\ crate provides a configuration loading mechanism for ServiceRadar Rust services, mirroring the functionality of the Go \pkg/config/bootstrap\ module. It enables services to load configuration files in JSON or TOML format from disk and apply an optional 'pinned' overlay configuration (specified via the \PINNED\_CONFIG\_PATH\ environment variable) to ensure sensitive values take precedence. This change establishes a unified config loading experience across the Rust component of the ServiceRadar platform.

rust/config-bootstrap · high confidence

Introduces Rust native add-on SDK and reference implementation

Adds a Rust SDK (\addon-sdk\) that allows native agent add-ons to be launched and supervised by the ServiceRadar agent's existing HashiCorp go-plugin client, implementing the plugin server half of the go-plugin wire protocol (stdout handshake, AutoMTLS certificate exchange, and gRPC \AddonService\ over a Unix-domain socket). This enables add-ons to be written in Rust while being treated identically to Go add-ons by the agent. The change includes the SDK library, a reference sample add-on binary, and the underlying protocol definitions (\addon.proto\, \discovery.proto\).

rust · high confidence

Introduces ServiceRadar configuration validation logic

The \ServiceradarConfig.Validator\ module has been added to evaluate committed rule sets against environment instances at load time. This implementation enforces the semantics defined in \config/SEMANTICS.md\, utilizing Elixir's \Regex\ (PCRE) for pattern matching instead of RE2, with conformance vectors ensuring outcome parity. The validator supports a range of predicates including \required\, \non\_empty\, \int\_range\, \one\_of\, \matches\, \required\_if\, \forbidden\_value\, and \forbidden\_if\, and treats rules referencing non-existent fields as hard errors to prevent silent failures.

_config/manager\validator/elixir · high confidence

Migrate Docker image builds to Bazel with hermetic, multi-arch OCI support

The \docker/images\ directory now uses Bazel to define and build all container images, replacing previous ad-hoc methods. This change introduces hermetic build rules for the \web-ng\, \core-elx\, and \CNPG\ images, ensuring deterministic, byte-identical layers across rebuilds by normalizing timestamps and file ordering. It adds multi-architecture (amd64/arm64) support for key services, including the \web-ng\ and \core-elx\ images, and introduces a new \cnpg-analytics\ image for cold-tier analytics. The build system now includes strict ABI checks for PostgreSQL extensions (TimescaleDB, AGE) to prevent runtime failures caused by glibc version mismatches between the build executor and the runtime base. Additionally, a new \workflow-runner\ image is provided for BuildBuddy, optimized for size and containing only the necessary utilities for CI workflows.

docker/images · high confidence

Native Rust NIF for God View topology, causality, and telemetry

The God View visualization backend now offloads heavy graph processing to a new Rust Native Implemented Function (NIF). This change introduces high-performance serialization of topology snapshots into Apache Arrow IPC streams, enabling the frontend to receive thousands of nodes and edges without Erlang term limits. It also adds native causal inference to identify root-cause devices in cascading failures using betweenness centrality, implements layered graph layout algorithms for optimal 2D spatial arrangement, and enriches topology edges with real-time interface telemetry (PPS/BPS) to display accurate link performance metrics.

_elixir/web-ng/native/god\_view\nif · high confidence

Native Rust add-on SDK with go-plugin interop

ServiceRadar now supports native Rust add-ons via a new SDK that implements the HashiCorp go-plugin wire protocol. This allows Rust binaries to be launched and supervised by the existing Go agent without host-side changes, using a Unix-domain socket and gRPC. The SDK includes a reference sample add-on, structured health reporting, and support for AutoMTLS (including ECDSA P-521 verification) to ensure secure, byte-for-byte compatibility with the Go plugin client.

rust/addon-sdk · high confidence

Native add-on build, signing, and release gate infrastructure

This change introduces the build and release guardrails for native agent add-ons. It adds a Bazel package that defines the inventory of first-party add-ons (netprobe, PowerDNS, workload identity, Bumblebee, Scalibr, RDP adapter, anomaly, and others) and assembles per-architecture bundles (zip + sha256 + metadata.json) with deterministic, reproducible outputs. A new Go tool signs and verifies these pushed-artifacts using the ServiceRadar agent release ed25519 key, matching the agent's verification contract. The build enforces binary portability by compiling Rust add-ons against musl and validating ELF headers, checks binary sizes against a baseline, ensures dependency isolation so the base agent does not depend on add-on implementations, and validates add-on manifests. These gates run as CI/build checks to prevent invalid or oversized bundles from being published.

_build/native\addons · high confidence

Netprobe delivered as a standalone systemd-supervised add-on

The netprobe host-network-visibility component is now packaged as a native add-on (version 0.2.63) rather than being baked into the base agent. It is installed as a signed pushed-artifact bundle containing a systemd service unit, a JSON configuration schema, and the compiled binary. The service runs as the 'serviceradar' user, requires specific Linux capabilities (CAP\_NET\_RAW, CAP\_NET\_ADMIN, CAP\_BPF, CAP\_PERFMON), and communicates with the agent via a local IPC socket. This change decouples the netprobe lifecycle from the base agent, allowing it to be managed and updated independently.

addons/netprobe · high confidence

New AGE-to-Dgraph topology migrator tool

Introduces the \age-to-dgraph\ Rust binary and library, enabling operators to rebuild or verify the Dgraph topology graph from the AGE (PostgreSQL) source of truth. The tool supports three modes: \rebuild\ (default) to upsert canonical edges and devices into Dgraph from AGE or mapper evidence, \checksum\ to compare node/edge counts and content hashes between AGE and Dgraph (failing the job on divergence), and \dump-load\ for lab-only synthetic data bootstrapping. It handles TLS connections to CNPG (supporting PKCS\#1, PKCS\#8, and SEC1 client keys), deduplicates edges by link key to ensure consistent checksums, and enforces strict environment variable controls to prevent live data dumps from entering the repository.

