Skip to content
CAI
Software that uses CAICheck a score

module-federation/aegis-host

45.4

Weak · 21 September 2026

70.7k

lines of production code

JavaScript

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Aegis is a modular, serverless-capable host application that manages service mesh configurations, TLS certificate generation, and WebAssembly module loading. It provides a secure, extensible framework for handling HTTP/HTTPS requests, JWT-based authentication, and remote module federation via Webpack. The system has been refactored to replace legacy in-memory data sources and controllers with a modern, dependency-injected architecture.

How it got here

2020 — Aegis host infrastructure and security hardening

10 changes.

This period focused on modernizing the Aegis host by introducing Docker, serverless, and utility scripts while upgrading dependencies. The codebase underwent significant refactoring, removing legacy controllers, in-memory data sources, and old logging mechanisms to support a more modular, secure, and cloud-ready architecture.

2021–2022 — Security and infrastructure automation

4 changes.

This period focused on hardening the application's security posture and automating critical infrastructure tasks. The team implemented automated TLS key generation and ACME challenge files to streamline certificate management, while simultaneously expanding the test suite to cover the Aegis domain and adapters.

Features

Added build, deployment, and utility scripts for the Aegis host

The repository now includes a Dockerfile for a development environment, a serverless deployment configuration for AWS Lambda, and several shell scripts (start.sh, status.sh, stop.sh, mongo.sh, rustup-init.sh) for managing the Aegis host, MongoDB, and Rust toolchains. Additionally, a proxy.js utility and a webpack client configuration for module federation have been added, while legacy configuration files like .babelrc and .prettierrc.json were removed.

(repo-wide) · high confidence

New remote entry configurations for local, cache, WASM, and worker modules

The \webpack/remote-entries\ directory has been restructured with new configuration files that define how various module types are loaded. This includes local development entries (\local.js\, \cache-local.js\) pointing to \localhost:8000\ and \localhost:8001\, as well as remote entries for caching (\cache.js\), WebAssembly (\wasm.js\, \wasm-local.js\), Python (\python.js\), and custom workers (\worker.js\). These files establish the mapping between module names, remote URLs, and the specific import functions (e.g., \importWebAssembly\, \importPython\) required to load them.

webpack/remote-entries · high confidence

Public-facing configuration and architecture documentation added

The public directory now includes a new \aegis.config.json\ file that defines live-updateable environmental variables, default service mesh implementations (WebSwitch, MeshLink, NatsMesh, QuicMesh), and authentication settings (including Auth0 integration). Additionally, \public/app.js\ provides the client-side logic for interacting with the API, handling progress tracking, JWT-based authentication, and idempotency keys. The \public/arch.drawio\ and \public/arch.html\ files introduce a visual representation of the system's C4 architecture, providing users with a clear understanding of the service mesh, adapters, and external system interactions.

public · high confidence

Refactored server entry points and added security middleware

The application's entry points have been restructured: the previous \src/index.js\ was removed and replaced with a new \src/server.js\ that handles HTTP/HTTPS server startup, certificate management, and graceful shutdown. A new \src/server-less.js\ entry point was added to support serverless execution via the \@module-federation/aegis\ library. Additionally, \src/middleware.js\ was introduced to integrate \helmet\ for security headers and \express-attack\ for rate limiting, which is applied to the Express app in \src/bootstrap.js\.

src · high confidence

Support for fetching remote entry files from GitHub repositories

Users can now configure remote modules hosted on GitHub by specifying the repository owner, repo name, file directory, and branch in the webpack configuration. The new \fetch-remotes.js\ module handles downloading these remote entry files, supporting both standard HTTP URLs and GitHub API endpoints. This enables multi-entry-point configurations where different remote modules are sourced from various GitHub repositories, with local file paths generated based on the repository and branch details to ensure unique caching.

webpack · medium confidence

Removals

Removed in-memory datasource implementations and factory

The abstract DataSource base class, the specific DataSource1 and DataSource2 in-memory implementations, and the DataSourceFactory that managed their singleton instances have all been removed from the codebase. This eliminates the previous in-memory data storage mechanism and its associated factory pattern.

