Skip to content
CAI
Software that uses CAICheck a score

j5ik2o/akka-cqrs-es-example-typed

64.3

Adequate · 21 September 2026

9.4k

lines of production code

Scala

with Java, Kotlin

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Features

Add AWS ECR and STS integration for Docker image management

New build-time scripts and libraries have been added to the project to manage AWS Elastic Container Registry (ECR) repositories and authenticate with Docker. The \AwsEcr\ object provides methods to create ECR repositories, set repository and lifecycle policies, and retrieve Docker credentials for a given AWS region. The \AwsSts\ object allows retrieving the current AWS account ID. These utilities are used by the build system to handle container image publishing, supporting both standard AWS credentials and AWS SSO authentication.

project · high confidence

Add AWS Load Balancer Controller infrastructure

Added Terraform configuration to deploy the AWS Load Balancer Controller in the kube-system namespace, including the Helm release (chart 1.4.2), an IAM role with OIDC-based trust, and a comprehensive IAM policy granting permissions for EC2, ELBv2, ACM, WAF, and Shield services to manage load balancers and target groups.

tools/terraform/aws-load-balancer-controller · medium confidence

Add Dockerized DynamoDB setup and scanning tools

The tools/dynamodb-setup directory now includes a Dockerfile, Makefile, and shell scripts (create-tables.sh, scan.sh) that allow users to build and run a containerized environment for setting up DynamoDB tables and scanning data. The setup script creates 'Journal' and 'Snapshot' tables with specific key schemas and global secondary indexes, while the scan script provides a way to query a local DynamoDB instance. This change introduces new operational tooling for database initialization and data inspection.

tools/dynamodb-setup · high confidence

Add EKS external-dns module for DNS management

The EKS external-dns module has been added, introducing a new Terraform configuration that deploys the external-dns Helm chart to manage AWS Route53 DNS records. This includes the necessary IAM policies for Route53 access, an AWS IAM role with OIDC federation for the Kubernetes service account, and the Kubernetes service account resource itself, enabling automated DNS record synchronization for the EKS cluster.

tools/terraform/eks-external-dns · high confidence

Add Flyway Helm chart for database migrations

A new Helm chart named 'flyway' has been introduced to manage Flyway database migration jobs on Kubernetes. The chart includes a Kubernetes Job template that executes the 'flyway migrate' command, along with supporting templates for service account names, labels, and connection tests. Default values are provided for image configuration, service types, and resource limits, enabling users to deploy Flyway as a one-time migration job within their Kubernetes clusters.

tools/charts/flyway · high confidence

Add Flyway-based database migration tooling

A new Flyway container image and build system have been added to the tools/flyway directory. The Dockerfile bundles configuration, SQL migration scripts (including V1\_\_Create\_Tables.sql which defines threads, members, and messages tables), and JDBC drivers, while the Makefile provides targets to build, run, and publish the container. This introduces a standardized way to manage and apply database schema changes via Flyway.

tools/flyway · high confidence

Add Helm chart for the read-model-updater service

A new Helm chart named 'read-model-updater' has been added to the codebase, providing a complete Kubernetes deployment template. This includes the chart metadata, helper templates, and resource definitions for a Deployment, Service, Ingress, HorizontalPodAutoscaler, and ServiceAccount, along with default configuration values and a test connection template.

tools/charts/read-model-updater · high confidence

Add Helm charts for ALB controller CRDs and write-api-server

Introduces two new Helm charts to the repository. The \tools/charts/alb-controller-crds\ chart packages Kubernetes CustomResourceDefinitions for the AWS Load Balancer Controller, specifically defining \IngressClassParams\ and \TargetGroupBinding\ resources. The \tools/charts/write-api-server\ chart provides a generic deployment template for Akka-based applications, including configuration for cluster discovery (DNS, Kubernetes API, or aggregate), HTTP services, management endpoints, and autoscaling. Both charts include standard Helm scaffolding such as \Chart.yaml\, \values.yaml\, and template helpers.