rust/age-to-dgraph · high confidence

New BGP, NetFlow, and Flow visualization chart components

This update introduces a suite of new JavaScript hooks for the charts directory, adding dedicated visualizations for BGP time-series data (BGPTimeSeriesChart), NetFlow grid layouts (NetflowGridChart), and general flow rates (FlowRateChart, FlowSparkline, FlowDonut). These components provide users with interactive time-series plots, grid-based multi-panel views, and summary donut/sparkline charts. The implementation includes robust handling of time zones (displaying localized labels while preserving canonical UTC data), gap handling for null data points, and accessible status updates for range selections.

elixir/web-ng/assets/js/hooks/charts · high confidence

New Bazel build infrastructure for benchmarks, integration test topology, and Elixir release assembly

This change introduces a new set of Bazel build rules and scripts in the \build/\ directory to improve build reliability and test coverage. It adds a benchmark runner (\benchmark\_runner.py\ and \benchmarks.bzl\) that executes Go and Rust benchmarks to ensure they actually run, preventing silent failures where benchmarks compile but measure nothing. It also introduces a comprehensive integration test topology (\integration\_shards.bzl\) that manages database connection pools and shards for Elixir integration tests, along with an equivalence test (\integration\_selection\_equivalence\_test.exs\) to verify that test selection matches the disposition inventory. Additionally, it provides new Elixir release rules (\elixir\_release.bzl\) to correctly handle ERTS shipping for multi-architecture builds (specifically arm64) and a configuration loader (\elixir\_test\_config\_loader.exs\) to ensure test environments are properly initialized in Bazel.

build · high confidence

New Bazel build rules and tests for agent release packaging

The \build/release\ directory now contains the Bazel build definitions and Go source code for the \publish\_packages\ release tool. This includes new rules to build the publishing binary and its tests, along with specific test suites that validate the structure and metadata of Linux agent packages (both amd64 and arm64 deb and rpm formats) and verify the integrity of the managed runtime archives. The implementation also introduces logic to handle macOS and Windows installer provenance, ensuring that release artifacts are correctly prepared and validated before upload.

build/release · high confidence

New Docker Compose infrastructure and service definitions

This change introduces the foundational Docker Compose environment for ServiceRadar, adding build definitions (Dockerfiles) for all core services including the Go-based agent, Elixir core and web interfaces, data services, log collector, and debugging tools. It includes a Caddy reverse-proxy configuration for the web interface, Bazel build rules to expose compose assets, and shell scripts for bootstrapping admin credentials, database users, and CNPG (CloudNativePG) initialization. The entry also adds comprehensive configuration files (JSON) for agent, gateway, and collector services, along with environment examples for the optional cold-tier analytics profile.

docker/compose · high confidence

New Docker build infrastructure and Harbor registry integration

This change introduces a new Remote Build Execution (RBE) executor image (Dockerfile.rbe) based on Ubuntu 24.04, optimized for hermetic builds with specific tooling like Docker CE, PostgreSQL 18 libraries, and SBOM/signing tools (Syft, Cosign). It also adds documentation (LOCAL\_BUILD.md, README.md) and configuration for building and pushing ServiceRadar images to the new Harbor registry (registry.carverauto.dev), replacing previous build and hosting assumptions.

docker · high confidence

New Dockerfiles for building RPM packages for ServiceRadar components

Added a suite of Dockerfiles in the docker/rpm directory to build RPM packages for various ServiceRadar components, including NATS, rperf, BMP collector, profiler, trapd, and generic Go-based components. These files define multi-stage builds using Rocky Linux 9, handling Rust compilation (with specific toolchains like nightly for eBPF or stable for others), Go compilation, and dependency installation (such as protobuf, clang/llvm for eBPF, and capnproto). The builds produce RPMs for components like serviceradar-nats, serviceradar-rperf, serviceradar-bmp-collector, serviceradar-profiler, and serviceradar-trapd, ensuring consistent packaging across different language stacks and component types.

docker/rpm · high confidence

New FieldSurvey local development skill for web-ng

Added a new agent skill that provides scripts and documentation to run the web-ng application locally against the Kubernetes demo namespace's FieldSurvey data. This includes automated setup for CNPG NodePort database access, NATS Object Store port-forwarding, and Playwright-based smoke tests to verify the dashboard, settings preview, and FieldSurvey review page.

.agents/skills/fieldsurvey-local-web-ng · high confidence

New KV utility library for key-value operations and secure client connections

Added a new \kvutil\ Rust crate that provides a \KvClient\ for interacting with a key-value service. The client supports standard get, put, and put-if-absent operations, as well as a watch-apply mechanism for real-time key updates. It handles connection configuration via environment variables, supporting three security modes: no TLS, mutual TLS (mTLS) with explicit certificate files, and SPIFFE-based TLS using a workload socket for identity management.

rust/kvutil · high confidence

New RDP connector probe for validating security boundaries and TLS configuration

The \rust/rdp-connector-probe\ module has been introduced to provide a dedicated testing and validation layer for the RDP connection flow. It parses the \ServiceRadarOpenRequest\ payload and uses the \ironrdp\ library to simulate the RDP handshake, allowing operators to verify that the connector correctly negotiates security protocols (such as CredSSP and NLA) and enforces TLS policies. The probe includes strict validation for CA bundles, ensuring that only PEM-encoded certificates are accepted and raw DER data is rejected with structured errors, and it verifies that credentials are not exposed in cleartext during the initial connection PDU. This tool enables automated checks of the RDP adapter's security posture, including TLS downgrade protection and credential handling, before a live session is established.

rust/rdp-connector-probe · high confidence

New React dashboard templates for blank, map, and table views

Added three new CLI templates (react-blank, react-map, react-table) that scaffold React-based dashboard components using the @carverauto/serviceradar-dashboard-sdk. The blank template provides a minimal view displaying primary frame results, the map template renders an interactive site map with region filtering and popups, and the table template offers a paginated, searchable device list with status filtering.

js/cli/templates/react-blank, js/cli/templates/react-map, js/cli/templates/react-table · high confidence

New Rust edge-onboarding library for ServiceRadar checkers

A new Rust library has been added to the edge-onboarding crate to handle secure agent and checker onboarding. It supports mTLS bootstrap via signed edgepkg-v2 tokens and Core API package downloads, automatic deployment type detection (Docker, Kubernetes, or bare-metal), and generation of sysmon checker configurations. The library manages mTLS certificate installation, token parsing and validation, and provides a structured error model for onboarding failures.

rust/edge-onboarding · high confidence

New Rust-based configuration validator for ServiceRadar

A new Rust library in \config/manager\_validator/rust\ has been introduced to evaluate committed configuration rules against environment instances. This validator parses protobuf text-format configuration files, extracts leaf field paths and enum values directly from the schema descriptor to ensure coverage rules stay in sync with the schema, and scans configuration values for credential-shaped patterns (such as embedded passwords in URLs or high-entropy tokens) to prevent accidental secret exposure. It provides a normative evaluation engine that checks rules against specific environment kinds and phases, ensuring that configuration changes are validated for both structural correctness and security compliance.

