Skip to content
CAI
Software that uses CAICheck a score

chef/chef-server

63.2

Adequate · 23 September 2026

56.5k

lines of production code

Erlang

with Ruby

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is Chef Server, a configuration management platform that manages infrastructure nodes, cookbooks, and users through a REST API. It handles identity and access control via an OAuth 2 provider and a dedicated authorization service, while storing data in PostgreSQL and indexing search queries with Elasticsearch or OpenSearch. The platform also includes an object storage service for cookbook artifacts and provides command-line tools for administration, backup, and migration.

How it got here

2010–2015 — Component extraction and modernization

99 changes.

This period focused on extracting core services like Chef Identity, Bookshelf, and Bifrost into standalone components while migrating the backend from CouchDB to PostgreSQL. It also established a modern, self-contained development environment and expanded the API test suite to cover the new authorization and search capabilities.

2016–2020 — Habitat packaging and CI migration

42 changes.

The project transitioned its core services to Habitat packaging, introducing build plans, lifecycle hooks, and configuration templates for components like Bookshelf, Nginx, and oc\_erchef. This effort was accompanied by a major migration of the CI/CD infrastructure to Buildkite and Expeditor, alongside significant restructuring of the chef-server-ctl tooling and the introduction of Sqitch-based schema management.

2021–2024 — Telemetry and license enforcement

7 changes.

This period focused on implementing core infrastructure components for usage tracking and compliance, specifically introducing the chef\_telemetry application for collecting and reporting node metrics and the chef\_license application for local license enforcement. Additionally, the team enhanced code quality and operational flexibility by adding documentation linting rules, expanding test coverage for email verification, and making the OneTrust integration configurable via environment variables.

Features

Add Habitat packaging for the Bookshelf service

Introduces Habitat build and configuration files for the Bookshelf S3-compatible object store. The new plan.sh defines dependencies on Erlang 26, PostgreSQL 14 client, and other core packages, while default.toml provides configuration for the service's listening port (4321), database connection settings, and log rotation behavior.

src/bookshelf/habitat · high confidence

Add Habitat packaging hooks for oc\_erchef

The oc\_erchef service now includes Habitat packaging hooks (init, run, reconfigure, health\_check) to support containerized deployment. The run hook configures the environment to use Ruby 3.1 and sets up necessary paths for the application, while the init hook handles logging setup and database migrations. A new health\_check hook is also added to monitor service status via HTTP requests to the local status endpoint.

_src/oc\erchef/habitat/hooks · high confidence

Add application layout template for Chef Identity Service

The application layout template for the Chef Identity Service has been added, providing the base HTML structure for the user interface. This layout includes the navigation bar with conditional links for signed-in users (profile, applications, sign out) and guests (sign in, sign up), displays flash messages, and renders the footer with links to the Privacy and Cookie Policies. It also integrates the analytics partial and includes necessary JavaScript and CSS assets.

src/oc-id/app/views/layouts · high confidence

Add bookshelf stress test suite

A new stress testing tool for bookshelf has been added to the \src/bookshelf/stest\ directory. This suite uses basho\_bench to simulate high-load scenarios, specifically targeting process leaks that cause 'Too many processes' failures. It includes an Erlang-based benchmark configuration (\bookshelf\_bench.config.example\) for connecting to a bookshelf instance, an R script (\priv/summary.r\) for generating visual reports of throughput and latency, and standard build files (Makefile, rebar.config) to manage dependencies and execution.

src/bookshelf/stest · high confidence

Add development provisioning cookbook for local LDAP and Chef Server setup

Introduces a new 'provisioning' cookbook that automates the setup of a local development environment. This includes configuring an OpenLDAP server with pre-seeded test users (such as 'Julia Child' and 'Tom Douglas'), generating SSL certificates for LDAP, and managing Chef Server and Opscode Reporting configurations via templates. It also handles host file updates and pre-seeds Diffie-Hellman parameters to speed up nginx startup in the development VM.

dev/cookbooks/provisioning · high confidence

Add fix\_permissions knife script for Chef 11 to 12 migration

A new \fix\_permissions.knife\ script is included in the \chef-server-ctl\ knife directory to repair object permissions after migrating from Open Source Chef Server 11. This script updates node ACLs to grant the node-specific client CRUDG permissions, correcting the permission model that differs between the legacy server and the RBAC-enabled Chef Server 12.

src/chef-server-ctl · high confidence

Added Chef Web Core UI asset library

The \src/oc-id/lib/assets/stylesheets\ directory now includes the \chef-web-core\ library, providing a complete set of SCSS stylesheets for the Chef UI. This adds a branded design system built on Foundation, including a main entry point (\chef.scss\), global settings (colors, typography, layout), and reusable components such as accordions, alerts, buttons, forms, modals, and navigation bars. It also bundles the Foundation Icons font and specific Chef SVG icon assets.

src/oc-id/lib/assets/stylesheets · high confidence

Added Chef Web Core asset pipeline configuration and stylesheets

The OC-ID application now includes the Chef Web Core asset pipeline, adding JavaScript manifests for jQuery, Turbolinks, and the 'chef' library, alongside SCSS stylesheets that import Chef's layout, theme, and animation mixins. This change establishes the foundational CSS and JS assets required for the application's UI, including support for vendor-prefixed CSS3 animations and transforms.

src/oc-id/app/assets · high confidence

Added Chef brand and platform icon assets to the OC-ID component

The OC-ID component now includes a new directory of SVG assets, providing the Chef logo and a comprehensive set of icons for Chef products (Analytics, Client, Community, Delivery, DK, Manage, Ohai, Push Jobs, Server, Supermarket) and supported platforms (CentOS, Debian, Git, GitHub, macOS, Red Hat, RubyGems, Ubuntu, Windows), as well as node type indicators (Application, Bare Metal, Container, Middleware, Network Device, Node, Platform, Private Cloud, Public Cloud).

src/oc-id/lib/assets/images · high confidence

Added Ruby binstubs for application commands

The project now includes executable binstubs in the bin directory for key tools including Rails, Rake, RSpec, Bundler, Unicorn, and Spring. These scripts facilitate running application commands by loading the correct environment and gems, with Spring integrated to speed up Rails and RSpec execution.

src/oc-id/bin · high confidence

Added Ruby dependency solver and macOS setup documentation

The \chef\_objects\ application now includes a Ruby-based dependency solver (\depselector.rb\) located in \priv/depselector\_rb\, which handles cookbook version resolution by building dependency graphs and returning solutions or specific error details (such as invalid constraints or timeouts) to the Erlang side. Additionally, a \README.md\ file has been added to this directory, providing instructions for setting up the required \gecode\ library on macOS via Homebrew to ensure the solver functions correctly.

_src/oc\_erchef/apps/chef\objects/priv · high confidence

Added Vale documentation linting rules

Added Vale configuration files to enforce Microsoft style guidelines and Chef-specific terminology in documentation. The new rules cover grammar, style, and product naming (e.g., standardizing 'Chef Infra Client' and 'Chef Automate'), ensuring consistent and accessible writing across the docs.

docs-chef-io/tools · high confidence

Added bookshelf benchmarking support via basho\_bench integration

A new benchmarking application (bookshelf\_bench) has been added to the src/bookshelf/stest/src location, enabling performance testing of the bookshelf service using basho\_bench. This component initializes a gen\_server that configures S3 connectivity (using mini\_s3 and ibrowse) and pre-generates random data objects with specific checksum sizes for testing. It exposes API functions to perform random GET and PUT operations against the configured S3 host, facilitating load and stress testing of the bookshelf storage layer.

src/bookshelf/stest/src · high confidence

Added chef-web-core library assets

The OC-ID component now includes the \chef-web-core\ library, providing core web assets and utilities. This addition introduces a Rails engine (\Chef::Web::Core::Engine\) that manages asset precompilation for various file types (images, fonts, etc.) and configures asset caching behavior for development and test environments. It also provides helper modules for generating UI components (like the Chef logo with customizable taglines) and managing URL helpers for various Chef services (account management, server, blog, docs, etc.), allowing for consistent branding and navigation across the web interface.

src/oc-id/lib/chef · high confidence

Added chef\_telemetry application scaffolding

Introduced the new chef\_telemetry application, which serves as an HTTP exporter for Chef Server node stats to external services. This change adds the initial project structure, including build configuration via rebar3 (with lager as a dependency), a Makefile for compilation and testing, and documentation.

