carverauto/threadr
46.8
Weak · 21 September 2026
35.2k
lines of production code
Elixir
with Go, JavaScript
7
measurements over time
What this system is
This system is a distributed platform for managing and visualizing graph topologies, centered around an Elixir/Phoenix backend and a Rust/WASM-based graph execution engine. It provides a control plane that ingests events from IRC and Discord bots via NATS, processes them through a CloudEvents messaging layer, and stores relationship data in Neo4j. The infrastructure is fully containerized with Kubernetes manifests for deployment, including operators for bot workloads and configuration for remote build execution.
How it got here
2024 — Initial infrastructure and service scaffolding
12 changes.
This period focused on establishing the foundational infrastructure and build systems for the project, including Bazel, Kubernetes manifests, and NATS-based messaging. It introduced core services such as the API server, IRC/Discord bots, and database clusters, while also setting up the necessary operational tooling and CI/CD pipelines.
2026 — Elixir backend and graph UI scaffolding
6 changes.
This period focused on establishing the foundational architecture for Threadr 2.0, centering on the Elixir backend and Phoenix-based frontend. Key work included setting up the application configuration, implementing Rust-based graph execution logic for the UI, and creating a comprehensive test suite with mocked dependencies.
Features
Add NATS-based CloudEvents messaging and multi-platform message adapters
The system now supports publishing and subscribing to CloudEvents via a new NATS broker adapter, enabling asynchronous message handling. This change introduces adapters for Discord and IRC, which capture messages and publish them as CloudEvents to the NATS broker. Additionally, a batch processor is added to handle message processing, and a Neo4j graph database adapter is introduced for relationship storage. The architecture also includes a composite message handler to delegate events to multiple handlers.
pkg · high confidence
Add cert-manager configurations for Azure and K3s environments
This change introduces new Kubernetes manifests for managing TLS certificates using cert-manager. For Azure, it adds a self-signed issuer, a production and staging ClusterIssuer configured for Azure DNS, and a Certificate resource for www.threadr.ai. It also includes a sample deployment and service for testing TLS. For K3s, it adds a self-signed CA bootstrap, a Cloudflare DNS-01 issuer, and Certificate resources for tunnel.carverauto.dev and tunnel.serviceradar.cloud. Additionally, test resources are added to verify the cert-manager setup.
k8s/cert-manager · high confidence
Added FRR configuration for BGP routing
The FRR (Free Range Routing) configuration file has been added to the k8s/frr directory, establishing a BGP routing setup for a UDM Pro device. The configuration defines BGP neighbors across both IPv4 and IPv6 address families, enabling dynamic routing capabilities within the cluster.
k8s/frr · high confidence
Added Kubernetes manifests for deploying Nebula Studio and NebulaGraph clusters
New Kubernetes configuration files have been added to the \k8s/nebula\ directory, providing the necessary resources to deploy and manage a NebulaGraph cluster. This includes a Custom Resource Definition (CRD) for \NebulaCluster\, a sample cluster configuration (\cr.yaml\), a detailed \nebulacluster.yaml\ defining the Graph, Meta, and Storage service specifications, and Service manifests (\graphd-clusterip-service.yaml\, \nodeport.yaml\) to expose the cluster via NodePort. Additionally, a \README.md\ is included with a Helm upgrade example for the Nebula Studio component.
k8s/nebula · high confidence
Added admin client for managing user claims and secure endpoints
A new admin client tool has been introduced in the \cmd/client/admin\ directory. This utility allows administrators to retrieve and update custom user claims via HTTP requests to the API, as well as access secure endpoints that require tenant-level security headers. The package includes functions for Firebase authentication and claim management, providing a dedicated interface for admin-level operations.
cmd/client · high confidence
Added graph execution and snapshot encoding logic
The graph execution module now includes Rust implementations for computing state masks and three-hop neighbor masks, enabling the frontend to determine which nodes to display based on their health status and proximity to a root node. Additionally, the native interface now supports encoding graph snapshots into Arrow IPC format, allowing efficient serialization of node and edge data for the UI.
_elixir/threadr/assets/wasm/threadr\_graph\_exec, elixir/threadr/native/threadr\_graph\nif · high confidence
Added script to configure BuildBuddy remote cache
A new shell script, write\_remote\_rc.sh, has been added to the tools directory. This script generates a .bazelrc.remote file containing the API key for BuildBuddy remote caching, reading the key from environment variables BUILDBUDDY\_API\_KEY or BUILDBUDDY\_ORG\_API\_KEY.
tools · high confidence
IRC and Discord bot implementations added to cmd/bots
The repository now includes standalone Go applications for IRC and Discord bots, each with their own main.go entry points and Makefiles for building Docker images. The IRC bot connects to an IRC server, listens for messages, publishes CloudEvents to NATS, and receives results back to post in the channel. The Discord bot similarly connects to Discord, publishes chat messages to NATS, and listens for results to send back to Discord channels. Both bots use CloudEventsNATSHandler for message brokering and are structured as independent commands under cmd/bots.
