Clivern/Lynx
48.5
Weak · 3 October 2026
8.6k
lines of production code
Elixir
primary language
2
measurements over time
What this system is
Lynx is a Terraform state management platform that provides a web-based interface for managing environments, snapshots, and distributed locks. It exposes a comprehensive REST API secured by session and API key authentication, allowing users to create, restore, and monitor infrastructure state. The system supports team-based project hierarchies and includes background workers for periodic snapshot operations, all configured via environment variables for flexible deployment.
How it got here
2023 — Rebranding to Lynx and architectural overhaul
13 changes.
The project was rebranded from Civet to Lynx, involving a comprehensive update of configuration, documentation, and deployment infrastructure. This period saw the removal of legacy web layers, Vue scaffolding, and old test suites, while the database schema was refactored to support a new team-based hierarchy and core dependencies were upgraded to modern Elixir and Phoenix versions.
2024 — Rebranding to Lynx and core feature implementation
16 changes.
The project was rebranded from Civet to Lynx, involving a comprehensive update of namespaces, OTP applications, and web entrypoints. This period established the core domain model and context modules for managing environments, snapshots, and teams, while introducing a new Vue.js-based frontend theme and Bootstrap styling. Additionally, essential infrastructure for authentication, middleware, background workers, and release scripts was implemented to support the new application architecture.
Features
Added Terraform example for Lynx HTTP backend integration
The example directory now includes a complete Terraform configuration demonstrating how to use Lynx as a remote backend. This setup utilizes the HTTP backend type with specific endpoints for state, locking, and unlocking, requiring authentication via environment variables. The example also configures the required Terraform version (\>= 1.3.7) and providers, including the local provider and the hashicorp/time provider (v0.13.1), to create a local file and implement a 30-second sleep resource.
example · high confidence
Added release scripts for database migrations and server startup
The release now includes shell and batch scripts to manage database migrations and start the application server. Users can run \migrate\ to execute the \Lynx.Release.migrate\ task, ensuring database schema updates are applied, and use \server\ to start the application with the \PHX\_SERVER\ environment variable set to true, enabling the Phoenix server component.
rel · high confidence
Added snapshot worker for periodic snapshot and restore operations
A new background worker, Lynx.Worker.SnapshotWorker, has been introduced to manage snapshot lifecycle tasks. This GenServer runs on a scheduled interval (currently set to 60 seconds) and triggers two main operations: creating outstanding snapshots and restoring snapshots. While the actual implementation logic for these operations is currently represented by logging statements, the worker infrastructure is in place to handle these asynchronous tasks in the background.
lib/lynx/worker · high confidence
Initial release of core web interface templates
This change introduces the foundational view templates for the Lynx web application, establishing the user-facing UI for the first time. The new files in lib/lynx\_web/templates/page include the installation wizard (install.html.heex) for initial setup, authentication screens (login.html.heex), and the main application shell with a consistent header, sidebar navigation, and profile menu (profile.html.heex, project.html.heex, projects.html.heex, settings.html.heex). It also adds standard utility pages such as the home page (home.html.heex) and a styled 404 error page (404.html.heex), completing the basic routing structure for the application.
_lib/lynx\web/templates/page · high confidence
Introduces core context modules for Lynx domain entities
This change adds a comprehensive set of Ecto-based context modules in \lib/lynx/context\ to manage the persistence and retrieval of core domain entities. New modules include \ConfigContext\, \EnvironmentContext\, \LockContext\, \ProjectContext\, \SnapshotContext\, \StateContext\, \TeamContext\, and \UserContext\, providing standard CRUD operations and specific queries (such as retrieving by UUID, slug, or team) for their respective models. Additionally, the previous \ChannelContext\ from the \civet\ namespace has been renamed and refactored into \TaskContext\ to handle task-related data, including status-based filtering for pending tasks.
lib/lynx/context · high confidence
Introduces new default layout templates for the web interface
The application now includes new default HTML layout templates (app, live, and root) in the web layer. These templates define the structure for page rendering, including the inclusion of CSS/JS assets (Bootstrap, Vue, Axios, Swiper), meta tags, flash message handling, and the main content area, establishing the visual foundation for the user interface.
