Skip to content
CAI
Software that uses CAICheck a score

mingrammer/diagrams

69.4

Adequate · 26 September 2026

4.5k

lines of production code

TypeScript

with Python, JavaScript

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a Python library for generating infrastructure architecture diagrams from code, supporting a wide range of cloud providers (AWS, Azure, GCP, Kubernetes, etc.), on-premises, and SaaS services. It provides a programmatic API to define nodes and relationships, which are rendered into visual formats like SVG or PNG, and includes a C4 model module for software architecture visualization. The project also features an automated code generation pipeline for maintaining provider icons and documentation, alongside a web-based playground for interactive diagram creation.

How it got here

2020 — multi-provider expansion and automation

24 changes.

The project significantly broadened its scope by adding support for numerous cloud, on-premises, SaaS, and programming framework providers, while introducing a new Kubernetes module. This expansion was underpinned by a major infrastructure overhaul, including a migration to the Hatch build system, the implementation of automated code and documentation generation, and the creation of a web-based playground.

2022–2026 — Provider expansion and web playground

4 changes.

This period focused on expanding the library's coverage by adding new providers for DigitalOcean, C4 architecture modeling, and a comprehensive GIS ecosystem. Concurrently, the project introduced a browser-based Diagrams Playground, enabling users to create and share diagrams without local installation through an integrated Python runtime and editor.

Features

Add Alibaba Cloud provider support

Users can now diagram Alibaba Cloud infrastructure by importing from the new \diagrams.alibabacloud\ package. This addition introduces a base \AlibabaCloud\ node and organizes services into modules for compute (e.g., ECS, FunctionCompute), storage (OSS, NAS), database (RDS, PolarDB), network (VPC, SLB), security, and other categories, complete with corresponding icons and common aliases.

diagrams/alibabacloud · high confidence

Add Custom Node class for image-based nodes

Users can now create custom nodes that display a specific image by instantiating the new \diagrams.custom.Custom\ class. This class accepts an \icon\_path\ argument to load the image and passes any additional arguments to the underlying Node implementation, enabling flexible visual customization of diagram elements.

diagrams/custom · high confidence

Add DigitalOcean provider with compute, database, network, and storage diagrams

Users can now include DigitalOcean services in their architecture diagrams. This change introduces a new provider module under \diagrams/digitalocean\ containing classes for compute resources (such as Droplets, Kubernetes clusters, and Docker containers), database services (including Dbaas primary, standby, and read-only nodes), network components (like Load Balancers, Firewalls, VPCs, and Domains), and storage options (Spaces, Volumes, and Snapshots).

diagrams/digitalocean · high confidence

Add Elastic Stack diagram components

This change introduces a new set of diagram nodes for the Elastic ecosystem, allowing users to visually represent Elastic services in their architecture diagrams. The update adds modules for the core Elastic platform, Elasticsearch (including Kibana, Logstash, and specific features like APM and Machine Learning), Beats (such as Filebeat and Metricbeat), Enterprise Search, Observability, Security (SIEM, XDR), Orchestration (ECK, ECE), and SaaS offerings. These components are now available for import from the \diagrams.elastic\ package.

diagrams/elastic · high confidence

Add Firebase service diagram nodes

New diagram nodes have been added for the Firebase provider, allowing users to visualize Firebase services in their architecture diagrams. The update includes a base Firebase node and specific nodes organized by category: Development (Authentication, Firestore, Functions, Hosting, ML Kit, Realtime Database, Storage), Extensions, Growth (AB Testing, App Indexing, Dynamic Links, In-App Messaging, Invites, Messaging, Predictions, Remote Config), and Quality (App Distribution, Crash Reporting, Crashlytics, Performance Monitoring, Test Lab).

diagrams/firebase · high confidence

Add Kubernetes diagram support

Users can now create diagrams for Kubernetes architectures. This change introduces a new \diagrams.k8s\ module containing classes for core Kubernetes components (such as Pods, Deployments, Services, and ConfigMaps), infrastructure elements (like Nodes and ETCD), control plane components, networking resources, storage, RBAC, and ecosystem tools including Chaos Mesh, LitmusChaos, External DNS, Helm, and Kustomize.

