flawlesscode254/dapr
53.5
Adequate · 5 August 2026
35.7k
lines of production code
Go
primary language
4
measurements over time
What this system is
This system is a distributed application runtime that provides sidecar-based infrastructure for building microservices. It manages the lifecycle of application containers, facilitating service invocation, state management, and pub/sub messaging through a pluggable component architecture. The platform includes a control plane for configuration and discovery, a placement service for actor state management, and a certificate authority for secure mTLS communication between workloads.
How it got here
2019 — Component and runtime refactoring
78 changes.
This period focused on replacing the legacy action and eventing subsystems with a pluggable component architecture, introducing a unified runtime entry point (daprd), and establishing a modular structure for HTTP and gRPC communication. The work also standardized deployment via Helm charts and expanded configuration capabilities for security, middleware, and observability.
2020 — Sentry CA and distributed placement service
68 changes.
This period focused on implementing the Dapr Sentry control plane, introducing a modular Certificate Authority service with gRPC APIs for workload certificate issuance and identity validation. Concurrently, the placement service was refactored to support a Raft-based, highly available distributed state for actor host management. The work also included expanding the gRPC protocol definitions for the runtime and operator, alongside comprehensive end-to-end and performance testing for these new components.
2021–2022 — extensibility and resiliency features
50 changes.
This period focused on introducing core extensibility and resiliency features, including automatic component registration, pluggable components, and a new resiliency policy engine with circuit breaker support. The team also expanded the gRPC interface for state stores and added comprehensive end-to-end and performance tests for actors, pub/sub, and health checks.
Features
Add Dapr Dashboard Helm chart
The Dapr Dashboard is now available as a standalone Helm chart, allowing users to deploy the dashboard as a separate service. The chart includes configuration for the container image (version 0.10.0), resource limits, and security settings such as running as a non-root user.
_charts/dapr/charts/dapr\dashboard · high confidence
Add Dapr RBAC Helm chart with secretReader configuration
A new Helm chart for Dapr's Kubernetes RBAC components has been introduced. The chart includes a .helmignore file for build filtering, a Chart.yaml defining the 'dapr\_rbac' chart, and a values.yaml that enables the 'secretReader' component in the 'default' namespace by default.
_charts/dapr/charts/dapr\rbac · high confidence
Add Kubernetes identity validation for Sentry workloads
A new validator is introduced in the Sentry identity package to verify Kubernetes service account tokens. It validates that the provided token is a valid Kubernetes service account token, that the token is authenticated, and that the identity (namespace and service account name) matches the expected value. This ensures that only properly structured and authenticated service account tokens are accepted for Sentry workloads.
pkg/sentry/identity/kubernetes · high confidence
Add OpenTelemetry tracing and OpenCensus metrics utility functions
The diagnostics utilities now include helpers for OpenTelemetry tracing and OpenCensus metrics. A new \StdoutExporter\ prints trace data to the console, while \TraceSampler\ and \IsTracingEnabled\ manage probabilistic trace sampling rates. Additionally, \SpanFromContext\ and \SpanToFastHTTPContext\ facilitate span propagation in fasthttp contexts, and \NewMeasureView\ and \WithTags\ provide OpenCensus metrics helpers.
pkg/diagnostics/utils · high confidence
Add Resiliency Custom Resource Definition (CRD) API
The Resiliency API has been introduced as a new Custom Resource Definition (CRD) under the 'dapr.io' group, version v1alpha1. This change adds the Go types and Kubernetes schema definitions for the Resiliency resource, which allows users to configure timeout, retry, and circuit breaker policies for applications, actors, and components.
pkg/apis/resiliency · high confidence
Add TLS credentials support for the placement service
The placement service now supports TLS-based authentication. New files in the credentials package introduce a CertChain struct and helper functions to load certificate and key files from disk, and to configure gRPC server and client transport credentials with mutual TLS (mTLS). This enables secure, encrypted communication for the placement service.
pkg/credentials · high confidence
Add app health check implementation
The apphealth package now includes a new Config struct and AppHealth type that manage application health probes. The implementation tracks failure counts, enforces a configurable threshold before marking the app as unhealthy, and rate-limits health reports to prevent excessive signaling. Tests verify the threshold logic and report rate-limiting behavior.
pkg/apphealth · medium confidence
Add component, HTTP, and gRPC monitoring and tracing implementations
Added new files in pkg/diagnostics to implement structured metrics and distributed tracing for internal components, HTTP requests, and gRPC calls. The changes introduce \component\_monitoring.go\ to track metrics for pub/sub, bindings, state, configuration, and secrets; \http\_monitoring.go\ and \http\_tracing.go\ to capture HTTP server/client metrics and OpenTelemetry spans; and \grpc\_monitoring.go\ and \grpc\_tracing.go\ to record gRPC server/client metrics and spans. Each implementation includes corresponding test files to verify metric recording and span generation.
pkg/diagnostics · high confidence
Add configuration component registry
A new configuration component registry has been introduced in the pkg/components/configuration package. This adds a Registry struct that manages a map of configuration store implementations, allowing components to be registered and retrieved by name and version. The implementation includes a DefaultRegistry singleton, a RegisterComponent method to add new configuration stores, and a Create method to instantiate them, supporting case-insensitive lookups and version fallback logic.
pkg/components/configuration · high confidence
Add configuration structs for Kubernetes and Standalone modes
New configuration structs, KubernetesConfig and StandaloneConfig, are introduced to define settings for their respective operational modes. KubernetesConfig includes a ControlPlaneAddress field, while StandaloneConfig includes a ComponentsPath field, enabling mode-specific configuration.
pkg/config/modes · high confidence
Add gRPC proxy codec to support proto v1 messages
A new gRPC proxy codec has been added to the \pkg/grpc/proxy/codec\ package, enabling the system to handle both proto v1 and proto v2 (protobuf) messages during proxying. This change introduces a \Proxy\ codec that treats gRPC message frames as raw bytes, allowing the proxy server to remain oblivious to the schema of forwarded messages while falling back to standard marshaling for non-proxy-internal functions. The implementation includes the codec logic, associated unit tests, and generated protobuf files for a test service, facilitating the 'bring-your-own-proto' capability.
pkg/grpc/proxy/codec · high confidence
Add gRPC proxying support for bring-your-own-proto scenarios
The gRPC proxy package now includes core proxying logic (director and handler) adapted from the trusch/grpc-proxy library, enabling the system to forward gRPC requests to backend services. This change introduces the infrastructure for transparent gRPC proxying, allowing the platform to route requests to external or internal services based on a stream director, while integrating with the existing resiliency provider for retry and timeout policies.
pkg/grpc/proxy · high confidence
Add health check utility and healthz server
The \pkg/health\ package introduces a new \StartEndpointHealthCheck\ function that continuously monitors an HTTP endpoint's health status, emitting a boolean channel to signal whether the endpoint is healthy or has failed a configurable number of consecutive checks. Additionally, a new \Server\ interface and implementation are provided to expose a \/healthz\ HTTP endpoint that reflects the internal readiness state of the application, allowing external systems to monitor if the service is ready to accept traffic.
pkg/health · high confidence
Add host IP and Kubernetes cluster domain resolution utilities
The utils package introduces new helper functions to resolve the host's outbound IP address (via the DAPR\_HOST\_IP environment variable or network probing) and to determine the Kubernetes cluster domain from /etc/resolv.conf. Additionally, the package adds utility functions for environment variable management (SetEnvVariables, GetEnvOrElse), boolean string parsing (IsTruthy), YAML file detection (IsYaml), and generic slice containment (Contains).
utils · high confidence
Add initial Helm chart for Dapr Operator
Introduces the first version of the Helm chart for the Dapr Operator, including configuration for replica count, logging, image settings, and health check probes.