_lib/lynx\web/templates/layout · high confidence
New authentication and logging middleware for API and UI access
This change introduces three new middleware components in the application pipeline. The API Auth Middleware (\api\_auth.ex\) handles authentication via session tokens or the \X-API-KEY\ header, assigning user context to the connection. The UI Auth Middleware (\ui\_auth.ex\) manages session-based authentication for web UI users using \\_uid\ and \\_token\ cookies. Additionally, the Logger Middleware (\logger.ex\) sanitizes incoming request bodies by redacting sensitive fields like \password\ and \admin\_password\ before logging, ensuring credentials are not exposed in log files.
lib/lynx/middleware · high confidence
New service layer for authentication, validation, and slug generation
This change introduces a new service layer in \lib/lynx/service\ containing three core modules: \AuthService\ handles user authentication flows including password hashing, login, session management, and API key lookup; \ValidatorService\ provides a suite of input validation functions for data types, formats (email, URL, UUID, password), and business rules (checking if emails or slugs are already in use); and \SlugService\ offers a utility for generating URL-friendly slugs from text. These services centralize logic previously likely scattered across controllers or contexts, providing a consistent interface for security and data integrity checks.
lib/lynx/service · high confidence
New web controllers for environments, snapshots, locking, and state management
This change introduces a comprehensive set of new API controllers in the \lib/lynx\_web/controllers\ directory, expanding the application's capabilities. The \EnvironmentController\ adds endpoints to list, create, update, and delete project environments. The \SnapshotController\ provides functionality to create, list, view, update, delete, and restore snapshots. The \LockController\ and \StateController\ introduce new endpoints for managing distributed locks and Terraform state, both secured via Basic Auth. Additionally, the \TaskController\ adds a task index endpoint, while \ProfileController\ exposes endpoints to update user profiles and rotate API keys. The \MiscController\ handles application installation and authentication, and \SettingsController\ allows super-users to update application settings. Existing health and readiness endpoints have been migrated from the \civet\_web\ namespace to \lynx\_web\, with the ready endpoint now checking if the application is installed.
_lib/lynx\web/controllers · high confidence
Project rebranded from Civet to Lynx with comprehensive deployment and documentation updates
The application has been renamed from Civet to Lynx, reflected in the Makefile targets, .gitignore patterns, and README documentation. The Dockerfile has been significantly refactored to use a multi-stage build with Elixir 1.16.1 and Debian Bullseye, replacing the previous single-stage build with entrypoint.sh. New deployment configurations have been added, including docker-compose files for single-node, Nginx reverse-proxy, and 3-node cluster setups, along with corresponding Nginx configuration files. The project now ships with an OpenAPI 3.0.1 specification (api.yml) defining health, user, and other endpoints, and a SECURITY.md file for vulnerability reporting. Additionally, the default PostgreSQL image in docker-compose.yml has been upgraded from 15.2 to 16.10, and the .env.example file now includes APP\_HTTP\_SCHEMA and DB\_SSL configuration options.
(repo-wide) · high confidence
Removals
Removal of Phoenix web layer and API endpoints
The entire \lib/civet\_web\ module has been removed, eliminating the Phoenix-based HTTP server and WebSocket infrastructure. This deletes all API routes (including user, client, channel, and action endpoints under \/api/v1\ and \/action/v1\), the \RoomChannel\ for real-time communication, and all associated controllers, views, and HTML templates. Users can no longer access the web interface or interact with the application via HTTP/WebSocket.
_lib/civet\web · high confidence
Removal of core Civet library modules
The \lib/civet\ directory has been removed, deleting the application's core context and service layers. This eliminates the database access layer (including the Ecto repository and contexts for clients, messages, rooms, and users), the location and user services, and the validator utilities. Users of this library will no longer have access to these data management and validation capabilities.
lib/civet · high confidence
Removed Vue 3 + Vite project scaffolding
The web application's initial scaffolding has been removed, deleting the entire source tree including the Vue 3 entry point, Vite configuration, routing setup, Pinia store, and all default UI components and assets. This clears the project of the template boilerplate, leaving the web directory empty of application code.
web · high confidence
Behavioural changes
Application rebranded from Civet to Lynx with new runtime configuration and worker infrastructure
The application has been renamed from Civet to Lynx, updating the OTP application name, module namespaces (including the Application, Repo, Mailer, and Web endpoints), and supervisor names. This change introduces a new runtime configuration helper (Lynx.Config) that allows the HTTP request body size limit to be tuned at runtime via the APP\_HTTP\_MAX\_BODY\_LENGTH environment variable, defaulting to 8 MB. Additionally, a new worker infrastructure is added, including a Supervisor (Lynx.Workers) that manages a SnapshotWorker, and the previous service modules have been refactored into specific exception types (InternalError, InvalidRequest, ResourceNotFound). A new release module (Lynx.Release) is also provided to handle database migrations and rollbacks in production environments without Mix.
lib/lynx · high confidence
Application rebranded from Civet to Lynx with updated web entrypoints
The application has been renamed from Civet to Lynx, reflected in the main module (lib/lynx.ex) and the web entrypoint (lib/lynx\_web.ex). The web module now configures Phoenix controllers and views to use the new LynxWeb namespace and layout, and updates the view helpers to import Phoenix.HTML.Form, PhoenixHTMLHelpers, and Phoenix.Component for modern template support.
