openclosed-org/axum-harness
66.8
Adequate · 6 October 2026
34.4k
lines of production code
Rust
primary language
4
measurements over time
What this system is
This system is an older backend platform that has recently undergone significant architectural shifts, notably migrating its data persistence layer to SurrealDB and restructuring its repository to support modular, commercial capabilities for AI and bot channels. It operates as a distributed service ecosystem featuring a Backend-for-Frontend (BFF), counter services, and worker-based event projection, with a strong emphasis on security hardening and operational reliability through rigorous audit logging and idempotency checks. The codebase is currently focused on stabilizing this new structure by enforcing strict security contracts, fixing checkpoint corruption issues, and establishing robust local development and deployment profiles.
Narrated so far: 2026-05-09 – 2026-08-04; history before 2026-05-09 not narrated yet.
How it got here
Week 19 of 2026 (4 May – 10 May) — not summarised yet
- SurrealDB adapter switches to external HTTP transport and typed query operations — The SurrealDB data adapter now connects to an external SurrealDB server via HTTP (using the \reqwest\ client) instead of the embedded Rust SDK, which simplifies deployment for local, single-VPS, and k3s environments. To enforce safer, tenant-scoped data access, raw SQL queries have been replaced with a typed \TenantQueryOperation\ API (Create, Select, Update, Delete, etc.) that validates identifiers and prevents injection, while admin operations remain available via an explicit \SurrealAdminMarker\. The tenant-service and user-service repository implementations have been updated to use these new typed operations and the new HTTP-based port, ensuring consistent multi-tenant isolation across both services. ((repo-wide))
- BFF audit logging and SurrealDB support — The Web BFF now records audit events for authorization checks, counter mutations, and tenant resolution, capturing details like actor, tenant, and request IDs while redacting sensitive metadata. Additionally, the BFF can now be configured to use SurrealDB as the data store instead of Turso, requiring new configuration options for the SurrealDB connection. (servers/bff/web-bff)
- Added tests for BFF audit logging and SurrealDB integration — Added end-to-end tests for the BFF service to verify that audit events correctly redact sensitive idempotency keys and capture request IDs and tenant IDs, and that tenant resolution failures are logged with the appropriate denied outcome. Additionally, added a new integration test to verify that the BFF correctly wires and initializes tenant, counter, and user services when using the SurrealDB store provider. (servers)
- Counter service adds SurrealDB support and enhances idempotency evidence — The counter service now supports SurrealDB as a storage backend alongside the existing libsql/Turso adapter, enabling users to choose their preferred database engine. Additionally, the idempotency tracking mechanism has been strengthened: the system now records a SHA-256 fingerprint of the request (including tenant, resource, and operation) and a digest of the response value and version. This provides verifiable evidence for audit trails and ensures that idempotency keys are scoped correctly to specific tenants and operations, preventing cross-tenant interference. (services/counter-service)
- Fixes checkpoint corruption handling and adds replay tests — The worker runtime now safely handles corrupted checkpoint files by falling back to an initial value instead of failing, and the projector explicitly propagates checkpoint errors rather than silently ignoring them. Additionally, comprehensive tests were added to verify that the projector can correctly rebuild counter projections from the event outbox history. (packages/worker-runtime, workers/projector)
- Extracts framework-neutral security and authorization contracts — This change refactors the security layer by extracting framework-neutral contracts into dedicated packages. In \packages/authz\, it introduces \AuthzCheck\ and \AuthzDecision\ types to standardize authorization check contexts and outcomes, making the authorization interface independent of specific web frameworks. In \packages/security\, it establishes new crates for shared contracts: \audit\ defines the \AuditEvent\ shape, \AuditOutcome\, and an \AuditSink\ trait with an in-memory implementation and metadata redaction; \context\ defines \SecurityContext\, \ExecutionContext\, and \TenantContext\ for identity and request metadata; and \runtime-policy\ defines \RuntimeProfile\ and \RuntimeSecurityPolicy\ for validating deployment environments. These changes provide stable, reusable interfaces for security-related data and operations across the system. (packages/authz, packages/security)
- Expanded local verification gates and SurrealDB integration testing — Developers can now run comprehensive local quality gates using the new \justfiles/gates.just\ and \justfiles/k3d.just\ profiles, which automate Kubernetes smoke tests (via K3d/Colima) and verify SurrealDB persistence and service readiness. The \verify.just\ file has been updated to include a new \validate-publish-intent\ gate for Phase 0 evidence, and the backend verification lanes now explicitly test the \web-bff\ and \storage\_surrealdb\ components with specific feature flags (\web-bff/surrealdb\, \storage\_surrealdb/http\), alongside new targets for local SurrealDB integration and SDK testing. (justfiles)
