Skip to content
CAI
Software that uses CAICheck a score

microsoft/metered-billing-accelerator

60.8

Adequate · 3 October 2026

7.8k

lines of production code

F#

with C#, JavaScript

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is an Azure Marketplace metering service that aggregates usage data from Event Hubs and submits billing events to the marketplace. It provides infrastructure-as-code templates for deploying the necessary Azure resources, including Event Hubs, storage, and container apps, alongside a managed application framework for provisioning and lifecycle management. The codebase includes a .NET-based aggregation engine, an SDK for submitting metering data, and various demo applications to illustrate integration patterns.

Features

Add DemoWebApp with .NET 6.0 and ANSI color code disabling

A new DemoWebApp project has been added to the src/Demos directory, providing a Razor Pages application built on .NET 6.0 (specifically SDK 6.0.300) that integrates the Metering.ClientSDK. The application includes a Dockerfile for containerization and configuration files that explicitly disable ANSI color codes in console logging, ensuring cleaner output in containerized environments.

src/Demos/DemoWebApp · high confidence

Add legacy ARM and Bicep deployment infrastructure for Azure Metering

This change introduces a complete legacy deployment package for the Azure Metering solution, including ARM templates and Bicep scripts to provision the required infrastructure. The \templates/infra\ directory contains definitions for an Event Hubs namespace, a Storage Account with specific containers (checkpoints, snapshots, capture), an Azure Function App with a consumption plan, and associated monitoring resources (Log Analytics, Application Insights), along with role assignments for service principals. The \templates/sample\ directory provides an ARM template to deploy a sample Web App and its hosting plan. Supporting artifacts include GitHub Actions workflows (\deployInfraArmTemplate.yml\, \deploySampleArmTemplate.yml\) for automated deployment, shell scripts (\0-set-values.sh\, \1-deploy-dev.sh\, \2-create-windows-config.sh\) to manage configuration and execute deployments, and helper utilities (\get-value.sh\, \put-value.sh\) for JSON settings management. Documentation (\DEPLOYMENT.md\, \README.md\) explains the architecture and usage, noting this is a legacy, unmaintained option.

deploy/arm-legacy · high confidence

Added Azure Functions host for the metering aggregator

A new Azure Functions project has been introduced to host the metering aggregation logic. This host exposes a timer-triggered function that executes every five minutes, utilizing dependency injection to retrieve configuration from environment variables and running the aggregation worker with a three-minute timeout. The setup includes standard Azure Functions configuration files for host settings, local service dependencies (Application Insights and Storage), and a .gitignore tailored for the Azure Functions development environment.

src/AggregatorFunctionHost · high confidence

Added Bootstrap 5.1.0 grid library and default site styles to the demo app

The demo application now includes the Bootstrap 5.1.0 grid CSS (along with its source map and license) in the wwwroot/lib/bootstrap directory, providing responsive container and column classes for layout. Additionally, default site styles (site.css) and a placeholder JavaScript file (site.js) have been added to wwwroot/css and wwwroot/js respectively to support the demo's basic presentation.

src/Demos/DemoWebApp/wwwroot · high confidence

Added Databricks notebook for metering data analytics demos

A new Databricks notebook (\metering-data-analytics.ipynb\) has been added to the \src/Demos/DemoAnalytics\ directory. This notebook provides example SQL and Python code for analyzing metering data, including setup instructions for mounting Azure storage, querying AVRO capture content, and performing operational aggregations such as event counting and date-based summaries.

src/Demos/DemoAnalytics · high confidence

Added Event Hub capture sample for reading and processing metering events

A new demo application (ReadEventHubCaptureSampleProgram.fs) has been added to demonstrate how to read events from an Event Hub capture store. The sample reads all events or resumes from a stored state, processes them into metering update events, and outputs details for subscription purchases and usage submissions, including handling errors like duplicates or resource not found.

