Skip to content
CAI
Software that uses CAICheck a score

etcd-io/etcd

67.9

Adequate · 6 August 2026

81k

lines of production code

Go

primary language

3

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is the etcd distributed key-value store, providing a reliable and consistent data store for distributed systems. It includes a Go client library for interacting with the cluster, a command-line interface (etcdctl) for administration, and a server implementation that manages Raft consensus, storage, and gRPC/HTTP APIs. The codebase also provides various utilities, monitoring tools, and testing frameworks to support development, deployment, and reliability verification.

How it got here

2013–2020 — Modularization and tooling expansion

106 changes.

This period focused on restructuring the codebase into a modular, interface-based architecture, particularly within the server and client packages. Significant effort was dedicated to expanding the Go client library with new features like caching, namespacing, and distributed recipes, while also introducing a wide array of diagnostic, benchmarking, and testing utilities.

2021–2022 — storage and client architecture refactoring

48 changes.

This period focused on reorganizing the codebase by moving backend storage, WAL, and MVCC logic into a dedicated 'storage' package, while simultaneously restructuring the client library with new endpoint management and naming APIs. The work also included significant improvements to the test framework, the introduction of utility tools like etcdutl, and the addition of monitoring and verification features.

2023–2026 — Robustness testing and monitoring expansion

32 changes.

This period focused on significantly expanding the robustness testing framework, introducing deep integration with Antithesis for failure injection and state validation. Concurrently, the project enhanced observability by adding comprehensive monitoring dashboards and alerting rules, while also introducing new client-side features like an in-memory cache and Kubernetes-specific KV interfaces.

Features

Add CPU utility package for endianness detection

A new \pkg/cpuutil\ package has been introduced, providing a \ByteOrder\ function that returns the CPU's native byte order (big or little endian) using the \golang.org/x/sys/cpu\ library.

pkg/cpuutil · high confidence

Add Go-based rw-heatmaps tool for mixed read/write performance evaluation

The \rw-heatmaps\ tool, previously implemented in another language, has been reimplemented in Go. This change introduces a new Go-based utility for generating read/write heatmaps and line charts from etcd benchmark CSV data. The tool now supports generating both heatmap and line chart visualizations, with options to compare two datasets or analyze a single run. The implementation includes command-line argument parsing, data loading from CSV files, and chart plotting using the \gonum\ library. A shell script (\rw-benchmark.sh\) is also provided to run mixed read/write benchmarks and save test parameters.

tools/rw-heatmaps · high confidence

Add Linux-specific file descriptor counting and limit retrieval

The runtime package now includes platform-specific implementations for tracking file descriptors. On Linux, the \FDUsage\ function counts open file descriptors by reading \/proc/self/fd\ using \Readdirnames\, and \FDLimit\ retrieves the current file descriptor limit via \syscall.Getrlimit\. For non-Linux systems, these functions return an error indicating the operation is unsupported. This change introduces new utility functions to monitor and report file descriptor usage and limits.

pkg/runtime · high confidence

Add OWNERS file and update contrib README with new examples

The contrib directory now includes an OWNERS file to define area labels for pull requests. The contrib README has been updated to document new examples: a systemd unit file for deploying etcd on systemd-based distributions, a multi-node cluster setup, an example key-value store using raft, and a lock example addressing the expired lease problem of distributed locking with etcd.

contrib · medium confidence

Add TCP proxy for routing client connections

A new userspace TCP proxy is introduced in the server/proxy/tcpproxy package. It accepts incoming TCP connections and forwards them to backend servers using a weighted round-robin selection algorithm that respects SRV record priorities and weights. The implementation includes a monitor interval for health checking and logs endpoint status, providing a transparent proxying layer for etcd clients.

server/proxy/tcpproxy · high confidence

Add YAML configuration loader for clientv3

The client/v3/yaml package now provides a NewConfig function that reads a YAML file to populate a clientv3.Config, supporting TLS certificates, CA files, and insecure transport settings. A corresponding test suite validates the loading of these configuration options.

client/v3/yaml · high confidence

Add client-side ordering violation detection for clientv3

The client/v3/ordering package introduces a wrapper for the clientv3 KV and Txn interfaces that detects when a response header revision is lower than the previous one, indicating an ordering violation. Users can supply a custom policy to handle these violations, with a default implementation that tracks the count of violations and eventually returns an error if too many stale responses are received, helping clients detect and recover from partitioned member issues.

client/v3/ordering · high confidence

Add contention detection utility

Added a new \contention\ package that provides a \TimeoutDetector\ for identifying routine starvations by observing the actual time duration to finish an action or between two events. This utility enables the system to detect when operations exceed expected timeframes, which can indicate underlying system contention or performance issues.

pkg/contention · high confidence

Add endpoint management and watch capabilities to the client/v3/naming API

The client/v3/naming/endpoints package now provides a new Manager interface and implementation for managing service endpoints in etcd. Users can add, delete, and list endpoints using the new Update, AddEndpoint, and DeleteEndpoint methods, and can subscribe to endpoint changes via a WatchChannel. This introduces a structured way to handle endpoint registration and discovery, replacing the previous approach that relied on the deprecated Metadata field in the Endpoint struct.

client/v3/naming/endpoints · high confidence

Add etcd alerting rules to the monitoring mixin

The \contrib/mixin/alerts/alerts.libsonnet\ file has been added, introducing a comprehensive set of Prometheus alerting rules for monitoring etcd cluster health. This includes alerts for member availability, leader election status, gRPC performance, and disk I/O latency, allowing users to detect issues such as cluster members being down, insufficient quorum, high leader change rates, and slow communication or commit durations.

contrib/mixin/alerts · high confidence

Add etcd benchmarking tool

Users can now run the official etcd benchmarking tool to measure cluster performance. The new \tools/benchmark\ directory includes a Go-based utility that can be installed via \go install\ or executed directly with \go run\. It provides a \--help\ interface for running benchmarks against the etcd v3 API.

tools/benchmark · high confidence

Add etcd monitoring dashboards for Grafana 7.x

Introduced new etcd monitoring dashboards for Grafana 7.x, including \etcd-grafana7x.libsonnet\ and supporting modules (\variables.libsonnet\, \targets.libsonnet\, \panels.libsonnet\, and \g.libsonnet\). These files provide a complete dashboard definition for tracking etcd metrics such as RPC rates, leader elections, and peer round-trip times, accessible by enabling the \grafana7x\ configuration option.

contrib/mixin/dashboards · high confidence

Add etcd monitoring mixin to contrib

A new etcd monitoring mixin has been added to the contrib/mixin directory, providing a customizable set of Prometheus alerts and Grafana dashboards for monitoring etcd clusters. The mixin includes alerting rules for conditions such as members being down, insufficient cluster members, high leader change frequency, excessive database growth, and high database fragmentation. It also provides a Grafana dashboard template that supports both Grafana 8.x and 7.x versions, with configuration options for cluster labels, instance labels, and dashboard variable refresh rates.

contrib/mixin · high confidence

Add etcd-backed gRPC naming and resolver package

Users can now discover and resolve gRPC service endpoints via etcd using the new \go.etcd.io/etcd/client/v3/naming\ package, which provides an abstraction layer for storing and reading endpoint information, along with a gRPC resolver and endpoint manager for dynamic service discovery.

client/v3/naming · high confidence

Add etcd-dump-logs tool for analyzing WAL logs

A new \etcd-dump-logs\ utility is introduced to help users inspect and filter etcd Write-Ahead Log (WAL) entries. The tool supports filtering entries by type (e.g., ConfigChange, Normal, Request), specifying start and end indices, and using a custom stream decoder for raw log data. It also provides a \--raw\ mode for low-level log inspection and includes comprehensive tests to verify its functionality.

tools/etcd-dump-logs · high confidence

Add etcd-dump-metrics tool for fetching and documenting Prometheus metrics

A new command-line utility, etcd-dump-metrics, is introduced to automate the collection of Prometheus metrics from etcd. The tool supports fetching metrics from a running endpoint, downloading specific release binaries to fetch metrics from, or starting an embedded two-node cluster to capture peer-to-peer metrics. It parses and formats the metrics output, including server version and gRPC codes, and is available for Linux, macOS, and Windows (with Windows install currently unsupported).

tools/etcd-dump-metrics · high confidence

Add experimental distributed synchronization recipes

The \client/v3/experimental/recipes\ package is introduced, providing a set of experimental client-side distributed synchronization primitives. This includes a \Barrier\ for blocking processes, a \DoubleBarrier\ for collective entry/exit coordination, a \Queue\ for FIFO message passing, a \PriorityQueue\ for ordered message handling, an \RWMutex\ for read-write locking, and helper utilities for key management and event waiting. These components enable building distributed applications with etcd as a coordination service.

