Skip to content
CAI
Software that uses CAICheck a score

Netflix/zuul

45.9

Weak · 25 September 2026

26.4k

lines of production code

Java

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a high-performance, Netty-based HTTP gateway and reverse proxy engine designed for handling complex request routing, load balancing, and protocol translation. It provides a robust filter lifecycle for processing inbound and outbound traffic, supporting HTTP/1.1, HTTP/2, WebSocket, and Server-Sent Events with built-in concurrency control, throttling, and security features like TLS PSK and header validation. The platform includes comprehensive observability through structured logging, detailed request tracing, and granular metrics, alongside pluggable service discovery and dynamic filter management.

How it got here

2012–2018 — Zuul 2.0 Netty migration and core refactoring

46 changes.

This period marks the foundational development of Zuul 2.0, characterized by a major migration from legacy Java and RxJava to a modern Netty-based architecture with JDK 21 and CompletableFuture. The work involved a comprehensive refactoring of the core filter engine, introducing typed attributes, strict concurrency controls, and a new lifecycle management system. Additionally, the project established robust observability through the CurrentPassport tracing system and added support for real-time push notifications via WebSocket and SSE.

2019–2020 — test coverage expansion and annotation processing

22 changes.

This period focused on significantly expanding unit test coverage across zuul-core components, including server handlers, SSL, HTTP/2, and connection pooling, while migrating test dependencies to JUnit 5. It also introduced an annotation processor in zuul-processor to automate filter discovery and added new connection monitoring metrics to track active connections and setup latency.

2021–2026 — test coverage expansion and security features

20 changes.

This period focused on significantly expanding unit and integration test coverage across core Netty handlers, timeout management, and connection lifecycle logic. It also introduced new capabilities including a pluggable service discovery abstraction, TLS Pre-Shared Key (PSK) server support, and event-based connection draining for graceful shutdowns.

Features

Add passport stamping filters for inbound and outbound requests

New filter classes (InboundPassportStampingFilter, OutboundPassportStampingFilter, and their base PassportStampingFilter) have been added to the zuul-core passport package. These filters automatically add a specified PassportState to the request context during processing, with separate implementations for inbound and outbound traffic, enabling consistent tracking of request lifecycle stages.

zuul-core/src/main/java/com/netflix/zuul/filters/passport · high confidence

Added HttpRequestBuilder for unit testing

A new HttpRequestBuilder utility class has been added to the zuul-core module to simplify the creation of HTTP request messages in unit tests. This builder allows test code to easily configure request attributes such as headers, query parameters, HTTP method, URI, and port, providing sensible defaults (like HTTPS and HTTP/1.1) while allowing specific overrides before building the final HttpRequestMessage.

zuul-core/src/main/java/com/netflix/zuul/message/util · high confidence

Initial Zuul 2.0 sample server with SSE and WebSocket push support

The \zuul-sample\ module now provides a complete, working bootstrap for Zuul 2.0, replacing the previous WebSockets-only sample with a flexible HTTP server that supports multiple protocols including HTTP, HTTP/2, Mutual TLS, and push notifications via both WebSocket and Server-Sent Events (SSE). The sample demonstrates how to configure the Netty-based server startup, register inbound and outbound filters, and integrate with Eureka for service discovery, while also showcasing the new async filter execution model using \CompletableFuture\ instead of RxJava.

zuul-sample/src/main/java/com/netflix/zuul/sample · high confidence

Initial implementation of the CurrentPassport request tracing system

This change introduces the core \CurrentPassport\ class and supporting types (\PassportState\, \PassportItem\, \StartAndEnd\) in the \zuul-core\ module, establishing the foundation for request lifecycle tracing. The implementation provides a thread-safe mechanism to record and query state transitions (such as header reception, content sending, and filter execution) using a history deque protected by a reentrant lock, while also integrating with Netty channels and session contexts to attach and retrieve passport data.

zuul-core/src/main/java/com/netflix/zuul/passport · high confidence

Initial project scaffolding and license configuration

The repository has been initialized with core project files, including the Apache License 2.0, a README with usage and release instructions, and an OSSMETADATA file marking the project lifecycle as active. The build environment is configured with a .netflixoss file specifying JDK 8, a new dependencies.lock file pinning versions for JMH and OpenRewrite, and updated Gradle wrapper scripts (gradlew/gradlew.bat) that now enforce the Apache 2.0 license header. Additionally, IDE-specific configuration files (.classpath, .project) have been removed in favor of a comprehensive .gitignore.