src/Demos/ReadEventHubCaptureSample · high confidence

Added Razor Pages for the Metered Billing Demo

The demo application now includes a set of Razor Pages (Index, Error, Layout, and Imports) that provide a user interface for submitting dummy metering charges. Users can interact with the demo via the home page, which presents buttons to trigger specific charge types (node, CPU, data source, message, and object) that send consumption data to an Event Hub via the ClientSDK. The layout includes standard Bootstrap styling and a footer with a 2022 copyright notice.

src/Demos/DemoWebApp/Pages · high confidence

Added SaaS Integration Demo with Landing Page and Azure Deployment

Introduced a new SaaS integration demo in \src/Demos/SaaSIntegration\ that includes an ARM template (\Azuredeploy.json\) for provisioning Azure resources and a complete Landing Page web application. The Landing Page handles Azure AD authentication, resolves marketplace subscriptions via the \IMarketplaceSaaSClient\, and provides UI views for subscription details, plan information, and unsubscribe actions.

src/Demos/SaaSIntegration · high confidence

Added SimpleSerialization demo to iterate over meter collection data

A new demo application has been added at src/Demos/SimpleSerialization that reads a MeterCollection JSON file, deserializes it, and iterates through the Meters to print each meter's MarketplaceResourceId along with its subscription plan's billing dimensions. This demonstrates the usage of the updated MeterCollection structure (now a list of Meters) and the renamed MarketplaceResourceId type.

src/Demos/SimpleSerialization · high confidence

Added demo application for capturing and displaying metering events

A new console-based demo application has been added to demonstrate how to consume and display metering events from an Event Hub. The application connects to the environment, reads events from a specific partition, and prints details for subscription purchases, deletions, usage reports, and unprocessable messages to the console.

src/Demos/DemoDownloadCapture · high confidence

Added local Event Hub capture replay utility

A new diagnostic tool has been added to locally replay Event Hub capture files for a specific partition. This utility reads AVRO capture files from a local directory, processes the events to reconstruct the metering state, and outputs the final state as a JSON file. It also provides capabilities to export individual events as JSON, print events with or without partition keys, count messages, and retrieve unique marketplace resource IDs, aiding in local debugging and state verification.

src/Tools/ReprocessLocalEventHubCaptureFiles · high confidence

Initial Bicep infrastructure modules for Azure deployment

This change introduces the foundational Bicep templates for deploying the application's Azure infrastructure. The new modules define the Container App environment (including managed identity, ingress, and Dapr configuration), an Azure Container Registry, and the core data plane resources (Storage Account with blob containers, Event Hubs namespace with capture enabled, and associated role assignments for senders and infrastructure identities). It also includes the environment module to provision the Log Analytics workspace and Application Insights linked to the managed environment.

deploy/modules · high confidence

Initial Bicep templates for managed app metering and deployment scripts

This change introduces the foundational Bicep templates for the managed application's metering infrastructure. It adds \meteredBillingDependencies.bicep\ to provision the necessary Azure resources, including user-assigned managed identities, a runtime Key Vault, and a deployment script to bootstrap service principal creation. Supporting modules are included: \setSecret.bicep\ handles merging and storing secrets in Key Vault, \permissionOnManagedAppDeployment.bicep\ manages role assignments on the managed app object, and \submitCreationMessage.bicep\ orchestrates the initial metering message submission via a deployment script. The templates utilize updated API versions (e.g., Key Vault 2023-07-01, Deployment Scripts 2023-08-01) and mark sensitive parameters like SAS tokens and bootstrap secrets with \@secure()\ to prevent exposure in deployment outputs.

managed-app/src/nestedtemplates · high confidence

Initial demo for Azure Marketplace managed app metering integration

This change introduces a new demo solution under \src/Demos/ManagedAppIntegration/src\ containing two Azure Functions: \MeteredTimerFunction\ and \NotificationFunction\. The \MeteredTimerFunction\ periodically emits usage events to a configured webhook, while the \NotificationFunction\ handles marketplace lifecycle notifications (such as successful provisioning) to initiate subscription creation in the metering system. The implementation includes necessary data models for billing details, plans, and usage events, along with configuration files for local development.

