Skip to content
CAI
Software that uses CAICheck a score

MAIF/izanami

44.2

Weak · 20 September 2026

58.7k

lines of production code

Scala

with TypeScript

1

measurement over time

CAI band scale
CAI lens gauges

What this system is

Izanami is a feature flag and configuration management service that enables granular control over application features through boolean, string, and numeric flag values. It supports distributed deployments via leader/worker modes and provides real-time updates through Server-Sent Events, alongside comprehensive audit logging and webhook-based event notifications. The system facilitates secure access via OIDC and personal access tokens, while offering robust data portability through tenant import/export capabilities and fuzzy search across projects and features.

Features

Add Swagger UI and OpenAPI documentation for client API

Developers can now view and interact with the Izanami client API documentation via a Swagger UI interface. This change introduces a new static Swagger UI page (version 5.15.0) and an OpenAPI 3.0.3 specification file (\swagger.json\) that details the available client endpoints, such as feature activation checks and event subscriptions, along with their required parameters and response schemas.

manual/static/swagger · high confidence

Added datasets/with-users.ndjson with comprehensive test fixtures

A new NDJSON dataset file has been added to the datasets directory, providing a rich set of test fixtures for the application. This file includes sample tags, projects, and feature flags (including those with percentage/user conditions, date-based activation, and OPA WASM configurations), global and local contexts, API keys, and user/project permissions. It also embeds a base64-encoded OPA WASM policy, enabling local testing of feature evaluation logic without external dependencies.

datasets · high confidence

Database schema updates for audit logging, personal access tokens, and text constraints

This release introduces several database schema changes to support new capabilities and enforce data integrity. A new event tracking system is added via the \global\_events\ table and \eventid\ sequence, including columns for emission timestamps, origin, authentication method, and username to enable detailed audit logging. Personal access tokens are now persisted in a dedicated \personnal\_access\_tokens\ table with granular rights (such as export, import, and later expanded to read/update features, delete resources, and read tenants/projects/keys) and a new \PROJECT\_RIGHT\_LEVEL\ enum for finer-grained project permissions. OIDC configuration is extended with a JSONB column to support default user rights mapping. Additionally, text size constraints are applied to tenants, users, configuration, invitations, and personal access tokens to prevent oversized data, and user roles are stored in a JSONB column for OIDC users.

conf/sql/globals · high confidence

Frontend migration to TanStack Query and new management pages

The frontend has migrated its data-fetching layer from react-query to TanStack Query, updating all page components (including GlobalContexts, Home, Invitation, Keys, Login, Menu, and Profile) to use the new query/mutation APIs and the shared Loader component. This change introduces several new management capabilities: a dedicated Tags page for creating, editing, and bulk-deleting tags; a Webhooks page for managing webhook configurations; Swagger UI integration for API documentation; and Project/Tenant Audit Log pages for tracking feature and entity changes. Additionally, the Global Contexts view now supports protecting contexts, and the Menu component includes a project selector for easier navigation.

izanami-frontend/src/pages · high confidence

Frontend utility library expansion and API integration

The frontend utility layer has been significantly expanded to support new product capabilities. New modules were added for context management (including URL resolution and protected context impact analysis), feature format conversion (modern to legacy and vice versa), and user rights mapping. The codebase now includes dedicated utilities for toast notifications, icon rendering, and input validation patterns, with regexes updated to allow spaces in feature names and additional special characters in passwords and usernames. Additionally, the queries module now exposes functions and query keys for Personal Access Tokens, webhooks, and project logs, while the types module introduces definitions for audit log entries, import errors, and token rights.

izanami-frontend/src/utils · high confidence

Introduction of light mode and CSS variable-based theming

The frontend now supports a light theme, allowing users to switch between dark and light visual modes. This is achieved by replacing hardcoded color values with CSS custom properties (e.g., \--bg-color\_level1\, \--color\_level1\) defined in the new \\_variables.module.scss\ file, which maps specific color palettes to \\[data-theme="light"\]\ and default dark states. Additionally, the styling system has been migrated from the legacy \@import\ syntax to the modern \@use\ syntax for better encapsulation, and the React Select component styles have been updated to dynamically reflect these theme variables, ensuring consistent appearance across dropdowns and inputs in both modes.

izanami-frontend/src/styles · high confidence

New datastores for events, feature calls, import/export, personal access tokens, search, and webhooks