_src/oc\_erchef/apps/chef\_telemetry, src/oc\_erchef/apps/chef\telemetry/priv · high confidence

Added error pages and static assets for oc-id, and build tooling for oc\_erchef

The oc-id application now includes standard HTTP error pages (404, 422, 500) and a robots.txt file, ensuring users see consistent messaging for common errors. Additionally, the oc\_erchef project introduces a new xcheck script for static code analysis (identifying undefined function calls and unused locals) and updates its .gitignore files to better manage build artifacts.

(repo-wide) · high confidence

Added executable test runner for Bifrost pedant tests

A new executable script (oc-bifrost-pedant) has been added to the project, allowing users to run the Bifrost pedant test suite directly without needing to manually invoke bundle exec. The script sets up the Bundler environment, configures the test suite to 'bifrost', and executes the RSpec runner.

_src/oc\bifrost/oc-bifrost-pedant/bin · high confidence

Added logo template component

A new ERB template for rendering SVG logos has been added to the application. This template dynamically wraps the provided SVG content within a specified HTML element and applies any necessary attributes, enabling consistent logo rendering across the interface.

src/oc-id/templates · high confidence

Added password reset email template

A new text-based email template for password reset requests has been added to the Chef ID application. Users will now receive an email containing a secure link to reset their password, which includes their username, email, expiration time, and a cryptographic signature to ensure the link's validity and security.

_src/oc-id/app/views/password\_reset\mailer · high confidence

Baseline PostgreSQL schema and test suite added

The \src/oc\_erchef/schema/baseline\ directory now contains the foundational Chef Server PostgreSQL schema (version 1.0.4), including tables for users, nodes, clients, roles, data bags, cookbooks, and checksums, along with their corresponding revert scripts. This baseline is managed via Sqitch and includes a comprehensive pgTAP test suite to validate table structures, constraints, and indexes, ensuring the core data model is correctly deployed and verifiable.

_src/oc\erchef/schema · high confidence

Bookshelf component initialization and dependency configuration

The Bookshelf S3-compatible object store component is introduced with its core build and configuration files. The Erlang application is configured to require OTP version 26.2.5.21 and includes dependencies such as lager, chef\_secrets, erlcloud, mini\_s3, and sqerl, with source repositories updated to use HTTPS and main branches. The release is built using rebar3 and relx, packaging the application along with supporting libraries like sync, mixer, and observer\_cli. Development and testing tooling is established via Makefiles for database provisioning and CI integration, alongside standard project files like .gitignore, LICENSE, and README.

src/bookshelf · high confidence

Bookshelf service configuration and database migration setup

This change introduces the core configuration files for the Bookshelf service within the Habitat environment. It adds a database migration script (database-migrations.sh) that handles connection setup and runs Sqitch migrations, a sys.config file defining Erlang application settings for logging (Lager/SASL), database connectivity (Sqerl), and storage, a vm.args file tuning Erlang VM performance parameters like process limits and ports, and a veil-secrets.json template for injecting secrets from bound services.

src/bookshelf/habitat/config · high confidence

Bookshelf storage backend becomes configurable with SQL support

The Bookshelf service now supports a configurable storage backend, allowing operators to choose between the existing filesystem mode and a new SQL-based mode. This change introduces SQL-specific WebMachine resources, a cleanup task for managing expired data and abandoned uploads in the database, and a configuration file containing precompiled PostgreSQL statements. The system conditionally starts the \sqerl\ database driver only when the SQL storage type is selected, and the configuration API exposes settings for storage type, disk store path, and SQL retry behavior.

src/bookshelf/src · high confidence

Expanded development environment provisioning and reporting test automation

The development scripts now support provisioning Chef Backend, OpenSearch 1.2.4, and Solr 4.10.4 alongside existing Elasticsearch and PostgreSQL setups, with PostgreSQL defaulting to version 13. A new automated reporting test suite has been added, enabling developers to validate Chef Server and Reporting installation, upgrade, and external database configurations (shared or independent) via Vagrant.

dev/scripts · high confidence

Habitat configuration for Chef Infra Server initialization and runtime

This change introduces the Habitat-specific configuration files required to bootstrap and run the Chef Infra Server. It adds a Ruby bootstrap script (\chef\_server\_data\_bootstrap.rb\) that initializes the pivotal superuser and server-admins groups in both the authorization service (Bifrost) and the database (Erchef). It includes shell scripts (\database-migrations.sh\, \elasticsearch-init.sh\) to handle database schema deployment via Sqitch and search index creation. New JSON configuration files define dark launch feature flags, OpenSearch/Elasticsearch index mappings, and secrets handling. The Erlang \sys.config\ is updated to support these components, configuring connection retry logic for the authorization service, FIPS mode support via Erlang's crypto module, and search provider settings.

_src/oc\erchef/habitat/config · high confidence

Habitat configuration templates for database, secrets, and production settings

Added Habitat-specific configuration templates for the oc-id service, including database connection settings (database.yml, database-migrations.sh), secret management (secret\_key\_base.sh, secret\_token.rb, veil-secrets.json), and production defaults (production.yml). These files enable the service to dynamically bind to Chef Server components and configure PostgreSQL connections within the Habitat environment.

src/oc-id/habitat/config · high confidence

Habitat packaging for chef-server-ctl, knife-pivotal, and oc-chef-pedant

New shell wrappers are introduced in the Habitat build to launch chef-server-ctl, knife-pivotal, and oc-chef-pedant with the correct runtime environment. These scripts configure Ruby and Gem paths, load secrets from /hab/svc/chef-server-ctl/config, and execute the respective binaries via bundle exec, enabling these tools to run correctly within the Habitat service context.

src/chef-server-ctl/habitat/bin · high confidence

Initial Habitat configuration for oc\_bifrost service

Adds the Habitat build configuration files for the oc\_bifrost service, including the Erlang sys.config, vm.args, database migration script, and secrets template. This enables the service to be packaged and deployed via Habitat, handling database connection setup, logging, and FIPS mode support.

_src/oc\bifrost/habitat/config · high confidence

Initial Habitat packaging for OpenID Connect (oc-id)

This change introduces the Habitat build plan (plan.sh) and default configuration (default.toml) for the OpenID Connect service. It configures the package to depend on Ruby 3.1.7, Node.js, and the PostgreSQL 14 client, establishing the runtime environment and dependency graph required to build and run the service within the Habitat ecosystem.

src/oc-id/habitat · high confidence

Initial Habitat packaging for OpenResty

This change introduces the Habitat build plan and configuration for the OpenResty web platform (version 1.31.1.1) within the \src/openresty-noroot\ directory. It establishes the service lifecycle through \hooks/init\ and \hooks/run\, configuring the service to run as the \hab\ user, expose port 80, and execute OpenResty in the foreground. The build process compiles OpenResty with LuaJIT support and includes the LPEG library, while \default.toml\ sets baseline performance tuning for worker processes and connections.

src/openresty-noroot · high confidence

Initial Habitat packaging for chef-server-ctl

This change introduces the Habitat build plan (plan.sh), configuration (default.toml), and runtime hooks (hooks/run) for the chef-server-ctl component. It establishes a reproducible build environment using Ruby 3.1.7 and PostgreSQL 14 client libraries, and packages specific tooling including oc-chef-pedant, the knife utility, and chef-server-ctl binaries. The configuration file provides default settings for API endpoints and Elasticsearch search servers, while the runtime hook manages FIPS mode and executes the secrets bootstrap process at startup.