- Harden OIDC JWT verification to reject non-RS256 algorithms — The OIDC verifier in \packages/authn/oidc-verifier\ now strictly enforces the RS256 algorithm for JWTs, rejecting tokens signed with other algorithms (such as HS256 or none) to prevent signature confusion attacks. The verification logic explicitly sets the allowed algorithm list to RS256 and adds a check to reject any token with a different algorithm header. Additionally, the \exp\ (expiration) claim is now explicitly parsed into the \IdTokenClaims\ struct to ensure expiration is handled correctly during validation. Negative tests have been added to verify that tokens with disallowed algorithms, unknown keys, wrong issuers, or wrong audiences are rejected. (packages/authn)
- New publish intent validation gate and replay checkpoint fix — The repo-tools now include a new \validate-publish-intent\ command and gate that checks workspace packages to ensure they explicitly declare \publish=false\ (or are in an empty allowlist), enforcing a Phase 0 policy against unintended registry publishing. This validation is integrated into the standard gate workflow via both \just\ and \cargo run\ invocations. Additionally, the \verify\_replay\ command for workers has been fixed to correctly enforce that checkpoints are advanced only after event processing, by relaxing the regex pattern to allow whitespace between \process\_event\ and \checkpoint().advance\. (tools/repo-tools)
- Outbox relay preserves checkpoint safety for failed entries — The outbox-relay worker now ensures that the processing checkpoint is only advanced for entries that have been successfully published and recorded in the database. Previously, the checkpoint was advanced for all polled entries regardless of outcome, risking data loss if a publish failure occurred. The new logic tracks successfully completed entries and passes this list to the poller, which then marks only those specific IDs as processed. This prevents the system from forgetting about entries that failed to publish, ensuring they are retried in subsequent cycles. A new test confirms that failed entries are not checkpointed and remain available for re-processing. (workers/outbox-relay)
- Local K3d profile and Phase 0 evidence gates — Developers can now run a local Kubernetes cluster using K3d (via Colima) and execute new governance evidence gates. This change introduces local cluster profiles and Justfile recipes (such as \smoke-local-k3d\ and \gate-local-k3d\) to manage the K3d environment, while also adding Phase 0 evidence gates to the verification workflow to support package classification and security auditing. ((repo-wide))
- Add security contracts and update dependencies — This update introduces three new internal security packages—security-audit, security-context, and security-runtime-policy—and wires them into the web-bff service. It also adds hex and sha2 dependencies to the counter-service, adds base64 and mockito dev-dependencies to the oidc-verifier, and updates the surrealdb dependency to use specific features (protocol-ws, rustls) while disabling default features. Additionally, several packages are marked as non-publishable, and the axum-harness version is bumped to 0.5.0. ((dependencies))
- Adopts workspace-hack and updates dependencies — The project now uses a centralized \workspace-hack\ crate (version 0.1) to manage shared dependencies across all packages, replacing individual direct dependencies in many modules. The \workspace-hack\ package itself has been updated to include new dependencies like \bumpalo\, \flate2\, \hashbrown\ (v0.12), \once\_cell\, \reqwest\ (v0.13), \thiserror\ (v2), \toml\_parser\, and \winnow\, while removing \anstream\, \anstyle\, \env\_filter\, \env\_logger\, \figment\, \futures\, \jiff\, \jiff-static\, and \utoipa\. This change consolidates dependency management and updates several underlying libraries. ((dependencies))
- Binary-first deployment profiles and SOPS-backed transient env-file export — Deployment guidance now centers on three profiles (systemd-binary, optional Podman, and future k3s-ha) with a binary-first approach: runtime hosts consume prebuilt binaries or images and do not compile Rust code. New just recipes (release-web-bff, package-web-bff, smoke-web-bff-binary) and sccache-aware build entrypoints support local/CI binary packaging and smoke testing. Podman resource containers are now opt-in via presets (lite, surrealdb, standard, full) controlled by just podman-resources-up/down/status/logs, and storage cleanup commands are added. Secrets are injected via SOPS + age using just sops-run for local processes and a new just sops-export-env command that writes transient 0600 host env-files for systemd or Podman; .env files are explicitly excluded from the backend deployment reference path. The web-bff Dockerfile is updated to use distroless/cc (due to dynamic Rust linking), copies additional workspace crates, uses cache mounts, and aligns environment variable names (APP\_SERVER\_HOST/PORT, APP\_DATABASE\_URL). Additionally, web-bff CORS configuration now accepts both comma-separated strings and list-shaped input for APP\_CORS\_ALLOWED\_ORIGINS. ((repo-wide))
Week 20 of 2026 (11 May – 17 May) — Commercial capability seams
3 changes.
