traderepublic/Cilicon
51.3
Adequate · 1 October 2026
2.3k
lines of production code
Swift
primary language
2
measurements over time
What this system is
Cilicon is a macOS application that provisions and manages virtual machines for CI/CD runners, supporting GitHub Actions, GitLab, and Buildkite. It handles VM lifecycle operations by downloading pre-built images via an OCI client and configuring runners through direct SSH execution. The system provides a user interface for monitoring SSH logs and managing VM configurations, replacing older manual installation and file-based setup methods.
How it got here
2022 — Cilicon 2.0 major release
9 changes.
This period focused on the major release of Cilicon 2.0, which overhauled the application's architecture by replacing legacy installation and provisioning methods with direct OCI image handling and SSH-based execution. The update introduced a redesigned UI with live SSH logging, expanded support for multiple CI/CD providers like GitLab and Buildkite, and removed obsolete components such as the standalone installer and manual setup scripts.
2023–2025 — OCI support and CI provisioner expansion
6 changes.
This period focused on expanding Cilicon's capabilities by introducing an OCI registry client and a Layer V2 downloader with concurrent LZ4 decompression for faster image handling. It also added provisioning support for GitLab Runners and Buildkite Agents, enabling automated setup of CI infrastructure on virtual machines. Additionally, VM configuration storage was consolidated into a single JSON file to improve persistence and network device stability.
Features
Add GitLab Runner provisioning capability
Users can now provision GitLab Runners on virtual machines via the new GitLabRunnerProvisioner. This component handles downloading the runner binary, configuring it via a TOML file or direct registration parameters (token, URL, executor, max builds), and executing the setup commands over SSH.
Cilicon/Provisioner/GitLab Runner · high confidence
Added Buildkite Agent Provisioner
Introduced a new BuildkiteAgentProvisioner component that automates the installation and startup of the Buildkite agent on provisioned virtual machines. This provisioner handles agent registration using a provided token and optional tags, streaming installation output for visibility.
Cilicon/Provisioner/Buildkite Agent · high confidence
Expanded CI/CD provisioner support and configurable VM settings
The configuration system now supports provisioning runners for GitLab and Buildkite in addition to GitHub, allowing users to define specific settings for each provider. Users can also configure liveness probes for GitHub Actions runners to monitor VM health, set custom SSH credentials and retry limits, define pre-run and post-run commands, and specify console devices. Directory mounts can now be configured as read-only, and the VM source path is managed via a new \source\ field with a configurable clone path, replacing the previous \vmBundlePath\ and \editorMode\ settings.
Cilicon/Config · high confidence
Initial OCI registry client support
This change introduces a new Swift-based client for interacting with OCI (Open Container Initiative) registries. It adds model structs for parsing OCI descriptors and manifests, a parser for OCI URL schemes, and a core \OCI\ struct that enables fetching image manifests and pulling blob data. The client handles HTTP authentication, supporting both basic credentials and bearer tokens via the standard WWW-Authenticate challenge-response flow.
Cilicon/OCI · high confidence
Introduce Layer V2 downloader with concurrent LZ4 decompression
The Cilicon downloader now supports OCI image layer format V2, enabling faster downloads through concurrent decompression of multiple layers using LZ4. This change adds a new LayerV2Downloader that pre-allocates the target file size and processes layers in parallel, alongside a new Decompressor component that handles LZ4 decompression directly to disk.
Cilicon/Downloader · high confidence
Major UI overhaul with live SSH logging and new provisioning support
The Cilicon interface has been redesigned to display a scrollable, syntax-highlighted log of SSH output from the virtual machine, replacing the previous static status messages. This change introduces a new \SSHLogger\ and \ANSIParser\ to render terminal colors and styles in the SwiftUI view. Additionally, the application now supports a \ScriptProvisioner\ for executing custom shell scripts during VM setup, allows mounting shared directories as read-only, and adds support for GitLab Runner and Buildkite provisioners alongside the existing GitHub Actions support. The legacy volume-copying feature has been removed in favor of a direct OCI download and local bundle cloning workflow.
Cilicon · high confidence
Removals
Removal of NSSound system sound extensions
The Common module no longer provides the convenience extensions for NSSound that exposed macOS system sounds (such as Basso, Blow, Bottle, Frog, Funk, Glass, Hero, Morse, Ping, Pop, Purr, Sosumi, Submarine, and Tink). Any code relying on these static properties or the associated NSSound.Name constants will need to be updated to use alternative sound handling or define these sounds directly.
Common · high confidence
Removal of legacy GitHub Actions runner setup scripts
The VM Resources directory no longer includes the legacy shell scripts and configuration files used to manually bootstrap a self-hosted GitHub Actions runner. Specifically, the \setup-actions.sh\, \pre-run.sh\, \post-run.sh\, \start.command\, and \IMAGE\_LABELS\ files have been deleted, along with the \README.md\ that documented their placement in the VM bundle. This indicates a shift away from the previous manual runner configuration method, likely in favor of the 'Cilicon 2.0' approach mentioned in the commit history.