_src/chef-server-ctl/habitat, src/oc\erchef/habitat · high confidence

Initial Habitat packaging for the OC Bifrost service

This change introduces the Habitat build plan and default configuration for the OC Bifrost service, an Erlang-based authentication component of Chef Server. The package is configured to depend on Erlang 26 and the PostgreSQL 14 client, and it exposes port 9463 for service communication. The default configuration sets up database connection parameters for a local PostgreSQL instance and enables log rotation, providing the necessary infrastructure to package and deploy Bifrost within a Habitat environment.

_src/oc\bifrost/habitat · high confidence

Initial Habitat service hooks for core components

This change introduces the initial Habitat lifecycle hooks (init, run, health\_check, and reconfigure) for the bookshelf, nginx, oc-id, and oc\_bifrost services. These scripts establish the runtime environment, including directory structures, SSL certificate generation for nginx, database migrations, and health check endpoints, enabling these services to be managed and deployed via Habitat.

(repo-wide) · high confidence

Initial PostgreSQL authorization schema and API documentation

The Bifrost service now includes a complete PostgreSQL authorization schema managed via Sqitch, featuring tables for actors, groups, objects, and containers, along with granular ACL tables and stored procedures for permission checks and updates. This change introduces concurrency control for ACL updates using advisory locks to prevent race conditions, and adds a recursive cycle-detection trigger to maintain valid group hierarchies. Additionally, the location now contains comprehensive documentation for the REST API, metrics collection via Graphite, and sample Erlang Web Machine code for handling authorization requests.

_src/oc\bifrost/schema · high confidence

Initial RAML 1.0 API documentation source for Chef Server

This change introduces the source files for generating Chef Server API documentation using RAML 1.0. It includes a Makefile to build HTML docs via raml2html, an index.raml entry point, and modular YAML files defining endpoints for organizations, users, ACLs, and server status/license information. The documentation structure also incorporates shared traits, resource types, and JSON schemas to standardize response formats and error handling across the API surface.

_src/oc\erchef/raml-docs · high confidence

Initial configuration structure for the oc-id Rails application

The oc-id service now includes a standard Rails configuration scaffold, establishing the application entry point, database connections (PostgreSQL), and runtime settings. This setup defines the routing for identity management features, including sign-in/sign-out flows, password resets, and profile management (email and password changes), while integrating Doorkeeper for OAuth2 authorization and configuring ActionMailer for email delivery.

src/oc-id/config · high confidence

Initial import of the Erlang depsolver library

The depsolver application has been added to the project, providing an Erlang-based dependency solver that allows users to define a graph of versioned packages and resolve valid dependency sets based on specific constraints. This change introduces the core library files, including the rebar build configuration (which depends on erlware\_commons), a Makefile for building and testing, and documentation explaining the API for adding packages and solving dependency graphs.

_src/oc\erchef/apps/depsolver · high confidence

Initial open-source release of Chef Identity (oc-id)

The Chef Identity service, an OAuth 2 provider for Chef Server, is now available as an open-source component. This release includes the core Rails application, configuration files, and a version bump to 1.0.1. It introduces support for the Resource Owner Password Credentials flow, a new endpoint to list user organizations, and configurable sign-up and forgot-password functionality. The application requires Ruby \>= 2.0, Node.js for asset compilation, and a Postgres database, and is licensed under the Apache License 2.0.

src/oc-id · high confidence

Initial project scaffolding for the Chef Index application

The chef\_index application is introduced with its core build infrastructure, including a rebar3 configuration, a Makefile for managing dependencies and code generation, and a .gitignore file. This setup establishes the foundation for the search and indexing layer, configuring it to pull the efast\_xs dependency and use neotoma for parsing, while providing standard targets for compilation, testing, and static analysis.

_src/oc\_erchef/apps/chef\index · high confidence

Initial release of oc-chef-pedant test suite

The oc-chef-pedant directory is introduced as a standalone repository for the Chef Server API test suite. This change adds the core test configuration (pedant\_config.rb), shared RSpec methods, a Rakefile for running tests against chef-zero, and supporting files like .gitignore, .rubocop.yml, and a pre-commit hook to prevent accidental inclusion of :focus tags. It establishes the foundational structure for running the pedant tests in development and CI environments.

oc-chef-pedant · high confidence

Initial release of the Pedant testing framework library

This change introduces the core library files for the Pedant testing framework, providing the infrastructure for running and configuring API tests. It includes the main Pedant module for setup and logging, a command-line parser for handling test filters (such as smoke tests, focus tags, and skip lists), and a configuration system that merges command-line arguments with file-based settings. The library also adds RSpec helpers for common test operations, including HTTP status code matchers, permission verification, and utilities for creating and cleaning up test actors and groups, alongside shared context methods for managing test state.

_src/oc\bifrost/oc-bifrost-pedant/lib · high confidence

Initial release of the oc\_bifrost authorization service

The oc\_bifrost component is introduced as the new Opscode Authorization API server, replacing the legacy opscode-authz service. This release includes the Erlang application source code, a rebar3 build configuration requiring Erlang OTP 26.2.5.21, and a Makefile to manage compilation, testing (EUnit, Dialyzer, and Pedant), and release generation. The service depends on several internal and external libraries, including chef\_secrets, sqerl, lager, and opscoderl\_wm, and is licensed under Apache 2.0.

_src/oc\bifrost · high confidence

Initial setup of Chef Infra Server documentation build infrastructure

This change introduces the foundational build and configuration files for the Chef Infra Server documentation site. It adds a Makefile to manage local development (serving via Hugo) and Netlify preview deployments, along with a netlify.toml to define build contexts and commands. Configuration includes a .gitignore for generated resources, a config.toml pointing to the source repository, and a placeholder main.go to support Hugo modules. Additionally, it establishes automated quality checks by adding .markdownlint.yaml and .vale.ini for linting and style validation, and a README.md to guide contributors on the documentation workflow.

docs-chef-io · high confidence

Introduce Data Collector application for exporting Chef Server actions

Adds the new data\_collector Erlang application to the oc\_erchef suite, which functions as an HTTP exporter for Chef Server actions to external services. The addition includes the application structure (Makefile, rebar.config, README) and configures dependencies on lager, opscoderl\_httpc, and pooler to facilitate this functionality.

_src/oc\_erchef/apps/data\collector · high confidence

Introduce Data Collector application for sending telemetry to Chef

This change adds the \data\_collector\ Erlang application to the \oc\_erchef\ suite. It introduces a new service that collects and sends operational data to a configured remote endpoint. The application retrieves an authentication token from \chef\_secrets\ and automatically injects it into HTTP requests via the \x-data-collector-token\ header. It includes an HTTP client wrapper (\data\_collector\_http\) for performing GET, POST, and DELETE operations, and a supervision tree that conditionally starts an HTTP connection pool only if the collector is enabled via configuration.

_src/oc\_erchef/apps/data\collector/src · high confidence

Introduces Habitat packaging for Chef Server NGINX

Adds a new Habitat plan (plan.sh) and configuration (default.toml) for the Chef Server NGINX component, enabling it to be built and run as a Habitat package. The configuration sets default ports (8080 for HTTP, 8443 for HTTPS), enforces TLSv1.2 with specific cipher suites, and configures access logging to support both Dockerized and non-Dockerized environments. The plan defines dependencies on core/curl, core/libossp-uuid, and openresty-noroot, and exposes ports and optional binds for integration with other Chef Server services like Bookshelf, oc\_erchef, and elasticsearch.

src/nginx/habitat · high confidence

Introduction of Chef Telemetry application

A new \chef\_telemetry\ application has been added to the Chef Server codebase. This component introduces a background worker process that collects usage metrics—such as node counts, active nodes, and FQDNs—and periodically sends them to a reporting endpoint (defaulting to \https://services.chef.io/usage/v1/payload\). The feature is controlled by a configuration flag (\chef\_telemetry.is\_enabled\) and includes a supervisor and gen\_server implementation to manage the periodic data collection and transmission lifecycle.

