SteveLTN/https-portal
57.0
Adequate · 26 September 2026
650
lines of production code
Ruby
primary language
4
measurements over time
What this system is
Features
Added certificate management scripts for container setup and renewal
New executable scripts have been added to the container's usr/bin directory to handle certificate lifecycle management. The setup, reconfig, and renew\_certs scripts now delegate to a Ruby-based CertsManager, enabling automated certificate setup, reconfiguration, and renewal processes within the container environment.
_fs\overlay/usr · high confidence
Added example Nginx configuration templates for HTTP and HTTPS
Added example Nginx configuration templates for HTTP and HTTPS. The new files provide a redirect from HTTP to HTTPS and configure SSL/TLS settings, including protocol versions, ciphers, and certificate paths.
_examples/custom\config/nginx-conf · high confidence
Default welcome page and static site support
A default welcome page is now served at the root of the web server, displaying a message about HTTPS and Let's Encrypt certificates. The page content varies based on the domain's stage (production, staging, or local), with specific instructions for each. Additionally, the system now supports serving static sites by mounting a custom www root directory at the specified path, allowing users to replace the default page with their own static files.
_fs\overlay/var · high confidence
Initial project structure and build configuration
The repository is initialized with a complete build and development environment. The Dockerfile establishes the runtime by installing dependencies (Python 3, Ruby, cron, logrotate, etc.) and downloading specific versions of s6-overlay, docker-gen, and acme-tiny. The Makefile is added to support multi-architecture Docker image builds using buildx and QEMU. Additionally, configuration files for Ruby testing (.rspec, .ruby-version) and file exclusion patterns (.dockerignore, .gitignore, .ignore) are introduced to support local development and CI workflows.
(repo-wide) · high confidence
Introduce domain model with multi-stage, multi-upstream, and access-restriction support
The system now supports configuring domains across production, staging, and local environments, each with their own certificate paths and upstreams. Users can define multiple upstreams per domain, enable HTTP basic authentication, and restrict access by IP address. The domain model also handles redirection targets and provides debug information for each domain configuration.
_fs\_overlay/opt/certs\manager/models · high confidence
New container initialization scripts for welcome message, setup, and Docker status
Added three new initialization scripts in the container's entrypoint: a welcome message script that displays the current HTTPS-Portal version (v1.25.5), a setup script that executes the main setup process with dynamic environment variables, and a Docker status check that disables the docker-gen service if the Docker socket is unavailable.
_fs\overlay/etc/cont-init.d · high confidence
Behavioural changes
Added built-in log rotation for Nginx
A new logrotate configuration file for Nginx has been added to the filesystem overlay. This enables automatic daily rotation of Nginx access and error logs, retaining 30 days of history with compression. The rotation process uses the 'nginx -s reopen' command to ensure logs are properly rotated without service interruption.
_fs\overlay/etc/logrotate.d · high confidence
Configure automated certificate renewal with randomized scheduling and environment support
A new crontab template is introduced to automate certificate renewal. The schedule is randomized to distribute load, and the renewal command is updated to use s6-overlay's environment variables via /command/with-contenv, ensuring the renewal process has access to the correct runtime configuration.
_fs\overlay/var/lib · high confidence
Container shutdown on critical service failure
The container now stops entirely if the crond or docker-gen services fail. Previously, these services could fail without affecting the overall container state; now, their failure triggers a graceful shutdown via s6-overlay's finish scripts.
_fs\overlay/etc/services.d/10-docker-gen · high confidence
Enable live environment variable hot-reloading
The dynamic-env service now monitors /var/lib/https-portal/dynamic-env for changes to uppercase environment files and automatically applies them using s6-envdir, allowing configuration updates without restarting the container.
_fs\overlay/etc/services.d/30-dynamic-env · medium confidence
Improved multi-port container routing in docker-gen
The template for generating domain routing rules has been updated to correctly handle containers exposing multiple ports. Previously, the system failed to parse the domain list when multiple ports were exposed. The new logic iterates through all exposed ports, using the VIRTUAL\_PORT environment variable to select the appropriate upstream address, falling back to port 80 if not specified. This ensures that containers with multiple exposed ports are correctly routed based on the configured virtual host.
_fs\overlay/etc/docker-gen · medium confidence
Introduce configurable Nginx configuration templates
The Nginx configuration is now generated from new ERB templates (nginx.conf.erb, default.conf.erb, default.ssl.conf.erb) that support environment-variable-driven settings. Users can now control HTTP/2, IPv6 listening, gzip compression, proxy timeouts, access restrictions, basic authentication, HSTS headers, and custom global/server blocks via environment variables. The templates also allow per-domain configuration blocks and support for multiple upstreams, WebSocket proxying, and static site serving.
_fs\overlay/var/lib/nginx-conf · medium confidence
Refactored certificate management into modular components
The certificate management logic has been refactored from a single file into a modular structure, introducing separate classes and modules for ACME signing, Nginx configuration, OpenSSL operations, and environment configuration. This change improves code maintainability and allows for more granular control over certificate renewal, signing, and Nginx reload processes.
_fs\_overlay/opt/certs\manager · high confidence
Test coverage
Added RSpec feature tests for HTTPS-PORTAL configurations; Added test compositions for local, auto-discovery, linked containers, minimal setup, and static site scenarios; Added tests for domain parsing and configuration; Initialize RSpec test suite configuration.
Dependencies
Added RSpec testing framework
The project now includes a Gemfile and Gemfile.lock that define RSpec version 3.10.0 as a dependency, enabling the use of RSpec for writing and running tests.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 44 → 57 (+13.4)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 100 → 100 (+0.0)
- Architecture 69 → 69 (+0.0)
- Maturity 65 → 65 (+0.0)
- Readiness 12 → 39 (+27.0)
- Security 86 → 94 (+7.3)
Resolved (7)
- Coverage not measured — test suite did not build
- Dimension evaluation failed
- High: security finding (details withheld)
- Low: security finding (details withheld)
- No exposed public API
- No tests found
- Test reliability not included
New (4)
- High IaC: WD-DOCKER-0001 (Dockerfile)
- Medium IaC: WD-DOCKER-0003 (Dockerfile)
- No ADRs found
- Outdated: rspec
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
SteveLTN/https-portal was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 26 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 0e72267b57d54dec723de1228dc370cb43f30e74 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-7c1cb6328e11.