Skip to content
CAI
Software that uses CAICheck a score

nerves-hub/nerves_hub_web

50.8

Weak · 18 September 2026

57.7k

lines of production code

Elixir

primary language

1

measurement over time

CAI band scale
CAI lens gauges

What this system is

NervesHub is a fleet management platform for IoT devices, providing a web interface and API to monitor device health, manage firmware updates, and configure device connections. It supports staged rollouts with approval workflows, advanced device filtering, and real-time telemetry analytics stored in ClickHouse. The system handles multi-tenant organization structures with granular role-based access control and supports various firmware update tools like fwup, ESP-IDF, and RAUC.

How it got here

2018–2023 — NervesHub platform foundation

43 changes.

This period established the core NervesHub application architecture, implementing the initial database schema, authentication systems, and device management contexts. It introduced critical infrastructure for firmware lifecycle handling, including multi-tool support and S3 storage, alongside a modernized web interface using Phoenix LiveView. The work also set up comprehensive testing, analytics buffering with ClickHouse, and background job processing to support fleet-scale operations.

2024–2025 — UI modernization and managed deployments

48 changes.

This period focused on a comprehensive overhaul of the web interface, migrating core management pages to Phoenix LiveView with a new sidebar layout, command palette, and advanced device filtering. It also introduced a robust Managed Deployments system supporting staged rollouts, alongside significant backend enhancements like OpenTelemetry tracing, a modular device extension framework, and expanded firmware format support.

2026 — Light theme and advanced device filtering

19 changes.

This period focused on introducing a comprehensive light theme with unified design tokens and expanding the UI with interactive components like a command palette and device location map. Significant backend work included implementing a new advanced query language for precise device filtering and refactoring device connection handling into a transport-independent contract. The effort was heavily supported by extensive test coverage for these new features, including browser tests, telemetry validations, and firmware update tool backends.

Features

Add OpenTelemetry tracing with request filtering and customization

The telemetry module now supports OpenTelemetry tracing, introducing a custom sampler that filters out noise from static assets, health checks, and internal heartbeats to reduce trace volume. It also includes a customization handler that renames WebSocket request spans for better visibility and safely handles connection timeouts without crashing.

_lib/nerves\hub/telemetry · high confidence

Added Base62 encoding utility module

A new \NervesHub.Utils.Base62\ module has been added to provide functions for encoding and decoding binary data or integers using the Base62 scheme. This utility generates URL-safe ASCII strings using digits and letters, which can be used for compact data representation in contexts where standard Base64 characters might be problematic.

_lib/nerves\hub/utils · high confidence

Added world geographic boundary data

The application now includes a static GeoJSON file containing administrative boundary data for countries in the Americas (including Costa Rica, Nicaragua, Haiti, Dominican Republic, El Salvador, Guatemala, Cuba, Honduras, the United States, and Canada). This data is served from the \priv/static/geo/\ directory and can be used by client-side components to render maps or geographic visualizations.

priv/static · high confidence

Advanced device filtering and bulk management capabilities

Users can now filter devices using a dedicated advanced query language that supports boolean expressions over whitelisted columns, with free-text input automatically converted to substring searches. The device list also supports bulk actions, allowing users to add or remove tags from multiple devices at once, import devices in bulk via CSV or Microchip Trust and Go formats, and move or remove devices from deployment groups in batches.

_lib/nerves\hub/devices · high confidence

Centralized Sentry logging helper for devices and deployments

A new \NervesHub.Helpers.Logging\ module has been introduced to standardize error reporting to Sentry. This helper provides functions to log messages or exceptions with automatic context tagging for Devices, Deployment Groups, and DeviceInfo, ensuring that relevant identifiers (such as device ID, product ID, and organization ID) are consistently attached to Sentry events for easier debugging and monitoring.

_lib/nerves\hub/helpers · high confidence

Configurable health profiles and product notifications

Products now support configurable health profiles, allowing administrators to define per-product (and per-platform) warning and alert thresholds for device metrics, with built-in suggestions based on fleet history. Additionally, a new product notification system has been introduced to track and display event-level information (info, warning, error) associated with specific products.

_lib/nerves\hub/products · high confidence

Initial configuration structure for NervesHub

The application now uses a standard Elixir configuration layout with \config.exs\ for shared settings and environment-specific files (\dev.exs\, \prod.exs\, \test.exs\, \runtime.exs\) for runtime overrides. This setup configures the Phoenix endpoints to use the Bandit adapter, sets up Oban for background job scheduling with specific cron jobs for cleanup and truncation, and defines runtime environment variables for features like device metrics, logging, and file uploads. It also establishes the scope system for users, organizations, and products, and configures Sentry, Swoosh, and other dependencies.

config · high confidence

Introduce CA Certificate ownership verification and JITP schema

Added new modules to handle CA certificate lifecycle and Just-In-Time Provisioning (JITP). The \CSR\ module implements ownership verification by generating validation codes, checking Certificate Signing Requests (CSRs) against certificates, and managing verification tokens to ensure the user controls the private key. The \JITP\ module introduces an Ecto schema for JITP configurations, linking CA certificates to specific products and allowing the storage of tags and descriptions that are applied to devices upon creation.