(repo-wide) · high confidence

Initial sample configuration and SSL assets for Zuul 2.0

The sample application now includes the foundational resource files required to run the Zuul 2.0 core, including \application.properties\ for Eureka registration and load balancing, \application-benchmark.properties\ to disable safety throttles for performance testing, and \log4j2.xml\ for logging. Additionally, sample SSL certificates and keys are provided in the \ssl/\ directory to support secure communication scenarios.

zuul-sample/src/main/resources · high confidence

Introduce Netty-based origin implementation with concurrency protection

The \zuul-core/src/main/java/com/netflix/zuul/origins\ package now includes a new \BasicNettyOrigin\ implementation and its manager, \BasicNettyOriginManager\, which handle outbound connections using Netty. This change introduces built-in concurrency protection for origins, allowing administrators to configure maximum concurrent request limits via properties like \zuul.origin.\<clientName\>.concurrency.max.requests\. When these limits are exceeded, requests are rejected with an \OriginConcurrencyExceededException\ (HTTP 503), and metrics are exposed via Spectator gauges and counters to track concurrent requests and rejections. The package also defines the core \Origin\, \NettyOrigin\, and \OriginName\ interfaces and classes that structure how origins are identified, configured, and managed.

zuul-core/src/main/java/com/netflix/zuul/origins · high confidence

Introduce TLS PSK server support in Zuul core

Added a new package \com.netflix.zuul.netty.server.psk\ containing the core components for TLS Pre-Shared Key (PSK) authentication on the server side. This includes \TlsPskHandler\ and \TlsPskDecoder\ for managing the Netty channel pipeline, \ZuulPskServer\ for handling the TLS handshake logic using Bouncy Castle, and \ExternalTlsPskProvider\ to allow external injection of PSK secrets. The implementation supports TLS 1.3 with specific cipher suites (TLS\_AES\_128\_GCM\_SHA256, TLS\_AES\_256\_GCM\_SHA384) and exposes metrics via Spectator for handshake timing.

zuul-core/src/main/java/com/netflix/zuul/netty/server/psk · high confidence

Introduce Zuul Push Server with WebSocket and SSE support

This change adds the core server-side components for a new push notification capability in Zuul, enabling backend services to push messages to connected clients via WebSocket or Server-Sent Events (SSE). The implementation includes a \PushConnectionRegistry\ to track client sessions, a \PushMessageSender\ handler to receive POST requests from internal backends (with secure token verification and rate limiting), and protocol-specific handlers (\PushRegistrationHandler\, \PushAuthHandler\) to manage client authentication, keep-alive pings, and connection lifecycle. This allows Zuul to act as a persistent connection broker for real-time updates.

zuul-core/src/main/java/com/netflix/zuul/netty/server/push · high confidence

Introduce dynamic HTTP/2 frame logging

Added a new DynamicHttp2FrameLogger component that extends Netty's Http2FrameLogger to provide configurable, dynamic logging of HTTP/2 frames. This logger allows runtime control over which frame types (such as SETTINGS, HEADERS, PING, etc.) are logged via a dynamic property, enabling users to adjust HTTP/2 debug verbosity without restarting the service.

zuul-core/src/main/java/com/netflix/netty/common/http2 · high confidence

Introduce pluggable resolver abstraction for service discovery

The \zuul-discovery\ module now exposes a new \Resolver\ interface and \ResolverListener\ that decouple service discovery from the underlying Ribbon load balancer. This change introduces a \DynamicServerResolver\ implementation that wraps the Ribbon load balancer, allowing the load balancer instance to be injected rather than created via reflection, which makes the discovery mechanism more pluggable. The new \ResolverResult\ interface and \DiscoveryResult\ class provide a standardized way to access server details (host, port, metadata) and load balancer statistics, including a sentinel \EMPTY\ result for handling empty discovery responses. Additionally, a \getServers()\ method is added to the resolver to allow read-only access to the entire server pool, supporting use cases like per-server discovery metadata inspection.

zuul-discovery/src/main · high confidence

Introduces Netty lifecycle, timeout, and exception-handling utilities

This change adds a suite of new handler classes to the Netty common layer to improve connection management and observability. It introduces lifecycle handlers (HttpLifecycleChannelHandler, HttpServerLifecycleChannelHandler, HttpClientLifecycleChannelHandler) that fire start and complete events for HTTP sessions, including specific handling for 1xx interim responses. It adds a dedicated timeout handler (HttpRequestReadTimeoutHandler) that tracks the time to read the full request body without closing the channel, and a handler (CloseOnIdleStateHandler) to close channels on idle timeouts. Additionally, it adds exception swallows for SSL and HTTP/2 errors to reduce log noise, a utility for ByteBuf leak detection, and a handler to store source/destination addresses on the channel.

zuul-core/src/main/java/com/netflix/netty/common · high confidence

Introduces connection throttling and request rejection utilities

Adds the MaxInboundConnectionsHandler to enforce a global limit on inbound connections, closing new connections that exceed the threshold and firing a throttling event. Introduces RejectionUtils and the RejectionType enum to standardize how malformed or rejected requests are handled, supporting both immediate connection closure and sending HTTP rejection responses with optional custom headers and latency injection. The new RequestRejectedEvent record provides structured details about these rejections for downstream monitoring and logging.