_src/oc\_erchef/apps/chef\telemetry/src · high confidence

Introduction of core application helper modules

This change introduces four new helper modules in the application to standardize UI and session management. The ApplicationHelper provides utilities for rendering error messages, mapping flash types to CSS classes, and generating delete confirmation buttons. The SessionsHelper implements user authentication logic, including signing in, signing out, and managing the current user session. The FeatureFlagHelper exposes a check for OneTrust availability, while the ZendesksHelper provides functionality to generate Zendesk SSO URLs when the service is enabled.

src/oc-id/app/helpers · high confidence

Introduction of the depsolver package constraint solver

A new dependency constraint solver application has been added to the system. This component allows users to define a set of packages with their versions and dependencies, and then resolve valid dependency graphs based on specified constraints (such as exact versions, greater-than-or-equal, or range constraints). It provides APIs to add packages, filter them against constraints, and solve for a consistent set of dependencies.

_src/oc\erchef/apps/depsolver/src · high confidence

Introduction of the self-contained DVM development environment

A new self-contained development environment (DVM) is introduced in the \dev\ directory, allowing developers to run Chef Server components in a Vagrant VM while editing code on the host. This setup includes a Vagrantfile that provisions a Ubuntu 24.04 base box, supports external services like PostgreSQL, LDAP, and Elasticsearch, and enables hot-reloading for Erlang projects (e.g., \oc\_erchef\) and Rails projects (e.g., \oc-id\). It also provides configuration files (\defaults.yml\, \config.yml.example\) to manage plugins, VM resources, and node attributes, along with tooling (\dvm.mk\, \dvm/parse.es\) for building and loading dependencies.

dev · high confidence

New API endpoints for policies, policy groups, keys, and validation

The Chef Server now exposes several new API capabilities via the updated dispatch configuration. Users can manage policies and policy groups through new endpoints for listing, creating, and retrieving named policies and revisions. Access control lists (ACLs) are now supported for policies, policy groups, and cookbook artifacts. Additionally, new endpoints allow users to manage client and user keys, including organization-scoped key retrieval, and a new validation endpoint is available for validating organization data. The server also exposes a universe endpoint for cookbook visibility and basic stats/status endpoints.

_src/oc\_erchef/apps/oc\_chef\wm/priv · high confidence

New Buildkite test environment setup scripts

Added new scripts to configure the test environment for Buildkite CI, including \bk\_install.sh\ which sets up dependencies like PostgreSQL 13, Erlang 26.2, and Ruby tools, while fixing repository issues by switching to PostgreSQL archives and removing the Microsoft apt mirror. Also added \chef\_zero-Gemfile\ to manage Ruby dependencies for chef-zero testing and \pb\_hba.conf\ to configure PostgreSQL for password-less local connections during tests.

_scripts/bk\tests · high confidence

New DVM CLI application and project management infrastructure

The development VM (DVM) tooling now includes a structured CLI application (\dev/dvm/lib/dvm/application.rb\) built on Thor, allowing users to manage development projects (Omnibus, Erlang, Ruby, Rails) via commands like \load\, \unload\, \start\, \stop\, and \console\. This change introduces a new project abstraction layer (\dev/dvm/lib/dvm/project.rb\) that delegates behavior to specific project types, and adds a \Populator\ class (\dev/dvm/lib/dvm/populate.rb\) to automatically create organizations and users defined in configuration files. Supporting utilities in \tools.rb\ handle system interactions such as bind mounting directories, cloning repositories, and checking out specific git refs, providing a more robust and modular foundation for the local development environment.

dev/dvm/lib/dvm · high confidence

New Erlang Common Test harness for Chef Server

The \chef\_test\ application has been introduced to provide a reusable Common Test (CT) harness for the Erlang-based components of Chef Server. This new library includes helper modules (\chef\_test\_db\_helper\, \chef\_test\_suite\_helper\) that automate the setup and teardown of PostgreSQL databases for integration tests, manage application environment configurations, and provide utilities for creating test data (such as organizations and records). It also includes a Makefile and documentation to standardize how developers run and view Common Test outputs within the \oc\_erchef\ project.

_src/oc\_erchef/apps/chef\test · high confidence

New Erlang development utilities for debugging and hot-reloading

Added two new Erlang source files to the development environment: \b2f\, a Beam-to-Function decompiler that extracts and pretty-prints abstract code from BEAM files, and \user\_default\, a shell module providing hot-reload capabilities (\um/1\) for in-place module updates during development, along with functions to enable, report, and disable code coverage analysis.

dev/cookbooks/dev/files · high confidence

New User and Signature models for authentication and password management

This change introduces the \User\ and \Signature\ models in the \src/oc-id/app/models\ directory. The \User\ model provides core functionality for user authentication, password updates, and profile management, including support for finding users by email or username and verifying signed requests via Mixlib::Authentication. The \Signature\ model manages password reset tokens, utilizing OpenSSL::Digest::SHA1 for secure hashing to ensure FIPS compliance. These models enable the backend logic for user registration, login, and password reset flows.

src/oc-id/app/models · high confidence

New administrative escripts for granular reindexing operations

Two new executable scripts have been added to the server's private utilities to give administrators more control over search index maintenance. The \reindex-opc-organization\ script allows for organization-level reindexing with explicit \drop\, \reindex\, or \complete\ actions, providing detailed error reporting for failed objects. The \reindex-opc-piecewise\ script enables targeted reindexing of specific indices (nodes, roles, environments, clients, or data bags) within an organization, supporting both name-based and ID-based item selection via the \--ids\ flag. These tools replace hardcoded assumptions with dynamic API version detection and improved SSL handling for internal RPC calls.

_src/oc\erchef/priv · high confidence

New authorization API service (Bifrost) with recursive group membership checks

This change introduces the Bifrost authorization service, replacing the previous authz implementation. It provides a new REST API for managing actors, groups, objects, and containers, including creating entities, managing ACLs, and checking permissions. A key new capability is the GET /groups/:group/transitive\_member/actors/:actor endpoint, which allows checking if an actor is a recursive member of a group. The service uses PostgreSQL for storage and integrates with chef\_secrets for superuser configuration. It also includes a bulk permission check endpoint and supports SSL configuration.

_src/oc\bifrost/apps/bifrost/src · high confidence

New chef\_license OTP application for local license enforcement

This change introduces the \chef\_license\ OTP application, which implements local license checking and enforcement. The application includes a worker that periodically scans for license status (defaulting to CLI-based checks via \chef-automate license status\, with support for file-based paths via the \OC\_LICENSE\_PATH\ build-time option) and exposes the current license state (type, expiration, grace period, customer name) through a public API. It also includes EUnit tests covering valid, expired, and grace-period license scenarios.

_src/oc\_erchef/apps/chef\license · high confidence

New development VM provisioning recipes for test data, knife access, and user environment

The development environment now includes new Chef recipes to automate the setup of a self-contained dev VM. The \create-test-data\ recipe provisions a test organization ('clownville') and an admin user ('bobo') with their respective key files. The \setup-knife\ recipe configures knife access for both the root user inside the VM and the vagrant user on the host, ensuring SSL certificates and keys are synchronized. The \user-env\ recipe sets up the user environment, including SSH configuration, Erlang console helpers, and the ability to load external dotfiles from a \/dotfiles\ directory. Additionally, \system.rb\ handles system-level configurations like timezone, SSH host keys, and MOTD, while \dvm.rb\ links the DVM tool and autoloads omnibus components before the first reconfigure.

dev/cookbooks/dev/recipes · high confidence

New documentation for ACLs, containers, groups, and migration plans

Added comprehensive documentation for the Erlang-based authorization and data management components. This includes API reference guides for Access Control Lists (ACLs), containers, and groups, detailing their endpoints, authentication, and behavior. Additionally, the release includes migration planning documents outlining the transition from CouchDB to PostgreSQL, the deployment strategy for the OpenResty load balancer, and reverse-engineering notes on the legacy opscode-account schema.

_src/oc\erchef/doc · high confidence

Users attempting to change the email address on their Chef account will now receive a verification email containing a secure link. This link includes a signed, time-expired token to confirm the new email address, ensuring that only the account owner can complete the update.