_lib/nerves\_hub/devices/ca\certificate · high confidence

Introduce ClickHouse-backed analytics buffering and new core contexts

The NervesHub library now includes a new analytics infrastructure that batches device connection events, log lines, metrics, and health data into ClickHouse via a dedicated \AnalyticsRepo\ and \Analytics.Buffer\ GenServers, significantly improving write performance at fleet scale. This change is accompanied by the introduction of several new core contexts: \NervesHub.Accounts\ for user and organization management, \NervesHub.Archives\ for handling additional firmware files, \NervesHub.AuditLogs\ for tracking system changes, \NervesHub.Certificate\ for X.509 certificate parsing, \NervesHub.CLISessionCache\ for distributed CLI session storage, and \NervesHub.CommandPalette\ for scoped search functionality. These modules form the foundation for the new UI features and improved device management capabilities.

_lib/nerves\hub · high confidence

Introduce Managed Deployments with deployment group management UI

The platform now features a new Managed Deployments system, replacing the previous deployment model. Users can create deployment groups by selecting a platform, architecture, and firmware, and defining device matching conditions via tags and version constraints. The deployment group index page allows filtering by name, platform, and architecture, sorting by various columns, and customizing which columns are displayed. Individual deployment group pages support staged firmware rollouts through a visual workflow, with status indicators for delta update preparation and failure states. The UI also includes tabs for summary, releases, activity, and settings, providing a comprehensive view of the deployment lifecycle.

_lib/nerves\_hub\_web/live/deployment\groups · high confidence

Introduce device health status tooltips and metric label management

This change adds the UI components for displaying device health status and managing metric labels. The new \HealthStatus\ component renders an icon with a tooltip that details health reasons, including formatted thresholds, periods, and directionality (e.g., 'at or over' vs 'at or under'). The \MetricLabels\ module centralizes the display names for health metrics (such as CPU, memory, and disk usage), prioritizing built-in profile labels, then custom product labels, and finally falling back to humanized defaults, ensuring consistency across the health tab, device details, and health profiles pages.

_lib/nerves\_hub\_web/components/device\health · high confidence

Introduce local and S3 adapters for firmware file storage

The firmware upload system now supports two distinct storage backends: a local file adapter and an Amazon S3 adapter. The local adapter stores firmware files on the server's filesystem and generates public URLs based on the web endpoint configuration, while the S3 adapter uploads files to an S3 bucket and provides time-limited presigned download URLs. Both adapters implement the same interface, allowing the system to handle firmware uploads, downloads, deletions, and metadata generation (including delta updates) consistently regardless of the underlying storage mechanism.

_lib/nerves\hub/firmwares/upload · high confidence

Introduce staged firmware rollouts via deployment workflows

Users can now define multi-step deployment workflows for firmware releases, enabling staged rollouts with canary stages, manual approval gates, and configurable failure tolerance. The system introduces \DeploymentWorkflowStep\ entities to track progress through stages like \update\_devices\ and \approval\_required\, managed by a new \WorkflowCoordinator\ that processes steps sequentially. This allows for controlled firmware updates where specific device subsets (canaries) are updated first, requiring explicit approval before the rest of the fleet is updated, while a \catch\_all\ step handles remaining devices. The orchestrator now supports these workflows alongside the existing default deployment model, providing granular control over the update process.

_lib/nerves\_hub/managed\deployments · high confidence

New API endpoints for CA certificates, device logs, and iroh endpoints

The API now exposes dedicated controllers for managing organization CA certificates (including creation with ownership verification and listing), retrieving device logs with filtering by level, time, and search terms, and managing iroh endpoint IDs. These additions complement the existing device, firmware, and deployment group endpoints, providing more granular control over certificate lifecycles, observability via logs, and network identity management.

_lib/nerves\_hub\web/controllers/api · high confidence

New API token authentication for user websockets and external device event streams

Users and external services can now authenticate to the platform's WebSocket channels using API tokens instead of session cookies. The new \APISocket\ allows the \UserConsoleChannel\ and \UserLocalShellChannel\ to be joined via API token, enabling programmatic access to device consoles and local shells. Additionally, the new \EventStreamSocket\ and \DeviceEventsStreamChannel\ provide a dedicated endpoint for external services to subscribe to device firmware update progress events using the same API token authentication mechanism.

_lib/nerves\_hub\web/channels · high confidence

New CLI login flow and updated sign-in page

Users can now authenticate via the command-line interface through a new browser-based confirmation flow (cli.html.heex, cli\_confirmed.html.heex, cli\_invalid.html.heex) that displays a code for verification. The main sign-in page (new.html.heex) has been refreshed with a redesigned layout, a 'Remember me' checkbox, and a disabled-submit button with a spinner to prevent double-submission. Additionally, a new error page (confirm\_error.html.heex) provides specific messaging and support contact details for account confirmation issues.