This change introduces a suite of new data access layers in the \datastores\ package to support recent feature additions. \EventDatastore\ manages the storage, querying, and expiration of audit events. \FeatureCallsDatastore\ handles the recording and aggregation of feature usage metrics. \ImportExportDatastore\ provides the backend logic for tenant data import and export operations. \PersonnalAccessTokenDatastore\ implements storage and validation for personal access tokens. \SearchDatastore\ enables fuzzy search capabilities across projects, features, keys, tags, and other entities. \WebhooksDatastore\ manages webhook configurations and call status tracking. Additionally, \ApiKeyDatastore\ has been refactored to use \UserInformation\ for user context and enforce tenant-scoped SQL queries, while \ConfigurationDatastore\ now includes logic to clean up OIDC role mappings by removing references to non-existent resources.

app/fr/maif/izanami/datastores · high confidence

New frontend components for context management, audit logging, and feature testing

The frontend now includes a suite of new UI components to enhance context handling, auditing, and feature validation. A new \AllContexts\ selector allows users to browse and select global contexts, while \AuditLogs\ provides a detailed, paginated view of system events with advanced filtering. Feature management is improved with \ExistingFeatureTestForm\ for evaluating feature states against specific contexts and users, and \OverloadTable\ for managing context-specific feature overloads with protection impact analysis. Additionally, \WebhookTransformationEditor\ enables users to test Handlebars templates for webhook payloads, and \MultiSelect\ adds indeterminate state support for better bulk selection UX.

izanami-frontend/src/components · high confidence

New search modal with tenant selection, filtering, and history

The frontend now includes a new search modal component (SearchComponant) that allows users to search across all tenants or a specific one, apply type-based filters (such as Features, Projects, Keys, Tags, etc.), and view previous search history. The modal includes a search input with a clear button, tenant selection via buttons or dropdown, and a results area that groups items by type. Search history is persisted in localStorage and displayed when no search term is entered, allowing quick re-access to previous searches.

izanami-frontend/src/components/SearchComponant · high confidence

New standalone Docker image with embedded PostgreSQL for the demo

A new Docker image is now available that bundles PostgreSQL 17.2 directly with the Izanami application, eliminating the need for an external database service. This image, defined by the new Dockerfile-pg-embeded and script.sh, automatically starts the PostgreSQL instance, waits for it to be ready, and then launches the Izanami JAR, providing a self-contained environment for running the demo on port 9000.

demo-docker-image · high confidence

New web controllers for export, search, webhooks, and personal access tokens

This change introduces several new web controllers in the application layer: ExportController for tenant data export, SearchController for feature and context search, WebhookController for webhook management, and PersonnalAccessTokenController for managing personal access tokens. It also refactors ApiKeyController to use a service-based architecture and updates AuthAction to support personal access token authentication alongside existing methods. Additionally, ConfigurationController is updated to include version information in the configuration response and handle OIDC configuration changes with role-based right updates.

app/fr/maif/izanami/web · high confidence

Support for non-boolean feature flags and patch operations

Feature flags can now return String or Number values in addition to Boolean, allowing for more granular feature control. This change introduces new model classes (ActivationCondition, PatchOperation, ResultType) to handle these valued result types, including validation for numeric ranges and JSON parsing for the new data structures. It also adds support for patch operations to update feature properties like enabled status, project, and tags via specific API paths.

app/fr/maif/izanami/models/features · high confidence

Webhook delivery with retry and template support

A new WebhookListener component has been added to the jobs module to handle asynchronous webhook notifications. This feature allows Izanami to send HTTP requests to configured endpoints when feature events occur, supporting customizable request bodies via Handlebars templates. The implementation includes a robust retry mechanism with configurable exponential backoff to handle transient failures, and it automatically recovers abandoned webhook calls after database reconnections or tenant lifecycle changes.

app/fr/maif/izanami/jobs · high confidence

Removals

Removed Play Scala form scaffolding template

The .g8 form template, which previously generated a Play Scala controller, view, and test suite for handling a simple form with name and age fields, has been removed. Users can no longer use this specific scaffolding to quickly create a basic form-handling controller in Play Scala applications.

