MAIF/otoroshi
36.2
Weak · 5 October 2026
189.5k
lines of production code
Scala
with JavaScript
1
measurement over time
What this system is
Otoroshi is an API gateway and management platform that provides a unified interface for defining, securing, and monitoring API traffic. It features a modern proxy engine supporting HTTP/1.1, HTTP/2, and HTTP/3, alongside a comprehensive plugin system for authentication, transformation, and security. The system includes robust deployment capabilities for Kubernetes via Helm and Kustomize, supporting leader-worker clustering and remote catalog synchronization. Additionally, it offers extensive observability through user-defined analytics dashboards, alerting, and a visual workflow engine for complex request handling.
How it got here
2017–2018 — Otoroshi server scaffolding and core architecture
38 changes.
This period established the foundational structure of the Otoroshi server project, introducing a new unified storage abstraction, a restructured gateway with circuit breakers, and a comprehensive eventing subsystem. It also implemented core security features, including multi-provider authentication and dynamic SSL management, while migrating the backend to Apache Pekko and modernizing the frontend with Vite and a redesigned Back Office UI.
2019–2022 — Next-Gen Engine and Kubernetes Support
50 changes.
This period focused on developing a next-generation proxy engine with a new plugin architecture, modernized data storage drivers, and comprehensive Kubernetes integration via Helm and Kustomize. It also introduced advanced networking capabilities like TCP proxying, HTTP/3 support, and a redesigned administrative UI with automated configuration generation.
2023–2026 — v18 architecture and observability overhaul
56 changes.
This period focused on a comprehensive architectural upgrade for Otoroshi v18, introducing a generic schema-driven API layer, a new extension system, and a visual workflow engine. Significant efforts were directed toward enhanced observability through OpenTelemetry integration, a new user analytics engine with PostgreSQL support, and a Green Score extension for environmental impact monitoring. The work also included modernizing the infrastructure with a sidecar proxy, remote catalog management, and extensive Playwright end-to-end testing to support the new draft-based API lifecycle.
Features
Add 'Foo' extension with back-office management and route designer integration
A new 'Foo' extension is introduced, providing a dedicated back-office section for managing 'Foo' resources (create, read, update, delete) via a new UI page and sidebar item. It also integrates a 'Foo' tab into the route designer, allowing users to configure 'Foo'-specific settings directly within route definitions.
otoroshi/public/javascripts/extensions · high confidence
Add JSON and YAML export buttons for entities
New JSONButton and YAMLButton components have been added to the exporters directory, providing users with the ability to export individual entities (such as routes) as downloadable files. The JSON exporter generates a local JSON blob including the entity's kind and metadata, while the YAML exporter sends the entity data to the backend API endpoint /bo/api/json\_to\_yaml to generate a YAML representation before downloading. These components integrate with the existing SquareButton UI element to offer a consistent export experience.
otoroshi/javascript/src/components/exporters · high confidence
Add JSON diff viewer component for draft comparison
A new \JsonViewCompare\ component has been added to the Drafts module, enabling users to visually compare two JSON objects or arrays. The component highlights additions with green backgrounds and deletions with red backgrounds, supports collapsible nested structures, and provides syntax highlighting for different data types (strings, numbers, booleans, etc.).
otoroshi/javascript/src/components/Drafts/Compare · high confidence
Add Otoroshi Admin API documentation and static site configuration
This change introduces the static documentation assets for the Otoroshi Admin API. It adds a \.nojekyll\ file to ensure GitHub Pages (or similar static hosts) serve the content without processing, and includes the \openapi.json\ specification file (version 18.0.0-dev) which defines the API endpoints for entities such as routes, backends, API keys, and security modules.
manual/next/static · high confidence
Add Otoroshi sidecar tooling and Kubernetes deployment examples
The \tools\ directory now includes a \sidecar\ subdirectory containing the build infrastructure, configuration, and examples for the Otoroshi sidecar. This includes a \build.sh\ script for creating and pushing Docker images (\maif/otoroshi-sidecar\ and \maif/otoroshi-sidecar-init\), a \cert.sh\ script for generating test certificates, and a \deployment.yaml\ demonstrating how to inject the sidecar into Kubernetes pods with necessary secret mounts. Additionally, entrypoint scripts (\entrypoint.sh\, \init.sh\) and local run scripts (\run.sh\, \runjs.sh\) are provided to facilitate local development and testing of the sidecar's traffic interception and TLS handling capabilities.
tools · high confidence
Add PostgreSQL reactive data store driver
Introduces a new reactive PostgreSQL storage driver (\ReactivePgDataStores\) that implements the system's data store interfaces (such as API, route, and cluster state stores) using the Vert.x PostgreSQL client. This enables users to persist Otoroshi state in a PostgreSQL database with support for configurable SSL/TLS settings (including client certificates) and connection options, providing a scalable alternative to the existing in-memory or Redis backends.
otoroshi/app/storage/drivers/reactivepg · high confidence
Add legacy configuration files for Otoroshi
Added \old-application.conf\ and \old-base.conf\ to the \otoroshi/conf/old\ directory, providing default configuration settings for storage, boot behavior, instance identity, proxy, backoffice, admin API, and Akka HTTP server parameters. These files serve as the baseline configuration for older versions or specific deployment modes of Otoroshi, allowing users to customize environment variables and system defaults.
otoroshi/conf/old · high confidence
Add simple Kustomize overlay for single-pod Otoroshi deployment
Introduces a new \simple\ overlay in the Kustomize directory structure, providing a ready-to-use configuration for deploying Otoroshi on managed Kubernetes clusters. This overlay configures a single Deployment with two replicas, an internal ClusterIP Service, and an external LoadBalancer Service for public access. It includes default configurations for admin credentials, Redis connectivity, and domain settings, along with documentation and DNS examples to guide users through initial setup and customization.
kubernetes/kustomize/overlays/simple · high confidence
Add simple-baremetal Kustomize overlay for on-premises Kubernetes
Introduces a new \simple-baremetal\ overlay designed for bare-metal Kubernetes clusters (such as k3s or kubeadm) that lack a cloud-managed LoadBalancer. This overlay configures Otoroshi to expose traffic via NodePort services on ports 31080 (HTTP) and 31443 (HTTPS), allowing users to place an external Layer 4 load balancer (with example configurations for HAProxy and Nginx provided) in front of the cluster nodes. The deployment includes two replicas, pre-configured admin credentials, and references to an external Redis instance, providing a ready-to-use baseline for on-premises deployments.
kubernetes/kustomize/overlays/simple-baremetal · high confidence
Add simple-baremetal-daemonset Kustomize overlay for high-performance baremetal deployments
This change introduces a new Kustomize overlay (\simple-baremetal-daemonset\) designed for baremetal Kubernetes clusters where performance and source IP preservation are priorities. It deploys Otoroshi as a DaemonSet using \hostPort\ bindings (41080/41443) to bypass kube-proxy, reducing network hops. The overlay includes the DaemonSet definition, a ClusterIP Service for internal traffic, a Certificate resource, and example configurations for external L4 load balancers (HAProxy, Nginx) and DNS. It defaults to Otoroshi image version 18.0.0-dev and requires nodes to be labeled with \otoroshi-kind=instance\.
kubernetes/kustomize/overlays/simple-baremetal-daemonset · high confidence
Add support for remote tunnel calls via new TunnelPlugin
Users can now route backend calls through remote tunnels using the new 'Remote tunnel calls' plugin. This feature allows Otoroshi to contact remote services by establishing a tunnel connection, configurable via tunnel ID, URL, authentication credentials, and optional TLS/mTLS settings. The plugin integrates into the backend call step, enabling scenarios where services are exposed through tunnels rather than direct network access.
otoroshi/app/next/tunnel · high confidence
Added Clippy assistant agent to the public interface
The public-facing assets now include a JavaScript configuration for the 'Clippy' helper agent, enabling the animated paperclip assistant with its associated animations (such as Congratulate, SendMail, and Thinking) and sound effects to be served to users.
otoroshi/public/fonts · high confidence
Added Docker-based development environment for Otoroshi
A new Docker development container setup has been added to the \docker/dev\ directory, providing a pre-configured environment for working on Otoroshi. The \Dockerfile.devcontainer\ provisions an OpenJDK 11 base image with essential development tools (git, vim, curl, etc.), Node.js 18 via NVM, and SBT 1.3.3, streamlining the local development workflow. A \.gitignore\ file has also been included to exclude the \oto\ artifact.
docker/dev · high confidence
Added UI controls for deploying, testing, and undeploying remote catalogs
The remote catalogs extension now includes interactive buttons in the configuration UI that allow users to deploy, test (dry run), and undeploy catalog configurations directly from the interface. These components send requests to the backend endpoints (\_deploy, \_test, \_undeploy) and display the results or errors inline, providing immediate feedback on the status of catalog operations without requiring external tools or manual API calls.
otoroshi/javascript/src/extensions/catalogs · high confidence
Added one-shot migration from legacy PostgreSQL exporter to user analytics
A new \LegacyPgMigrator\ component has been added to the analytics migration module, enabling users to migrate historical event data from a legacy single-column JSONB PostgreSQL table into the active user-analytics schema. The migrator uses keyset pagination for efficient processing of large tables and supports idempotent inserts via \ON CONFLICT (id) DO NOTHING\. It also provides a dry-run mode to preview migration counts without modifying the target database.
otoroshi/app/next/analytics/migration · high confidence
Automated OpenAPI specification and UI form generation
The Otoroshi Admin API now uses an automated pipeline to generate its OpenAPI specification, Kubernetes Custom Resource Definitions (CRDs), and UI configuration forms directly from the application's classpath and route definitions. This change introduces a new scanner and generator system that produces the \openapi.json\ specification, flattens it for internal use, and converts the schema into structured forms for the admin UI, while also exporting the necessary CRD YAML files for Kubernetes deployments.