_src/oc-id/app/views/email\_verify\mailer · high confidence

New health check endpoint and user profile API

A new health check endpoint is now available at the V1 API level, allowing users to monitor the status of the oc-id service by checking key metrics and receiving a clear OK or service unavailable response. Additionally, the V1 API now exposes user profile information through a new UsersController, which supports retrieving public user details, the current user's profile via the 'me' endpoint, and the user's associated organizations, all secured using Doorkeeper authorization where appropriate.

src/oc-id/app/controllers/v1 · high confidence

New helper modules for disk space checks and key management in chef-server-ctl

The chef-server-ctl tool now includes new helper libraries to support disk space validation and key operations. A new \du.rb\ helper wraps the \du\ command to calculate directory usage, and a \statfs.rb\ helper uses FFI to call \statvfs\ for checking free disk space and inodes, enabling warnings when insufficient disk space is detected for operations like Elasticsearch reindexing. Additionally, a \key\_ctl\_helper.rb\ module provides utilities for validating public keys, parsing command-line arguments, and managing client/user key objects with expiration dates.

_src/chef-server-ctl/lib/chef\_server\ctl/helpers · high confidence

New internal Erlang headers for API versioning, search providers, and data models

The server now includes a set of new internal Erlang header files that define core data structures and configuration constants. \server\_api\_version.hrl\ establishes API versions 0 through 2, with v2 deprecating cookbook segments. \chef\_solr.hrl\ updates the search query record to support \elasticsearch\ and \opensearch\ providers alongside the existing \solr\ backend. \chef\_types.hrl\ and \oc\_chef\_types.hrl\ introduce records for policy management (policies, policy groups, and revisions) and cookbook artifacts, while \chef\_regex.hrl\ adds validation patterns for policy file names and user name components. These headers provide the type definitions and records required for the new policy, artifact, and multi-provider search capabilities.

_src/oc\erchef/include · high confidence

New object model and caching infrastructure in chef\_objects

This change introduces a comprehensive set of new Erlang modules in the chef\_objects application to handle Chef data structures and operations. It adds object definitions for clients, cookbook versions, data bags, and data bag items, along with supporting utilities for database compression, dependency solving (via a Ruby worker), deep merging, and HTTP certificate generation. Additionally, it implements a new gen\_server-based cache (chef\_cbv\_cache) for cookbook version results, featuring claim-based concurrency control and queue-length load shedding to improve performance under high load.

_src/oc\_erchef/apps/chef\objects/src · high confidence

New profile management interface with password and key controls

The profile view now includes dedicated sections for updating personal details, changing passwords, and regenerating private keys. Users can edit their first, middle, and last name, as well as their email address, via a new profile form. Additionally, a password change form allows users to update their credentials, and a key generation section enables users to download a new private key, with a warning that the old key will cease to function upon regeneration.

src/oc-id/app/views/profiles · high confidence

New reindexing and web resource modules in oc\_chef\_wm

The oc\_chef\_wm application introduces several new Erlang modules to support reindexing operations and standardize web resource handling. The new chef\_reindex module provides functionality to batch-reindex organization data (nodes, roles, environments, clients, and data bags) to Solr, including helpers for name-to-ID mapping and batch processing. Additionally, a suite of new webmachine resource modules (chef\_wm, chef\_wm\_clients, chef\_wm\_cookbook\_version, chef\_wm\_cookbooks, chef\_wm\_data, chef\_wm\_depsolver, chef\_wm\_enforce, chef\_wm\_environment\_cookbooks) implements REST endpoints for managing clients, cookbooks, data bags, dependency resolution, and environment-cookbook relationships, while enforcing request size limits and authentication constraints.

_src/oc\_erchef/apps/oc\_chef\wm/src · high confidence

New utility scripts for component import, disk analysis, and file validation

Added three new scripts to the repository: \scripts/import-components.sh\ automates the one-time import of external component repositories (such as bookshelf, oc-id, and erchef) into the chef-server codebase; \scripts/space\_analyzer.rb\ provides a Ruby-based tool to analyze and report disk space usage by directory size; and \scripts/filetype-check.sh\ validates that files do not contain non-ASCII UTF-8 characters, failing the build if such content is detected.

scripts · high confidence

Search index now supports Elasticsearch and OpenSearch alongside Solr

The search index layer has been extended to support Elasticsearch and OpenSearch in addition to the existing Solr backend. Users can now configure the search provider via the \search\_provider\ setting (solr, elasticsearch, or opensearch). The system uses a unified HTTP client (\chef\_index\_http\) for all search interactions, and the batch indexing worker (\chef\_index\_batch\) and document expansion logic (\chef\_index\_expand\) have been updated to handle the specific JSON formats and API requirements of Elasticsearch and OpenSearch, including version-aware handling for delete operations and field tags. Prometheus metrics have been added to track performance for all supported search providers.

_src/oc\_erchef/apps/chef\index/src · high confidence

Removals

Removal of the Opscode Expander module

The \lib/opscode/expander\ module and its associated components (consumer, loggable, version) have been completely removed from the codebase. This deletion eliminates the previous implementation that relied on AMQP, EventMachine, and Chef's Solr indexing libraries to process and index data, effectively stripping out this specific indexing and queue-consumption capability.

lib/opscode · high confidence

Removal of the opscode-expander binary

The \bin/opscode-expander\ executable script has been removed from the project. This file previously served as the entry point for the Opscode Expander application, handling Ruby environment setup, bundler initialization, and the invocation of the consumer component.

bin · high confidence

Behavioural changes

Add Rails environment configuration files for development, production, and test

The application now includes explicit configuration files for its three primary environments (development, production, and test). These files define how the Rails application behaves in each context, including settings for code reloading, asset compilation and caching, error reporting, and email delivery methods. For instance, development mode is configured for debuggability with code reloading and local SMTP, production mode enables eager loading and asset compression, and test mode isolates email delivery and disables forgery protection.

src/oc-id/config/environments · high confidence

Add running\_configs suite to oc-chef-pedant runner

The oc-chef-pedant executable now includes the 'running\_configs' test suite alongside the existing 'api' suite, allowing users to execute both sets of tests by running the single binary without needing to specify 'bundle exec'.

oc-chef-pedant/bin · high confidence

Centralized authorization SQL statements in pgsql\_statements.config

The authorization SQL queries for the Chef Authz service have been consolidated into a new configuration file, pgsql\_statements.config. This change moves the raw SQL statements for managing users, organizations, containers, groups, policies, and policy revisions out of application code and into a centralized, declarative format. This allows for easier maintenance and auditing of the database interactions used for access control decisions.

_src/oc\_erchef/apps/oc\_chef\authz/priv · high confidence

Configurable OneTrust integration via environment variable

The application now loads the OneTrust consent management SDK using the value of the ONETRUST\_ID environment variable instead of a hardcoded key. This partial view ensures the script is only included when OneTrust is enabled and the ID is present, allowing operators to configure the integration without code changes.

src/oc-id/app/views/application · high confidence

DVM library structure reorganization

The DVM library has been restructured to improve modularity and maintainability. The main entry point now explicitly requires separate modules for tools, project handling, application logic, and data population, replacing the previous monolithic structure. This change also introduces a custom DVMArgumentError class for better error handling within the DVM context.

dev/dvm/lib · high confidence

DVM project loading refactored into modular, language-specific classes

The DVM (Dev VM) project loading mechanism has been restructured from a monolithic implementation into distinct, modular classes for Erlang, Rails, Ruby, and Omnibus projects. This change introduces a base \Project\ class and specific subclasses (\ErlangProject\, \RailsProject\, \RubyProject\, \OmnibusProject\) along with corresponding dependency classes (\ErlangDep\, \OmnibusDep\). For users, this means the development environment now handles different project types with specialized logic: Erlang projects use \rebar3\ and \relx\ for builds and symlinks, Rails projects manage \bundle install\ and server processes, Ruby projects support system-level gem mounting, and Omnibus projects handle component-specific loading. The refactoring also improves dependency management by allowing granular loading and unloading of sub-projects and dependencies, and ensures file descriptors are preserved during execution.

dev/dvm/lib/dvm/project · high confidence

DVM script now provides user-friendly error handling for argument errors

The dev/dvm/bin/dvm script has been updated to catch DVM::DVMArgumentError exceptions and display the error message in red using HighLine, rather than allowing the exception to propagate as a raw stack trace. This change improves the user experience by presenting clear, colored feedback when invalid arguments are passed to the tool.

dev/dvm/bin · high confidence

Database abstraction layer refactored into the chef\_db application

The database access logic has been reorganized into a dedicated \chef\_db\ application, introducing a new \chef\_db.app.src\ manifest that declares dependencies on \stats\_hero\, \chef\_secrets\, and \sqerl\. This change replaces the previous CouchDB-based implementation with a PostgreSQL backend via \sqerl\, as evidenced by the new \chef\_sql\ module and \chef\_pgsql\_collector\ for Prometheus metrics. The refactoring also introduces a dark-launch mechanism (\chef\_db\_darklaunch\) to toggle features and updates the API to support policy groups and revisions.