_config/manager\validator/rust · high confidence

New Rust-based log ingestion and decoding pipeline in flowgger

The flowgger component now includes a comprehensive Rust implementation for parsing and encoding log data. This adds support for multiple syslog standards (RFC3164, RFC5424) and formats (GELF, LTSV) via a new decoder module that can automatically detect and parse incoming messages. It also introduces a Cap'n Proto encoder for efficient serialization and a TOML-based configuration system to manage input and output settings.

rust/flowgger · high confidence

New ServiceRadar Kubernetes edge sensor chart

A new Helm chart, \serviceradar-k8s-edge\, is available for clusters that do not run the full ServiceRadar platform. It deploys a lightweight \serviceradar-agent\ (outbound mTLS to a central or SaaS \agent-gateway\) and an optional \serviceradar-k8s-inventory\ component that watches the Kubernetes API for public VIP and Gateway ownership. The chart supports cluster-scoped or namespace-scoped RBAC, Gateway API discovery, and publishes inventory data via an \agent\_spool\ path to the central platform.

helm · high confidence

New ServiceRadar binary for extracting environment configuration sections

A new Rust-based tool (\config/tools/rust\) has been introduced to extract specific sections (database, nats, core, or dgraph) from a compiled \EnvironmentConfig\ binary. This utility supports a least-privilege security model by allowing targets to declare exactly which configuration section they require, ensuring that sandboxed processes (such as database tests) do not physically contain unrelated configuration data like NATS settings. The tool reads a protobuf-encoded input file, decodes the full environment config, extracts the requested section, and writes the result to an output file, failing if the section is missing or unknown.

config/tools/rust · high confidence

New agent add-on, discovery, and netprobe protocol contracts

The platform introduces new protobuf contracts that define the native agent add-on interface, the device discovery envelope, and the netprobe IPC protocol. The add-on contract (AddonService) standardizes how native plugins communicate with the agent over a restricted Unix-domain socket, supporting telemetry streaming, artifact staging, OTLP relay, local metric feeds, and command execution. The discovery envelope (DiscoveryEnvelope) provides a schema-driven, opaque payload mechanism for add-ons to report device observations to the control plane without requiring protocol changes for new observation types. The netprobe protocol (NetprobeFrame) defines the wire format for network visibility data, including fingerprinting, DPI, flow attribution, and remote capture sessions.

proto · high confidence

New build hygiene and release-contract validation scripts

The repository now includes a comprehensive suite of new shell and Python scripts in the \scripts/\ directory to enforce build hygiene, validate release contracts, and manage packaging. These scripts introduce automated gates for native add-on binary size regression, dead-code elimination, and forbidden stdlib plugin usage, ensuring add-ons remain lean and compatible with the host agent. Release workflows are now backed by strict validation scripts that check Helm chart defaults (such as CNPG WAL capacity and core analytics settings), verify OCI publish signatures, and ensure version bumps are correctly reflected in add-on manifests. Additionally, new tooling supports macOS agent packaging with notarization, multi-platform Docker image building, and fixture provisioning for remote-access smoke tests.

scripts · high confidence

New build/buildbuddy release pipeline entry point

A new Bazel build target and shell script have been added to the build/buildbuddy directory to orchestrate the release process. The release\_pipeline.sh script automates the setup of remote execution credentials, ensures required tools like Cosign and ORAS are installed, resolves the release tag from various environment variables or the VERSION file, and executes the container push via Bazel. It also handles post-push signing and verification of OCI images, providing a centralized, reproducible entry point for publishing releases.

build/buildbuddy · high confidence

New built-in dashboards for endpoint inventory, security findings, and service availability

The web interface now includes three new built-in dashboard renderers: Endpoint Inventory, Security Findings, and Service Availability (NOC). The Endpoint Inventory dashboard displays device scan coverage, package rollups, shared CPE exposure, and recent package rows. The Security Findings dashboard aggregates active findings, device correlation, scan activity, and DNS security events, including scanner signal coverage and exposure posture. The Service Availability dashboard shows overall availability, degraded services, SLO risk, and active incidents. All dashboards support user-configurable timezones for timestamp display and include interactive SRQL query links for deeper investigation.

elixir/web-ng/assets/js/dashboards · high confidence

New client-side hooks for device metadata, bulk editing, camera relay, and dashboard controls

This update introduces a suite of new JavaScript hooks in the web-ng frontend to enhance device details, bulk operations, camera streaming, and dashboard interactivity. The AllMetadataCard hook adds client-side filtering and a 'copy as JSON' button to the device metadata view. BulkEditTagsToggle dynamically reveals tag input fields during bulk actions. CameraRelayStatusStream manages WebRTC and MSE-based camera relay playback, handling browser compatibility and reconnection logic. Dashboard hooks (BuilderCanvas, MapViewSelect, PanelChart, WasmHost, WindowSelect) integrate React components for the dashboard builder, manage map view switching, render charts, and handle WASM-based dashboard rendering and time-window preferences. CommandPalette provides a keyboard-driven command interface for the Settings shell. CredentialDeepLinkFocus ensures deep-linked credential rows are scrolled into view and focused. DetailsState preserves the open/closed state of native \<details\> elements across LiveView patches. DialogTopLayer promotes modals to the browser's top layer to ensure they render above the ops sidebar and sticky UI elements.

elixir/web-ng/assets/js/hooks · high confidence

New demo skill for running web-ng against live CNPG database

Added a new agent skill (demo-cnpg-local-web-ng) that provides a script to run the local web-ng application against the live Kubernetes demo CNPG database. This allows users to test the dashboard, SRQL, and UI features using real demo data without relying on fragile kubectl port-forwarding, with automatic fallback to NodePort routes if the internal LoadBalancer VIP is unreachable.