otoroshi/app/openapi · high confidence
Automated generation of built-in plugin documentation
A new documentation generator scans the application's classpath to identify all built-in plugins implementing the NgNamedPlugin interface and automatically creates individual Markdown pages for each. These generated pages include the plugin's name, description, default configuration, and specific documentation steps, ensuring the user-facing documentation stays synchronized with the available plugins without manual updates.
otoroshi/app/next/doc · high confidence
Automated release tooling for versioning, changelog generation, and deployment
This change introduces a new set of scripts in the \scripts/release\ directory to automate the release process. The \github-action-release.js\ script handles updating version numbers across Kubernetes Kustomize manifests, Helm charts, the manual documentation site, and the core application code. The \changelog.js\ script automatically generates release notes by querying the GitHub API for issues and pull requests associated with a milestone. Additionally, \git-push-master.sh\ ensures release commits are safely pushed to the main branch, handling conflicts by rebasing if necessary.
scripts/release · high confidence
Centralized workflow node, operator, and function catalog
The workflows UI now uses a centralized model file to define and register all available workflow components. This change introduces a unified catalog that maps internal node kinds (such as assign, switch, while, and try/catch) and operators to their specific implementation classes, while also supporting extension-provided overloads. Users benefit from a consistent structure for how nodes, operators, and functions are discovered, categorized, and rendered in the workflow editor, ensuring that both built-in and custom extension components are properly integrated into the visual graph.
otoroshi/javascript/src/extensions/workflows/models · high confidence
Default user-analytics dashboards added
The system now ships with five pre-configured user-analytics dashboards (Global Overview, Performance, Errors, APIs & Routes, and Consumers) that are automatically seeded on first activation. These defaults use stable internal identifiers to ensure they are created only once and can be restored without overwriting any user customizations.
otoroshi/app/next/analytics/defaults · high confidence
Initial Helm chart release with cluster mode, Gateway API, and admission webhooks
The Helm chart templates for Otoroshi are now available, providing a complete Kubernetes deployment solution. The chart supports both standalone and Leader/Worker cluster modes, with dedicated deployments and PodDisruptionBudgets for each role. It includes native support for the Kubernetes Gateway API (replacing Ingress) and configures admission webhooks for CRD validation and sidecar injection. Security is enhanced by defaulting to an authenticated, bundled Redis instance and using checksum annotations on pods to trigger rolling restarts when secrets change. The chart also generates a Certificate resource for automatic TLS management and provides a NOTES.txt file to guide users through initial access, credential retrieval, and CRD upgrades.
kubernetes/helm/otoroshi/templates · high confidence
Initial Otoroshi server project scaffolding and documentation
This change introduces the foundational structure for the Otoroshi server project. It adds a .gitignore file to exclude build artifacts, IDE configurations, and local environment files, along with a .scalafmt.conf to enforce consistent Scala code formatting. A docker-compose.yml is provided to spin up local Elasticsearch and Kibana instances for development and analytics. Finally, a readme.md documents the prerequisites (JDK 17, Node 24, Rust, Sbt) and instructions for building the server, admin UI, manual, and CLI in both production and development modes.
otoroshi · high confidence
Initial configuration and routing structure for Otoroshi
This change introduces the foundational configuration and routing files for the Otoroshi gateway. The \application.conf\ and \base.conf\ files define the server's operational parameters, including storage backends (Redis, Cassandra, PostgreSQL, etc.), boot sequence timeouts, instance metadata, and HTTP/HTTPS port settings. It also establishes the underlying Akka/Pekko actor system configuration and Play framework server settings. The \routes\ file maps the initial set of administrative and health endpoints, such as \/health\, \/metrics\, \/bo/dashboard\, and various certificate management APIs, while \logback.xml\ configures the logging infrastructure for these components.
otoroshi/conf · high confidence
Initial custom CSS for Otoroshi documentation site
A new custom stylesheet (custom.css) has been added to define the visual identity of the Otoroshi documentation. This includes a gold/amber color palette, dark mode support, and specific styling for the navbar, sidebar, and footer. It also introduces utility classes for centered images and a grid-based layout for provider cards, enhancing the presentation of setup and deployment guides.
manual/next/src/css · high confidence
Initial release of the Otoroshi Helm chart
This change introduces the first version of the Otoroshi Helm chart (v18.0.0-dev), providing a standardized way to deploy the Otoroshi API gateway on Kubernetes. The chart includes a \Chart.yaml\ (apiVersion v2) and \values.yaml\ that configure a default deployment with 2 replicas, a LoadBalancer service, and a bundled Redis subchart (cloudpirates/redis v0.29.2) for the Lettuce storage backend. It also supports external Redis via \env.redisURL\, custom admin credentials, and JVM resource sizing based on container limits.
kubernetes/helm/otoroshi · high confidence
Initial release of the Otoroshi v18 documentation site
This change introduces the new documentation structure for Otoroshi version 18.0.0-dev, built with Docusaurus. It provides a complete, navigable manual including sections for installation, main entities, detailed topics, tutorials, and plugins, along with an API reference and blog. The site is configured for both production deployment at /otoroshi/manual/ and development at /otoroshi/devmanual/, and includes a plugin catalog definition in plugins.json to support the documentation of Otoroshi's plugin system.
manual/next · high confidence
Introduce API quality scoring and rule engine
Added a new quality assessment system for APIs in the editor, featuring a set of configurable rules across documentation, security, routing, and governance categories. The system evaluates API configurations against these rules (e.g., missing descriptions, lack of HTTPS enforcement, absent rate limiting) and assigns a letter grade (A-F) with corresponding colors based on the percentage of passed checks. This provides users with immediate feedback on API completeness and best-practice adherence directly within the editing interface.
otoroshi/javascript/src/pages/ApiEditor/quality · high confidence
Introduce Green Score extension for API environmental impact monitoring
This change adds a new Green Score extension that calculates and displays an environmental impact score for API routes based on metrics such as overhead, duration, backend duration, call volume, and data transfer sizes. The extension introduces configurable thresholds (excellent, sufficient, poor) for these metrics, allowing users to define what constitutes efficient versus inefficient resource usage. It includes a backend component that listens to gateway events to collect route performance data, stores green score entities with associated rules and thresholds, and provides an API to retrieve current scores. Users can now view green scores for individual routes or groups of routes, with the ability to configure efficiency rules and view detailed breakdowns of metric performance against defined thresholds.
otoroshi/app/greenscore · high confidence
Introduce Netty-based HTTP server and client with HTTP/3 support
This change adds a new Netty-based implementation for both the inbound HTTP server and the outbound HTTP client, replacing the previous stack. The server now supports HTTP/1.1, HTTP/2, and experimental HTTP/3 (QUIC) protocols, with configuration options for native drivers (Epoll, KQueue, IOUring) and specific HTTP/3 settings like QPACK and UDP payload sizes. The new client (\NettyHttpClient\ and \NettyHttp3Client\) provides a unified interface for making HTTP requests over HTTP/1.1, HTTP/2, and HTTP/3, including support for trailers, TLS/mTLS, and proxy configurations. This enables users to leverage HTTP/3 for improved performance and lower latency, while maintaining compatibility with existing HTTP/1.1 and HTTP/2 traffic.
otoroshi/app/netty · high confidence
Introduce Remote Catalogs for external configuration management
This change adds a new Remote Catalogs feature, allowing Otoroshi to import and deploy API entities from external sources such as GitHub, GitLab, Bitbucket, S3, Consul KV, and local files. The \catalogs\ module introduces a new \RemoteCatalog\ data model, a pluggable \CatalogSource\ interface with default implementations for various providers, and a scheduling engine to periodically sync these external configurations. Users can now manage their proxy configuration via version-controlled repositories or key-value stores, with support for JSON and YAML formats, webhook-driven updates, and automated reconciliation of entities.
otoroshi/app/next/catalogs · high confidence
Introduce TCP proxy service with SNI and TLS passthrough support
A new TCP service capability has been added to Otoroshi, allowing users to configure TCP proxies that listen on specific ports and forward traffic to backend targets. The implementation supports multiple modes of operation: standard TCP forwarding, TLS termination, and TLS pass-through. A key feature is SNI (Server Name Indication) matching, which allows multiple TCP services to share the same port by routing connections based on the requested domain name. The service includes configuration for client authentication (mTLS), custom SSL engine providers, and rule-based routing to different target hosts and ports. This change introduces the core data models (TcpService, TcpTarget, TcpRule) and the underlying Akka-based networking logic required to handle these connections.
otoroshi/app/tcp · high confidence
Introduce draft mode for API entities
Adds a new Drafts component area that enables users to create, edit, and toggle between 'published' and 'draft' versions of entities (such as routes and APIs) via a UI toggle. The implementation uses a signal-based state management system to track draft content and version context, automatically syncing changes to the backend via a debounced daemon, and allows viewing the draft state through a URL query parameter.
otoroshi/javascript/src/components/Drafts · high confidence
Introduce experimental Next-Gen Proxy Engine
Adds a new experimental proxy engine (NextGenProxyEngine) that replaces the legacy request handling path with a new architecture based on Pekko Streams, a tree-based routing strategy, and a plugin-step model. This engine introduces a new state management system (NgProxyState) for routes, backends, and API keys, supports advanced features like relay routing for clustered deployments, WebSocket handling, and detailed execution reporting with per-plugin timing. It is enabled via the 'NextGenProxyEngine' configuration block and is marked as experimental in the UI.
otoroshi/app/next/proxy · high confidence
Introduce generic Redis-based data store implementation
A new \GenericDataStores\ class has been added to the \storage/drivers/generic\ location, providing a unified Redis-backed implementation for Otoroshi's data persistence layer. This component initializes a dedicated Akka Actor System and Materializer to interact with Redis, wiring up a comprehensive set of internal data stores including those for APIs, subscriptions, routes, backends, certificates, scripts, and user analytics. It serves as the concrete storage driver that replaces or supplements previous storage mechanisms, enabling the platform to persist configuration and runtime state in a generic Redis backend.