_src/oc\_erchef/apps/chef\db/src · high confidence

Enhanced external PostgreSQL status and cleanse operations

The chef-server-ctl utility now provides detailed status reporting and data cleansing capabilities for external PostgreSQL databases. Users can check the health of an external PostgreSQL instance, including connection status, active connections, and lock information, via the status command. Additionally, the cleanse command now supports removing databases and roles from an external PostgreSQL server, generating a manual cleanup SQL script if automatic deletion is not performed or fails.

src/chef-server-ctl/bin · high confidence

Habitat secrets management and configuration templates for chef-server-ctl

The chef-server-ctl Habitat package now includes a comprehensive set of configuration templates and a secrets bootstrap mechanism. New files such as \secrets-bootstrap.rb\ automatically generate and apply required secrets (including RSA keypairs for the superuser and web UI, and passwords for PostgreSQL, Redis, and other services) when they are missing, ensuring secure initialization. Template files like \pedant\_config.rb\, \pivotal.rb\, and \hab-secrets-config.json\/\.toml\ parameterize service endpoints and credentials using Habitat bindings and configuration variables, allowing the control service to dynamically connect to the Chef Server API and manage test environments without hardcoded values.

src/chef-server-ctl/habitat/config · high confidence

Habitat-native Nginx configuration and Lua routing layer

The Nginx configuration for Chef Server has been rewritten to support Habitat packaging. This introduces a new set of configuration files (nginx.conf, chef\_http\_lb.conf, chef\_https\_lb.conf) and Lua scripts (config.lua, dispatch.lua, routes.lua, resolver.lua, route\_checks.lua, validator.lua) that handle request routing, upstream resolution, and access control. The configuration now uses Habitat templating to dynamically bind to upstream services (oc\_erchef, bookshelf, oc\_id, elasticsearch) and supports SSL termination, data collector integration, and compliance endpoint forwarding. Notably, dark launch and maintenance mode features are stubbed out for the Habitat environment, defaulting to safe states (e.g., no dark launch, no maintenance mode).

src/nginx/habitat/config · high confidence

Introduce Sqitch-based schema management for Bookshelf

The Bookshelf service now uses Sqitch to manage its PostgreSQL schema, replacing ad-hoc deployment with a versioned, reversible migration system. This change introduces the base schema (buckets, files, file\_data, file\_chunks) and smart-delete logic (tombstoning, purging, and cleanup functions) as deployable units. Administrators must now use Partybus migrations to apply schema upgrades via the run\_sqitch utility, ensuring consistent and safe schema evolution during Chef Server upgrades.

src/bookshelf/schema · high confidence

Introduce centralized Erlang configuration for erchef

The erchef service now uses a new centralized configuration structure consisting of app.config and vars.config files. This change consolidates settings for core components including the REST API, database connections (PostgreSQL), search engine integration, and logging, replacing previous ad-hoc or distributed configuration methods with a unified Erlang-based approach.

_src/oc\erchef/config · high confidence

Introduce configurable chef-server-ctl with environment variable overrides

The chef-server-ctl tool now supports a new global configuration module that allows key settings—such as the load balancer URL, database connection URIs, and paths for knife and reindex scripts—to be overridden via environment variables (e.g., CSC\_LB\_URL, CSC\_BIFROST\_DB\_URI). This change enables easier integration with wrapper scripts, particularly for Habitat-packaged versions, and fixes connection URI formatting issues that previously caused 'bad URI' errors in external Azure PostgreSQL setups. Additionally, the tool now supports mutual TLS for server admin commands when running in Habitat mode.

_src/chef-server-ctl/lib/chef\_server\ctl · high confidence

Introduction of Chef Web Core JavaScript library

The OC-ID component now includes a new JavaScript library (chef-web-core) that provides a modular framework for UI components. This library initializes core utilities and specific modules for rendering SVG icons, managing logo animations, and handling top-bar navigation interactions, replacing the previous foundation-rails dependency with this custom implementation.

src/oc-id/lib/assets/javascripts · high confidence

Major overhaul of chef-server-ctl plugin commands and structure

The chef-server-ctl command-line interface has been significantly restructured and expanded. The plugin files have been moved to the src/chef-server-ctl/plugins directory, and many commands have been rewritten or replaced. New commands include check-config for preflight configuration checks, filtered-dump for exporting sanitized indexable objects, and maintenance mode controls with IP allowlisting. The backup and restore commands have been updated with new options like --config-only and --staging-dir. Key management commands (add-client-key, add-user-key, list-client-keys) now support expiration dates and public key paths. The high-availability (ha) plugin has been removed, with commands now displaying deprecation warnings pointing to Chef Backend. Additionally, the notice command now displays updated license information for Progress Software Corporation and its third-party components.

src/chef-server-ctl/plugins · high confidence

Migrate Chef Server CI/CD to Buildkite and Expeditor

The project has replaced its previous CI infrastructure with a new Buildkite-based pipeline orchestrated by Expeditor. This change introduces a comprehensive configuration (\.expeditor/config.yml\) that defines workflows for verification, Habitat package building, and Omnibus releases. It includes specific scripts for building and testing components like \oc\_erchef\, \chef-server-ctl\, and \bookshelf\, as well as integration tests for Chef Server, HA configurations, and Automate scenarios. The release process now generates and uploads manifests and license scout reports to S3, promotes Habitat packages to channels such as \LTS-2024\, and purges Fastly caches upon promotion.

.expeditor · high confidence

New development environment configuration templates for Chef Server

The development environment now includes new template files that configure the Vagrant-based dev VM. These templates set up Knife client credentials (node/client name 'bobo'), define the Chef Server API URL, and configure environment variables for the embedded Omnibus environment. A new message of the day (motd) provides quick-start instructions for using the dvm tool to load and run projects like oc\_erchef and oc-chef-pedant, and the sudoers configuration is updated to allow passwordless sudo for the vagrant user and preserve necessary environment variables.

dev/cookbooks/dev/templates · high confidence

New internal record and type definitions for object storage and access control

This change introduces new Erlang header files that define the core data structures and types for the bookshelf and Bifrost components. Specifically, it adds records for \object\ and \bucket\ in the bookshelf module, and defines types for authentication IDs, permissions, and request states in Bifrost. It also establishes a \base\_state\ record for Web Machine resources, enabling consistent handling of access control lists (ACLs) and group resources across the API.

_src/bookshelf/include, src/oc\bifrost/apps/bifrost/include · high confidence

Password reset flow now accepts usernames in addition to email addresses

The password reset interface has been updated to allow users to initiate a reset using either their username or their email address, rather than requiring an email address alone. This change is implemented in the new password reset views (new.html.erb and show.html.erb) and the sign-in form, which now includes a link to the password reset page and supports username-based identification.