client/v3/experimental/recipes · high confidence

Add gRPC experimental API checker tool

A new Go-based tool has been added to the repository to scan the codebase for usage of experimental gRPC APIs. The tool parses Go source files, identifies references to gRPC symbols, and cross-references them against an allowlist of permitted experimental APIs. If any unapproved experimental APIs are detected, the tool exits with an error, enforcing a policy to prevent reliance on unstable gRPC interfaces.

tools/check-grpc-experimental · high confidence

Add gRPC server-to-client adapters for the gRPC proxy

The gRPC proxy now includes a new \adapter\ package that provides client-side wrappers for every gRPC service (Auth, Cluster, Election, KV, Lease, Lock, Maintenance, and Watch). These adapters allow the proxy to call local server handlers as if they were remote gRPC clients, enabling the proxy to forward requests to the local etcd server. The implementation includes a \chanStream\ mechanism to bridge server and client stream interfaces, ensuring that server-streaming RPCs correctly return \io.EOF\ upon successful completion, as required by the gRPC client stream contract.

server/proxy/grpcproxy/adapter · high confidence

Add gRPC testing utilities for interceptors and stub servers

The grpctesting package now includes new recorder and stub server utilities to support gRPC testing. The recorder provides a unary server interceptor that captures request metadata (full method and authority) for verification in tests. Additionally, a StubServer helper is added to easily spin up a local gRPC server for testing, including a NewDummyStubServer convenience function that returns a server responding to UnaryCall with a simple counter-based payload.

pkg/grpctesting · high confidence

Add in-process v3 client wrapper for the etcd server

The v3client package now provides a way to create a clientv3 client that wraps an in-process EtcdServer. This allows applications to interact with the server directly through function calls rather than gRPC sockets, simplifying integration for embedded or in-memory server scenarios.

server/etcdserver/api/v3client · high confidence

Add interval tree implementation to the abstract data types package

The \pkg/adt\ package now includes a new \IntervalTree\ implementation based on a red-black tree, providing methods to insert, delete, and query overlapping intervals. This adds a new capability for users to perform stabbing queries and manage interval ranges efficiently within the etcd codebase.

pkg/adt · high confidence

Add local etcd cluster discovery script

A new 'insta-discovery' script and supporting files (Procfile, README) are added to the hack directory. The script provisions a local three-node etcd cluster using the etcd discovery service, simplifying local testing and development workflows.

hack/insta-discovery · high confidence

Add lock storage example with HTTP API

A new example implementation for lock storage is added, providing an HTTP-based key-value store that supports read and write operations with version checking. The service listens on port 8080 and exposes a JSON API for managing lock state, including handling of concurrent access via versioned writes.

contrib/lock/storage · high confidence

Add mirror syncer for key-value state synchronization

Introduced a new mirror package in the v3 client that provides a Syncer interface for synchronizing the key-value state of an etcd cluster. The Syncer allows clients to fetch the base state and stream updates via channels, handling pagination and revision tracking automatically.

client/v3/mirror · high confidence

Add mock server implementation for testing

A new mock server implementation has been added to the client/v3/mock package, providing a mock gRPC server for the etcd server interface. This includes the MockServer and MockServers structs, along with methods to start, stop, and manage mock servers on TCP or Unix sockets. The mock server implements the KV and Lease server interfaces, allowing for easier testing of client code without needing a full etcd cluster.

client/v3/mock · high confidence

Add mock storage implementation for testing

A new mock storage package has been introduced to provide mock implementations of the etcdserver's storage interface. This includes a StorageRecorder that tracks storage actions like Save, SaveSnap, Release, and Sync, facilitating easier testing of components that depend on storage interfaces.

server/mock/mockstorage · medium confidence

Add namespace package for automatic key prefixing

The client/v3/namespace package provides wrapper types for KV, Lease, and Watcher that automatically prepend a configurable prefix to all keys. This allows users to isolate data by namespace without manually modifying every key in their application code. The implementation handles prefixing for Put, Get, Delete, and transaction operations, and strips the prefix from responses and watch events.

client/v3/namespace · high confidence

Add pkg/expect package for process interaction and testing

The new pkg/expect package provides an expect-style interface for managing and interacting with external processes. It allows tests to spawn processes, send input, and match output lines (including regular expressions) with configurable timeouts. The implementation includes utilities for handling process signals, tracking exit codes, and managing process lifecycle, supporting both interactive and automated testing scenarios.

pkg/expect · high confidence

Add pprof HTTP handlers for Go runtime profiling

The debugutil package now exposes a set of HTTP handlers for Go's pprof profiling tools. These handlers are registered under the /debug/pprof path and include endpoints for index, profile, symbol, cmdline, trace, heap, goroutine, threadcreate, block, and mutex profiling. This enables users to collect runtime performance data via standard pprof endpoints.

pkg/debugutil · high confidence

Add proto-annotation tool to extract etcd\_version annotations

A new command-line tool has been added to the proto-annotations package to extract and print etcd\_version annotations from all protobuf definitions used by etcd. The tool scans the protobuf registry, filters out external packages (such as grpc.gateway and prometheus), and outputs the version annotations in a structured format. This enables users to verify that all newly introduced proto definitions include the required etcd\_version annotation, facilitating version tracking and validation.

tools/proto-annotations/cmd · high confidence

Add server-side verification of persisted state

A new \server/verify\ package has been introduced to analyze the persistent state of etcd, specifically cross-checking the consistency between the WAL (Write-Ahead Log) and the backend storage. This new verification framework checks that the consistent index and term in the backend match or are consistent with the WAL's hard state, and will skip verification if the database file does not exist. This provides a mechanism to detect potential data inconsistencies in the data directory.

server/verify · high confidence

Add static validation to etcd\_version proto annotation

A new Go tool at tools/proto-annotations has been introduced to perform static validation on proto annotations, specifically for the etcd\_version field. This addition supports improved documentation and a refactored approach to handling WAL versioning via a visitor pattern, enhancing the reliability of proto annotation checks.

tools/proto-annotations · medium confidence

Add string normalization utility for etcdctl

A new \Normalize\ function has been added to the \etcdctl/util\ package. This utility trims leading and trailing whitespace from a string and adds a two-space indentation to each line, providing a reusable helper for formatting text in the CLI tool.

etcdctl/util · high confidence

Add string utility functions for generating random strings

The pkg/stringutil package now includes new utility functions for generating random strings. Specifically, it adds the UniqueStrings and RandomStrings functions, which generate slices of random strings of a specified length and count. The implementation uses the math/rand package to create these strings, and corresponding tests verify that UniqueStrings produces distinct values.

pkg/stringutil · high confidence

Add systemd service and user configuration for etcd

Users can now deploy etcd as a managed service on Linux systems using systemd. This change introduces a new \etcd.service\ unit file for single-node deployments, a \sysusers\ configuration to automatically create the \etcd\ system user and its data directory, and a comprehensive README with step-by-step instructions for setting up a multi-node etcd cluster using individual systemd service files.

contrib/systemd · high confidence

Add testgrid-analysis tool to detect flaky tests

A new Go-based CLI tool has been added at tools/testgrid-analysis to analyze Testgrid test results and identify flaky tests. The tool fetches data from the Testgrid API, calculates failure rates, and can automatically generate GitHub issues for tests that exceed a configurable failure threshold, helping developers track and address intermittent test failures.

tools/testgrid-analysis · high confidence

Add user\_add.sh script for gRPC gateway authentication

A new shell script, user\_add.sh, has been added to the client/v3/experimental/recipes/grpc\_gateway directory. This script provides a command-line utility for authenticating with the etcd gRPC gateway and adding new users, utilizing curl to interact with the /auth/authenticate and /auth/user/add endpoints.