otoroshi/app/storage/drivers/generic · high confidence
Introduce new Route Designer UI components
The Route Designer page now uses a new set of React components for its interface. This includes a visual flow editor (Designer.js) with node-based plugin configuration, a step-by-step Route Wizard for creating new routes from templates (e.g., REST API, GraphQL, Mocks), and a dedicated Routes Table for managing existing routes. The update also adds specific forms for configuring Eureka targets (both internal and external) and a GraphQL schema editor, replacing previous implementation approaches with this new modular design.
otoroshi/javascript/src/pages/RouteDesigner · high confidence
Introduce new workflow engine, nodes, functions, and operators
This change adds the core backend infrastructure for the new workflow system in the \next\ admin UI. It introduces a \WorkflowEngine\ capable of executing workflows with support for pausing, resuming, and jumping between nodes, along with a \WorkflowDebugger\ for step-by-step execution. The update registers a comprehensive set of workflow nodes (including flow control like \parallel\, \switch\, \foreach\, and error handling via \try\/\catch\), core functions (such as HTTP client calls, memory management, file I/O, and email sending), and data transformation operators (including array manipulation, string processing, and JSON parsing). Additionally, it defines the data models for workflows, including support for orphans, notes, and scheduled job configurations.
otoroshi/app/next/workflow · high confidence
Introduce sidecar proxy with internal/external routing and mTLS support
The sidecar component now includes a proxy implementation (\proxy.js\) that manages two distinct listeners: an internal proxy bound to \127.0.0.1\ and an external proxy bound to \0.0.0.0\. The proxy routes requests to the Otoroshi backend, handling TLS termination and mutual TLS (mTLS) via configurable client certificates and CA roots. It enforces origin checks to ensure requests originate from localhost and supports environment-driven configuration for ports, certificate paths, and security flags (e.g., \REJECT\_UNAUTHORIZED\, \ENABLE\_ORIGIN\_CHECK\). The entry also adds test utilities for generating PKI certificates and simulating mTLS server/client interactions to validate the proxy's security behavior.
tools/sidecar · high confidence
Introduce user-defined analytics alerting
Added the backend logic for user-defined alerts based on analytics queries. This includes the \AlertEvaluationJob\ which periodically evaluates enabled alerts, the \AlertEvaluator\ which executes queries against the active analytics exporter and applies reducers/comparisons, and the \UserAnalyticsAlertEvent\ model which emits structured alert events containing per-condition evaluation details when thresholds are met.
otoroshi/app/next/analytics/alerts · high confidence
Introduce user-defined analytics alerts and dashboards
Users can now create and manage custom analytics alerts and dashboards. The \UserAlert\ model allows defining conditions based on analytics queries (e.g., error rates) with configurable thresholds, reducers, and operators, which are evaluated periodically to trigger events. The \UserDashboard\ model enables the creation of custom dashboards composed of widgets that display data from analytics queries. Both entities support storage in Redis and can be initialized from global configuration templates.
otoroshi/app/next/analytics/models · high confidence
Introduce workflow designer with visual graph layout, debugging, and function management
The workflow designer now provides a visual interface for building and managing workflows, featuring automatic graph layout via ELK, a node catalog for selecting operators and functions, and a terminal for live testing and debugging. Users can run workflows in step-by-step debug mode, view execution reports, and manage user-defined functions directly within the workflow context. The designer also supports tagging workflows and preserves node positions for a consistent editing experience.
otoroshi/javascript/src/extensions/workflows · high confidence
Introduces a new extensible plugin architecture with multiple execution stages
Users can now extend Otoroshi's behavior through a new scripting plugin system that supports multiple execution stages: access validation, pre-routing, request transformation, request sinks, event listening, scheduled jobs, and custom request handling. This change adds the core Scala traits and context objects (such as AccessValidator, PreRouting, RequestSink, Job, and RequestHandler) that define these extension points, along with a documentation generator that scans the classpath to discover and list available plugins. The system includes default and compiling-state implementations for each stage to manage plugin lifecycle and loading states.
otoroshi/app/script · high confidence
Introduces lightweight async utility wrappers to replace external functional libraries
The \otoroshi/app/next/utils\ package now includes new \FEither\ and \FOption\ classes, which provide \Future\-based monadic wrappers for \Either\ and \Option\ respectively. These utilities allow the application to handle asynchronous error handling and optional values without depending on external functional programming libraries like Cats, simplifying the dependency footprint while maintaining consistent async composition patterns for plugin and core logic.
otoroshi/app/next/utils · high confidence
Introduces new 'next' generation API, route, and plugin data models
This change adds a new set of internal data models for the Otoroshi proxy engine, located in the \otoroshi/app/next/models\ package. These new models replace or supplement the legacy structures, introducing \NgRoute\ for granular routing definitions, \NgRouteComposition\ for grouping multiple minimal routes, and \NgMinimalRoute\ for simplified route configurations. The update also brings in \NgPlugins\ and \NgPluginInstance\ to manage plugin execution with explicit indexing and binding capabilities, \NgBackend\ and \NgClientConfig\ for backend connection and timeout settings, and \NgFrontend\ for defining domain, path, and header matching rules. Additionally, it includes \RouteTemplate\ for reusable route definitions and \NgTreeRouter\ data structures to support a new tree-based routing strategy.
otoroshi/app/next/models · high confidence
Introduces the new Ng plugin architecture
The plugin system has been rewritten with a new internal architecture (Ng plugins). This location introduces the core API definitions, typed context keys for request state management, and the initial set of plugins implemented using this new framework, including access control plugins for API keys, legacy authentication modules, multi-authentication, and domain name validation.
otoroshi/app/next/plugins · high confidence
Introduction of BackOfficeServices.js for API client operations
The file \BackOfficeServices.js\ has been added to the \otoroshi/javascript/src/services\ directory, establishing a centralized client-side service layer for Back Office API interactions. This module exposes functions for managing cluster state (syncing with leader, resetting database, managing cluster members), monitoring system health (fetching tunnels, snow monkey outages and configuration), and retrieving environment metadata (version, user context). It also includes deprecated stubs for legacy service descriptor fetching, indicating a shift away from per-service descriptor handling in the frontend.
otoroshi/javascript/src/services · high confidence
Introduction of Global Expression Language (EL) engine
A new Global Expression Language (EL) engine has been added to Otoroshi, enabling users to evaluate dynamic expressions within string values using the \${...}\ syntax. This feature allows for the extraction and manipulation of contextual data, including request parameters, route details, API keys, user information, and JWT tokens. It also provides built-in support for date formatting and arithmetic operations, as well as expression chaining with default value fallbacks, allowing for more flexible and dynamic configuration of routes and services without hardcoding values.
otoroshi/app/el · high confidence
Introduction of a generic, schema-driven API layer with OpenAPI generation
The \otoroshi/app/api\ package now provides a foundational, generic API infrastructure that allows entities (such as APIs, routes, and consumers) to be exposed via a standardized REST interface. This change introduces core abstractions like \Resource\, \ResourceVersion\, and \WriteAction\ to define entity metadata and access controls, alongside a \TweakedGlobalConfig\ wrapper. Crucially, the new \openapi.scala\ module automatically generates valid OpenAPI specifications for these resources, including endpoints for counting and retrieving entities by ID, with security and error responses defined per resource access rights. This enables consistent, schema-backed management of Otoroshi entities through a unified API surface.
otoroshi/app/api · high confidence
Introduction of cluster mode with leader/worker architecture
Otoroshi now supports a clustered deployment mode, allowing users to run multiple instances in a leader-worker topology for high availability and scalability. The system introduces distinct roles: a Leader node that manages the authoritative state and a Worker node that synchronizes with the leader. This change includes configuration options for worker behavior (such as polling intervals, retries, and local database paths), state synchronization mechanisms, and specific filtering rules for keys that should not be synced across the cluster. Users can enable this mode via environment variables to distribute load and ensure resilience against single-node failures.
otoroshi/app/cluster · high confidence
Introduction of new authentication module implementations and user validation framework
This change introduces the core implementation files for several new authentication providers, including Basic Auth, LDAP, OAuth 1, OAuth 2, WebAuthn, and Wasm-based authentication. It also establishes a unified user validation framework via \RemoteUserValidatorSettings\ and the \ValidableUser\ trait, allowing auth modules to enforce user access through local JSON path checks, remote HTTP validators, and allow/deny lists. Additionally, a dedicated \PrivateAppsSessionManager\ is added to handle session cookie encoding and decoding for private applications, supporting both standard and JWT-based session configurations.
otoroshi/app/auth · high confidence
Introduction of new core model entities and data structures
This change introduces a comprehensive set of new model classes in the \otoroshi/app/models\ package, establishing the data structures for core platform features. Key additions include \JWTVerifier\ for handling JSON Web Token verification and injection, \ApiKey\ with support for rotation and throttling quotas, and \OtoroshiAdmin\ models supporting both simple and WebAuthn authentication types. The diff also adds models for \BackOfficeUser\ session management, \ChaosConfig\ for fault injection testing, \CorsSettings\ for cross-origin resource sharing, and \DataExporter\ configurations for sending analytics to destinations like S3 and Elasticsearch. These files define the serialization, validation, and storage interfaces for these new capabilities.
otoroshi/app/models · high confidence
New API consistency service for plan lifecycle management
A new ApiConsistencyService has been introduced to automatically manage API subscriptions when API plans are modified. This service detects changes in API plans (additions, deletions, or updates) and synchronizes the corresponding subscriptions in both draft and live data stores, ensuring that subscription data remains consistent with the current API configuration.
otoroshi/app/next/services · high confidence
New Coraza WAF extension configuration UI
A new JavaScript-based extension for the Coraza Web Application Firewall has been added to the Otoroshi back-office. This introduces a dedicated configuration page where users can define WAF settings, including toggles for inspecting request and response bodies, setting the number of Coraza instances, configuring the engine mode (Blocking vs DetectionOnly), enabling the OWASP Core Rule Set, and managing custom SecRules directives via a JSON code editor.