_src/oc-id/app/views/password\resets · high confidence

Pedant test framework refactored into modular library components

The oc-chef-pedant test runner has been restructured from a monolithic script into a modular Ruby library. This change introduces dedicated modules for command-line argument parsing (CommandLine), configuration management (Config), and HTTP request handling (Request), alongside new utilities for generating knife.rb files and managing user credentials (ChefUtility, Requestor). The refactoring also adds support for configurable SSL/TLS versions, RSpec seed values for deterministic test ordering, and explicit retry logic for network timeouts, improving the stability and configurability of the test environment.

oc-chef-pedant/lib/pedant · high confidence

Pedant test suite adds Hash extension and custom Net::HTTP implementation for IPv6 support

The oc-chef-pedant test suite now includes a new Hash core extension providing \with\, \with!\, \except\, and \except!\ methods for easier hash manipulation. Additionally, a custom Net::HTTP core extension is introduced to handle SSL connections with proper IPv6 literal support in the Host header, ensuring the test suite functions correctly when connecting to HTTPS endpoints using IPv6 addresses.

_oc-chef-pedant/lib/pedant/core\ext · high confidence

Profile email updates now require verification and Zendesk SSO is restricted for specific domains

Users updating their email address in their profile will now receive a verification email containing a link to confirm the change, rather than having the email updated immediately. This prevents unauthorized email changes and ensures the user controls the new address. Additionally, users with @chef.io or @progress.com email addresses are now blocked from using ZenDesk Single Sign-On (SSO), receiving a forbidden error if they attempt to access it.

src/oc-id/app/controllers · high confidence

Refactor Chef API integration and add health check and Zendesk SSO support

The oc-id service now uses the Chef v0 API via Chef::ServerAPI for all server interactions, replacing the previous Chef::REST implementation. A new health check mechanism has been introduced to monitor the reachability and status of the Chef server (erchef) and the PostgreSQL database, reporting specific states like timeout or authentication errors. Additionally, support for Zendesk Single Sign-On (SSO) has been added, allowing users to be redirected to Zendesk using a signed JWT token.

src/oc-id/lib · high confidence

Refactor Pedant test runner to use RSpec shared configuration

The oc-chef-pedant test runner has been restructured to integrate the rspec-shared library for managing RSpec configuration. The main pedant.rb entry point now loads the rspec-shared gem and delegates configuration extension to it, while rspec-shared.rb explicitly requires the core library and its methods. This change modifies how the test suite initializes its configuration and syntax settings, moving some setup logic into the shared extension module.

oc-chef-pedant/lib · medium confidence

Refactor and modernize pedant RSpec test utilities

The test suite's shared contexts and utilities in \oc-chef-pedant/lib/pedant/rspec\ have been restructured to support modern Chef Server capabilities. This includes adding support for the v1.3 signing protocol (using SHA-256 digests) in \auth\_headers\_util.rb\, introducing helpers for managing test data (clients, data bags, environments, nodes, roles) in \chef\_data.rb\, and updating client and cookbook utilities to handle the new \chef\_key\ response structure introduced in API version 1.0+. Additionally, generic HTTP response matchers in \common\_responses.rb\ and \http\_status\_codes.rb\ have been standardized to improve test consistency and readability.

oc-chef-pedant/lib/pedant/rspec · high confidence

Resolves Erlang SSL memory leak and fixes SIGTERM handling

The oc\_erchef application now bypasses a memory leak in Erlang's ssl\_session\_cache by introducing a noop session cache module that prevents session reuse. Additionally, the application startup process has been updated to revert SIGTERM signal handling to default behavior, resolving runit failures caused by changes in Erlang 19.3.x.

_src/oc\erchef/src · high confidence

Restructured development environment into a Chef cookbook

The development environment setup has been reorganized from a Rakefile into a dedicated Chef cookbook located at dev/cookbooks/dev. This change introduces a new metadata file defining the 'dev' cookbook (version 0.0.1) for development environment setup and moves the previous Rakefile content into the cookbook's attributes/default.rb, establishing a self-contained structure for configuring the local development environment.

dev/cookbooks/dev, dev/cookbooks/dev/attributes · medium confidence

Updated OAuth application management and authorization views

The OAuth application management interface and authorization flows have been updated with new view templates. Users can now create, edit, and view OAuth applications, with the application form explicitly guiding them to use one line per URI and providing the native redirect URI for local testing. The authorization screen now clearly lists the specific scopes (permissions) the application is requesting before the user grants access. Additionally, the authorized applications list now displays the creation timestamp for each granted permission, and error pages for 404 and 500 errors have been standardized.

src/oc-id/app/views/doorkeeper · high confidence

Updated OAuth database schema for Doorkeeper 2.x compatibility

The database schema for the Open Code Institute's OAuth provider has been updated to support the Doorkeeper 2.x gem. This change introduces new migration files and regenerates the schema definition, adding a 'confidential' boolean column to the 'oauth\_applications' table (defaulting to true) and changing the 'resource\_owner\_id' column type from integer to string in the 'oauth\_access\_grants' and 'oauth\_access\_tokens' tables. These structural adjustments ensure the database structure aligns with the requirements of the upgraded OAuth library.

src/oc-id/db · high confidence

Updated database query definitions and added stats endpoint

The database query configuration in \pgsql\_statements.config\ has been updated to support new functionality and performance improvements. A new stats endpoint is now available, exposing database performance metrics such as table scans, tuple counts, and active connections. The node management queries have been modified to include \policy\_name\ and \policy\_group\ columns in insert and update operations, reflecting changes to the node schema. Additionally, a specific query \count\_nodes\ has been added to support license checks by counting nodes across organizations. The bulk fetch query for nodes has been optimized to return only the serialized object data, reducing the amount of data transferred.

_src/oc\_erchef/apps/chef\db/priv · high confidence

oc-id configuration restructured for Rails 7 and Veil secrets

The oc-id application initializer files have been regenerated to align with the Rails 7.0.4 upgrade, introducing standard configuration for assets (including precompilation of chef-web-core.js), JSON parameter wrapping, and secret key management via the Settings object. Session storage is now explicitly configured as a secure cookie store. Additionally, a new secrets initializer integrates the Veil library to retrieve credentials using the 'chef-secrets-env' or 'chef-secrets-fd' providers, replacing previous mechanisms, while the Doorkeeper OAuth initializer is updated to enforce specific grant flows (authorization\_code, implicit) and authentication logic.

src/oc-id/config/initializers · high confidence

oc\_bifrost configuration updated to use chef\_secrets and explicit runtime settings

The oc\_bifrost service configuration has been updated to source secrets (such as the SQL password) from a dedicated secrets.json file via the chef\_secrets provider, replacing previous default or hardcoded credential handling. Additionally, the sys.config and vm.args files now explicitly define runtime parameters including the node name, distributed Erlang cookie, logging behavior, database connection details, and performance tuning options, ensuring consistent and secure configuration for the service.

_src/oc\bifrost/config · high confidence

Fixes

Added placeholder file to data\_collector priv directory

A .gitkeep file was added to the src/oc\_erchef/apps/data\_collector/priv directory to ensure the directory is tracked in version control. This change supports the project's eunit test infrastructure by maintaining the directory structure required for test execution.

_src/oc\_erchef/apps/data\collector/priv · low confidence

Test coverage

Add integration tests for the authorization service; Added API client tests for ACLs, groups, and creation workflows; Added API endpoint tests for data bags and roles; Added API integration tests for cookbook artifact CRUD operations; Added API integration tests for knife commands; Added API integration tests for the Cookbooks endpoint; Added API key tests for users and clients; Added API tests for nodes endpoint validation and HTTP methods; Added API tests for sandbox creation and validation; Added API v1 behavior tests for user and client key validation; Added Bifrost API integration tests; Added EUnit tests for the data collector application; Added automeck configuration files for authz tests; Added comprehensive API tests for Policies and Policy Groups endpoints; Added controller and helper specs for identity management features; Added dependency solver test harness and benchmark results; Added integration tests for chef\_db SQL operations; Added maxfile.json fixture for request size testing; Added model tests for User authentication and password updates; Added request specs for the sign-in flow; Added search API validation tests for node policyfile attributes and special character handling; Added shared test context for requestor scenarios; Added test coverage for chef-server-ctl commands; Added test coverage for chef\_objects module; Added test infrastructure and routing specs for OC-ID; Added test suite and fixtures for Bookshelf API and security functions; Added test suite for chef\_index components; Added tests for health check and Zendesk SSO URL generation; Added tests for the email verification mailer; Added unit tests for chef\_db and chefp modules; Added unit tests for dependency version filtering; Added unit tests for oc\_chef\_wm request handling and status checks; Added unit tests for the oc\_chef\_authz authorization module; Added unit tests for the telemetry worker; Added validation tests for Chef Server running configuration; Expanded API test coverage for authentication, authorization, and environment management; Expanded test coverage for account API endpoints; New integration tests for oc\_chef\_wm endpoints.