.agents/skills/demo-cnpg-local-web-ng · high confidence

New development and CI precommit scripts for web-ng

Added \bazel\_precommit.sh\ to automate the Bazel precommit environment, handling OpenSSL detection, Git HTTPS redirection, and dependency caching for reliable CI runs. Introduced \dev-with-k8s-db.sh\ to streamline local development by automatically port-forwarding to a Kubernetes CNPG database, extracting TLS certificates and application secrets (including Cloak keys) from cluster secrets, and launching the Phoenix server with the correct configuration.

elixir/web-ng/scripts · high confidence

New example configuration for declarative Ansible controller setup

Added a new Terraform example in \terraform/examples/configuration/main.tf\ that demonstrates how to declaratively configure a ServiceRadar Ansible controller. This example shows users how to define an AWX inventory reader credential, link an existing execution credential, and configure an Ansible controller with specific sync intervals for inventory and catalog, alongside an associated playbook repository.

terraform · high confidence

New local development loop for web-ng with Docker-backed database

Developers can now iterate on the web-ng UI and dashboard packages locally without rebuilding the release image. This change introduces a new skill that provides scripts to start the local Phoenix server against the Docker Compose CNPG database, automatically handling mTLS certificate copying, database password validation (with a repair option for mismatched secrets), and syncing plugin storage. It also includes a script to import and enable dashboard packages directly into the running Docker instance via RPC, along with Playwright commands for browser verification.

.agents/skills/web-ng-docker-loop · high confidence

New reproducible proof harness for the ServiceRadar anomaly engine

A new \tools/anomaly-proof\ directory provides a reproducible proof harness that runs the real Rust anomaly detector and disposition kernels over synthetic labeled data to measure precision, recall, and latency. It includes Python generators for edge metrics (CPU, memory, disk, SNMP counters) and core seasonal/capacity baselines, a real TimescaleDB end-to-end feed proof, and plotting/scoring scripts. Additionally, a Bazel wrapper script and a musl download mirror configuration are added to stabilize CI builds, and a Go utility is introduced to derive the agent release public key from a private signing key.

tools · high confidence

New utility modules for chart rendering, time formatting, and timezone handling

This change introduces a suite of new JavaScript utility modules in the web-ng frontend to improve chart accuracy, time display, and timezone support. The new \chart\_axis\_grid.js\ and \chart\_hover\_geometry.js\ modules provide precise calculations for chart axis ticks and hover interactions, ensuring correct mapping of mouse positions to data points even with asymmetric plot gutters. The \user\_time.js\ and \dashboard\_user\_time.js\ modules replace ad-hoc formatting with a robust system that respects user timezones, handles DST transitions, and preserves canonical timestamp precision for both dashboard displays and chart axes. Additionally, \timezone\_options.js\ adds logic to filter and search available timezones based on browser support, while \formatters.js\ standardizes the display of network flow metrics (bytes, bits, rates). Finally, \window\_events.js\ centralizes clipboard and file download handling, and \registerLiveReloadHelpers\ adds development conveniences for server log streaming and editor navigation.

elixir/web-ng/assets/js/utils · high confidence

SRQL service initialization and data model definitions

The SRQL service is now bootstrapped with a new configuration system that reads environment variables (prefixed with SRQL\_) and manages PostgreSQL connection pooling with explicit TLS certificate handling. The service exposes a comprehensive set of data models for querying fleet inventory (agents, devices, gateways), observability data (logs, traces, metrics), network events (BMP routing, OCSF events), and endpoint inventory (packages, scans), providing the foundational row structures for the query engine.

rust/srql · high confidence

ServiceRadar Core-ELX release environment and VM configuration

The ServiceRadar Core-ELX release now includes a new environment script (rel/env.sh.eex) and VM arguments file (rel/vm.args.eex) to configure the Erlang runtime. The environment script handles node naming, mTLS distribution settings, remote shell access, and cookie management. The VM arguments file sets performance tuning parameters, including capping schedulers to a 4-core cgroup quota, disabling busy-wait spin, and increasing process, port, and atom limits. It also enables kernel polling, configures cluster connectivity, and sets up crash dump logging.

_elixir/serviceradar\_core\elx/rel · high confidence

ServiceRadar anomaly core introduces seasonal, drift, and robust detection primitives

The \rust/anomaly-core\ crate now provides a comprehensive set of detection algorithms for per-series anomaly detection. It introduces a two-sided CUSUM drift detector (\cusum.rs\) to catch slow, sustained shifts that point z-scores miss, and Seasonal-Hybrid ESD primitives (\esd.rs\) using robust median/MAD to identify outliers while controlling family-wise error rates. A Robust PCA implementation (\rpca.rs\) via Principal Component Pursuit with Jacobi SVD is added for optional, heavyweight multivariate and seasonal pattern decomposition. The core detector (\detector.rs\) and its backtest harness (\anomaly-backtest.rs\, \scorecard.rs\) now support configurable seasonal baselines, dispersion floors (min std/CV), and saturation gates to prevent benign gauge values from triggering critical alerts, ensuring edge and central scoring parity.

rust/anomaly-core · high confidence

ServiceRadar config manager added for Elixir and Go

Added the \ServiceradarConfig.Manager\ implementation in Elixir and Go within \config/manager\_config\. This component resolves environment configuration from the \SERVICERADAR\_ENV\ variable, loading instances from built-in artifacts (for \localhost\/\ci\) or mounted files (for \saas\/\demo\/\onprem\). It validates loaded configurations against an embedded rule set and performs an identity check to prevent connecting to the wrong database. The Elixir implementation includes a \Dsn\ type that redacts connection strings in logs, and both implementations include comprehensive tests for identity parsing, source resolution, and error reporting.