cmd/bots · high confidence
Initial Bazel build system and remote execution configuration
The repository now supports building with Bazel, introducing a complete build infrastructure including \MODULE.bazel\ with dependencies for Elixir, Erlang, and C/C++ toolchains, alongside configuration for remote execution via BuildBuddy. This enables consistent, reproducible builds and remote caching/execution, with the default remote executor set to \docker://ghcr.io/carverauto/serviceradar/rbe-executor:v1.0.21\. The setup includes \.bazelrc\ for build and test configurations, a \.bazelversion\ file pinning Bazel 7.4.1, and helper scripts for Docker authentication. This change establishes the foundation for the project's build and CI/CD pipeline.
(repo-wide) · high confidence
Initial Kubernetes manifests for Threadr infrastructure and services
This change introduces the complete Kubernetes deployment manifests for the Threadr platform, establishing the foundational infrastructure and service layers. It defines the control plane, worker nodes, and supporting services including NATS (with TLS and certificate management), a CloudNative PostgreSQL cluster, and a bot operator. The configuration includes base definitions for IRC, Discord, and message processing bots, alongside production overlays that enforce network policies, TLS ingress routing, and specific environment variable patches for each component.
k8s/threadr · high confidence
Initial Phoenix scaffold and graph explorer for Threadr 2.0
The Threadr Elixir application is now scaffolded with a Phoenix LiveView foundation, including a new TenantGraphExplorer JavaScript hook and associated WASM graph rendering logic. This adds the frontend infrastructure for the graph topology UI, while the Elixir side provides the control-plane resources, Broadway pipelines, and Ash/Ecto models required to support it.
elixir/threadr · high confidence
Initial configuration for the Threadr application
The Threadr application is now fully configurable across all environments. The default config sets up Ecto, Ash domains, and various background dispatchers (e.g., BotOperationDispatcher, TenantMigrationDispatcher). The development environment enables code reloading, debugging, and hot-reload watchers. The production environment configures Swoosh for email and disables local memory storage. The runtime configuration dynamically loads NATS messaging settings (host, port, TLS, authentication) and database SSL options from environment variables, allowing secure and flexible deployment. Test configurations disable background jobs and use in-memory or sandboxed database setups for faster, isolated testing.
elixir/threadr/config · high confidence
Introduce ircbot-operator for managing IRC and Threadr bot workloads
A new Kubernetes operator for the \cache.threadr.ai/v1alpha1\ API group has been added to \k8s/operators/ircbot-operator\. This operator manages two custom resources: \IRCBot\, which handles legacy IRC bot configurations, and \ThreadrBot\, which manages the Threadr 2.0 control-plane contract. The operator includes controllers to reconcile these resources into Kubernetes Deployments, with \ThreadrBot\ supporting synchronization with an external control plane via environment variables (\THREADR\_CONTROL\_PLANE\_BASE\_URL\, \THREADR\_CONTROL\_PLANE\_TOKEN\). The package also provides build infrastructure, including a Dockerfile, Makefile, and Operator Lifecycle Manager (OLM) bundle manifests for deployment.
k8s/operators · high confidence
Introduce natsctl CLI for NATS configuration management
A new command-line tool, natsctl, is added to manage NATS configuration, including initializing the server setup, creating and listing accounts and users, generating credentials, and testing connectivity. This tool is designed to bootstrap and maintain NATS server configuration, though cloud users are advised that their configuration is managed by the cloud service.
cmd/natsctl · high confidence
Introduce the main entry point for the API server
Added cmd/api/main.go, which initializes the Fiber application, loads environment variables, sets up Firebase, and registers both protected (/secure) and general routes.
cmd/api · high confidence
Behavioural changes
Hermetic Elixir and Erlang toolchains via new environment variables
The Elixir and Erlang third-party rules now support fully hermetic builds by allowing users to skip host-installed toolchains. Setting the environment variables RULES\_ELIXIR\_SKIP\_SYSTEM=1 or RULES\_ERLANG\_SKIP\_SYSTEM=1 disables the automatic detection of system Elixir and Erlang/OTP installations, ensuring consistent builds in CI or remote execution environments. Additionally, the apple\_support dependency is updated to version 1.15.1.