_lib/nerves\_hub\_web/controllers/session\html · high confidence

New LiveView-based Organization management pages

The Organization settings area has been rebuilt using Phoenix LiveViews, replacing the previous implementation. This change introduces dedicated LiveView modules and HEEx templates for managing Organization Settings, Certificate Authorities, Signing Keys, Network Identities (Iroh Endpoints), Users, and Organization Deletion. Users can now perform these administrative actions with real-time updates and improved navigation within the organization context.

_lib/nerves\_hub\web/live/org · high confidence

New Mix tasks for asset management, device/metrics generation, and version auditing

This change introduces several new Mix tasks in the \lib/mix/tasks\ directory to improve development workflows and data management. Developers can now use \mix assets.install\ and \mix assets.build\ to manage web assets via npm. For testing and debugging, \mix nerves\_hub.gen.devices\ generates sample devices with randomized locations, while \mix nerves\_hub.gen.metrics\ populates a device's history with simulated metrics (CPU, memory, load) over a week, writing to ClickHouse. Additionally, \mix nerves\_hub.versions.report\_invalid\ provides a read-only audit of existing firmware and archive records that do not conform to SemVer standards, helping identify data that was not caught by new validation rules.

lib/mix · high confidence

New OpenAPI specifications for device, log, and support script APIs

The API documentation now includes generated OpenAPI specs for the device management, device log retrieval, and support script endpoints. Users can now see the full contract for listing and filtering devices (including advanced query syntax, firmware validation status, and CA signer tracking), retrieving device logs with time-based pagination and level filtering, and listing support scripts. The specs cover both the standard organization/product-scoped paths and the shorter device-identifier-only paths, ensuring consistent documentation for all supported API routes.

_lib/nerves\_hub\web/controllers/api/openapi · high confidence

New UI components for device management and navigation

The web interface introduces a suite of new LiveView components to support the updated device management experience. Users can now use an advanced search field with syntax highlighting and autosuggestions on the device list, a command palette (CMD-K) for quick navigation across devices, deployment groups, and firmware, and a bulk actions sidebar to manage selected devices (move products, assign deployment groups, update tags, push firmware). Additional UI improvements include a breadcrumb navigation component, timezone-aware date rendering, device location maps, and external network identity displays.

_lib/nerves\_hub\web/components · high confidence

New advanced query language for device filtering

Users can now filter the device list using a custom query syntax (e.g., \platform=raspberry\_pi and last\_seen \> "7 days ago"\) instead of relying solely on the sidebar filters. This new capability supports filtering by identifier, search text, platform, firmware, architecture, firmware validation status, signer CA, connection status, last seen time, tags, health status, connection type, updates, alarm status, deletion status, update status, and deployment group. The system includes a lexer, parser, and compiler that translates these queries into efficient database filters, allowing for more precise and complex device discovery.

_lib/nerves\_hub/devices/advanced\query · high confidence

New authorization, IP resolution, and timezone helper modules

This change introduces several new helper modules in the web layer to support updated platform capabilities. The new \Authorization\ module centralizes permission checks for organization, device, firmware, and deployment group actions, enforcing role-based access control. \ClientIP\ provides robust resolution of device connection addresses from forwarded headers, accounting for proxy hops and infrastructure entries. \Timezone\ validates and resolves viewer time zones from browser inputs with safe fallbacks to UTC. Additionally, \FirmwareDeletion\ generates user-facing messages for deletion blockers and warnings, \RoleValidateHelpers\ offers a plug for role validation, \SortedMapJasonEncoder\ ensures deterministic JSON output for sorted maps, and \WebsocketConnectionError\ handles specific device connection errors including redirects to the correct websocket host.

_lib/nerves\_hub\web/helpers · high confidence

New deployment group page with activity, releases, and workflow management

The deployment group interface has been restructured into a tabbed layout with dedicated LiveComponents for Activity, Releases, Settings, Summary, and Workflow steps. Users can now view a paginated audit log of recent changes, manage a history of firmware releases with optional notes and delta status, and configure deployment settings including workflow definitions, device matching conditions, and queue management. The summary tab provides device statistics and supports importing devices via CSV, while the workflow visualization allows users to monitor and skip steps in staged rollouts.

_lib/nerves\_hub\_web/components/deployment\_group\page · high confidence

New device page tabs for activity, data history, errors, and firmware history

The device detail view now includes dedicated tabs for Activity (audit logs), Data History (live-streamed device messages with filtering), Errors (aggregated error reports with live updates), and Firmware History (installed firmware versions and validation status). These tabs provide persistent, paginated, and filterable views of device events and telemetry, replacing or supplementing previous inline displays.

_lib/nerves\_hub\_web/components/device\page · high confidence

New email view with configurable closing and signoff

Added a new EmailView module that provides a standard closing section for email templates. This view dynamically generates a support message based on the configured support email address and allows for a custom signoff text, enabling users to personalize the footer of outgoing emails.

_lib/nerves\hub/views · high confidence

New extensible device extension framework with configurable modules

The platform now supports a modular extension system for device connections, allowing features like health monitoring, metrics, logging, local shell access, geo-location, network identities, and error reports to be enabled or disabled independently. This change introduces a new dispatch mechanism that routes device traffic to specific extension modules based on version negotiation, replacing previous monolithic handling. It also implements targeted PubSub using the \:group\ library to reduce cross-node traffic for console and local shell interactions, and adds configuration schemas for both device-level and product-level extension toggles.