zuul-core/src/main/java/com/netflix/netty/common/throttle · high confidence

Introduction of RequestAttempt and RequestAttempts classes for detailed request tracking

The \zuul-core\ module now includes \RequestAttempt\ and \RequestAttempts\ classes to provide detailed tracking of individual request attempts. \RequestAttempt\ captures metadata such as status, duration, error details, and server information (including IP address, availability zone, and region) for each retry or connection attempt. \RequestAttempts\ manages a collection of these attempts, allowing them to be serialized to JSON and stored in the session context for observability and debugging purposes.

zuul-core/src/main/java/com/netflix/zuul/niws · high confidence

Introduction of ServerStatusManager for instance status management

A new ServerStatusManager component has been added to the Netty common status module, providing a centralized way to manage the local server's instance status. This class, annotated as a singleton and utilizing Jakarta EE dependency injection, wraps the ApplicationInfoManager to expose a localStatus method, allowing the application to programmatically update its status within the service discovery registry.

zuul-core/src/main/java/com/netflix/netty/common/status · high confidence

Introduction of centralized Zuul HTTP header constants

A new \ZuulHeaders\ utility class has been added to define standard HTTP headers (such as \X-Forwarded-For\, \Host\, and \Transfer-Encoding\) and internal \X-Zuul\ headers (such as \X-Zuul-Status\ and \X-Zuul-Filter-Executions\) as public constants. This centralizes header string definitions to prevent typos and ensures consistent usage across the Zuul core, with a private constructor to prevent instantiation.

zuul-core/src/main/java/com/netflix/zuul/constants · high confidence

Introduction of structured status category tracking with reason codes

The \zuul-core\ status package now provides a structured way to track request outcomes using \StatusCategory\ and \StatusCategoryGroup\ interfaces, along with a \StatusCategoryUtils\ helper. This change introduces specific categories (such as \SUCCESS\, \FAILURE\_LOCAL\, \FAILURE\_ORIGIN\) that include human-readable reason strings, allowing users to distinguish between different types of failures (e.g., client timeouts vs. origin connectivity issues) and successes (e.g., standard proxy vs. 404s). The utility class ensures these categories and their associated reasons are consistently stored and retrieved from the session context.

zuul-core/src/main/java/com/netflix/zuul/stats/status · high confidence

New EndpointLifecycle interface and MissingEndpointHandlingFilter

The \ProxyEndpoint\ now implements the new \EndpointLifecycle\ interface, which defines a \finish(boolean error)\ method to ensure proper resource cleanup (such as releasing connections and streams) when a request completes or encounters an error. Additionally, a new \MissingEndpointHandlingFilter\ has been introduced to handle cases where no endpoint is configured, returning a 500 error response and logging the issue.

zuul-core/src/main/java/com/netflix/zuul/filters/endpoint · high confidence

New GZipResponseFilter for configurable response compression

A new GZipResponseFilter has been added to the common filters package to handle gzip compression of HTTP response bodies. This filter operates as an outbound sync filter and is designed to run late in the chain to ensure final encoded body length is considered. It compresses responses based on configurable criteria: content type (including text/event-stream), minimum body size (default 860 bytes), and client acceptance headers. The filter is enabled by default but can be disabled via the 'zuul.response.gzip.filter.enabled' property, and the set of gzippable content types can be customized via 'zuul.gzip.contenttypes'.

zuul-core/src/main/java/com/netflix/zuul/filters/common · high confidence

New Passport state tracking and logging handlers for HTTP connections

Added a new set of Netty channel handlers in the \zuul.netty.insights\ package to track detailed request lifecycle states and improve observability. \PassportStateHttpServerHandler\ and \PassportStateHttpServerHandler\ (client/origin) now record specific passport states for HTTP headers and content transmission, while \PassportStateOriginHandler\ tracks origin connection lifecycle events. \PassportStateListener\ ensures failure states are captured only once to avoid noise. \ServerStateHandler\ integrates connection metrics (total, closed, errors) with passport state tracking, and \PassportLoggingHandler\ provides structured logging of passport data, incomplete proxy sessions, and request/response processing times against configurable thresholds.

zuul-core/src/main/java/com/netflix/zuul/netty/insights · high confidence

New connection monitoring counters and timers

Zuul now provides built-in metrics for tracking active connections and connection setup latency. The new ConnCounter class exposes an active connection count via Spectator PolledMeters, allowing users to monitor current load. The ConnTimer class records the duration of connection establishment phases, emitting timer metrics for each step (e.g., 'accept-handshake') and optionally high-resolution percentile data if the 'zuul.conn.precise\_timing' property is enabled. These metrics are attached to Netty channels and include standard connection dimensions for filtering.