tools/charts/write-api-server · high confidence

Add Helm charts for DynamoDB and DynamoDB setup

Introduced two new Helm charts: 'dynamodb' and 'dynamodb-setup'. The 'dynamodb' chart deploys Amazon DynamoDB Local with a DynamoDB Admin UI, supporting multiple storage backends (emptyDir, PVC, or direct volume) and optional ingress. The 'dynamodb-setup' chart provides a Kubernetes Job to execute a 'create-tables.sh' script for initial table creation. Both charts include standard Kubernetes templates (Deployment, Service, Ingress, HPA, etc.) and helper templates.

tools/charts/dynamodb · high confidence

Add Kubernetes dashboard ClusterRoleBinding chart

A new Helm chart named 'k8s-dashboard-crb' has been introduced to manage a Kubernetes ClusterRoleBinding. This chart configures a binding that grants the 'cluster-admin' ClusterRole to the Kubernetes dashboard service account, with configurable namespace and service account name via values.

tools/charts/k8s-dashboard-crb · high confidence

Add Scala read-model updater for thread events

Introduced a new Scala-based read-model updater service that consumes DynamoDB streams to update MySQL-based read models for threads, members, and messages. The change adds the application entry point (Main.scala), the core updater logic (ThreadReadModelUpdater.scala), and supporting protocol definitions (ThreadReadModelUpdaterProtocol.scala). Configuration files (application.conf, production.conf) define AWS credentials, DynamoDB/CloudWatch endpoints, and health check probes, while logback.xml configures logging for both production and test environments.

scala/read-model-updater-scala · high confidence

Add Terraform configuration for EKS cluster-autoscaler

Introduces a new Terraform module to deploy the Kubernetes cluster-autoscaler on EKS. The configuration includes an IAM role and policy granting the autoscaler permissions to manage Auto Scaling groups and EC2 instances, along with a Helm release that installs the autoscaler with auto-discovery enabled and specific scaling arguments.

tools/terraform/cluster-autoscaler · high confidence

Add configuration files for the write-api-base service

Added configuration files for the write-api-base service, including Akka, j5ik2o (DynamoDB persistence), Kamon (monitoring), and Logback (logging) settings. These files define HTTP ports, cluster roles, persistence plugins, and logging levels for local, production, and frontend/backend environments.

common/write-api-base · high confidence

Add health check and K8s probe endpoints for the write API server

The write API server now exposes health check and Kubernetes probe endpoints. A new \reference.conf\ configures the K8s probe on host 0.0.0.0 port 8086 with liveness at /live and readiness at /ready. The Scala \k8s\ package provides \livenessProbe\ and \readinessProbe\ helpers that bind routes to these paths. The \HealthCheckRoutes\ implementation supports a /health endpoint that accepts a list of \HealthCheck\ instances, returning a JSON response with check statuses and messages, and respects a \full\ query parameter for detailed results. The Java \write-api-server-java\ module adds a \Main\ entry point, Guice modules (\MainModule\, \MainActorModule\) for dependency injection, and Akka Typed actors (\MainActor\, \MainActorFactory\) to start the HTTP server and cluster sharding for thread aggregates. Tests are added for the health check routes and K8s probes.

(repo-wide) · high confidence

Added Helm chart for the read-api-server

Users can now deploy the read-api-server to a Kubernetes cluster using the new Helm chart located in tools/charts/read-api-server. The chart includes templates for the Deployment, Service, Ingress, HorizontalPodAutoscaler, and ServiceAccount, along with default values and helper templates to manage the application's lifecycle and networking.