otoroshi/javascript/src/extensions/coraza · high confidence
New Coraza WAF plugin and refactored WASM runtime infrastructure
Users can now deploy the Coraza Web Application Firewall as a native Otoroshi plugin, with the system introducing a dedicated \coraza.scala\ implementation that manages a pool of WASM VM instances for request and response inspection. This change is part of a broader refactoring of the WASM runtime in \otoroshi/app/wasm\, which includes new host function definitions in \host.scala\ to support proxy-WASM interfaces and updated core configuration models in \wasm.scala\ that expose granular authorizations (such as HTTP access, data store access, and proxy state access) and lifetime management options for WASM instances.
otoroshi/app/wasm · high confidence
New Docker build infrastructure with optimized JVM configuration
The docker/build directory now provides a complete, new set of Dockerfiles and build scripts for Otoroshi. The images are built using multi-architecture support (linux/arm64, linux/amd64) and support multiple JDK versions (17, 21, 25) via Eclipse Temurin, Amazon Corretto, and GraalVM. The entrypoint scripts automatically size the JVM heap based on container memory limits (capping at 60% or ensuring a minimum 25% / 512 MB reserve), enforce the G1 garbage collector, and set MALLOC\_ARENA\_MAX=2 to reduce memory overhead. The build system also supports running with or without root privileges and handles plugin loading via classpath injection.
docker/build · high confidence
New Elastic and Webhook analytics implementations
Added new \ElasticAnalytics\ and \WebHookAnalytics\ services in the \otoroshi/events/impl\ package to handle event ingestion. The \ElasticAnalytics\ component introduces support for Elasticsearch 7+ index templates and mappings, including configuration for field limits and dynamic string templates, while the \WebHookAnalytics\ component enables pushing analytics events to external webhooks with support for URL parameter substitution and mutual TLS authentication.
otoroshi/app/events/impl · high confidence
New Green Score extension for API efficiency and sustainability scoring
The Green Score extension is now available in the Otoroshi Back Office, providing a dedicated dashboard to monitor and configure the environmental efficiency of your APIs. Users can create and manage 'groups' of routes, applying specific scoring rules and thresholds to calculate static and dynamic green scores. The interface includes visualizations such as radar charts for rule breakdowns, stacked area charts for historical trends, and efficiency charts for route-level performance. Configuration is handled via a new 'Edit Group' form where users can select routes, define efficiency paths, and set thresholds for metrics like overhead, duration, and data usage.
otoroshi/javascript/src/extensions/greenscore · high confidence
New HTTP Listeners management UI
A new interface for managing HTTP listeners has been added to the Back Office. This feature introduces a dedicated page and form schema that allows users to configure listener properties including host, port, TLS settings, and protocol support (HTTP/1.1, HTTP/2, H2C, HTTP/3). The UI displays a table of existing listeners with columns for name, host, port, and status indicators for enabled, TLS, and protocol states, enabling direct configuration of access logs and client authentication.
otoroshi/javascript/src/extensions/httplisteners · high confidence
New JWT Verifier entity form with configurable signature algorithms and verification strategies
A new form entity for configuring JWT Verifiers has been added, allowing users to define signature settings (such as HMAC, RSA, ECDSA, and JWK Set sources) and select from verification strategies including PassThrough, Sign, and Transform. This change introduces the UI components necessary to manage these specific JWT validation and signing configurations within the application.
otoroshi/javascript/src/forms/entities · high confidence
New JWT-based API key extraction plugin
A new core plugin, JwtApikeyExtractor, has been added to allow extracting API keys from JWT tokens. This plugin supports verification via HMAC (HS256/384/512) and asymmetric algorithms (ECDSA, RSA) using configured key pairs or secrets. It validates token claims including expiration, issuer, and optional XSRF tokens, and can enforce request attributes (path, verb, host) matching. The plugin is registered in the default core plugin set alongside existing API key extractors.
otoroshi/app/plugins/core · high confidence
New JavaScript entry points and utility modules for backoffice and login flows
This change introduces a set of new JavaScript source files in the backoffice frontend to support specific UI entry points and shared utilities. New entry points include \backoffice.js\ for the main application, \genericlogin.js\ and \multilogin.js\ for authentication flows, and \simplelogin.js\ for basic login scenarios. It also adds \webauthn.js\ to handle WebAuthn credential ceremonies with retry logic, \util.js\ for common helpers (like formatting and random data generation), \explainations.js\ for circuit breaker configuration tooltips, and \raf.js\ for requestAnimationFrame polyfills. These files provide the foundational client-side code for the backoffice interface and its various login modes.
otoroshi/javascript/src · high confidence
New Kubernetes integration jobs for CRDs, Gateway API, and certificate synchronization
This change introduces a new set of scheduled jobs in the \otoroshi/app/plugins/jobs/kubernetes\ directory to manage Kubernetes resources. The \KubernetesOtoroshiCRDsControllerJob\ watches and syncs Otoroshi Custom Resource Definitions, while the \KubernetesGatewayApiControllerJob\ implements support for the Kubernetes Gateway API by watching Gateway, HTTPRoute, and GRPCRoute resources and translating them into Otoroshi NgRoute entities. Additionally, the \KubernetesCertSyncJob\ handles the bidirectional synchronization of TLS certificates between Kubernetes secrets and Otoroshi's internal certificate store, ensuring that certificates are imported, updated, and cleaned up based on cluster state. These jobs rely on a new \KubernetesClient\ for API communication and a comprehensive \KubernetesConfig\ for configuration.
otoroshi/app/plugins/jobs · high confidence
New Lettuce-based Redis data store driver
Otoroshi introduces a new Redis storage driver built on the Lettuce client library, replacing the previous implementation. This driver supports standalone, sentinel, and cluster topologies, and allows configuring connection pooling, read preferences, and thread pool sizes via configuration. It also enables TLS/SSL for Redis connections using PEM certificates or keys provided directly in the configuration, eliminating the need for JVM-wide SSL system properties.
otoroshi/app/storage/drivers/lettuce · high confidence
New Next-Gen API Management Controllers
This change introduces a new set of administrative API controllers for the next-generation API management engine. The \ApisController\ provides live statistics for draft and published APIs, while \NgBackendsController\, \NgRoutesController\, and \NgRouteCompositionsController\ expose full CRUD operations for backends, routes, and route compositions. Additionally, \NgPluginsController\ exposes plugin metadata and forms, \EntitiesController\ allows querying entity dependency graphs, and \TryItController\ enables testing routes and services with support for TLS and Kafka. These controllers form the backend API layer for the new Otoroshi Next engine.
otoroshi/app/next/controllers · high confidence
New PostgreSQL-based user analytics query engine
Added a new analytics query layer in the \otoroshi/app/next/analytics/queries\ package that supports querying user analytics data stored in PostgreSQL. This includes core query definitions for scalar metrics (total requests, total errors), pie charts (requests by status code, by method), and top-N lists (by route, API, API key, user, domain, country, and error routes). The implementation introduces time-bucketing logic for time-series data, parameterized SQL generation with automatic filter handling, and helper utilities for binding Vert.x SQL client tuples and converting database rows to JSON responses.
otoroshi/app/next/analytics/queries · high confidence
New SAML authentication module with full protocol support
This change introduces a new SAML authentication module (\SAMLClient\ and \ValidatorUtils\) that enables Single Sign-On and Single Logout capabilities. It supports both HTTP-POST and HTTP-Redirect protocol bindings for SSO and logout flows, allowing users to configure custom forms and manage relay states. The implementation includes robust validation of SAML responses and assertions, signature verification using X.509 certificates, and support for encrypted assertions. Users can now integrate with SAML Identity Providers (such as Okta) by providing certificate details for signing and decryption, with the system handling the creation of signed requests and validation of incoming responses.
otoroshi/app/auth/saml · high confidence
New TrafficCaptureEvent for GoReplay-compatible traffic mirroring
A new \TrafficCaptureEvent\ analytic event has been added to the \otoroshi/app/next/events\ module, enabling users to capture and export traffic data in a format compatible with GoReplay. This event supports capturing both requests and responses, with options to prefer backend or original traffic details, and outputs data either as a structured JSON object or as a raw GoReplay-formatted string for immediate use in traffic replay scenarios.
otoroshi/app/next/events · high confidence
New User Analytics API endpoints for dashboards, queries, and alert events
This change introduces three new API controllers that expose the user-analytics capabilities to the backend. The \AnalyticsController\ provides endpoints to run dynamic queries (\POST /api/analytics/\_query\), retrieve the available query schema and widget types (\GET /api/analytics/\_schema\), list data projections (\GET /api/analytics/\_projections\), and test database connections (\POST /api/analytics/\_test-connection\). The \AlertEventsController\ adds endpoints to list fired alert events and manage their 'seen' status (\GET/POST /api/analytics/alerts/:alertId/events\). The \UserDashboardController\ allows super-admins to restore default dashboard configurations (\POST /api/analytics/dashboards/\_restore-defaults\). These endpoints enforce tenant-based access control and require super-admin privileges for administrative actions.
otoroshi/app/next/analytics/controllers · high confidence
New admin API controllers for analytics, API keys, auth modules, and more
The admin API surface is expanded with a suite of new controllers in the \adminapi\ package, providing dedicated endpoints for managing analytics data streams, API key quotas and lifecycle, authentication module configurations, certificate management (including a new deduplication tool for Let's Encrypt certificates), client certificate validators, cluster state monitoring, data exporter configurations, and error templates. These controllers standardize CRUD operations, enforce user rights checks, and integrate with the underlying data stores and event systems.