diagrams/k8s · high confidence

Add OpenStack cloud provider diagrams

Users can now include OpenStack services in their architecture diagrams. This change adds a new \openstack\ provider module with classes for core services (Nova, Neutron, Cinder, Swift, Keystone, etc.) and categorized sub-modules (compute, networking, storage, orchestration, deployment, etc.), enabling visualization of OpenStack infrastructure components.

diagrams/ibm, diagrams/openstack · high confidence

Add Oracle Cloud Infrastructure (OCI) diagram provider

Introduces a new provider for Oracle Cloud Infrastructure, enabling users to diagram OCI resources. The change adds the core OCI node class and defines modules for Compute, Connectivity, Database, DevOps, Governance, Monitoring, Network, Security, and Storage services, each providing specific node icons (including white variants) and convenient aliases.

diagrams/oci · high confidence

Add Outscale provider with compute, network, security, and storage nodes

Users can now include Outscale cloud resources in their diagrams. This change introduces the Outscale provider module, defining base node classes and specific icons for compute (Compute, DirectConnect), network (ClientVpn, InternetService, LoadBalancer, NatService, Net, SiteToSiteVpng), security (Firewall, IdentityAndAccessManagement), and storage (SimpleStorageService, Storage) services.

diagrams/outscale · high confidence

Add auto-generated API documentation templates for node classes

New Jinja2 templates (apidoc.tmpl and apidoc\_custom.tmpl) have been added to the templates directory to support the automatic generation of API documentation. The apidoc.tmpl template structures the documentation for node classes by listing them with their associated icons and aliases, while apidoc\_custom.tmpl provides a reference link for examples involving custom nodes.

templates · high confidence

Expanded AWS icon library with granular service variants and new category modules

The AWS diagram library has been significantly expanded to provide more granular visual representation of AWS services. New modules have been added for AR, Blockchain, Business, Cost, Enablement, End User, Engagement, Game, Quantum, Robotics, and Satellite services. Existing modules have been enriched with specific sub-component icons, such as distinct icons for EC2 instance types, ECS task and service variants, DynamoDB tables and streams, RDS engine instances, and detailed EventBridge and IoT device types. Additionally, the CloudFront icon has been renamed to CloudFront, and new aliases have been introduced for common services like ALB, CLB, NLB, and IAM roles.

diagrams/aws · high confidence

Expanded Azure icon library with new service nodes and updated branding

The Azure diagram library has been significantly expanded to include a comprehensive set of new service icons and modules, covering areas such as AI/Machine Learning (e.g., Azure OpenAI, AI Studio), Compute (e.g., Container Apps, AKS Automatic), Identity (e.g., Entra ID, Entra Connect), and Storage. This update also introduces new categorized modules like \aimachinelearning\, \azureecosystem\, and \newicons\ to organize the growing icon set. Additionally, existing modules have been updated to reflect Azure's rebranding efforts, such as renaming 'Azure AD' nodes to 'Entra ID' equivalents, and correcting icon file paths and naming conventions (e.g., fixing \app-service---mobile.png\ to \app-service-mobile.png\).

diagrams/azure · high confidence

Expanded GCP service coverage with new diagram nodes and aliases

The GCP diagram library has been significantly expanded to include many more Google Cloud services. New nodes have been added across categories: API (API Gateway, Apigee, Endpoints), Management (Billing, Project, Quotas, Support), Operations (Logging, Monitoring), Analytics (Looker), Compute (Binary Authorization, OS Configuration/Inventory/Patch Management, Cloud Run), DevTools (Cloud Shell, Service Catalog), Migration (Migrate Compute Engine), ML (Vertex AI), Network (Cloud IDS, Network Connectivity/Intelligence Centers, Network Security/Tiers/Topology, Private Service Connect, Service Mesh), Security (Access Context Manager, Assured Workloads, Certificate Authority/Manager, Cloud Asset Inventory, IAP, Secret Manager, Security Health Advisor), and Storage (Local SSD). Additionally, a top-level GCP node is now available, and several legacy or new aliases (e.g., CloudRun, CE, PSC, SSD) have been introduced to improve discoverability.