src/Demos/ManagedAppIntegration/src · high confidence

Initial managed app skeleton with VM and metering infrastructure

This change introduces the foundational structure for a managed application in Azure. It adds a createUiDefinition.json that defines the user input fields for SSH credentials, DNS prefix, and VM size selection. The mainTemplate.bicep orchestrates the deployment by configuring metered billing dependencies (including Key Vault integration for secrets) and passing parameters to the core application module. The managedAppContents.bicep file implements the actual workload, provisioning a Linux Virtual Machine (Ubuntu 20.04) with a public IP, virtual network, and network security group, while attaching a user-assigned managed identity for runtime operations.

managed-app/src · high confidence

Initial setup and local development scripts for Shared Resource Broker

This change introduces the initial deployment and configuration scripts for the Metering.SharedResourceBroker component. It adds a Bicep template (isv-backend.bicep) to provision the underlying Azure infrastructure, including an App Service (upgraded to .NET 8.0 and Standard S1 SKU), Key Vault, and Managed Identity. It also provides shell scripts (setup.sh, setup-local-dev-service-principal.sh) to automate the creation of Azure AD groups, service principals, and role assignments, along with a config template and test scripts to demonstrate service principal creation and token fetching workflows.

scripts/Metering.SharedResourceBroker · high confidence

Initial skeleton for Azure Marketplace Managed Application

Added a new managed-app directory containing the foundational structure for an Azure Marketplace Managed Application. This includes Bicep templates (mainTemplate, managedAppContents) to deploy a virtual machine with Azure Metering submission capabilities, configuration files for customer usage attribution and metering endpoints, and a build script to package the application for the partner portal.

managed-app · high confidence

Introduce Shared Resource Broker API endpoints

The Metering.SharedResourceBroker service now exposes HTTP controllers to manage application lifecycle and service principals. The ResourceController handles Azure Marketplace notifications, verifying a signature via configuration and triggering application deletion upon receiving a 'Deleted' provisioning state. The ServicePrincipalController provides an authorized endpoint to create service principals in Key Vault, returning specific error responses for authorization failures or existing principals. A DefaultController redirects root, docs, and swagger paths to the Swagger UI.

src/Metering.SharedResourceBroker/Controllers · high confidence

Introduce Shared Resource Broker service for Azure Managed Application lifecycle management

Added the \Metering.SharedResourceBroker\ component, an ASP.NET Core web service that automates the creation and deletion of Azure AD service principals for managed applications. The service integrates with Microsoft Graph to provision applications and secrets, manages Key Vault access via managed identity, and handles subscription registration events. It includes configuration for service principal prefixes and resource groups, along with middleware for request identity logging and Swagger API documentation.

src/Metering.SharedResourceBroker · high confidence

Introduce managed-app metering and provisioning scripts

Adds a set of shell scripts to the managed-app infrastructure to handle runtime metering and publisher-side provisioning. localScript.sh bootstraps the VM by installing dependencies, retrieving Key Vault secrets via the managed identity, and writing a metering configuration file. submit-meter.sh and submitCreationMessage.sh use this configuration to authenticate with Azure Active Directory and submit usage events to an Event Hubs endpoint. triggerServicePrincipalCreation.sh initiates the creation of a service principal in the publisher's Key Vault, while perms.sh provides a mechanism to assign RBAC roles to the managed application's identity. These scripts collectively enable the managed app to report usage and manage its own credentials.

managed-app/src/scripts · high confidence

Introduces EventHubObservableClient with periodic health pings

The src/Metering.EventHub module now includes EventHubObservableClient.cs, which implements an observable client for Azure Event Hubs. This client processes events from partitions and introduces a new behavioral feature: it sends periodic 'ping' messages to a designated Event Hub partition. Specifically, a ping is sent when a partition starts processing and subsequently every hour (10 minutes past the top of the hour) to signal ongoing activity. The implementation handles partition lifecycle events (initialization, closing, errors) and manages the cancellation of these ping tasks when partition ownership is lost or the client is disposed.