_lib/nerves\hub/extensions · high confidence

This change introduces a suite of new JavaScript hooks and helpers that power several new interface capabilities. It adds a configurable command palette (CMD-K) for quick navigation, a syntax-aware advanced query editor with autocomplete for device filtering, and a new device location map that respects the user's theme. The device console and local shell are rebuilt on xterm.js, featuring a Mac-specific Option-as-Meta toggle for correct character input, and support for drag-and-drop file uploads. Additionally, new chart hooks (bar, line, and donut) provide richer visualizations for device metrics and firmware versions, while a generic copy-to-clipboard hook and a cross-fade animation hook improve general UI polish.

assets/js/hooks · high confidence

New product creation interface with device extension configuration

Users can now create new products through a dedicated UI that includes a form for the product name and a section to enable or disable device extensions. The interface lists available extensions with descriptions, allowing administrators to configure isolated channels for device behaviors and messaging at the product level before finalizing creation.

_lib/nerves\_hub\web/live/products · high confidence

New product insights, error reporting, and health profile management

This change introduces three new LiveView pages to the product settings and insights area. The Insights page now displays fleet health metrics, including a firmware version distribution donut chart, device connection history graphs (supporting 24-hour, 14-day, and 4-week periods), and lists of devices with flapping connections or health status. A new Error Reports section allows users to view, filter, and manage error groups (resolve, mute, reopen) with detailed occurrence data and affected device counts. Additionally, a new Health Profiles page enables configuration of device health metrics, allowing users to define warning and alert thresholds for specific platforms and metrics.

_lib/nerves\_hub\web/live/product · high confidence

New request-handling plugs for health checks, uploads, and session management

This change introduces a suite of new Plug modules in the web layer to handle specific request behaviors. The \/status/alive\ health check now verifies database connectivity, returning 200 or 500 based on the result. Local file uploads are now supported via new \FileUpload\ and \StaticUploads\ plugs, which serve files from configured local paths when enabled. Session handling includes a new \PruneDuplicateSessionCookie\ plug to resolve login issues caused by stale host-only cookies during domain migrations, and a \Timezone\ plug to persist the user's browser timezone in the session for consistent rendering. Additional plugs include \Attack\ for IP-based rate limiting, \Device\ for device-specific 404 handling, \DeviceEndpointRedirect\ for invalid endpoint redirection, \ServerAuth\ for Oban Web access control, \SetLocale\ for language negotiation, and \OpenApiSpec\ for standardized API documentation output.

_lib/nerves\_hub\web/plugs · high confidence

Support for AtomVM, ESP-IDF, and RAUC firmware formats

The update tool now supports three additional firmware formats alongside the existing fwup support. It can process AtomVM packbeam archives (.avm) for BEAM-based applications, ESP-IDF application images (.bin) for Espressif chips (supporting delta updates via detools), and RAUC bundles (.raucb) for Linux-based devices using A/B slot updates. Each format has its own metadata extraction, signature verification, and delta capabilities defined in new implementation modules.

_lib/nerves\_hub/firmwares/update\tool · high confidence

Support scripts can now be written in Elixir or Shell with syntax validation

The system now supports creating and running support scripts in either Elixir or Shell. When an Elixir script is saved, the server validates its syntax and provides specific error messages (including line and column details) to help authors fix issues before execution. Shell scripts are stored as-is without server-side syntax checking. Scripts are executed on devices via a new runner that sends the code to the device channel, with a 30-second timeout and a fallback mechanism to capture output from the console if the device is offline or incompatible.

_lib/nerves\hub/scripts · high confidence

API

Comprehensive OpenAPI schema definitions for API resources

This change introduces formal OpenAPI (Swagger) schema definitions for the NervesHub API, covering core resources such as Devices, Deployment Groups, Firmwares, CA and Device Certificates, Signing Keys, and Network Identities. It also adds schemas for organizational entities (Orgs, Users, Products), support scripts, CLI authentication sessions, and Iroh endpoints. These schemas standardize request and response structures, document validation rules (e.g., required fields, enums, patterns), and provide examples, thereby improving API documentation and client generation accuracy.

_lib/nerves\_hub\web/controllers/api/schemas · high confidence

Architecture

Introduce NervesHubWeb module as the central web interface entrypoint

The application now uses the new \NervesHubWeb\ module to standardize the setup for controllers, LiveViews, and live components. This change centralizes common imports and behaviors, such as verified routes, Gettext localization, and specific helper functions (e.g., breadcrumbs, date formatting, and authorization), ensuring consistent configuration across all web-facing components.

lib · high confidence

Behavioural changes

Account management overhaul with granular permissions and custom UI preferences

The accounts module has been restructured to support a three-tier role system (admin, manage, view) for organization members, allowing more precise access control. Users can now customize the columns displayed in device and deployment group lists via new display preferences. The user identity model has shifted from username to name, and invitations now require a specific role assignment. Additionally, account removal has been hardened to safely soft-delete related data (devices, products, orgs) while permanently purging firmwares and associated keys, and email notifications are now processed asynchronously via background jobs to prevent request blocking.

