metalbear-co/mirrord
61.6
Adequate · 30 September 2026
186.2k
lines of production code
Rust
with TypeScript
2
measurements over time
What this system is
Mirrord is a development tooling suite that intercepts and manipulates network and file system traffic for applications running in local or containerized environments. It enables developers to run local code against live remote services by injecting a layer that redirects syscalls, supporting features such as traffic stealing, mirroring, and chaos testing. The system comprises a CLI for session management, a Kubernetes operator for orchestration, a unified UI for monitoring, and a background agent to handle traffic operations.
How it got here
2022–2023 — monorepo restructuring and protocol modernization
48 changes.
The project underwent a comprehensive architectural overhaul, reorganizing the Rust monorepo into modular crates and introducing a versioned binary protocol for component communication. This period focused on stabilizing the core infrastructure by refactoring the CLI, agent, and internal proxy into distinct, maintainable modules while expanding support for advanced features like database branching, HTTP filtering, and Unix socket mirroring.
2024–2025 — multi-target expansion and Windows support
33 changes.
This period focused on significantly expanding mirrord's compatibility by adding support for diverse Kubernetes resource types, numerous message brokers, and a wide array of database engines for branching. Concurrently, the project introduced comprehensive Windows support, including a native installer, unified layer libraries, and robust process injection mechanisms. These efforts were complemented by architectural improvements to the agent, CLI, and internal proxy to enhance stability, security, and CI/CD integration.
2026 — Terminal UI and multi-service orchestration
47 changes.
This period focused on introducing a comprehensive Terminal UI (TUI) and a unified web interface for managing sessions, targets, and preview environments. It also expanded core capabilities with the \mirrord up\ command for multi-service local development, database branching support, and robust chaos testing features. Underlying infrastructure improvements included a new protocol client, Windows crash diagnostics, and extensive integration test coverage for the layer and proxy components.
Features
Add CRI-O container runtime support with OpenShift compatibility
The agent now supports the CRI-O container runtime, enabling mirroring on OpenShift clusters. A new \crio.rs\ module implements the \ContainerRuntime\ interface to communicate with the CRI-O socket, specifically handling a fallback logic to parse container PIDs from the \info\ JSON field when the standard \pid\ key is missing, which addresses observed behavior differences on OpenShift. This is accompanied by a new \error.rs\ module defining specific error types for CRI-O, Docker, and containerd runtime interactions.
mirrord/agent/src/runtime · high confidence
Add Events tab and context-aware API v2 endpoints to the UI server
The UI server now exposes new API v2 endpoints to support an Events tab and context-aware target selection. The \/api/v2/operator/events\ endpoint streams interception events from the operator via Server-Sent Events (SSE), allowing users to monitor live session activity across contexts. Additionally, the \/api/v2/kube/targets\ and \/api/v2/kube/target-types\ endpoints enable the UI to enumerate Kubernetes targets (such as Pods, Deployments, and Jobs) within a specific context and namespace, facilitating the configuration wizard's target picker with real-time cluster data.
mirrord/cli/src/ui/server/v2 · high confidence
Add configuration support for branching ClickHouse, CockroachDB, DynamoDB, Google Spanner, MariaDB, MongoDB, MSSQL, S3, and turbopuffer
The database branching feature now supports branching for ClickHouse, CockroachDB, DynamoDB, Google Spanner, MariaDB, MongoDB, MSSQL, S3, and turbopuffer. Users can configure these branches by setting the \type\ field in their \db\_branches\ configuration to the respective database or service name. Each type includes specific configuration options for connection, copying data (schema and/or data), and authentication, allowing users to create isolated branches for development and testing.
_mirrord/config/src/feature/database\branches · high confidence
Add dedicated connection logic for port-forwarding and TLS-secured external proxy
The internal proxy now includes specific modules for establishing agent connections: \portforward.rs\ handles Kubernetes-based port-forwarding connections, while \tls.rs\ provides a function to wrap raw TCP streams with TLS for external proxy communication. This separates the connection creation logic for these two distinct transport mechanisms.
_mirrord/intproxy/src/agent\conn · high confidence
Added Node.js sample application and Kubernetes deployment manifests
A new Node.js sample application (sample/node/app.mjs) has been added to demonstrate file operations and network server functionality, accompanied by a Kubernetes deployment manifest (sample/kubernetes/app.yaml) that configures the 'py-serv' deployment and NodePort service for running the sample in a cluster environment.
sample · high confidence
Added Rust sample application demonstrating file and network operations
A new Rust sample application has been added to the \sample/rust\ directory. This sample demonstrates basic file I/O operations (reading, writing, seeking) using both standard Rust libraries and unsafe \libc\ calls, as well as establishing a TCP listener to handle incoming network connections. It serves as a reference implementation for interacting with local file systems and network sockets in Rust.
sample/rust · high confidence
Added Windows-specific string utilities and error handling
Introduced the \str-win\ crate to provide safe, efficient utilities for converting between Rust strings and Windows-style null-terminated buffers (UTF-8 and UTF-16), including proper handling of surrogate pairs and multi-string formats. Added a dedicated error module in \layer-lib\ to re-export Windows-specific error types and define console-related errors, supporting the new Windows layer capabilities.
mirrord/layer-lib/src/error, mirrord/str-win · high confidence
Agent iptables logic extracted to a dedicated crate with multi-container support
The iptables management code has been moved into a new \mirrord/agent/iptables\ crate, introducing a modular redirector architecture (Standard, Mesh, Ambient, and FlushConnections) that improves reliability and cleanup. A key behavioral change is the introduction of dynamic iptables chain names (e.g., \MRDIN\_{id}\) via the \MIRRORD\_AGENT\_IPTABLES\_IDENTIFIER\ environment variable, which allows multiple mirrord agents to coexist within the same pod network namespace without rule collisions. The agent now also automatically detects the service mesh vendor (Istio, Linkerd, Kuma) and handles Istio Ambient mode's \route\_localnet\ coordination, while connection flushing now uses \ss -K\ and selectively applies \conntrack -D\ only when necessary.
mirrord/agent/iptables · high confidence
Agent outgoing traffic now supports Unix stream and seqpacket sockets
The agent's outgoing connection router has been expanded to handle Unix domain sockets in addition to TCP and UDP. New modules (\tcp\_unix.rs\ and \seqpacket.rs\) implement the \ConnectionKind\ trait for \TcpOrUnixConnection\ (covering both TCP and Unix stream sockets) and \SeqpacketConnection\ (covering Unix seqpacket sockets). This allows applications to mirror outgoing traffic to Unix sockets, including pathname-based, abstract, and unnamed addresses, with connection attempts executed in the target's network namespace and subject to the same throttling and timeout policies as existing IP-based connections.
mirrord/agent/src/outgoing · high confidence
Agent utility modules for path resolution, protocol versioning, and I/O handling
The agent now includes dedicated utility modules in \mirrord/agent/src/util\ to support core mirroring operations. \InTargetPathResolver\ handles resolving and normalizing file paths from the target container's perspective, correctly managing symlinks and root prefixes. \ClientProtocolVersion\ provides a shared, thread-safe wrapper for tracking the client's protocol version, defaulting to 1.2.2 for backward compatibility. \RolledBackStream\ enables prepending data buffers to existing I/O streams, which is essential for handling TLS traffic where initial handshake data must be processed before the stream is handed off. Additional utilities include error types for runtime creation and modular I/O helpers for buffering, throttling, and timeouts.
mirrord/agent/src/util · high confidence
Automatic port forwarding for database branches
The internal proxy now automatically establishes and manages port forwards for database branches configured in mirrord.json. This change introduces logic to resolve connection parameters (such as host, port, user, and password) from the target environment, handle connection URL patterns, and apply query parameter overrides (e.g., for SSL modes or IAM authentication) to ensure local connections correctly route to the remote database branch.
