ytti/oxidized
63.6
Adequate · 28 September 2026
12.9k
lines of production code
Ruby
primary language
2
measurements over time
What this system is
Oxidized is a network device configuration backup and management system that automates the collection, storage, and monitoring of device configurations. It supports a wide variety of network hardware through extensible input and output plugins, storing data in Git repositories, HTTP endpoints, or local files. The system provides robust operational features including customizable hooks for notifications, dynamic node mapping, and comprehensive diagnostic tools for troubleshooting.
How it got here
2013 — v0.37.0 architectural overhaul
11 changes.
This period focused on a comprehensive architectural overhaul for version 0.37.0, replacing legacy logging and configuration systems with SemanticLogger and a robust variable resolution engine. The codebase was significantly expanded with new input, output, and source modules, alongside extensive device model support and a new extensible hook system. Operational maturity was further enhanced through a complete test suite, modernized dependency management, and a suite of deployment and monitoring scripts.
2014–2026 — Extensibility and test coverage expansion
10 changes.
This period focused on enhancing Oxidized's extensibility through a new hook notification system and configurable node statistics tracking. Significant effort was dedicated to expanding test coverage across input, output, source, and model components, including the introduction of the ATOMS framework for automated model testing. Additionally, diagnostic capabilities were improved with a new support command featuring sensitive data redaction.
Features
Add --support diagnostic command with sensitive data redaction
Users can now run the new --support option to generate a comprehensive system diagnostic report. This output includes the Oxidized version, OS details, Ruby environment, installed gems, and Rugged SSH support status. Crucially, the command automatically redacts sensitive information from environment variables (such as passwords, tokens, and keys) and configuration files before printing, helping users safely share diagnostics for troubleshooting.
lib/oxidized/cli · high confidence
Add CLI entry point and interactive console script
The bin directory now includes a new executable script (bin/oxidized) that serves as the primary command-line interface, instantiating and running the Oxidized::CLI class while handling errors by warning the user and exiting with a non-zero status code if debug mode is disabled. Additionally, a bin/console script has been added to facilitate interactive development by loading the library and starting a Pry session.
bin · high confidence
Add configurable node execution statistics tracking
A new stats module has been added to the Node component to track job execution history, including start/end times, duration, and success/failure counts. The history size is configurable via the application config (defaulting to 10 entries), and modification times are now recorded to reflect the last update.
lib/oxidized/node · high confidence
Add device models for ACME Packet, A10 ACOS, Cisco ACE, AddPack, Adtran, ADVA, Accedian, AireOS, Airfiber, AirOS, Alteon, Alvarion, AOS, AOS7, ArubaOS-CX, and AOSW
New configuration backup models have been added for a wide range of network and security devices, including ACME Packet, A10 ACOS, Cisco ACE, AddPack, Adtran, ADVA, Accedian, Cisco AireOS, Ubiquiti Airfiber and AirOS, Alteon, Alvarion, Alcatel-Lucent AOS and AOS7, ArubaOS-CX, and Aruba AOSW. These models define the specific prompts, commands, and secret-filtering rules required to successfully collect and sanitize configurations from these platforms.
lib/oxidized/model · high confidence
Initial release of the hook notification system
Introduces a new extensible hook framework that allows Oxidized to trigger external actions upon configuration changes. The initial set of supported hooks includes SlackDiff for posting colorized diffs to Slack channels, CiscoSparkDiff for Cisco Spark notifications, XMPPDiff for XMPP Multi-User Chat alerts, AwsSns for publishing messages to AWS SNS topics, GithubRepo for pushing configuration changes to remote Git repositories, and Exec for running arbitrary external commands with configurable timeouts and environment variables.
lib/oxidized/hook · high confidence
New example hooks for dynamic model and IP mapping
Added three example Ruby hooks in the \extra/hooks\ directory that demonstrate how to use the \source\_node\_transform\ event to modify node attributes before configuration retrieval. \modelrules.rb\ provides a basic example of overriding a device's model based on vendor and group. \modelrulesadvanced.rb\ offers a more flexible, generic implementation that matches rules against any mapped node field (such as name, IP, or vendor) to dynamically assign models. \srcipmap.rb\ illustrates how to override a node's IP address based on specific attributes like role. These files serve as templates for users to customize node data handling.