_config/manager\config · high confidence

Unified configuration schema and validation rule set

ServiceRadar introduces a centralized configuration schema (config.proto) and a data-driven validation rule set (rules.proto) to replace fragmented, language-specific checks. The schema defines environment kinds (including a new DEMO mode), database, NATS, and Dgraph connection details, and transport security settings, enforcing explicit presence and rejecting unspecified enum defaults to prevent silent misconfiguration. Validation logic is now declarative: rules specify predicates (such as Required, ForbiddenIf, and IntRange) and scopes, allowing constraints to be defined once and enforced across Go, Elixir, and other implementations via generated bindings and drift tests, ensuring consistency between committed instances and code.

config/proto · high confidence

Vendor Bumblebee scanner and Swift Arrow library into third\_party

This change introduces vendored copies of two third-party components under the \third\_party\ directory. The Bumblebee scanner (v0.1.1) is added as a Go library, enabling in-process vulnerability scanning for various ecosystems including browser extensions, editor extensions, and package managers (Bun, Composer, Go, MCP, npm). Additionally, the Swift Arrow library is vendored with a local patch to \ArrowData.swift\ that skips validity-bitmap access when the null count is zero, supporting omitted validity buffers.

_third\party · high confidence

Vendor addr2line and dlmalloc into third\_party for eBPF tooling

The repository now includes vendored copies of the addr2line Rust library and the dlmalloc allocator under third\_party/netprobe\_ebpf\_vendor. The addr2line source provides a cross-platform DWARF debug information parser capable of translating virtual memory addresses to source file names, line numbers, and function names (including inlined frames), with a CLI wrapper that supports options like demangling, pretty-printing, and LLVM-compatible output. The dlmalloc source provides a Rust port of the Doug Lea malloc implementation for memory management. These additions support the eBPF-based network probe toolchain by providing local, dependency-free implementations for address resolution and memory allocation.

(repo-wide) · high confidence

Behavioural changes

3 commits (0 fixes) modifying docker/images/\_\_pycache\_\_

A change to existing behaviour in docker/images/\_\pycache\\_ — 3 commits, 1 file.

docker/images/\\pycache\\_ · medium confidence · unverified_

Centralized configuration management with embedded validation rules

The Rust configuration crate now provides a unified system for resolving environment-specific settings, including dedicated modules for fetching CA bundles, managing secret names (such as database and Dgraph credentials), and enforcing a committed rule set embedded directly in the binary. This change ensures that configuration instances are validated against trusted, build-time rules rather than untrusted mounted files, and it centralizes the definition of secret identifiers so that multiple components can consistently resolve the same credentials without duplicating logic or introducing circular dependencies.

_config/manager\config/rust/src · high confidence

Enable Jump-specific Credo linting rules for Elixir code

The Elixir build now enforces a new set of code quality checks via Credo. A base configuration has been introduced to standardize file inclusion/exclusion, while specific rule sets for ExDNA and ExSlop have been added. Most notably, a new \jump\_checks.exs\ file activates custom Jump Credo checks (such as \AssertElementSelectorCanNeverFail\, \AvoidFunctionLevelElse\, and \VacuousTest\) across the Elixir applications, ensuring stricter adherence to internal coding standards during development and CI.

elixir · high confidence

Enforce Elixir formatting locally and add pre-push secret scanning

The repository now includes local git hooks to improve code quality and security before commits and pushes. The new \mix-format-elixir\ hook formats staged Elixir files and checks for unformatted code in sibling projects, failing the commit if issues are found (replacing the previous behavior where unformatted code was silently skipped locally). A \pre-commit\ hook now runs \pre-commit\ checks and specific quick checks for the \god\_view\ component. Additionally, a \pre-push\ hook integrates \gitleaks\ to scan for secrets in pushed commits, providing local feedback before pushing to the remote where Forgejo Actions also enforces secret scanning.

.githooks · high confidence

Introduce LargeIngestionGate release qualification and Git metadata verification

The CI pipeline now enforces a new release gate for large ingestion changes. A new \LargeIngestionGate\ policy checks that a specific \ex\_unit\_test\ target and BuildBuddy action are present in the release commit and that the \LargeIngestionGate\ status is successful before allowing a release. Additionally, a new Git metadata verification tool validates submodule configurations, ensuring paths and URLs are safe and consistent, and rejects unsafe or malformed submodule definitions.

build/ci · high confidence

Introduce unified, file-based environment configuration for ServiceRadar

ServiceRadar now uses a centralized configuration schema defined in \config/environments\ to manage deployment settings for CI, localhost, SaaS, and demo environments. These \.textproto\ files replace the previous reliance on ambient process environment variables, allowing consumers to declare specific environment instances as build dependencies. This change ensures that configuration is a declared input, improves security by excluding secrets from version control (resolved via SecretManager at runtime), and standardizes connection details for databases, NATS, core services, and Dgraph across all supported environments.

config/environments · high confidence

Migrate build system from Mix to Bazel

The Elixir build process has been migrated from the standard Mix toolchain to Bazel. This change enables hermetic compilation, consistent remote execution, and improved build performance across development and CI environments.

(repo-wide) · high confidence

Migrate external fetches to EgressClient

ServiceRadar core now routes all external network fetches through the dedicated EgressClient rather than the shared, proxied Finch pool. This change isolates outbound traffic handling, ensuring that external requests are managed by a specialized client instead of the general-purpose HTTP pool, which improves reliability and separation of concerns for outbound connectivity.

_elixir/serviceradar\core · high confidence

Migrate web-ng settings to a structured 3-category, 2-level navigation tree

The Settings interface has been reorganized into a structured navigation tree with three main categories and two levels of hierarchy, replacing the previous flat or legacy layout. This change includes migrating the remaining settings pages to the new catalog, updating contextual and suppressed status cards, and removing unused legacy navigation components to streamline access to configuration options.

elixir/web-ng · high confidence

Native SRQL NIF build system migrated to Bazel with hermetic LLVM

The ServiceRadar SRQL native component (the Rust NIF) has switched its build system from Cargo/Mix to Bazel, consolidating on a hermetic LLVM toolchain. This change introduces a new BUILD.bazel file that statically links the C++ runtime into the shared object to prevent runtime library resolution failures when the BEAM loads the NIF, and configures the Rust compiler to correctly expose the NIF initialization symbol. The build script now supports sandboxed builds by falling back to a vendored Cap'n Proto codegen when the capnp tool is unavailable, ensuring the NIF builds reliably in isolated environments.