_mirrord/cli/src/internal\proxy · high confidence
Background mirrord UI daemon with context-aware API v2 and chaos management
The mirrord UI now runs as a persistent background daemon process, handling local session discovery, authentication, and shared database port forwards. It exposes a new versioned API (v2) that is context and namespace-aware, allowing the browser interface to query multiple clusters simultaneously without shared server state. The UI also introduces endpoints for managing ChaosRules (CRUD operations for latency and other traffic effects) and integrates with the operator to display preview environment phases, failure reasons, and pod output.
mirrord/cli/src/ui · high confidence
Chaos latency delays outgoing connection traffic
The outgoing interceptor now supports chaos latency simulation by introducing a \DelayQueue\ that holds read and write messages until a configured deadline. When a chaos rule matches an outgoing connection, the interceptor routes traffic through background tasks (\InterceptorReadQueue\ and \AgentWriteQueue\) that enforce this delay, ensuring messages are released in insertion order to preserve byte stream integrity. This change also integrates backpressure handling for client-to-agent writes, releasing write-budget permits only when messages are actually sent to the agent.
mirrord/intproxy/src/proxies/outgoing/interceptor · high confidence
Expanded Kubernetes target support for CronJob, Job, ReplicaSet, StatefulSet, Service, and Rollout
The mirrord runtime API now supports targeting additional Kubernetes resource types beyond Deployments and Pods. New implementation files in \mirrord/kube/src/api/runtime\ add support for CronJob, Job, ReplicaSet, StatefulSet, Service, and ArgoCD Rollout targets. This allows users to mirror traffic to workloads managed by these controllers, with specific handling for label-based selection (e.g., Service, LabelTarget) and selector extraction (e.g., CronJob, StatefulSet, Rollout).
mirrord/kube/src/api/runtime · high confidence
Expanded queue splitting and database branching support in operator client
The operator client now supports a significantly broader range of queue splitting targets, including Kafka, RabbitMQ, Google Pub/Sub, Azure Service Bus, Redis Pub/Sub, Temporal, BullMQ, and NATS, with configurable jq filters and protobuf payload decoding for Kafka. Additionally, database branching capabilities have been extended to include MySQL, PostgreSQL, MongoDB, ClickHouse, CockroachDB, MariaDB, DynamoDB, Google Spanner, S3, and Turbopuffer, with specific client logic for creating, monitoring, and reusing branch databases for each supported type.
mirrord/operator/src/client · high confidence
Initial Vale configuration and CI integration
Added the initial Vale configuration for the project, including a custom MetalBear vocabulary to recognize domain-specific terms (e.g., mirrord, Kubernetes, Rust ecosystem terms), a Tree-sitter view to correctly lint Rust doc comments as Markdown, and a custom HTML report template for CI output.
.vale/styles/config · high confidence
Introduce Chaos API for managing latency rules
The mirrord UI now exposes an internal API to manage chaos (latency) rules for active sessions. This change adds handlers for creating, listing, updating, and deleting chaos rules, as well as clearing all rules for a session, by forwarding requests to the intproxy session monitor. It also introduces error handling for cases where a session is not found or upstream communication fails.
mirrord/cli/src/ui/chaos · high confidence
Introduce Chaos Testing via Fault Injection Rules
The intproxy session monitor now supports a Chaos feature that allows users to define rules for injecting faults into network traffic during a mirrord session. This location implements the core rule management logic, including the \ChaosRule\ data structure and the API handlers for creating, reading, updating, and deleting these rules. Users can configure selectors (currently TCP) and effects (such as latency) to simulate network conditions, with the system tracking rule usage and lifetime for analytics reporting.
_mirrord/intproxy/src/session\monitor/chaos · high confidence
Introduce Chaos testing feature and Unix socket support for outgoing connections
The outgoing proxy now supports the new Chaos testing feature, allowing users to inject connection errors, latency, resets, and stalls into intercepted traffic via configurable rules. Additionally, Unix socket support has been added for outgoing connections in container mode, ensuring proper permissions for cross-UID access, and the proxy now handles SOCK\_SEQPACKET protocol types.
mirrord/intproxy/src/proxies/outgoing · high confidence
Introduce VPN mode for mirrord
Added a new VPN feature that allows mirrord to intercept traffic by creating a virtual network interface (TUN device) and routing it through the mirrord agent. This includes platform-specific logic for Linux (mounting routes and overriding /etc/resolv.conf) and macOS (using /etc/resolver and route commands), along with the necessary agent communication protocol to handle network configuration, packet forwarding, and checksum patching.
mirrord/vpn · high confidence
Introduce \`mirrord up\` for multi-service local development
Users can now run multiple local services against Kubernetes targets simultaneously using a single \mirrord-up.yaml\ configuration file. The new \mirrord up\ command supports three traffic modes per service—Split, Replace, and Mirror—allowing fine-grained control over how incoming requests are handled. It includes an interactive \mirrord up init\ wizard to scaffold configurations, supports Tera templating for dynamic values, and manages complex process lifecycles with platform-specific signal handling and graceful shutdown for both Unix and Windows environments.
mirrord/up · high confidence
Introduce database-specific Custom Resource Definitions for branching
The operator now defines dedicated Kubernetes Custom Resource Definitions (CRDs) for each supported database engine—PostgreSQL, MySQL, MongoDB, and others—under the group \dbs.mirrord.metalbear.co\ (version \v1alpha1\). These resources (e.g., \PgBranchDatabase\, \MysqlBranchDatabase\, \MongodbBranchDatabase\) allow users to configure database-specific branching options, including connection sources, data copy modes (empty, schema, or all with filters), and engine-specific settings like IAM authentication for PostgreSQL. This replaces the previous generic \BranchDatabase\ CRD with specialized types that expose engine-specific capabilities directly in the Kubernetes API.
_mirrord/operator/src/crd/db\branching · high confidence
Introduce medschool CLI tool for extracting Rust documentation
A new \medschool\ command-line tool is added to extract documentation from Rust source code into a Markdown file. The tool parses Rust structs, enums, and modules using \syn\, resolves references to a specified root type, and outputs a structured \configuration.md\ file. It supports command-line arguments to define the root type, specify input/output paths, and prepend custom headers. Logging is controlled via the \MIRRORD\_LOG\ environment variable.
medschool/src · high confidence
Introduce mirrord configuration wizard
The mirrord configuration wizard is now available as a React application in \packages/wizard\. It provides a guided interface for creating \mirrord.json\ files, allowing users to select between Filtering, Mirror, and Replace modes, configure target namespaces and ports, and manage HTTP filters. The wizard connects to a backend API to fetch Kubernetes cluster details and includes a mock server for local development.
packages/wizard/src · high confidence
Introduce mirrord-jaq for SQS configuration and a new test macro
The mirrord/jaq crate now provides a dedicated library for evaluating jq filters, featuring compile-time validation via VerifiedJqString, asynchronous evaluation with configurable timeouts, and structured error reporting for load, compile, and evaluation failures. This library is utilized for SQS configuration, replacing the previous jaq-all dependency. Additionally, a new test macro in mirrord/test-macros allows async tests to run with optional timeouts and background runtime shutdown, preventing hangs from spawned blocking tasks.
mirrord/jaq · high confidence
Introduce mirrord/tls-util crate for TLS certificate and channel management
The new \mirrord/tls-util\ crate provides shared utilities for handling TLS operations, including parsing PEM certificate chains and private keys, generating temporary certificates, and establishing secure TLS channels. It introduces \SecureChannelSetup\ to create temporary, mutually-authenticated TLS connections using certificates stored in \\~/.mirrord/temp\, which ensures compatibility with container runtimes like Colima that cannot access the system temp directory. The crate also exposes helpers for building root certificate stores from files and directories, extracting Subject Alternate Names (SANs) from certificates, and a \MaybeTls\ wrapper to abstract over plain TCP and TLS connections.
mirrord/tls-util · high confidence
Introduce operator client library and CRD definitions
This change introduces the core Rust client library (\mirrord/operator/src/client.rs\) and Custom Resource Definition (CRD) schemas (\mirrord/operator/src/crd.rs\) for the mirrord operator. For users, this establishes the foundational API for managing operator sessions, including support for isolated operators, unified database branching, and queue splitting. The client now handles operator discovery, certificate preparation, and connection parameters (including sending connect params in headers to bypass ingress proxy limitations). The CRDs define the structure for Targets, Copy Targets, Database Branches, and Preview Sessions, enabling the CLI to interact with the operator for features like target resolution, session management, and license tracking.
mirrord/operator/src · high confidence
Introduce the Session Monitor UI for local and operator sessions
The \packages/monitor\ package now provides a dedicated React-based UI for monitoring Mirrord sessions. It supports both local and operator sessions, allowing users to select Kubernetes contexts and namespaces, view live traffic events with filtering and search, and manage chaos rules. The interface integrates with the \mirrord-ui\ shell via a top-bar slot, includes an operator installation wizard, and captures telemetry (with session recording and user-facing error reporting) via PostHog.
packages/monitor · high confidence
Introduce the mirrord Terminal UI (TUI)
Adds a new terminal-based interface for mirrord, providing a full-screen application with multiple screens for managing Kubernetes contexts, namespaces, targets, sessions, databases, queues, and preview environments. The UI features a status bar that displays connection state and scopes, and includes a dedicated error dialog for connection failures that captures and displays stderr output from authentication plugins (like gke-gcloud-auth-plugin) to help users resolve credential issues. It also implements anonymous usage telemetry reporting for actions such as session starts and tab visits, and ensures safe integration with long-lived processes by properly managing terminal state, panic hooks, and stderr redirection.
mirrord/tui/src · high confidence
Introduces \`cargo xtask\` build automation tool
Developers can now use the new \cargo xtask\ CLI to build, test, and run mirrord locally, replacing previous shell scripts. The tool provides commands like \build-cli\ to compile the full CLI (including the merged UI frontend and layer) for specific platforms (macOS universal, Linux, Windows) and \build-ui\ to compile the frontend assets. It also includes \test-e2e\, \test-integration\, and \test-ut\ for running test suites, and \run-cli\ for quick local development. The build process handles cross-compilation, macOS universal binary creation via \lipo\, and code signing (using \gon\ in CI or ad-hoc \codesign\ locally).