otoroshi/app/controllers/adminapi · high confidence
New back-office pages for alerts, audit logs, API key analytics, and atomic design system
This change introduces several new pages in the Otoroshi back-office UI. The AlertPage and AuditPage provide super-admins with dedicated tables to view and inspect alert and audit log events, including a button to view full event content. The ApiKeyStatsPage adds a dedicated analytics view for individual API keys, displaying usage charts. Additionally, the AtomicDesignPage serves as a visual reference for the UI's atomic design system, showcasing buttons, inputs, colors, and other components to aid in styling and development.
otoroshi/javascript/src/pages · high confidence
New background jobs for API key rotation, certificate management, and service descriptor migration
This update introduces several new scheduled jobs to handle routine maintenance and migration tasks automatically. The new API keys secrets rotation job periodically rotates API keys to enhance security. Certificate management is handled by a new initial certs job that generates and manages root, intermediate, wildcard, client, and JWT signing certificates using the modern PKI system, while deprecating the old self-signed method. A service descriptor migration job is added to automatically convert legacy Service Descriptors into the new Route format, with safeguards to prevent data loss during the transition. Additionally, an eventstore checker job monitors Elasticsearch connectivity, a new engine alert job notifies users when the legacy proxy engine is still in use, and a state exporter job allows for periodic full state exports.
otoroshi/app/jobs · high confidence
New baremetal DaemonSet overlay for Otoroshi
Adds a new \cluster-baremetal-daemonset\ Kustomize overlay that deploys Otoroshi as DaemonSets (one pod per node) on baremetal Kubernetes clusters. This configuration introduces separate Leader and Worker DaemonSets using node affinity labels (\otoroshi-kind=leader\/\worker\) and exposes HTTP/HTTPS traffic directly via host ports (41080/41443 for leaders, 42080/42443 for workers), eliminating the need for an external load balancer for ingress. The overlay includes example configurations for HAProxy and Nginx to route external traffic to these host ports, along with default secret and config map generators for initial setup.
kubernetes/kustomize/overlays/cluster-baremetal-daemonset · high confidence
New baremetal deployment overlay with NodePort services and load balancer examples
Adds a new \cluster-baremetal\ Kustomize overlay that patches the leader and worker services to use NodePort type, exposing HTTP/HTTPS on ports 31080, 31443, 32080, and 32443. Includes example configurations for HAProxy and Nginx to route traffic to these NodePorts, along with a DNS example file and a README detailing prerequisites and port allocation for baremetal Kubernetes clusters.
kubernetes/kustomize/overlays/cluster-baremetal · high confidence
New challenge verification demo server
A new Express-based demo server has been added to the challenge demo area to verify Otoroshi authentication challenges. It supports both V1 and V2 challenge protocols by inspecting the Otoroshi-State header, verifying JWTs using a configurable secret key, and returning decoded token information along with the challenge version in the response.
demos/challenge · high confidence
New cluster overlay for leader-worker deployment mode
Adds a new \cluster\ overlay that deploys Otoroshi in leader-worker mode, providing separate control-plane (leader) and data-plane (worker) deployments with cloud-managed LoadBalancer services for external access. The overlay configures two leader and two worker replicas by default, includes DNS examples for routing admin and production traffic to the respective load balancers, and sets up initial admin credentials and Redis connection details via secret and config maps.
kubernetes/kustomize/overlays/cluster · high confidence
New developer tooling and demo scripts for Otoroshi
This change introduces a suite of new scripts to streamline development, testing, and documentation workflows. The \api-plans-demo.ts\ script allows developers to provision a local Otoroshi instance with various API plans (keyless, apikey, jwt, mtls, oauth2) and test them interactively. Build and test automation is enhanced with \build.sh\ and \tests.sh\, which orchestrate UI compilation, server builds, and specific test suites (including browser and mTLS tests). Documentation generation is updated via \doc.sh\ to support the new manual structure, while \fmt.sh\ standardizes code formatting for both UI and server components. Additional utility scripts include \helm.sh\ for packaging Helm charts, \sbom.sh\ for generating software bill of materials, \dependencies.sh\ for checking library updates, and \update-extism.sh\ for managing native library dependencies.
scripts · high confidence
New documentation components for plugins, data exporters, and expression language
The manual now includes dedicated React components to enhance the documentation experience. A new BuiltInPlugins page allows users to search and filter plugins by name, category, and step, with expandable cards showing descriptions and default configurations. DataExporterDocs provides a reference for filtering and projection expressions used in data exporters, while ExpressionLanguage documents available variables for dates, services, requests, API keys, tokens, and context. Additional utility components include Badge for status indicators, Image for base URL handling, NewTabLink for external links, SetupOtoroshi for quick start instructions, and TabitemWithVersion for versioned content tabs.
manual/next/src/components · high confidence
New documentation site pages for API Reference and Ecosystem
The documentation site now includes dedicated pages for the API Reference and the Ecosystem. The API Reference page dynamically loads Swagger UI to display the Otoroshi Admin REST API documentation using the local OpenAPI spec. The Ecosystem page showcases community-maintained open-source projects (such as AI gateway extensions, WAF, and CLI tools), integrated developer portals (like Daikoku), and managed hosting providers (Cloud APIM, Clever Cloud). These pages are part of the new Next.js-based documentation structure.
manual/next/src/pages · high confidence
New dynamic SSL context and key management with PKI and OCSP support
This change introduces a new dynamic SSL infrastructure in the \otoroshi/app/ssl\ package, replacing or augmenting previous static configurations. It adds a \DynamicSSLContext\ that can be reconfigured on the fly based on configuration hashes, and a \DynamicKeyManager\ that handles certificate selection, caching, and auto-generation for domains. The update includes a new PKI API (\pki.scala\, \pkiModels.scala\) for generating key pairs, CSRs, and certificates (including self-signed CAs and sub-CAs), as well as an OCSP responder (\ocsp.scala\) for certificate revocation checking. Utility classes like \CertInfo\, \PemUtils\, \P12Helper\, and \PemCertificate\ are added to handle PEM/PKCS12 parsing and certificate metadata extraction. These components work together to enable more flexible, dynamic, and automated TLS certificate management within Otoroshi.
otoroshi/app/ssl · high confidence
New eventing subsystem with multi-target data exporters
Otoroshi introduces a new eventing architecture in the \otoroshi/app/events\ package, replacing the previous analytics model. This change adds a centralized \OtoroshiEventsActor\ and \OtoroshiEventsActorSupervizer\ to manage a unified event stream. Users can now configure data exporters to send events to multiple targets, including Kafka (with SASL/SSL/mTLS support), Pulsar, S3, StatsD/Datadog, and Webhooks. The system also introduces new event types for alerts (e.g., API key rotation, circuit breaker states), audit logs (back-office and admin API actions), and analytics, allowing for more granular monitoring and external integration.
otoroshi/app/events · high confidence
New extension system for HTTP listeners and admin APIs
This change introduces the foundational infrastructure for the new extension system in Otoroshi. It adds the core \AdminExtension\ trait and router, allowing extensions to define custom routes for the Admin API, Back Office, Private Apps, and Well-Known endpoints. It also introduces the \HttpListener\ model and configuration, enabling users to define and manage multiple HTTP listeners with specific protocol settings (HTTP/1.1, HTTP/2, h2c, HTTP/3) and TLS options, replacing the previous single-listener approach. An example extension (\Foo\) is provided to demonstrate how to implement data stores and state management within this new framework.
otoroshi/app/next/extensions · high confidence
New form input components for array, object, and code editing
The inputs directory now includes a suite of new React components to enhance form building: ArrayInput and ArraySelectInput allow users to dynamically add, remove, and edit lists of values or key-value pairs; ObjectInput enables editing of key-value object structures with support for bcrypt hashing; CodeInput and MonacoInput provide syntax-highlighted code editing with JSON validation and theme awareness; BooleanInput offers toggle switches for boolean fields; and supporting components like Collapse, Help, and NumberInput improve layout and usability. These components replace previous ad-hoc implementations and provide a consistent, reusable API for form fields across the application.
otoroshi/javascript/src/components/inputs · high confidence
New health checker implementation with mTLS, logic checks, and blocking on failure
A new health checker component has been introduced in the \otoroshi/app/health\ directory. This implementation performs health checks using mTLS configuration and injects security claims (state and info tokens) into requests. It supports a new 'logic check' feature that validates a specific header response to confirm backend processing. Additionally, the system can now block incoming requests if a target's health check fails (configured via \blockOnRed\), preventing traffic from reaching unhealthy backends.
otoroshi/app/health · high confidence
New in-memory datastore with file, HTTP, and S3 persistence backends
The in-memory storage driver now supports persistent state via three new backend options: file-based (NDJSON), HTTP, and S3. Users can configure the persistence mode via \app.inmemory.persistenceKind\ (FilePersistenceKind, HttpPersistenceKind, or S3PersistenceKind) to ensure data survives restarts or cluster swaps. The implementation introduces a modern swap strategy for cluster state synchronization and includes a configurable \app.inmemory.modern\ flag to toggle between legacy and optimized data structures.
otoroshi/app/storage/drivers/inmemory · high confidence
New mTLS demo with backend, frontend, and client components
Added a new mTLS demonstration in the demos/mtls directory, including Node.js scripts for a backend server (backend.js, backend2.js, validator.js), a client script (client.js), and the necessary CA certificates, keys, and CSRs in the ca/ and client/ directories to facilitate mutual TLS authentication.
demos/mtls · high confidence
New mTLS integration test suite and fake Kube API server
Added a new mTLS testing harness under \scripts/tools/mtls-tests\ that validates mutual TLS communication between a Go-based backend server, the Otoroshi gateway, and a frontend client. The suite includes Go clients and servers, certificate generation scripts, and a Node.js script (\oto.js\) to configure the Otoroshi service with mTLS settings. Additionally, a new \scripts/tools/fakekubeapiserver\ tool was introduced to mock Kubernetes API responses, supporting the test environment.
scripts/tools · high confidence
New private apps authentication UI views
Added new Scala HTML templates for the private apps authentication flow, including a home page with login/logout actions, a main layout template, and specific views for multi-login, simple login, and passwordless login. These views integrate Bootstrap and Font Awesome assets and initialize JavaScript bundles (multilogin, simplelogin) to handle the respective authentication interactions.