_client/v3/experimental/recipes/grpc\gateway · high confidence

Add v2 in-memory key/value store implementation

The v2store package introduces the in-memory key/value store for the v2 API, including the core store, node, and event handling logic. It provides the \Store\ interface and its implementation, along with metrics, stats, and TTL support. The change also adds comprehensive unit tests for the store, node, and stats components.

server/etcdserver/api/v2store · high confidence

Add v3 discovery support for bootstrapping new etcd clusters

The v3discovery package now provides the implementation for cluster discovery using the v3 client, enabling the bootstrapping of new etcd clusters. This change introduces the \GetCluster\ and \JoinCluster\ functions, which allow clients to retrieve cluster information and register members via a discovery service. The \DiscoveryConfig\ struct, which includes a \ConfigSpec\ for client configuration, is defined to support these operations.

server/etcdserver/api/v3discovery · high confidence

Add v3 election and lock server implementations

The etcd server now includes concrete implementations for the v3 election and lock APIs. The v3election package provides the ElectionServer, implementing Campaign, Proclaim, Observe, Leader, and Resign operations using the concurrency package. The v3lock package provides the LockServer, implementing Lock and Unlock operations via distributed mutexes. These changes expose the underlying concurrency primitives through the gRPC API.

server/etcdserver/api/v3election, server/etcdserver/api/v3lock · high confidence

Add wait and wait-time utilities for event and deadline-based synchronization

The codebase now includes a new \pkg/wait\ package providing two synchronization abstractions. The \Wait\ interface and its \list\ implementation allow callers to register for events by ID and trigger them, using a sharded array of maps with RWMutexes to reduce lock contention. Additionally, a \WaitTime\ interface and \timeList\ implementation provide logical deadline-based waiting, where channels are triggered when a deadline is reached. Tests and benchmarks for both utilities are included.

pkg/wait · high confidence

Added CRC-32 utility package with test coverage

A new 'crc' package has been added to provide a utility for computing CRC-32 checksums. The package exposes a 'New' function that accepts a previous CRC value and a table, allowing for incremental checksum computation. A corresponding test file verifies that the implementation behaves identically to the standard library's CRC-32 logic, including handling of initial states and resets.

pkg/crc · high confidence

Added DNS SRV record lookup for cluster and client discovery

The client package now includes a new srv package that provides functions to look up DNS SRV records for discovering cluster members and client endpoints. This includes logic to handle SRV record lookups for both cluster and client discovery, with support for both HTTP and HTTPS schemes. The implementation includes unit tests to verify the correct parsing of SRV records and handling of edge cases like missing records or scheme mismatches.

client/pkg/srv · high confidence

Added TLS 1.3 and configurable cipher suite support

The client's TLS utility package now includes support for TLS 1.3 and allows for configurable cipher suites. New functions \GetTLSVersion\ and \GetCipherSuite\ enable users to explicitly select TLS 1.3 or specific cipher suites, with corresponding tests verifying the mapping of version strings and cipher names to their underlying constants.

client/pkg/tlsutil · high confidence

Added local-tester network bridge with failure injection capabilities

The local-tester network bridge tool was added, providing a new utility for simulating network failures and conditions during testing. This new component supports injecting packet corruption, reordering, and configurable transmit/receive delays, as well as blackholing, one-way traffic, and random connection closures. The tool is marked as deprecated in favor of the etcd robustness testing suite.

tools/local-tester/bridge · high confidence

Added pbutil package for Protocol Buffer utilities

The pkg/pbutil package was introduced to provide helper functions for handling Protocol Buffer objects. This includes interfaces and wrappers for marshaling and unmarshaling (MustMarshal, MustUnmarshal, MaybeUnmarshal) as well as specific support for proto.Message types (MustMarshalMessage, MustUnmarshalMessage). Additionally, utility functions for handling boolean pointers (GetBool, Boolp) were added. The change also includes corresponding unit tests for these new capabilities.

pkg/pbutil · high confidence

Added proxy fixture files for certificate generation

The repository now includes a new set of fixture files in pkg/proxy/fixtures to support generating test certificates. This includes configuration files (ca-csr.json, gencert.json, server-ca-csr.json) and the gencerts.sh script, which uses cfssl to generate a CA certificate and a server certificate for localhost/127.0.0.1. The generated CA and server certificates (ca.crt, server.crt) and the server's insecure private key (server.key.insecure) are also included.

pkg/proxy/fixtures · high confidence

Added v2stats package for cluster and server statistics

The v2stats package was added to the server directory, introducing new types for tracking cluster leader and follower statistics (LeaderStats, FollowerStats, LatencyStats, CountsStats) and server-level metrics (ServerStats, statsQueue). These components provide JSON-serializable statistics about communication with followers, request rates, and bandwidth usage, integrating with the raft module to monitor node states and message traffic.

server/etcdserver/api/v2stats · high confidence

Added version annotations to protocol buffer definitions

The \api/versionpb\ package now includes generated Go code and proto definitions that annotate messages, fields, enums, and enum values with etcd version information. These annotations allow the system to detect the etcd version that generated the WAL (Write-Ahead Log), enabling better compatibility checks and version tracking for data interpretation.

api/versionpb · high confidence

Centralized gRPC error definitions and types in api/v3rpc/rpctypes

The v3 RPC error types and their corresponding gRPC status codes are now defined in the centralized \api/v3rpc/rpctypes\ package. This change introduces a unified set of server-side error variables (e.g., \ErrGRPCKeyNotFound\, \ErrGRPCAuthFailed\) mapped to specific gRPC codes (e.g., \codes.InvalidArgument\, \codes.PermissionDenied\), along with client-side error wrappers. This allows both the etcd server and client to share consistent error handling and reporting for all v3 RPC interactions.

api/v3rpc · high confidence

Centralized server configuration and v2 deprecation controls

The server configuration is now consolidated in the \server/config\ package, introducing a \ServerConfig\ struct that exposes key tuning parameters such as \MaxConcurrentStreams\ for HTTP/2, \MemoryMlock\ for memory locking, and \BootstrapDefragThresholdMegabytes\ for bootstrap defragmentation. Additionally, the \v2\_deprecation.go\ file introduces a \V2DeprecationEnum\ with levels (e.g., \write-only\, \gone\) that allow users to control the deprecation state of the v2 API, with corresponding tests verifying the deprecation level logic.

server/config · high confidence

Centralized tool dependency management via tools/mod

The project now uses a dedicated \tools/mod\ directory to explicitly track and manage all tool dependencies (such as golangci-lint, protoc-gen-go, and various linters) as Go modules. This change ensures that \go mod tidy\ preserves these tool dependencies and prevents them from being removed, providing a single, auditable location for all build and development tool versions.

tools/mod · high confidence

Client-side leasing for linearizable reads

Added a new \client/v3/leasing\ package that enables linearizable reads from a local cache by acquiring exclusive write access to keys through a client-side leasing protocol. This allows multiple clients to have write access while serving cached reads, improving performance for read-heavy workloads.

client/v3/leasing · high confidence

Establishes etcd's security response process and reporting channels

The security directory now contains the foundational documentation for handling vulnerabilities, including a README outlining how to report security issues to [e-mail redacted], a detailed security release process managed by the Product Security Committee, and email templates for security announcements. This change provides users with a clear, structured path for responsible disclosure and ensures the community understands the timeline and procedures for security fixes.

security · high confidence

Expose lease renewal and time-to-live via HTTP endpoints

The server now exposes HTTP handlers for lease keep-alive and lease time-to-live operations, allowing clients to renew leases and query lease status via HTTP requests. The implementation includes a new HTTP handler that processes lease renewal requests and returns TTL information, with support for both public and internal lease endpoints. The code includes comprehensive tests for lease renewal and time-to-live operations, including timeout handling. This change enables HTTP-based lease management alongside existing gRPC interfaces.

server/lease/leasehttp · high confidence

Initial project structure and development environment setup

The repository is initialized with essential project infrastructure files, including a .gitignore to exclude build artifacts and IDE files, a .go-version file specifying Go 1.26.5, a .header file for copyright headers, and a Dockerfile for containerized builds. Additionally, the project establishes its governance model in GOVERNANCE.md, defines the developer certificate of origin in DCO, and provides a comprehensive guide for contributors in CONTRIBUTING.md.

(repo-wide) · high confidence

Introduce Kubernetes KV interface to etcd client

The etcd Go client now includes a new \client/v3/kubernetes\ package that provides a Kubernetes-specific key-value interface. This new client exposes methods for \Get\, \List\, \Count\, \OptimisticPut\, and \OptimisticDelete\ operations, allowing users to interact with etcd using semantics tailored for Kubernetes workloads.

client/v3/kubernetes · high confidence

Introduce etcd-dump-db diagnostic tool

The \etcd-dump-db\ utility is introduced to inspect etcd database files. Users can now list all buckets, compute a hash of the database, iterate through key-value pairs in reverse order, and scan the key space starting from a specific revision. The tool supports decoding Protocol Buffer encoded data for buckets such as \key\, \lease\, \auth\, \authRoles\, \authUsers\, and \meta\, providing a more friendly and structured output for debugging and analysis.

tools/etcd-dump-db · high confidence

Introduce etcdutl as a dedicated utility for direct file operations

A new \etcdutl\ command-line tool is introduced to handle direct operations on etcd data files, such as snapshot restore, hash verification, and defragmentation, separating these administrative tasks from the network-based \etcdctl\ commands. The utility includes commands for snapshot management, hash verification, and version reporting, along with shell completion and a global timeout flag for file locking.