xtask · high confidence
Introduces the mirrord-protocol client library with retry and connection management
The \mirrord/protocol-api/src/client\ module now provides the core client library for the mirrord protocol. This includes a \MirrordClient\ backed by a background \ClientTask\ that manages the connection lifecycle, including automatic reconnection on loss and ping-pong keep-alive. The library introduces a \MirrordClientRetry\ extension trait that adds automatic retry logic for operations like DNS lookups, file access, and port subscriptions, handling transient connection errors and agent restarts transparently. Configuration for timeouts and buffer capacities is centralized in \ClientConfig\, and the client supports both V1 and V2 protocol versions for outgoing connections and DNS lookups.
mirrord/protocol-api/src/client · high confidence
Introduction of \`hook\_fn\` and \`hook\_guard\_fn\` procedural macros for C FFI hooks
The \mirrord/layer/macro\ crate now provides two new procedural macros, \hook\_fn\ and \hook\_guard\_fn\, to simplify the creation of C FFI hook functions. \hook\_fn\ automatically generates the necessary type aliases and static variables for storing original function pointers, while \hook\_guard\_fn\ extends this by wrapping the function body with a guard check that bypasses the hook when necessary. This reduces boilerplate for defining detours in the mirrord layer.
mirrord/layer/macro · high confidence
Introduction of container-based internal proxy sidecar
The CLI now supports running the internal proxy inside a dedicated container sidecar. This change introduces a builder for constructing container runtime commands (supporting Docker, Podman, and Nerdctl) and logic to manage a sidecar container that exposes the proxy to the user's application container via shared volumes and network configuration. It also includes utilities for displaying commands and handling errors specific to container execution, such as TLS PEM access and host proxy connection failures.
mirrord/cli/src/container · high confidence
Introduction of the \`mirrord-protocol\` crate with versioned wire format and new capabilities
The \mirrord-protocol\ crate has been introduced to centralize the definition of the wire format used for communication between mirrord components (CLI, agent, operator). The protocol is versioned independently and uses \bincode\ for serialization, ensuring backwards compatibility through strict rules on type changes and version negotiation. This release adds support for several new capabilities, including HTTP/2 framing for stealer traffic, advanced HTTP filtering with JSON path and jaq support, reverse DNS lookups for outgoing network policies, and V2 statfs requests with additional filesystem metadata. It also introduces support for SOCK\_SEQPACKET sockets, share links for session joining, and operator latency ping-pong metrics. The pause feature has been removed from the protocol.
mirrord/protocol · high confidence
Major restructuring of the configuration system with new modules and features
The configuration module has been significantly reorganized into dedicated files for agent, CI, container, external proxy, internal proxy, and feature-specific settings. This change introduces new configuration capabilities including a session key system for traffic filtering, environment variable remapping via regex patterns, and enhanced logging controls for proxies. The refactoring also adds support for container runtime detection, host gateway mechanisms, and improved error handling for config parsing and template rendering.
mirrord/config/src · high confidence
New CLI commands for managing operator sessions and viewing detailed status
The CLI now includes dedicated commands to manage operator sessions and view comprehensive operator status. Users can start, stop, and retain active sessions via the new session management interface, which interacts with the operator's SessionCrd to handle session lifecycle operations. Additionally, the operator status command has been enhanced to display detailed information for both Kafka and SQS sessions, including topic names, queue filters, and jq filters, providing better visibility into active mirroring configurations.
mirrord/cli/src/operator · high confidence
New CLI subcommands for CI, browser extension, and process attachment
The CLI now includes three new capabilities: a \mirrord ci\ subcommand with \start\, \stop\, and \container\ actions for CI environments (requiring the \MIRRORD\_CI\_API\_KEY\ environment variable); a browser extension integration that automatically opens Chrome on macOS/Linux to configure header filters for the extension; and a \mirrord attach\ command that injects the mirrord layer DLL into an already-running process by PID, relying on the IDE extension to have pre-configured the necessary environment variables.
mirrord/cli/src · high confidence
New CRD types for preview environments, copy targets, and queue splitting
The operator now defines Kubernetes Custom Resource Definitions for managing preview environments (\PreviewSession\), copy targets (\CopyTarget\), and queue splitting sessions (\MirrordKafkaEphemeralTopic\, \MirrordRMQSession\). These resources allow the operator to track the lifecycle of preview pods, manage ephemeral queue topics, and expose queue-splitting status, enabling users to create isolated preview environments with specific configurations for traffic, environment variables, and queue filtering.
mirrord/operator/src/crd · high confidence
New HTTP filtering and TLS delivery configuration options
The incoming network configuration now supports granular HTTP traffic filtering via \header\_filter\, \path\_filter\, \method\_filter\, \body\_filter\, and \header\_filter\_jq\, including composite \all\_of\ and \any\_of\ logic for complex matching rules. Additionally, the \tls\_delivery\ section allows users to control how stolen TLS traffic is delivered locally, supporting both plain TCP and TLS protocols with options for custom trust roots, server names, and mutual TLS client certificates.
mirrord/config/src/feature/network/incoming · high confidence
New Preview Environments screen in the TUI
The TUI now includes a dedicated screen for managing preview environments, featuring a live cluster watch that groups sessions by namespace and target. Users can browse, filter, and navigate this hierarchy using modal modes for filtering, go-to search, and help. The screen supports stopping single environments or entire targets/namespaces with confirmation dialogs, and displays session phases using brand-aligned colors that adapt to terminal truecolor support.
_mirrord/tui/src/screens/preview\envs · high confidence
New PreviewEnv CRD view for multi-cluster preview status
The operator now exposes a new \PreviewEnv\ CustomResource (plural: \previews\) under the \operator.metalbear.co/v1alpha1\ API group. This read-only view aggregates the state of preview environments across multiple clusters, allowing clients to see the lifecycle phase, failure messages, and per-cluster replica status (including \Unreachable\ or \Missing\ states) in a single endpoint. It also supports fetching recent pod logs via a subresource to aid in debugging preview failures.
mirrord/operator/src/crd/preview · high confidence
New Windows utility crate with clipboard, diagnostics, and error handling
A new \mirrord/utils-win\ crate has been added to provide shared Windows-specific utilities for the injected layer and CLI. It introduces a clipboard helper for copying text, a comprehensive diagnostics module for collecting crash and exception data (with crash reporting enabled by default but disableable for extension sessions), and a relocated \WindowsError\ type for consistent error formatting. The crate also includes safe, allocation-free helpers for fixed-buffer formatting, module enumeration, and process identity/status inspection to support robust crash reporting and system interaction on Windows.
mirrord/utils-win/src · high confidence
New \`mirrord ci\` subcommands for containerized and background execution
This change introduces the \mirrord ci container\, \mirrord ci start\, and \mirrord ci stop\ commands, enabling mirrord to be used in CI environments. The \mirrord ci container\ command spawns the user's binary within a container, allowing it to persist after the CLI exits. The \mirrord ci start\ command launches mirrord in the background (similar to \mirrord exec\ but detached), while \mirrord ci stop\ handles cleanup by terminating associated processes and containers. These commands rely on a new \CiStore\ for state management and specific error handling for CI-specific requirements like API keys and environment variables.
mirrord/cli/src/ci · high confidence
New \`protocol\_break\` macro to enforce versioned code revisions
The \mirrord-macros\ crate now includes a \protocol\_break\ procedural macro attribute. When applied to code items, this macro checks the current crate version against a specified major version number; if the current version meets or exceeds the target, it triggers a compilation error. This mechanism ensures that deprecated protocol variants or logic marked for removal are actively addressed during major version bumps, preventing technical debt from accumulating silently.
mirrord/macros · high confidence
New authentication module for CLI operator credentials
The \mirrord/auth\ crate introduces a dedicated authentication layer for the CLI, handling the storage and lifecycle of X.509 certificates and private keys used to communicate with the mirrord operator. It provides a \CredentialStore\ that persists credentials to \\~/.mirrord/credentials\, manages key pair generation and rotation, and supports license renewal by mapping signing keys to operator subscription IDs. The module also includes a \CiApiKey\ container for CI integration and ensures compatibility with legacy key formats via DER patching.
mirrord/auth · high confidence
New background IO buffering, throttling, and timeout utilities for the agent
The agent now includes new utility modules in \mirrord/agent/src/util/io\ to improve outgoing traffic handling. \buffered.rs\ adds \UnboundedBufferedStream\ and \UnboundedBufferedSink\ wrappers that offload IO operations to background Tokio tasks, allowing connections to be progressed concurrently. \throttle.rs\ introduces \Throttle\, \ThrottledStream\, and \ThrottledSink\ to rate-limit client data flow using semaphore-based permits. \timeout.rs\ provides a \TimeoutSink\ that applies configurable timeouts to sink operations, addressing the lack of flow control in mirrord-protocol. These components collectively enhance stability and performance for outgoing connections.