_lib/nerves\hub/accounts · high confidence

Adoption of Phoenix LiveView and modern frontend tooling

The JavaScript assets have been restructured to support Phoenix LiveView, introducing a new \app.js\ entry point that registers a comprehensive set of hooks (including charts, command palette, and map visualizations) and handles timezone persistence. This change is accompanied by the addition of ESLint and Prettier configuration files to standardize code quality and formatting, as well as a new module for integrating the Stoplight OpenAPI UI.

assets/js · high confidence

Archive model enforces SemVer validation and safe deletion

The new Archive model introduces strict validation for archive versions, requiring them to be valid semantic versions to ensure correct ordering. It also implements a safer deletion mechanism that prevents the removal of archives currently referenced by deployment releases, replacing previous crashes caused by foreign key violations with a clear error message.

_lib/nerves\hub/archives · high confidence

Audit log schema enforces description length limits

The audit log schema now includes a 500-character limit on the description field. If a description exceeds this length, it is automatically truncated with an ellipsis rather than causing a validation error or crash, ensuring that long or unbounded input values do not disrupt the application flow.

_lib/nerves\_hub/audit\logs · high confidence

Background workers for device cleanup, firmware deltas, and audit logs

This change introduces a set of new Oban background workers in the \lib/nerves\_hub/workers\ directory to offload specific maintenance and processing tasks. Users will benefit from automated cleanup of stale device connections and soft-deleted devices, as well as the background generation and timeout handling of firmware deltas. Additionally, the system now supports configurable audit log data retention policies per organization, with scheduled truncation jobs ensuring logs are kept for the specified duration. Email delivery is also moved to a background job to improve web request performance.

_lib/nerves\hub/workers · high confidence

Centralized audit logging templates for deployments, devices, and products

Audit log descriptions for managed deployments, device operations, and product scripts are now generated through dedicated template modules. This change standardizes how audit entries are formatted for actions such as creating or deleting deployment groups, tracking firmware update attempts and failures, managing device reboots, and handling script or error group lifecycle events, ensuring consistent and detailed logging across these core management features.

_lib/nerves\_hub/audit\logs/templates · high confidence

Database migration scripts and seed data for NervesHub

The repository now includes scripts to populate the database with initial data and migrate existing records. \priv/repo/seeds.exs\ creates a default root user and sample organizations (NervesTeam, Personal) with products, firmwares, and devices. Two new migration scripts, \add\_org\_id.exs\ and \add\_audit\_log\_descriptions.exs\, backfill missing \org\_id\ fields on Firmwares, DeviceCertificates, Deployments, and AuditLogs, and generate descriptions for AuditLog entries that previously lacked them.

priv/repo · high confidence

Database schema migrations for core entities and features

This update introduces a comprehensive set of database migrations that establish and evolve the application's data model. It creates foundational tables for tenants, users, devices, firmwares, and deployments, while introducing organizational structures (orgs) and role-based access control (admin, write, read, delete) for both organizations and products. The schema supports device management through unique identifiers, certificate tracking (user, device, and CA certificates with JITP support), and firmware lifecycle management including delta updates, patching, and versioning. Additional features include soft-delete capabilities across core entities, audit logging with detailed change tracking, usage metrics, and background job processing via Oban.

priv/repo/migrations · high confidence

Establishes modern development tooling and code quality standards

The repository now enforces a consistent code style and quality baseline through the integration of Credo, Dialyzer, and CSpell. A new \.credo.exs\ configuration enables strict checks for consistency, readability, and refactoring opportunities, while \.dialyzer\_ignore.exs\ manages known type warnings. Spell checking is configured via \.cspell.json\ with a curated dictionary of technical terms. The Elixir formatter is extended with the Quokka plugin for automatic struct and alias sorting, and the LiveView HTML formatter. These tools are documented in the new \AGENTS.md\ guide, which also outlines the repository layout, runtime architecture, and local development setup using mise for version management.

(repo-wide) · high confidence

Firmware and Archive pages adopt new sidebar layout and UI components

The firmware and archive listing and detail pages have been rewritten to use the new \NervesHubWeb.Layouts.sidebar\ layout, replacing the previous structure. This update introduces a consistent visual design with updated Tailwind CSS classes, adds a visual drop-overlay when dragging files onto the firmware list, and implements a 'Show deleted' toggle on the firmware list to view retired versions. The archive pages now feature a cleaner two-column detail view for general info and metadata, while firmware details include a tooltip explaining deletion blockers and a notice for deleted firmware that preserves history without allowing downloads.

_lib/nerves\_hub\_web/live/firmware\templates · high confidence

Firmware management refactored to support multiple update tools and granular delta tracking

The firmware module has been restructured to support multiple firmware update tools (such as fwup, ESP-IDF, and RAUC) simultaneously, allowing different devices to use different update mechanisms within the same organization. This change introduces tool-agnostic metadata storage, requiring specific version constraints for both full and delta updates per tool. Additionally, the system now tracks firmware delta generation in greater detail with a dedicated schema and implements a targeted PubSub mechanism for real-time delta status updates, improving efficiency and user visibility during the delta build process.

