cloudfoundry/bosh
34.9
Weak · 19 September 2026
39.5k
lines of production code
Ruby
primary language
1
measurement over time
What this system is
This system is the BOSH Director, a core infrastructure management platform that orchestrates the deployment, configuration, and lifecycle of software releases across cloud environments. It manages virtual machines, networks, and persistent disks by coordinating with Cloud Provider Interfaces (CPIs) and handling complex deployment plans, including dynamic disk attachment and VIP allocation. The system also provides robust health monitoring, automated problem resolution, and secure communication via NATS, while supporting modern features like mutual TLS, team-scoped access control, and external database backends.
How it got here
2010–2016 — Monolithic to modular architecture migration
87 changes.
This period focused on dismantling the BOSH Director's legacy monolithic codebase, replacing the Ohm ORM with Sequel, and refactoring deployment logic into modular components. It also standardized process management across all jobs using BPM, modernized the runtime environment to Ruby 4.0, and established a comprehensive CI/CD pipeline with extensive test coverage.
2017–2023 — Architecture modernization and CI expansion
40 changes.
This period focused on refactoring the BOSH Director's core deployment engine into modular stages and steps, while restructuring link management and addon filtering for greater precision. Significant infrastructure improvements included introducing mutual TLS for NATS, adding support for multiple cloud configurations, and expanding CI capabilities with new Docker images and GCP Terraform modules for comprehensive integration testing.
2024–2026 — director core refactoring and testing expansion
24 changes.
This period focused on restructuring the BOSH Director's core components, including a new template rendering pipeline, reorganized blobstore clients, and background workers for dynamic disk management. Significant effort was also dedicated to expanding test coverage, introducing comprehensive acceptance tests for external databases and performance metrics, and establishing robust integration test sandboxes.
Features
Add ConfigUserManager for local identity provider with custom scopes
A new ConfigUserManager class has been introduced to support local identity provider authentication. This component allows users to authenticate via username and password against a configured list of users and supports defining custom scopes for each user, defaulting to 'bosh.admin' if none are specified. Note that user management operations (create, update, delete) are not supported by this manager.
src/bosh-director/lib/bosh/director/api/user · high confidence
Add GCP Terraform configuration for BOSH with optional MySQL support
The CI test infrastructure now includes a new Terraform module for GCP that provisions the necessary VPC, subnets, and firewall rules for BOSH deployments. This update introduces optional support for a Cloud SQL MySQL 8.0 database, which is created via private VPC peering when enabled, and exposes the database credentials and host details as outputs for use in integration tests.
ci/bats/iaas/gcp/terraform · high confidence
Add Postgres 13 package definition
A new package for Postgres 13 has been introduced, including a build script that compiles and installs the database server, client tools, and libpq from source, along with the corresponding package specification files.
packages/postgres-13 · high confidence
Add azure-storage-cli package for Azure Storage account communication
A new package named 'azure-storage-cli' has been added to the Bosh environment. This package integrates the Azure Storage CLI tool, which is compiled from the bosh-azure-storage-cli project, enabling communication with Azure Storage accounts. The package definition specifies the binary file to be included and the packaging script ensures the executable is installed to the bin directory with appropriate permissions.
packages/azure-storage-cli · high confidence
Add bosh-gcscli package for GCS blobstore communication
A new package named bosh-gcscli has been introduced to enable communication with GCS blobstores. This package includes a specification defining the binary files, a packaging script that installs the executable to the bin directory, and documentation explaining its purpose and source.
packages/bosh-gcscli · high confidence
Add executable entry points for BOSH Health Monitor
New executable scripts \bosh-monitor\ and \bosh-monitor-console\ have been added to the \src/bosh-monitor/bin\ directory. The \bosh-monitor\ script serves as the main entry point to run the health monitor using a specified configuration file and handles graceful shutdown signals. The \bosh-monitor-console\ script provides an interactive IRB console for debugging and inspection, also accepting a configuration file and optionally enabling the ruby-debug library if available.
src/bosh-monitor/bin · high confidence
Add packaging documentation and build scripts for davcli
The davcli package now includes a README explaining its purpose as a client for WebDAV blobstores, a spec file defining the package name and binary files, and a packaging script that installs the Linux binary to the target bin directory. These changes formalize the build and distribution structure for the davcli component within the Bosh release folder structure.
packages/davcli · high confidence
Add verify\_multidigest package
Added a new BOSH package named verify\_multidigest that bundles the verify-multidigest binary for Linux AMD64 systems. The package includes a spec file defining the source files, a packaging script to install the binary to the target bin directory, and a README providing links to the source code and CI build pipeline.
_packages/verify\multidigest · high confidence
Added Rake tasks for generating database migrations and digests
A new \db.rake\ file introduces two Rake tasks to streamline database schema management. The \db:migration:generate\ task creates new migration files and corresponding RSpec test stubs in the \bosh-director/db/migrations\ directory, while the \db:migration:generate\_digest\ task updates the \migration\_digests.json\ file with SHA1 hashes for existing migrations, including a warning if a released migration is being modified.
src/bosh-director/lib/bosh/director/tasks · high confidence
Added support for Postgres 15
A new package for Postgres 15 has been introduced, including the build script, specification, and documentation. This allows users to deploy and utilize Postgres version 15 within their infrastructure.
packages/postgres-15 · high confidence
Introduce Bosh::Common library with template testing and utility modules
This change adds the \bosh-common\ gem, providing a shared library for BOSH components. It introduces a new \Bosh::Common::Template\ module that includes an \EvaluationContext\ for rendering ERB templates with support for properties, links, and instance specs, along with a \Test\ sub-module (\Bosh::Common::Template::Test\) that allows release authors to unit-test their templates locally without deploying to a director. Additionally, the library adds utility modules for shell command execution (\Bosh::Common::Exec\), retryable operations (\Bosh::Common::Retryable\), thread pooling (\Bosh::Common::ThreadPool\), and common Ruby extensions like \symbolize\_keys\ and \which\.
src/bosh-common · high confidence
Introduce background workers for dynamic disk lifecycle operations
The BOSH Director now includes dedicated background workers (queued on the :dynamic\_disks queue) to handle the creation, attachment, detachment, and deletion of dynamic disks. New job classes—CreateDynamicDisk, AttachDynamicDisk, DetachDynamicDisk, DeleteDynamicDisk, and ProvideDynamicDisk—manage the underlying CPI calls (create\_disk, attach\_disk, detach\_disk, delete\_disk) and agent interactions (add\_dynamic\_disk, remove\_dynamic\_disk) asynchronously. This shifts disk management tasks from synchronous execution to a background job system, ensuring that operations like attaching a disk to a VM or creating a disk in a specific availability zone are processed reliably without blocking the main request thread.