src/Metering.EventHub · high confidence

Introduces core metering domain types and JSON serialization in BaseTypes

This change establishes the foundational data structures for the metering system within the \src/Metering.BaseTypes\ assembly. It defines key domain models including \BillingDimension\ (supporting both Simple and Waterfall billing logic), \Meter\ (tracking subscription state, usage to be reported, and deletion flags), and \MarketplaceResourceId\ (handling both resource IDs and URIs for Azure Marketplace aggregation). Additionally, it introduces \InternalUsageEvent\ for application-to-aggregator communication and provides comprehensive JSON serialization logic in \Json.fs\ for these types, enabling the system to persist and exchange metering state.

src/Metering.BaseTypes · high confidence

Introduction of the Aggregator background service

A new .NET Hosted Service has been added to the application to run the Metering Aggregator. This service initializes the \AggregationWorker\ using configuration loaded from environment variables and runs it as a background task. The entry point is defined in \HostProgram.cs\, with supporting configuration files (\appsettings.json\, \launchSettings.json\) provided to manage logging (including disabling ANSI color codes) and development environment settings.

src/Aggregator · high confidence

New Bicep-based deployment templates for Azure resources

Users can now deploy the solution using Bicep infrastructure-as-code templates, offering two options: creating a new resource group or deploying into an existing one. The deployment process requires an Azure Marketplace Offer, Active Directory application credentials, and the Bicep CLI. The templates configure the necessary Azure resources, including Event Hubs and Container Apps, and output the Event Hub name for subsequent metering event configuration.

deploy · high confidence

New Event Hub type definitions and utilities extracted to separate assembly

The \src/Metering.EventHubTypes\ assembly has been introduced to centralize Event Hub-related types and utilities. This includes core abstractions for partition identifiers, message positions, and event sources (distinguishing between live Event Hub events and captured blob data), as well as specific message types like \PingMessage\ for heartbeat signals. Additionally, helper modules for F\# function conversion and standardized date-time handling via NodaTime have been added to support these types.

src/Metering.EventHubTypes · high confidence

New Metering Runtime SDK for Azure Event Hubs integration

The Metering.Runtime library now provides a comprehensive F\# SDK for integrating with Azure Event Hubs and the Azure Marketplace Metering API. This includes a ClientSDK for submitting metering updates, subscription lifecycle events, and handling unprocessable messages with partition affinity. The runtime also features an EventHubCaptureProcessor to read and replay historical events from Avro capture blobs, a MeterCollectionStore for persisting state snapshots to Azure Blob Storage with gzip compression, and credential management for Managed Identity and Service Principal authentication via Azure Identity.

src/Metering.Runtime · high confidence

New ReplayCaptureForPartition utility for exporting EventHub partition data

A new tool has been added at src/Tools/ReplayCaptureForPartition that reads the complete EventHub capture for a specific partition and exports the events and resulting state as JSON files. The utility iterates through all partition IDs, processes each event to update the metering state, and writes the individual event data and the cumulative state to the local filesystem using descriptive filenames that include partition ID, sequence number, and timestamp.

src/Tools/ReplayCaptureForPartition · high confidence

New SaaS usage demo client added

A new demo application (DemoClient) has been added to demonstrate SaaS metering workflows. It provides an interactive console interface and programmatic methods to submit subscription creation and deletion events, as well as emit metered usage data (such as CPU and memory) to an Event Hubs endpoint. The demo includes a sample plan configuration file and utilizes the Metering Client SDK to handle resource identification and data submission.

src/Demos/DemoClient · high confidence

New metering runtime components for aggregation, capture processing, and partitioning