_lib/nerves\hub/firmwares · high confidence

Introduction of a comprehensive light theme with unified design tokens

The application now supports a light theme alongside the existing dark mode, allowing users to switch their visual preference. This change introduces a centralized design system in the main CSS file, defining semantic tokens for surfaces, text, and interactive states that automatically invert or adjust between dark and light contexts. It also establishes fixed layout dimensions for the sidebar and topbar, ensuring consistent spacing regardless of the active theme.

assets/css · high confidence

Migrate Account, Archives, and Firmware management to Phoenix LiveView

The Account settings, Archives, and Firmware management interfaces have been rewritten as Phoenix LiveView components. This migration enables real-time interactivity, such as instant feedback on account updates and password changes, live sorting and pagination for Archives and Firmware lists, and immediate UI updates during file uploads without full page reloads. Users benefit from a more responsive experience when managing API tokens, viewing product archives, and handling firmware versions.

_lib/nerves\_hub\web/live · high confidence

New ClickHouse tables for device telemetry and history

The analytics repository now includes new ClickHouse tables to store device log lines, connection history, messages, error reports, metrics, alarms, and health status. These tables support richer device insights by capturing detailed telemetry data, including IP addresses, firmware versions, and error contexts, with specific retention policies (30 days for metrics and errors, 90 days for alarms and health history).

_priv/analytics\repo · high confidence

New Organizations page with onboarding and live device counts

The Organizations list view has been replaced with a new LiveView interface. For new users, an onboarding flow automatically prompts them to create their first organization and product. Existing users see a list of their organizations, each displaying real-time online and offline device counts that update via PubSub. The view also highlights pinned devices at the top and provides direct links to create new organizations or products.

_lib/nerves\_hub\web/live/orgs · high confidence

New account management UI with access token controls

The account settings interface has been redesigned to consolidate personal info, password changes, and access token management into a single view. Users can now update their name and email, change their password, and generate or delete access tokens directly from the account page. A new dedicated delete-account flow requires email confirmation to permanently remove the account and all associated data.

_lib/nerves\_hub\_web/live/account\templates · high confidence

New account management and authentication UI templates

This change introduces a new set of Heex templates for the account and authentication flows, including pages for accepting organization invitations, creating new accounts, email confirmation, password reset requests and completions, and handling OAuth (Google) login failures. Users will now see a refreshed, consistent interface for signing up, resetting passwords, and managing organization invites, with specific messaging for scenarios like wrong-account mismatches or failed Google authentication.

_lib/nerves\_hub\_web/controllers/account\html · high confidence

New account, session, and authentication controllers

The web UI now uses dedicated controllers for account management, user sessions, and OAuth flows. Users can register for new accounts (if open), accept organization invitations, and manage their profiles via the new AccountController. The SessionController handles login, logout, email confirmation, and password resets, while the OAuthController integrates external identity providers. Additionally, the HomeController now redirects visitors to the organizations list, and the ProductController provides a streaming CSV export of devices filtered by user permissions.

_lib/nerves\_hub\web/controllers · high confidence

New application layout system with theme switching and collapsible sidebar

The application's layout structure has been replaced with a new set of HEEx templates (root, sidebar, no\_sidebar, and auth) that introduce a collapsible sidebar navigation, a user menu with account/logout links, and a built-in theme selector supporting light, dark, and system preferences. The root layout now handles theme initialization via JavaScript to prevent flash, while the sidebar layout integrates a command palette and an organization/product picker, providing a refreshed and more responsive user interface.

_lib/nerves\_hub\web/components/layouts · high confidence

New authentication, API specification, and upload handling components

The web layer introduces a new \NervesHubWeb.Auth\ module that manages user sessions, including a configurable remember-me cookie and an allow-listed external redirect mechanism to prevent open-redirect vulnerabilities. A new \NervesHubWeb.ApiSpec\ module generates the OpenAPI 3.0 specification for the REST API, while \NervesHubWeb.BrieflyUploadWriter\ implements a durable, chunked upload writer for LiveView that uses the \Briefly\ library to manage temporary file lifecycles. Additionally, \NervesHubWeb.DynamicConfigMultipart\ enables runtime configuration of maximum file upload sizes, and \NervesHubWeb.RateLimitPubSub\ synchronizes IP-based rate limiting across web nodes using the \Group\ library.

_lib/nerves\_hub\web · high confidence

New device management UI with advanced filtering and bulk actions

The device index and detail pages have been replaced with a new interface that supports advanced query filtering, bulk tag management, and customizable column sorting. The device list now includes a dedicated filter sidebar, an advanced search field, and the ability to select and modify multiple devices at once. Individual device pages feature a tabbed layout for details, health, firmware history, console, and logs, along with real-time connection status indicators and firmware update progress tracking.

_lib/nerves\_hub\web/live/devices · high confidence

New sidebar-based UI for organization user management

The organization user management interface has been redesigned with a new sidebar layout, introducing dedicated pages for listing active members and outstanding invites, inviting new users, and editing existing member roles. Users can now view a table of active memberships showing names, emails, roles, and join dates, manage outstanding invitations by copying or resending links, and update user roles through a dedicated edit form, all within a consistent sidebar-wrapped view.