etcdutl · high confidence

Introduce etcdutl utility commands for storage management

The \etcdutl\ tool now includes new commands for managing etcd storage: \migrate\ to upgrade the storage schema to a target version, \snapshot restore\ to restore from a snapshot file with optional revision bumping and compaction marking, \snapshot status\ to inspect snapshot metadata, \hashkv\ to compute a hash of the keyspace, and \defrag\ to defragment a data directory. A shared \common.go\ provides helper functions like \validateDataDir\ and \getLatestWALSnap\, while \printer\ modules support simple, JSON, protobuf, and table output formats for these commands.

etcdutl/etcdutl · high confidence

Introduce experimental etcd client cache

A new \cache\ package provides an in-memory cache for etcd watch streams, allowing clients to receive events with guaranteed monotonicity and atomic delivery. The cache buffers a single upstream watch, fan-outs to multiple local watchers, and replays historical events to catch up lagging clients. It supports progress notifications, configurable history window sizes, and is designed to work with consistent reads. Note: gRPC proxy is not supported as the cache relies on \RequestProgress\ RPCs which the proxy does not forward.

cache · high confidence

Introduce idutil package for generating unique identifiers

The idutil package provides a Generator for creating unique, randomized 64-bit identifiers composed of a member ID prefix, a timestamp, and an atomic counter. This implementation uses an atomic variable for the count field to reduce the ID conflict rate from 1% to 0.005%, effectively extending the event window to 2^48.

pkg/idutil · medium confidence

Introduce local-tester tool for fault-injected local cluster testing

A new local-tester tool is added to the repository, providing a way to run a fault-injected etcd cluster using local processes. The tool uses a Procfile to manage multiple processes including peer and client network bridges, fault injection scripts, and stress tests. The bridge script simulates unreliable network conditions, while the faults script periodically kills cluster members and disrupts bridge connectivity. The tool also supports failpoints for more advanced fault injection scenarios. The README includes a warning that this tool is deprecated in favor of the robustness testing suite.

tools/local-tester · high confidence

Introduce network fault-injection proxy server

The \pkg/proxy\ package now provides a \Server\ interface and implementation that simulates network faults such as latency, packet drops, and corruption. This allows users to test their applications' resilience to network issues by injecting controlled delays, pauses, or data modifications into the connection layer.

pkg/proxy · high confidence

Introduce new etcdctl commands for alarms, auth status, and cluster checks

The etcdctl v3 CLI now includes new subcommands for managing and inspecting the cluster. Users can now check the health of endpoints and verify if there are active alarms using the new 'endpoint health' and 'endpoint status' commands. Authentication management is enhanced with 'auth status' to check the current state, and 'alarm' commands to list or disarm cluster alarms. Additionally, a 'check' command is introduced with 'perf' and 'datascale' subcommands to benchmark and validate cluster performance and storage scale. These additions provide better observability and maintenance capabilities for cluster administrators.

etcdctl/ctlv3/command · high confidence

Introduce new flag value types and environment variable support in pkg/flags

The \pkg/flags\ package has been reorganized and expanded with new flag value types: \SelectiveStringValue\ and \SelectiveStringsValue\ for validating against a set of allowed strings; \StringsValue\ for comma-separated string slices; \UniqueStringsValue\ and \UniqueURLs\ for deduplicated string and URL lists; and \uint32Value\ for 32-bit unsigned integers. Additionally, \SetFlagsFromEnv\ and \SetPflagsFromEnv\ now support reading flag values from environment variables, with validation and logging of conflicting or unrecognized environment variables.

pkg/flags · high confidence

Introduce structured tracing utility package

A new \pkg/traceutil\ package has been added to provide structured tracing capabilities. It introduces a \Trace\ type that records operation steps, sub-traces, and key-value fields, integrating with OpenTelemetry for trace context propagation. The implementation supports configurable step logging thresholds to control log volume and ensures stable message names with trace IDs and operation names as structured fields for better observability.

pkg/traceutil · high confidence

Introduce verification framework with environment-controlled assertions

A new verification package has been added to the client codebase, providing a mechanism to enable or disable specific verification checks via the ETCD\_VERIFY environment variable. This includes a generic Assert function that panics on failure, and a Verify function that conditionally executes checks based on the environment. This allows users to enable additional consistency checks during testing or debugging without affecting production behavior.

client/pkg/verify · high confidence

Introduced AlarmStore for managing etcd server alarms

Added a new AlarmStore implementation in the v3alarm package that manages the lifecycle of server alarms. This change introduces a persistent alarm store that interacts with the backend storage via a new AlarmBackend interface, allowing for activation, deactivation, and retrieval of member alarms.

server/etcdserver/api/v3alarm · high confidence

Introduces a new gRPC proxy cache for range requests

A new cache implementation for the gRPC proxy has been added to store and retrieve cached RangeResponse objects. The cache uses an LRU (Least Recently Used) strategy, with a default maximum of 2048 entries, and includes logic to handle compaction and invalidation of cached responses based on key ranges.

server/proxy/grpcproxy/cache · high confidence

Introduction of a thread-safe notification mechanism

A new \Notifier\ struct has been added to the \pkg/notify\ package, providing a thread-safe way to broadcast events to multiple consumers. The implementation uses a read-write lock to manage a channel that is closed to signal consumers, and a new channel is created for each subsequent notification cycle.

pkg/notify · high confidence

New FIFO scheduler for sequential job execution

A new package, pkg/schedule, has been introduced to provide mechanisms and policies for scheduling units of work. It includes a FIFO (First-In-First-Out) scheduler that executes jobs sequentially, ensuring that tasks are processed in the order they are scheduled. The implementation includes a Job interface, a Scheduler interface, and a concrete fifo scheduler that supports scheduling, waiting for completion, and graceful shutdown. Tests verify that jobs are executed in the correct order and that the scheduler handles panics and cleanup correctly.

pkg/schedule · high confidence

New HTTP utility functions for connection reuse and host extraction

The \pkg/httputil\ package now includes two new utility functions. \GracefulClose\ drains the response body before closing it, which helps keep TCP/TLS connections available for reuse. \GetHostname\ extracts the hostname from an HTTP request's Host header, handling edge cases like missing ports or invalid formats. A corresponding test suite validates the new \GetHostname\ behavior.

pkg/httputil · high confidence

New TLS setup example for etcd cluster

A new example in the hack/tls-setup directory demonstrates how to generate TLS certificates for an etcd cluster using Cloudflare's cfssl tool. The setup includes a Makefile to automate certificate generation, a Procfile to run the etcd nodes and proxy with mutual TLS authentication, and a README with instructions to configure IP addresses for the cluster nodes.

hack/tls-setup · high confidence

New benchmark report generation and raw data exposure

The \pkg/report\ package now provides structured benchmark reporting capabilities. Users can generate JSON reports for the PerfDash dashboard, which includes 50th, 90th, and 99th percentile latencies. Additionally, the \Report\ interface exposes raw statistical data via a new \Stats()\ method, allowing access to detailed metrics such as average, fastest, slowest, standard deviation, and error distributions.

pkg/report · high confidence

New cobrautl package for shared CLI utilities

A new \pkg/cobrautl\ package has been introduced to centralize common Cobra CLI utilities, including error handling and help formatting. This refactors shared code previously located in \etcdctl\ and the main package into a reusable library, making these helpers available for other tools. The package provides functions for standardized exit codes and custom usage templates for Cobra commands.

pkg/cobrautl · high confidence

New datadir package for etcd storage paths

The storage package now includes a new 'datadir' sub-package that provides utility functions for constructing file-system paths for etcd's data directory, including member, snapshot, and WAL directories. A corresponding test suite verifies the path construction logic for these storage components.

server/storage/datadir · high confidence

New distributed locking example for etcd

Added an example implementation of a distributed lock with fencing using etcd's client/v3 concurrency package. The new \contrib/lock/client\ directory contains a Go program that demonstrates acquiring a lock, performing a write operation, and handling lease expiration, serving as a practical reference for building distributed locking mechanisms.

contrib/lock/client · high confidence

New file and directory utility functions in client/pkg/fileutil

The fileutil package in the client package now includes new utilities for file operations, including directory management (TouchDirAll, CreateDirAll, IsDirWriteable, CheckDirPermission), file locking (LockFile, TryLockFile with platform-specific implementations for Linux, Windows, Solaris, and Plan9), file purging (PurgeFile), and file reading (FileReader, FileBufReader). These changes introduce new capabilities for managing temporary files, ensuring directory permissions, and handling file locks across different operating systems.

client/pkg/fileutil · high confidence

New ioutil utilities: PageWriter, ExactReadCloser, LimitedBufferReader, and WriteAndSyncFile