mirrord/agent/src/util/io · high confidence
New build, installation, and release automation scripts
The repository now includes a suite of new shell and PowerShell scripts to streamline development and distribution. The \install.sh\ script provides a POSIX-compliant installer that automatically detects the platform (Linux x86\_64/aarch64 or macOS universal) and installs the latest or a specified version of mirrord. Build automation is improved with \build\_fat\_mac.sh\ and \build\_layer\_mac.sh\ for creating signed universal binaries on macOS, and \build\_c\_apps.sh\/\build\_go\_apps.sh\ for compiling test applications. A new \release.sh\ script automates version bumping and changelog generation using \towncrier\. Additionally, \prepare\_e2e.sh\ and Windows-specific scripts (\win\_build\_test\_apps.ps1\, \setup\_ci\_env\_wsl.sh\) standardize the setup of test environments across CI and local WSL setups.
scripts · high confidence
New configuration schema for copy target, database branching, environment, file system, magic, network, preview, and queue splitting features
The configuration system in \mirrord/config/src/feature\ has been restructured into distinct modules for each feature area. This introduces a new \copy\_target\ configuration allowing users to create dynamic pods with options to scale down the original deployment and exclude specific containers. Database branching support is now centralized in \database\_branches.rs\, providing unified configuration for various engines (PostgreSQL, MySQL, CockroachDB, etc.) including copy modes, migrations, and IAM authentication. Environment variable handling (\env.rs\) now supports explicit unsetting, file-based loading, and value mapping. File system operations (\fs.rs\) are configured with modes and filters. The \magic\ module adds sensible defaults for AWS credentials, Kubernetes volume mounting, and Next.js/Turbopack compatibility. Network configuration (\network.rs\) now defaults IPv6 support to enabled. Preview environments (\preview.rs\) offer granular control over TTL, replicas, labels, idle mode, and config/secret mounts. Finally, queue splitting (\split\_queues.rs\) is configured with composable message filters and support for multiple queue types (SQS, Kafka, RabbitMQ, etc.).
mirrord/config/src/feature · high confidence
New file filtering, path remapping, and prefetching logic in layer-lib
The \mirrord/layer-lib/src/file\ module now implements the core logic for controlling how file operations are handled during mirroring. It introduces a \FileFilter\ that uses regex patterns to decide whether files should be opened locally, remotely (read-only or read-write), or treated as not found, based on user configuration and default system paths. Additionally, a \FileRemapper\ allows users to define regex-based path mappings to translate remote file paths to local equivalents, and a \PrefetchedFiles\ component manages local copies of files specified in the \feature.fs.prefetch\ configuration, enabling faster access by serving these pre-cached copies instead of hitting the remote filesystem.
mirrord/layer-lib/src/file · high confidence
New interactive targets wizard for configuring mirrord sessions
The terminal interface now includes a new targets wizard that lets you browse cluster resources, configure service plans, and launch mirrord sessions without writing YAML manually. The wizard provides a target browser with per-kind badges, a session plan pane for ordering and editing services, and a generic settings form with tab-completion for commands and paths. It automatically detects common run commands based on project markers (e.g., package.json, Cargo.toml, go.mod) and remembers your last launch settings per target in XDG state history. You can now export your configuration to a mirrord-up.yaml file, handle lingering session conflicts with a kill-and-relaunch prompt, and navigate using standard keys plus vim-style alternatives.
mirrord/tui/src/screens/targets · high confidence
New mirrord CLI container image with cross-platform support and CA certificates
The mirrord CLI is now distributed via a dedicated Dockerfile that builds the binary and layer libraries using cargo-zigbuild for cross-compilation. The runtime image is based on Debian and includes ca-certificates to ensure HTTP clients (local daemon, analytics) can verify TLS connections. The build process supports both x86\_64 and ARM64 architectures, with ARM64 builds additionally including an x86\_64 version of the layer library to support cross-platform container scenarios. A build.rs script ensures the UI frontend placeholder exists and handles macOS-specific SIP binary packaging.
mirrord/cli · high confidence
New protocol client library with connection resilience and traffic tunneling
The \mirrord/protocol-api/src\ module introduces a new \MirrordClient\ that manages the connection to the mirrord server, featuring automatic reconnection and retry capabilities to maintain stability during network interruptions. It includes a robust traffic tunneling system for mirroring incoming connections and handling outgoing sockets, along with an \IdTracker\ to ensure consistent file descriptor IDs across reconnects. The client also implements a size-aware FIFO queue with backpressure support to manage memory usage for protocol messages and traffic data.
mirrord/protocol-api/src · high confidence
New protocol-IO module with WebSocket support
The \mirrord/protocol-io\ crate has been introduced to handle wire-level IO for the mirrord protocol. This new module provides the \Connection\ abstraction for managing message queues and scheduling, and includes a dedicated WebSocket adapter (\websocket.rs\) that integrates with \tokio\_tungstenite\ to support connections to the operator. This change establishes the foundational IO layer for protocol communication.
mirrord/protocol-io · high confidence
New session-monitor protocol defines session and port subscription data structures
The session-monitor protocol now exposes structured data for session management, including \SessionInfo\ which carries target, namespace, and Kubernetes context details for UI display, as well as \PortSubscription\ objects that now include an optional \hit\_count\ field to track connection activity. This change establishes the data contract between the session monitor and its clients, enabling features like Windows named pipe support and enhanced session visibility in the UI.
mirrord/session-monitor-protocol · high confidence
New session-monitor-client library for cross-platform session management
Added a new \mirrord/session-monitor-client\ library that provides a cross-platform HTTP client for interacting with the per-session API exposed by mirrord-intproxy's session monitor. On Unix, it communicates via Unix domain sockets, while on Windows, it uses named pipes with a sentinel file for discovery. The client handles session endpoint resolution, request building, and response parsing, including support for Server-Sent Events (SSE) for streaming data. It also includes error handling for upstream session monitor errors and implements retry logic for Windows named pipe connectivity issues.
mirrord/session-monitor-client · high confidence
New sessions-manager client and Go runtime syscall interception support
This change introduces the sessions-manager client library, which enables agents and intproxies to register with the sessions-manager service, subscribe to connection assignments via HTTP/SSE, and manage data-plane upgrades with deduplication and retry logic. It also adds a new \mirrord/layer-go\ crate that provides the low-level machinery to intercept syscalls made by Go runtimes on Linux (x86\_64 and aarch64) by hooking runtime entry points and switching to the system stack, allowing mirrord layers to interpose on Go applications.
(repo-wide) · high confidence
New shared WebSocket transport crate for operator connections
A new \mirrord-operator-websocket\ crate has been introduced to centralize the WebSocket transport layer used by operator API consumers. This crate provides \connection.rs\ to adapt upgraded WebSocket streams into \mirrord-protocol\ streams and sinks, and \upgrade.rs\ to handle the WebSocket handshake via the Kubernetes API server or direct HTTPS endpoints. This change decouples the transport logic from higher-level operator concerns like CRDs and credentials, allowing the agent to establish protocol connections without depending on the full operator client stack.
mirrord/operator-websocket · high confidence
New terminal interface screens for managing sessions, targets, and databases
The terminal UI now includes dedicated screens for browsing and managing branch databases, queue-splitting sessions, preview environments, and mirrord sessions, alongside a targets wizard for configuring and launching services and an interactive shell pane with session tracking. This adds the first concrete user-facing screens for these capabilities, replacing the previous placeholder or non-existent state with functional, navigable interfaces.
mirrord/tui/src/screens · high confidence
New terminal pane for interactive mirrord sessions
A new terminal pane has been added to the TUI, allowing users to spawn a shell and view active mirrord sessions in a side panel. The pane manages a pseudo-terminal (PTY) to run the child shell, correctly handling terminal resizing and encoding keystrokes (including cursor keys and modifiers) to ensure compatibility with full-screen applications like vim or less. The side panel automatically detects sessions running under the pane's shell by walking the process tree, displaying session targets, port subscription modes (steal/copy), and uptime, while polling the local session registry for real-time updates.
mirrord/tui/src/screens/terminal · high confidence
Repository structure and developer tooling overhaul
The repository has been reorganized to improve developer experience and security posture. A new monolithic CLAUDE.md file now serves as the primary instruction set for AI coding agents, replacing previous per-crate instructions. A comprehensive STYLE.md guide has been added to standardize Rust code conventions, and a new SECURITY.md file establishes a formal vulnerability reporting process. Developer tooling is enhanced with new configuration files for markdown linting (.markdownlint.json), code formatting (.prettierrc.json), and prose validation (.vale.ini). Additionally, the project now includes a Cross.toml for cross-compilation support, a deny.toml for dependency auditing, and a flake.nix/flake.lock for Nix-based development environments.
(repo-wide) · high confidence
Secure per-session HTTP API for session monitoring and chaos testing
The session monitor now exposes a local HTTP API to inspect session state and manage chaos testing rules. On Unix, this is served over a Unix socket with \0o600\ permissions; on Windows, it uses a named pipe with a restrictive DACL allowing access only to the current user, ensuring confidentiality of sensitive session data like process names and file paths. The API provides endpoints for health checks, session information, and server-sent events for real-time monitoring, as well as a dedicated router for creating, updating, and deleting chaos rules to simulate network conditions.