_src/bosh-director/lib/bosh/director/jobs/dynamic\disks · high confidence
Introduce extensible plugin architecture for BOSH Health Monitor
The BOSH Health Monitor now supports a pluggable architecture, allowing operators to extend monitoring capabilities via dedicated plugins. This change introduces a base plugin class and a suite of built-in delivery agents, including DataDog, Consul, Graphite, TSDB, Riemann, PagerDuty, Email, and a JSON stdout plugin for custom process integration. The Resurrector plugin has been refactored to support configurable resurrection rules and improved meltdown state handling, while the EventLogger plugin now stores events in the Director database. This modular approach replaces the previous monolithic implementation, enabling easier integration with external observability and alerting systems.
src/bosh-monitor/lib/bosh/monitor/plugins · high confidence
New BRATS assets for external database, DNS, and deployment configuration
This change adds a comprehensive set of new asset files to the BOSH Release Acceptance Tests (BRATS) suite to support testing against external databases (MySQL and PostgreSQL on GCP and AWS RDS), DNS template linking, and various deployment configurations. Specifically, it introduces connection options and CA certificates for GCP MySQL/Postgres and AWS RDS MySQL/Postgres, including SSL verification settings (verify\_ca/verify-ca) to handle certificate CN mismatches. It also adds manifests and ops files for testing BOSH DNS with linked templates, syslog forwarding via BPM, short DNS addresses, metrics endpoints, and specific database versions like PostgreSQL 13.
src/brats/assets · high confidence
New CI configuration script and pipeline definition for BOSH Director
Added a new \ci/configure.sh\ script to automate the login and application of the Concourse pipeline, alongside a comprehensive \ci/pipeline.yml\ that defines the build structure. The pipeline organizes jobs into groups for BOSH, stemcells (Noble, Jammy FIPS, Resolute), release cutting, and container images, covering unit tests, integration tests, BRATS, and candidate release creation.
ci · high confidence
New CI task to validate Bosh release template rendering
A new shared CI task, \test-release-template-rendering\, has been added to the \ci/shared/tasks\ directory. This task allows users to perform a dry-run Bosh deployment to verify that release templates render correctly without executing actual jobs. It accepts a Bosh director, a release, and optional manifests as inputs, automatically filling in infrastructure details like stemcells and networks, and supports both final and development release uploads via the \DEV\_RELEASE\ parameter.
ci/shared/tasks · high confidence
New CI tasks for automated dependency bumping and integration testing
The CI pipeline now includes dedicated tasks to automatically update and commit specific dependency blobs—namely the blobstore CLI (supporting dav, gcs, s3, and azure-storage backends), mariadb-connector, nats-server, verify-multidigest-cli, and postgres packages—without manual intervention. Additionally, new tasks have been added to run disaster recovery acceptance tests (bdrats) against the director, execute arbitrary rake tasks with configurable database backends (MySQL and PostgreSQL) and performance optimizations (such as tmpfs mounts and WAL disabling for PostgreSQL), and manage infrastructure cleanup including stale terraform state and leftover GCP resources.
ci/tasks · high confidence
New ReleaseJob class for validating and storing BOSH release jobs
A new \Bosh::Director::ReleaseJob\ class has been introduced to handle the ingestion of BOSH release jobs. This component validates job metadata (name and version), unpacks job archives, and verifies the presence and structure of required artifacts such as the job manifest (\job.MF\), templates, monit files, and link specifications. Upon successful validation, it persists the job model and stores the job archive in the blobstore, ensuring that release jobs meet the required structural and naming constraints before being accepted by the director.
src/bosh-director/lib/bosh/director/jobs/release · high confidence
New Terraform infrastructure for BRATS database testing
This change introduces a new set of Terraform configuration files under \ci/shared/brats/terraform\ to provision the database environments required for BRATS (BOSH Runtime Acceptance Tests). The configuration defines resources for both AWS and GCP, including VPCs, security groups, and database instances for MySQL (version 8.0) and PostgreSQL (version 15.18 on AWS, POSTGRES\_15 on GCP). It also includes provider credentials setup for AWS and GCP, along with input variables for database connection details and project configurations, enabling the CI system to spin up isolated database backends for integration testing.
ci/shared/brats/terraform · high confidence
New Warden CPI Docker image for CI testing
A new Docker image for the Warden CPI has been added to the CI infrastructure to support BOSH Release Acceptance Tests (BRATs). This image pre-installs the Bosh CLI, BOSH Lite, and specific releases (bosh-warden-cpi v43, garden-runc v1.25.0, UAA, Credhub) to provide a self-contained environment for running tests. It includes custom scripts to start the BOSH director, manage inner Bosh directors for parallel test execution, and configure the Warden CPI to use systemd for container initialization, addressing compatibility issues with newer Ubuntu bases.
ci/dockerfiles/warden-cpi · high confidence
New development scripts for local director updates and testing
Added four new shell scripts to the \scripts/\ directory to streamline local development workflows. \rsync-bbl\ and \rsync-vbox\ automate the process of syncing Bosh Director and related component code to local BBL and VirtualBox environments, respectively, including version replacement and service restarts. \test-unit\ and \test-unit-erb\ provide dedicated entry points for running general unit tests and ERB-specific unit tests via Rake and RSpec.
scripts · high confidence
New docker-cpi CI image for running BOSH Director in containers
A new Docker image and associated CI scripts have been added to the \ci/dockerfiles/docker-cpi\ location to support running a BOSH Director inside a Docker container using the Docker CPI. The image includes the BOSH CLI, Ruby, Go, and the \bosh-deployment\ repository, along with helper scripts (\start-bosh.sh\, \start-docker.sh\) that configure the Docker daemon (including TLS, cgroups v2 support, and GCP internal DNS) and deploy the BOSH Director. This enables CI pipelines to spin up isolated Bosh environments for testing and acceptance tests (BRATs) without requiring a separate VM or host.
ci/dockerfiles/docker-cpi · high confidence
New problem handlers for disk and VM issues
The BOSH Director now includes a new problem-handling framework with specific handlers for detecting and resolving issues with inactive, missing, or mismatched persistent disks, as well as missing or unresponsive VMs. Users will see new automated resolutions for these scenarios, such as reattaching disks, recreating VMs, or deleting stale references, improving the director's ability to self-heal infrastructure problems.
_src/bosh-director/lib/bosh/director/problem\handlers · high confidence
New template rendering and validation subsystem in bosh-director-core
The \bosh-director/lib/bosh/director/core\ area now includes a complete, new template rendering pipeline. This introduces classes for loading job templates from blobs, rendering ERB templates with property bindings, and persisting the results as compressed archives. A key behavioral addition is the \JobSchemaValidator\, which enforces JSON Schema (Draft 2020-12) validation on job properties and supports a custom 'certificate' type. The system also handles template caching and in-memory tarball generation for agent uploads.
src/bosh-director/lib/bosh/director/core · high confidence
Support for merging multiple cloud configurations
The BOSH Director now supports managing multiple cloud configurations simultaneously. A new consolidator component merges settings from several cloud configs into a single manifest, allowing users to split infrastructure definitions across different configs. The merge logic combines availability zones, VM types, disk types, networks, and VM extensions, while ensuring that the 'compilation' key remains unique across all configs to prevent conflicts.
_src/bosh-director/lib/bosh/director/cloud\config · high confidence
Removals
Removal of legacy Director core components
The Director has removed its legacy internal components, including the RPC client, cloud interface abstraction, configuration manager, deployment plan models, instance and job updaters, package compiler, and various utility modules. This change eliminates the previous monolithic implementation in favor of a new architecture, meaning these specific classes and their associated behaviors are no longer available within the Director codebase.
director/lib/director · high confidence
Removal of the legacy Director monolithic entry point
The monolithic \director/lib/director.rb\ file, which previously served as the single entry point for the BOSH Director, has been removed. This file contained the Sinatra-based HTTP controller, authentication middleware, and the Thin server startup logic. Its removal indicates a shift away from this self-contained server model, likely as part of the broader refactoring to modularize the Director into separate gems and components.
director/lib · high confidence
Architecture
Director jobs refactored into a unified job runner architecture
The director's background job execution has been restructured to use a new \BaseJob\ class and a \DBJob\ runner that executes tasks in forked processes. This change introduces a consistent interface for all director jobs (such as \AttachDisk\, \DeleteDeployment\, \RunErrand\, and various scheduled cleanup jobs) and improves task state management, including better handling of task cancellation and checkpointing.