zuul-core/src/main/java/com/netflix/zuul/monitoring · high confidence

New per-event-loop and HTTP/2 metrics instrumentation

The metrics package now includes new classes to provide finer-grained observability: \EventLoopGroupMetrics\ and \PerEventLoopMetricsChannelHandler\ track current connections and in-flight HTTP requests specifically per Netty event loop, while \Http2MetricsChannelHandlers\ adds inbound and outbound counters for HTTP/2 frames and errors. Additionally, \HttpBodySizeRecordingChannelHandler\ now supports both inbound and outbound body size tracking, and \InstrumentedResourceLeakDetector\ exposes Netty resource leak counts as Spectator gauges.

zuul-core/src/main/java/com/netflix/netty/common/metrics · high confidence

New sample filter implementations for health, routing, and response handling

The sample application now includes concrete implementations for key request lifecycle stages: a Healthcheck endpoint that returns a 200 status for liveness probes, a Routes inbound filter that directs /healthcheck requests to the health endpoint and all other traffic to a proxy, a SampleServiceFilter demonstrating asynchronous external service calls via CompletableFuture, and a ZuulResponseFilter that appends diagnostic headers (such as status, proxy attempts, and instance ID) to outgoing responses.

zuul-sample/src/main/java/com/netflix/zuul/sample/filters · high confidence

New stats monitoring classes for error and route status codes

Added new classes in the stats package to support monitoring: ErrorStatsData for counting errors by route and cause, RouteStatusCodeMonitor for counting requests by route and status code, and the NamedCount interface used by these monitors. These components integrate with Spectator's PolledMeter to expose metrics for error and route status tracking.

zuul-core/src/main/java/com/netflix/zuul/stats · high confidence

Sample push notification handlers for SSE and WebSocket protocols

The sample application now includes concrete implementations for server-sent events (SSE) and WebSocket push channels. This adds a cookie-based authentication handler, a message sender initializer, and protocol-specific channel initializers and client handlers that enable the sample to accept and manage push connections using these two streaming protocols.

zuul-sample/src/main/java/com/netflix/zuul/sample/push · high confidence

Removals

Removal of legacy Eclipse project files and Java source code

The template-client module has removed its Eclipse-specific configuration files (.classpath, .project, and .settings) along with the core Java source files (TalkClient, Conversation, and Sentence). This cleanup eliminates the legacy IDE project structure and the original client implementation code from the repository.

template-client · high confidence

Removal of legacy template-server REST endpoints and configuration

The template-server module has been removed, eliminating the legacy REST API endpoints (such as /talk/greeting and /talk/farewell) and its associated deployment configuration (web.xml, Eclipse project files). Users relying on these specific template endpoints will no longer have access to them.

template-server · high confidence

Behavioural changes

Event-based connection draining replaces direct channel closure

Connection lifecycle management in Zuul has been refactored to use an event-driven model for graceful shutdown and expiry. Instead of closing channels directly, expiry and shutdown signals now fire structured events (ConnectionCloseEvent) that are handled by protocol-specific close handlers. This introduces jittered delays for HTTP/2 shutdowns to prevent thundering herds, ensures HTTP/1.1 connections wait for in-flight responses to complete before closing, and provides detailed metrics for connection close triggers and reasons.

zuul-core/src/main/java/com/netflix/netty/common/close · high confidence

HTTP filter base classes and sync endpoint body-waiting behavior

This change introduces new abstract base classes for HTTP filters in the \zuul-core\ module: \HttpInboundFilter\, \HttpInboundSyncFilter\, \HttpOutboundFilter\, and \HttpOutboundSyncFilter\, which simplify filter implementation by extending base filter classes and defining specific filter types (INBOUND, OUTBOUND). Additionally, \HttpSyncEndpoint\ is updated to conditionally wait for the complete request body (LastContent) before responding, controlled by the \zuul.endpoint.sync.wait\_for\_lastcontent\ property, to prevent potential HTTP state corruption when the request body is not fully received.

zuul-core/src/main/java/com/netflix/zuul/filters/http · high confidence

HTTP/1.1 request framing enforcement and stricter request validation

Zuul now enforces HTTP/1.1 message framing rules to prevent request smuggling by rejecting requests with ambiguous framing, such as those containing both Transfer-Encoding and Content-Length headers, multiple Content-Length headers, or invalid Content-Length values. Additionally, the server now validates HTTP request headers and rejects malformed requests at the decoder level, ensuring that invalid URIs and other decode failures result in immediate connection closure or a 400 Bad Request response rather than being passed up the filter chain.

zuul-core/src/main/java/com/netflix/zuul/netty/server · high confidence

HTTP/2 connection and stream handling improvements

This change introduces several enhancements to the HTTP/2 implementation in Zuul. It adds an Http2ConnectionErrorHandler to log and track connection-level errors, improving observability. The Http2ContentLengthEnforcingHandler now validates that request content-length headers match the actual body, rejecting mismatches to prevent protocol errors. Additionally, the Http2StreamHeaderCleaner strips internal 'x-http2-' headers from requests to avoid confusion, and the Http2ResetFrameHandler ensures proper request cancellation when reset frames are received. These changes collectively improve the robustness, security, and debugging capabilities of HTTP/2 traffic handling.