_charts/dapr/charts/dapr\operator · high confidence
Add monitoring metrics for the Sentry service
The Sentry service now exposes operational metrics via OpenCensus, including counters for certificate signing requests, successes, and failures, as well as tracking for server TLS certificate issuance failures, issuer certificate changes, and expiry timestamps. These metrics are initialized and registered for observability.
pkg/sentry/monitoring · high confidence
Add placement service runtime metrics
The placement service now exposes two new metrics—\placement/runtimes\_total\ and \placement/actor\_runtimes\_total\—to track the number of connected and actor runtimes, respectively. These metrics are registered via OpenCensus and can be used to monitor the health and scale of the placement service.
pkg/placement/monitoring · high confidence
Add pub/sub scope parsing for subscription and publishing topics
A new \pkg/scopes\ package has been introduced to handle Pub/Sub scope configurations. It provides functions to parse and validate topic lists for both subscriptions and publishing, supporting comma-separated topic lists and app-specific scoping (e.g., \appid=topic1,topic2\). This enables more granular control over which topics an application can subscribe to or publish to, with support for whitespace and duplicate handling.
pkg/scopes · high confidence
Add self-hosted identity validator
A new validator implementation for self-hosted environments has been added to the Sentry identity package. This component provides a no-op validation path for self-hosted deployments, ensuring that identity validation is handled consistently across different deployment modes.
pkg/sentry/identity/selfhosted · high confidence
Add version reporting capabilities
A new version package has been introduced to the codebase, providing functions to retrieve the current Dapr version, the git commit SHA, and the git version. These values are injected at build time, allowing users to identify the specific build of the software they are running.
pkg/version · high confidence
Added Dapr Helm chart templates and release notes
The Dapr Helm chart now includes the NOTESTemplate for displaying installation confirmation and quickstart links, alongside the \_helpers.tpl template defining Kubernetes naming conventions for the operator. These additions provide users with immediate post-installation guidance and standardized naming for resources.
charts/dapr/templates · high confidence
Added access control list (ACL) parsing and validation logic
The \pkg/acl\ package now includes \acl.go\ and \acl\_test.go\, introducing the \ParseAccessControlSpec\ function which converts an \AccessControlSpec\ configuration into an in-memory \AccessControlList\ for fast lookup. This implementation validates required fields such as \AppName\, \Namespace\, and \TrustDomain\, and handles default actions (defaulting to Deny if app-level policies are present but no global default is set). The tests verify the correct translation of HTTP verb and operation-based access rules.
pkg/acl · high confidence
Added build-tools CLI for e2e and perf commands
A new Go-based CLI tool has been added to the .build-tools directory, providing 'e2e' and 'perf' commands to build, push, and cache Docker images for end-to-end and performance test apps. The CLI supports building images locally, pushing them to a registry, and using a cache registry to speed up test runs by avoiding unnecessary pulls.
.build-tools · high confidence
Added gRPC service definitions for state store operations
New Go source files were added to the \pkg/proto/components/v1\ directory, generating the Go client and server interfaces for the \QueriableStateStore\ and \TransactionalStateStore\ gRPC services. This introduces the \Query\ and \Transact\ RPCs, enabling state store components to expose query and transactional capabilities over the Dapr component interface.
pkg/proto/components · high confidence
Added gRPC test service and generated code
Added the \testservice\ package containing the \test.proto\ definition and the generated Go code (\test.pb.go\, \test\_grpc.pb.go\) for the \TestService\. This introduces the \PingEmpty\, \Ping\, \PingError\, \PingList\, and \PingStream\ RPCs, along with the corresponding client and server interfaces, to support gRPC testing scenarios.
pkg/grpc/proxy/testservice · high confidence
Automatic registration of Dapr components
The Dapr runtime now automatically discovers and registers all available components (bindings, configuration, locks, and middleware) at startup via the \cmd/daprd/components\ package. This change replaces manual component registration with a system that scans for and initializes each supported integration—such as AWS, Azure, GCP, and various middleware—without requiring explicit code changes for each new component. Users benefit from a more maintainable and extensible architecture where new components are supported simply by adding their registration files to this directory.
cmd/daprd/components · high confidence
Automatic state store encryption support
The \pkg/encryption\ package introduces automatic encryption for state store data. It provides functions to extract encryption keys from component metadata and secret stores, and to encrypt or decrypt values for registered state stores. This enables transparent encryption of state data using AES-GCM with support for primary and secondary keys.
pkg/encryption · high confidence
Dapr RBac Helm chart templates added
The Dapr RBAC Helm chart now includes the complete set of Kubernetes RBAC resources required for the Dapr operator and dashboard. This adds the ServiceAccounts for the operator and dashboard-reader, along with the corresponding ClusterRoles and ClusterRoleBindings that grant permissions to manage deployments, statefulsets, pods, configmaps, secrets, and Dapr-specific resources (components, configurations, subscriptions, resiliencies). It also introduces a conditional secret-reader Role and RoleBinding, allowing the operator to read secrets from a specified namespace when enabled.
_charts/dapr/charts/dapr\rbac/templates · high confidence
Initial Dapr Dashboard Helm chart with HA and scheduling support
Introduced the Dapr Dashboard Helm chart, providing a configurable Kubernetes Deployment, Service, and PodDisruptionBudget for the dashboard component. The chart supports high-availability configurations via pod anti-affinity and PDBs, allows custom pod and node selectors, tolerations, and image pull secrets, and dynamically selects the correct Policy API version (policy/v1 vs policy/v1beta1) for the PodDisruptionBudget.
_charts/dapr/charts/dapr\dashboard/templates · high confidence
Initial release of the Dapr sidecar injector Helm chart
The Dapr sidecar injector Helm chart is now available, providing a standardized way to deploy the sidecar injector component. The chart includes default configuration values for the injector service image, sidecar image, webhook failure policy, and Kubernetes cluster domain. It also exposes configurable probes, debug settings, and network policies such as hostNetwork and image pull policies.
