coryodaniel/k8s
59.1
Adequate · 18 September 2026
6.3k
lines of production code
Elixir
primary language
1
measurement over time
What this system is
This system is an Elixir library that provides a robust client for interacting with the Kubernetes API. It manages connections, authentication, and resource discovery while supporting parallel execution, streaming responses, and waiting for specific resource states. The library features a pluggable HTTP provider architecture and middleware infrastructure to handle request processing and observability.
How it got here
2019 — Major API overhaul and modernization
26 changes.
The project underwent a significant architectural refactoring, replacing the deprecated configuration system and HTTP client stack with a modern, pluggable architecture centered on K8s.Conn and K8s.Client. This overhaul introduced new modules for authentication, middleware, discovery, and streaming operations, while upgrading dependencies to require Elixir 1.15 and Mint. Comprehensive test coverage was added to validate the new connection handling, runner implementations, and resource discovery mechanisms.
2020–2022 — HTTP client modernization and test coverage
5 changes.
The project modernized its Kubernetes client by replacing the HTTP adapter with a Mint-based implementation featuring connection pooling and streaming support. This architectural shift was accompanied by the addition of comprehensive test suites for the new client modules and the creation of debugging utilities to aid development.
Features
Add file and HTTP discovery drivers for Kubernetes API resources
Users can now discover Kubernetes API versions and resources using two new drivers: an HTTP driver that queries the Kubernetes API server endpoints (/api and /apis) to retrieve available versions and resources, and a file driver that loads hardcoded API definitions from a JSON configuration file, primarily useful for testing or environments where live discovery is not desired.
lib/k8s/discovery/driver · high confidence
Add telemetry integration and logging support
This change introduces a new telemetry system for the library, defining HTTP request start, stop, and exception events in \K8s.Sys.Telemetry\. It provides a \K8s.Sys.Logger\ module that attaches these telemetry events to the Elixir Logger, automatically mapping failure events to error level and including library metadata. A deprecated \K8s.Sys.Event\ module is added as a shim to delegate to the new telemetry system, ensuring backward compatibility. Additionally, custom \Inspect\ implementations are added for \K8s.Conn.Auth\ structs (\AuthProvider\, \Certificate\, \Token\) to mask sensitive data during debugging.
lib/k8s/sys · high confidence
Added hack scripts and YAML manifests for Kubernetes inspection and debugging
This change introduces new utility files in the hack directory to assist with development and debugging. A new Ruby script, inspect-actions.rb, has been added to fetch and parse the Kubernetes OpenAPI swagger specification, specifically identifying API endpoints with the 'connect' action. Additionally, new Kubernetes Pod manifests (pod.yaml and shell.yaml) are provided to easily spin up an nginx container or a persistent shell pod for interactive debugging against a cluster.
hack · high confidence
Introduce Just-In-Time Kubernetes resource discovery
Added a new discovery subsystem that dynamically resolves Kubernetes resource names and API versions at runtime. This includes a driver behavior for pluggable discovery implementations, a resource finder that maps resource kinds to their correct REST paths (handling singular/plural forms, case insensitivity, and subresources like \/status\), and a naming matcher to accurately identify resources from various input formats.
lib/k8s/discovery · high confidence
Introduces new middleware infrastructure for request handling
Adds the foundational components for a new middleware system: \K8s.Middleware.Request\ defines the request struct and callback interface, \K8s.Middleware.Error\ encapsulates processing errors, and \K8s.Middleware.Stack\ provides a mechanism to organize and apply request and response middleware to a connection. This establishes the structure for future middleware implementations.
lib/k8s/middleware · high confidence
Kubernetes list and watch operations now return Elixir Streams
The \K8s.Client.Runner.Stream\ module now provides \ListRequest\ and \Watch\ implementations that expose Kubernetes list and watch operations as lazy Elixir Streams. This allows users to process large lists with automatic pagination and handle watch events with built-in retry logic, connection restarts, and resource version management, replacing previous imperative or non-streaming approaches for these client operations.
lib/k8s/client/runner/stream · high confidence
New authentication and PKI handling modules for Kubernetes connections
This change introduces four new modules in the \lib/k8s/conn\ directory to support Kubernetes API authentication and certificate management. \K8s.Conn.Auth\ defines the behavior for authentication providers, allowing them to create structs that implement the \K8s.Conn.RequestOptions\ protocol. \K8s.Conn.PKI\ provides utilities for reading and decoding certificates and private keys from PEM files or base64-encoded data, supporting both file paths and in-memory data. \K8s.Conn.RequestOptions\ encapsulates HTTP request options (headers and SSL options) and includes a protocol generator to convert authentication data into these options. \K8s.Conn.Error\ defines a custom exception type for connection-related errors. These modules collectively enable more robust and flexible authentication and certificate handling for Kubernetes connections.