extra/hooks · high confidence
New operational scripts and deployment examples for Oxidized
This update adds a collection of utility scripts and configuration examples to the 'extra' directory to support common operational tasks and deployment patterns. Key additions include a syslog monitor (extra/syslog.rb) that listens for configuration change events from network devices and triggers updates via the REST API, and a Nagios check script (extra/nagios\_check\_failing\_nodes.rb) for monitoring backup health with critical, warning, and OK statuses. For version control integration, new hooks are provided: gitdiff-msteams.sh posts configuration diffs to Microsoft Teams webhooks, and oxidized-report-git-commits emails git diffs for configuration changes. Additionally, a device2yaml.rb script is introduced to simulate device interactions for model testing, and an auto-reload-config.runit script enables automatic configuration reloading. The update also includes deployment examples for systemd, upstart, runit, supervisord, init.d, and reverse proxies (Nginx, Apache, HAProxy), along with logrotate and CA certificate update helpers.
extra · high confidence
Output subsystem refactored with new GitCrypt and HTTP outputs
The output subsystem has been restructured to support new output types and improve existing ones. A new GitCrypt output plugin was added, enabling encrypted configuration storage in Git repositories using the git-crypt tool. An HTTP output plugin was introduced, allowing configurations to be pushed to remote web APIs via POST requests, with support for SSL verification and custom headers. The existing Git output was migrated from the Grit library to Rugged for better performance and stability, and the File output was refactored to support group-based directory structures and cleaning of obsolete node configurations. The base Output class now uses SemanticLogger for logging and provides a standardized interface for all output plugins.
lib/oxidized/output · high confidence
Behavioural changes
Introduces String refinements and migrates to SemanticLogger
The library now includes a new \lib/refinements.rb\ module that adds string manipulation methods (\cut\_tail\, \cut\_head\, \cut\_both\, \keep\_lines\, \reject\_lines\) and command processing helpers to the \String\ class via Ruby refinements. Additionally, the core \lib/oxidized.rb\ file has been updated to require and include \SemanticLogger\, replacing the previous custom logging implementation with a standardized logging framework, while also removing the obsolete \lib/tst\ test script.
lib · high confidence
Oxidized 0.37.0: Hook system, SemanticLogger, and configurable job scheduling
This release upgrades the logging infrastructure to SemanticLogger, enabling flexible appenders (file, syslog, stderr) and signal-based log-level changes, while deprecating the legacy 'log' and 'use\_syslog' config keys. A new extensible Hook system allows users to register callbacks for events like node\_success, node\_fail, post\_store, and source\_node\_transform. Job scheduling is now more robust with configurable thread limits (use\_max\_threads), a rolling average for duration estimation, and a timelimit per job to prevent hangs. The CLI gains a --support diagnostic flag, and the node resolution logic now supports IP addresses with netmasks and configurable DNS resolution.
lib/oxidized · high confidence
Refactored configuration variable resolution and removed legacy bootstrap logic
The configuration system now uses a dedicated \lib/oxidized/config/vars.rb\ module to handle variable lookups, implementing a specific precedence order (node, group-model, group, model, global) and explicitly ignoring nil values during resolution. This change accompanies the removal of the legacy \bootstrap.rb\ and \core.rb\ files, which previously handled configuration loading via OpenStruct and YAML, indicating a shift in how the application initializes and persists its settings.
lib/oxidized/config · high confidence
Refactored input modules with shared base classes and new debug logging
The input modules have been restructured to improve code reuse and debugging capabilities. SSH and SCP inputs now inherit from a new SSHBase class, which centralizes connection logic, proxy support, and SSH-specific options (such as key exchange, encryption, and host key verification). A new Exec input allows running arbitrary shell commands, while FTP and TFTP inputs are implemented as standalone classes. The CLI input module now provides a generic login mechanism that handles username and password prompts, supporting both regex-based detection and block-based post-login/pre-logout hooks. Additionally, new DebugText and DebugYAML classes enable detailed I/O logging for troubleshooting, writing session data to text or YAML files in the debug directory.
lib/oxidized/input · high confidence
Source modules refactored to support node variables, GPG decryption, and regexp mapping
The source modules (CSV, SQL, JSONFile, and the new HTTP source) have been refactored to support node-specific variables via a new \vars\_map\ configuration option, allowing dynamic values to be interpolated into node data. GPG decryption is now supported for CSV and JSONFile sources when the \gpg\ config option is enabled, with decrypted content handled via a unified \open\_file\ method. Model and group mapping now supports regular expressions in addition to exact string matches, enabling more flexible node classification. The HTTP source adds pagination support, configurable read timeouts, and basic authentication. These changes improve flexibility and security for node discovery and configuration management.
lib/oxidized/source · high confidence
Test coverage
Added test coverage for config vars, SSH/SCP inputs, and HTTP input; Added test coverage for file and git output plugins; Added tests for CLI support module and redaction logic; Added unit tests for source configuration validation and features; Added unit tests for the GitHubRepo hook; Expanded model unit tests and ATOMS framework; Initial test suite for Oxidized core components.