zuul-core/src/main/java/com/netflix/zuul/netty/server/http2 · high confidence

Introduce configurable access logging with request/response body sizes and URI length limits

The access log now includes the request and response body sizes in bytes, providing visibility into data transfer volumes. Additionally, the logged URI is truncated to a configurable maximum length (controlled by the \zuul.access.log.uri.length.limit\ property) to prevent excessively long log lines. The log format also captures the local server port and includes configurable request and response headers (such as \x-forwarded-for\ and \user-agent\), with the remote IP extracted from the source address attribute.

zuul-core/src/main/java/com/netflix/netty/common/accesslog · high confidence

Introduces configurable HTTP/2 channel parameters

This change adds a new configuration layer for Netty channel settings, specifically exposing HTTP/2 tuning options such as max concurrent streams (default 100), initial window size (default 5MB), graceful shutdown timeouts, and encoder reset frame limits. Users can now adjust these HTTP/2-specific behaviors via the new \CommonChannelConfigKeys\ rather than relying solely on hardcoded defaults.

zuul-core/src/main/java/com/netflix/netty/common/channel · high confidence

Introduces filter constraints and refactors the async filter execution model

The filter execution engine in \zuul-core\ has been refactored to support \FilterConstraints\, allowing filters to declare requirements (such as needing the full request body) that the runtime respects before execution. This change introduces \FilterConstraints\ and \FilterRunner\ interfaces, and updates \BaseZuulFilterRunner\, \ZuulFilterChainRunner\, and \ZuulEndPointRunner\ to manage filter state, handle chunk buffering, and resume filter chains only when constraints are met. Additionally, the implementation switches from RxJava to \CompletableFuture\ for async filter execution, uses \PerfMark\ for lightweight tracing, and ensures response filters are not left waiting for buffered bodies by properly firing completion events.

zuul-core/src/main/java/com/netflix/zuul/netty/filter · high confidence

New HTTP header read timeout and origin timeout management components

This change introduces two new classes in the timeouts package to handle request timing. The new \HttpHeadersTimeoutHandler\ monitors the time taken to read HTTP headers, recording the duration via a percentile timer and closing the connection if the configured timeout is exceeded. Additionally, \OriginTimeoutManager\ centralizes the logic for computing outbound read timeouts by evaluating both origin-level and request-level configurations, selecting the stricter (lower) of the two values while enforcing a maximum upper bound defined by the \zuul.origin.readtimeout.max\ property.

zuul-core/src/main/java/com/netflix/zuul/netty/timeouts · high confidence

New Zuul-to-Netty header conversion and error-mapping utilities

This change introduces new utility classes in the zuul-core/netty package to improve header handling and error reporting. ZuulToNettyHttpHeaders provides a custom HttpHeaders implementation that stores headers in a flat name-value array to avoid per-header allocations during the Zuul-to-Netty handoff, using LinkedHashSet for efficient name iteration. NettyRequestAttemptFactory adds explicit mapping logic to convert Netty-specific exceptions (such as HeaderListSizeException, ReadTimeoutException, and connection resets) into Zuul's OutboundErrorType, ensuring consistent error types for downstream consumers. Supporting utilities include ChannelUtils for detailed channel state logging and SpectatorUtils for standardized metrics creation.

zuul-core/src/main/java/com/netflix/zuul/netty · high confidence

New exception hierarchy for outbound errors and concurrency limits

The \zuul-core\ exception package now includes \ErrorType\ and \OutboundErrorType\ to map specific outbound failures (such as read timeouts, connection errors, and header size limits) to configurable HTTP status codes and status categories. A new \OutboundException\ decorator wraps these types to automatically set the appropriate status code and suppress error-level logging. Additionally, \RequestExpiredException\ and \ZuulFilterConcurrencyExceededException\ have been added to handle request expiration and filter concurrency limit breaches, while \ZuulException\ itself has been updated with constructors that support suppressing stack trace generation to reduce logging overhead.

zuul-core/src/main/java/com/netflix/zuul/exception · high confidence

Refactored HTTP header handling with new Header/HeaderName classes and validation

The \zuul-core\ message package has been restructured to improve header management and security. A new \HeaderName\ class provides immutable, case-insensitive header name handling with normalization, and a \Header\ class encapsulates individual header entries. The \Headers\ collection now supports iteration over \Header\ objects, allows collapsing specific multi-valued headers (such as \content-type\ and \host\), and includes validation to reject invalid characters, addressing potential XSS vulnerabilities. Additionally, \ZuulMessageImpl\ now automatically sets the \Content-Length\ header when the body is modified via \setBody\ or \setBodyAsText\.