src/bosh-director/lib/bosh/director/jobs · high confidence
Director models migrated from Ohm to Sequel ORM
The internal data access layer for the BOSH Director has been refactored to use the Sequel ORM instead of the previous Ohm library. This change updates the model definitions in \src/bosh-director/lib/bosh/director/models\ to use Sequel's validation and association syntax (e.g., \validates\_presence\, \many\_to\_one\), affecting core entities such as Deployment, Instance, VM, Config, and Release. For users, this represents a backend architectural improvement that standardizes the database interaction layer, potentially enhancing stability and maintainability without altering the external CLI or API behavior.
src/bosh-director/lib/bosh/director/models · high confidence
Refactored deployment plan assembly and cloud-config parsing into new modular classes
The deployment plan logic has been restructured into a set of dedicated classes to improve maintainability and separation of concerns. The \DeploymentPlan::Assembler\ now orchestrates the binding of models, instance planning, and link resolution, while \CloudManifestParser\ and \CloudPlanner\ handle the parsing and management of cloud configuration (availability zones, networks, VM types, disk types). New components like \AgentStateMigrator\ centralize the retrieval and verification of agent states, and \DeploymentFeaturesParser\ manages feature flags such as DNS and variable convergence. This refactoring isolates specific responsibilities, making the deployment planning process more modular and easier to test.
_src/bosh-director/lib/bosh/director/deployment\plan · high confidence
Behavioural changes
API extensions for authorization, request logging, and scoping
The BOSH Director API now includes new extension modules to enforce stricter access controls and improve auditability. The DeploymentSecurity extension ensures that API routes default to admin-level authorization and handles specific permission checks for deployment operations, such as granting 'create\_deployment' permissions when a deployment is not found. The RequestLogger extension captures detailed audit logs in CEF format, recording request headers, user identity, and response statuses to support security monitoring. Additionally, the Scoping extension introduces a flexible routing mechanism that allows API endpoints to be scoped by default or parameter-based rules, ensuring that only authorized users with the correct token scopes can access specific resources.
src/bosh-director/lib/bosh/director/api/extensions · high confidence
Add Ruby 3.2 compatibility shim for =\~ operator
A new shim in the Ruby shims library overrides the Kernel\#=\~ method to return nil, restoring the pre-Ruby 3.2 behavior where the operator returned nil when called on non-string/non-regex objects. This change ensures the BOSH Director remains compatible with Ruby 3.2+ while maintaining backward compatibility with existing code that relied on the previous default behavior.
_src/bosh-director/lib/ruby\shims · high confidence
Addons now support granular filtering and deployment-level configuration
The addon system has been refactored to allow addons to be filtered by instance groups, jobs, availability zones, networks, teams, stemcells, and lifecycle type, enabling more precise control over where addons are applied. Additionally, addons can now be defined at the deployment level (in addition to the existing runtime level), although deployment-level addons currently do not support the deployment name filter. The implementation introduces new classes for parsing and filtering addon configurations, and deprecates the use of top-level properties in addon definitions in favor of job-level properties.
src/bosh-director/lib/bosh/director/addon · high confidence
BOSH Director binaries restructured to use Puma and Prometheus metrics
The BOSH Director executable scripts in src/bosh-director/bin have been rewritten to replace the previous Thin web server with Puma, binding the API server to localhost (127.0.0.1) by default. This change introduces a dedicated metrics server process that exposes Prometheus metrics via a separate endpoint, and updates the main director binary to integrate Prometheus middleware for API metrics collection. Additionally, the binaries now enforce migration completion before starting the scheduler and configure Puma workers to manage database connections explicitly via before\_fork hooks.
src/bosh-director/bin · high confidence
BOSH Health Monitor rewritten with new architecture and API endpoints
The BOSH Health Monitor in this location has been completely rewritten, introducing a new modular architecture with dedicated classes for agents, deployments, instances, and event processing. It now exposes a new HTTP API via an ApiController (running on Puma) with endpoints for health checks (/healthz), unresponsive agents (/unresponsive\_agents), unhealthy agents (/unhealthy\_agents), failing/stopped/unknown instances, and total agent counts. The monitor now supports UAA authentication with configurable CA certificates and public keys, implements resurrection rules via a ResurrectionManager, and uses the Async gem instead of EventMachine for concurrency. It also adds metrics tracking for various VM states and unmanaged agents, and includes NATS connection retry logic during startup.
src/bosh-monitor/lib/bosh/monitor · high confidence
BOSH Monitor restructured with modern async runtime and plugin architecture
The BOSH Monitor has been significantly refactored to replace the legacy EventMachine runtime with the Async library and swap the Thin web server for Puma, resulting in a more modern and maintainable HTTP handling layer. The monitor now utilizes a plugin-based architecture for health metrics and alerts, introducing a new JSON plugin that sends heartbeats to local processes and standardizing metric values to strings for consistent hashing. Additionally, the codebase has been reorganized to align with the BOSH release folder structure, and NATS connectivity has been improved with retry logic during startup and a switch to the nats-pure client.
src/bosh-monitor/lib/bosh · high confidence
BOSH release metadata files added and symlink restored
The \releases\ directory now contains a \bosh\ symlink pointing to the current release and a series of versioned release manifest files (e.g., \bosh-1.yml\ through \bosh-109.yml\). These YAML files define the BOSH release structure, including packages (such as director, blobstore, registry, and various dependencies like ruby, mysql, and postgres) and jobs, along with their specific versions, SHA1 hashes, and fingerprints. This change restores the missing release symlink and populates the directory with the complete set of release metadata required for BOSH to identify and deploy the software.
releases · high confidence
BRATS CI tasks now support optional DNS ops files and explicit stemcell lines
The BRATS (BOSH Release Acceptance Tests) CI tasks have been restructured to allow optional DNS operations files via a new \dns-ops-file-source\ input, enabling flexible DNS configuration for acceptance tests. Additionally, the tasks now require explicit \DIRECTOR\_STEMCELL\_OS\ and \STEMCELL\_OS\ parameters to ensure tests run against the correct stemcell line, preventing accidental cross-line testing. The acceptance and performance test scripts also now support running tests against external databases (MySQL/PostgreSQL) on AWS and GCP when metadata is provided.
ci/shared/brats · high confidence
Blobstore backup and restore now supports empty stores and configurable enablement
The blobstore job now includes BBR backup and restore scripts that respect the new \blobstore.bbr.enabled\ property, allowing operators to opt out of blobstore backups. The backup script correctly handles empty blobstore directories by creating a placeholder and signaling BBR to skip content, while the restore script safely handles this state and ensures correct file permissions after restoration.
jobs/blobstore/templates · high confidence
Blobstore job adopts BPM process management and adds TLS, IPv6, and signed URL capabilities
The blobstore job has been restructured to use the Binary Process Manager (BPM) for process lifecycle control, replacing the previous monit-based approach. This change introduces several new configuration options: operators can now enable TLS encryption with configurable protocols (defaulting to TLS 1.2) and ciphers, allow HTTP connections alongside HTTPS, and bind to IPv6 addresses. Additionally, the job supports pre-signed URLs for clients to access blobs without direct credentials, allows optional agent credentials when signed URLs are enabled, and exposes basic Nginx metrics via a stub status endpoint. The maximum upload size is configurable, defaulting to 10GB, and backup/restore operations can be opted out of.
jobs/blobstore · high confidence
Cloud check jobs now support max\_in\_flight overrides and structured resolution application
The cloud check subsystem has been restructured into dedicated job classes (Scan, ApplyResolutions, ScanAndFix) to handle problem detection and remediation. A key behavioral change is that the ApplyResolutions job now accepts a \max\_in\_flight\_overrides\ parameter, allowing users to specify instance-group-specific overrides for the \max\_in\_flight\ setting during problem resolution, rather than relying on a global default. Additionally, the ScanAndFix job, used by the resurrector health monitor, now explicitly filters out instances with active persistent disks unless \fix\_stateful\_jobs\ is enabled, ensuring stateful instances are not automatically recreated during automatic fixes.