_charts/dapr/charts/dapr\_placement, charts/dapr/charts/dapr\_sentry, charts/dapr/charts/dapr\_sidecar\injector · high confidence
Introduce AppChannel interface for user application communication
A new AppChannel interface is introduced in the channel package to abstract communication with the user application. This interface defines methods for retrieving the base address, fetching application configuration, invoking methods, performing health probes, and setting app health status, providing a structured way to interact with the user's application.
pkg/channel · high confidence
Introduce Dapr Helm chart for Kubernetes deployment
The Dapr Helm chart is now available for installing the Dapr control plane on Kubernetes. This chart bundles the Dapr operator, sidecar injector, placement service, Sentry, and dashboard as child charts, allowing users to deploy the full Dapr system with a single Helm install command. The chart supports configuration for high availability, mutual TLS, Prometheus metrics, and resource limits, providing a standardized way to manage Dapr's infrastructure components.
charts/dapr · high confidence
Introduce Dapr Operator Helm chart templates
The Dapr Operator is now installable via a dedicated Helm chart, providing a complete Kubernetes deployment manifest for the operator. This includes a Deployment with configurable liveness and readiness probes, a Service for the operator API and webhook, and a PodDisruptionBudget to ensure high availability. The chart also generates TLS certificates for the webhook and supports custom labels, resource limits, and OS/architecture-specific scheduling constraints.
_charts/dapr/charts/dapr\operator/templates · high confidence
Introduce Dapr Operator gRPC API for Components, Configurations, and Resiliency
A new gRPC service definition for the Dapr Operator is introduced, exposing RPCs to list and retrieve components, configurations, pub/sub subscriptions, and resiliency configurations. This establishes the contract for sidecars to discover available pluggable components, fetch configuration and subscription data, and access resiliency settings, enabling the operator to push component updates and provide discovery endpoints for these resources.
dapr/proto/operator · high confidence
Introduce Dapr Sentry control plane with high availability and security features
Adds the Dapr Sentry control plane deployment, service, and PodDisruptionBudget to the Dapr Helm chart. The Sentry component is now deployed as a Kubernetes Deployment with configurable replicas for high availability, supported by a PodDisruptionBudget to ensure availability during voluntary disruptions. The deployment includes TLS configuration for trust bundles, Prometheus metrics scraping, and supports Linux OS constraints with node affinity rules to ensure Sentry runs on Linux nodes. Additionally, the chart supports custom labels, tolerations, and node selectors for scheduling flexibility.
_charts/dapr/charts/dapr\sentry/templates · high confidence
Introduce Dapr runtime mode constants
A new \pkg/modes\ package is added, defining the \DaprMode\ type and constants for \KubernetesMode\ and \StandaloneMode\. This introduces the foundational types used to represent Dapr's runtime modes.
pkg/modes · high confidence
Introduce HTTP app channel implementation
Added a new HTTP-based AppChannel implementation in the runtime, enabling the Dapr sidecar to communicate with user applications over HTTP. This includes support for SSL/TLS, configurable max concurrency, request body size limits, and health check probes. The implementation integrates with existing tracing and metrics systems, ensuring that HTTP invocations are properly traced and monitored.
pkg/channel/http · high confidence
Introduce HTTP middleware registry for component auto-registration
A new HTTP middleware registry has been added to the Dapr runtime, enabling automatic registration and instantiation of HTTP middleware components. This change introduces a centralized registry that allows middleware to be registered by name and version, supporting case-insensitive lookups and versioned component resolution. This infrastructure supports the broader component auto-registration system, allowing users to configure and manage HTTP middleware through standardized registration patterns.
pkg/components/middleware · high confidence
Introduce Raft-based placement service for actor host state
Added a new Raft-based implementation for the Dapr placement service in the \pkg/placement/raft\ package. This introduces a finite state machine (FSM) to manage actor host member state and consistent hashing tables with strong consistency guarantees. The change includes the Raft server, state management, snapshot/restore logic, and a logger adapter, enabling the placement service to maintain a replicated log of member upserts and removals. This provides a more robust, distributed approach to managing actor host registrations and load balancing tables compared to the previous non-replicated state.
pkg/placement/raft · high confidence
Introduce SPIFFE-based identity structures and validation interface
Added new identity management components in the sentry package, including a Bundle struct to hold workload identification data (ID, namespace, trust domain) and a CreateSPIFFEID function that generates SPIFFE URIs with strict validation of trust domains and namespace/app IDs. A new Validator interface was also introduced to support certificate requester identity validation using IDs and tokens.
pkg/sentry/identity · high confidence
Introduce Sentry CA server implementation
Added a new file pkg/sentry/server/server.go that implements the Certificate Authority (CA) server for the Sentry service. This change introduces the core gRPC server logic for handling Certificate Signing Requests (CSRs) and managing TLS configurations, including client certificate validation and certificate signing workflows.
pkg/sentry/server · high confidence
Introduce Sentry CA service with health and metrics endpoints
The Sentry Certificate Authority (CA) service is now fully bootstrapped with a dedicated main entry point. It registers command-line flags for configuration paths, issuer credentials, and trust domain, and initializes the Dapr logger and metrics exporter. The service starts a background health check server on port 8080 and exposes Prometheus metrics, enabling operational monitoring and health verification for the CA component.
cmd/sentry · high confidence
Introduce Sentry configuration loading for Kubernetes and self-hosted environments
A new configuration module has been added for the Sentry component, enabling the loading of Certificate Authority settings from either Kubernetes Custom Resources or standalone configuration files. The implementation provides a unified \FromConfigName\ interface that automatically detects the environment (Kubernetes vs. self-hosted) and retrieves the appropriate configuration, supporting parameters such as WorkloadCertTTL and AllowedClockSkew. This change establishes the foundation for managing TLS and CA settings within the Dapr system.
pkg/sentry/config · high confidence
Introduce bindings registry for component auto-registration
The bindings package now includes a central registry that manages input and output bindings. This registry supports versioned component lookups, allowing the system to resolve bindings by name and version, and enables automatic component registration for Dapr builds.
pkg/components/bindings · high confidence
Introduce certificate and credential management for Sentry
Added new Go packages under pkg/sentry/certs and pkg/sentry/consts to handle certificate and key storage. The certs package provides utilities to decode PEM-encoded certificates and private keys (including EC, RSA, and PKCS8 formats), validate that a certificate matches its corresponding private key, and construct certificate pools. The store.go file implements logic to persist these credentials, saving them as Kubernetes secrets in hosted environments or as local files in self-hosted modes. The consts package defines constants for the Kubernetes secret name (dapr-trust-bundle) and environment variables for trust anchors and certificates.
pkg/sentry/certs · high confidence
Introduce component loading abstractions and implementations
The \pkg/components\ package now provides a structured, interface-based approach to loading Dapr components. This includes a \ComponentHandler\ interface for reacting to component updates, a \ComponentLoader\ interface for retrieving components, and specific implementations for different environments: \DiskManifestLoader\ for loading components from local YAML files (used in standalone mode) and \KubernetesComponents\ for fetching components from the control plane in Kubernetes environments. Additionally, a \Pluggable\ type and \WellKnownTypes\ constant are introduced to categorize and iterate over supported component types such as state stores, pub/sub, and bindings. Versioning logic is also added to identify initial (v0/v1) component versions.