zuul-core/src/main/java/com/netflix/zuul/message · high confidence

The HTTP message classes in \zuul-core/src/main/java/com/netflix/zuul/message/http\ have been refactored to improve performance and correctness. A new \Cookies\ class now wraps Netty's \Cookie\ objects, enabling support for cookies with duplicate keys and providing methods like \getNames()\ and \getFirstValue()\. \HttpRequestMessageImpl\ and \HttpResponseMessageImpl\ have been updated to use this new cookie model, with cookie parsing moved to \HttpRequestInfo\ and lazily cached. Additionally, a new \HttpHeaderNames\ class and its backing cache (\HttpHeaderNamesCache\) have been introduced to optimize case-insensitive header lookups by caching \HeaderName\ objects for common HTTP headers (including CORS and X-Forwarded-\* headers). Query parameter parsing in \HttpQueryParams\ now correctly handles key-only parameters (e.g., \key=\) and preserves their trailing equals sign. The \HttpRequestMessageImpl\ also includes performance optimizations for lazy-caching expensive operations on the original inbound request instance.

zuul-core/src/main/java/com/netflix/zuul/message/http · high confidence

Refactored HTTP utility classes and introduced Gzipper

The \zuul-core\ utility package has been reorganized into four new classes: \Gzipper\, \HttpUtils\, \ProxyUtils\, and \VipUtils\. \Gzipper\ extracts the GZIP compression logic previously embedded in filters into a reusable component. \HttpUtils\ consolidates HTTP helper methods, including a security-focused \stripMaliciousHeaderChars\ method to prevent header injection, IP extraction from \X-Forwarded-For\ headers, and content encoding checks. \ProxyUtils\ centralizes the logic for adding and managing \X-Forwarded-\*\ headers, introducing a configurable property to control whether these headers are overwritten or preserved. \VipUtils\ provides utilities for parsing VIP addresses, deprecating the old \extractAppNameFromVIP\ in favor of \extractUntrustedAppNameFromVIP\.

zuul-core/src/main/java/com/netflix/zuul/util · high confidence

Refactored SSL context creation with configurable TLS 1.3 and named groups

The SSL handling in \zuul-core\ has been restructured into a new \BaseSslContextFactory\ and \ClientSslContextFactory\ hierarchy. This change introduces support for configuring TLS named groups (e.g., x25519, secp256r1) for OpenSSL contexts and adds a dynamic property (\com.netflix.zuul.netty.ssl.enable\_tls13\) to allow clients to opt into TLS 1.3. Additionally, the new implementation exposes OpenSsl session statistics as Spectator metrics for better observability of SSL handshake performance.

zuul-core/src/main/java/com/netflix/zuul/netty/ssl · high confidence

Refactored SessionContext with type-safe keys and configurable initialization

The SessionContext in zuul-core has been refactored to use a new type-safe Key\<T\> mechanism for storing and retrieving context data, replacing the previous string-keyed map approach to improve type safety and performance. This change introduces CommonContextKeys to define strongly-typed keys for common attributes like status categories, origin details, and body size providers. Additionally, the initial capacity of the SessionContext's internal maps is now configurable via system properties (com.netflix.zuul.context.SessionContext.initialSize and com.netflix.zuul.context.SessionContext.eventProperties.initialSize), allowing users to tune performance characteristics for high-throughput scenarios.

zuul-core/src/main/java/com/netflix/zuul/context · high confidence

Refactored connection pool metrics and timeout handling

The connection pool now uses a dedicated \ConnectionPoolMetrics\ record to consolidate Spectator metrics (counters, gauges, and a \PercentileTimer\ for connection establishment duration) and a new \ClientTimeoutHandler\ to manage read timeouts. This change improves observability by providing granular metrics for connection lifecycle events and ensures timeouts are applied only after the request body is fully written.

zuul-core/src/main/java/com/netflix/zuul/netty/connectionpool · high confidence

Refactored proxy protocol handling and added untrusted header stripping

The proxy protocol pipeline has been restructured into specialized handlers: ElbProxyProtocolChannelHandler now acts as a decision maker that conditionally inserts the HAProxyMessageDecoder and HAProxyMessageChannelHandler, while the latter parses the HAProxy message to populate channel attributes (including custom TLVs) and connection dimensions without passing the message further up the pipeline. Additionally, a new StripUntrustedProxyHeadersHandler has been introduced to remove X-Forwarded-\* and Forwarded headers from HTTP requests when the connection is not trusted, supporting configurable policies (Always, Mutual SSL Auth, Never) and a blacklist for the Host header.

zuul-core/src/main/java/com/netflix/netty/common/proxyprotocol · high confidence

Refined SSL handshake failure detection and enriched handshake metrics

The SSL handshake handler now distinguishes between genuine handshake failures and benign connection closures (such as client disconnects or idle timeouts occurring before the handshake completes), preventing these normal events from being recorded as failures in metrics. Additionally, the handler now captures and exposes more detailed handshake information—including the TLS named group, SNI status, and PSK usage—in both the channel context and Spectator metrics, providing better visibility into connection parameters.

zuul-core/src/main/java/com/netflix/zuul/netty/server/ssl · high confidence

Removal of legacy SpringSource STS Gradle import preferences

The project has removed the legacy SpringSource Tool Suite (STS) Gradle import preference files (com.springsource.sts.gradle.core.import.prefs, com.springsource.sts.gradle.core.prefs, and com.springsource.sts.gradle.refresh.prefs). These files previously configured Eclipse/STS-specific behaviors such as enabling dependency management, linking resources, and defining before/after task hooks for Gradle imports. Their removal indicates a shift away from these specific IDE-integration settings, likely as part of a broader restructure or migration to a different build tooling or IDE configuration standard.