The pkg/ioutil package now includes several new I/O utilities. A page-aligned buffered writer (PageWriter) is added to handle writes in page-sized chunks with configurable offsets. An exact read closer (ExactReadCloser) ensures that a specified number of bytes are read before signaling EOF, returning specific errors for short reads or unexpected EOF. A limited buffer reader restricts the amount of data returned from an underlying reader. Additionally, a file writing utility (WriteAndSyncFile) is provided that writes data to a file and ensures it is synced to disk. These additions expand the available I/O primitives for handling structured or constrained data flows.

pkg/ioutil · high confidence

New scripts for building, releasing, and testing etcd

Added a suite of new scripts in the \scripts/\ directory to support the release process, build pipeline, and testing infrastructure. This includes \build.sh\ and \build\_lib.sh\ for compiling binaries and tools, \build-docker.sh\ and \build-release.sh\ for creating multi-architecture Docker images and release artifacts, and \release.sh\ and \release\_mod.sh\ for managing version bumps, tagging, and publishing releases. Additionally, \benchmark\_test.sh\ provides a script for running local benchmarks, \fuzzing.sh\ enables fuzz testing, and \cherrypick.sh\ automates cherry-picking pull requests. The \genproto.sh\ script is also introduced to generate Protocol Buffer bindings. These scripts collectively streamline the development, testing, and release workflows for the project.

scripts · high confidence

New scripts/fix shell scripts for build and linting tasks

Added new executable scripts in the scripts/fix/ directory to handle specific maintenance tasks: bom.sh generates the bill of materials, mod-tidy.sh tidies Go module files, shell\_ws.sh fixes whitespace in bash scripts, sync\_go\_toolchain\_directive.sh updates Go toolchain directives, and yamllint.sh fixes YAML linting issues. These scripts encapsulate previously embedded or separate logic into dedicated, reusable utilities.

scripts/fix · high confidence

Rewrite of the benchmarking tool with expanded command set

The \tools/benchmark\ utility has been completely rewritten to provide a comprehensive suite of performance testing commands. The tool now supports benchmarking put, range, watch, STM (short transactional memory), and lease keepalive operations. New subcommands include \mvcc\ for low-level storage benchmarking, \stm\ for testing transaction isolation levels, and \watch-latency\ for measuring watch event delays. The implementation migrates to the \clientv3\ API, supports connecting to multiple endpoints, and includes options for rate limiting, TLS, and detailed reporting.

tools/benchmark/cmd · high confidence

Snapshot save now returns the etcd server version

The \SaveWithVersion\ function in the client/v3/snapshot package has been updated to return the etcd server version alongside the snapshot data. This allows users to verify the version of the etcd cluster from which the snapshot was taken, which was previously not returned by the snapshot utility.

client/v3/snapshot · high confidence

etcdctl: Add LICENSE, OWNERS, and README documentation

The etcdctl directory now includes an Apache 2.0 LICENSE file, an OWNERS file designating the area as 'area/etcdctl', and a comprehensive README.md documenting the v3 API usage, global flags, and key-value commands. This establishes the standard project governance and documentation for the tool.

etcdctl · high confidence

Architecture

Refactored MVCC storage and indexing into a new 'storage' package

The MVCC storage implementation has been reorganized into a dedicated 'server/storage/mvcc' package, moving files such as index.go, key\_index.go, and hash.go into this new structure. This change improves code organization and introduces a clearer separation of concerns within the storage layer, while also including new benchmark tests for the index and store operations.

server/storage/mvcc · high confidence

Refactored and expanded the Write-Ahead Log (WAL) storage implementation

The Write-Ahead Log (WAL) storage implementation has been significantly refactored and expanded. The core logic has been moved into the \server/storage/wal\ package, introducing new files for encoding, decoding, and file pipeline management. A new \version.go\ module was added to detect the minimal etcd version required to interpret WAL entries, enabling better version compatibility checks. Additionally, a \repair.go\ module was introduced to handle corrupted or truncated WAL files by truncating them to the last valid record. The \Decoder\ interface was also exposed as a package-visible interface to allow tools to access WAL entry types.

server/storage/wal · high confidence

Refactored etcdserver bootstrap and cluster management into dedicated modules

The server/etcdserver package has been restructured to improve modularity and reduce cyclic dependencies. The bootstrap logic has been extracted into a new \bootstrap.go\ file, which handles the initialization of the Raft node, WAL, and storage. Additionally, cluster utility functions and corruption checking logic have been moved to dedicated files (\cluster\_util.go\ and \corrupt.go\), and the HTTP error handling has been encapsulated in \api/etcdhttp/types/errors.go\. These changes isolate specific responsibilities, making the server startup and cluster state management easier to maintain and test.

server/etcdserver · high confidence

Refactored server apply logic into a modular applier chain

The server's raft message application logic has been restructured into a modular, chainable applier system within the new \server/etcdserver/apply\ package. This change introduces an \UberApplier\ that wraps a stack of specialized appliers—including \authApplierV3\ for permission checks, \quotaApplierV3\ for storage limits, and \applierV3Corrupt\ for data integrity—allowing each concern to be handled in isolation. This refactoring improves code maintainability and makes it easier to reason about the order of operations, such as ensuring authentication checks occur before quota enforcement.

server/etcdserver/apply · high confidence

Restructured gRPC proxy into modular components

The gRPC proxy implementation has been reorganized into distinct, single-responsibility files (auth, cluster, election, health, kv, leader, lease, lock, maintenance, metrics, register, util, watch, and watcher) to improve code maintainability and separation of concerns within the server/proxy/grpcproxy package.

server/proxy/grpcproxy · high confidence

Restructured v3 RPC server into a modular, interface-based architecture

The v3 RPC server has been refactored into a modular architecture where each gRPC service (KV, Watch, Lease, Auth, etc.) is implemented as a distinct struct (e.g., \kvServer\, \LeaseServer\) that wraps the \EtcdServer\ and implements the corresponding protobuf \Unsafe\ interface. This change introduces a cleaner separation of concerns, with dedicated files for each service (e.g., \key.go\, \lease.go\, \auth.go\) and a unified error translation layer (\util.go\) that maps internal errors to appropriate gRPC status codes. Additionally, the gRPC server setup in \grpc.go\ now chains interceptors for logging, metrics, and distributed tracing, while the health notifier dynamically updates the gRPC health status based on the defrag state.

server/etcdserver/api/v3rpc · high confidence

Behavioural changes

Add support for etcd 3.6, 3.7, and 3.8 in capability management

The server's capability management system has been updated to recognize and enable features for etcd versions 3.6, 3.7, and 3.8. This change ensures that the cluster correctly identifies supported versions and activates the corresponding capabilities (such as 'auth' and 'v3rpc') for these newer releases.

server/etcdserver/api · high confidence

Add test decoders for etcd log parsing

Two new shell scripts, decoder\_correctoutputformat.sh and decoder\_wrongoutputformat.sh, have been added to the etcd-dump-logs testdecoder directory. These scripts process input lines by replacing digits with letters, allowing the etcd log dumping tool to be tested against both correctly and incorrectly formatted output.

tools/etcd-dump-logs/testdecoder · medium confidence

Added Apache 2.0 license and Go module guard configuration for the server package

The server directory now includes an Apache 2.0 license file and a \.gomodguard.yaml\ configuration that blocks specific etcd dependencies (go.etcd.io/etcd, go.etcd.io/etcd/tests/v3, go.etcd.io/etcd/v3) as forbidden. Additionally, a \main.go\ entrypoint was added to wrap the etcd main package, ensuring the module remains 'go getable'.

server · high confidence

Added v2 error handling types and tests

Added the v2 error handling package, including error codes, HTTP status mappings, and the Error struct with serialization and HTTP writing capabilities, along with corresponding unit tests.

server/etcdserver/api/v2error · medium confidence

Backend storage and quota management moved to the storage package

The backend storage and quota management logic has been moved to the server/storage package. This includes the backend initialization, snapshot recovery, and quota enforcement (including the cost calculation for transactions and puts). The storage package now owns the Storage interface and the BackendHooks for managing consistent index and configuration state. This change reorganizes the codebase to separate storage concerns from the server layer, improving modularity and testability.

server/storage · high confidence

Centralized linting and formatting configuration for the tools directory

The \tools\ directory now includes dedicated configuration files to enforce code quality and style standards. A new \tools/.golangci.yaml\ file centralizes Go linting rules, enabling a comprehensive set of linters (including \errorlint\, \gofmt\, \golangci-lint\ settings, and \testifylint\ rules) and formatters (\gci\, \gofmt\, \goimports\). Additionally, new configuration files \.markdownlint.jsonc\, \.yamlfmt\, and \.yamllint\ are introduced to standardize Markdown, YAML formatting, and YAML linting respectively. These changes ensure consistent code style and automated checks for all files within the \tools\ directory.