This change introduces the core C\# runtime implementation for the metering service, adding three new files: AggregationWorker.cs, EventHubCaptureProcessor.cs, and PartitionIDHash.cs. The AggregationWorker handles the main processing loop, subscribing to EventHub partitions to aggregate metering data, regularly creating snapshots based on a configurable interval, and submitting usage batches to the Azure Marketplace API. The EventHubCaptureProcessor provides utilities to read and parse Avro-formatted Event Hubs capture blobs from Azure Blob Storage, allowing the system to catch up on historical data. Additionally, PartitionIDHash.cs implements a consistent hashing algorithm to determine which Event Hub partition a given resource ID should map to, ensuring uniform distribution of metering events.

src/Metering.RuntimeCS · high confidence

New operational scripts for Azure Event Hubs metering and infrastructure deployment

This change introduces a suite of new shell scripts in the \scripts/\ directory to support Azure Event Hubs metering operations and infrastructure management. The new tools allow users to fetch access tokens for Event Hubs and Azure Storage, query partition counts, and send messages to Event Hubs using either partition keys or specific partition IDs. It also includes scripts for submitting meter usage data, removing unprocessed messages (either exactly or up to a sequence number), and viewing meter collections and values from Azure Storage snapshots. Additionally, deployment scripts (\80\_deploy-infra.sh\, \81\_deploy-sample.sh\) are added to validate and deploy ARM templates for infrastructure and sample resources, while utility scripts handle subscription deletion and listing customer subscriptions via Azure Graph.

scripts · high confidence

New utility to add metadata to Event Hub capture blobs

A new standalone utility has been added to the \AddMetadataToEventHubCapture\ location that iterates through existing Event Hub capture files in Azure Blob Storage. For each blob, it reads the internal Avro data to extract the first and last sequence numbers, offsets, and enqueue times, then updates the blob's metadata with these details. This allows users to quickly enrich historical capture data with specific event timing and ordering information without re-processing the entire stream.

src/AddMetadataToEventHubCapture · high confidence

Behavioural changes

1 commit (0 fixes) modifying bin

A change to existing behaviour in bin — 1 commit, 2 files.

bin · medium confidence · unverified

Docker Compose configuration moved to dedicated subdirectory

The Docker Compose files (docker-compose.yml, docker-compose.override.yml, and the associated .dcproj and .dockerignore) have been moved into a new src/docker-compose subdirectory. This change cleans up the main project directory by preventing build artifacts like bin/ and obj/ from appearing there, and establishes a dedicated location for container orchestration configuration.

src/docker-compose · high confidence

Solution structure reorganized with .NET 8 and versioning tooling

The \src\ directory has been restructured to include a new \Metering.sln\ that aggregates all projects, including CMS demos and tools. The solution now targets .NET 8.0, as evidenced by the \Dockerfile.Aggregator\ using the \mcr.microsoft.com/dotnet/runtime:8.0\ base image. Additionally, \Directory.Build.props\ introduces \Nerdbank.GitVersioning\ (version 3.7.48-alpha) for build versioning, and standard \.editorconfig\ and \.gitignore\ files have been added to enforce code style and exclude build artifacts.

src · high confidence

Updated Metering Business Logic Demo Application

The Metering.BusinessLogicDemoApp has been updated to reflect recent architectural changes, including the migration of Event Hub types into a separate assembly and the renaming of InternalResourceId to MarketplaceResourceId. The demo code now utilizes these updated types and includes new sample data for subscription creation and consumption events, allowing users to test the metering logic against the revised data structures.

src/Demos/Metering.BusinessLogicDemoApp · high confidence

Updated architecture diagram in images folder

The architecture diagram located in the images folder has been updated with a new version (2022-03-15--13-00-00). The change includes new vector (SVG) and source (AI/PDF) files that reflect modifications to the system's visual representation, likely incorporating recent structural or component adjustments.

images · medium confidence

Test coverage

1 commit adding/updating tests in src/Metering.Tests/data/Capture; Added unit tests for Metering business logic and serialization.