otoroshi/app/otoroshi/views/privateapps · high confidence
New relay routing demo for multi-zone Otoroshi clusters
Added a new demo in demos/relay that illustrates how to deploy an Otoroshi cluster across multiple network zones with automatic relay routing. The setup includes three leader zones and three worker zones, configured via docker-compose to communicate through a shared Redis instance, along with a call.sh script to test cross-zone service discovery and routing.
demos/relay · high confidence
New remark and rehype plugins for file inclusion and image base URL handling
Added two new documentation build plugins: \remark-file-include\ allows including external file content into code blocks via an \include=\ meta tag with variable substitution (e.g., \@{version}\), and \rehype-img-baseurl\ ensures local image sources in both Markdown and MDX files are correctly prefixed with the site's base URL, fixing broken image links when the site is deployed under a sub-path.
manual/next/plugins · high confidence
New stateful client lifecycle management for Redis, PostgreSQL, Kafka, and Pulsar
Otoroshi now manages the lifecycle of stateful clients (Redis, PostgreSQL, Kafka, and Pulsar) through a centralized manager that binds them to the node's lifecycle. This change introduces a new configuration structure under \otoroshi.stateful-clients\ (and \stateful-clients-json\) allowing users to define pre-configured clients with specific IDs and node-kind scoping (all, leader, worker). The system automatically handles client creation, reuse, and cleanup based on configuration changes, ensuring that clients are properly started and stopped in sync with the Otoroshi node. Additionally, dedicated stateful clients are now available for the distributed rate-limiter, supporting both standalone/sentinel and cluster Redis topologies.
otoroshi/app/statefulclients · high confidence
New user analytics dashboards and alerting interface
This change introduces a complete front-end for user-defined analytics dashboards and alerting. Users can now create and manage dashboards with configurable widgets (line, bar, pie, table, etc.) that visualize analytics queries, apply time-range and entity filters, and set auto-refresh intervals. Additionally, users can define custom alerts based on these analytics queries, configure alert conditions (thresholds, operators, filters), and view a log of fired alert events with severity indicators.
otoroshi/javascript/src/pages/analytics · high confidence
New utility library for metrics, filtering, and async operations
Added a suite of new utility classes in the \otoroshi/app/utils\ package to support core platform capabilities. This includes \CustomCollector\ for exposing internal metrics to Prometheus, \EntityFiltering\ for query-based JSON filtering and sorting, and \AsyncUtils\ for sequential asynchronous processing without Akka Streams. Additional utilities include \KaleidoscopeShim\ for regex pattern matching, \Base64Codec\ for high-performance encoding/decoding, and \FutureImplicits\ for enhanced Future handling.
otoroshi/app/utils · high confidence
New wizards for creating and managing authentication and JWT verifier configurations
Users can now use guided wizards to create, select, clone, and update authentication configurations and JWT verifiers. The new AuthenticationWizard and JwtVerifierWizard components provide a step-by-step interface for these tasks, including options to start from scratch, pick an existing configuration, or clone an existing one. The wizards integrate with the existing form system, allowing users to edit and manage these settings directly within the wizard flow.
otoroshi/javascript/src/forms/wizards · high confidence
New workflow function nodes for logging, email, user-defined code, and sub-workflows
This change introduces four new function nodes for Otoroshi workflows, each with its own configuration UI. The LogFunction node allows logging messages with a custom renderer. The SendMailFunction node enables sending emails via various providers (Mailjet, Mailgun, SendGrid, Scaleway, MailPace, or generic) with a dynamic form schema. The UserDefinedFunction node allows calling user-defined JavaScript functions with a code editor for arguments. The WorkflowFunction node enables calling other workflows (local or global) by selecting from a catalog, passing inputs.
otoroshi/javascript/src/extensions/workflows/functions · high confidence
New workflow node definitions and UI components
The workflow editor now includes definitions and UI components for a comprehensive set of node types, enabling more complex logic flows. New nodes include control flow structures (IfThenElse, Switch, ParallelFlows, While, TryCatch, Jump), data transformation (Map, FlatMap, ForEach, Filter, Assign, Value), and execution management (Async, Call, Wait, Returned, Start, End, StopAndError). Additionally, a Note node allows for visual annotations within the workflow graph.
otoroshi/javascript/src/extensions/workflows/nodes · high confidence
New workflow operators for array, map, and data manipulation
This change introduces a comprehensive set of new workflow operators for the Otoroshi UI, enabling users to manipulate data structures directly within their workflows. The diff adds definitions for array operations (append, prepend, drop, get by index, check emptiness, pagination), map operations (get, put, delete, rename, check emptiness), and general data utilities (base64 encode/decode, JSON parsing, string splitting, equality checks, boolean logic, and memory references). These operators are defined with specific form schemas that support reading values from memory or using direct JSON input, providing a consistent interface for data transformation tasks.
otoroshi/javascript/src/extensions/workflows/operators · high confidence
User analytics exporter refactored to support extensible event projections
The user analytics exporter now uses an extensible projection system, allowing extensions to define their own event types and storage tables instead of relying on hardcoded logic for gateway and alert events. This change introduces the \AnalyticsProjection\ trait, which standardizes how events are accepted, stripped, and stored in PostgreSQL, and adds a retention job that automatically prunes data from all registered projections based on the configured retention period. Existing gateway and alert event handling is preserved through core projections, while the new architecture enables third-party plugins to seamlessly integrate their own analytics data into the same dashboard and alerting infrastructure.
otoroshi/app/next/analytics/exporter · high confidence
Architecture
New unified storage abstraction layer
The storage subsystem now uses a new \DataStores\ trait and \BasicStore\/\RawDataStore\ interfaces to manage all entities (routes, APIs, backends, users, etc.) through a unified abstraction. This change introduces a centralized builder pattern for initializing data stores and standardizes CRUD operations across different backend implementations, laying the groundwork for pluggable storage drivers and improved consistency in how data is persisted and retrieved.
otoroshi/app/storage · high confidence
Behavioural changes
Automated reference configuration generation for documentation
The manual now includes a build script (manual/config.js) that automatically processes the reference configuration file (reference.conf) to generate a filtered version (reference-env.conf) for documentation purposes. This script removes lines marked with '\#not-used' and filters content based on specific delimiters or inclusion rules, simplifying the documentation generation process by ensuring only relevant configuration snippets are included in the final docs.
manual · high confidence
Back Office App restructured with new analytics, security, and plugin management pages
The Back Office application has been significantly reorganized to support new management capabilities. The UI now includes dedicated pages for user-defined analytics dashboards and alerts, data exporters, global JWT verifiers, client certificate validators, and WebAssembly plugins. Additionally, the sidebar mode persistence logic has been updated to support expanded, collapsed, and hover states, migrating from the previous boolean flag. Legacy Service Descriptor components have been removed from the frontend codebase.
otoroshi/javascript/src/apps · high confidence
Backoffice UI refactored with new component architecture and sidebar enhancements
The backoffice interface has been significantly refactored to improve maintainability and user experience. The navigation sidebar now supports user-customizable shortcuts that can be reordered via drag-and-drop and are persisted in local storage. A new search bar allows users to quickly find and navigate to routes and APIs. The UI now features a dynamic title system that supports draft version banners and pinning, and a new 'Advanced/Simple view' toggle for entity forms (such as API keys and JWT verifiers) that saves the user's preference. Additionally, the dashboard now displays live cluster metrics and real-time performance statistics using sparkline charts, and JWT verifier forms include a usage graph to show which routes and services depend on a specific verifier.
otoroshi/javascript/src/components · high confidence
Backoffice UI restructured with new layout templates and light mode support
The backoffice interface has been refactored to use new Twirl layout templates (main.scala.html, unauthmain.scala.html) that support a configurable UI mode (light/dark) via the uiMode parameter, enabling users to switch between dark and bright themes. The login and dashboard views (index.scala.html, u2flogin.scala.html, dashboard.scala.html) have been updated to integrate with this new structure, including the addition of a 'dark-light-mode.js' script for theme toggling. Additionally, the documentation frame (documentationframe.scala.html) now uses a standalone Swagger UI layout without service descriptor injection, and the unauthorized page has been simplified.
otoroshi/app/otoroshi/views/backoffice · high confidence
Cassandra storage driver now uses Apache Pekko and implements a unified Redis-like abstraction
The Cassandra storage driver has been rewritten to replace the legacy Redis implementation with a new \NewCassandraRedis\ class that exposes a \RedisLike\ interface, allowing Otoroshi to use Cassandra as a drop-in replacement for Redis-based key-value and counter storage. This change migrates the underlying actor system from Akka to Apache Pekko and introduces a unified data store layer (\CassandraDataStores\) that manages all entities (routes, backends, APIs, users, etc.) via Cassandra tables, including automatic keyspace and table creation, TTL-based expiration cleanup, and metrics collection.
otoroshi/app/storage/drivers/cassandra · high confidence
Configurable boot sequence with readiness checks
The application now waits for specific subsystems to become ready before accepting requests, controlled by new configuration keys under \app.boot\ (e.g., \waitForTlsInit\, \waitForPluginsSearch\, \waitForFirstClusterFetch\). This ensures that TLS, plugins, scripts, and cluster state are initialized before the server starts listening, with configurable timeouts and the ability to fail the boot process if readiness is not achieved.
otoroshi/app · high confidence
Improved ID generation and JWT claim handling in security module
The security module introduces a new lock-free ID generator that uses CAS operations and thread-local secure random instances to improve performance and reduce contention during ID generation. It also adds a new OtoroshiClaim class for constructing and serializing JWTs with support for custom metadata and key IDs (kid), and includes an Auth0Config case class for managing Auth0 integration settings.