Dependencies
Migrate to gemspec-based dependency management and update runtime requirements
The project has replaced the explicit Gemfile with a gemspec-driven approach, consolidating dependency declarations into oxidized.gemspec. This change updates the minimum supported Ruby version to 3.0 and significantly refreshes the dependency tree: it removes legacy gems like grit, sqlite3, and rspec, while adding modern runtime dependencies such as net-ssh (\~\> 7.3), rugged (\~\> 1.6), and asetus (\~\> 0.4). Development dependencies have also been updated to include newer versions of rubocop, minitest, and mocha, ensuring compatibility with current Ruby ecosystems.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 65 → 64 (-1.5)
- Rubric changed (rubric-2026.09.8 → rubric-2026.09.16) — scores are not directly comparable.
Lenses
- Code Health 99 → 99 (+0.0)
- Architecture 98 → 73 (-25.1)
- Maturity 51 → 51 (+0.1)
- Readiness 78 → 74 (-3.7)
- Security 68 → 72 (+3.9)
Resolved (6)
- Documentation: no contributor guidance (README.md)
- Documentation: no installation or build instructions (README.md)
- Documentation: no installation or build instructions (README.md)
- Documentation: no project overview (README.md)
- Documentation: no usage examples (README.md)
- Off-boarding risk: anonymized user #1
New (6)
- Ambiguous retrieval methods. 'fetch' takes name/group, 'show' takes a node object, 'get' takes no args. It is unclear what 'get' returns or if it's a list vs single item. 'fetch' and 'show' seem to overlap in intent (retrieving node info) but differ in input type.
- Inconsistent first parameter name for the node object. File and Http use 'node', while Git and GitCrypt use 'file'. This suggests a copy-paste error or lack of standardization in the Output plugin interface.
- Inconsistent parameter naming and presence in Source plugins. CSV uses '_node_want' (underscore prefix implying unused/ignored), HTTP and SQL use 'node_want', while JSONFile takes no arguments. This creates confusion about whether the node_want argument is optional or required for all sources.
- Off-boarding risk: anonymized user #1
- Projects may be oversized for their cohesion
- While the signatures are identical, the semantic meaning of 'fetch' varies slightly in implementation context (Git fetches from repo, File fetches from disk), but more importantly, the lack of a common base class or interface definition for these methods makes it hard to enforce consistency. However, the signature consistency is high here.
Changes since last survey
- 23 commits — 20 feature/other, 3 fixes
By area
- (repo) — 10 commits
- (root) — 7 commits
- .github/ISSUE_TEMPLATE — 2 commits
- lib/oxidized — 2 commits
- .github/PULL_REQUEST_TEMPLATE.md — 1 commit
- .github/workflows — 1 commit
Notable commits
- fix: Fix gemspec and add http tests for ports
- fix: Merge pull request #3910 from ytti/fix/3806-documentation
- fix: Merge pull request #3911 from ytti/fix/3700
- change: Add AGENTS.md and AI contribution policy
- change: Add Cisco FTD model
- change: Hint to run --suuport in the same environment as oxidized
- change: Make simulation files standard for model submissions
- change: Merge branch 'master' into feat/agents-and-ai-contribution-policy
- change: Merge branch 'ytti:master' into 3819-fastiron-pager
- change: Merge pull request #3886 from FusionBrah/3819-fastiron-pager
- change: Merge pull request #3892 from freddy36/cnos3
- change: Merge pull request #3904 from ytti/dependabot/github_actions/master/github/codeql-action-4.37.9
- change: Merge pull request #3908 from mgrocock-cwcs/cwcs-ftd
- change: Merge pull request #3917 from ytti/feat/agents-and-ai-contribution-policy
- change: Merge pull request #3918 from ytti/dependabot/github_actions/master/github/codeql-action-4.38.1
- change: Refactor FTD model into ConfigExporter class and add unit tests
- change: Support DELETE method in HTTP input
- change: Support overriding port in HTTP input
- change: Update CONTRIBUTING.md
- change: Update Issue templates
- …and 3 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
ytti/oxidized was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 28 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 2cb5053566dfe4141aa02032d2cc8520be63c68a — the exact code this score is about.
- Scored under rubric-2026.09.16 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-2d9048c36d26.