lib/k8s/conn · high confidence
New authentication providers and dynamic worker management
This change introduces several new authentication strategies for Kubernetes connections, including BasicAuth, Azure, DigitalOcean, generic auth-provider, and exec-based authentication (such as AWS IAM). It also adds support for service account token authentication with automatic background refresh. To support these, the library now uses a dynamic supervisor to manage long-lived authentication workers (GenServers) for exec and service account auth, ensuring tokens are refreshed and processes are resilient to crashes.
lib/k8s/conn/auth · high confidence
New parallel, streaming, and wait runners for Kubernetes operations
The \lib/k8s/client/runner\ module now provides specialized runners to extend how Kubernetes operations are executed. \K8s.Client.Runner.Async\ allows running multiple operations in parallel and returning results in order. \K8s.Client.Runner.Stream\ and \K8s.Client.Runner.StreamTo\ enable streaming responses for list, watch, and connect operations, with \StreamTo\ supporting delivery to a specific PID. Additionally, \K8s.Client.Runner.Wait\ introduces a polling mechanism to wait for specific conditions (e.g., job completion or resource deletion) by repeatedly executing GET or DELETE operations until a timeout or condition is met.
lib/k8s/client/runner · high confidence
New path generation and error handling modules for Kubernetes operations
This change introduces two new modules, \K8s.Operation.Error\ and \K8s.Operation.Path\, to the library. The new error module provides a dedicated exception type for operation-related failures. The path module adds logic to generate Kubernetes REST API paths from operation definitions, supporting cluster-scoped and namespace-scoped resources, subresources, and various verbs like create, list, and delete. It handles path parameter validation and replacement, ensuring that required parameters are present before constructing the final API URL.
lib/k8s/operation · high confidence
New request middleware components for body encoding and initialization
Added two new middleware modules to the request pipeline: \EncodeBody\ handles JSON encoding for modifying HTTP verbs (PUT, PATCH, POST) while returning nil for others, and \Initialize\ populates request headers and HTTPoison options by merging connection details from \K8s.Conn.RequestOptions\.
lib/k8s/middleware/request · high confidence
New resource field accessors, named list handling, and utilization parsers
This change introduces three new modules in the \lib/k8s/resource\ directory to improve how Kubernetes resource data is accessed and parsed. \K8s.Resource.FieldAccessors\ provides helper functions to easily retrieve common metadata fields such as kind, API version, name, namespace, labels, and annotations. \K8s.Resource.NamedList\ adds support for accessing lists of maps by a unique 'name' key, offering both safe (\access/1\) and raising (\access!/1\) accessors compatible with Elixir's \get\_in\, \put\_in\, and \pop\_in\ macros. Additionally, \K8s.Resource.Utilization\ introduces deserializers for CPU and memory quantities, supporting standard Kubernetes suffixes like 'm' (millicpu), 'n' (nanocpu), and binary/decimal multipliers for memory.
lib/k8s/resource · high confidence
Behavioural changes
Centralized default configuration for HTTP, discovery, and TLS providers
The K8s module now exposes functions to retrieve default settings for the HTTP client (defaulting to MintHTTPProvider), the discovery driver (defaulting to K8s.Discovery.Driver.HTTP), and the CA certificate file (defaulting to CAStore.file\_path()). This replaces the previous utility functions for extracting resource metadata with a configuration-centric approach, allowing users to globally override these components via application environment variables while maintaining per-connection overrides.
lib · high confidence
Introduce pluggable HTTP provider architecture with Mint implementation
The Kubernetes client now supports a pluggable HTTP provider architecture, allowing the underlying HTTP client to be swapped or mocked. A new \K8s.Client.Provider\ behaviour defines the interface for HTTP and WebSocket operations, and a \K8s.Client.MintHTTPProvider\ implementation is added to use the \mint\ library for connections. A \K8s.Client.DynamicHTTPProvider\ is introduced to allow per-process registration of custom handlers, primarily to facilitate testing and mocking of Kubernetes API responses. Additionally, new error types (\APIError\, \HTTPError\) and stream processing helpers (\HTTPStream\) are provided to handle Kubernetes-specific error payloads and stream transformations.
lib/k8s/client · high confidence
Major API overhaul with new connection and client architecture
The library has been refactored to use a new \K8s.Conn\ struct for connection configuration (replacing the previous \Conf\), introducing dedicated modules for authentication providers (\K8s.Conn.Auth\), middleware, and discovery. The client API now centers on \K8s.Client\ with explicit \run/2\, \async/3\, \stream/2\, and \apply/2\ functions, while \K8s.Operation\ encapsulates API requests. This change also adds support for server-side apply, label/field selectors, and dynamic supervisor management for connections and auth providers.