_src/bosh-director/lib/bosh/director/jobs/cloud\check · high confidence
Database schema updates for dynamic disks, IP address normalization, and VM configuration tracking
This release introduces several database schema changes to support new capabilities and improve data integrity. A new \dynamic\_disks\ table is added to track dynamically provisioned disks, including their association with deployments and VMs, along with metadata and availability zone information. The \ip\_addresses\ table is migrated to store IP addresses in CIDR notation instead of integer representations, and a \nic\_group\ column is added to support network interface grouping. Additionally, the \vms\ table gains columns to store SHA1 hashes of blobstore and NATS configurations, as well as a flag for permanent NATS credentials, while the \dns\_records\ column is removed from the \instances\ table as it is no longer needed.
src/bosh-director/db · high confidence
Deployment execution restructured into explicit stages
The deployment workflow has been refactored from a monolithic process into a sequence of distinct, named stages (e.g., CreateNetwork, DownloadPackages, PackageCompile, Setup, Update, Cleanup). This change introduces a new \Agenda\ struct to manage the execution context and organizes the deployment plan logic into modular classes, improving the clarity and maintainability of how deployments are orchestrated.
_src/bosh-director/lib/bosh/director/deployment\plan/stages · high confidence
Deprecation of the postgres-13 job with migration guidance
The postgres-13 job is now deprecated and scheduled for removal in the next BOSH release. Users are advised to migrate to the postgres job from the cloudfoundry/postgres-release, following the instructions in docs/postgres-migration.md. The job includes pre-start logic that prevents operation if data from a newer postgres-15 job exists or if data from the obsolete postgres-10 job is present, ensuring a clean migration path.
jobs/postgres-13 · high confidence
Director API controllers refactored into a modular, team-scoped architecture
The BOSH Director API has been restructured from a monolithic controller into a set of specialized, team-aware controllers (such as Configs, Deployments, Disks, and Links). This change introduces granular authorization scopes (e.g., \:list\_configs\, \:create\_dynamic\_disks\) that enforce team-based access control, ensuring operators can only interact with resources assigned to their teams. The refactoring also standardizes request handling by switching configuration APIs to JSON bodies, implementing compare-and-swap semantics for config updates to prevent race conditions, and adding new endpoints for dynamic disk management, deployment variable querying, and artifact cleanup.
src/bosh-director/lib/bosh/director/api/controllers · high confidence
Director job templates migrated to BPM process management with enhanced TLS and metrics support
The BOSH Director job templates have been restructured to use the BPM (BOSH Process Manager) for managing director processes, replacing the previous manual control scripts. This change introduces a new \bpm.yml\ template that defines processes for the director, nginx, scheduler, sync-dns, and a new metrics server, along with configurable workers (including dedicated status and dynamic disks workers). The migration includes new templates for BBR backup and restore scripts (\bbr\_backup\, \bbr\_restore\) and configuration (\bbr\_config.json.erb\) that support mutual TLS for database connections. Additionally, the job now supports a dedicated metrics server with mutual TLS configuration, certificate expiry monitoring (\certificate\_expiry.json.erb\), and updated nginx configuration to handle IPv6 and remove the \X-Forwarded-Host\ header for security. The drain script has been updated to properly stop workers via BPM, and environment variables for Ruby stack sizes and library paths are now standardized across worker and control scripts.
jobs/director/templates · high confidence
Director module reorganization and constant definition
The Bosh::Director module has been restructured to consolidate core constants (such as instance states and virtual states) and standardize the loading of internal components. This change introduces explicit definitions for instance lifecycle states and reorganizes the require statements to reflect a more modular architecture, including the relocation of common utilities and the introduction of new classes for DNS management, blobstore clients, and link handling.
src/bosh-director/lib/bosh · medium confidence
Director workers and auxiliary processes now managed by BPM
The director job now uses the BOSH Process Manager (BPM) to supervise worker, scheduler, metrics server, and DNS sync processes, replacing the previous direct invocation of \worker\_ctl\. Operators can control this behavior via the new \director.use\_bpm\_for\_workers\ property (defaulting to false) and configure the number of dedicated dynamic disk workers via \director.dynamic\_disks\_workers\. This change introduces a more standardized lifecycle management for these background processes within the director job.
jobs/director · high confidence
Enforces CPI API version 2 minimum and adapts create\_stemcell/attach\_disk for version 3
The BOSH Director now requires a minimum CPI API version of 2, rejecting older configurations, and updates the external CPI wrapper to support API version 3. Specifically, the create\_stemcell method now passes full arguments for API version 3 or later to enable tag support, while attach\_disk validates that the CPI returns a disk hint. These changes ensure compatibility with modern CPI implementations while maintaining backward compatibility for version 2.
src/bosh-director/lib/clouds · high confidence
Errands can now run on selected instances and multiple instances in parallel
The errand execution engine has been refactored to support running errands on specific instances within a group and executing them across multiple instances simultaneously. Operators can now use the \--instance\ flag to target a single instance or a specific index, and the system will warn if an errand is executed on multiple instances in parallel. The new \InstanceMatcher\ and \InstanceFilter\ classes handle the filtering logic, while \ParallelStep\ manages concurrent execution. Additionally, the system now aborts errand runs if any targeted instances are stopped, unless the \allow\_errands\_on\_stopped\_instances\ director property is enabled, and provides clearer warnings for ambiguous errand names that match both job and instance group names.
src/bosh-director/lib/bosh/director/errand · high confidence
Extracted DNS name server parsing into a dedicated class
The logic for parsing DNS name servers from network subnet properties has been moved into a new, dedicated \NameServersParser\ class. This change isolates the validation and conversion of DNS entries (ensuring they are single IPs) from the broader network parsing logic, improving code organization and maintainability without altering the external behavior of how DNS servers are configured in deployments.
_src/bosh-director/lib/bosh/director/deployment\_plan/network\parser · high confidence
Fix mariadb\_config symlink resolution for mysql2 gem compilation
A wrapper script for the mariadb\_config binary has been added to handle path resolution issues introduced by the MariaDB connector 3.1.11 upgrade. Previously, the binary began returning dereferenced symlinks instead of symlink paths, which caused the mysql2 gem to generate incorrect rpaths during compilation on one VM that failed when used on another. The new script intercepts mariadb\_config output and rewrites paths to use the symlink location, ensuring consistent compilation results across different environments.
src/mysql-customization · high confidence
Health Monitor adopts BPM for process management and enables mutual TLS for NATS
The Health Monitor job now uses the BOSH Process Manager (BPM) to manage its lifecycle, replacing the previous init script approach. This change introduces a new bpm.yml configuration that grants the process access to job binaries and makes the /var/vcap/sys/log directory writable, which is required for HM plugins to function correctly. Additionally, the job now supports mutual TLS (mTLS) for its connection to NATS, requiring the provision of client certificates and private keys, and updates the configuration templates to use the new director\_ca\_cert property name.
_jobs/health\monitor/templates · high confidence
Health Monitor job restructured to use BPM and mutual TLS for NATS
The Health Monitor job has been restructured to use the BOSH Process Manager (BPM) for process supervision instead of the legacy Monit configuration, and now supports mutual TLS for NATS connections. This change introduces new properties for NATS client certificates and private keys, updates the Ruby runtime dependency to version 4.0, and adds configuration options for custom DataDog tags and UAA public keys, while removing deprecated syslog forwarding and defunct Cloudwatch plugin support.