src/datasources · high confidence

Removed legacy model factory and model1 implementation

The model factory singleton and related event factories have been removed from the codebase. Specifically, src/models/index.js, model-factory.js, model1.js, model1-create-event.js, and model1-update-event.js were deleted. This eliminates the previous mechanism for registering and instantiating 'model1' and its associated CREATE/UPDATE events, likely as part of a broader refactoring to simplify the model creation and event handling architecture.

src/models · high confidence

Behavioural changes

Added ACME challenge files for certificate management

The site now includes specific files in the public/.well-known/acme-challenge/ directory, such as RK65fkXKs7LTryMYAc4u4RCSboUBRLFsg8TWCk9ldHo and others. These files contain unique challenge tokens required by the ACME HTTP test, enabling automatic certificate management as defined by RFC 8555.

public/.well-known · medium confidence

Added automated TLS key generation for the mesh service

The cert/mesh directory now includes a keys.js script that programmatically generates 2048-bit RSA key pairs (public and private keys) and writes them as PEM files. This automation removes the need for manual certificate generation or renewal, as the system handles the creation of these keys for TLS.

cert · high confidence

Removal of legacy logger and observer modules

The \src/lib\ directory has been refactored by removing the \logger.js\ and \observer.js\ files. The \logger.js\ file, which previously exported a simple console logging function, has been deleted. Similarly, the \observer.js\ file, which implemented an event-based observer pattern with a singleton factory, has been removed. These changes indicate a cleanup or migration away from these specific implementation details within the library.

src/lib · high confidence

Removal of legacy use-case factories

The \add-model\, \edit-model\, and \list-models\ use-case modules have been removed from the application. This change eliminates the previous factory-based approach for managing model creation, editing, and listing, which previously relied on a centralized \UseCaseFactory\ to wire together data sources and observers.

src/use-cases · high confidence

Removed legacy REST controller implementations

The specific REST controllers for managing Model 1 (get, post, and patch operations) and the associated build-callback and index registration files have been removed from the codebase. This eliminates the previous direct HTTP request handling for these endpoints, indicating a shift away from the legacy controller structure.

src/controllers · high confidence

Test coverage

Added test suite for Aegis domain and adapters

Added new test files covering the Aegis domain, including model creation, dependency injection, port attachment, and controller logic, as well as serverless adapter and event service tests.

\\test\\_ · high confidence_

Dependencies

Upgrade to Aegis host with modernized dependencies

The project has been renamed to 'aegis-host' and upgraded to version 1.2.0, shifting from a 'federated-monolith' structure to a more modular setup. The dependency list has been significantly updated: the core '@module-federation/aegis' library is now at version 1.4.2-beta. Several new dependencies have been added, including 'bufferutil', 'cors', 'dotenv', 'helmet' (for security headers), 'pino' (for logging), and 'rustwasmc' (for WebAssembly support). Development dependencies have also been updated, with '@babel' tools upgraded to version 7.18.6, 'webpack' pinned to 5.47.1, and testing libraries like 'jest' and 'mocha' added or updated. The lock file format has been upgraded to version 2, reflecting modern npm practices.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 42 → 45 (+3.0)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 64 → 64 (-0.5)
  • Architecture 99 → 100 (+0.5)
  • Maturity 64 → 66 (+2.8)
  • Readiness 22 → 33 (+10.8)
  • Security 51 → 49 (-1.8)
  • Accessibility 61 → 55 (-6.2)

Resolved (63)

  • Change coupling: add-model.js ↔ execute-command.js (test/use-cases/add-model.js)
  • Coverage not included — suite not readable by the collector
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • High CVE: [GHSA redacted] (package-lock.json)
  • …and 43 more

New (153)

  • (anonymous) (cognitive 53) (public/app.js)
  • (anonymous) (cyclomatic 44) (public/app.js)
  • Coverage not measured — JavaScript/TypeScript suite
  • Critical CVE: [CVE redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Critical CVE: [GHSA redacted] (package-lock.json)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • High CVE: [GHSA redacted] (package-lock.json)
  • …and 133 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

module-federation/aegis-host was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 21 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 662098161c37105046862744c312e2740ae1f565 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-fa71c66cabd8.