.settings · high confidence

SSL configuration and handshake info now use Builder pattern with expanded TLS details

ServerSslConfig and SslHandshakeInfo now require the Builder pattern for construction, deprecating previous constructors. ServerSslConfig introduces a list-based default cipher configuration and explicit session timeout settings. SslHandshakeInfo now captures additional TLS handshake details including the requested SNI, named group, and PSK identity information, providing more granular visibility into connection security parameters.

zuul-core/src/main/java/com/netflix/netty/common/ssl · high confidence

Zuul Filter discovery via annotation processing

The zuul-processor module now uses a Java annotation processor (FilterProcessor) to automatically discover Zuul Filters. Instead of generating new Java source files, the processor scans for classes annotated with @Filter and aggregates their fully qualified names into a single resource file (META-INF/zuul/allfilters). This resource is updated incrementally to include only new or changed filters, enabling the runtime to load filters without manual configuration or generated code.

zuul-processor/src/main · high confidence

Zuul core refactors: new filter lifecycle, typed attributes, and category constraints

This change introduces several foundational updates to the Zuul core filter engine. It adds a typed, heterogeneous attribute map (Attrs) to replace loose key-value storage, and introduces a FilterCategory enum to classify filters (e.g., routing, access, abuse) with an 'unspecified' default. Filter execution is now governed by a FilterConstraint interface and @Filter annotation attributes (ApplyBefore/ApplyAfter) to declaratively control execution order and conditional skipping. The filter loading architecture is split into DynamicFilterLoader (mutable, runtime) and StaticFilterLoader (immutable, classpath/META-INF), both using a new FilterFactory interface for instantiation. Additionally, filter usage metrics are now published via a pluggable FilterUsageNotifier (with a Basic implementation), and request completion is handled by a configurable RequestCompleteHandler.

zuul-core/src/main/java/com/netflix/zuul · high confidence

Zuul filter concurrency protection and sync/async execution model

The filter execution model in zuul-core now includes built-in concurrency protection for async filters, allowing them to reject requests when a configurable limit is reached to prevent overload. A new FilterSyncType enum and SyncZuulFilter interface explicitly distinguish synchronous filters from asynchronous ones, with BaseSyncFilter providing a wrapper for non-blocking apply() methods. Additionally, filter metadata such as type, order, and category are now derived from annotations, and the filter registry supports dynamic mutation.

zuul-core/src/main/java/com/netflix/zuul/filters · high confidence

Test coverage

Added header performance benchmarks; Added test coverage for InstrumentedResourceLeakDetector; Added test for ZuulStatusCategory unique IDs; Added tests for RequestAttempt exception handling; Added tests for ServerSslConfig builder and default ciphers; Added tests for ServerStateHandler connection metrics and passport state; Added tests for connection monitoring metrics; Added tests for filter concurrency limits and chunk processing detection; Added tests for retry body buffering and buffer queue reader index behavior; Added unit tests for Attrs, DynamicFilterLoader, and StaticFilterLoader; Added unit tests for CurrentPassport state tracking and pair finding; Added unit tests for DiscoveryResult and DynamicServerResolver; Added unit tests for GZipResponseFilter behavior; Added unit tests for HTTP headers and origin timeout handling; Added unit tests for HTTP message components; Added unit tests for HTTP/2 connection error handling and content validation; Added unit tests for HttpUtils and VipUtils; Added unit tests for MaxInboundConnectionsHandler; Added unit tests for Netty channel handlers; Added unit tests for Netty request attempt mapping and HTTP header handling; Added unit tests for OriginName authority and equality logic; Added unit tests for PSK TLS handler and server components; Added unit tests for PushConnection rate limiting; Added unit tests for SSL context factory and OpenSSL availability; Added unit tests for SSL handshake info handling; Added unit tests for SessionContext; Added unit tests for Zuul connection pool components; Added unit tests for Zuul filter execution and constraints; Added unit tests for Zuul message headers and implementation; Added unit tests for Zuul server channel handlers and connection lifecycle; Added unit tests for connection close and expiry handlers; Added unit tests for proxy protocol and header stripping handlers; Added unit tests for push connection server components; Added unit tests for stats classes; Added unit tests for the FilterProcessor; New integration tests for connection lifecycle and resource leak detection.