tools · high confidence

Centralized version and downgrade management logic

The version and downgrade detection logic has been moved into a new \server/etcdserver/version\ package. This includes the \Monitor\ for tracking cluster and storage versions, the \Manager\ for handling downgrade enable/cancel/validate operations, and helper functions for version validation. This refactoring consolidates previously scattered version-checking code, making the downgrade process more robust and easier to test.

server/etcdserver/version · high confidence

Centralized version management and new version constants

The version package has been moved to a centralized location (api/version) and now defines all supported versions (V3\_0 through V4\_0) as constants, along with helper functions for comparison. The current version has been updated to 3.8.0-alpha.0, and the package now relies on the Masterminds semver library for version parsing and comparison.

api/version · high confidence

Improved URL comparison and host resolution in netutil

The netutil package now normalizes and compares URLs by host, including proper handling of IPv6 addresses and ports. The \URLStringsEqual\ function has been updated to resolve hostnames to IP addresses before comparison, ensuring that URLs with hostnames and their corresponding IP addresses are treated as equal. Additionally, a new \urlsHostNormalizedEqual\ function and \normalizeHost\ helper ensure consistent formatting of IPv6 addresses. The \GetDefaultHost\ and \GetDefaultInterfaces\ functions are now implemented for Linux, allowing the system to identify the default network interface and its IP address.

pkg/netutil · high confidence

Improved process shutdown and signal handling

The \osutil\ package now provides a robust, cross-platform mechanism for handling interrupt signals (SIGINT/SIGTERM). On Unix systems, the new \HandleInterrupts\ function executes registered handlers and then resets the signal disposition to \SIG\_DFL\ before re-sending the signal to ensure a clean shutdown. A specific fix ensures that PID 1 (the init process) exits directly rather than attempting to kill itself, which would be ineffective. Windows builds receive a no-op implementation for these functions. This change improves graceful shutdown behavior for the application.

pkg/osutil · high confidence

Improved snapshot status reporting and integrity verification

The snapshot utility now provides more detailed status information, including the etcd version stored in the snapshot file and a hash of the snapshot contents. The status command also performs integrity checks on the snapshot file, reporting errors for corrupt revisions or negative revision numbers. Additionally, the tool now uses a map to count unique user keys, ensuring that tombstoned (deleted) keys are not double-counted, which improves the accuracy of the total key count in the status output.

etcdutl/snapshot · high confidence

Introduced local feature gate implementation to replace k8s dependency

The \pkg/featuregate\ package now provides a local implementation of the feature gate system, copied from k8s.io/component-base@v0.30.1, to eliminate circular dependencies with k8s packages. This change introduces the \featuregate\ package with its associated tests, allowing users to manage feature flags via command-line flags (e.g., \--feature-gates\) without relying on external Kubernetes libraries.

pkg/featuregate · high confidence

Lease management code moved to server/lease

The lease management implementation, including the Lessor, Lease, and queue structures, has been moved into the new server/lease package. This change reorganizes the codebase by separating lease-related logic from the broader server directory, providing a dedicated location for lease lifecycle management, metrics, and associated tests.

server/lease · high confidence

Major overhaul of the Go client/v3 library

The client/v3 package has been significantly refactored and expanded. Key changes include replacing the custom load-balancing logic with standard gRPC components, adding backoff and retry logic for watch streams and authentication, and introducing a new block logger for throttling log output. The client now supports setting a custom Zap logger, allows configuring backoff parameters, and includes improved error handling for authentication tokens and unavailable endpoints. Additionally, the codebase has been cleaned up with stricter linting, updated dependencies, and comprehensive test coverage for the new behaviors.

client/v3 · medium confidence

Membership data is now persisted to the backend store

The membership package has been refactored to persist cluster state to the backend storage. The \RaftCluster\ now uses a \MembershipBackend\ interface to read and write member data, allowing the cluster to recover its state from the backend on startup. This change ensures that membership information is no longer solely held in memory or in the v2 store, but is instead stored in the backend, improving data durability and recovery capabilities.

server/etcdserver/api/membership · high confidence

Migrate authpb to Google's protobuf-go and update enum naming

The authpb package has been regenerated using Google's protobuf-go library (v1.36.11) instead of the previous gogo/protobuf implementation. This migration changes the generated Go code's internal structure and naming conventions. Specifically, the enum constants for permissions are now namespaced under the type (e.g., \Permission\_READ\ instead of \READ\). To maintain backward compatibility, the old names (\READ\, \WRITE\, \READWRITE\) are preserved as deprecated aliases in \deprecated.go\, which will be removed in a future release.

api/authpb · high confidence

Migrate etcd API to Google's protobuf library

The \api/etcdserverpb\ package has been regenerated using the \google.golang.org/protobuf\ library instead of the previous \gogo/protobuf\ implementation. This change updates the generated Go code for all proto messages and services (including \rpc.proto\ and \raft\_internal.proto\), which may require users to update their dependencies to the new protobuf library. The migration includes the addition of a \RangeStream\ RPC to the KV service and the introduction of version annotations to detect the etcd version that generated the WAL.

api/etcdserverpb · high confidence

Migrate mvccpb Event types to nested enum and add helper methods

The mvccpb package now uses nested enums for event types (Event\_PUT, Event\_DELETE) instead of the previous flat constants, with deprecated aliases (PUT, DELETE) provided for backward compatibility. Additionally, the Event type now includes helper methods IsCreate() and IsModify() to simplify checking whether an event represents a new key creation or a modification of an existing key.

api/mvccpb · medium confidence

Migrate snapshotter to use the new raft module go.etcd.io/raft/v3

The snapshotter implementation in the server has been updated to use the new raft module go.etcd.io/raft/v3. This change updates the snapshotter to work with the new raft module, ensuring compatibility with the latest raft protocol and features.

server/etcdserver/api/snap · high confidence

Migrated test utilities to client/pkg/testutil

The test utility package has been moved from the root \pkg/\ directory to \client/pkg/testutil\. This relocation includes the full suite of testing helpers such as \assert.go\ (containing deprecated assertion functions like \AssertNil\ and \AssertTrue\), \leak.go\ (goroutine leak detection), \before.go\ (test setup and cleanup), \pauseable\_handler.go\, \recorder.go\, \testingtb.go\, \testutil.go\, and \var.go\. Users relying on the previous \pkg/testutil\ path will need to update their imports to \client/pkg/testutil\.

client/pkg/testutil · high confidence

Move and expose etcd v3 client credentials implementation

The gRPC credential implementation for the v3 client has been moved to the client/v3/credentials package. This change exposes the credential bundle and transport credential constructors, allowing users to configure authentication tokens and TLS settings for the v3 client. A corresponding test file was added to verify the token update functionality.

client/v3/credentials · high confidence

Moved and expanded the client/pkg/types package with new utility types

The \client/pkg/types\ package has been moved from the root \pkg/\ directory to \client/pkg/types\ to better reflect its usage within the client codebase. This change introduces several new types and utilities, including \ID\ for handling identifiers as base-16 strings, \URLs\ and \URLsMap\ for managing and parsing endpoint lists, and \Set\/\ThreadsafeSet\ for managing string collections. The move is accompanied by comprehensive test coverage for all new types, ensuring correct behavior for sorting, stringification, and error handling.

client/pkg/types · high confidence

Moved concurrency primitives to client/v3/concurrency

The concurrency package, which provides distributed locks, barriers, and elections, has been moved to the client/v3/concurrency directory. This change reorganizes the codebase structure without altering the public API or behavior of the concurrency primitives.

client/v3/concurrency · high confidence

Moved mock implementations to new server/mock directories

The mock implementations for the store and wait packages have been relocated from the previous locations to new directories under server/mock (specifically server/mock/mockstore and server/mock/mockwait). This change reorganizes the codebase structure, moving the mock store recorder and wait recorder into their respective new packages, which may affect how these testing utilities are imported and used in other parts of the server codebase.

server/mock/mockstore · high confidence

New endpoint parsing and credential requirement logic

The client now uses a new internal \endpoint\ package to parse endpoint strings and determine whether credentials are required. The \Interpret\ function extracts the address and server name, while \RequiresCredentials\ returns whether a connection needs certificates based on the scheme (e.g., \https\ or \unixs\ require credentials, \http\ drops them). This replaces the previous balancer-based approach with a more direct translation of etcd endpoint formats (including \unix\, \unixs\, \http\, \https\, and raw host:port) into gRPC-compatible targets.