_jobs/health\monitor · high confidence
Introduce AgentBroadcaster for DNS synchronization
The BOSH Director now uses a dedicated AgentBroadcaster component to handle DNS synchronization across instances. This change introduces a new mechanism for broadcasting DNS updates to agents, replacing previous direct communication patterns. The broadcaster manages the lifecycle of DNS sync requests, including timeout handling, response validation, and tracking of unresponsive agents. This improves the reliability of DNS updates during deployments and configuration changes by providing better visibility into agent communication status.
src/bosh-director/lib/bosh/director · high confidence
Introduce BOSH NATS Sync component with UAA and HTTP-based authentication
The new bosh-nats-sync component synchronizes NATS user permissions with BOSH director state. It replaces the previous RestClient dependency with Ruby's standard Net::HTTP for director API communication and adds retry logic to handle director startup delays. Authentication is now flexible: it supports UAA token-based access (preferring the UAA CA certificate when available) and falls back to basic authentication if UAA is unavailable. The component also implements short-lived NATS credentials and caches the director /info endpoint to reduce API load.
src/bosh-nats-sync/lib · high confidence
Introduce parallel persistent disk and VM problem scanning
The problem scanner now performs disk and VM health checks in parallel using a thread pool, significantly reducing scan duration for large deployments. The new architecture separates scanning into distinct stages: VMScanStage checks agent responsiveness and VM existence, while DiskScanStage verifies persistent disk presence and mount consistency. Results are aggregated and reported via the event logger, providing users with detailed breakdowns of OK, missing, inactive, and mismatched resources.
_src/bosh-director/lib/bosh/director/problem\scanner · high confidence
Introduces configurable connection retries with exponential backoff for Graphite and TSDB protocols
The BOSH Monitor now supports configurable and infinite connection retries for its Graphite and TSDB protocol implementations. A new base \TcpConnection\ class manages the underlying TCP socket and implements an exponential backoff strategy (capped at 9 seconds) when reconnection attempts fail. Users can now specify a \max\_retries\ parameter when initializing connections; setting this to -1 allows for infinite retry attempts, ensuring that monitoring data continues to be sent once connectivity is restored rather than failing permanently after a fixed number of attempts.
src/bosh-monitor/lib/bosh/monitor/protocols · high confidence
Introduces structured event models for heartbeats and alerts
The bosh-monitor now uses dedicated \Heartbeat\ and \Alert\ classes to structure monitoring data. Heartbeats automatically parse system vitals (CPU, memory, disk, load) into specific metrics and include deployment, job, and team information. Alerts are now validated for required fields (id, severity, title) and include deployment context, with severity levels mapped to standard categories (alert, critical, error, warning). This provides a consistent, validated format for all monitoring events sent to downstream systems.
src/bosh-monitor/lib/bosh/monitor/events · high confidence
Migrate director models from Ohm to Sequel
The director's internal data models (including CompiledPackage, Deployment, Instance, Package, Stemcell, Task, Template, User, and Vm) have been removed from the Ohm ORM library and are being replaced by a Sequel-based implementation. This architectural change updates how the director persists and queries core infrastructure entities, moving away from the previous key-value store approach to a relational database structure.
director/lib/director/models · high confidence
MySQL package restructured with new build configuration and documentation
The MySQL package has been restructured to use a new Bosh release folder layout, introducing a dedicated README for documentation and a new packaging script that builds the MariaDB connector from source. The build process now explicitly sets CMake flags to handle GCC 15 warnings and disables default SSL server certificate verification (DDEFAULT\_SSL\_VERIFY\_SERVER\_CERT=0) to maintain compatibility with current client libraries, while the package spec now explicitly lists the connector source tarball and a custom mariadb\_config wrapper script as required files.
packages/mysql · high confidence
NATS job migration to BPM and enhanced TLS configuration
The NATS job has been restructured to use the BOSH Process Manager (BPM) for process supervision, replacing the previous monit-based approach with new bpm.yml and monit configurations. This change introduces configurable mutual TLS support for client connections, allowing operators to specify CA certificates and client certificates for health monitor and director interactions. Additionally, the job now exposes configurable timeouts for authentication and TLS handshakes (defaulting to 30s), supports IPv6 listening, and includes retry logic for director API connections during startup to mitigate race conditions.
jobs/nats · high confidence
NATS job now uses mutual TLS and a dedicated sync process
The NATS job has been reconfigured to require mutual TLS for client connections, with templates now generating specific client CA and certificate files for the director and health monitor. A new \bosh\_nats\_sync\ process, managed via BPM, handles synchronization with the director using these credentials and configurable timeouts. The NATS configuration template now supports a \max\_payload\_mb\ property and enables a local metrics endpoint, while pre-start scripts extract client certificate subjects for internal routing.
jobs/nats/templates · high confidence
NATS package updated to use Director Ruby 4.0
The NATS package has been restructured to depend on the \director-ruby-4.0\ runtime instead of a vendored or older Ruby version. This change updates the packaging script to source the environment from the new Ruby package and adjusts the dependency list in the spec file, ensuring the NATS server and its associated Bosh gems are built and run against the Director's Ruby 4.0 environment.
packages/nats · high confidence
New DBMigrator class with retry logic and missing migration tolerance
A new DBMigrator class has been introduced to manage database migrations using Sequel. This class allows missing migration files during status checks, implements a retry mechanism with configurable intervals and a maximum attempt limit for ensuring migrations are current, and provides methods to check current status, run migrations, and ensure completion with error handling.
src/bosh-director/lib · high confidence
New GCP BATS configuration and pipeline resources
The CI pipeline for GCP-based BATS tests now uses dedicated scripts and configuration files to set up the test environment. A new \prepare-bats-config.sh\ script generates \bats.env\ and \bats-config.yml\ by extracting Terraform outputs and Bosh director credentials, ensuring tests run against the correct GCP infrastructure. The configuration explicitly enables ephemeral external IPs for test VMs and sets specific RSpec tags to exclude unsupported features. Additionally, a new \director-vars\ script is introduced to format GCP-specific variables for the Bosh director, and a Concourse task definition (\prepare-bats-config.yml\) is added to orchestrate this setup step within the CI pipeline.
ci/bats/iaas/gcp · high confidence
New Rake task structure for local and CI test execution
The \src/tasks\ directory now provides two new Rake files, \fly.rake\ and \spec.rake\, which restructure how tests are executed. \spec.rake\ defines local development tasks for running unit and integration specs, including parallel execution support and dynamic task generation for individual components. \fly.rake\ introduces a new \fly\ namespace for running these same tests within Concourse CI pipelines, utilizing specific database images and inputs for unit and integration contexts. This change separates local test orchestration from CI-specific execution logic, replacing previous inline or differently structured task definitions.
src/tasks · high confidence
New deployment options and model helper utilities
The deployment plan now includes a new \SkipDrain\ option that allows users to specify which jobs should skip the drain process during deployments, supporting both wildcard selection for all jobs and comma-separated lists for specific jobs. Additionally, a new \ModelHelper\ module provides a \safe\_find\_or\_create\ method that wraps the standard find-or-create operation with retry logic to handle transient exceptions, improving reliability when creating model records.
_src/bosh-director/lib/bosh/director/deployment\plan/options, src/bosh-director/lib/bosh/director/models/helpers · high confidence
New manifest parsing logic for compiled releases
A new Manifest class has been introduced in the compiled release module to handle the parsing and validation of release metadata. This component extracts compiled package lists and provides logic to verify if a specific package matches the current stemcell OS, version, and dependency key, which supports the fix for archive extraction failures during release uploads.