pkg/components · high confidence
Introduce configurable lock key prefix strategies
The lock component now supports configuring how lock keys are prefixed. Users can choose between three strategies: using the application ID, using the store name, or using a custom fixed prefix. This allows for better organization and collision avoidance in distributed locking scenarios. The implementation includes a new configuration structure and a registry for lock stores, with tests verifying the different prefixing behaviors.
pkg/components/lock · high confidence
Introduce core resiliency policy execution and no-op provider
The resiliency package now includes a \NoOp\ provider that acts as a true bypass, allowing operations to run without applying any resiliency policies. Additionally, a new \Policy\ function and supporting types have been added to encapsulate timeout, retry, and circuit breaker logic into a single execution wrapper, enabling consistent application of resiliency rules across the runtime.
pkg/resiliency · high confidence
Introduce dapr\_config subchart for Dapr configuration
A new dapr\_config subchart has been added to the Dapr Helm charts, providing a dedicated configuration component. This includes a Chart.yaml defining the 'dapr\_config' chart, a .helmignore file to exclude common IDE and backup files, and a values.yaml that sets the default system config name to 'daprsystem'. The chart is controlled by the 'dapr\_config\_chart\_included' flag, allowing users to conditionally include or exclude this configuration during manifest generation.
_charts/dapr/charts/dapr\config · high confidence
Introduce dedicated security package for API authentication and certificate management
Added a new \pkg/runtime/security\ package that centralizes security logic for the Dapr runtime. This includes an \Authenticator\ interface and implementation for managing workload certificates and trust anchors, along with helper functions to retrieve API and application tokens from environment variables. The package also defines constants for token headers and environment variables, and explicitly excludes the \/healthz\ endpoint from token authentication checks.
pkg/runtime/security · high confidence
Introduce file-system watcher utility
Added a new \fswatcher\ package that monitors a directory for file creation and write events, sending notifications to a channel. The implementation uses \github.com/fsnotify/fsnotify\ and \github.com/pkg/errors\ for error handling.
pkg/fswatcher · high confidence
Introduce gRPC-based app channel for service invocation
Users can now communicate with their applications via gRPC, enabling more efficient service-to-service invocation. The new \grpc\_channel.go\ implementation supports health probes, request header/metadata transfer, and respects the configured max concurrency and body size limits.
pkg/channel/grpc · high confidence
Introduce internal placement client for actor runtime
Added the internal placement client implementation for the actor runtime, including the \ActorPlacement\ struct and its associated test suite. This change introduces the core logic for the actor service to connect to the placement service, manage consistent hash tables for actor discovery, and handle heartbeat reporting and leader election among placement nodes.
pkg/actors/internal · high confidence
Introduce name resolution component registry
A new name resolution component registry has been added to the system, providing a centralized way to register and instantiate name resolution components. The registry supports versioned components, allowing multiple versions of the same resolver to coexist, and handles case-insensitive lookups. This change replaces the previous service discovery package with a dedicated nameresolution package, removing mDNS code and establishing a clear separation of concerns for name resolution logic.
pkg/components/nameresolution · high confidence
Introduce new CSR generation and certificate template logic in the Sentry package
The Sentry package now includes a new \csr\ sub-package that provides functions for generating Certificate Signing Requests (CSRs) and certificate templates. This includes support for PKCS\#8 private keys, SPIFFE ID extensions, and configurable certificate validity periods with clock skew adjustments. The implementation adds new types and functions for generating root and issuer certificates, as well as signing CSRs with specific key usages and extensions.
pkg/sentry/csr · high confidence
Introduce pluggable component support with Kubernetes and gRPC connectivity
Added a new pluggable component system that enables dynamic loading of components from disk or Kubernetes. The change introduces a gRPC-based client for connecting to pluggable components via Unix domain sockets, a loader that reads component manifests from disk or fetches them from the Kubernetes operator, and a registry system to register and initialize these components at runtime.
pkg/components/pluggable · high confidence
Introduce pub/sub component registry for dynamic component loading
A new pub/sub component registry has been added to the Dapr runtime, enabling dynamic loading and instantiation of message bus components. The \pkg/components/pubsub/registry.go\ file introduces a \Registry\ struct that maintains a map of message bus factories, allowing the runtime to look up and create pub/sub implementations by name and version. This change supports case-insensitive lookups and versioned component resolution, laying the groundwork for auto-registration of pub/sub components.
pkg/components/pubsub · high confidence
Introduce v1 messaging abstractions for service invocation
Added new \InvokeMethodRequest\ and \InvokeMethodResponse\ wrappers in \pkg/messaging/v1\ to manage internal invoke requests and responses. These abstractions provide helper methods for setting actor details, metadata, HTTP extensions, and raw data, while also handling content-type defaults and header conversions. The changes include corresponding unit tests for the new request and response types, as well as utility functions for metadata conversion and content-type checking.
pkg/messaging/v1 · high confidence
Introduce v1alpha1 Component and PluggableComponent APIs
The v1alpha1 API for Dapr components is introduced, defining the \Component\ and \PluggableComponent\ resource types along with their corresponding list types. The \ComponentSpec\ includes fields for type, version, metadata, and an optional \initTimeout\. The \PluggableComponentSpec\ specifies type and version for pluggable components. These changes establish the foundational schema for managing Dapr components via Kubernetes Custom Resource Definitions (CRDs).
pkg/apis/components · high confidence
Introduce v1alpha1 Subscription CRD with metadata, routing, and dead-letter support
The v1alpha1 API for pub/sub subscriptions has been introduced, defining the Subscription and SubscriptionSpec types. Users can now create subscriptions that include optional metadata, specify a routing path, and configure a dead-letter topic for failed messages. The API also supports scoping subscriptions to specific application identities. This change establishes the core data model for declarative pub/sub subscriptions, moving the registration from the previous eventing group to the subscriptions group.
pkg/apis/subscriptions/v1alpha1 · high confidence
Introduce v2alpha1 Subscription API with scope and dead-letter topic support
A new v2alpha1 API version for event subscriptions is added, defining the Subscription and SubscriptionSpec types with support for Scopes and DeadLetterTopic. Conversion logic is implemented to map between this new version and the existing v1alpha1 hub version, ensuring that scope and dead-letter topic fields are correctly transferred during version conversion. Tests are included to verify the round-trip conversion.
pkg/apis/subscriptions/v2alpha1 · high confidence
Introduces gRPC API server implementation and concurrency limiter
Adds the core gRPC server implementation for Dapr, including the \api\ struct that implements the Dapr runtime interface, along with supporting files for configuration, authentication, endpoint access control, and connection pooling. This change also introduces a concurrency limiter (\pkg/concurrency/limiter.go\) to manage concurrent execution of jobs, and includes comprehensive unit tests for the new gRPC components.