client/v3/internal/endpoint · high confidence

New feature gate system for etcd server features

The etcd server now uses a feature gate system to control the availability of various experimental and beta features. This change introduces a new \server/features\ module that defines feature gates for capabilities such as \StopGRPCServiceOnDefrag\, \TxnModeWriteWithSharedBuffer\, \InitialCorruptCheck\, \CompactHashCheck\, \LeaseCheckpoint\, \LeaseCheckpointPersist\, \SetMemberLocalAddr\, \FastLeaseKeepAlive\, and \PriorityRequest\. Users can now enable or disable these features via the \server-feature-gates\ flag, allowing for more granular control over server behavior and future compatibility.

server/features · high confidence

Persist and enforce consistency index and term in the backend

The \cindex\ package now persists the consistent index and term to the backend storage. This change ensures that the consistent index is saved even when it decreases, while also adding validation to prevent the consistent index from decreasing in a way that would cause a panic. The implementation includes a new \ConsistentIndexer\ interface and a \consistentIndex\ struct that manages these values, with tests verifying the new persistence and validation behavior.

server/etcdserver/cindex · medium confidence

Read logic and metrics moved to a dedicated subpackage

The read-related implementation and its associated Prometheus metrics (slow read index, failed read indexes) have been moved from the top-level etcdserver package into a new server/etcdserver/read subpackage. This reorganization groups the read index request handling, the linearizable read loop, and the corresponding unit tests together, making the server package more modular without changing the external API or user-facing behavior.

server/etcdserver/read · high confidence

Refactor etcd CLI entry point and configuration parsing

The etcd server and proxy command-line interface has been refactored to use a new \config\ struct and \configFlags\ type in \server/etcdmain/config.go\, which centralizes the parsing of command-line arguments and configuration files. This change introduces a more structured approach to handling flags, including deprecation warnings for legacy options like \--max-snapshots\ and \--v2-deprecation\. The refactoring also adds comprehensive unit tests in \config\_test.go\ to validate the new parsing logic for member, clustering, and proxy configurations.

server/etcdmain · high confidence

Refactor transaction handling into a dedicated \`server/etcdserver/txn\` package

The transaction logic for the etcd server has been reorganized into a new \server/etcdserver/txn\ package, separating \delete\, \put\, \range\, and core \txn\ execution into distinct files. This refactoring includes adding Prometheus metrics for range and apply durations, implementing a fast-path optimization for range requests that retrieves data from memory when possible, and adding comprehensive benchmark tests to validate performance improvements for key sorting and limit handling.

server/etcdserver/txn · high confidence

Refactored Raft HTTP transport layer with new encoder/decoder interfaces

The \rafthttp\ package has been refactored to use explicit \encoder\ and \decoder\ interfaces, separating message encoding and decoding logic into dedicated files (\coder.go\, \msg\_codec.go\, \msgappv2\_codec.go\). This change introduces a more modular approach to handling Raft messages over HTTP, with specific encoders for different message types (e.g., \MsgAppV2\) and decoders that respect size limits. The refactoring also includes updated metrics for peer connectivity and message statistics, along with comprehensive functional and unit tests for the new encoding/decoding logic.

server/etcdserver/api/rafthttp · high confidence

Refactored and expanded health check endpoints with new /livez and /readyz routes

The HTTP health check implementation in the etcd server was restructured into separate files (health.go, metrics.go, debug.go, etc.) and extended with new endpoints: /livez and /readyz. The /health endpoint now supports a serializable query parameter to validate cluster health, and allows excluding specific alarms (e.g., ?exclude=NOSPACE). Additionally, Prometheus metrics are exposed at /metrics and /proxy/metrics, and a /debug/vars endpoint is added for debugging. These changes improve observability and allow more granular health status reporting for cluster and node readiness.

server/etcdserver/api/etcdhttp · high confidence

Refactored client transport package with improved keep-alive and socket options

The transport package in client/pkg/transport has been restructured and expanded. A new keep-alive listener implementation (keepalive\_listener.go) ensures TCP keep-alive settings are applied to connections, with platform-specific handling for OpenBSD and Unix systems. Socket options for port and address reuse (sockopt.go) are now explicitly supported via listener options, with platform-specific implementations for Solaris, Windows, and WASM. The listener creation logic (listener.go, listener\_opts.go) now uses an options-based approach (WithTimeout, WithSocketOpts, WithTLSInfo) to configure listeners, improving flexibility. Additionally, the TLS listener (listener\_tls.go) now enforces a 10-second handshake timeout and integrates CRL (Certificate Revocation List) verification via a new ConfigureCRLVerification method, enhancing security by rejecting revoked client certificates.

client/pkg/transport · high confidence

Refactored embed package structure and added logging/tracing configuration

The \server/embed\ package has been reorganized into multiple files, including \config.go\, \config\_logging.go\, \config\_tracing.go\, and \etcd.go\, separating configuration, logging, and tracing concerns. This refactoring introduces explicit configuration for log rotation, distributed tracing (OpenTelemetry), and socket options. Additionally, new tests have been added for authentication, configuration parsing, and tracing setup.

server/embed · high confidence

Refactored logging configuration and added path utility

The logging utilities in client/pkg/logutil have been restructured to support configurable log formats (JSON or console) and levels, with validation that returns an error for invalid formats. The default timestamp format has been updated to include microsecond precision. Additionally, a new path utility package (client/pkg/pathutil) was added to provide a function for canonicalizing URL paths.

client/pkg/logutil · high confidence

Refactored storage schema into a modular backend architecture

The storage schema package has been restructured to separate concerns by introducing dedicated backend interfaces and implementations for alarms, authentication (users and roles), and membership. This refactoring introduces new files such as \actions.go\ to handle reversible schema changes, \alarm.go\ for alarm storage, \auth.go\ and \auth\_roles.go\ for authentication data, and \membership.go\ for cluster membership. These changes provide a cleaner, more maintainable way to manage the etcd backend schema, supporting both upgrade and downgrade paths for schema migrations.

server/storage/schema · high confidence

Refine periodic compaction timing and fix flaky tests

The v3compactor module was restructured and its behavior refined. The code was moved from the root into the server/etcdserver/api/v3compactor directory. The periodic compactor now correctly uses 24-hour intervals for the compaction period, with the revision recording interval updated to 144 minutes (1/10 of the 24-hour period) and the retry interval adjusted to 144 minutes. Additionally, the implementation uses strict synchronization for the revision getter to minimize flaky results caused by time racing, and tests were updated to use zaptest.NewLogger and goimports for automated fixing.

server/etcdserver/api/v3compactor · high confidence

Regenerate lease protobuf code with Google protobuf

The generated Go code for the lease package has been regenerated using the Google protobuf library instead of the previous gogo/protobuf implementation. This change updates the serialization and deserialization logic for lease-related messages, which may affect how lease data is encoded and decoded in the server.

server/lease/leasepb · medium confidence

Regenerate v3election protobuf code with Google's protobuf library

The Go source files for the v3election gRPC service have been regenerated using the standard google.golang.org/protobuf library instead of the previous gogo/protobuf implementation. This update modernizes the generated code to use the official Google protobuf runtime, which changes the underlying serialization and reflection behavior for the election service's request and response types.

server/etcdserver/api/snap/snappb, server/etcdserver/api/v3election/v3electionpb · medium confidence

Regenerated gRPC-Gateway reverse proxy code for Election and Lock services

The generated Go files for the v3 Election and Lock services (v3election.pb.gw.go and v3lock.pb.gw.go) have been regenerated. This update aligns the HTTP/JSON reverse-proxy layer with the latest gRPC-Gateway and protobuf definitions, ensuring that RESTful API endpoints for election and distributed locking operations remain compatible with the underlying gRPC services.

server/etcdserver/api/v3election/v3electionpb/gw, server/etcdserver/api/v3lock/v3lockpb/gw · medium confidence

Regenerated v3lock protobuf code with Google protobuf and gRPC-Go v1.64.0+

The generated Go code for the v3lock service (Lock, Unlock, LockRequest, LockResponse, UnlockRequest, UnlockResponse) has been regenerated using the Google protobuf library instead of gogo/protobuf, and the gRPC stubs now require gRPC-Go v1.64.0 or later. This update aligns the v3lock API with the project's broader migration to Google's protobuf implementation, which may affect how clients interact with the lock service at the code level, though the logical behavior of the lock service remains unchanged.

server/etcdserver/api/v3lock/v3lockpb · medium confidence

Rename etcdserver/etcderrors package to etcdserver/errors

The \etcdserver/etcderrors\ Go package has been renamed to \etcdserver/errors\. This change updates the package path and internal naming conventions, which may require updates to import statements in dependent code.

server/etcdserver/errors · high confidence

Replace custom resolver with gRPC's manual resolver and round-robin load balancing

The client's internal resolver has been replaced with gRPC's manual resolver, allowing endpoints to be updated dynamically via SetEndpoints. The resolver now configures a round-robin load balancing policy and populates the resolver state using gRPC's standard Endpoint and Address structures, ensuring compatibility with gRPC's built-in load balancing mechanisms.

client/v3/internal/resolver · high confidence

Restructure documentation directory and add OWNERS file

The Documentation directory has been restructured to support a new site generation system. An OWNERS file was added to define ownership and labeling for the documentation area, and the README was updated to clarify that user and developer documentation is now hosted at etcd.io, with internal contributor docs remaining in this directory.