Dependencies

Upgrade Gradle wrapper to version 9.6.1

The Gradle wrapper has been updated from version 1.0-milestone-9 to 9.6.1. This change switches the distribution URL from HTTP to HTTPS, adds a network timeout of 10,000ms, and enables distribution URL validation to ensure the integrity of the downloaded Gradle binary.

gradle · high confidence

Upgrade to Netty 4.2 and JDK 21 with modernized build tooling

This change upgrades the project's core networking library from Netty 4.1 to Netty 4.2.18 and raises the Java language level to JDK 21, requiring users to run the application on Java 21 or later. The build system has been modernized by migrating from legacy Gradle conventions to the Nebula Netflix OSS plugin (v13.0.0) and Gradle 8.0.2, introducing Spotless for code formatting, Error Prone with NullAway for static analysis, and OpenRewrite for automated refactoring. Additionally, the project has migrated logging implementations to Log4j 2 and SLF4J 2, and updated test dependencies to JUnit 5 and Mockito 5.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 45 → 46 (+1.1)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 87 → 91 (+4.6)
  • Architecture 98 → 95 (-3.0)
  • Maturity 52 → 36 (-15.9)
  • Readiness 35 → 35 (+0.1)
  • Security 37 → 60 (+22.9)

Resolved (27)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • Duplicated block (10 lines × 2) (zuul-core/src/main/java/com/netflix/zuul/netty/connectionpool/PerServerConnectionPool.java)
  • Duplicated block (10 lines × 2) (zuul-sample/src/main/java/com/netflix/zuul/sample/SampleServerStartup.java)
  • Duplicated block (12 lines × 2) (zuul-core/src/main/java/com/netflix/zuul/netty/filter/BaseZuulFilterRunner.java)
  • Duplicated block (9 lines × 2) (zuul-core/src/main/java/com/netflix/zuul/message/http/HttpQueryParams.java)
  • Duplicated block (9 lines × 2) (zuul-core/src/main/java/com/netflix/zuul/netty/server/BaseServerStartup.java)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 7 more

New (87)

  • ClassTooLong: HttpRequestMessageImpl (zuul-core/src/main/java/com/netflix/zuul/message/http/HttpRequestMessageImpl.java)
  • Dependency hygiene PARTLY measured — Maven/Gradle declarations read, no dependency graph resolved
  • Documentation: no contributor guidance (README.md)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • Duplicated block (10–12 lines × 2) (zuul-core/src/main/java/com/netflix/zuul/netty/server/ClientRequestReceiver.java)
  • Duplicated block (11 lines × 2) (zuul-sample/src/main/java/com/netflix/zuul/sample/SampleServerStartup.java)
  • Duplicated block (19 lines × 2) (zuul-core/src/main/java/com/netflix/zuul/netty/filter/BaseZuulFilterRunner.java)
  • Duplicated block (24 lines × 2) (zuul-core/src/main/java/com/netflix/zuul/netty/server/BaseServerStartup.java)
  • Duplicated block (5 lines × 2) (zuul-core/src/main/java/com/netflix/zuul/monitoring/ConnCounter.java)
  • Duplicated block (7 lines × 2) (zuul-core/src/main/java/com/netflix/zuul/monitoring/ConnCounter.java)
  • Duplicated block (9 lines × 2) (zuul-core/src/main/java/com/netflix/zuul/message/http/HttpQueryParams.java)
  • HackComment (zuul-core/src/main/java/com/netflix/zuul/niws/RequestAttempt.java)
  • HackComment (zuul-core/src/main/java/com/netflix/zuul/niws/RequestAttempt.java)
  • High secret: WD-SECRET-0004 (zuul-sample/src/main/resources/ssl/truststore.jks)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 67 more

Changes since last survey

  • 12 commits — 12 feature/other, 0 fixes

By area

  • zuul-core/src — 6 commits
  • .github/workflows — 3 commits
  • (root) — 2 commits
  • zuul-integration-test/src — 1 commit

Notable commits

  • change: Add method for case insensitive query param lookup (#2224)
  • change: Avoid per-header allocation in Zuul-to-Netty handoffs
  • change: Match query param names verbatim in HttpQueryParams.get (#2213)
  • change: Restrict the headers that are collapsed (#2210)
  • change: Switch ConnCounter to rely on PolledMeters (#2206)
  • change: Updating Netty to version 4.2.18 (#2214)
  • change: Use LinkedHashSet and better align set with DefaultHttpHeaders conversion flow
  • change: Use retainedDuplicate when buffering the last content chunk (#2211)
  • change: build(deps): bump actions/setup-java from 5 to 6 (#2209)
  • change: build(deps): bump actions/stale from 10 to 11 (#2203)
  • change: build(deps): bump gradle/actions from 6 to 6.2.0 (#2204)
  • change: build(deps): bump org.openrewrite.rewrite from 7.12.1 to 7.37.0 (#2194)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

Netflix/zuul was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 25 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 139a7ddbd6fe0a0899c88f49ddf7abb53ae18fba — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-f917f263222d.