pkg/grpc · high confidence
New CEL expression evaluation support in pkg/expr
A new \pkg/expr\ package has been introduced to provide a wrapper around the \google/cel-go\ library, enabling the parsing and evaluation of Common Expression Language (CEL) expressions. The \Expr\ struct handles the compilation of CEL strings into executable programs and provides an \Eval\ method to execute them against a map of variables. The implementation includes logic to dynamically discover and declare undeclared variables during compilation, and supports JSON serialization/deserialization for the expression strings. Corresponding unit tests verify the evaluation logic and JSON marshaling.
pkg/expr · high confidence
New Dapr runtime gRPC API definitions
The Dapr runtime exposes a new gRPC API for inter-process communication, defined in \dapr/proto/runtime/v1/dapr.proto\ and \appcallback.proto\. This introduces the \Dapr\ service with RPCs for state management (Get, Save, Delete, Query, Transactional), PubSub (Publish, Subscribe), Bindings, Secrets, Configuration, Actor management (Timers, Reminders, State, Invocations), Distributed Locking, and Sidecar Metadata. It also defines the \AppCallback\ service, allowing user applications to receive events from PubSub topics and Input Bindings, and to handle service invocations.
dapr/proto/runtime · high confidence
New Dockerfiles and scripts for Dapr container images and dev environment
The docker directory now contains the definitive build definitions for Dapr's container images. This includes the release image (Dockerfile) and debug image (Dockerfile-debug) based on distroless and golang:1.19.1 respectively. A new Mariner-based image (Dockerfile-mariner) is introduced for users requiring that specific OS variant. For development, the VS Code dev container (Dockerfile-dev) is established with Go 1.18 and various tooling. Windows support is added via base images (Dockerfile-windows, Dockerfile-windows-base) that allow setting custom certificates. The build system is updated with a new Makefile (docker.mk) that supports multi-architecture builds using buildx and separates images for runtime, placement, and sentry components.
docker · high confidence
New circuit breaker implementation with configurable trip conditions
The resiliency package now includes a new circuit breaker implementation in pkg/resiliency/breaker. This adds a configurable circuit breaker that supports custom trip conditions via CEL expressions, allowing users to define when a circuit should open based on request counts and failure metrics. The implementation includes both the core breaker logic and corresponding tests to ensure correct state transitions and error handling.
pkg/resiliency/breaker · high confidence
New configuration options for access control, secrets, and HTTP middleware pipeline
Users can now configure access control lists (ACLs) with wildcard support for service invocation, define allowlists for secrets, and set up an HTTP middleware pipeline. The configuration package introduces new structs for managing these features, including a Trie-based ACL implementation and support for component deny lists.
pkg/config · high confidence
New gRPC interfaces for state store query and transactional operations
Added new Protocol Buffers definitions in dapr/proto/components that introduce the QueriableStateStore and TransactionalStateStore gRPC services. These additions enable state store components to support advanced query capabilities and multi-operation transactions, extending the existing StateStore service with specialized interfaces for these features.
dapr/proto/components · high confidence
New internal proto definitions for API versioning, status, and service invocation
The Dapr runtime now includes new internal protocol buffer definitions for API versioning, status, and service invocation. This introduces the \APIVersion\ enum to track Dapr Runtime API versions, a \Status\ message to represent HTTP and gRPC app channel response statuses, and the \ServiceInvocation\ service with \InternalInvokeRequest\ and \InternalInvokeResponse\ messages to facilitate data exchange between caller and callee Dapr runtimes. These proto files establish the internal communication contract for service invocation and status reporting.
dapr/proto/internals · high confidence
Operator API server exposes component and configuration data via gRPC
The Dapr operator now exposes a new gRPC API server that allows Dapr runtime instances to retrieve component definitions, configurations, and pluggable components. This change introduces the \pkg/operator/api\ package, which implements the \OperatorServer\ interface, handling requests for listing components and configurations while also managing secret extraction for Kubernetes-based secret stores. The server listens on port 6500 and provides endpoints for \ListComponents\, \GetConfiguration\, and \ListPluggableComponents\, enabling the operator to push updates to connected runtimes.
pkg/operator/api · high confidence
Operator now manages Dapr sidecar services for Deployments and StatefulSets
The Dapr operator now automatically creates and updates Kubernetes headless services for Dapr sidecars associated with Deployments and StatefulSets. This change introduces the \DaprHandler\ and \Reconciler\ logic in \pkg/operator/handlers\ to watch for annotated workloads, validate app IDs, and ensure the corresponding Dapr service exists with correct annotations (including metrics port and scrape settings). The implementation includes wrapper types for \Deployment\ and \StatefulSet\ to unify their handling, and adds unit tests for the new service management logic.
pkg/operator/handlers · high confidence
Operator service metrics added
The operator now exposes metrics for service lifecycle events, specifically tracking the total number of Dapr services created, deleted, and updated. These metrics are registered via the diagnostics utils package and can be used to monitor operator activity.
pkg/operator/monitoring · high confidence
Refactored HTTP API into a modular, testable server and API layer
The HTTP server and API implementation have been refactored into distinct, modular components. The \pkg/http\ package now contains a dedicated \Server\ struct that manages the fasthttp server lifecycle, including support for Unix domain sockets, multiple listen addresses, and optional profiling. The \API\ interface and its implementation have been separated into \api.go\ and \api\_test.go\, providing a clean contract for HTTP endpoints. Additionally, a new \config.go\ file introduces a \ServerConfig\ struct to centralize HTTP server configuration, and \endpoint.go\ defines the \Endpoint\ struct for route information. This refactoring improves testability and allows for more granular control over the HTTP server's behavior and configuration.
pkg/http · high confidence
Refactored sidecar injector into modular, testable components
The sidecar injector logic has been restructured into distinct, focused packages: \pkg/injector/annotations\ defines all Dapr annotation keys and their default values; \pkg/injector/config\ handles configuration loading and validation; \pkg/injector/sidecar\ contains the core logic for building the sidecar container and generating Kubernetes patch operations; and \pkg/injector/monitoring\ exposes metrics for injection success/failure rates. This separation improves testability and maintainability of the injection process.
pkg/injector · high confidence
Regenerated Dapr runtime and internals gRPC/protobuf code
The Dapr runtime and internal gRPC clients and message types have been regenerated using protoc v3.21.1 and protoc-gen-go v1.28.0. This update introduces new proto-generated Go code for the Dapr runtime API, including the \AppCallback\ service (handling topic events, input bindings, and service invocations) and the main \Dapr\ service (covering state, secrets, configuration, actor timers/reminders, and distributed locking). The changes ensure the Go client and server stubs are synchronized with the latest protobuf definitions.
pkg/proto/runtime · high confidence
Sentry CA server and certificate expiry monitoring
The Sentry service now runs a Certificate Authority (CA) server that manages certificate issuance and validation. A background goroutine monitors the root certificate's expiration, logging warnings when the certificate is within 30 days of expiring. The system also supports both Kubernetes and self-hosted identity validation strategies, initializing the appropriate validator based on the deployment environment.