Documentation · medium confidence

Rework backend storage interface and transaction management

The backend package has been restructured to provide a cleaner, more explicit transaction management model. The \Backend\ interface now exposes distinct methods for acquiring locks: \LockOutsideApply\ and \LockInsideApply\, allowing the system to verify that write transactions are only acquired in the correct execution context (outside the Raft apply loop). Additionally, the \BatchTx\ interface has been updated to support these new locking modes, and the internal buffer handling for write-backs now includes logic to deduplicate keys when writing to empty read buffer buckets. These changes improve data consistency verification and prevent race conditions during concurrent read and write operations.

server/storage/backend · high confidence

Unify and extend compaction hash testing

The \TestCompactionHash\ helper in \server/storage/mvcc/testutil\ has been unified and extended to also cover key deletion and defragmentation, ensuring hash consistency across the full compaction lifecycle. Additionally, the \CorruptBBolt\ helper was moved to this test utility package to centralize test helpers.

server/storage/mvcc/testutil · high confidence

Updated gRPC naming resolver to use the Endpoint API

The etcd client's gRPC naming resolver has been updated to use the newer gRPC Endpoint API. This change replaces the deprecated Address-based state with an Endpoint-based state, allowing the resolver to properly handle endpoint watches and updates through the endpoints package. This aligns the client with gRPC 1.30+ standards.

client/v3/naming/resolver · high confidence

Upgrade JWT library to v5 and add EdDSA algorithm support

The server's authentication system now uses the golang-jwt/jwt v5 library, replacing the previous version. This upgrade brings support for the EdDSA (Ed25519) JWT algorithm, allowing users to configure JWT-based authentication using this modern cryptographic standard alongside existing RSA, ECDSA, and HMAC methods.

server/auth · high confidence

WAL snapshot validation and CRC checking

The WAL package now enforces stricter validation on snapshot writes, requiring the index, term, and (for non-initial snapshots) the ConfState to be populated, and adds a CRC mismatch error to detect corrupted WAL records.

server/storage/wal/walpb · high confidence

etcdctl v3 CLI restructured with new global flags and commands

The etcdctl v3 command-line interface has been restructured to support new global flags for connection timeouts (dial-timeout, keepalive-time, keepalive-timeout), request size limits (max-request-bytes, max-recv-bytes), and authentication (auth-jwt-token, user, password). The tool now includes new commands for managing cluster state (move-leader, check, downgrade, completion) and supports additional output formats (fields, json, protobuf, simple, table). Global flags are hidden by default, and the help text now directs users to 'etcdctl options' to view available global options.

etcdctl/ctlv3 · high confidence

Test coverage

Add Go-based health check entrypoint for Antithesis tests; Add common test framework configuration for cluster and client setup; Add devcontainer test script; Add expected output files for etcd log dump tests; Add integration tests for client v3 connectivity scenarios; Add integration tests for clientv3; Add integration tests for the embedded etcd server; Add robustness test configuration via environment variables; Add robustness test report persistence for client operations and WAL entries; Add robustness test traffic generator for etcd and Kubernetes workloads; Add robustness validation tests for watch and serializable operations; Add robustness/coverage tests for Kubernetes API usage; Added Antithesis random number generator wrappers for testing; Added integration tests for clientv3 concurrency primitives; Added integration tests for clientv3 examples; Added integration tests for clientv3 naming functionality; Added integration tests for clientv3 snapshot operations; Added integration tests for clientv3/experimental recipes; Added integration tests for etcd snapshot restore and validation; Added integration tests for gRPC proxy functionality; Added randomizable configuration options for robustness testing; Added robustness test infrastructure for the etcd client; Added robustness test model and identity providers; Added robustness validation test for Antithesis; Added test fixtures for certificate generation and validation; Added test fixtures for expired certificates; Added test helper utilities for WAL operations; Added test infrastructure files and placeholder scripts; Added tests for kubernetes etcd contract tracing; Consolidated integration test suite; Consolidated integration tests for the v3 watch API; Enable Antithesis instrumentation for the etcd server; Expanded e2e test coverage for cluster operations and security; Expanded robustness test scenarios for varied cluster configurations; Expanded robustness testing with new failpoints and test infrastructure; Lease integration tests moved to a dedicated package; Migrate e2e and integration tests to the common test framework; New e2e test framework for cluster and client operations; New integration test framework infrastructure; New test utility helpers for execution, logging, and paths; Refactored robustness test traffic generation into a modular traffic package; Robustness test infrastructure and documentation.

Dependencies

New Go modules for API, cache, and client/pkg packages

The \api\, \cache\, and \client/pkg\ packages have been converted into separate Go modules, each with its own \go.mod\ and \go.sum\ files. These modules are configured to use Go 1.26 and include updated dependencies such as \google.golang.org/grpc\ v1.82.1, \google.golang.org/protobuf\ v1.36.11, and \go.opentelemetry.io/otel\ v1.44.0.

(dependencies) · high confidence

Updated gRPC-Gateway and protobuf dependencies for API generation

The API gateway code in api/etcdserverpb/gw has been regenerated to align with updated dependencies: gRPC-Gateway was upgraded from 2.18.1 to 2.27.0, and google.golang.org/grpc was upgraded from 1.63.2 to 1.64.0. This ensures the generated reverse-proxy handlers for the etcd server RPCs are compatible with the latest gRPC and protobuf libraries.

api/etcdserverpb/gw · medium confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 68.

Lenses

  • Code Health 77
  • Architecture 100
  • Maturity 66
  • Readiness 81
  • Security 61

Changes since last survey

  • 300 commits — 280 feature/other, 20 fixes

By area

  • (repo) — 129 commits
  • (root) — 29 commits
  • .github/workflows — 25 commits
  • tests/robustness — 14 commits
  • CHANGELOG/CHANGELOG-3.5.md — 11 commits
  • CHANGELOG/CHANGELOG-3.7.md — 7 commits
  • server/storage — 7 commits
  • tools/mod — 7 commits
  • Documentation/contributor-guide — 6 commits
  • client/v3 — 6 commits
  • server/etcdserver — 6 commits
  • tests/antithesis — 6 commits
  • tools/rw-heatmaps — 6 commits
  • tests/integration — 5 commits
  • CHANGELOG/CHANGELOG-3.6.md — 4 commits
  • etcdctl/ctlv3 — 4 commits
  • .github/dependabot.yml — 3 commits
  • client/pkg — 3 commits
  • scripts/test.sh — 2 commits
  • server/embed — 2 commits

Notable commits

  • fix: Fix handling V2 entry in robustness tests after changes to proto
  • fix: Fix the costTxnReq ignores nested RequestTxn issue
  • fix: Fix the security issue where a user granted read permission on one key could receive watch responses for every key starting from that key
  • fix: Fix unbounded io.ReadAll on peer lease HTTP handler body
  • fix: Fix unsynchronized range over leaseCache.entries
  • fix: Merge pull request #21422 from huajianxiaowanzi/fix-txn-lease-hex-parsing
  • fix: Merge pull request #21916 from ivanvc/fix-devcontainer-workflow-remove-workflows-permission
  • fix: Merge pull request #21970 from AwesomePatrol/fix-etcd-k8s-patches
  • fix: Merge pull request #21973 from s3onghyun/docs-fix-changelog-link
  • fix: Merge pull request #22080 from marksmwl/fix/22010-double-barrier-nil-session
  • fix: Merge pull request #22208 from anveshreddy18/fix-etcdctl-duplicate-raftterm
  • fix: Update changelog to cover recent security fixes
  • fix: changelog: add etcdctl RaftTerm fix entry for 3.5, 3.6 and 3.7
  • fix: etcdctl: fix txn command import grouping
  • fix: etcdctl: fix txn compare test for wrapped Cmp
  • fix: fix golangci-lint path, genproto, go.work.sum
  • fix: fix(txn): parse lease ID as hex in comparison
  • fix: robustness: Fix defaulting for proto comparison when merging WAL history
  • fix: robustness: fix downgrade test failure
  • fix: tests: fix data race on client watch operations
  • …and 280 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

etcd-io/etcd was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 6 August 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 7d7f884852f728972bf1e20c3f26840b6bbeb94c — the exact code this score is about.
  • Scored under rubric-2026.08.19 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer latest.