lib/lynx/module · high confidence
Application renamed to Lynx with environment-driven configuration and runtime HTTP tuning
The application has been renamed from Civet to Lynx, updating all configuration keys, module references (e.g., Lynx.Repo, LynxWeb.Endpoint), and database names accordingly. Configuration is now heavily driven by environment variables: database credentials, hostnames, ports, and secret keys are read from variables like DB\_USERNAME, APP\_HOST, and APP\_SECRET, with sensible defaults provided. In development and production, the database connection now supports optional SSL via DB\_SSL and DB\_CA\_CERTFILE\_PATH. The HTTP server's maximum body length is now tunable at runtime via the APP\_HTTP\_MAX\_BODY\_LENGTH environment variable, and the Phoenix plug initialization mode is set to :runtime to allow these config changes to take effect without rebuilding the release. Additionally, the esbuild configuration no longer specifies an input file in the default args, and the test logger level was adjusted to :warning.
config · high confidence
Database schema refactored for Lynx application
The database schema has been restructured to support the Lynx application, replacing the previous Civet model with new tables for teams, environments, states, locks, snapshots, tasks, and users. This change introduces a team-based hierarchy where projects belong to teams, adds user roles and API keys, and implements new capabilities for managing environment states, operational locks, and task execution with associated metadata.
priv/repo · high confidence
New frontend theme and application shell
The application now uses a new frontend theme located in priv/static/theme, introducing a complete visual overhaul. This includes a new JavaScript backend client (backend.js) that handles core UI interactions such as installation, login, settings, and snapshot restoration via Vue.js components, alongside a comprehensive CSS stylesheet (app.css) built on Bootstrap v5.1.3 to define the new look and feel.
priv/static/theme · high confidence
Rebrand to Lynx and enable runtime HTTP body size limits
The web layer has been rebranded from Civet to Lynx, updating module names, OTP application identifiers, session keys, and telemetry metric prefixes across the router, endpoint, and telemetry modules. A new \LynxWeb.Plug.RuntimeParsers\ plug replaces the static \Plug.Parsers\ configuration, allowing the HTTP request body size limit to be resolved at runtime from the application environment rather than at compile time. Additionally, session cookies are now configured to be secure only when the \APP\_HTTP\_SCHEMA\ environment variable is set to \https\, and the static file serving now includes the \theme\ directory.
_lib/lynx\web · high confidence
Rebrand to Lynx and introduce new API response structures
The application has been rebranded from Civet to Lynx, with all web views (including error, layout, page, and user views) updated to use the new LynxWeb namespace and module names. This change also introduces new JSON response structures for several entities: environments now include a lock status and state version, projects display team details and environment counts, snapshots show team information, and teams expose user/project counts and member lists. The user profile view has been simplified to return only the API key, and the error helpers have been updated to use the new Gettext domain and HTML helper libraries.
_lib/lynx\web/views · high confidence
Removal of default Phoenix starter CSS styles
The default starter application styles have been removed from the asset pipeline. The \assets/css/phoenix.css\ file, which provided the Milligram v1.4.1 base framework and specific Phoenix promo styling, has been deleted. Additionally, \assets/css/app.css\ has been emptied, removing the \@import\ of the deleted file as well as all default alert, form error, and LiveView-specific animation classes (such as \.phx-modal\, \.phx-click-loading\, and fade animations). Users will no longer receive these pre-built UI components and will need to provide their own styling or import a different CSS framework.
assets/css · high confidence
Removal of legacy Phoenix Socket connection
The legacy Phoenix Socket implementation has been removed from the JavaScript assets. The \user\_socket.js\ file, which handled WebSocket connections and channel subscriptions for the Phoenix framework, has been deleted, and its import has been removed from \app.js\. This change eliminates the old real-time communication layer, leaving only the LiveView socket connection active.
assets/js · high confidence
Reworked data models and renamed core entities
The \lib/lynx/model\ directory has been completely restructured, migrating all Ecto schemas from the \Civet\ namespace to \Lynx\. This change renames several core entities to reflect a shift in domain focus: \Client\ becomes \Environment\, \Room\ becomes \Team\, and \Channel\ becomes \UserTeam\. Additionally, new models for \Lock\, \Snapshot\, \State\, \Task\, and \Config\ have been introduced, while the \User\ model has been updated to include \role\ and \api\_key\ fields and remove demographic fields like \age\ and \gender\.
lib/lynx/model · high confidence
Updated localization templates and refined validation error messages
The application's localization infrastructure has been initialized with new default and English (en) PO/POT template files containing standard UI strings (e.g., Home, Login, Projects). Additionally, the error message templates have been refined: the English error file now reorders and consolidates validation messages to align with Ecto's \validate\_length/3\ behavior, while the general error POT template has been cleaned up to remove unnecessary blank lines.
priv/gettext · high confidence
Test coverage
Added controller and endpoint tests for Lynx Web; Added tests for ConfigContext, SlugService, and ValidatorService; Removal of legacy Orangutan test suite; Updated test support modules to use new application namespace.