diagrams/gcp · high confidence

Expanded provider support and automated code generation

The library now supports a significantly broader range of cloud and on-premises providers, including DigitalOcean, IBM, Firebase, Kubernetes, Alibaba Cloud, Oracle Cloud, OpenStack, OutScale, and GIS, in addition to the existing AWS, Azure, GCP, and on-premises support. To facilitate maintenance and consistency, the project introduces an automated code generation pipeline (via \autogen.sh\) that handles node class creation, documentation generation, and icon processing using tools like Inkscape, ImageMagick, and Black. This automation is supported by new pre-commit hooks and a Docker-based local development environment, while the minimum Python version has been raised to 3.9.

(repo-wide) · high confidence

Initial support for C4 model architecture diagrams

Users can now create diagrams using the C4 model primitives by importing from the new \diagrams.c4\ module. This addition provides specific node types including \Person\, \Container\, \Database\, and \System\ (with support for external systems), as well as \SystemBoundary\ for grouping and \Relationship\ for connecting elements, allowing for structured visualization of software architecture.

diagrams/c4 · high confidence

Introduce SaaS v2 diagram module with categorized service nodes

The \diagrams/saas\ package has been replaced by a new SaaS v2 structure that organizes services into specific sub-modules (alerting, analytics, automation, CDN, chat, communication, CRM, filesharing, identity, logging, media, payment, recommendation, security, and social). This change provides users with granular, category-specific imports for SaaS providers—such as Okta and Auth0 in identity, or New Relic and PagerDuty in alerting—rather than a single generic SaaS node, enabling more precise and semantically meaningful architecture diagrams.

diagrams/saas · high confidence

Introduce generic diagram nodes for infrastructure components

Adds a new \diagrams.generic\ module providing a set of generic, vendor-neutral icons for common infrastructure elements. Users can now include generic representations for operating systems (Android, CentOS, Debian, iOS, Linux, Raspbian, RedHat, SUSE, Ubuntu, Windows), virtualization platforms (QEMU, VirtualBox, VMware, XEN), network devices (Firewall, Router, Subnet, Switch, VPN), compute hardware (Rack), storage, databases (SQL), and mobile/tablet devices in their diagrams.

diagrams/generic · high confidence

Introduce on-premises service diagramming module

Users can now diagram on-premises infrastructure using the new \diagrams.onprem\ package. This addition provides a comprehensive set of Python classes and icons organized by category—including analytics, CI/CD, databases, monitoring, networking, and storage—allowing for detailed representation of self-hosted services like PostgreSQL, Kafka, Prometheus, and Nginx.

diagrams/onprem · high confidence

Introduce the Diagrams Playground web editor

A new online Python diagram editor is now available at the playground location, allowing users to write and render AWS, Azure, GCP, and Kubernetes architecture diagrams directly in the browser without any local installation. The editor features a CodeMirror-based interface with Python syntax highlighting, intelligent autocompletion for diagram nodes, and signature tooltips. It runs a Pyodide-based Python runtime in the browser to execute code and render SVG diagrams in real-time. Users can share their work via URL-encoded code snippets, export diagrams as PNG, SVG, or JPEG, and copy images to the clipboard. The application includes a gallery of examples, a node search sidebar, and a dark/light theme. SEO metadata, social sharing cards, and Google Search Console verification tags have been added to the landing page to improve discoverability. End-to-end tests using Playwright verify the editor's core functionality, including rendering, autocompletion, sharing, and error handling.