The project introduced commercial capability seams for AI and bot channels, establishing the core feature logic. This work was supported by a workspace restructuring that removed the Tauri desktop app and organized new capability packages. To ensure reliability, end-to-end tests were added to verify the new commercial integration points.
Week 21 of 2026 (18 May – 24 May) — Repository tooling and structure restructure
3 changes.
This period focused on restructuring the repository's tooling infrastructure, specifically by splitting harness commands and introducing new validation and audit capabilities. The team reorganized justfiles into a structured taxonomy with added validation gates to improve consistency. Additionally, the overall repository structure was clarified, and new agent-focused verification commands were introduced to enhance operational oversight.
August 2026 — Security regression in security module
1 change.
A security regression was introduced in the security module, potentially exposing the application to vulnerabilities. This change requires immediate attention to restore the intended security posture.
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Baseline
- First survey — no prior run to compare against. CAI 67.
Lenses
- Code Health 87
- Architecture 94
- Maturity 74
- Readiness 62
- Security 60
- Domain Modelling 100
- Event-Driven 80
- Event Sourcing 100
- Performance 100
Changes since last survey
- 300 commits — 219 feature/other, 81 fixes
By area
- (root) — 49 commits
- .planning/phases — 28 commits
- apps/client — 28 commits
- .github/workflows — 26 commits
- servers/bff — 18 commits
- servers/api — 12 commits
- e2e-desktop-playwright/tests — 8 commits
- platform/model — 7 commits
- apps/web — 6 commits
- services/counter-service — 6 commits
- packages/adapters — 5 commits
- scripts/e2e — 5 commits
- .planning/ROADMAP.md — 4 commits
- docs/architecture — 4 commits
- docs/operations — 4 commits
- packages/contracts — 4 commits
- platform/validators — 4 commits
- tools/repo-tools — 4 commits
- workers/outbox-relay — 4 commits
- .agents/skills — 3 commits
Notable commits
- fix: chore(turso): fix embedded/remote adapter sync and DDL
- fix: chore: remove stale tests and fix flaky outbox-relay poll test
- fix: ci: add timeout-minutes to all workflow jobs, fix rustup hang in quality-gate
- fix: ci: fix all backend CI/gate failures — hakari, workflow syntax, platform generator, golden baselines
- fix: ci: fix backend CI/gate — stale packages, YAML comments, path filters, security audit
- fix: ci: fix backend-experiments clippy — remove invalid --exclude flag
- fix: ci: fix indexer-worker test module order, replace broken k6 action with apt install
- fix: ci: fix k6 install and make load test non-blocking (needs Turso Cloud DB)
- fix: ci: fix k6 install — download binary directly instead of apt with broken GPG keyserver
- fix: ci: fix load-test by setting APP_DATABASE_URL=:memory: for BFF startup
- fix: fix(10.3-01): replace top-level Tauri event import in auth store
- fix: fix(10.3-01): replace top-level Tauri imports in agent IPC with safe bridge
- fix: fix(10.3-01): replace top-level Tauri imports in auth IPC with safe bridge
- fix: fix(10.3-01): replace top-level Tauri imports in layout with safe bridge
- fix: fix(10.3-02): add /api prefix to admin route
- fix: fix(10.3-02): add /api prefix to agent routes
- fix: fix(10.3-02): add Authorization header to counter fetch calls
- fix: fix(10.3-02): replace CSS custom vars with Tailwind theme tokens
- fix: fix(10.3-03): remove full reload in sendMessage finally block to eliminate flicker
- fix: fix(10.3-03): sort conversations by created_at descending for stable order
- …and 280 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
openclosed-org/axum-harness was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 6 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit c1acef03103bb384b84641d709bd83fa9846dec8 — the exact code this score is about.
- Scored under rubric-2026.10.1 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-1f9c535fa862.