_mirrord/intproxy/src/session\monitor · high confidence
Support for Argo Rollout targets and improved port-forward reliability
Mirrord now supports targeting Argo Rollout resources, allowing users to mirror traffic from applications managed by Argo Rollouts. This includes handling both inline pod templates and those referenced via \workloadRef\, with support for underlying workloads like Deployments, ReplicaSets, StatefulSets, and PodTemplates. Additionally, a new port-forwarding implementation with automatic retry logic has been introduced to improve connection stability when communicating with the mirrord agent.
mirrord/kube/src/api/kubernetes · high confidence
Support for CronJob, ReplicaSet, Service, and Rollout targets
Mirrord now allows users to target CronJob, ReplicaSet, Service, and ArgoCD Rollout resources in addition to existing types like Deployment, Job, Pod, and StatefulSet. This change adds the necessary resolution logic for these new resource types, enabling mirroring against workloads managed by CronJobs or ReplicaSets, direct service-based targeting, and ArgoCD Rollouts that may not rely on standard LabelSelectors.
mirrord/kube/src/resolved · high confidence
Unified layer library with cross-platform debugger detection and logging
The \mirrord/layer-lib\ crate now provides a shared codebase for both Unix and Windows layers, introducing a new \debugger\_ports\ module that automatically detects and ignores ports used by debuggers (DebugPy, PyDevD, ReSharper, JavaAgent, and NodeInspector) to prevent them from being intercepted. Logging is unified via the \MIRRORD\_LAYER\_LOG\_PATH\ environment variable, and the layer now respects the \JB\_IDE\_PORT\ environment variable for JetBrains IDEs. The library also includes a new \detour\ module for managing hook bypasses, a \Mutex\ wrapper with a \MIRRORD\_NODEADLOCK\ mode to prevent deadlocks, and support for \SOCK\_SEQPACKET\ sockets.
mirrord/layer-lib/src · high confidence
Unified mirrord UI with Session Monitor, Events, and Config Wizard
The \packages/ui\ location now serves as the single entry point for the mirrord interface, merging the previously separate Session Monitor and Config Wizard into one application with a shared top navigation bar. Users can now switch between the Session Monitor, a new Events tab, and the Config Wizard without losing state, as features are lazy-loaded and kept mounted. The UI also introduces a neutral dark gray palette for dark mode to improve readability, a global light/dark theme toggle in the header, and a shared error boundary to catch crashes across all features.
packages/ui · high confidence
Windows crash and exception diagnostics UI
mirrord now displays a native Windows dialog when a process running under the layer crashes, is terminated, or fails to initialize. The dialog presents the crash title, a subtitle with the exception code, a body with troubleshooting links (Slack, GitHub, email), and a process tree showing the relationship between the mirrord monitor and the crashed process. This change adds the build script to embed the dialog logo and example programs to preview the different diagnostic scenarios (crash, kill, fastfail, initfail) on Windows.
mirrord/utils-win · high confidence
Windows crash diagnostics and native error dialog
The Windows layer now captures detailed crash information and presents a native error dialog to the user. This includes an in-process crash handler that writes text records and minidumps, an out-of-process monitor that safely dumps crashed processes from the outside, and a custom Win32 dialog featuring the metalbear logo, a scrollable report box with clickable links, and buttons to report, copy, or open the crash folder.
mirrord/utils-win/src/diagnostics · high confidence
Windows installer package definition added
The project now includes the necessary WiX source files (main.wxs and License.rtf) to build a Windows MSI installer. This package installs the mirrord executable and its Windows-specific layer DLL into the Program Files directory and automatically adds the installation bin folder to the system PATH, enabling users to run mirrord commands from any location on Windows.
mirrord/cli/wix · high confidence
mirrord-agent build infrastructure and documentation added
This change introduces the build and documentation assets for the mirrord-agent component. It adds a Dockerfile that compiles the agent using a specific nightly Rust toolchain (2026-08-13) and the mold linker for performance, utilizing a shared CI build image. It also includes a platform detection script (platform.sh) to handle cross-compilation for amd64 and arm64 architectures. Additionally, a CONTRIBUTING.md guide is added to establish logging standards and warn against blocking the single-threaded Tokio runtime, while a README.md documents the agent's purpose and provides configuration examples for enabling Prometheus metrics. Finally, a nightly-polyfill library is added to provide stable Rust stand-ins for unstable nightly features like std::error::Report.
mirrord/agent · high confidence
Architecture
Agent refactored into modular source files with new CLI and TLS support
The agent source code has been reorganized from a single monolithic file into distinct modules (cli, client\_connection, container\_handle, dns, entrypoint, env, error, file, http, incoming, main). This change introduces a new command-line interface for configuring the agent, adds support for TLS-secured client connections via an \AgentTlsConnector\, and extracts environment variable filtering logic into a dedicated module. The agent now uses a modular structure for better maintainability while preserving its core functionality for traffic interception and management.
mirrord/agent/src · high confidence
Agent startup logic refactored into dedicated setup module
The agent's initialization process has been restructured by introducing a new \setup.rs\ module that explicitly manages the lifecycle of core background tasks. This change centralizes the creation and configuration of the traffic redirector (handling both steal and mirror modes), the TCP stealer, and the DNS worker, ensuring they are spawned on the designated background runtime. Users benefit from a more robust and maintainable agent startup sequence that clearly separates task configuration from execution.
mirrord/agent/src/entrypoint · high confidence
Extracted agent environment configuration into a dedicated crate
The mirrord-agent's environment variable definitions and their type-safe parsing logic have been extracted into a new, standalone \mirrord/agent/env\ crate. This change introduces a \CheckedEnv\ framework that enforces strict type checking for configuration values (such as \SocketAddr\, \bool\, and \Vec\<IpAddr\>\) and provides utilities for generating Kubernetes \EnvVar\ specs. The crate centralizes the definitions of all agent configuration variables (e.g., \MIRRORD\_AGENT\_METRICS\, \MIRRORD\_AGENT\_STEAL\_TLS\_CONFIG\, \MIRRORD\_AGENT\_CLEAN\_IPTABLES\_ON\_START\) and includes the \MeshVendor\ enum and \StealPortTlsConfig\ structures, ensuring that environment handling is consistent, backward-compatible, and isolated from the rest of the agent's implementation.
mirrord/agent/env · high confidence
Internal proxy refactored into a modular background-task architecture with robust failover and process termination
The internal proxy has been restructured to manage its components (agent connection, layer connections, ping-pong, and various proxies) as independent background tasks coordinated by a central message bus. This change introduces a dedicated failover strategy that detects unrecoverable agent connection losses and actively terminates all injected user processes to prevent them from lingering as zombies holding ports. It also adds a new \LayerInitializer\ to handle layer handshakes sequentially, ensuring clean shutdown and quiescence, while the \AgentConnection\ and \PingPong\ tasks are now restartable to handle transient network issues more resiliently.
mirrord/intproxy/src · high confidence
Refactor hooking infrastructure into mirrord-layer-core
The layer's hooking logic has been moved from \mirrord/layer/src/hooks.rs\ into a new \mirrord-layer-core\ crate. This introduces a centralized \HookManager\ for managing Frida-based detours and provides macros (\replace\, \replace\_with\_fallback\, \hook\_symbol\) to simplify installing hooks for libc functions and Go symbols. The \mirrord/layer\ crate now re-exports these core hooking utilities, unifying how system calls are intercepted across different platforms and runtimes.
mirrord/layer/src · high confidence
Refactored config derive macro internals
The internal implementation of the \\#\[config\]\ attribute macro has been restructured by introducing dedicated \ConfigField\ and \ConfigFlags\ modules. This change separates the parsing of configuration attributes (such as \env\, \default\, \nested\, \rename\, \unstable\, and \deprecated\) from the code generation logic, resulting in a more modular and maintainable derive macro implementation.
mirrord/config/derive/src/config · high confidence
Refactored internal proxy into modular file, incoming, outgoing, and simple proxies
The internal proxy logic has been reorganized into distinct, dedicated modules for handling specific traffic types: \files.rs\ manages file system operations with buffering and agent-loss handling, \incoming.rs\ handles incoming TCP and HTTP connections (including mirroring, stealing, and HTTP upgrades), \outgoing.rs\ manages outbound network connections with support for non-blocking flows and Unix sockets, and \simple.rs\ handles straightforward passthrough requests like DNS lookups and environment variable retrieval. This structural change improves code maintainability and isolates the behavior of each proxy type.
mirrord/intproxy/src/proxies · high confidence
Restructure socket hooking logic into dedicated ops and hooks modules
The socket interception logic in \mirrord/layer\ has been reorganized into \socket/hooks.rs\ and \socket/ops.rs\. This change separates the raw C-function detours (such as \socket\, \bind\, \connect\, \listen\, \accept\, \gethostbyname\, and \gethostname\) from the core business logic. The new \ops.rs\ module centralizes the handling of socket states, address binding fallbacks, and incoming port filtering, while \hooks.rs\ manages the entry points for the injected functions. This refactoring improves code maintainability and clarity for the socket layer without altering the external behavior of the tool.