pkg/sentry · high confidence
Support for pluggable state store components via gRPC
The state component system now supports pluggable state stores that communicate via a gRPC protocol. This change introduces a new \pluggable.go\ implementation that wraps external state store components, allowing them to be registered and used as standard Dapr components. Additionally, state key prefixing strategies (such as app ID, namespace, or store name) are now configurable per state store, enabling better multi-tenant isolation and key management.
pkg/components/state · high confidence
Removals
Removal of action and assigner CLI entry points
The command-line interface entry points for the 'action' and 'assigner' services have been removed from the codebase. Specifically, the main.go files for cmd/action and cmd/assigner have been deleted, indicating that these specific executable targets are no longer part of the build or deployment process.
cmd/action · high confidence
Removal of legacy action and event source implementations
The \pkg/action\ package has been completely removed from the codebase. This deletion eliminates the entire \pkg/action\ directory, including the core \action.go\ implementation, all event source handlers (AWS, Azure, GCP, HTTP, Kafka, MQTT, RabbitMQ, Redis), state stores (CosmosDB, DynamoDB, Memory, Redis), and the Redis-based sender infrastructure. This change removes the legacy execution and eventing layer, indicating a shift away from this specific implementation of action handling and event sourcing.
pkg/action · high confidence
Removal of legacy controller and handler implementations
The legacy controller logic in pkg/controller/controller.go and the associated handler implementations (actions\_handler.go, eventsources\_handler.go, and handler.go) have been removed. This eliminates the previous mechanism where the controller directly managed deployment sidecars and event source propagation through the handlers package, indicating a structural shift in how the system processes actions and events.
pkg/handlers · high confidence
Removed Dockerfile from dist directory
The Dockerfile located in the dist directory has been removed, eliminating the container build configuration for this directory.
dist · high confidence
Removed end-to-end test suite and supporting utilities
The end-to-end (e2e) test suite has been removed. This includes the Go test files for performance and reliability scenarios (e.g., \single\_invoker\_throughput\_test.go\, \evt\_source\_to\_app\_test.go\), the distributed test infrastructure (\crashing\_host.go\, \crashing\_topology.go\, \test\_harness.go\), and associated YAML/Go/Shell assets. Users will no longer be able to run these specific end-to-end validation and benchmarking tests.
e2e · high confidence
Removed obsolete controller entry point
The main entry point for the controller, located at cmd/controller/main.go, has been removed from the codebase. This eliminates the previous hardcoded startup logic that initialized Kubernetes clients and ran the controller, indicating a shift in how the controller is deployed or managed.
cmd/controller · high confidence
Removed vendored Kubernetes client-go apps API clients
The vendored copies of the Kubernetes client-go apps API clients for versions v1, v1beta1, and v1beta2 have been removed from the repository. This change eliminates the local copy of the \k8s.io/client-go\ library's generated client code for managing Deployments, StatefulSets, DaemonSets, ReplicaSets, and ControllerRevisions, likely as part of a broader shift away from vendoring this dependency.
vendor/k8s.io/client-go/kubernetes/typed/apps/v1, vendor/k8s.io/client-go/kubernetes/typed/apps/v1beta1, vendor/k8s.io/client-go/kubernetes/typed/apps/v1beta2 · high confidence
API
New Sentry CA service definition for workload certificate signing
The Dapr Sentry service now exposes a gRPC API for issuing time-bound, X.509 certificates to workloads. Clients can call the new \SignCertificate\ RPC, providing a CSR, identity, and trust domain, to receive a signed workload certificate, the trust chain, and an expiration timestamp. This change introduces the protocol contract that enables secure workload identity management within the Dapr runtime.
dapr/proto/sentry · high confidence
Architecture
Refactored pub/sub runtime into a modular package
The pub/sub runtime logic has been refactored into a new \pkg/runtime/pubsub\ package, separating concerns into dedicated files for adapters, CloudEvents handling, error definitions, subscription models, and subscription loading (both HTTP and gRPC). This change introduces structured types for subscriptions (including support for multiple routes and dead-letter topics) and adds tests for the new CloudEvent creation and subscription filtering logic.
pkg/runtime/pubsub · high confidence
Runtime initialization and configuration refactored into dedicated modules
The Dapr runtime's startup and configuration logic has been reorganized into separate, dedicated files. Command-line flag parsing and the main entry point are now handled in \cli.go\, while configuration structures and constants are defined in \config.go\. Component authorization logic is isolated in \component\_authorizer.go\, and error handling for initialization is encapsulated in \initError.go\. Additionally, OpenTelemetry tracing setup is moved to \trace.go\, and the outbound readiness wait logic is in \wait.go\. These changes improve code modularity and testability, with corresponding unit tests added for the new structures.
pkg/runtime · high confidence
Behavioural changes
Conditional Dapr default configuration with mTLS settings
The Dapr configuration chart now conditionally creates a default Configuration resource (dapr\_default\_config.yaml) that configures mTLS settings (enabled status, workload certificate TTL, and clock skew) based on global values. This change introduces helper templates for naming and ensures the configuration is only applied when the dapr\_config\_chart\_included value is true.
_charts/dapr/charts/dapr\config/templates · high confidence
Dapr Sidecar Injector gains health check endpoint and configurable certificate keys
The Dapr Sidecar Injector now exposes a health check server on port 8080 by default, allowing users to monitor the injector's availability. Additionally, the injector can now be configured with specific secret keys for the CA certificate, issuer certificate, and issuer private key via command-line flags (issuer-ca-secret-key, issuer-certificate-secret-key, issuer-key-secret-key), providing more granular control over credential file paths.
cmd/injector · high confidence
Direct messaging and gRPC proxying now support cross-namespace invocation and resiliency policies
The direct messaging component now supports invoking applications in different Kubernetes namespaces by parsing the namespace from the app ID (e.g., app1.ns1). The gRPC proxy and direct messaging implementations have been updated to include resiliency providers, enabling built-in retry policies for service invocations. Additionally, the proxy now handles access control lists (ACLs) to enforce security policies on incoming gRPC requests. These changes allow for more robust and secure service-to-service communication across namespace boundaries.
pkg/messaging · high confidence
Enforce Kubernetes DNS-1123 label constraints on App IDs
The validation logic for Dapr App IDs on Kubernetes has been updated to enforce RFC 1123 label restrictions. App IDs must now consist of lowercase alphanumeric characters or hyphens, start and end with an alphanumeric character, and not exceed 63 characters (including the appended '-dapr' suffix). Invalid IDs will now produce specific error messages indicating the validation failure.