Dependencies

Upgrade to .NET 8 and update core Azure dependencies

The Metering platform and its associated demo applications have been upgraded from .NET 7 to .NET 8. This update includes bumping core Azure SDK packages, specifically Azure.Identity to 1.11.4 and Azure.Messaging.EventHubs to 5.11.2, alongside updates to Microsoft.Identity.Web and other supporting libraries to ensure compatibility with the new runtime.

(dependencies) · high confidence

Housekeeping

Initial repository setup and documentation

The repository has been initialized with standard open-source governance and documentation files, including the MIT License, Code of Conduct, Security policy, and Support guidelines. A comprehensive README explains the architecture for aggregating Azure Marketplace metering data, and a pattern document details the event-sourcing approach for billing. The project also includes a docker-compose file for local execution, demo scripts for .NET and shell-based usage reporting, and configuration via Nerdbank.GitVersioning for build versioning.

(repo-wide) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 61 → 61 (+0.1)
  • Rubric changed (rubric-2026.09.15 → rubric-2026.10.1) — scores are not directly comparable.

Lenses

  • Code Health 56 → 56 (+0.2)
  • Architecture 91 → 90 (-1.5)
  • Maturity 62 → 62 (+0.0)
  • Readiness 62 → 62 (-0.0)
  • Security 69 → 70 (+0.4)

Resolved (33)

  • Critical CVE: Microsoft.AspNetCore.Server.Kestrel.Core 2.2.0
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no installation or build instructions (docs/2023-01-17--full-demo-with-managed-app.md)
  • High CVE: Microsoft.Extensions.Caching.Memory 8.0.0
  • High CVE: Newtonsoft.Json 11.0.2
  • High CVE: System.Formats.Asn1 8.0.0
  • High CVE: System.Security.Cryptography.Xml 8.0.0
  • High CVE: System.Text.Json 6.0.5
  • High CVE: System.Text.Json 6.0.6
  • High CVE: System.Text.Json 8.0.0
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 13 more

New (27)

  • Deprecated: Azure.Identity
  • Documentation: no project overview (README.md)
  • Inconsistent casing convention for property names within the BillingDefinition type. 'id' uses lowercase while 'processStatus' uses camelCase. Given the presence of other camelCase properties (e.g., Access_token, Quantity), 'id' appears to be an outlier or a direct mapping to a wire-format key that breaks the local naming convention.
  • Inconsistent casing style for compound property names. 'Access_token' uses an underscore separator while 'processStatus' uses camelCase. This indicates a lack of consistent naming convention for multi-word identifiers within the ManagedWebhook.Definitions namespace.
  • Outdated: Apache.Avro
  • Outdated: Azure.Identity
  • Outdated: Azure.Messaging.EventHubs
  • Outdated: Azure.Messaging.EventHubs.Processor
  • Outdated: Azure.Storage.Blobs
  • Outdated: FSharp.Control.AsyncSeq
  • Outdated: FSharp.Core
  • Outdated: Microsoft.Extensions.Configuration
  • Outdated: Microsoft.Extensions.Configuration.EnvironmentVariables
  • Outdated: Microsoft.Extensions.DependencyInjection.Abstractions
  • Outdated: Microsoft.Extensions.Hosting
  • Outdated: Microsoft.Extensions.Logging.Abstractions
  • Outdated: Microsoft.NET.Test.Sdk
  • Outdated: Microsoft.VisualStudio.Azure.Containers.Tools.Targets
  • Outdated: NUnit
  • Outdated: NUnit3TestAdapter
  • …and 7 more

API surface

  • Unchanged — 2 HTTP endpoints

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

microsoft/metered-billing-accelerator was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 3 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit aa38730b0f661fb6e7f7f63fd5b5a0a0804f21f8 — the exact code this score is about.
  • Scored under rubric-2026.10.1 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-4f4226d619ea.