Dependencies

Introduce dependency floors and lockfiles for oc-chef-pedant, chef-server-ctl, and oc-id

This change adds explicit Gemfile, Gemfile.lock, and gemspec files for the oc-chef-pedant, chef-server-ctl, and oc-id components, establishing a single source of truth for their dependencies. It enforces minimum safe versions for rack, rexml, and net-imap by sourcing floors from the omnibus-config safe\_versions.rb, ensuring bundle install fails loudly if vulnerable versions are resolved. It also pins concurrent-ruby to \>= 1.3.8 to address Dependabot alerts, updates oc-id to Rails 7.2.3.1 and JWT to \>= 3.2.0 to fix CVEs, and pins public\_suffix \< 7.0 for Ruby 3.1 compatibility.

(dependencies) · high confidence

oc\_erchef project structure and dependency configuration

The oc\_erchef Erlang project has been restructured with a new top-level rebar.config that mandates Erlang OTP 26.2.5.21 and defines its dependency graph, including chef\_authn, chef\_secrets, sqerl, and opscoderl\_httpc. The release configuration (relx) now excludes the Erlang runtime system (ERTS) and source code from the final package. Supporting files include a Makefile for build and test automation, a Gemfile\_habitat specifying Ruby dependencies (rest-client 2.1.0, pg 1.5.9), and a .edts file for Erlang development tooling.

_src/oc\erchef · high confidence

Housekeeping

Consolidation of developer documentation into dev-docs directory; Version bump to 14.0.83.

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 48 → 63 (+15.2)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 68 → 67 (-1.4)
  • Architecture 100 → 98 (-1.7)
  • Maturity 80 → 73 (-7.1)
  • Readiness 41 → 73 (+31.9)
  • Security 40 → 69 (+28.3)
  • Event Sourcing 100 → 100 (+0.0)
  • Accessibility 52 → 54 (+1.8)

Resolved (33)

  • Coverage not included — suite not readable by the collector
  • Critical CVE: [GHSA redacted] (src/chef-server-ctl/Gemfile.lock)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High CVE: [GHSA redacted] (src/chef-server-ctl/Gemfile.lock)
  • High CVE: [GHSA redacted] (src/chef-server-ctl/Gemfile.lock)
  • High CVE: [GHSA redacted] (oc-chef-pedant/Gemfile.lock)
  • High CVE: [GHSA redacted] (src/oc_bifrost/oc-bifrost-pedant/Gemfile.lock)
  • High vulnerability: [GHSA redacted] (src/chef-server-ctl/Gemfile.lock)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Low CVE: [GHSA redacted] (src/chef-server-ctl/Gemfile.lock)
  • Low CVE: [GHSA redacted] (src/chef-server-ctl/Gemfile.lock)
  • Low CVE: [GHSA redacted] (src/chef-server-ctl/Gemfile.lock)
  • Medium CVE: [GHSA redacted] (src/oc_bifrost/oc-bifrost-pedant/Gemfile.lock)
  • Medium CVE: [GHSA redacted] (src/chef-server-ctl/Gemfile.lock)
  • Medium CVE: [GHSA redacted] (src/oc_bifrost/oc-bifrost-pedant/Gemfile.lock)
  • Medium CVE: GO-2021-0234 (docs-chef-io/go.mod)
  • …and 13 more

New (482)

  • Concentrated knowledge decay
  • Critical CVE: [GHSA redacted] (src/oc-id/Gemfile.lock)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: written for insiders (src/bookshelf/schema/README.md)
  • Duplicated block (10 lines × 16) (src/bookshelf/src/bksw_xml.erl)
  • Duplicated block (10 lines × 2) (src/bookshelf/src/bksw_wm_object.erl)
  • Duplicated block (10 lines × 2) (src/oc_erchef/apps/chef_index/src/chef_elasticsearch.erl)
  • Duplicated block (10–11 lines × 2) (src/oc_erchef/apps/chef_db/itest/chef_sql_latest_cookbooks.erl)
  • Duplicated block (11 lines × 2) (src/bookshelf/src/bksw_xml.erl)
  • Duplicated block (11 lines × 2) (src/bookshelf/src/bksw_xml.erl)
  • Duplicated block (11 lines × 3) (src/bookshelf/src/bksw_app.erl)
  • Duplicated block (11 lines × 3) (src/bookshelf/src/bksw_xml.erl)
  • Duplicated block (13 lines × 2) (src/bookshelf/src/bksw_xml.erl)
  • Duplicated block (13 lines × 2) (src/oc_erchef/apps/chef_db/itest/chef_sql_environment_cookbooks.erl)
  • Duplicated block (13 lines × 2) (src/oc_erchef/apps/oc_chef_wm/src/oc_chef_wm_authenticate_user.erl)
  • Duplicated block (13–14 lines × 2) (src/oc_erchef/apps/chef_objects/src/chef_cookbook_version.erl)
  • Duplicated block (13–14 lines × 3) (src/oc_erchef/apps/chef_db/itest/chef_sql_cookbook_deps.erl)
  • Duplicated block (14–16 lines × 2) (src/oc_erchef/apps/oc_chef_wm/src/oc_chef_wm_authenticate_user.erl)
  • Duplicated block (15 lines × 2) (src/bookshelf/src/bksw_xml.erl)
  • Duplicated block (17 lines × 2) (src/oc_erchef/apps/chef_objects/src/chef_cookbook_version.erl)
  • …and 462 more

Changes since last survey

  • 21 commits — 20 feature/other, 1 fixes

By area

  • (root) — 16 commits
  • src/chef-server-ctl — 2 commits
  • docs-chef-io/content — 1 commit
  • src/oc-id — 1 commit
  • src/openresty-noroot — 1 commit

Notable commits

  • fix: CHEF-37669 - [verify pipeline fix] Fall back to omnibus submodule's safe_versions.rb when not copied into place (#4232)
  • change: Add deprecation message to all pages (#4238)
  • change: Bump version to 15.10.117 by Chef Expeditor
  • change: Bump version to 15.10.118 by Chef Expeditor
  • change: Bump version to 15.10.119 by Chef Expeditor
  • change: Bump version to 15.10.120 by Chef Expeditor
  • change: Bump version to 15.10.121 by Chef Expeditor
  • change: Bump version to 15.10.122 by Chef Expeditor
  • change: Bump version to 15.10.123 by Chef Expeditor
  • change: Bump version to 15.10.124 by Chef Expeditor
  • change: Bump version to 15.10.125 by Chef Expeditor
  • change: Bump version to 15.10.126 by Chef Expeditor
  • change: CHEF-35182 ruby net-imap (#4227)
  • change: CHEF-37239: Sync omnibus submodule to support external PostgreSQL 14 (#4225)
  • change: CHEF-37625 - Add concurrent-ruby >= 1.3.8 floor across chef-server-ctl, oc-id, oc-chef-pedant, oc_bifrost-pedant Gemfiles (#4231)
  • change: Omnibus sync. (#4237)
  • change: Shahid/openresty 1.31.1 hab (#4236)
  • change: Sync omnibus for pg 17 and other. (#4235)
  • change: Update CHANGELOG.md to reflect the promotion of 15.10.125
  • change: Updated NOTICE.TXT. (#4234)
  • …and 1 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

chef/chef-server was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 23 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 6a599ba7875b13e516f07c714bf8bb804302a952 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-955b9cee9818.