_lib/nerves\_hub\_web/live/org/user\templates · high confidence

New view modules and error helpers introduced

The application now includes dedicated view modules for the home page, layout, and products, alongside a new error helper module. The layout view provides utility functions to humanize file sizes (bytes to KB/MB/GB/TB) and format timestamps (e.g., '2 hours ago'), while the error helpers module standardizes how form validation errors are displayed and translated using Gettext. These changes support the underlying UI structure and error reporting mechanisms.

_lib/nerves\_hub\web/views · high confidence

Redesigned Certificate Authority management interface

The Certificate Authority settings pages (list, new, edit, and show) have been completely rewritten to use the new sidebar layout and Tailwind CSS styling. The new list view displays serial numbers, descriptions, device counts, and expiration dates in a table. The new and edit forms now include a toggleable Just In Time Provisioning (JITP) section that allows users to configure device descriptions, tags, and target products. The show page provides a detailed view of the CA's status, expiration settings, and a breakdown of devices by product, with updated breadcrumbs and action buttons.

_lib/nerves\_hub\_web/live/org/certificate\_authority\templates · high confidence

Redesigned error pages with new UI theme

The 400, 404, and 500 error pages have been updated to use a new visual design that aligns with the application's light theme. These pages now feature a centered layout with a product logo, specific error messages for each status code, and a link to report issues on GitHub, replacing the previous error page styling.

_lib/nerves\_hub\_web/controllers/error\html · high confidence

Refactor API authentication and resource loading to use Phoenix Scopes

The API plug layer has been restructured to centralize authentication and resource fetching using a new \current\_scope\ concept. A new \FetchCurrentUser\ plug extracts the API token from the Authorization header and assigns a \Scope\ struct to the connection, replacing previous authentication mechanisms. Resource-specific plugs (Device, Product) now load their respective entities using this scope, and a \RequireAuthenticatedUser\ plug enforces login by raising an \UnauthorizedError\ if no user is present in the scope. This change standardizes how the API identifies users and loads associated data, improving consistency across endpoints.

_lib/nerves\_hub\web/plugs/api · high confidence

Refactored PubSub event dispatching for deployment orchestrator and device updates

The system now uses dedicated event modules (\DeploymentOrchestratorEvents\ and \DeviceEvents\) to encapsulate and broadcast state changes. For the deployment orchestrator, device lifecycle events (such as online status, updates, and additions) are dispatched via a targeted \:group\-based PubSub mechanism, allowing consumers to subscribe to specific deployment groups. For devices, the \DeviceEvents\ module centralizes broadcasts for actions like firmware updates, deployments, reboots, and identification, ensuring that payloads (including firmware URLs, checksums, and telemetry data) are consistently formatted and sent to the correct device channels.

_lib/nerves\hub/events · high confidence

Refactored device connection handling into a transport-independent contract

The device link logic has been extracted into a new, transport-independent module structure (\NervesHub.DeviceLink\) that separates the connection protocol from the platform's internal state. This change introduces a dispatcher pattern allowing device connections to be handled either locally or remotely, enabling scenarios where the connection socket is held by a node without database access while the platform logic runs elsewhere. The refactor includes new modules for authentication (supporting both X.509 certificates and HMAC shared secrets), device info structs, session management, and peer verification, ensuring that device authentication and session state are managed consistently regardless of where the connection terminates.

_lib/nerves\_hub/device\link · high confidence

Refactored release migration tasks with configurable options and analytics exclusion

The release migration logic has been restructured into a new \NervesHub.Release.Tasks\ module that supports passing specific options (such as stopping at a certain migration version) to individual repositories. The migration process now explicitly starts required applications (logger, ssl, postgrex, ecto\_sql) before running, and automatically excludes the analytics repository from migrations if analytics are disabled in the configuration.

_lib/nerves\hub/release · high confidence

Refreshed email templates with consistent branding and plain-text support

All system emails (welcome, account confirmation, password reset, Google login reminders, and organization invite/notify messages) now use a unified MJML-based design featuring the NervesHub logo header, a standardized layout, and a configurable support footer. Each template also includes a plain-text version, ensuring that recipients who cannot view HTML still receive the full message content.

_lib/nerves\hub/emails · high confidence

Support Scripts management moved to LiveViews with new UI

The Support Scripts interface has been rebuilt as Phoenix LiveViews, replacing the previous implementation. This change introduces a new listing page with search, sorting, and pagination, alongside dedicated views for creating and editing scripts. Users can now manage scripts with features such as tagging, language selection (Elixir or Shell), and deletion, all within a unified sidebar layout that displays script metadata like the last editor and update time.