_elixir/serviceradar\srql/native · high confidence

NetFlow charts now localize time labels to user timezone and improve axis readability

The NetFlow page now displays time labels on axes and tooltips according to the user's selected timezone instead of forcing UTC, while still preserving the canonical UTC instant for accessibility and data integrity. Additionally, the chart axes now intelligently switch their label format based on the time range: showing clock time for single-day views, adding dates for multi-day views, and showing full dates for longer periods to prevent label ambiguity. These changes are implemented in the new \netflow\_charts/util.js\ module, which handles timezone formatting, axis styling logic, and tooltip geometry.

_elixir/web-ng/assets/js/netflow\charts · high confidence

New Rust-based integration database lifecycle and connection observer

The integration database lifecycle has been rewritten in Rust to replace shell scripts and reduce CI startup overhead. New binaries manage the shared schema template (\prepare\_template\, \reset\_template\), provision per-run databases (\provision\_base\), and handle immutable schema generations (\generation\). A new connection observer (\observe\_connections\) monitors PostgreSQL connection capacity and quiescence during tests. Configuration is now resolved via a unified ConfigManager and SecretManager, eliminating fragile DSN parsing and hand-rolled runfile lookups.

rust/integration-db · high confidence

Port capacity forecasting kernel to Rust with improved prediction intervals

The capacity forecasting logic in the \anomaly-disposition\ crate has been rewritten in Rust, porting the Elixir \ServiceRadar.Observability.CapacityForecasting.Model\ to provide linear and Holt-Winters seasonal forecasts. This change introduces a new \disposition-backtest\ tool for replaying synthetic data through the core disposition kernels without a database. The forecasting engine now uses closed-form OLS prediction intervals for linear models and residual-bootstrap intervals for Holt-Winters, replacing the previous constant ±1.96·RMSE band. It also adds robust slope significance testing via the Theil-Sen estimator to skip forecasts where trends are not statistically significant, and improves exhaustion ETA reporting by distinguishing between history-capped and raw crossings.

rust/anomaly-disposition · high confidence

Rewritten ServiceRadar CLI with PKCE authentication and improved error reporting

The ServiceRadar CLI has been rewritten in TypeScript, introducing a new \auth\ command group that supports both the default OAuth 2.0 Device Authorization Grant and a new PKCE-based browser flow (enabled via \--web\). Authentication tokens are now securely stored in a versioned credential file with strict permissions. The CLI now provides detailed, actionable error messages for API failures—such as specific scope requirements or permission denials—instead of generic network errors. Additionally, the dashboard development workflow now uses Vite in middleware mode to enable Hot Module Replacement (HMR), allowing developers to see code changes instantly without manual rebuilds.

js/cli · high confidence

ServiceRadar brand theme and CSS architecture overhaul

The web application's visual identity has been updated to the ServiceRadar brand, replacing the previous Nocturne cyan/blue color scheme with a marketing-aligned green palette in both light and dark modes. This change introduces a new set of design tokens (e.g., \--color-sr-\*\) and removes the daisyUI plugin in favor of custom Tailwind brand primitives, ensuring consistent styling across components like the SRQL input and dashboard maps.

elixir/web-ng/assets/css · high confidence

ServiceRadar introduces automatic StarRocks schema migration and partitioned telemetry storage

ServiceRadar now automatically applies StarRocks DDL migrations at startup via a new SchemaMigrator, establishing a dedicated telemetry warehouse with daily-partitioned tables for network flows, timeseries metrics, logs, and events. This change introduces hourly materialized views for dashboard aggregates, which are rebuilt to be day-partitioned for efficient incremental refreshes, and adds specific columns to support sampling-weighted byte/packet totals, attribution data, and JSON-based event filtering, ensuring parity with the existing CNPG data source.

_elixir/serviceradar\core/priv/starrocks · high confidence

Unified log collector merges Flowgger and OTEL pipelines

The log-collector service has been refactored to combine the previously separate Flowgger (syslog/GELF) and OpenTelemetry (OTLP) ingestion pipelines into a single binary. Users now configure both pipelines via a unified TOML config file, with each pipeline independently enabled or disabled and pointing to its own native configuration file (defaulting to /etc/serviceradar/flowgger.toml and /etc/serviceradar/otel.toml). A unified gRPC health check server is now exposed on port 50044, reporting the status of the log-collector, flowgger, and otel services individually. The binary also switches the rustls TLS provider from aws-lc-rs to ring and includes a self-telemetry CPU storm reduction by adjusting log levels, the OTel root sampler, and the self-telemetry denylist.

rust/log-collector · medium confidence

Fixes

Add local test SDK stubs for WASM plugin builds

A new test-only Go library has been added to the build system to provide compile-time stubs for the ServiceRadar SDK. This includes definitions for signal schema references, telemetry records, and logging interfaces, allowing WASM plugin components (such as Axis, Proxmox, and UniFi Protect) to build against a consistent, minimal surface without requiring the full external SDK during compilation.

_build/wasm\plugins/testsdk · high confidence

Fix God View WASM loading in production builds

The God View feature now correctly loads its WebAssembly module in production environments. Previously, the code relied on \import.meta.url\ to locate the \.wasm\ asset, which fails in the production IIFE bundle because \import.meta.url\ is empty, causing the topology view to hang on a loading state. This change introduces a dedicated runtime (\GodViewWasmEngine\) that fetches the WASM file from a static Phoenix asset path (\/assets/js/god\_view\_exec.wasm\) and includes logic to retry with fallback paths, ensuring the visualization loads reliably.

elixir/web-ng/assets/js/wasm · high confidence

Initialize ServiceRadar schema baseline for fresh database installs

Added a frozen schema baseline (platform\_schema.sql) and its metadata (metadata.json) for the ServiceRadar core module, generated from a replayed empty database on PostgreSQL 18. This ensures that fresh installations start with a consistent, checksummed schema state, preventing bootstrap failures caused by schema drift or missing baseline files.