mirrord/layer/src/socket · high confidence
Behavioural changes
Added home screen logo assets to the TUI
The TUI now includes dedicated resource files for the application logo, specifically 'logo-big' and 'logo-small', which are used to render the home screen visual identity.
mirrord/tui/resources · high confidence
Analytics now detects AI coding agents and reports preview environment usage
The analytics module now distinguishes usage driven by AI coding agents (Claude Code, Cursor, Codex, Gemini CLI, and Amp) by detecting specific environment variables, allowing these sessions to be identified separately from direct human usage. Additionally, the module introduces dedicated reporting for preview environment events (start, stop, status, and failure), including runtime tracking and session key identification, enabling visibility into how preview environments are utilized.
mirrord/analytics · high confidence
CI build optimization and tooling updates
CI now passes the \--target\ flag to Cargo only during cross-compilation, allowing native builds and tests to share the build cache for faster execution. The \cargo-zigbuild\ tool has been removed from the Nix development shell and CI runner images, with the \xtask\ now using a \--zigbuild\ flag to invoke it conditionally. Clippy warnings are now enforced using the \CARGO\_BUILD\_WARNINGS=deny\ environment variable instead of the \--deny warnings\ flag. Additionally, \mirrord ci\ persists its cleanup state atomically and rejects malformed state to prevent silent data loss, and the Greptile review rule has been updated to check issue requirements and inform the product team of scope changes.
changelog.d · high confidence
Consolidate CI image definitions using Docker Bake
The CI infrastructure has been refactored to use Docker Bake (docker-bake.hcl) for defining and building CI images, replacing the previous scattered approach. This change introduces a centralized build configuration that manages targets for the agent builder, agent runtime, CLI, and various cross-compilation environments (including x86\_64 and aarch64 layer builds for CentOS 7/Amazon Linux 2 compatibility). It also pins the Rust toolchain to the nightly build from 2026-08-13 across the builder and rust-build images, ensuring consistent build environments for the agent and CLI artifacts.
ci · high confidence
Improved DNS resolution reliability and memory safety
The DNS resolution layer now correctly honors the AI\_NUMERICHOST flag, preventing unnecessary remote lookups when applications are merely checking if a string is a literal IP address. Additionally, a new reverse DNS cache with a 1,000-entry limit has been introduced to map resolved IP addresses back to their hostnames, preventing potential memory exhaustion while supporting debugging and logging. Windows address info structures are now managed with explicit ownership tracking to ensure proper cleanup and prevent memory leaks.
mirrord/layer-lib/src/socket/dns · high confidence
Improved HTTP client reuse and response streaming in the incoming proxy
The incoming HTTP proxy now manages local HTTP client connections more robustly by introducing a \ClientStore\ that caches idle clients for reuse, while explicitly dropping clients that the local application has already closed to prevent hanging requests. Additionally, a new \StreamingBody\ implementation allows HTTP response bodies to be streamed efficiently via channels, and a \ResponseMode\ enum enables the proxy to select the appropriate response format (Basic, Framed, or Chunked) based on the agent's protocol version support.
mirrord/intproxy/src/proxies/incoming/http · high confidence
Improved reliability for multi-cluster preview startup
The \mirrord preview start\ command now handles multi-cluster scenarios more robustly by introducing a dedicated wait mechanism for replica clusters. This change ensures that users receive clear feedback if a preview fails or is deleted while waiting for replicas on non-default clusters, rather than silently succeeding. It also prevents the command from hanging indefinitely by enforcing a 60-second timeout and tolerates transient API errors, providing warnings instead of silent failures when the operator status is unavailable or slow.
mirrord/cli/src/preview · high confidence
Introduce async console logging with configurable log level
The mirrord console now supports an asynchronous logging mode (enabled via the \async-logger\ feature) that sends log records to the console application over a TCP connection using an async encoder, improving reliability when the Tokio runtime is not yet initialized. The console binary itself now uses the \MIRRORD\_LOG\ environment variable to configure its own tracing log level, replacing the previous \RUST\_LOG\ setting.
mirrord/console · high confidence
New HTTP request extraction and filtering infrastructure
The agent now uses a new internal HTTP handling layer that extracts requests into a stream, allowing for more granular control over request processing. This includes support for filtering HTTP requests by headers, paths, methods, and JSON body content using regex and JSONPath queries, as well as filtering headers using jq expressions. The system also introduces a share-link mechanism that allows users to join active mirrord sessions via a browser link, handling session key registration and cleanup. Additionally, error responses now include the agent version, and HTTP/2 requests without an authority in the URI are automatically downgraded to HTTP/1.1 to ensure compatibility.
mirrord/agent/src/http · high confidence
New SIP patching implementation with bundled utilities and Santa support
The mirrord SIP module has been rewritten to improve macOS compatibility and reliability. It now includes a pre-built bundle of system binaries (from /bin, /sbin, /usr/bin, /usr/sbin) to bypass SIP restrictions without patching protected executables, with transparent handling for aliases like sh→bash. Code signing logic has been updated to use the apple\_codesign crate for safer in-process signing, ensuring ad-hoc signatures and unique identifiers to avoid conflicts. The implementation adds support for Santa security policies via an environment variable, allowing the use of the system codesign binary to bypass Santa blocks when needed. Additionally, it introduces file-based logging for SIP operations to aid debugging, improved error handling for file descriptor limits, and version-aware extraction of the utility bundle to prevent stale patches.
mirrord/sip · high confidence
New \`not\_found\` filter and buffer size limits for file system operations
The file system configuration now supports a \not\_found\ filter, allowing users to specify path patterns that should be treated as non-existent by the application. Additionally, buffer size limits for read-only remote files have been introduced, with a warning issued for values exceeding 1 MB and a hard limit of 15 MB to prevent excessive memory usage.
mirrord/config/src/feature/fs · high confidence
New file operation hooking implementation in mirrord-layer
The file subsystem in mirrord-layer has been restructured with new modules (hooks.rs, open\_dirs.rs, ops.rs) that implement detours for standard libc file operations (open, opendir, readdir, statfs, etc.). This change introduces a new mechanism for handling file system operations by intercepting calls, applying path remapping and filtering rules, and forwarding requests to the remote agent or bypassing to local execution based on configuration. Users will experience more consistent file system mirroring behavior, particularly for directory operations and file metadata queries, as the layer now explicitly manages open directory states and applies path checks before remote operations.
mirrord/layer/src/file · high confidence
New global configuration and user data persistence modules
The CLI now introduces dedicated modules for managing persistent user state. A new global configuration system loads and validates settings from \\~/.mirrord/mirrord.json\, allowing users to edit this file via schema-validated CLI commands and applying its values to project configurations without overriding explicit local settings. Additionally, a new user data store at \\~/.mirrord/data.json\ tracks internal metrics such as session counts and machine IDs for analytics, while also recording whether a user has engaged with the configuration wizard.
mirrord/cli/src/data · high confidence
New internal proxy protocol with custom binary codec
The communication protocol between the layer and the internal proxy has been replaced with a new implementation. This new protocol defines a custom binary framing format (4-byte big-endian length prefix followed by bincode-encoded payloads) and provides both synchronous and asynchronous (feature-gated) encoders and decoders. It introduces new message types for the layer-to-proxy channel, including support for \SOCK\_SEQPACKET\ outgoing connections, and utilizes helper macros to manage request/response wrapping.
mirrord/intproxy/protocol · high confidence
New structured progress reporting system with IDE and JSON modes
The \mirrord/progress\ module has been replaced with a new implementation that supports structured progress tracking via JSON output and dedicated IDE communication channels. Users can now set the \MIRRORD\_PROGRESS\_MODE\ environment variable to \json\ for machine-readable output or rely on the new \ide()\ API for internal IDE notifications (controlled by \MIRRORD\_PROGRESS\_SUPPORT\_IDE\). The system also introduces specific warning messages for multi-pod deployments, HTTP filters, and incorrect \mirrord exec\ usage, along with a standardized \SESSION\_READY\_MESSAGE\ to signal session initialization completion.
mirrord/progress · high confidence
Optimized pre-commit hook for the wizard package
The pre-commit hook in the wizard package now skips linting when no files within the packages/wizard directory are staged. This optimization reduces startup overhead for commits that do not affect the wizard frontend, while still running lint-staged when relevant changes are present.
packages/wizard/.husky · high confidence
Refactored Kubernetes API into modular container and runtime components
The Kubernetes API logic in \mirrord-kube\ has been reorganized into distinct modules (\container\, \kubernetes\, \runtime\) to improve structure and maintainability. This change introduces a \ContainerConfig\ and \ContainerParams\ system that centralizes agent container settings, including the new \idle\_ttl\ configuration for controlling how long the agent persists after client disconnection. It also implements robust mesh vendor detection (supporting Istio Ambient, Istio CNI, Linkerd, and Kuma) and refined container selection logic that respects Kubernetes default container annotations and skips known sidecars (like Telepresence, Vault, and Cloud SQL Proxy). Additionally, the API now explicitly handles OpenShift detection more efficiently and ensures TCP\_NODELAY is set on agent connections to reduce latency.