_src/bosh-director/lib/bosh/director/compiled\release · medium confidence
New shared integration Docker image with consolidated tooling and cloud SDKs
The CI pipeline now uses a new, consolidated \bosh/integration\ Docker image that bundles essential development and testing tools, including Ruby 3.2, Go, golangci-lint, yq, and the BOSH CLI. This image also installs cloud provider SDKs (AWS CLI, Azure CLI, Google Cloud CLI) and database clients (PostgreSQL, MySQL) required for integration tests. A new \build-docker-args\ script and CI resource automate the resolution of latest release URLs for these tools, ensuring the image stays up-to-date without hardcoding versions.
ci/dockerfiles/integration · high confidence
Postgres job upgraded to version 15 with BPM integration
The Postgres job now runs version 15, replacing previous versions (9.4, 10, 13) which are marked as obsolete. The job is now managed by BOSH Process Manager (BPM) via a new bpm.yml configuration, which sets the shutdown signal to INT and configures file limits. Data storage has moved to the postgres-15 directory, and the pre-start script handles upgrades from version 13 using pg\_upgrade, while also rebuilding indexes if the host's glibc version changes to prevent data corruption.
jobs/postgres/templates · high confidence
Redesigned manifest handling with structured config classes and secure diffing
The manifest processing logic has been restructured into dedicated classes (DeploymentConfig, InstanceGroupConfig, Changeset, Redactor) to improve maintainability and security. Operators can now view deployment diffs that respect include/exclude rules and automatically redact sensitive data, including basic authentication credentials found in release URLs. The system also supports YAML aliases and symbols during safe loading, and ensures that the manifest text submitted by the operator is preserved and retrievable exactly as provided.
src/bosh-director/lib/bosh/director/manifest · high confidence
Refactor BOSH Director API into modular manager and helper classes
The BOSH Director API implementation has been restructured from a monolithic controller-based design into a set of focused, modular classes within the \bosh/director/api\ directory. This change introduces dedicated managers for specific domains—such as \ConfigManager\, \DeploymentManager\, \InstanceManager\, \ReleaseManager\, and \StemcellManager\—along with helper utilities like \ApiHelper\ and \DeploymentCertificateProvider\. For users, this refactoring underpins the new generic configuration API (allowing unified management of cloud, CPI, and runtime configs), exposes deployment certificate expiry dates via a new endpoint, and improves the stability and maintainability of the API surface without altering existing CLI or API behaviors.
src/bosh-director/lib/bosh/director/api · high confidence
Refactor link address resolution to support DNS and short DNS flags
The link address resolution logic has been refactored to distinguish between global DNS address usage and specific link-level IP address preferences. The \Link\ class now explicitly tracks \use\_dns\_addresses\, \use\_short\_dns\_addresses\, and \use\_link\_dns\_names\ flags, allowing consumers to discover unique DNS addresses for each link. This change ensures that the \/link\_address\ API endpoint and link consumption honor the provider deployment's \use\_short\_dns\_addresses\ setting and the consumer's \ip\_address\ flag, enabling more precise control over whether IP or DNS addresses are returned for both local and cross-deployment links.
_src/bosh-director/lib/bosh/director/deployment\plan/links · high confidence
Refactored BATS director deployment and teardown into reusable CI tasks
The BATS CI infrastructure now uses dedicated \deploy-director\ and \destroy-director\ tasks to manage the BOSH director lifecycle. The new deploy task supports upgrade scenarios by preserving and restoring director state between runs, ensuring that the specific BOSH release under test is always deployed by validating the release URL. The teardown task reliably cleans up deployments and the director environment, even if the director is unreachable, and uses unique director names based on the environment metadata to prevent cross-job interference during cleanup.
ci/bats/tasks · high confidence
Refactored Config Server client with new authentication and interpolation architecture
The Config Server integration has been restructured to use a new \AuthHTTPClient\ for UAA-based authentication and a dedicated \VariablesInterpolator\ for managing variable resolution. This change introduces support for versioned variable sets, allowing operators to control update strategies (such as 'on-deploy' or 'on-stemcell-change') and enabling cross-deployment link interpolation. The new client also adds retry logic for connection errors and validates variable name syntax, including support for dot-notation access and stricter error reporting when variables are missing or malformed.
_src/bosh-director/lib/bosh/director/config\server · high confidence
Refactored IP allocation logic to support globally allocated VIPs and improved conflict handling
The IP provider and repository have been restructured to introduce a new \IpProvider\ class that explicitly handles dynamic, manual, and VIP networks, replacing the previous monolithic logic. A key behavioral change is the support for globally allocated VIPs: when a VIP network is configured with global allocation, the system now dynamically assigns an available IP from the subnet's static range rather than requiring a pre-defined static reservation, while still allowing explicit IP assignment when provided. The underlying \IpRepo\ has been updated to use a new \IpAddrOrCidr\ type for more robust IP address handling, and allocation algorithms now include better conflict resolution for race conditions and stricter validation to prevent reserving IPs that are already in use or fall within restricted ranges.
_src/bosh-director/lib/bosh/director/deployment\_plan/ip\provider · high confidence
Refactored VM lifecycle into granular deployment steps
The VM creation, disk management, and deletion logic has been extracted from the monolithic VmCreator into a series of dedicated steps (e.g., CreateVmStep, AttachDiskStep, DeleteVmStep, OrphanVmStep). This change introduces short-lived NATS credentials for agent bootstrap, supports dynamic disk attachment/detachment, and ensures VM metadata and network settings are applied via specific steps, resulting in more modular and observable deployment operations.
_src/bosh-director/lib/bosh/director/deployment\plan/steps · high confidence
Refactored availability zone placement logic for improved balancing and static IP handling
The deployment plan's availability zone (AZ) placement logic has been restructured into dedicated components to improve instance distribution and static IP management. A new \Balancer\ class with pluggable \TieStrategy\ implementations (MinWins and RandomWins) now handles AZ selection, enabling better rebalancing when scaling down AZs and supporting optional randomization via a feature flag. Static IP placement is now managed by a \StaticIpsAvailabilityZonePicker\ and \NetworksToStaticIps\ helper, which validates that static IPs belong to declared subnets and AZs, and uses a \BruteForceIpAllocation\ strategy to evenly distribute static IPs across zones. The \AvailabilityZonePicker\ continues to handle dynamic IP placement, prioritizing instances with persistent disks and ignored instances in their existing AZs before balancing the rest. These changes ensure more predictable and balanced instance placement across availability zones while maintaining strict validation for static IP assignments.
