stritzinger/braidnet
67.1
Adequate · 17 September 2026
1.4k
lines of production code
Erlang
primary language
1
measurement over time
What this system is
Braidnet is an OTP application designed to spawn and orchestrate Docker containers, with specific support for deployment on Fly.io. It provides a secured REST API for managing container instances, including launching, listing, and executing remote procedures, while handling TLS certificate provisioning and mutual authentication for inter-node communication.
Features
Automated TLS certificate provisioning via Braidcert
The pre-start hook now automatically provisions TLS certificates for the service using the Braidcert infrastructure. During startup, the script retrieves the CA certificate, generates a private key, and creates a Certificate Signing Request (CSR) that includes Subject Alternative Names for the Fly.io machine ID, the app's fly.dev domain, and localhost. This CSR is submitted to the Braidcert service to obtain a signed certificate, ensuring secure TLS termination without manual certificate management.
hooks · high confidence
Initial release with Fly.io deployment support and Docker-in-Docker orchestration
This entry marks the initial release (v0.1.0/v0.2.0) of braidnet, an OTP application for spawning and orchestrating containers. The release introduces native support for deploying on Fly.io, configured via new \fly.toml\ and \fly-testing.toml\ files. The application now runs inside a Docker-in-Docker (DinD) environment using the \vfs\ storage driver to ensure compatibility with Fly.io's filesystem, and utilizes Erlang 27. It provides a REST API for launching and listing containers, secured by TLS distribution via Braidcert, and includes configuration for HTTP bearer authentication and Docker image trust verification.
(repo-wide) · high confidence
Introduce REST API, TLS distribution, and Fly.io support
Braidnet now exposes a new REST API (accessible via /api/:method) for managing container instances, listing nodes, retrieving logs, and executing remote procedure calls, secured by a Bearer token. The system supports TLS distribution via Braidcert, automatically generating and managing certificates for containers, and includes a health check endpoint for Fly.io deployments. Additionally, the orchestrator now detects the Fly.io environment to handle private networking and machine discovery, and Docker image trust checks can be disabled via configuration.
src · high confidence
Security
Enforce mutual TLS authentication for node distribution
The release configuration now mandates mutual TLS (mTLS) for Erlang distribution connections. Both server and client sides are configured to verify peer certificates using the Braidnet CA, and the server side specifically enforces that a peer certificate is present via the new \fail\_if\_no\_peer\_cert\ option. This ensures that only authenticated nodes can establish distribution links, significantly hardening inter-node communication security.
priv · high confidence
Behavioural changes
Configurable container runtime and environment variable support
The application now supports environment variable substitution in its main configuration file (renamed from sys.config to container.config.src), allowing users to dynamically set the REST API token, Braidcert URL and key, API port, and Docker trust settings without editing the source code. A new container-specific VM arguments file (container.vm.args.src) has been added to configure Erlang distribution options, including TLS-based distribution and specific port ranges for inter-node communication. Additionally, a dedicated shell configuration file (shell.config) provides a default setup for local development with dummy credentials and debug logging.
config · high confidence
Updated CA certificate and certificate generation configuration
The certificate infrastructure has been updated with a new configuration file (braidnet.cfg) for generating end-entity server certificates, which now omits organizational details like company name and location from the distinguished name. Additionally, the root CA certificate file (stritzinger\_grisp\_CA.pem) has been replaced with a new version containing the Stritzinger Root CA and the GriSP2 CA chain, ensuring the system uses the current trusted certificate authority for TLS distribution.
certs · high confidence
Test coverage
Added Common Test suite for Braidnet REST API and Fly.io integration
Added a new Common Test suite (\braidnet\_rest\_SUITE\) that validates the Braidnet REST API by launching containers on Fly.io, verifying the list endpoint returns expected node status, and testing RPC functionality between nodes. This includes new test utilities (\braidnet\_test\_utils\) to retrieve Fly.io machine names and restart the application, along with a test configuration file defining the connection parameters for the \braidnet-testing\ Fly.io app.
test · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Baseline
- First survey — no prior run to compare against. CAI 67.
Lenses
- Code Health 99
- Architecture 69
- Maturity 60
- Readiness 62
- Security 96
- Event Sourcing 100
Changes since last survey
- 77 commits — 66 feature/other, 11 fixes
By area
- (root) — 31 commits
- src/braidnet_braidnode_api.erl — 10 commits
- config/container.config.src — 5 commits
- src/braidnet.erl — 5 commits
- src/braidnet_container.erl — 4 commits
- (repo) — 3 commits
- certs/cfg — 2 commits
- priv/prod.ssl_dist_opts.rel — 2 commits
- src/braidnet_app.erl — 2 commits
- src/braidnet_orchestrator.erl — 2 commits
- test/braidnet_rest_SUITE.erl — 2 commits
- .github/workflows — 1 commit
- certs/stritzinger_grisp_CA.pem — 1 commit
- config/container.vm.args.src — 1 commit
- config/shell.config — 1 commit
- config/vm.args.src — 1 commit
- doc/architecture.png — 1 commit
- doc/braid_rest_api.md — 1 commit
- hooks/pre_start — 1 commit
- src/braidnet_cluster.erl — 1 commit
Notable commits
- fix: Fix Certificates loading into container
- fix: Fix braidnet version in wm.args
- fix: Fix certs mounting for fly.io
- fix: Fix dialyzer complaints
- fix: Fix envs in container
- fix: Fix local rest suite
- fix: Fix rest test suite
- fix: Fix string split bug
- fix: Fix sup tree and improve docker trust check (#10)
- fix: Merge pull request #14 from stritzinger/sylane/braid-fixes
- fix: Partially fix names()
- change: Add 'destroy' API call
- change: Add API to get container certificate
- change: Add RPC, dynamic dist ports and improve container start&stop (#7)
- change: Add comment in dockerfile
- change: Add diagrams
- change: Add fail_if_no_peer_cert to server side ssl dist options
- change: Add instances API method
- change: Add localhost to braidnet cert names
- change: Add logging and container disconnection detection (#1)
- …and 57 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
stritzinger/braidnet was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 17 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 43c473815598d2a783686db1b66e56d3b25257ef — the exact code this score is about.
- Scored under rubric-2026.09.13 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-d1ef6c0bd534.