otoroshi/app/security · high confidence
Introduction of dark and light theme support with modular SCSS architecture
The styling system has been restructured to support both dark (default) and light themes, allowing users to switch visual modes via the data-theme attribute. This change introduces a new modular SCSS structure in the style directory, featuring a dedicated variables file that defines distinct color palettes for background levels, text, inputs, and borders for each theme. It also externalizes utility classes like .hide and reorganizes component styles into a centralized main.scss entry point, ensuring consistent theming across the dashboard's UI components.
otoroshi/javascript/src/style · high confidence
Introduction of merged configuration and new environment infrastructure
The application now uses a merged configuration strategy by default, combining 'app' and 'otoroshi' configuration sections into a single unified configuration object. This change introduces a new \Env.scala\ file that serves as the central environment context, initializing the ActorSystem, materializer, and scheduler based on this merged configuration. It also integrates Vault support for filling secrets asynchronously during startup and establishes the foundational structure for the application's runtime environment, including metrics, health checks, and cluster management components.
otoroshi/app/env · high confidence
Migrate controllers to Apache Pekko and restructure authentication flows
The controllers in the backoffice, health, private apps, and authentication modules have been rewritten to use Apache Pekko (replacing Akka) and updated Play framework patterns. This change introduces new controller classes (AuthController, BackOfficeController, HealthController, PrivateAppsController, SwaggerController, U2FController) that handle core platform functions including admin login, health checks, private app self-registration, and API documentation serving. The authentication logic has been restructured to support multi-auth module configurations and WebAuthn/U2F flows, with specific endpoints for session management, profile updates, and simple admin login.
otoroshi/app/controllers · high confidence
Migrate frontend build from Webpack to Vite and add Playwright E2E tests
The JavaScript frontend build system has been migrated from Webpack to Vite, enabling faster development with React Fast Refresh and removing the dependency on jQuery. The Node.js runtime version has been updated to 24.6.0. Additionally, end-to-end testing infrastructure has been introduced using Playwright, including configuration for Chromium-based tests and caching support for CI environments.
otoroshi/javascript · high confidence
Migrated legacy plugins to the new plugin system
The plugins in the \otoroshi/app/plugins\ directory (including Access Log, API Keys, Auth Callers, Biscuit, Body Logger, Cache, Client Certificate, and Composite plugins) have been migrated to the new plugin architecture. This update aligns these components with the new \NgPluginCategory\, \NgPluginVisibility\, and \NgStep\ APIs, ensuring they function correctly within the updated proxy engine while preserving their existing configuration and behavior for users.
otoroshi/app/plugins · high confidence
New component styles for the redesigned UI
The frontend now uses a new set of SCSS files in the style components directory to support the updated visual design. This includes dedicated styles for the workflow and route designer, a new homepage layout with entity tiles, and updated themes for standard UI elements like buttons, tables, forms, and modals. The changes also introduce specific styling for the date picker, JSON comparison view, and service health indicators, ensuring a consistent look and feel across the application.
otoroshi/javascript/src/style/components · high confidence
New gateway architecture with circuit breakers, chaos testing, and WebSocket support
The gateway layer has been restructured into a new set of core components: circuit breakers with retry logic, a chaos testing subsystem (SnowMonkey) for injecting latency and faults, and full WebSocket proxying. Error handling and analytics have been centralized in dedicated modules to improve observability and resilience. This change introduces new behavioral patterns for request routing, failure recovery, and real-time communication through the gateway.
otoroshi/app/gateway · high confidence
New next-generation plugin configuration forms
The admin UI now uses a new 'ng\_plugins' form system for configuring gateway plugins. This change introduces structured configuration schemas and UI flows for a wide range of plugins, including authentication (Apikey, Basic, HMAC, OAuth2), traffic management (CORS, Conditional, Canary, Throttling), and data transformation (JQ, GraphQL, HTML Patcher). Users will see updated, guided wizards for these settings, replacing the previous configuration methods.
_otoroshi/javascript/src/forms/ng\plugins · high confidence
New nginputs form rendering system
The \otoroshi/javascript/src/components/nginputs\ directory has been replaced with a new form rendering engine. This change introduces a schema-driven approach for generating UI inputs, featuring a central \NgForm\ component that orchestrates steps, flows, and validation. It includes a suite of new renderers (e.g., \NgJsonRenderer\, \NgLocationRenderer\, \NgDotsRenderer\) and utilities like \LocalChangesRenderer\ for collapsible sections and \MarkdownInput\ with toolbar support. The system also provides a \NgFormPlayground\ for development testing and standardizes how form data is validated and displayed across the application.
otoroshi/javascript/src/components/nginputs · high confidence
New tunnel demo with multi-leader load balancing and manual DNS resolution
The tunnel demo now includes a Docker Compose setup with two exposition leaders and a remote leader to demonstrate load balancing across multiple tunnel endpoints, along with a helper script to verify traffic routing to exposed services. This update also adds support for manual DNS resolution in the WebSocket client, allowing the demo to function correctly in environments where automatic DNS resolution is not available.
demos/tunnel · medium confidence
Redesigned API Editor with Draft/Production Lifecycle and Guided Setup
The API Editor has been completely refactored to support a dual-version workflow (Draft and Production) with a new Getting Started stepper to guide users through configuration. Key changes include: a new API Gateway tab for setting domain and context path; a dedicated Backends management view; a new Clients management view for configuring API keys; a new Deployments view to track production releases; and a new ApiQualityCard that displays a health score and top issues. The editor now enforces a strict lifecycle where production views are read-only and edits must be made in the draft version, with a banner and 'Edit in Draft' button to switch contexts. Additionally, the dashboard now includes live ApiStats (requests, rate, duration, overhead) and a new Actions panel for publishing, duplicating, and exporting APIs.
otoroshi/javascript/src/pages/ApiEditor · high confidence
Redesigned Otoroshi UI with new views and dark/light mode support
The Otoroshi web interface has been updated with a new set of Scala HTML templates (login, error, maintenance, self-update, token, build, SAML, and OpenAPI frames) that replace the previous implementation. This change introduces a modernized look and feel, including support for dark and light themes via a dedicated JavaScript module, and updates the login and self-update flows to use a new generic JavaScript bundle for authentication interactions. The OpenAPI frame now uses a standalone Swagger UI configuration, and the SAML binding view has been simplified to handle HTTP-POST submissions directly.
otoroshi/app/otoroshi/views/oto · high confidence
Redesigned sidebar and layout with glassmorphism and responsive controls
The application's layout and navigation have been significantly updated to improve usability and visual style. The sidebar now features a 'liquid glass' aesthetic with backdrop blur, supports a collapsible mode (toggling between 52px and 250px width), and includes a new mode-toggle control at the bottom for switching between expanded and collapsed states. The header and page content areas have been restructured to support responsive design, with specific padding adjustments for mobile views and a centered content container limited to 1000px width. Additionally, new styles for the 'Green Score' heatmap and global page containers ensure consistent theming and scrolling behavior across the interface.
otoroshi/javascript/src/style/layout · high confidence
Redesigned workflow node and edge UI with enhanced interaction states
The workflow designer's visual interface has been updated to improve clarity and interactivity. Nodes now feature dynamic styling that reflects execution states, such as highlighting during processing, success indicators upon completion, and error states for failures. Edges connecting nodes now support hover effects and display a delete button for easier connection management. Additionally, nodes support breakpoints (indicated by a red dot) and allow users to add or remove output handles directly from the UI, providing more granular control over workflow structure.
otoroshi/javascript/src/extensions/workflows/flow · high confidence
Redis storage driver deprecated in favor of Lettuce
The Rediscala-based Redis storage drivers (including RedisCPStore, RedisMCPStore, RedisClusterStore, RedisLFStore, and their corresponding DataStore implementations) are now deprecated and marked for removal. Users are advised to migrate to the Lettuce-based Redis driver to ensure continued support and compatibility with modern Akka/Pekko actor systems. The deprecated classes remain present in the codebase but carry a deprecation annotation since version 1.5.0.
otoroshi/app/storage/drivers/rediscala · high confidence
Redis-backed storage implementation for Otoroshi data stores
The storage layer in \otoroshi/app/storage/stores\ has been replaced with a new set of Redis-backed data stores (e.g., \KvAlertDataStore\, \KvApiKeyDataStore\, \KvCertificateDataStore\). This change introduces persistent, cluster-aware storage for core entities including API keys, certificates, global configuration, and audit logs. Key behavioral updates include the migration of analytics and alerts to data exporters, the addition of file appenders for logs, and the implementation of cluster-wide synchronization for certificate renewal and creation to prevent redundant operations on worker nodes. The new stores also handle throttling quotas, canary traffic distribution, and chaos engineering states via Redis keys, ensuring consistent state across the cluster.
otoroshi/app/storage/stores · high confidence
Refactored API and BackOffice action filters to centralize user rights and tenant context
The action filters in the API and BackOffice modules have been restructured to provide a unified context for user identity, tenant scope, and access rights. The new \ApiActionContext\ and \BackOfficeActionContext\ traits/classes now explicitly manage the extraction of the current user (from JWT tokens or API key metadata), determine the active tenant, and expose helper methods like \canUserRead\ and \canUserWrite\ to enforce granular permissions based on user rights and entity locations. This change ensures that authorization checks are consistently applied across API and BackOffice endpoints, simplifying the implementation of route-specific security rules by offloading user validation and rights verification into the action layer itself.
otoroshi/app/actions · high confidence
Refactored metrics subsystem with OpenTelemetry support and performance optimizations
The metrics module has been restructured to improve performance and extend observability. Timer instances are now cached per name to avoid redundant lookups and conflicting metric names during updates. The system now supports OpenTelemetry metrics via a new \opentelemetry.scala\ component, allowing metrics to be exported via OTLP (gRPC or HTTP) with configurable TLS, compression, and batching settings. Additionally, the codebase has been migrated to use Apache Pekko instead of Akka, and Scala 3 syntax conventions (such as \given\/\using\ and explicit imports) have been adopted throughout the metrics package.
otoroshi/app/metrics · high confidence
Updated Bootstrap CSS to version 5.3.3
The public stylesheet for the Otoroshi application has been replaced with the minified CSS for Bootstrap 5.3.3. This update brings the latest styling, component behavior, and CSS variable definitions from the Bootstrap framework to the application's user interface, ensuring that all visual elements render according to the new version's standards.
otoroshi/public/stylesheets · high confidence
Fixes
5 commits (3 fixes) fixing otoroshi/conf/wasm
A fix in otoroshi/conf/wasm — 5 commits (3 fixs), 1 file.
otoroshi/conf/wasm · medium confidence · unverified
Test coverage
8 commits adding/updating tests in otoroshi/test/resources/wasm; Added JavaScript test suite with setup documentation and utilities; Added Kubernetes integration test resources and configuration; Added Playwright authentication setup for end-to-end tests; Added Playwright end-to-end tests for user search functionality; Added Playwright smoke tests for login page rendering; Added Playwright tests for entity location defaults; Added TLS test certificates for oto.bar and Redis; Added gRPC server test resources with reflection support; Added plugin integration tests for cookies, headers, HTTP methods, and API key management; Added scripts to test Kubernetes Gateway API support; Added test utilities for configuration cleanup, OpenAPI generation, and plugin documentation; Consolidated test suite configuration for Otoroshi; Expanded Playwright end-to-end test coverage for admin dashboard; Expanded functional test coverage for core platform capabilities.
