danielberkompas/cloak
56.2
Adequate · 3 October 2026
994
lines of production code
Elixir
primary language
2
measurements over time
What this system is
Cloak is an Elixir library that provides encryption capabilities for Ecto models through a flexible, vault-based architecture. It manages encryption keys and algorithms via configurable Vault modules, supporting multiple concurrent ciphers and runtime configuration. The system facilitates key rotation through tagged ciphertexts and includes built-in mechanisms for migrating data between cipher versions.
How it got here
2015 — Vault-based architecture and cipher modernization
10 changes.
The project underwent a significant architectural shift from a global API to a Vault-based system, enabling concurrent ciphers and runtime configuration. This period introduced AES-GCM support with tagged ciphertexts for key rotation, while removing legacy Ecto field types and updating dependencies to Jason and modern Elixir configuration syntax.
2017–2023 — Vault abstraction and migration support
7 changes.
The project introduced a standardized crypto interface to decouple cryptographic operations from specific implementations, enhancing flexibility and maintainability. Significant effort was dedicated to supporting the migration from version 0.6 to 0.7 through deprecated cipher modules and comprehensive regression tests. The period also saw improvements in developer experience via structured exceptions, CI automation scripts, and new documentation guides.
Features
Add Cloak encryption cheatsheet
Added a new cheatsheet for the Cloak encryption library that provides quick-start examples for setting up a vault module, generating encryption keys, configuring ciphers via runtime config or module initialization, and performing safe/unsafe encrypt and decrypt operations, including a preview of Ecto integration.
guides/cheatsheets · high confidence
Add release, changelog, and CI test scripts
New executable scripts have been added to the bin directory to streamline the release process and continuous integration workflow. The bin/release script automates the generation of the changelog, git tagging, and publishing to Hex. The bin/changelog script provides a standalone way to generate changelogs for upcoming versions. Additionally, bin/test standardizes the CI execution by enforcing code formatting, treating compiler warnings as errors, and running tests with coverage reporting on Semaphore.
bin · high confidence
Initial release of Cloak encryption library
This entry introduces the Cloak library, an Elixir encryption tool designed for use with Ecto. The release establishes the core architecture, including \Vault\ modules for managing encryption keys and algorithms, and support for tagged ciphertexts that facilitate key rotation. It includes configuration examples for AES-GCM and AES-CTR ciphers, automatic generation of random initialization vectors, and documentation for installation and usage. The project also sets up development tooling via \.formatter.exs\ and \.tool-versions\ (specifying Elixir 1.19.5 and Erlang 28.4), adds MIT licensing, and configures code coverage reporting via Coveralls.
(repo-wide) · high confidence
Introduction of a new crypto interface module
A new \Cloak.Crypto.Interface\ module has been added to define the contract for cryptographic operations. This interface specifies callbacks for generating random bytes, performing symmetric encryption and decryption (both standard and AEAD modes), and mapping cipher names, providing a standardized abstraction layer for underlying crypto library interactions.
lib/cloak/crypto · high confidence
Removals
Removal of Ecto-specific field types
The Ecto-specific field implementations (EncryptedBinaryField, EncryptedField, EncryptedFloatField, EncryptedIntegerField, EncryptedMapField, and SHA256Field) have been removed from the library. Users relying on these specific Ecto field types for database integration will no longer have access to them and must migrate to alternative approaches for handling encrypted or hashed data within Ecto schemas.
lib/ecto · high confidence
Behavioural changes
Added deprecated cipher modules for migrating from Cloak 0.6 to 0.7
New modules \Cloak.Ciphers.Deprecated.AES.CTR\ and \Cloak.Ciphers.Deprecated.AES.GCM\ have been added to support migrating existing encrypted data from the Cloak 0.6 format to the new format used in 0.7. These modules allow decryption of old ciphertext (which included a module tag prefix) but will raise an error if used for encryption, ensuring users transition to the new \Cloak.Ciphers.AES.CTR\ and \Cloak.Ciphers.AES.GCM\ implementations.