mirrord/kube/src/api · high confidence
Refactored Kubernetes API module with new error handling and resource resolution
The \mirrord-kube\ library has been restructured to improve error reporting and target resolution. A new \KubeApiError\ enum provides specific, user-friendly error messages for issues such as missing kubeconfig fields, invalid resource states, node pod capacity limits, and agent startup failures. The module now includes a \ResolvedTarget\ system that standardizes how various Kubernetes resources (Deployments, StatefulSets, CronJobs, Services, etc.) are resolved and validated before mirroring. Additionally, a new \FromResource\ extraction trait and helper types (Name, Namespace, Uid) simplify accessing metadata from Kubernetes objects, and a \RetryPolicy\ helper integrates with the \kube\ client to automatically retry recoverable API errors during startup.
mirrord/kube/src · high confidence
Refactored MirrordConfig derive macro implementation
The internal implementation of the MirrordConfig derive macro has been restructured to improve code organization and maintainability. The macro logic is now split into dedicated modules for handling configuration fields and flags, allowing for more granular processing of struct attributes. This refactoring ensures that configuration structs are correctly generated with appropriate serialization and deserialization behaviors while maintaining backward compatibility with existing configuration definitions.
mirrord/config/derive/src · medium confidence
Refactored TCP and HTTP traffic stealing into a modular task-based architecture
The traffic stealing logic in the agent has been restructured from a monolithic implementation into distinct components: a background \TcpStealerTask\ that manages the lifecycle and distribution of stolen connections, a \PortSubscriptions\ module for handling port redirections and filtering metrics, and a \TcpStealerApi\ that serves as the communication bridge for individual client connections. This change introduces support for protocol version compatibility checks to ensure clients can handle specific traffic types (such as chunked HTTP requests or TLS upgrades), improves the handling of HTTP request body buffering, and adds comprehensive tests for scenarios including request upgrades, filtered vs. unfiltered subscriptions, and TCP passthrough.
mirrord/agent/src/steal · high confidence
Refactored agent container creation into dedicated modules with improved startup handling
The agent container creation logic in \mirrord-kube\ has been reorganized into specific modules (\ephemeral.rs\, \job.rs\, \pod.rs\, \targeted.rs\, \targetless.rs\, and \util.rs\) to separate concerns between ephemeral, job-based, and targetless agent deployments. This refactoring introduces faster failure detection for image pull errors (preventing indefinite waits in Pending state) and standardizes the use of \args\ over \command\ for agent container specifications to improve compatibility with Kubernetes restrictions like GKE Autopilot WorkloadAllowlists.
mirrord/kube/src/api/container · high confidence
Refactored configuration system with new source abstraction and context management
The configuration loading logic in \mirrord/config/src/config\ has been restructured to use a new \MirrordConfigSource\ trait and \ConfigContext\ for managing environment overrides, strict isolation, and deprecation/unstable warnings. This change introduces dedicated modules for handling environment variable sources (\from\_env.rs\), fallback logic (\source.rs\), and warning aggregation for deprecated or unstable fields (\deprecated.rs\, \unstable.rs\), ensuring that config verification and generation are isolated from the process environment when needed and that users are properly warned about legacy or experimental settings.
mirrord/config/src/config · medium confidence
Refactored connection handling to support HTTP passthrough and mirroring
The agent's incoming connection logic has been restructured to introduce explicit passthrough and mirroring modes for both HTTP and TCP traffic. New modules (\body\_utils\, \copy\_bidirectional\, \optional\_broadcast\) provide the underlying infrastructure for bidirectional data copying and efficient frame handling, while \http.rs\ and \tcp.rs\ now expose \steal\, \mirror\, and \pass\_through\ entry points. This change enables the agent to forward requests to the original destination (passthrough) while simultaneously capturing the traffic for mirroring, a capability required by recent HTTP filtering and body filter features.
mirrord/agent/src/incoming/connection · high confidence
Refactored incoming connection handling with dedicated redirector and task components
The agent's incoming traffic management has been restructured to support more flexible connection interception. A new \ComposedRedirector\ allows chaining multiple inner redirectors (e.g., for IPv4 and IPv6), ensuring that failures in one do not leave dangling redirections in another. The \IpTablesRedirector\ now supports dynamic chain names and mesh exclusions, enabling targeting of multiple containers within the same pod. Connection handling is now managed by a central \RedirectorTask\ that coordinates \StealHandle\ and \MirrorHandle\ instances, allowing for concurrent stealing and mirroring of TCP and HTTP traffic. The \ConnectionInfo\ struct now includes logic for \passthrough\_original\_dst\ to fix issues where applications listen on external IPs, and \TCP\_NODELAY\ is explicitly set on all proxying sockets to reduce latency.
mirrord/agent/src/incoming · high confidence
Refactored incoming proxy with improved HTTP handling and TCP performance
The incoming proxy module has been restructured into dedicated components (bound\_socket, http, http\_gateway, tcp\_proxy, tls, etc.) to support more robust traffic interception. Key improvements include setting TCP\_NODELAY on local proxy sockets to reduce latency for intercepted connections, enabling HTTP/1.1 and HTTP/2 upgrades for stolen requests, and adding support for TLS delivery with client certificate authentication for mutual TLS scenarios. The proxy now handles HTTP version mismatches more gracefully, rejects HTTP/2 CONNECT requests to HTTP/1 servers, and supports filtered HTTP mirroring with version negotiation for older agents.
mirrord/intproxy/src/proxies/incoming · high confidence
Refactored network configuration into modular DNS, filter, incoming, and outgoing components
The network feature configuration has been restructured into distinct modules (\dns.rs\, \filter.rs\, \incoming.rs\, \outgoing.rs\) to improve clarity and maintainability. This change introduces a dedicated \AddressFilter\ and \ProtocolFilter\ system for precise traffic matching, allowing users to define filters by port, socket address, subnet, or hostname. DNS resolution is now explicitly configurable via \feature.network.dns.filter\ to route queries locally or remotely, with automatic synchronization to outgoing filters. Incoming traffic supports advanced mode with HTTP filtering, port mapping, and listen ports, while outgoing traffic allows fine-grained control over TCP/UDP and Unix streams. The refactoring ensures that hostnames in outgoing filters are automatically mirrored to DNS filters to keep resolution consistent with the connection side.
mirrord/config/src/feature/network · high confidence
Refined default file system routing for local and remote modes
The default behavior for file access in mirrord has been updated to improve compatibility and security. System configuration files such as \/etc/ssl/certs\, \/etc/resolv.conf\, \/etc/hosts\, and \/etc/hostname\ are now read from the remote target by default to ensure correct network resolution and SSL trust. Service account tokens located in \/run/secrets\ and \/var/run/secrets\ are also routed remotely to maintain proper authentication. Conversely, a broader set of local paths—including standard system directories (\/usr\, \/lib\, \/etc\), user home contents, temporary files, and specific file extensions (\.py\, \.rb\, \.sh\, \.so\, etc.)—are now read locally by default. Additionally, hidden files in the user's home directory are excluded from remote access unless explicitly configured, and paths under \/Program Files\ are forced local to support WSL debugging.
mirrord/layer-lib/src/file/unix · high confidence
Removal of initial VS Code extension entry point
The initial \src/extension.ts\ file, which served as the entry point for the VS Code extension, has been removed. This file previously handled extension activation by logging a confirmation message and setting up a debug session listener to execute an external shell script (\bintest.sh\) when the \mirrord\ configuration was present. Its deletion indicates that the extension's core activation logic or structure has been refactored or replaced.
src · high confidence
TLS connection stealing now supports configurable server name verification
The TLS handler in the mirrord agent now allows specifying a server name for verifying the original destination when the stolen connection lacks an SNI extension. This change introduces new error types for setup failures (such as invalid server names or certificate issues) and updates the handler logic to prioritize the configured server name, falling back to the request URI or original destination IP if necessary. This ensures more robust TLS passthrough for connections where the SNI is missing or ambiguous.
mirrord/agent/src/incoming/tls · high confidence
Unified socket layer with remote DNS and hostname resolution
The socket interception logic in the layer library has been restructured into a unified, cross-platform implementation supporting both Unix and Windows. This change introduces remote DNS resolution via the proxy (replacing local lookups for configured domains) and adds the ability to fetch the remote hostname and Samba NetBIOS configuration from the target environment. It also implements a mechanism to share socket state between parent and child processes spawned via exec, ensuring continuity of intercepted connections across process boundaries.
mirrord/layer-lib/src/socket · high confidence
Windows layer crash diagnostics and file I/O hook unification
The Windows layer now captures early diagnostic snapshots and installs an in-process crash handler to log process identity, session role, and loaded modules (flagging security software) before any crash occurs, ensuring context is preserved even if the crash handler fails. Additionally, file system hooks have been reorganized into a unified structure with dedicated modules for operations like open, read, close, and query info, introducing a managed handle registry that tracks remote file descriptors and IOCP bindings to improve stability and reduce contention under heavy load.