playground · high confidence

New GIS provider with comprehensive node icons

A new GIS provider has been added to the diagrams library, introducing a wide range of nodes for geographic information systems. This includes specific nodes for CLI tools (GDAL, Imposm, Lastools, Mapnik, MDAL, PDAL), data sources (BAN, Here, IGN, OpenStreetMap, OvertureMaps), databases (PostGIS), desktop applications (Maptunik, QGIS), formats (GeoPackage, GeoParquet), geocoding services (Addok, Gisgraphy, Nominatim, Pelias), Java tools (GeoTools), JavaScript libraries (Cesium, GeoStyler, KeplerJS, Leaflet, MapLibre, OL-Ext, OpenLayers, Turf.js), mobile apps (Mergin, QField, Smash), OGC standards (OGC, WFS, WMS), organizations (OSGeo), Python libraries (GeoPandas, PySAL), routing engines (GraphHopper, OSRM, pgRouting, Valhalla), server software (Actinia, Baremaps, Deegree, G3WSuite, GeoHealthCheck, GeoMapFish, GeoMesa, GeoNetwork, GeoNode, GeoServer, GeoWebCache, Kepler, MapProxy, MapServer, MapStore, MViewer, pg\_tileserv, PyCSW, PyGeoAPI, QGIS Server, Zooproject), and toolkits. The \diagrams.gis.cplusplus\ module is deprecated in favor of \diagrams.gis.cli\.

diagrams/gis · high confidence

New programming language, framework, and flowchart node icons

The diagrams/programming module now exposes a comprehensive set of new diagram nodes for representing programming languages (e.g., Rust, Scala, Erlang, Elixir, SQL, Dart, Kotlin), frameworks (e.g., Angular, Next.js, Phoenix, Quarkus, JHipster, Hibernate, FastAPI, Svelte, Starlette, Vercel), and standard flowchart symbols (e.g., decision, loop, database). This allows users to visually depict a wider variety of tech stacks and process flows in their diagrams.

diagrams/programming · high confidence

Release validation and automated API documentation generation

The release process now includes a new \check\_release\_version.py\ script that validates the git tag matches the version in \pyproject.toml\, preventing mismatched releases. Additionally, the \generate.py\ script has been updated to automatically produce API documentation (\.md\ files) for each provider alongside the existing code generation, and the \resource.py\ script now supports a wider range of providers (including DigitalOcean, IBM, Firebase, K8s, Alibaba Cloud, OCI, and others) with specific file-name cleaning rules.

scripts · high confidence

Behavioural changes

The website footer now includes a direct link to the 'Nodes' documentation under the Docs section, with existing links updated to reflect new URL paths (e.g., 'getting-started/installation' and 'guides/diagram'). Additionally, the GitHub interaction element has been replaced with an embedded iframe badge to display the project's star count, replacing the previous custom button implementation.

website/core · high confidence

The website homepage now links the "Try It Out" button to the new playground instead of the installation page, and the "Explore" button points to the updated getting-started installation docs. The hero logo image has been switched from SVG to PNG. The "About Diagrams" section has been updated to reflect that the tool supports Kubernetes, Alibaba Cloud, Oracle Cloud, on-premises nodes, SaaS, and programming frameworks/languages in addition to AWS, Azure, and GCP, and includes a note clarifying that it only draws architecture diagrams and does not control cloud resources or generate infrastructure code. Minor grammar fixes were also applied to the descriptive text.

website/pages · high confidence

New CLI entry point and modernized diagram styling with theme support

Users can now execute diagrams code directly from the command line via the new \diagrams\ CLI. The library introduces a new theming system (neutral, pastel, blues, greens, orange) that updates default colors and styling, and changes the default edge routing from ortho to spline. Additionally, the Diagram constructor now supports explicit output filenames, multiple output formats (including dot), curve styles, autolabeling, strict mode, and custom graph/node/edge attributes.

diagrams · high confidence

The documentation site has been reorganized with a new sidebar structure that includes a dedicated 'Nodes' section for various cloud and infrastructure providers, alongside updated 'Getting Started' and 'Guides' paths. A new 'Playground' link has been added to the header for the online editor, and a 'Sponsoring' link directs users to a Buy Me a Coffee page. Additionally, the site now integrates Google Analytics 4 (GA4) for tracking, disables Facebook comments, and updates social media images to PNG format.

website · high confidence

Test coverage

Expanded test coverage for C4 model, CLI, release validation, and packaging invariants