lib/cloak/ciphers/deprecated · high confidence
Migrate to Elixir 1.9+ config syntax and update default cipher
The configuration system has been updated to use the modern \import Config\ syntax, replacing the deprecated \Mix.Config\ module. Environment-specific configuration files for development and production have been removed, with only the test environment now being explicitly imported. The default encryption cipher has changed from \Cloak.AES.CTR\ to \Cloak.Ciphers.AES.GCM\ with a 12-byte IV, and the JSON library is now explicitly set to Jason. Additionally, the default logger level has been set to \:warning\.
config · high confidence
Modernized cipher API and added AES-GCM support
The cipher interface has been updated to require a \:key\ and \:tag\ in the options map for encryption and decryption, replacing the previous implicit key lookup from application configuration. This change introduces a new tagging system (via \Cloak.Tags.Encoder\ and \Decoder\) to embed key identifiers directly into ciphertext headers, enabling key rotation and multi-key support. Additionally, a new \Cloak.Ciphers.AES.GCM\ module provides AES encryption in Galois/Counter Mode, allowing users to leverage authenticated encryption with an optional configurable IV length.
lib/cloak/ciphers · high confidence
Refactor encryption API to use Vaults and Ciphers
The global encryption API in the \Cloak\ module has been removed in favor of a new architecture based on \Cloak.Vault\ and \Cloak.Cipher\ behaviors. Users can no longer call \Cloak.encrypt/1\ or \Cloak.decrypt/1\ directly; instead, they must configure and use specific vaults to handle encryption and decryption, allowing for multiple concurrent ciphers and more flexible configuration.
lib · high confidence
Structured exceptions for configuration and vault errors
The library now raises specific, named exceptions to provide clearer error messages when issues occur. A new \Cloak.VaultNotStarted\ exception is raised with detailed instructions if the vault process is not running, \Cloak.MissingCipher\ provides context (vault, label, ciphertext) when no cipher is found, and \Cloak.InvalidConfig\ is raised for configuration errors. This replaces generic error handling with structured diagnostics to help users resolve setup issues faster.
lib/cloak/exceptions · high confidence
Vault-based encryption with configurable ciphers and runtime configuration
Cloak has been refactored to use a Vault-based architecture where encryption is managed by GenServer-backed Vault modules rather than implicit model macros. Users now define a Vault module (e.g., MyApp.Vault) that uses the new Cloak.Cipher behavior, allowing for multiple ciphers to be configured concurrently with specific labels. The system supports runtime configuration via the GenServer init callback, enabling dynamic setup such as loading keys from environment variables. The previous Cloak.Model macro for automatic encryption versioning has been removed, and configuration is now resolved at runtime from the Vault's ETS table. Additionally, the library now uses Jason as the default JSON library for serializing data before encryption.
lib/cloak · high confidence
Test coverage
Added regression tests for deprecated AES ciphers; Added test coverage for Cloak.Vault; Added test infrastructure for Cloak.Vault; Added tests for AES.GCM cipher and tag encoding/decoding; Removed Ecto encrypted field tests.
Dependencies
Major dependency overhaul and project configuration update
The Cloak library has replaced the JSON dependency from Poison to Jason, which is now an optional dependency, and removed the explicit application declaration for Poison in favor of standard OTP application management. This change is accompanied by a significant update to the project's build configuration in mix.exs, including the addition of test coverage tools (ExCoveralls, Castore), documentation generators (ExDoc, InchEx), and structured package metadata. The version has been bumped to 1.1.4, reflecting these structural changes and the removal of legacy dependencies.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 54 → 56 (+2.0)
- Rubric changed (rubric-2026.09.15 → rubric-2026.10.1) — scores are not directly comparable.
Lenses
- Code Health 100 → 100 (+0.0)
- Architecture 69 → 69 (+0.0)
- Maturity 47 → 47 (+0.0)
- Readiness 42 → 47 (+4.2)
- Security 98 → 98 (+0.4)
Resolved (2)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
danielberkompas/cloak was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 3 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 9a3d10c351f421f5e7b208bb1021910ce3a819b0 — the exact code this score is about.
- Scored under rubric-2026.10.1 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-8fe32cd45d00.