.g8, .g8/form · high confidence

Behavioural changes

Database schema overhaul for contexts, webhooks, and feature values

This update applies a series of database migrations (V1–V15) that fundamentally restructure how contexts, features, and webhooks are stored and managed. Contexts are migrated to a hierarchical ltree-based model with enforced global/project consistency and cascading protection rules, allowing projects to be deleted even when contexts exist. Feature values now support negative numbers and non-boolean types (strings, numbers) with stricter validation, while project and tag identifiers switch from UUIDs to text strings. Additionally, a new webhook system is introduced with dedicated tables for tracking call statuses and audit logs, and comprehensive text size constraints are added across all major entities to prevent data overflow.

conf/sql/tenants · high confidence

Documentation updates for v1.11.5 release and typo fixes

The manual has been updated to reflect the v1.11.5 release, with download links for binaries, Docker images, and the CLI now pointing to the specific version tag instead of the generic 'latest' release. Additionally, various typos in the documentation have been corrected, including fixes for 'Tracability', 'Advanded', 'betwwen', 'conditonal', and 'abilitations', as well as a correction to the OpenAPI Swagger UI path.

manual/v1 · high confidence

Expanded configuration options and API routes for new features

The application configuration now supports cluster mode settings (standalone, blocklists, allowlists, worker URLs), experimental stale feature tracking, audit log retention, webhook retry policies, and OpenID Connect enhancements including PKCE and configurable scopes/fields. New API routes have been added to support personal access tokens, tenant and project audit logs, search functionality, tenant export/import, webhooks, and Server-Sent Events (SSE) for real-time updates. Additionally, the routes file introduces context preservation options for feature updates and patches, and disables legacy mailer configuration endpoints.

conf · high confidence

Frontend infrastructure modernization and test environment stabilization

The frontend development environment has been updated to use the modern ESLint flat config format and Vitest for unit testing, replacing the legacy JSON-based ESLint configuration and removing obsolete database initialization scripts. To improve reliability in CI and local development, Playwright end-to-end tests now run with increased timeouts, single-worker execution, and a more robust web server startup sequence that explicitly waits for backend and frontend health checks. Additionally, the Vite development server is now fixed to port 3000 with a proxy for Swagger API definitions, and static assets like Bootstrap and FontAwesome are served from local node modules instead of external CDNs to ensure consistent builds.

izanami-frontend · high confidence

Frontend migration to TanStack Query and introduction of dark/light mode

The frontend has migrated its data-fetching library from react-query to @tanstack/react-query, requiring updates to the query client and application entry point. Additionally, a new dark/light mode toggle has been introduced, allowing users to switch themes via a context provider that persists the preference; this is supported by updated CSS variables and SCSS syntax in the stylesheets. The security context has also been expanded to support input-based confirmation for sensitive actions (replacing simple password protection) and to manage modal displays, while new routes have been added for Swagger documentation, atomic design, tags, webhooks, and audit logs for tenants and projects.

izanami-frontend/src · high confidence

Improved error handling with PostgreSQL constraint mapping and separated logging

The application now provides more specific and user-friendly error messages when database constraints are violated. A new \PostgresErrorMapper\ translates PostgreSQL constraint names (such as unique key violations or field length limits) into distinct Izanami error types, ensuring users receive clear feedback on issues like duplicate feature names or oversized fields. Additionally, the HTTP error handler has been refactored to separate client and server error logging into distinct loggers (\izanami-client-error-handler\ and \izanami-server-error-handler\), improving observability and debugging for operational teams.

app/fr/maif/izanami/errors · high confidence

Improved startup stability and configuration compatibility

The application now allows up to 120 seconds for startup initialization, providing more time for complex environments to initialize without timing out. Additionally, a new configuration utility automatically corrects legacy string-based formats for cluster settings (such as context blocklists, allowlists, and worker URLs) into the expected structured types, ensuring backward compatibility with older configuration files.

app/fr/maif/izanami · high confidence

Izanami 2.26.2-SNAPSHOT release with Scala 3 migration and OIDC improvements

This release updates the project version to 2.26.2-SNAPSHOT and migrates the build tooling to Scala 3, evidenced by the new \.scalafix.conf\ targeting Scala 3, the updated \.scalafmt.conf\ with \runner.dialect = scala3\, and the Dockerfile now copying the JAR from \target/izanami.jar\ instead of the Scala 2.13 specific path. The OIDC integration is enhanced with a new \oidc-server-mock\ service in \docker-compose.yml\ for development, the removal of the legacy \default-oidc-users.json\ file, and a fix to use the \id\_token\ instead of the \access\_token\ for role extraction. Additionally, the release includes a new \Server Sent Event\ endpoint for real-time feature updates, documented in the new \swagger.json\, and improves the developer experience with a unified \mise.toml\ setup and a rewritten \README.md\.