Added comprehensive test suites to ensure the correctness of new and existing features. New tests validate the C4 model primitives (Person, Container, System, Database, and relationships), the \diagrams\ CLI entry point (including multi-file processing and error handling), and the release version checking logic. Packaging tests verify that installed console scripts are importable and that all node icon resources are present in the distribution. Existing diagram tests were updated to cover new validation rules for curve styles and themes, support for the \dot\ output format, multi-format output generation, custom filenames, and autolabeling.

tests · high confidence

Dependencies

Migrate Python build system to Hatch and upgrade core dependencies

The project has switched its build backend from Poetry to Hatch, updating the \pyproject.toml\ to use \hatchling\ and raising the minimum Python version to 3.9. This migration is accompanied by significant dependency upgrades, including \black\ to 24.10.0, \click\ to 8.3.1, and \astroid\ to 3.3.11, while the package version is bumped to 0.25.1. Additionally, a new \playground\ sub-project was introduced with its own \package.json\ and \package-lock.json\, establishing a React-based web editor using CodeMirror, Vite, and Vitest.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 53 → 69 (+16.2)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 100 → 91 (-8.3)
  • Architecture 94 → 88 (-5.7)
  • Maturity 58 → 68 (+10.2)
  • Readiness 34 → 78 (+44.0)
  • Security 73 → 73 (+0.4)
  • Accessibility 65 (new)

Resolved (44)

  • Coverage not measured — test suite did not build
  • Dimension evaluation failed
  • High CVE: [GHSA redacted] (poetry.lock)
  • High IaC: DS-0002 (.devcontainer/Dockerfile)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • LLM evaluation failed
  • Low CVE: [GHSA redacted] (poetry.lock)
  • Low IaC: DS-0026 (.devcontainer/Dockerfile)
  • …and 24 more

New (80)

  • App.App (cognitive 23) (playground/src/App.tsx)
  • App.App (cyclomatic 19) (playground/src/App.tsx)
  • Coverage not measured — JavaScript/TypeScript suite
  • Critical CVE: [GHSA redacted] (playground/package-lock.json)
  • Dependency hygiene PARTLY measured — Python dependencies read, no exact pin to grade for currency
  • Diagram.init (cognitive 17) (diagrams/init.py)
  • Diagram.init (cyclomatic 17) (diagrams/init.py)
  • ExportBar.ExportBar (cognitive 25) (playground/src/components/ExportBar.tsx)
  • ExportBar.ExportBar (cyclomatic 20) (playground/src/components/ExportBar.tsx)
  • FixmeComment (diagrams/init.py)
  • High CVE: [GHSA redacted] (playground/package-lock.json)
  • High CVE: [GHSA redacted] (poetry.lock)
  • High CVE: [GHSA redacted] (playground/package-lock.json)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 60 more

Changes since last survey

  • 13 commits — 10 feature/other, 3 fixes

By area

  • (root) — 3 commits
  • .github/workflows — 3 commits
  • (repo) — 2 commits
  • website/static — 2 commits
  • .github/dependabot.yml — 1 commit
  • docs/getting-started — 1 commit
  • playground/src — 1 commit

Notable commits

  • fix: fix: move dev dependencies to hatch env to stop pre-commit leaking into runtime (#1248)
  • fix: fix: package_managers.dependabot.dependabot-missing-cooldown.dependabot-missing-cooldown security vulnerability (#1235)
  • fix: fix: verify built artifacts and gate release tags against pyproject version
  • change: Alias Prometheus and drop the stale Azure icon note
  • change: Merge pull request #1204 from thegovind/update-azure-icons
  • change: Merge pull request #1236 from mingrammer/filipeaaoliveira/02-packaging
  • change: Mirror updated Azure icons into website static assets
  • change: chore(site): add Google Search Console verification tag (#1247)
  • change: docs: refresh C4 example image (#1254)
  • change: feat(playground): add SEO metadata and social sharing card (#1245)
  • change: feat(playground): target search terms for the online editor (#1246)
  • change: feat: add Diagrams Playground web editor (#1240)
  • change: test: stabilize test workflow by removing Poetry lockfile coupling (#1258)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

mingrammer/diagrams was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 26 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 0cd0d84016087eead0f7a5b747571b3f92b56726 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-9984f8053b7b.