lib/k8s · high confidence
Migrate to Elixir Config module and update logger formatting
The configuration system has been migrated from the deprecated Mix.Config to the standard Config module, enabling environment-specific configuration files (dev.exs, test.exs) to be properly imported. Logger output format has been updated to include file, library, error, object, body, measurements, and metadata fields. Test environment now specifies default discovery driver, HTTP provider, CA certificate file path, and WebSocket provider.
config · high confidence
New Mint-based HTTP client with connection pooling and streaming
The Kubernetes client now uses a new Mint-based HTTP adapter that replaces the previous implementation. This change introduces a connection registry that manages HTTP/1 and HTTP/2 connections differently: HTTP/1 connections are pooled using poolboy to support simultaneous requests, while HTTP/2 connections use a singleton process model. The new client supports streaming request bodies for large payloads and handles response streaming to caller processes, improving performance and resource management for concurrent API interactions.
lib/k8s/client/mint · high confidence
Project infrastructure and documentation overhaul
The project has replaced Travis CI with GitHub Actions and mise for environment management, introducing new configuration files (.mise.toml, .mise.ci.toml) that specify Erlang 29.0.3 and Elixir 1.20.2, alongside k3d and kind for integration testing. A Credo configuration (.credo.exs) has been added to enforce code style and design checks, while a Makefile has been introduced to streamline running tests against k3d and kind clusters. The README has been significantly expanded with usage examples, feature lists, and badges, and the CHANGELOG has been initialized to document version history.
(repo-wide) · high confidence
Test coverage
Added TLS test fixtures and service account credentials; Added integration and unit tests for the K8s Client Runner; Added test coverage for K8s.Conn authentication providers and PKI utilities; Added test coverage for client, connection, discovery, and selector modules; Added test support fixtures and helpers for Kubernetes integration testing; Added tests for K8s discovery file and HTTP drivers; Added tests for K8s.Client.HTTPStream helper functions; Added tests for K8s.Operation.Path.build validation; Added tests for NamedList accessor and CPU utilization parsing; Added tests for request body encoding and initialization middleware; Added tests for the Kubernetes watch stream runner; Test suite configuration and coverage expansion.
Dependencies
Major dependency overhaul and Elixir 1.15 requirement
The project has been significantly refactored to require Elixir 1.15 and replaced the HTTP client stack, removing \httpoison\ and \hackney\ in favor of \mint\ and \mint\_web\_socket\. The dependency list now includes \castore\ for TLS certificate verification, \poolboy\ for connection pooling, and \telemetry\ for observability. Development tooling has also been updated, with \ex\_doc\ bumped to 0.40.1, \credo\ to 1.7.19, and \dialyxir\ to 1.4.7, while the application version is set to 2.8.0.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Baseline
- First survey — no prior run to compare against. CAI 59.
Lenses
- Code Health 99
- Architecture 99
- Maturity 36
- Readiness 77
- Security 73
Changes since last survey
- 300 commits — 279 feature/other, 21 fixes
By area
- (repo) — 125 commits
- (root) — 96 commits
- .github/workflows — 45 commits
- lib/k8s — 22 commits
- guides/testing.md — 3 commits
- guides/operations.md — 2 commits
- test/k8s — 2 commits
- .devcontainer/Dockerfile — 1 commit
- config/config.exs — 1 commit
- guides/connections.md — 1 commit
- guides/usage.md — 1 commit
- test/support — 1 commit
Notable commits
- fix: Fix link text
- fix: Fix links in testing guide
- fix: Fix watch_test link
- fix: Merge pull request #255 from coryodaniel/fix-connection-op-for-logs
- fix: Merge pull request #283 from JTarasovic/typo-fix
- fix: Merge pull request #285 from coryodaniel/fix-stopping-genserver
- fix: Merge pull request #365 from coryodaniel/fix-matrix-tests
- fix: add missing doc for K8s.Conn.from_env/2 and fix hexdocs
- fix: chore(K8s.Client.Runner.Stream.Watch): fix type
- fix: fix credo
- fix: fix credo
- fix: fix typing
- fix: fix: K8s.Conn.Auth.ServiceAccount type spec
- fix: fix: allow auth genserver to crash and restart
- fix: fix: allow http body types in the Base runner return
- fix: fix: allow params for pod/logs
- fix: fix: only stop genserver if connection is closed for reading, too.
- fix: fix: remove impossible else match arm in Stream.ListRequest
- fix: fix: update github ci workflows for new version
- fix: revert otp
- …and 280 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
coryodaniel/k8s was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 18 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 0c90816400bad05bf7a5367b345a96cefa982243 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-5d04157a340d.