pkg/validation · high confidence
Expanded Dapr Configuration CRD with new configuration sections
The Configuration Custom Resource Definition (CRD) schema has been significantly expanded to support new Dapr features. The \ConfigurationSpec\ now includes sections for HTTP middleware pipelines (\httpPipeline\), metrics (\metric\), mTLS settings (\mtls\), secrets management (\secrets\), access control (\accessControl\), name resolution (\nameResolution\), features (\features\), API access rules (\api\), and component loading restrictions (\components\). Additionally, the tracing configuration now supports OpenTelemetry (\otel\) alongside Zipkin, and the API access rules include a \protocol\ field.
pkg/apis/configuration · high confidence
Exposes Prometheus metrics endpoint for system processes
The Dapr runtime now exposes a Prometheus-compatible metrics endpoint by default on port 9090, allowing users to scrape system process metrics. This change introduces a new metrics exporter and configuration options (including \enable-metrics\ and \metrics-port\ flags) to control the metrics server, with tests verifying the exporter initialization and flag attachment.
pkg/metrics · high confidence
Introduce daprd as the new Dapr runtime entry point
The Dapr runtime is now launched via the new \cmd/daprd/main.go\ entry point. This change consolidates the initialization of all component registries (state, pub/sub, bindings, secret stores, etc.) and passes them to the runtime, while also configuring logging for each component loader and automatically setting GOMAXPROCS to match the container's CPU quota.
cmd/daprd · high confidence
Introduce modular Certificate Authority implementation in Sentry
The Certificate Authority logic in the Sentry service has been refactored into a new, modular package under \pkg/sentry/ca\. This change introduces a \CertificateAuthority\ interface and a \defaultCA\ implementation that handles loading trust bundles, validating Certificate Signing Requests (CSRs), and signing certificates. The refactoring separates concerns by introducing a dedicated \trust\_bundle.go\ file to manage root and issuer certificates, along with corresponding unit tests for the CA and trust bundle logic.
pkg/sentry/ca · high confidence
Migrated client-side APIs from EventSource to Component resources
The client-side API for managing resources has been renamed and restructured: the previous \EventSource\ type and its associated client, lister, and informer interfaces have been replaced with \Component\ types. This change updates the \pkg/client\ package to use the new \components.dapr.io\ API group instead of the old \eventing.actions.io\ group, affecting all generated client code, fake implementations, and informer factories within the client package.
pkg/client · high confidence
New Dapr gRPC protocol buffers for common types and placement service
The Dapr gRPC API surface is expanded with new protocol buffer definitions. The common types now include an HTTP extension supporting the PATCH verb, a StateItem message replacing the previous StateSaveRequest, and a ConfigurationItem message for configuration data. Additionally, the placement service is defined with Host and PlacementOrder messages to manage runtime host status reporting. These changes update the underlying contract for service invocation, state management, configuration, and actor placement.
dapr/proto/common · high confidence
Operator client now enforces mutual TLS for secure communication
The operator client implementation has been updated to require a certificate chain for establishing a secure gRPC connection. This change ensures that all communication between the sidecar and the operator is encrypted and authenticated via TLS, addressing a security requirement for the control plane. The client now validates the server's certificate against the provided root CA, preventing man-in-the-middle attacks.
pkg/operator/client · medium confidence
Operator refactored to use controller-runtime and adds a sidecar watchdog
The Kubernetes operator has been refactored to use the controller-runtime framework, introducing a new \Config\ struct for loading operator settings and a \DaprWatchdog\ controller that periodically checks all pods in the cluster. The watchdog ensures that pods with the \dapr.io/enabled\ annotation have the Dapr sidecar injected; if a pod is missing the sidecar, the watchdog deletes it so it can be restarted with the sidecar. The operator also registers webhooks for subscription CRDs and patches CRD conversion webhooks to include the correct CA bundle.
pkg/operator · medium confidence
Operator startup and configuration refactored with new flags and metrics
The operator's main entry point (cmd/operator/main.go) has been refactored to support new command-line flags for configuring the operator's behavior. Users can now specify the configuration file name (defaulting to 'daprsystem'), the path to the certificate chain, and the interval for polling pod states. Additionally, the operator now initializes and exposes Prometheus metrics via the standard Dapr metrics exporter, and supports disabling leader election or limiting pod restarts per minute.
cmd/operator · high confidence
Placement service configuration and entry point refactored
The placement service's command-line interface has been restructured into a dedicated configuration module (config.go) and a new main entry point (main.go). This change introduces explicit command-line flags for configuring Raft cluster peers, the placement gRPC port, the health check port, and TLS certificate paths. It also adds support for setting the actor replication factor and enables mTLS for the placement service. A corresponding test file (config\_test.go) validates the parsing of peer addresses from command-line arguments.
cmd/placement · high confidence
Placement service now supports high availability and configurable health checks
The Dapr placement service is now deployed as a StatefulSet, enabling high availability (HA) mode with three replicas. A PodDisruptionBudget is introduced to ensure availability during voluntary disruptions. Users can now configure liveness and readiness probes, including the failure threshold, and the chart supports passing custom pod labels and tolerations. Additionally, the placement service now enforces TLS and runs as a non-root user on Linux.
_charts/dapr/charts/dapr\placement/templates · high confidence
Refactored actor concurrency and locking mechanisms
The actor runtime's concurrency model has been refactored to improve turn-based execution and reentrancy handling. The \actor\ struct now explicitly manages pending calls and disposal state, while a new \ActorLock\ mechanism enforces turn-based concurrency with support for reentrant calls via a stack depth limit. This change ensures that actors process one call at a time unless reentrancy is explicitly enabled, preventing race conditions and improving stability during concurrent invocations.
pkg/actors · high confidence
Regenerate Go client code from updated protobuf definitions
The Go client code for the operator and placement services has been regenerated from updated protobuf definitions. This update introduces new request and response types, such as ListPluggableComponentsRequest/Response and ListSubscriptionsRequest/Response, and adds new gRPC methods including ListPluggableComponents, GetResiliency, ListResiliency, and ListSubscriptionsV2 to the operator service, as well as the ReportDaprStatus stream to the placement service.
pkg/proto/operator · high confidence
Regenerated Sentry v1 protobuf client and server code
The Go client and server stubs for the Sentry v1 gRPC service have been regenerated using the protobuf v2 API. This update updates the underlying protobuf library dependencies and regenerates the \sentry.pb.go\ and \sentry\_grpc.pb.go\ files, ensuring compatibility with the newer \google.golang.org/protobuf\ runtime and \protoc\ tooling.
pkg/proto/sentry · high confidence
Relocate and refactor consistent hashing package
The consistent hashing implementation has been moved from pkg/consistenthash to pkg/placement/hashing, reflecting its specific use within the placement service. The package has been renamed from 'consistenthash' to 'hashing', and internal types and functions have been renamed to be more descriptive (e.g., AssignmentTables to ConsistentHashTables, New to NewConsistentHash). The Host struct now includes an AppID field, and the Add method signature has been updated to accept an ID parameter, allowing the system to track which application a host belongs to.