tools/charts/read-api-server · high confidence

Added local development and EKS deployment scripts

Added a suite of shell scripts in the \tools/scripts\ directory to streamline local development and infrastructure management. This includes \minikube\ start/stop/delete scripts for local Kubernetes, \helmfile\ wrappers for applying or destroying EKS and local environments (backend, frontend, DynamoDB, MySQL, etc.), and utility scripts for running load tests (\run-ab.sh\), debugging (\run-ubuntu.sh\), and building/pushing Docker images (\sbt-ecr-push.sh\, \sbt-publish-local.sh\).

tools/scripts · high confidence

Adds configuration files and Swagger UI assets for the read API server

The read API server is now configured with environment-specific settings for HTTP (port 8081), MySQL database connectivity via Slick, and health check endpoints (/live, /ready). It also includes Akka and Kamon (Datadog tracing) configurations, and serves Swagger UI assets to expose the API documentation at /api-docs/swagger.json.

scala/read-api-server-scala · high confidence

Initial deployment of Terraform infrastructure-as-code for AWS EKS and supporting services

The \tools/terraform\ directory now contains a complete set of Terraform configurations to provision an AWS EKS cluster, VPC, and associated resources. This includes infrastructure for application persistence via DynamoDB tables, container image storage in ECR, and monitoring via Datadog. The setup also provisions an AWS Load Balancer Controller, Cluster Autoscaler, external DNS, Kubernetes Dashboard, and Metrics Server. Additionally, it establishes IAM roles and Kubernetes service accounts for the 'adceet' application, enabling secure access to AWS resources through OpenID Connect. Utility scripts are provided to initialize the state backend, plan, apply, and destroy the infrastructure.

tools/terraform · high confidence

Initial project scaffolding and configuration

The repository was initialized with essential configuration files to support development and maintenance workflows. A \.gitignore\ file was added to exclude build artifacts, IDE settings, and environment-specific files. Build tooling was configured with \.scalafmt.conf\ for code formatting, \.scalafix.conf\ for automated code fixes, and \.scala-steward.conf\ to manage dependency updates. Additionally, a \.git-blame-ignore-revs\ file was created to ignore specific commits, and a \README.md\ was added to document the CQRS/Event Sourcing architecture, supported languages (Scala, Kotlin, Java), and deployment instructions.

(repo-wide) · high confidence

New Docker Compose configuration for local development environment

The tools/docker-compose directory now contains a complete local development stack, including MySQL, Flyway, LocalStack, DynamoDB Local, and application services (write-api-server, read-model-updater, read-api-server) with their respective environment variables, ports, and dependencies. This introduces a new way to start the full local environment using the provided docker-compose-up.sh script, which orchestrates the services defined in docker-compose.yml and docker-compose-api.yml.

tools/docker-compose · high confidence

New Helmfile definitions for application and infrastructure services

Added Helmfile release definitions for the read-api-server, read-model-updater, and write-api-server (frontend and backend) components, each with corresponding value templates for image, probes, and environment configuration. Additionally, new Helmfile entries were introduced for infrastructure services including DynamoDB, Flyway, MySQL, and LocalStack, along with a centralized registry for image pull secrets (regcred) to support container image deployment across the environment.

tools/helmfile.d · high confidence

Test coverage

Added base test support classes for Akka, DynamoDB, and Slick

Added new test support classes in the scala/test-base-scala module, including ActorSpec for Akka test kit integration, LocalstackSpecSupport for DynamoDB and CloudWatch testing via Docker containers, Slick3SpecSupport for MySQL database testing, and RandomPortUtil for dynamic port allocation.

scala/test-base-scala · high confidence

Dependencies

Updated build dependencies and added new project modules

The build configuration was updated to include new project modules: \read-api-base-scala\, \read-api-server-scala\, \write-api-server-kotlin\, \write-api-server-java\, and \read-model-updater-base\. Several library dependencies were upgraded, including \docker-controller-scala-dynamodb-local\ to 1.15.34, \mockito-core\ to 5.9.0, \jaxb-impl\ to 4.0.4, and \enumeratum\ to 1.7.3.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 60 → 64 (+4.2)
  • Rubric changed (rubric-2026.08.18 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 100 → 99 (-0.8)
  • Architecture 100 → 73 (-27.4)
  • Maturity 50 → 57 (+6.7)
  • Readiness 67 → 70 (+2.8)
  • Security 52 → 64 (+12.7)
  • Domain Modelling 100 → 91 (-9.0)