(repo-wide) · high confidence

Major model refactoring and introduction of new security and operational features

This change introduces several new capabilities and significantly refactors the core data models. New features include Personal Access Tokens for granular API access control, Webhooks for event notifications, and Leader/Worker modes for distributed deployment. The system now supports fine-tuned conflict strategies for import operations and allows preserving protected contexts during overloads. Additionally, the model layer has been restructured: identifiers for Projects and Tags have migrated from UUIDs to strings, context handling has been expanded to support protected contexts and overloads, and OAuth2/OIDC configuration now includes PKCE support and role-based rights mapping.

app/fr/maif/izanami/models · high confidence

Manual site performance and layout improvements

The documentation site now uses a compressed WebP version of the Izanami logo to improve load performance, and the landing page layout has been adjusted to center and wrap content more effectively on smaller screens. Additionally, a new CSS class has been added to ensure checkmark tables are centered.

manual/src · high confidence

Migrate datastore utility to Apache Pekko

The \Datastore\ trait in the \app/fr/maif/izanami/utils\ package now imports \FastFuture\ from \org.apache.pekko.http.scaladsl\ instead of the legacy \akka.http\ package, aligning this component with the broader migration to Apache Pekko and Play 3. This change ensures that internal asynchronous operations within the datastore layer utilize the updated Pekko HTTP utilities.

app/fr/maif/izanami/utils · high confidence

Migration to Apache Pekko and Play 3 with expanded datastores

The application runtime has been upgraded from Akka to Apache Pekko and from Play 2 to Play 3, requiring new configuration structures via the typed \AppConf\ interface. This change introduces several new datastores to the environment initialization, including \FeatureCalls\, \Webhooks\, \ImportExport\, \Search\, \PersonalAccessToken\, and \Events\, while also adding corresponding lifecycle management for these components. Additionally, the PostgreSQL connection logic has been refactored to support new configuration fields like \username\ (with backward compatibility for \user\) and improved SSL handling via \ClientSSLOptions\.

app/fr/maif/izanami/env · high confidence

Migration to Apache Pekko and addition of FutureEither syntax helpers

The application has migrated its underlying actor and HTTP infrastructure from Akka to Apache Pekko, updating all relevant imports (akka.\* to org.apache.pekko.\*). Additionally, new implicit syntax extensions have been added to simplify error handling and type conversion: a \fEither\ method on values to create \FutureEither\ instances, and extension methods on \Future\, \Either\, and \Boolean\ to convert them into \FutureEither\ or Java Boolean types respectively.

app/fr/maif/izanami/utils/syntax · high confidence

Migration to CSS variables and SCSS @use syntax for layout styling

The layout styles in the frontend have been refactored to replace legacy SCSS variables (e.g., $fondBody, $primaryColor) with CSS custom properties (e.g., var(--bg-color\_level1), var(--color\_level2)) and SCSS module imports (@use). This change enables dynamic theming capabilities, such as the newly supported light mode, by allowing colors and backgrounds to be updated via CSS variables rather than hardcoded SCSS values. Additionally, the sidebar positioning was adjusted (top: 50px) and responsive breakpoints were updated to improve layout behavior on smaller screens.

izanami-frontend/src/styles/layout · high confidence

Migration to new feature, user, and event models with V2 event support

The v1 compatibility layer has been updated to map legacy data structures to the new domain models: features now use CompleteFeature instead of AbstractFeature, API keys and users include a new roles field, and rights are scoped using ProjectRightLevel. Additionally, a new V2FeatureEvents object provides structured event generation (creation, update, deletion, keep-alive, and error) with user metadata and Instant timestamps, while the WasmManagerClient now includes debug logging for script creation and build operations.

app/fr/maif/izanami/v1 · high confidence

Refactored backend services and introduced feature staleness tracking

The service layer has been restructured by extracting logic from controllers into dedicated service classes (APIKey, Event, Feature, FeatureUsage, Right, Tag, Tenant, and Webhook services). This refactoring introduces a new FeatureUsageService that tracks feature call history to determine and expose a 'stale' status for features that have not been called, changed, or created within a configurable time window. Additionally, the RightService now supports a supervised role-right mode and maps OIDC roles to Izanami rights, while the EventService has been relocated and expanded to handle detailed event origins and authentication types.