_src/bosh-director/lib/bosh/director/deployment\_plan/placement\planner · high confidence
Refactored cleanup logic into dedicated helper classes
The cleanup process for releases, stemcells, and packages has been restructured into a set of specialized helper classes (e.g., \CompiledPackageDeleter\, \ReleaseDeleter\, \StemcellDeleter\) to improve modularity and maintainability. This change introduces specific logic for picking which items to delete based on usage (e.g., checking for active deployments or runtime config references) and handles the deletion of associated artifacts like blobstore objects and database records. Users will see no functional change in the cleanup outcome, but the underlying implementation is now more granular and easier to test or extend.
src/bosh-director/lib/bosh/director/jobs/helpers · high confidence
Refactored deployment and release update jobs into modular components
The monolithic \UpdateDeployment\ and \UpdateRelease\ job classes have been removed and replaced with a refactored architecture that separates concerns into distinct components such as \DeploymentPlan::Assembler\, \DeploymentPlan::Preparer\, \DeploymentPlan::Updater\, and \ResourcePools\. This change moves logic for binding instance networks, managing resource pool networks, compiling packages, and handling IP reservations out of the main job execution flow into specialized classes, improving testability and maintainability of the director's deployment and release update processes.
director/lib/director/jobs · high confidence
Refactored digest verification and creation into a dedicated module
The digest handling logic has been reorganized into a new \Bosh::Director::BoshDigest\ module, introducing \MultiDigest\ to manage SHA1 and SHA256 operations via an external binary. This change adds specific error classes (\ShaMismatchError\, \DigestCreationError\) for better error handling and updates the implementation to invoke the multidigest binary using an array of arguments instead of a single command string, improving security and reliability during file verification and digest creation.
src/bosh-director/lib/bosh/director/digest · high confidence
Refactored instance update logic with new state management and recreate handling
The instance update process has been restructured into distinct components: \UpdateProcedure\ now orchestrates the update lifecycle, \RecreateHandler\ manages VM recreation (including disk detachment and swap-delete logic), and \StateApplier\ handles applying VM state and starting instances. A new \InstanceState\ class wraps updates to ensure proper event logging and completion tracking. This refactoring introduces optimizations to skip full updates when only DNS or tags change, and ensures variable sets and bound links are updated consistently during deployments, including for soft-stopped instances.
_src/bosh-director/lib/bosh/director/instance\updater · high confidence
Refactored link model schema to support provider/consumer intents and DNS discovery
The internal links API schema has been refactored to separate link definitions into distinct provider and consumer intents, introducing new database models (Link, LinkConsumer, LinkConsumerIntent, LinkProvider, LinkProviderIntent, InstancesLink) to manage these relationships. This structural change enables operators to discover unique DNS addresses for each link by resolving them from the database, ensuring that link rendering uses current or last-known successfully deployed links with fallback logic when targets are unavailable.
src/bosh-director/lib/bosh/director/models/links · medium confidence
Refactored link resolution and parsing into a database-backed intent model
The BOSH Director's link management has been restructured to use a database-backed model of providers, consumers, and their intents, replacing the previous in-memory or legacy storage approach. This change introduces dedicated parsers for processing link definitions from job manifests and variables, ensuring that link resolution respects deployment context via serial IDs and supports features like custom provider definitions, DNS aliasing, and explicit link binding. Users benefit from more robust link resolution during deployments, including better handling of migrations, clearer error messages for missing or ambiguous links, and the ability to consume links from variables.
src/bosh-director/lib/bosh/director/links · high confidence
Refactored local DNS management with new encoder and publisher components
The local DNS subsystem has been restructured into dedicated components to improve modularity and support advanced DNS features. A new \BlobstoreDnsPublisher\ handles the creation of DNS blobs and their broadcast to agents, while a \LocalDnsEncoderManager\ and \DnsEncoder\ class manage the encoding of DNS queries, including support for short DNS names and link-based DNS addresses. The \Canonicalizer\ ensures DNS names are strictly validated and normalized. Additionally, \LocalDnsManager\ and \LocalDnsRecordsRepo\ encapsulate the logic for updating and deleting DNS records for instances, and \DnsVersionConverger\ ensures agents receive the latest DNS information. These changes enable more robust DNS aliasing, better performance through caching, and clearer separation of concerns in the DNS handling logic.
src/bosh-director/lib/bosh/director/dns · high confidence
Refactored network planning to support VIP network migration and NIC group awareness
The network planning logic has been restructured into dedicated classes (Plan, Planner, ReservationReconciler, VipPlanner) to improve how BOSH Director manages network assignments during deployments. This change enables VIP networks to be configured with globally allocated static IPs, allowing the director to migrate instances between VIP networks while preserving their IP addresses. It also introduces support for the \nic\_group\ attribute in job networks, ensuring that network reservations are correctly matched and reused based on NIC group identity. Additionally, the new reconciliation logic prevents IP address leaks when networks collide and ensures that availability zones are considered when determining if existing reservations can be reused.
_src/bosh-director/lib/bosh/director/deployment\_plan/network\planner · high confidence
Refactored release update package handling into dedicated processors
The logic for managing packages during a release update has been split into two new classes: \PackageProcessor\ and \PackagePersister\. \PackageProcessor\ now handles the identification of new, existing, and registered packages, including validation of package fingerprints to detect collisions and logic to reuse blobs from other releases when appropriate. \PackagePersister\ takes over the responsibility of persisting these packages to the database and blobstore, introducing a stateless design and explicit keyword arguments for better clarity. This change also ensures that the \--fix\ flag is applied only to packages within the current release being updated, preventing unintended modifications to packages in other releases.
_src/bosh-director/lib/bosh/director/jobs/update\release · high confidence
Relocated version parsing classes to bosh-director
The version parsing implementation has been moved from the shared \bosh-common\ library into the \bosh-director\ codebase. This change introduces new files under \src/bosh-director/lib/bosh/version/\, including \SemiSemanticVersion\, \ReleaseVersion\, \StemcellVersion\, and their respective list parsers. For users, this represents an internal structural reorganization of how version strings are parsed and compared within the director, without altering the external versioning behavior or API.
src/bosh-director/lib/bosh/version · high confidence
Reorganized blobstore clients under Bosh::Director::Blobstore with new wrapper and validation components
The blobstore implementation has been restructured to reside under the Bosh::Director::Blobstore module, introducing a base Client class and specific implementations for Azure, S3, GCS, WebDAV, and local storage. This change adds wrapper classes (RetryableClientWrapper, Sha1VerifyingClientWrapper) to handle retry logic and SHA1 integrity verification, alongside a UuidValidation module to enforce strict UUID formats for local blobstore object IDs. Users benefit from improved reliability through automatic retries, data integrity checks on retrieval, and stricter validation of local blob identifiers.
src/bosh-director/lib/bosh/director/blobstore · high confidence
Restructure s3cli package to use standard Bosh release folder structure
The s3cli package has been reorganized to align with the standard Bosh release folder structure. This includes adding a README explaining the package's purpose and source, a packaging script to install the binary, and a spec file defining the package name and files.
packages/s3cli · high confidence
Ruby core extensions moved to dedicated directory
Ruby monkey-patches for Array, Hash, and Object classes, including methods like to\_openstruct and recursive\_merge, have been relocated to the src/bosh-director/lib/bosh/director/core\_ext/ directory. This change organizes the codebase by grouping these core extensions together, improving maintainability without altering their functionality.
_src/bosh-director/lib/bosh/director/core\ext · high confidence
Runtime config now supports variables and structured addon filtering
The runtime config system has been refactored to parse and merge variables alongside releases and addons, allowing deployments to consume links from variables defined in runtime configs. The new \ParsedRuntimeConfig\ class filters addons based on deployment-specific rules, ensuring that only applicable addons and their associated releases are included in the deployment plan, while empty addons and variables are excluded from the final manifest.
_src/bosh-director/lib/bosh/director/runtime\config · high confidence
Standardize Postgres job with BPM-native process management
The Postgres job now uses a standard Monit configuration that delegates process lifecycle to the BPM (BOSH Process Manager) native start and stop commands, replacing previous custom scripts. This change ensures consistent shutdown behavior across Postgres versions and simplifies the job structure by relying on BPM for signal handling and process monitoring.
jobs/postgres · high confidence
Standardize development environment and test configuration
The development environment is now standardized with a specific Ruby version (4.0.7) and a strict linting-only Rubocop configuration. RSpec is configured for consistent output and backtrace visibility, and the Rakefile is simplified to import specific task files and default to running specs, ensuring a consistent and predictable local development experience.
src · high confidence
Support for named CPI configurations with migration tracking
The CPI configuration system now supports named CPIs and allows specifying a list of CPIs from which the current configuration is migrating. This enables deployments to reference CPIs by name and ensures that the system can locate a CPI either by its current name or by any of its historical migration names, facilitating smoother transitions between CPI versions or types.