mirrord/layer-win · high confidence
Windows process injection now uses job objects and structured synchronization
The Windows layer now manages injected child processes more robustly by binding them to a job object with the \JOB\_OBJECT\_LIMIT\_KILL\_ON\_JOB\_CLOSE\ limit, ensuring that child processes are automatically terminated if the parent layer crashes or exits unexpectedly. Additionally, process initialization is synchronized via named Windows events (e.g., \mirrord\_layer\init\{pid}\) rather than relying solely on environment variables, and the layer now correctly handles command-line quoting for executables with spaces. The module also introduces session role classification to distinguish between parent and child processes and adds a debugger wait feature controlled by the \MIRRORD\_LAYER\_WAIT\_FOR\_DEBUGGER\ environment variable.
mirrord/layer-lib/src/process · high confidence
Windows-specific file system access defaults introduced
Mirrord now applies Windows-specific default rules for file system operations. Paths under the user's home directory (such as .aws, .config/gcloud, .kube, and .azure) are treated as not found by default unless explicitly allowed. Additionally, local system and application files (including DLLs, Python scripts, Program Files, and the TEMP directory) are read locally by default, while no paths are read remotely by default in local-with-overrides mode.
mirrord/layer-lib/src/file/windows · high confidence
Test coverage
Added Kafka consumer test harness for split-topic validation; Added Rust end-to-end tests for file operations; Added Rust-based SQS printer test utility; Added WebSocket echo test harness; Added common test infrastructure for layer integration tests; Added integration test applications for Windows layer support; Added integration test applications for layer validation; Added integration tests for the session monitor API; Added local test server for issue 1317; Added smoke tests for TUI layout and shell interaction; Added test app for duplicate listener descriptor behavior; Added test utilities for TCP and HTTP steal scenarios; Expanded integration test coverage for layer hooks and protocol behavior; New E2E test infrastructure and Go-based test applications; New test harness for the internal proxy (intproxy); New test utilities for managing mirrord test processes; Removed legacy VS Code test runner and sample tests.
Dependencies
Workspace dependency management and new internal crates
The project has restructured its Rust dependencies to use workspace-level inheritance, centralizing version management across the monorepo. This change introduces several new internal crates to support this structure and specific features: \medschool\ for documentation extraction, \mirrord-agent-env\ for agent environment configuration, \mirrord-agent-iptables\ for Linux-specific network rules, and \mirrord-config-derive\ for configuration macro generation. Additionally, Go test application dependencies have been updated, including \app\_go\ moving to Go 1.21 and \issue2988\ to Go 1.23.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 58 → 62 (+3.3)
- Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.
Lenses
- Code Health 81 → 82 (+0.8)
- Architecture 99 → 92 (-6.7)
- Maturity 71 → 76 (+4.2)
- Readiness 60 → 53 (-6.2)
- Security 47 → 65 (+17.6)
- Event Sourcing 100 → 100 (+0.0)
- Accessibility 67 → 67 (-0.1)
- Performance 70 (new)
Resolved (90)
- Change coupling: config.rs ↔ session.rs (mirrord/cli/src/config.rs)
- Change coupling: ops.rs ↔ mod.rs (mirrord/layer/src/file/ops.rs)
- ClassTooLong: SplitQueuesConfig (mirrord/config/src/feature/split_queues.rs)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Duplicated block (10 lines × 2) (mirrord/cli/src/data.rs)
- Duplicated block (11–12 lines × 2) (mirrord/cli/src/execution.rs)
- Duplicated block (12 lines × 2) (xtask/src/tasks/cli.rs)
- Duplicated block (13 lines × 2) (mirrord/layer/src/go/linux_aarch64.rs)
- Duplicated block (14 lines × 2) (mirrord/layer/src/go/linux_aarch64.rs)
- Duplicated block (16 lines × 2) (mirrord/layer/src/go/linux_x64.rs)
- Duplicated block (18 lines × 4) (mirrord/operator/src/client/database_branches.rs)
- Duplicated block (19–20 lines × 2) (mirrord/layer/src/go/mod.rs)
- Duplicated block (23 lines × 2) (mirrord/layer/src/go/linux_x64.rs)
- Duplicated block (5 lines × 2) (mirrord/cli/src/ci.rs)
- Duplicated block (5 lines × 2) (mirrord/layer/src/go/linux_x64.rs)
- Duplicated block (5 lines × 2) (xtask/src/tasks/cli.rs)
- Duplicated block (7 lines × 2) (xtask/src/tasks/cli.rs)
- FileTooLong: feature/split_queues.rs (mirrord/config/src/feature/split_queues.rs)
- FunctionTooLong: mirrord_layer::go::c_abi_syscall6_handler (mirrord/layer/src/go/mod.rs)
- …and 70 more
New (76)
- Ambiguous naming for cleanup operations. It is unclear if cleanup_verified performs a stricter check, returns different error types, or is simply a redundant alias.
- Change coupling: ops.rs ↔ go.rs (mirrord/layer/src/file/ops.rs)
- Dependency hygiene PARTLY measured — Cargo dependencies read, dependency currency not (crates.io unreachable)
- Documentation: no contributor guidance (README.md)
- Duplicated block (10–11 lines × 2) (mirrord/intproxy/src/failover_strategy.rs)
- Duplicated block (10–12 lines × 2) (mirrord/cli/src/data/global_config.rs)
- Duplicated block (12–13 lines × 2) (mirrord/intproxy/src/failover_strategy.rs)
- Duplicated block (13 lines × 2) (mirrord/layer-go/src/linux_aarch64.rs)
- Duplicated block (13 lines × 2) (mirrord/tui/src/screens/databases.rs)
- Duplicated block (14 lines × 2) (mirrord/layer-go/src/linux_aarch64.rs)
- Duplicated block (14 lines × 2) (mirrord/operator/src/client/database_branches.rs)
- Duplicated block (16 lines × 2) (mirrord/analytics/src/lib.rs)
- Duplicated block (17 lines × 2) (xtask/src/main.rs)
- Duplicated block (19 lines × 4) (mirrord/operator/src/client/database_branches.rs)
- Duplicated block (5 lines × 2) (mirrord/layer/src/go.rs)
- Duplicated block (7 lines × 2) (mirrord/cli/src/ci.rs)
- Duplicated block (7 lines × 2) (mirrord/operator/src/client/database_branches.rs)
- Duplicated block (7 lines × 2) (xtask/src/tasks/cli.rs)
- Duplicated block (9 lines × 2) (mirrord/config/src/feature/database_branches/s3.rs)
- EventBuffer.absorb (cognitive 16) (packages/monitor/src/eventBuffer.ts)
- …and 56 more
Changes since last survey
- 264 commits — 245 feature/other, 19 fixes
By area
- (repo) — 103 commits
- mirrord/cli — 30 commits
- (root) — 23 commits
- .github/workflows — 18 commits
- mirrord/up — 13 commits
- mirrord/operator — 8 commits
- mirrord/intproxy — 6 commits
- packages/monitor — 6 commits
- .vale/styles — 4 commits
- .github/scripts — 3 commits
- mirrord/agent — 3 commits
- mirrord/config — 3 commits
- mirrord/layer-lib — 3 commits
- .github/pull_request_template.md — 2 commits
- changelog.d/+container-unix-sockets.fixed.md — 2 commits
- changelog.d/+xcrun-macos-27.fixed.md — 2 commits
- mirrord/layer — 2 commits
- mirrord/operator-websocket — 2 commits
- xtask/src — 2 commits
- .github/actions — 1 commit
Notable commits
- fix: Fix PHP Unix socket pathname truncation
- fix: Fix Windows mirrord-up test lint
- fix: Fix Windows process shutdown future pinning
- fix: Fix a failing test in CI that was never run before :)
- fix: Fix arm64e.x1 SIP slice selection
- fix: Fix broken path_resolver algorithm
- fix: Fix error message
- fix: Fix fstatat(2)
- fix: Fix release monitor Homebrew check on Blacksmith and stale status lookup
- fix: Merge branch 'main' into fix/arm64e-x1-sip
- fix: Merge branch 'main' into gemma/cor-1893-fix-update_config_docs-in-mirrord-release-ci
- fix: Merge pull request #4892 from metalbear-co/fix/arm64e-x1-sip
- fix: Merge pull request #4898 from metalbear-co/gemma/cor-1893-fix-update_config_docs-in-mirrord-release-ci
- fix: Merge pull request #4901 from metalbear-co/aviram/cor-1898-fix-xcrun-compatibility-with-mirrord-on-macos-27
- fix: Merge pull request #4913 from metalbear-co/meowchinist/cor-1904-fix-php-unix-socket-path-truncation-in-mirrord
- fix: fix
- fix: fix(ci): specify WinGet installer architecture
- fix: fix(up): clean process trees before forced exit
- fix: medschool: explicitly set docs root to fix flakes
- change: Accept Jev as a word in the Vale vocabulary
- …and 244 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
metalbear-co/mirrord was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 30 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 0c407f04253c6cada8d76310c8c57b3175b184e5 — the exact code this score is about.
- Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-505904ce13c1.