Dependencies
Major dependency upgrade and project rename to Lynx
The application has been renamed from Civet to Lynx and upgraded to version 0.13.0, requiring Elixir 1.16. Core dependencies have been significantly updated, including Phoenix 1.6 to 1.8.5, Phoenix LiveView 0.17 to 1.1, Ecto 3.6 to 3.13, and Postgrex 0.16 to 0.22. The build system has shifted from a Node.js/Vue setup (package.json deleted) to using esbuild 0.10 for asset compilation, and the password hashing library was switched from argon2\_elixir to bcrypt\_elixir 3.3.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 47 → 49 (+2.0)
- Rubric changed (rubric-2026.09.15 → rubric-2026.10.1) — scores are not directly comparable.
Lenses
- Code Health 92 → 94 (+2.0)
- Architecture 79 → 69 (-10.2)
- Maturity 55 → 55 (+0.0)
- Readiness 41 → 41 (-0.4)
- Security 73 → 75 (+2.4)
- Accessibility 37 → 44 (+6.6)
Resolved (15)
- Documentation: no installation or build instructions (README.md)
- Duplicated block (13 lines × 3) (lib/lynx_web/controllers/settings_controller.ex)
- Duplicated block (13 lines × 4) (lib/lynx_web/controllers/environment_controller.ex)
- Duplicated block (13 lines × 4) (lib/lynx_web/controllers/environment_controller.ex)
- Duplicated block (13 lines × 6) (lib/lynx_web/controllers/environment_controller.ex)
- Duplicated block (16 lines × 2) (lib/lynx_web/views/lock_view.ex)
- Duplicated block (6 lines × 5) (lib/lynx_web/views/environment_view.ex)
- Duplicated block (7 lines × 3) (lib/lynx/module/project_module.ex)
- Duplicated block (9 lines × 2) (lib/lynx/module/lock_module.ex)
- Duplicated block (9 lines × 2) (lib/lynx_web/controllers/project_controller.ex)
- Members sharing a duplicated core (10 members, 50+ identical tokens) (lib/lynx_web/controllers/page_controller.ex)
- Members sharing a duplicated core (12 members, 50+ identical tokens) (lib/lynx/module/environment_module.ex)
- Members sharing a duplicated core (4 members, 50+ identical tokens) (lib/lynx/service/validator_service.ex)
- Members sharing a duplicated core (5 members, 50+ identical tokens) (lib/lynx/module/lock_module.ex)
- Members sharing a duplicated core (8 members, 50+ identical tokens) (lib/lynx_web/controllers/environment_controller.ex)
New (14)
- Duplicated block (10 lines × 2) (lib/lynx_web/controllers/project_controller.ex)
- Duplicated block (13–15 lines × 2) (lib/lynx/module/lock_module.ex)
- Duplicated block (14 lines × 3) (lib/lynx_web/controllers/settings_controller.ex)
- Duplicated block (14 lines × 6) (lib/lynx_web/controllers/environment_controller.ex)
- Duplicated block (16 lines × 2) (lib/lynx/service/validator_service.ex)
- Duplicated block (16 lines × 2) (lib/lynx_web/views/lock_view.ex)
- Duplicated block (8 lines × 3) (lib/lynx/module/project_module.ex)
- Duplicated block (8 lines × 5) (lib/lynx_web/views/environment_view.ex)
- Members sharing a duplicated core (10 members, 50+ identical tokens) (lib/lynx_web/controllers/page_controller.ex)
- Members sharing a duplicated core (12 members, 50+ identical tokens) (lib/lynx/module/environment_module.ex)
- Members sharing a duplicated core (4 members, 50+ identical tokens) (lib/lynx/service/validator_service.ex)
- Members sharing a duplicated core (5 members, 50+ identical tokens) (lib/lynx/module/lock_module.ex)
- Members sharing a duplicated core (8 members, 50+ identical tokens) (lib/lynx_web/controllers/environment_controller.ex)
- Projects may be oversized for their cohesion
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
Clivern/Lynx was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 3 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 58bcfe0a9f4f2aca90f56e0f42a53427c7c3af93 — the exact code this score is about.
- Scored under rubric-2026.10.1 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-24c657e50118.