_src/bosh-director/lib/bosh/director/cpi\config · high confidence
Updated BOSH Director configuration files
The BOSH Director location now includes a .gitignore file that excludes Gemfile.lock and a .simplecov configuration file that filters out the /db/ and /spec/ directories from coverage reports.
src/bosh-director · high confidence
Test coverage
Add BRATS utility package with external database configuration and test coverage; Add test release assets for compiled release validation; Added acceptance tests for BOSH director capabilities; Added comprehensive test suite for bosh-nats-sync; Added dummy CPI test asset for deadlock scenario; Added functional tests for notifying plugins; Added initial test suite for NATS Sync module; Added integration tests for CLI cloud-check and CCK resolution behaviors; Added integration tests for Config Server certificate expiry and linking; Added integration tests for Health Monitor resurrection behaviors; Added integration tests for IP reservation behavior; Added integration tests for NATS server configuration and CA certificate validation; Added integration tests for UAA authentication and authorization; Added integration tests for deployment scenarios; Added integration tests for director core behaviors; Added integration tests for global networking scenarios; Added integration tests for link aliasing, validation, and cross-deployment scenarios; Added integration tests for release management commands; Added performance tests for BOSH template rendering; Added shared test examples for DelayedJob, task cancellation, and subnet validation; Added shared test helpers for database and deployment manifest testing; Added spec support helpers for logging, host authorization, and UAA token validation; Added test assets for NATS agent certificate generation scenarios; Added test assets for fake errand release template; Added test assets for post-stop script behavior; Added test fixtures and assets for BOSH Director specs; Added test fixtures for Bosh release compilation and packaging; Added test fixtures for link consumption and provider scenarios; Added test infrastructure and validation for bosh-monitor; Added tests for Kernel =\~ shim behavior; Added unit tests for BOSH Director core components; Added unit tests for BOSH Health Monitor core components; Added unit tests for BOSH Health Monitor plugins; Added unit tests for BOSH Monitor event models; Added unit tests for External CPI response handling and API versioning; Added unit tests for TCP connection retry and error handling; Added unit tests for release job templates and configuration; Centralized shared RSpec configuration and helpers; Expanded integration test coverage for errand execution and lifecycle management; Expanded test release template for errand and lifecycle script validation; Integration test sandbox now includes pre-generated TLS certificates and configuration assets; Integration tests for runtime config addon scoping and named configs; New integration test support library for sandboxed BOSH environments; Refactored spec support helpers and migrated to FactoryBot; Removed director/spec Rakefile and spec\_helper.rb; Removed obsolete unit tests for director components; Standardized RSpec test configuration and helper loading; Test infrastructure modernized with FactoryBot and consolidated helpers.
Dependencies
Director package now uses the director-ruby-4.0 runtime
The BOSH Director package has been updated to depend on the \director-ruby-4.0\ package instead of a vendored or older Ruby version. This change updates the runtime environment for the Director, requiring the \libpq\ and \mysql\ packages for database connectivity, and modifies the build process to compile gems against these specific library paths.
packages/director · high confidence
Migrate BOSH components to a unified gem-based dependency structure with Ruby 3.4+ support
The BOSH codebase has been restructured from a legacy single-Gemfile layout into a modular gem architecture, introducing distinct gemspecs for bosh-common, bosh-director, bosh-monitor, and bosh-nats-sync, all of which now require Ruby 3.4.0 or higher. This change replaces older dependencies (such as eventmachine, ohm, and thin) with modern alternatives like nats-pure, sequel, and puma, and consolidates development tooling (RSpec, factory\_bot, simplecov) into a shared root Gemfile. Additionally, the BOSH Release Acceptance Tests (BRATS) have been updated to use Go 1.26.0 with the latest Ginkgo and Gomega libraries.
(dependencies) · high confidence
Updated vendored Ruby gems to latest versions
The vendored gem cache in src/vendor/cache has been updated with new versions of numerous Ruby dependencies, including activesupport (8.1.3.1), puma (8.0.2), rack (3.2.7), sinatra (4.2.1), and rubocop (1.91.0), among others. This ensures the application uses the latest available features and fixes for these core libraries.
src/vendor · high confidence
Updated vendored dependencies in brats acceptance tests
The vendored dependencies in the brats acceptance test suite have been updated, including a refresh of the Masterminds/semver v3 library to version 3.4.0 and the creack/pty library. These updates bring in upstream changes such as improved error handling, support for newer Go versions, and updated constraint checking logic for semantic versioning.
src/brats/vendor · high confidence
Upgrade libpq package to PostgreSQL 15
The libpq package definition has been updated to source the PostgreSQL 15 tarball (postgres/postgresql-15.\*.tar.gz) instead of previous versions. The build packaging script now compiles the library with OpenSSL support enabled, ensuring that the resulting client library includes TLS encryption capabilities.
packages/libpq · high confidence
Housekeeping
Initial repository structure and documentation
The repository has been initialized with the core BOSH release structure, including the Apache 2.0 LICENSE and NOTICE files, a comprehensive .gitignore configuration for build artifacts and local environments, and updated README and CONTRIBUTING documentation to guide users and contributors.
(repo-wide) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Baseline
- First survey — no prior run to compare against. CAI 35.
Lenses
- Code Health 91
- Architecture 90
- Maturity 55
- Readiness 62
- Security 1
Changes since last survey
- 300 commits — 281 feature/other, 19 fixes
By area
- config/blobs.yml — 140 commits
- .final_builds/packages — 33 commits
- (repo) — 19 commits
- jobs/director — 18 commits
- src/vendor — 16 commits
- src/brats — 15 commits
- src/bosh-director — 11 commits
- ci/pipeline.yml — 10 commits
- src/spec — 8 commits
- ci/tasks — 5 commits
- packages/director — 5 commits
- .github/workflows — 4 commits
- jobs/health_monitor — 3 commits
- ci/dockerfiles — 2 commits
- src/Gemfile.lock — 2 commits
- .final_builds/jobs — 1 commit
- ci/bats — 1 commit
- ci/shared — 1 commit
- docs/postgres-migration.md — 1 commit
- jobs/postgres-13 — 1 commit
Notable commits
- fix: CI: fix trigger, and pass constraints for bats-utils
- fix: Fix PostgreSQL out-of-space in integration tests
- fix: Fix PostgresVersionHelper#local_version on macOS
- fix: Fix timing-sensitive flake in NATSSync::Runner spec (#2801)
- fix: Fix: blobstore specs test correct method
- fix: Merge pull request #2791 from cloudfoundry/integration-specs-fix-decode-warning
- fix: Potential fix for code scanning alert no. 23: Workflow does not contain permissions
- fix: Potential fix for code scanning alert no. 31: Workflow does not contain permissions
- fix: Potential fix for code scanning alert no. 40: Workflow does not contain permissions
- fix: Potential fix for pull request finding
- fix: Potential fix for pull request finding
- fix: Potential fix for pull request finding
- fix: Revert broken 1.0.0 finalize from build 75
- fix: brats: fix upgrade from postgres 13 test
- fix: ci: fix Garden init in warden CI image
- fix: ci: pipeline fixes
- fix: fix: ruby 4 doesn't include cgi or irb
- fix: fix: semver resource uses git
- fix: packaging: harmonize script; fix shellcheck issues
- change: Add create, attach, and list endpoints to dynamic disks API (#2743)
- …and 280 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
cloudfoundry/bosh was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 19 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 6fb54a3307ad1b8fa7035442c60dbea43c074e31 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-13a154b7f5d1.