VM Resources · high confidence
Removal of macOS Installer application
The macOS installer application has been removed from the product. This change deletes the entire Installer module, including the SwiftUI user interface (ContentView), the core installation logic (Installer.swift), asset catalogs, and entitlements, effectively eliminating the capability to install macOS virtual machines via this standalone tool.
Installer · high confidence
Behavioural changes
Cilicon app renamed and test suite added to Xcode project
The Xcode project has been updated to reflect the renaming of the main application target from 'Cilicon Installer' to 'Cilicon', including the corresponding scheme and build configurations. Additionally, a new 'CiliconTests' target has been added to the project, and the build scheme is now configured to automatically run these tests during the Test action. The project file format has also been upgraded to the latest version.
Cilicon.xcodeproj · high confidence
GitHub Actions provisioner refactored to use JIT configuration and SSH execution
The GitHub Actions provisioner has been rewritten to configure runners via Just-In-Time (JIT) configuration and execute setup commands directly over SSH, replacing the previous file-based approach that wrote tokens and labels to disk. This change introduces a new \GithubService\ that supports both organization and repository-level runner scopes, adds support for custom runner groups and extra labels, and allows the runner name to be configured via the \runnerName\ config property rather than relying solely on the local host name.
Cilicon/Provisioner/GitHub Actions · high confidence
Major update to Cilicon 2.0 with new provisioning and image handling
Cilicon 2.0 introduces significant changes to how virtual machines are managed and provisioned. The application now uses an integrated OCI client to download pre-built CI images (adopting the tart format) instead of relying on user-defined Login Item scripts, and it executes commands directly via SSH. The configuration schema has changed, requiring users to rename \vmBundlePath\ to \source\ and configure SSH credentials for the new direct execution model. Additionally, the README has been updated to reflect these changes, including a warning about SSH reliability on macOS 15.0-15.3.X and instructions for migrating from version 1.0.
(repo-wide) · high confidence
Migrate VM configuration storage from individual files to JSON
Virtual machine configuration data (architecture, OS, hardware model, ECID, and MAC address) is now persisted in a single \config.json\ file within the VM bundle instead of separate \HardwareModel\ and \MachineIdentifier\ files. This change introduces a new \VMConfig\ struct and updates \VMConfigurationHelper\ to read/write this JSON, while \LegacyVMBundle\ provides an \upgrade()\ method to migrate existing VM bundles to the new format. Additionally, the network device configuration now uses the MAC address stored in this config file rather than generating a random one on each boot.
Cilicon/Common · high confidence
Test coverage
Added tests for OCI URL parsing, config decoding, and SSH logging behavior
This change introduces new test coverage for the Cilicon application. It adds tests for parsing OCI URLs, including support for sha256 revisions, and verifies that the configuration decoder correctly handles the new \consoleDevices\ setting. Additionally, it includes tests for the SSH logger to ensure it properly trims whitespace, splits lines, respects maximum log chunk limits by dropping oldest entries, and maintains non-decreasing timestamps.
CiliconTests · high confidence
Dependencies
Updated Swift package dependencies and resolved file format
The project's resolved dependencies have been updated to newer versions of several Swift libraries, including BlueRSA (1.0.201 to 1.0.203), Swift-JWT (4.0.0 to 4.0.2), Swift-Log (1.4.4 to 1.6.4), and Yams (5.0.1 to 5.4.0). New dependencies added to the project include BigInt, swift-asn1, swift-atomics, swift-collections, swift-crypto, swift-nio, swift-nio-ssh, and swift-system. The Package.resolved file has also been upgraded from version 2 to version 3.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 56 → 51 (-4.8)
- Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.
Lenses
- Code Health 99 → 99 (+0.1)
- Architecture 100 → 95 (-5.5)
- Maturity 45 → 45 (+0.0)
- Readiness 50 → 37 (-12.4)
- Security 71 → 71 (+0.0)
Resolved (4)
- Dependency hygiene PARTLY measured — SwiftPM pinning read, dependency currency NOT established
- Documentation: no contributor guidance (README.md)
- Documentation: no usage examples (README.md)
- Off-boarding risk: anonymized user #1
New (12)
- Off-boarding risk: anonymized user #1
- Outdated: citadel
- Outdated: kituracontracts
- Outdated: loggerapi
- Outdated: swift-asn1
- Outdated: swift-atomics
- Outdated: swift-collections
- Outdated: swift-crypto
- Outdated: swift-log
- Outdated: swift-nio
- Outdated: swift-nio-ssh
- Outdated: swift-system
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
traderepublic/Cilicon was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 1 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit a502beedef674c7d55984c069f005a35ba2fdeea — the exact code this score is about.
- Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.