_third\party · high confidence
Test coverage
Added test infrastructure and test doubles for the Elixir backend
This change introduces the foundational test suite for the Elixir application. It adds test helper modules (ConnCase, DataCase) to standardize database and HTTP connection setup, along with a suite of new test files covering the control plane (bootstrap, bot configuration, operation dispatching, status observation, and policy enforcement). It also includes tests for the history request logic and the Discord bot QA consumer. To support these tests, the diff adds several test double modules (e.g., TestEmbeddingProvider, TestGenerationProvider, TestIRCClient) that mock external ML and messaging services, ensuring the tests can run without live dependencies.
elixir/threadr/test · high confidence
Dependencies
Initial dependency manifests for threadr assets, WASM, and Elixir backend
Added package-lock.json and package.json for the threadr frontend assets, introducing dependencies on @deck.gl/core, @deck.gl/layers, and apache-arrow. Added Cargo.lock and Cargo.toml for the threadr\_graph\_exec WASM module. Added mix.exs and mix.lock for the Elixir threadr application, establishing the backend dependency graph including Ash, Phoenix, and various Elixir libraries.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 38 → 47 (+8.6)
- Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 32 → 37 (+4.9)
- Architecture 100 → 95 (-4.7)
- Maturity 74 → 69 (-6.0)
- Readiness 27 → 54 (+27.1)
- Security 48 → 48 (+0.3)
- Accessibility 62 (new)
Resolved (153)
- (anonymous) (cyclomatic 16) (elixir/threadr/assets/js/lib/threadr_graph/rendering_selection_methods.js)
- Change coupling: config.exs ↔ service.ex (elixir/threadr/config/config.exs)
- Coverage not included — suite not readable by the collector
- Critical CVE: [GHSA redacted] (go.mod)
- Critical CVE: [GHSA redacted] (go.mod)
- Critical CVE: [GHSA redacted] (go.mod)
- Critical CVE: [GHSA redacted] (go.mod)
- Critical IaC: KSV-0046 (k8s/argocd/base/argocd-install.yaml)
- Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
- Duplicated block (10 lines × 2) (elixir/threadr/lib/threadr/ml/actor_qa.ex)
- Duplicated block (10 lines × 2) (elixir/threadr/lib/threadr/ml/constrained_qa.ex)
- Duplicated block (10 lines × 2) (elixir/threadr/lib/threadr/ml/generation/chat_completions_provider.ex)
- Duplicated block (10 lines × 4) (elixir/threadr/lib/threadr/control_plane/analysis.ex)
- Duplicated block (10 lines × 4) (elixir/threadr/lib/threadr_web/controllers/api/v1/bot_controller.ex)
- Duplicated block (10 lines × 4) (elixir/threadr/lib/threadr_web/controllers/api/v1/me_controller.ex)
- Duplicated block (10 lines × 5) (elixir/threadr/lib/threadr_web/controllers/api/v1/bot_controller.ex)
- Duplicated block (11 lines × 2) (elixir/threadr/lib/threadr/control_plane/analysis.ex)
- Duplicated block (11 lines × 2) (elixir/threadr/lib/threadr/control_plane/service.ex)
- Duplicated block (11 lines × 2) (elixir/threadr/lib/threadr/control_plane/smoke_server.ex)
- Duplicated block (11 lines × 2) (elixir/threadr/lib/threadr/ml/actor_qa.ex)
- …and 133 more
New (1075)
- Critical CVE: [GHSA redacted] (go.mod)
- Critical CVE: [GHSA redacted] (go.mod)
- Critical CVE: [GHSA redacted] (go.mod)
- Critical CVE: [GHSA redacted] (elixir/threadr/mix.lock)
- Critical CVE: [GHSA redacted] (go.mod)
- Critical IaC: KSV-0046 (k8s/argocd/base/argocd-install.yaml)
- Critical IaC: KSV-0046 (k8s/argocd/base/argocd-install.yaml)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Dormant codebase
- Duplicated block (10 lines × 2) (elixir/threadr/lib/threadr/history_request.ex)
- Duplicated block (10 lines × 2) (elixir/threadr/lib/threadr/ml/generation/chat_completions_provider.ex)
- Duplicated block (10 lines × 2) (elixir/threadr/lib/threadr/tenant_data/ingest.ex)
- Duplicated block (10 lines × 6) (elixir/threadr/lib/threadr_web/controllers/api/v1/bot_controller.ex)
- Duplicated block (10–11 lines × 2) (elixir/threadr/lib/threadr/tenant_data/ingest.ex)
- Duplicated block (10–11 lines × 4) (elixir/threadr/lib/threadr_web/controllers/api/v1/me_controller.ex)
- Duplicated block (10–14 lines × 2) (elixir/threadr/lib/threadr_web/controllers/api/v1/history_controller.ex)
- Duplicated block (11 lines × 2) (elixir/threadr/lib/threadr/control_plane/service.ex)
- Duplicated block (11 lines × 2) (elixir/threadr/lib/threadr/control_plane/smoke_server.ex)
- Duplicated block (11 lines × 2) (elixir/threadr/lib/threadr/ingest/bot_qa.ex)
- …and 1055 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
carverauto/threadr was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit aba5b16ea92affbaa5287b897ffff0b4861caedf — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-b84573e22831.