_elixir/serviceradar\core/priv/repo/baseline · high confidence

Migrate web-ng asset build to Bazel and fix dependency lockfiles

The web-ng browser assets are now built using Bazel targets (defined in the new BUILD.bazel) instead of the previous release action, which improves build caching and performance by decoupling asset compilation from Elixir source changes. This change also resolves build failures caused by inconsistent JavaScript dependency lockfiles by regenerating bun.lock and pnpm-lock.yaml to align with package.json, specifically pinning @deck.gl and @luma.gl versions to prevent symbol resolution errors during bundling.

elixir/web-ng/assets · high confidence

Test coverage

Add SRQL integration tests with isolated fixture harness; Add automated regression tests for Elixir benchmarks; Add conformance fixtures for ServiceRadar configuration rules; Added comprehensive test coverage for Armis Northbound integration and composite value exports; Added comprehensive test coverage for authored dashboards, access control, and package management; Added comprehensive test coverage for the automation callback grants subsystem; Added controller integration tests for authentication, CLI, and dashboard APIs; Added empty ServiceRadar integration test crate; Added integration tests for CLI device-auth cleanup worker; Added integration tests for ScanRun lifecycle and NATS-backed AdhocScan ingestion; Added integration tests for ServiceRadar gateway registration; Added integration tests for graph Cypher passthrough and SRQL NIF gateway queries; Added integration tests for large ingestion release gates; Added property-based tests for API and LiveView stability; Added regression tests for API credentials and user settings LiveViews; Added regression tests for Swift Arrow package compilation; Added regression tests for schema migration ledger exclusion; Added shared test fixtures for configuration validation; Added shared-fixture database test helper with strict test count validation; Added static analysis and compilation gates for database migrations and JSONB parameters; Added test coverage for Agent Live views; Added test coverage for Ansible AWX automation components; Added test coverage for ProvisionAgentWorker and RecordEventWorker; Added test coverage for SNMP profile credential resolution, targeting, and lifecycle management; Added test coverage for ServiceRadar Edge onboarding and bundle generation; Added test coverage for ServiceRadar Northbound automation; Added test coverage for ServiceRadar Web-NG dashboard and telemetry components; Added test coverage for ServiceRadar background workers; Added test coverage for ServiceRadar core admission, flow attribution, and results routing; Added test coverage for ServiceRadar infrastructure components; Added test coverage for ServiceRadar sweep job internals; Added test coverage for Serviceradar inventory remediation steps; Added test coverage for StarRocks analytics components; Added test coverage for add-on and plugin domain logic; Added test coverage for admin LiveView pages; Added test coverage for advisory feed ingestion and configuration; Added test coverage for alert device identity and notification wiring; Added test coverage for camera relay and analysis subsystems; Added test coverage for credential broker grants, retention, and rotation; Added test coverage for dashboard frames, topology, and remote access channels; Added test coverage for discovery decoders, ingestor, and timestamp formatting; Added test coverage for identity address classification, revision fencing, and duplicate sweep logic; Added test coverage for inventory sync policies and execution; Added test coverage for notification action links, token redemption, and delivery retention; Added test coverage for remote access LiveViews; Added test coverage for security audit history, event recording, and rate limiting; Added test coverage for the Attributed Flows LiveView; Added test coverage for the SeasonalDisposition subsystem; Added test coverage for the ServiceRadar dashboard LiveView; Added test coverage for the Settings navigation catalog and notification settings UI; Added test coverage for the cold-tier telemetry offload system; Added test coverage for the new prefix tags subsystem; Added test coverage for the stateful alert engine lifecycle and routing; Added test coverage for topology graph canonical rebuild and mutation logic; Added test fixtures for accounts and notifications contexts; Added test helper to ensure telemetry application starts before tests; Added test support stubs and helpers for ServiceRadar web-ng; Added tests for AgentRegistry functionality; Added tests for AlienVault OTX provider sync; Added tests for CSRF protection on remote-access API routes; Added tests for DataService client channel management; Added tests for Device and SystemActor modules; Added tests for EgressClient and EgressProxy; Added tests for Event LiveView timezone localization, device linking, and alert rule creation; Added tests for God View topology snapshot validation and runtime graph processing; Added tests for MCP OAuth IDP session refresh logic; Added tests for MTR diagnostics comparison and data retrieval; Added tests for NATS account client, agent permissions, and JetStream consumer logic; Added tests for NetFlow Live visualization filters and flow list state handling; Added tests for Netflow Visualize query logic and state management; Added tests for OIDC token exchange retry logic; Added tests for OTel log exporter sanitization and gRPC channel lifecycle; Added tests for OTel log filtering and context propagation; Added tests for PluginConfigForm component behavior; Added tests for PostgreSQL schema SQL parsing and extension privilege handling; Added tests for RBAC Live View components and state management; Added tests for RBAC catalog permissions; Added tests for SNMP profile lifecycle, provenance, and targeting; Added tests for SRQL builder, catalog, and scope builder logic; Added tests for SRQL security, access control, and UI state management; Added tests for ServiceRadar Core event handling components; Added tests for ServiceRadar SRQL native encoding; Added tests for ServiceRadar automation callback contracts and security foundations; Added tests for ServiceRadar changes and identity modules; Added tests for ServiceRadar notification firehose replay logic; Added tests for ServiceRadar service port lookup and labeling; Added tests for Sysmon profile sample interval parsing and compiler logic; Added tests for WiFi Map batch ingestor and CSV seed payload parsing; Added tests for Zen normalizer caching and SNMP trap normalization; Added tests for admin user bootstrap logic; Added tests for agent command status handling and pubsub gating; Added tests for agent config compiler and dependency catalog; Added tests for alert acknowledgement, snoozing, and authorization controls; Added tests for anomaly detection series key generation and alignment; Added tests for attributed flow row mapping and time-window navigation; Added tests for authorization permissions; Added tests for camera relay analysis and media ingestion components; Added tests for camera relay, FieldSurvey Arrow, and notification firehose channels; Added tests for composite check catalog filtering logic; Added tests for composite check rules, sweep context, and agent picker components; Added tests for composite check validation coverage and orchestration; Added tests for credential coverage validation logic; Added tests for dashboard package access controls and UI behavior; Added tests for dashboard package validation and import logic; Added tests for database bootstrap, startup migrations, and schema validation; Added tests for device live endpoint inventory findings logic; Added tests for event-to-device reference extraction; Added tests for flow attribution event processing, persistence, and retention; Added tests for identity validation logic; Added tests for launch envelope encryption, resolution, and security constraints; Added tests for manual device creation and classification protection; Added tests for metric detail trace pivots and timestamp localization; Added tests for network address and outbound URL policies; Added tests for network configuration parsing, ingestion, and projection; Added tests for notification callback route buffering; Added tests for notification callback verification and key management; Added tests for object store retention logic; Added tests for outbound mail runtime configuration and SMTP TLS handling; Added tests for stale job reaping and trace summary refresh workers; Added tests for the Anomaly Disposition Peak Profile module; Added tests for the ServiceRadar dashboard frame runner; Added tests for the Threat Intel investigation workspace; Added tests for the declarative notification provider catalog and definition validator; Added tests for the new database integration test lifecycle and configuration; Added tests for the new notification transport layer; Added tests for the trace detail view (TraceLive.Show); Added tests for the web-ng authentication subsystem; Added tests for threat intel page model and STIX indicator normalization; Added tests for topology attachment metadata retention; Added unit tests for NetFlow enrichment expiry SQL generation; Added unit tests for Netflow Live chart states, interface traffic, and local anchors; Added unit tests for ServiceRadar Web-NG components; Added unit tests for composite export validation; Added unit tests for web-ng Phoenix components; Added unit tests for web-ng domain logic; Expanded LiveView test coverage for observability features; Expanded test coverage for ServiceRadar Agent Gateway; Expanded test coverage for ServiceRadar EventWriter components; Expanded test coverage for ServiceRadar domain resources and policies; Expanded test coverage for ServiceRadar network discovery and mapper logic; Expanded test coverage for Serviceradar Edge agent configuration and command bus; Expanded test coverage for Settings LiveViews; Expanded test coverage for dashboard, remote access, and SSH console components; Expanded test coverage for identity, access control, and device aliasing logic; Expanded test coverage for inventory core components; Expanded test coverage for plugin addon profiles, rollouts, and alert rule catalogs; Expanded test coverage for web-ng LiveView components and helpers; Expanded test infrastructure for automation, credentials, and observability; Integration test concurrency audit and live Armis integration test; New Playwright acceptance tests for visibility profiles, dashboard authoring, and UI layout; New contract tests for release keys, schema baseline, and CI workflows; Test coverage for web-ng API controllers; Test infrastructure overhaul: DB-free execution, zero-test detection, and OCSF schema support.