_lib/nerves\_hub\_web/live/support\scripts · high confidence

Updated release environment and VM configuration for distributed Erlang and memory optimization

The release environment script (rel/env.sh.eex) now supports the POD\_IP environment variable alongside PRIVATE\_IP for distributed Erlang node naming, ensuring compatibility with containerized deployments. Additionally, the VM arguments (rel/vm.args.eex) explicitly set the binary and heap allocator carrier sizes (+MBlmbcs and +MHlmbcs) to 512KB to reduce resident set size (RSS) memory usage, while deferring scheduler count configuration to runtime environment variables to optimize resource consumption across shared web and device node images.

rel · high confidence

Test coverage

Added browser tests for Deployment Groups index and creation; Added browser tests for Organization settings pages; Added browser tests for Product Insights, Health Profiles, and Settings; Added browser tests for account, firmware, and UI features; Added browser tests for deployment group show page tabs and workflows; Added browser tests for device show tabs; Added browser tests for the Organizations index and creation flows; Added comprehensive test coverage for device and console channels; Added controller tests for account, authentication, and resource management; Added fwup test fixtures for delta update scenarios; Added integration tests for the new UI devices index page; Added test coverage for DeviceLink dispatcher, peer verification, and serialization; Added test coverage for NervesHub Web plugs; Added test coverage for authentication, session, and upload logic; Added test coverage for background workers; Added test coverage for new firmware update tool backends; Added test coverage for the NervesHub Extensions subsystem; Added test coverage for the accounts module; Added test coverage for web components; Added test fixtures for ESP-IDF application image signing; Added test fixtures for RAUC bundle signing; Added test to verify database foreign key indexes; Added tests for API error JSON rendering; Added tests for API user authentication and token handling; Added tests for CA Certificate CSR validation and JITP changeset behavior; Added tests for audit log description truncation and device template error handling; Added tests for client IP resolution and timezone validation helpers; Added tests for configurable health profiles and product PubSub; Added tests for device list performance, subscriptions, and UI interactions; Added tests for device update event payloads; Added tests for firmware upload file metadata generation; Added tests for scripts runner, filtering, and validation; Added tests for telemetry customizations handling; Added tests for the advanced device query system; Added tests for web UI error pages and layout helper functions; Comprehensive test support infrastructure for device management and firmware formats; Expanded API test coverage for device management, deployments, and certificates; Expanded test coverage for core platform components; Expanded test coverage for device management and analytics components; Expanded test coverage for firmware upload, validation, and tool gating; Test suite configuration and mocking setup; Tests for configurable presigned download host; Updated SSL test fixtures for nerves\_hub\_ca v0.5.0.

Dependencies

Initial dependency manifests for assets and core application

The project now includes its first \assets/package.json\ and \mix.exs\ files, establishing the baseline dependency sets for the frontend and backend respectively. The frontend manifest defines JavaScript dependencies including Mapbox GL, Chart.js, and Phoenix LiveView client libraries, while the backend manifest specifies the Elixir application structure, target Elixir version (1.20.0), and core libraries such as Phoenix, Ecto, Oban, and Bandit.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 51.

Lenses

  • Code Health 65
  • Architecture 92
  • Maturity 62
  • Readiness 42
  • Security 58
  • Accessibility 54

Changes since last survey

  • 300 commits — 280 feature/other, 20 fixes

By area

  • (root) — 101 commits
  • lib/nerves_hub_web — 78 commits
  • lib/nerves_hub — 77 commits
  • test/nerves_hub — 8 commits
  • test/nerves_hub_web — 8 commits
  • assets/js — 7 commits
  • config/config.exs — 4 commits
  • priv/repo — 4 commits
  • assets/css — 3 commits
  • (repo) — 2 commits
  • config/runtime.exs — 2 commits
  • priv/static — 2 commits
  • .github/actions — 1 commit
  • .github/workflows — 1 commit
  • assets/package-lock.json — 1 commit
  • test/support — 1 commit

Notable commits

  • fix: Advanced search fixes (#2837)
  • fix: Context cleanup — Phase 1: dead code, spec fixes, auth hardening (#2873)
  • fix: Docker build fixes (#2758)
  • fix: Fix 9 of the 12 npm Dependabot alerts (#3046)
  • fix: Fix a flaky Briefly cleanup assertion in the delta builder test (#3022)
  • fix: Fix concurrency issue with CLI Session cache (#2779)
  • fix: Fix deployemnt group activity pagination (#2848)
  • fix: Fix device events stream never forwarding update progress (#2902)
  • fix: Fix error handling when updating network interface (#2844)
  • fix: Fix flaky DeviceLink test (#2842)
  • fix: Fix flaky test (#3004)
  • fix: Fix flaky tests (#2997)
  • fix: Fix four deletions that crashed on foreign keys (#3031)
  • fix: Fix how the location setting menu button is hidden (#2986)
  • fix: Fix several paths where memory grows and is never released (#2942)
  • fix: Fix some incorrect OpenAPI specs (#2739)
  • fix: Fix the Sentry source code path config key (#2937)
  • fix: Fix the device list x-overflow issues, and make the headers sticky (#2773)
  • fix: Fix two page re overflow, and adjust the bar chart top label (#2780)
  • fix: Upgrade hackney to 4.7 to fix four security advisories (#3045)
  • …and 280 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

nerves-hub/nerves_hub_web was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 18 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 7e6c7e6742324c754217b988594a0d4c370da5be — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-5d04157a340d.