Resolved (21)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High IaC: KSV-0014 (tools/charts/dynamodb/templates/deployment.yaml)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • LLM evaluation failed
  • Low IaC: KSV-0011 (tools/charts/dynamodb/templates/deployment.yaml)
  • Low IaC: KSV-0015 (tools/charts/dynamodb/templates/deployment.yaml)
  • Medium IaC: KSV-0001 (tools/charts/dynamodb/templates/deployment.yaml)
  • Medium IaC: KSV-0125 (tools/charts/dynamodb/templates/deployment.yaml)
  • Medium: security finding (details withheld)
  • Medium: security finding (details withheld)
  • No exposed public API
  • Test reliability not included
  • …and 1 more

New (97)

  • Critical IaC: AWS-0104 (tools/terraform/security-groups/main.tf)
  • Duplicated block (13 lines × 2) (scala/domain-scala/src/main/scala/com/github/j5ik2o/adceet/domain/MessageId.scala)
  • Duplicated block (14 lines × 2) (scala/domain-scala/src/main/scala/com/github/j5ik2o/adceet/domain/AccountId.scala)
  • Duplicated block (14 lines × 2) (scala/domain-scala/src/main/scala/com/github/j5ik2o/adceet/domain/ThreadId.scala)
  • Duplicated block (15 lines × 2) (scala/infrastructure-scala/src/main/scala/com/github/j5ik2o/adceet/infrastructure/aws/AmazonCloudWatchUtil.scala)
  • Duplicated block (16 lines × 2) (common/write-api-base/src/main/scala/com/github/j5ik2o/adceet/api/write/infrastructure/akka/persistence/dynamodb/journal/JournalPluginTraceReporter.scala)
  • Duplicated block (17 lines × 2) (scala/read-api-server-scala/src/main/scala/com/github/j5ik2o/adceet/api/read/MainActor.scala)
  • Duplicated block (19 lines × 2) (common/write-api-base/src/main/scala/com/github/j5ik2o/adceet/api/write/adaptor/http/SwaggerDocService.scala)
  • Duplicated block (19 lines × 3) (scala/infrastructure-scala/src/main/scala/com/github/j5ik2o/adceet/infrastructure/aws/AmazonCloudWatchUtil.scala)
  • Duplicated block (27 lines × 2) (scala/read-api-server-scala/src/main/scala/com/github/j5ik2o/adceet/api/read/adaptor/http/validation/Validation.scala)
  • Duplicated block (5 lines × 2) (scala/read-api-server-scala/src/main/scala/com/github/j5ik2o/adceet/api/read/DISettings.scala)
  • Duplicated block (5 lines × 4) (common/write-api-base/src/main/scala/com/github/j5ik2o/adceet/api/write/infrastructure/akka/persistence/dynamodb/V2MetricPublisher.scala)
  • FixmeComment (kotlin/write-api-server-kotlin/src/main/kotlin/com/github/j5ik2o/adceet/api/write/MainActor.kt)
  • High IaC: KSV-0014 (tools/charts/dynamodb/templates/deployment.yaml)
  • High IaC: KSV-0014 (tools/charts/dynamodb/templates/deployment.yaml)
  • High IaC: WD-COMPOSE-0002 (tools/docker-compose/docker-compose.yml)
  • High IaC: WD-COMPOSE-0002 (tools/docker-compose/docker-compose.yml)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 77 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

j5ik2o/akka-cqrs-es-example-typed was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit dc2cb64259c5aae42679dc25c4ac3e4fdca80641 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-28e75b8e3254.