app/fr/maif/izanami/services · high confidence

UI component styling modernized and light theme support added

The frontend component styles have been refactored to replace hardcoded color values with CSS variables (e.g., \var(--color-primary)\, \var(--bg-color\_level1)\), enabling consistent theming and easier light mode support. New styles have been added for pagination, search modals, and toast notifications, while existing components like buttons, tables, accordions, and modals have been updated to use the new variable system and improved visual hierarchy.

izanami-frontend/src/styles/components · high confidence

WASM integration migrates to Apache Pekko and adds HTTP call capabilities

The WASM integration backend has been migrated from Akka HTTP/Streams to Apache Pekko, updating the underlying HTTP client and stream materializer. This change also introduces new host functions that allow WASM scripts to make HTTP calls, controlled by the \httpAccess\ authorization setting in the WASM configuration. Additionally, a logging host function (\proxy\_log\) has been added to allow scripts to write to the application logger, and configuration access has been standardized to use typed configuration objects.

app/fr/maif/izanami/wasm · high confidence

Test coverage

Added comprehensive API specification tests for Izanami; Added test resources for script features and updated test logging configuration; Expanded screenshot test coverage and Playwright test stability improvements; Frontend test coverage expanded for audit, OIDC, protected contexts, and import/export.

Dependencies

Major dependency upgrades across backend and frontend

The backend build configuration (build.sbt) migrates the project from Scala 2.13 to Scala 3.3.7 and upgrades the Akka ecosystem to Apache Pekko 1.6.0. Key library updates include the PostgreSQL client driver to Vert.x 5.0.12, Flyway to 12.6.1, and the WASM bundle to wasm4s 5.0.3. On the frontend, the application upgrades to React 19.0.0, React Router 7.4.0, and Vite 6.2.3, while also adding Swagger UI integration and updating the UI component libraries. The manual documentation site adds swagger-ui-react to display API documentation.

(dependencies) · high confidence

Housekeeping

Documentation build artifacts cleared

The generated build artifacts in the manual's .docusaurus directory have been removed. This folder contains temporary files created by Docusaurus' client bundler, such as search indexes, route definitions, and plugin configurations, which are automatically regenerated during the next build process.

manual/.docusaurus · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 44.

Lenses

  • Code Health 62
  • Architecture 79
  • Maturity 74
  • Readiness 41
  • Security 41
  • Accessibility 40

Changes since last survey

  • 300 commits — 241 feature/other, 59 fixes

By area

  • (root) — 117 commits
  • app/fr — 81 commits
  • docs/v1 — 27 commits
  • izanami-frontend/src — 24 commits
  • manual/docs — 13 commits
  • test/fr — 12 commits
  • .github/workflows — 7 commits
  • docs/assets — 4 commits
  • manual/static — 4 commits
  • conf/sql — 2 commits
  • manual/.docusaurus — 2 commits
  • project/plugins.sbt — 2 commits
  • .g8/form — 1 commit
  • .github/dependabot.yml — 1 commit
  • conf/application.conf — 1 commit
  • izanami-frontend/playwright.config.ts — 1 commit
  • project/build.properties — 1 commit

Notable commits

  • fix: chore: fix backend compilation warnings
  • fix: chore: fix compilation warnings
  • fix: chore: fix compilation warnings
  • fix: chore: fix tests
  • fix: fix: V1 SSE compatibility issue
  • fix: fix: add value field for valued flag overloads
  • fix: fix: allow creating token with update feature right from frontend
  • fix: fix: allow negative numbers in valued flags
  • fix: fix: allow to call legacy endpoint without pattern
  • fix: fix: allow to delete project with contexts
  • fix: fix: allowlist through env variable
  • fix: fix: big configuration right update
  • fix: fix: blocklist / allowed list reading from env variables
  • fix: fix: broken link in doc
  • fix: fix: client secret copy not working for client keys
  • fix: fix: context uncorrectly formatted when condition param is true
  • fix: fix: default value not used for feature fine tuning merge strategy
  • fix: fix: don't allow context-less call when whitelist is set
  • fix: fix: embed tenant in worker urls by context
  • fix: fix: env var name for blocklist
  • …and 280 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

MAIF/izanami was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 20 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit ed8ca29a7ef1e0e951487221f3f79ba77bfd076f — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-b51f968c9b10.