Dependencies
New demo, tooling, and documentation dependency manifests
Added package manifests for the \demos/challenge\ (Express 5.2.1, jsonwebtoken 9.0.3), \demos/mtls\ (x509 0.3.4), and \scripts/tools/fakekubeapiserver\ (Express 5.2.1) directories, alongside updated dependency definitions for the \otoroshi-ui\ frontend (React 17.0.2, Vite 7.3.6, Ant Design 4.21.4) and the \otoroshi-documentation\ site (Docusaurus 3.10.2, React 19.2.8). Also included WASM plugin templates (extism-pdk 0.1.1, jsonparser 1.1.1) and updated the release script dependencies (node-fetch 2.6.7, minimist 1.2.6).
(dependencies) · high confidence
Updated bundled Swagger UI to version 5.33.1
The bundled Swagger UI library has been upgraded to version 5.33.1. This update replaces the previous JavaScript bundle and initializer scripts in the public directory, bringing in the latest features, bug fixes, and performance improvements from the upstream Swagger UI project for the API documentation interface.
otoroshi/public/swagger-ui · high confidence
Upgrade to Bootstrap 5.3.3
The frontend JavaScript library has been upgraded to Bootstrap v5.3.3. This update replaces the previous version with the latest stable release, bringing new features, bug fixes, and improvements to components such as dropdowns, modals, offcanvas, and popper-based positioning. Users will benefit from enhanced stability and compatibility with modern browser standards in the Otoroshi dashboard interface.
otoroshi/public/javascripts · high confidence
Housekeeping
Added .gitignore and .keepit files to the plugin development directory; Added WASM demo folder documentation.
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 37 → 36 (-0.6)
- Rubric changed (rubric-2026.09.15 → rubric-2026.10.1) — scores are not directly comparable.
Lenses
- Code Health 50 → 37 (-13.0)
- Architecture 54 → 64 (+10.1)
- Maturity 72 → 72 (+0.9)
- Readiness 34 → 30 (-4.2)
- Security 66 → 68 (+1.9)
- Accessibility 27 → 30 (+3.4)
- Performance 61 (new)
Resolved (141)
- Change coupling: GlobalScore.js ↔ RulesRadarchart.js (otoroshi/javascript/src/extensions/greenscore/GlobalScore.js)
- Change coupling: GroupRoutes.js ↔ page.js (otoroshi/javascript/src/extensions/greenscore/GroupRoutes.js)
- Documentation: no installation or build instructions (otoroshi/readme.md)
- High CVE: [GHSA redacted] (tools/sidecar/package-lock.json)
- High CVE: [GHSA redacted] (manual/next/package-lock.json)
- Leaked secret: password-hash-credential (docs/devmanual/assets/js/ed54b959.2bd416c2.js)
- Low IaC: KSV-0011 (kubernetes/kustomize/components/cluster-deployments/deployment.yaml)
- Low IaC: KSV-0011 (kubernetes/kustomize/components/cluster-deployments/deployment.yaml)
- Low IaC: KSV-0011 (kubernetes/kustomize/components/single-deployment/deployment.yaml)
- Low IaC: KSV-0011 (kubernetes/kustomize/overlays/cluster-baremetal-daemonset/deployment.yaml)
- Low IaC: KSV-0011 (kubernetes/kustomize/overlays/cluster-baremetal-daemonset/deployment.yaml)
- Low IaC: KSV-0011 (kubernetes/kustomize/overlays/simple-baremetal-daemonset/deployment.yaml)
- Low IaC: KSV-0015 (kubernetes/kustomize/components/cluster-deployments/deployment.yaml)
- Low IaC: KSV-0015 (kubernetes/kustomize/components/cluster-deployments/deployment.yaml)
- Low IaC: KSV-0015 (kubernetes/kustomize/components/single-deployment/deployment.yaml)
- Low IaC: KSV-0015 (kubernetes/kustomize/overlays/cluster-baremetal-daemonset/deployment.yaml)
- Low IaC: KSV-0015 (kubernetes/kustomize/overlays/cluster-baremetal-daemonset/deployment.yaml)
- Low IaC: KSV-0015 (kubernetes/kustomize/overlays/simple-baremetal-daemonset/deployment.yaml)
- Low IaC: KSV-0016 (kubernetes/kustomize/components/cluster-deployments/deployment.yaml)
- Low IaC: KSV-0016 (kubernetes/kustomize/components/cluster-deployments/deployment.yaml)
- …and 121 more
New (2167)
- (anonymous) (cognitive 18) (otoroshi/javascript/src/pages/ApiEditor/Actions.js)
- (anonymous) (cognitive 18) (otoroshi/javascript/src/pages/RouteDesigner/Informations.js)
- (anonymous) (cognitive 24) (otoroshi/javascript/src/components/DefaultSidebar.js)
- (anonymous) (cognitive 61) (otoroshi/javascript/src/components/inputs/Table.js)
- (anonymous) (cyclomatic 16) (otoroshi/javascript/src/pages/RouteDesigner/Informations.js)
- (anonymous) (cyclomatic 19) (otoroshi/javascript/src/components/DefaultSidebar.js)
- (anonymous) (cyclomatic 19) (otoroshi/javascript/src/components/inputs/Table.js)
- (anonymous) (cyclomatic 22) (otoroshi/javascript/src/pages/ApiEditor/Actions.js)
- AbstractRedisDataStores.fullNdJsonExport (cognitive 24) (otoroshi/app/storage/drivers/rediscala/rediscala.scala)
- AbstractRedisDataStores.rawExport (cognitive 24) (otoroshi/app/storage/drivers/rediscala/rediscala.scala)
- AccessLog.transformErrorWithCtx (cognitive 16) (otoroshi/app/plugins/accesslog.scala)
- AccessLog.transformResponseWithCtx (cognitive 16) (otoroshi/app/plugins/accesslog.scala)
- AccessLogJson.transformErrorWithCtx (cognitive 16) (otoroshi/app/plugins/accesslog.scala)
- AccessLogJson.transformResponseWithCtx (cognitive 16) (otoroshi/app/plugins/accesslog.scala)
- Actions.Actions (cognitive 40) (otoroshi/javascript/src/pages/ApiEditor/Actions.js)
- Actions.Actions (cyclomatic 41) (otoroshi/javascript/src/pages/ApiEditor/Actions.js)
- AdminApiHelper.fetchWithPaginationAndFiltering (cognitive 16) (otoroshi/app/utils/controllers.scala)
- AdminApiHelper.fetchWithPaginationAndFiltering (cyclomatic 16) (otoroshi/app/utils/controllers.scala)
- AdminExtensions.handleBackofficeCall (cognitive 29) (otoroshi/app/next/extensions/extension.scala)
- AdminExtensions.handleBackofficeCall (cyclomatic 25) (otoroshi/app/next/extensions/extension.scala)
- …and 2147 more
Changes since last survey
- 147 commits — 121 feature/other, 26 fixes
By area
- otoroshi/app — 43 commits
- otoroshi/test — 30 commits
- (repo) — 19 commits
- docs/devmanual — 15 commits
- manual/next — 12 commits
- otoroshi/javascript — 5 commits
- docs/manual — 4 commits
- kubernetes/kustomize — 4 commits
- kubernetes/helm — 3 commits
- (root) — 2 commits
- docs/helm — 2 commits
- tools/sidecar — 2 commits
- .github/workflows — 1 commit
- demos/challenge — 1 commit
- docker/build — 1 commit
- otoroshi/conf — 1 commit
- otoroshi/public — 1 commit
- scripts/release — 1 commit
Notable commits
- fix: Change lib for brotli support, working on apple silicon - fix #2677
- fix: avoid issue with keep-alive connection that sends 0 bytes on macos. mostly a pekko bug
- fix: disable pekko request timeout by default. validate request sizes without encoding them. check monitoring path before ip regex. lock free request counters and fix h2 counting
- fix: fix #2660
- fix: fix #2662
- fix: fix #2665
- fix: fix #2666
- fix: fix #2667
- fix: fix #2669 and address #2668 - Co-Author @davlgd
- fix: fix #2670
- fix: fix #2673
- fix: fix #2673
- fix: fix #2674
- fix: fix #2675
- fix: fix #2676
- fix: fix #2679
- fix: fix #2680
- fix: fix #2680
- fix: fix #2682
- fix: fix #2685
- …and 127 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
MAIF/otoroshi was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 5 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit e3d071eb2a58d2591de9ae836ed7e376d3591333 — the exact code this score is about.
- Scored under rubric-2026.10.1 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-3f806db95659.