Dependencies

Rust workspace migration to Edition 2024 and consolidated dependency management

The Rust build system has been upgraded to Edition 2024, requiring a minimum Rust version of 1.97.1, and all workspace dependencies are now centrally defined in the root \Cargo.toml\ to reduce redundancy. This change introduces a new \Cargo.lock\ file to track resolved versions and updates key libraries, including \axum\ to 0.8, \tonic\ and \prost\ to 0.14, and \diesel\ to 2.3, while also switching the TLS provider from \aws-lc-rs\ to \ring\ for improved hermeticity.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 68.

Lenses

  • Code Health 68
  • Architecture 76
  • Maturity 87
  • Readiness 69
  • Security 66
  • Domain Modelling 100
  • Event-Driven 100
  • Event Sourcing 100
  • Accessibility 64

Changes since last survey

  • 300 commits — 161 feature/other, 139 fixes

By area

  • (repo) — 93 commits
  • elixir/serviceradar_core — 49 commits
  • elixir/web-ng — 43 commits
  • openspec/changes — 25 commits
  • rust/srql — 21 commits
  • helm/serviceradar — 16 commits
  • (root) — 11 commits
  • js/cli — 11 commits
  • .github/workflows — 7 commits
  • docs/docs — 4 commits
  • k8s/starrocks — 3 commits
  • build/contracts — 2 commits
  • build/integration_test_dispositions.bzl — 2 commits
  • elixir/serviceradar_core_elx — 2 commits
  • go/pkg — 2 commits
  • openspec/specs — 2 commits
  • rust/age-to-dgraph — 2 commits
  • docker/images — 1 commit
  • docs/RELEASE_PUBLISHING.md — 1 commit
  • elixir/serviceradar_agent_gateway — 1 commit

Notable commits

  • fix: Merge branch 'staging' into fix/starrocks-logs-events-parity
  • fix: Merge pull request #4493 from carverauto/fix/netflow-activity-view-gate
  • fix: Merge pull request #4495 from carverauto/fix/publish-oci-drop-dead-skopeo-install
  • fix: Merge pull request #4496 from carverauto/fix/starrocks-catalog-generated-credentials
  • fix: Merge pull request #4498 from carverauto/fix/publish-oci-sign-by-registry-tag
  • fix: Merge pull request #4501 from carverauto/fix/netflow-map-distinct-arcs
  • fix: Merge pull request #4502 from carverauto/fix/netflow-sankey-true-top-edges
  • fix: Merge pull request #4503 from carverauto/fix/starrocks-direction-reserved-partition
  • fix: Merge pull request #4504 from carverauto/fix/netflow-map-draw-every-arc
  • fix: Merge pull request #4505 from carverauto/fix/dashboard-events-axis-labels
  • fix: Merge pull request #4508 from carverauto/fix/dashboard-events-axis-last-tick
  • fix: Merge pull request #4509 from carverauto/fix/dashboard-window-keep-data-while-loading
  • fix: Merge pull request #4510 from carverauto/fix/stateful-alert-engine-shard-dispatch
  • fix: Merge pull request #4522 from carverauto/fix/starrocks-counter-rate
  • fix: Merge pull request #4523 from carverauto/fix/srql-ip-cidr-encoding
  • fix: Merge pull request #4526 from carverauto/fix/starrocks-metrics-parity
  • fix: Merge pull request #4527 from carverauto/fix/demo-charts-read-starrocks
  • fix: Merge pull request #4532 from carverauto/fix/starrocks-flows-parity
  • fix: Merge pull request #4533 from carverauto/fix/agent-command-bus-test-handler-race
  • fix: Merge pull request #4535 from carverauto/fix/starrocks-async-env-race
  • …and 280 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

carverauto/serviceradar was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 24 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 0b777ea34e5aef68a7af877699685b88fbfc82ba — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-923689c465cf.