chef/chef_authn
50.8
Adequate · 17 September 2026
1.6k
lines of production code
Erlang
primary language
1
measurement over time
What this system is
This system is an Erlang library designed to handle authentication and request signing for the Chef API. It implements the v1.3 signing protocol using SHA-256 hashing and provides a caching mechanism for RSA key generation to optimize performance. The codebase includes utilities for managing keyrings and validating time skew, supported by a comprehensive test suite covering protocol versions 1.0 through 1.3.
Features
Initial project setup with rebar3, Apache 2.0 license, and CI configuration
The repository has been initialized with a standard Erlang project structure using rebar3 for build and dependency management. This includes a new Makefile to streamline running tests and dialyzer checks, a .travis.yml file to enable continuous integration on Erlang versions 17.5 through 21.0, and a .gitignore file to exclude build artifacts. The project is now licensed under the Apache License, Version 2.0, and includes standard documentation files such as README.md, CODE\_OF\_CONDUCT.md, and SECURITY.md to guide contributors and users.
(repo-wide) · high confidence
Initial release of chef\_authn with RSA key caching and v1.3 signing support
This change introduces the chef\_authn Erlang library for signing and authenticating Chef API requests. It adds a new RSA key generation and caching system (chef\_keygen\_cache) that pre-creates key pairs to improve performance, and implements the v1.3 signing protocol which mandates SHA-256 hashing and includes the X-Ops-Server-API-Version header in signed messages. The library also provides a keyring component for managing PEM-encoded keys and supports loading keys via environment variables or custom callbacks.
src · high confidence
Fixes
Added placeholder file to priv directory
A .gitkeep file was added to the priv directory to ensure the directory is tracked by version control.
priv · low confidence
Test coverage
Added test suite for Chef authentication and key management
Added comprehensive EUnit tests for the \chef\_authn\ module, covering request signing and authentication logic for protocol versions 1.0 through 1.3 (including SHA256 support for v1.3). The suite also includes tests for the \chef\_keyring\ module (key loading, listing, and reloading), the \chef\_keygen\_cache\ module (key generation, caching, and timeout handling), and \chef\_time\_utils\ (time skew validation). Additionally, numerous test fixtures (PEM keys, certificates, and private keys) were added to support these test scenarios.
test · high confidence
Housekeeping
Generated documentation for chef\_authn modules
The documentation in the doc directory has been regenerated using the edown tool, producing both HTML and Markdown versions for the chef\_authn, chef\_keygen\_cache, chef\_keygen\_worker, chef\_keygen\_worker\_sup, chef\_keyring, and chef\_time\_utils modules.
doc · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Baseline
- First survey — no prior run to compare against. CAI 51.
Lenses
- Code Health 97
- Architecture 100
- Maturity 35
- Readiness 44
- Security 75
Changes since last survey
- 159 commits — 141 feature/other, 18 fixes
By area
- src/chef_authn.erl — 57 commits
- (repo) — 35 commits
- (root) — 30 commits
- test/chef_authn_tests.erl — 11 commits
- src/chef_keyring.erl — 4 commits
- test/chef_keyring_tests.erl — 4 commits
- src/chef_keygen.hrl — 3 commits
- src/chef_authn.app.src — 2 commits
- src/chef_authn.beam — 2 commits
- src/chef_authn.hrl — 2 commits
- src/chef_keygen_cache.erl — 2 commits
- src/chef_time_utils.erl — 2 commits
- doc/README.md — 1 commit
- priv/.gitkeep — 1 commit
- src/chef_keygen_worker.erl — 1 commit
- test/private_key_pkcs8 — 1 commit
- test/private_key_pkcs8_dsa — 1 commit
Notable commits
- fix: Fix bugs in canonical_path and improve test coverage
- fix: Fix certificate encoding change
- fix: Fix dialyzer spec issues
- fix: Fix public key handling for version 1.2 authentication
- fix: Fix types (for real)
- fix: Fix warnings
- fix: Merge pull request #25 from chef/fix/rsa-private-key-type
- fix: Merge pull request #26 from chef/ssd-sr/fix-types
- fix: Merge pull request #27 from chef/ssd-sr/fix-cert-breakage
- fix: Merge pull request #31 from chef/sr/as-promised-fix-travis
- fix: Merge pull request #33 from chef/ssd-sr/fix-otp-18-ensure-binary
- fix: Revert "Update to Erlang 24x"
- fix: Updated to fix deprecations with 17
- fix: convert to rebar3 (fix test file references)
- fix: fix decrypt_sig to accept binary cert
- fix: fix dialyzer
- fix: fix get_key_der macro (replace with function)
- fix: fix rsa_{private,public}_key types
- change: Add .travis.yml
- change: Add X-Ops-Server-API-Version to signed message for v1.3
- …and 139 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
chef/chef_authn was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 17 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit cc93153535d89270ab56577926d94d42a5bd76c2 — the exact code this score is about.
- Scored under rubric-2026.09.13 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-d1ef6c0bd534.