pkg/placement/hashing · high confidence
Removal of legacy Kubernetes client and informer helpers
The \pkg/kubernetes\ package has been removed, eliminating the legacy helper functions for managing Kubernetes resources (such as \Clients\, \GetDeployment\, \UpdateDeployment\, \CreateService\, \ServiceExists\, \GetEndpoints\, and \GetDeploymentsBySelector\) and the associated informer logic. This change removes the direct dependency on the \actionscore/actions\ clientset and standard Kubernetes client-go wrappers, likely as part of a broader refactoring to modernize the Kubernetes integration layer.
pkg/kubernetes · high confidence
Removal of v1alpha1 EventSource API types
The v1alpha1 API version for the eventing subsystem has been removed. This includes the deletion of the \EventSource\ type and its associated specification structures (such as \SenderOptions\ and \BatchOptions\), along with the group name registration. Users relying on this alpha API version will need to migrate to a newer, stable API version to continue using event source functionality.
pkg/apis/eventing · high confidence
Removed Google Cloud Go vendor dependencies
Removed the entire \cloud.google.com/go\ vendor directory, including subpackages for compute metadata, IAM, storage, and internal utilities. This eliminates the bundled Google Cloud client libraries from the vendor tree, likely shifting to external module dependencies or removing unused Google Cloud dependencies.
vendor · high confidence
Removed deprecated Kubernetes apps API versions
The vendored \k8s.io/api/apps\ package has removed the \v1beta1\ and \v1beta2\ API versions. This change eliminates the deprecated beta APIs for managing Deployments, DaemonSets, StatefulSets, and ReplicaSets, requiring users to migrate to the stable \v1\ API versions for these workloads.
vendor/k8s.io/api/apps/v1, vendor/k8s.io/api/apps/v1beta1, vendor/k8s.io/api/apps/v1beta2 · high confidence
Removed legacy API server and assigner components
The HTTP-based API server in \pkg/api\ and the gRPC-based assigner in \pkg/assigner\ have been removed from the codebase. This eliminates the endpoints for retrieving event sources and configurations, as well as the logic for managing host assignments and table updates.
pkg/api, pkg/assigner · high confidence
Replace logrus-based logging with structured logger in signals package
The signals package now uses the dapr/kit logger instead of the external logrus library, providing a consistent structured logging approach across the codebase. Additionally, the signal channel buffer size has been increased from 0 to 1 to prevent potential signal loss.
pkg/signals · high confidence
Replaces manual build and codegen scripts with a unified Makefile and shell script
The repository replaces several platform-specific build scripts (for Linux, macOS, Windows, and ARM) with a new \tools/codegen.mk\ Makefile that manages code generation targets for gRPC and Protobuf. A new \tools/proto/generate.sh\ script handles downloading and invoking protocol buffers tools for multiple languages (Go, Java, Python, JavaScript, and .NET). The old \tools/codegen.sh\ script and the \tools/boilerplate.go.txt\ header file have been removed or repurposed, consolidating the code generation workflow into a more structured, multi-language approach.
tools · high confidence
Secret store component registration and versioning
The secretstores package now includes a registry system that manages secret store implementations. This system supports registering components with specific versions, allowing for versioned lookups (e.g., v0, v1, v2) and fallback to initial versions. The registry handles case-insensitive name matching and provides structured error messages when a secret store is not found.
pkg/components/secretstores · high confidence
Standardized error message constants for API components
The system now uses a centralized set of error message constants for various API components, including state, pub/sub, actor, secret, direct messaging, configuration, and lock stores. This change ensures consistent and descriptive error messages are returned to users when operations fail, such as when a state store is not configured, a topic is not found, or an actor reminder cannot be created.
pkg/messages · high confidence
Updated Dapr Go client library to use protobuf v2 and regenerate code
The Dapr Go client library has been updated to use the protobuf v2 API, with the generated code in pkg/proto/common/v1/common.pb.go regenerated using protoc v3.21.1 and protoc-gen-go v1.28.0. This change modernizes the underlying protocol buffer implementation, which may affect how the client interacts with the Dapr runtime. Additionally, the HTTP extension enum now includes the PATCH method, and state options for concurrency and consistency are explicitly defined, providing clearer semantics for state management operations.
pkg/proto/common · medium confidence
Updated devcontainer library scripts from VS Code
The scripts in docker/library-scripts have been updated to version v0.224.3 of the vscode-dev-containers script-library. This update includes new or refreshed scripts for installing tools such as Azure CLI, Docker-in-Docker, GitHub CLI, Go, and kubectl/Helm, ensuring the devcontainer environment is provisioned with the latest supported tooling and configurations.
docker/library-scripts · high confidence
Test coverage
Add Go-based performance test app for HTTP service invocation; Add actor features test application; Add actor test application and deployment config; Add binding\_output test application for e2e testing; Add end-to-end test for Dapr Job execution; Add end-to-end tests for Dapr actor features; Add end-to-end tests for service invocation; Add gRPC test application for service invocation; Add mock implementations for channel and gRPC testing; Add performance test for HTTP service invocation; Add performance test for actor timers; Add stateapp test application for e2e state management tests; Add testing mocks and utilities for component interfaces; Added .NET actor test application; Added Dockerfiles and build configuration for test apps; Added E2E test apps for PubSub routing and publishing; Added E2E test infrastructure and metadata test; Added Go-based actor test application for performance testing; Added Java actor performance test application; Added Java actor performance test application; Added Java actor test app with Docker and configuration files; Added Java actor test application for cross-SDK E2E testing; Added OpenTelemetry trace testing utilities; Added PHP-based e2e test app for actor functionality; Added Python actor test app for cross-SDK E2E testing; Added actor client test application for end-to-end testing; Added actor invocation test application; Added actor load test application and client; Added actor load test application components; Added e2e GRPC tests for bindings; Added e2e test app for Secrets API; Added e2e test app for actor reentrancy; Added e2e test app for middleware testing; Added e2e test app for service invocation; Added e2e test app for volume mount and binding tests; Added e2e tests for Dapr injector volume mounts and SSL certificate installation; Added e2e tests for the state app; Added end-to-end test for Dapr service owner reference; Added end-to-end test for actor reminder partitioning; Added end-to-end tests for Dapr middleware; Added end-to-end tests for Dapr runtime initialization; Added end-to-end tests for PubSub routing and gRPC support; Added end-to-end tests for actor invocation; Added end-to-end tests for actor reminders; Added end-to-end tests for app health check functionality; Added end-to-end tests for cross-SDK actor invocation; Added end-to-end tests for resiliency scenarios; Added end-to-end tests for service invocation allowlists; Added end-to-end tests for the PubSub component; Added end-to-end tests for the Secrets API; Added end-to-end tests for the hellodapr demo application; Added gRPC proxy test application for service invocation; Added gRPC-based end-to-end tests for pubsub; Added gRPC-based pub/sub subscriber routing test app; Added gRPC-based pub/sub subscriber test application; Added job-publisher test application for E2E testing; Added metadata test application for sidecar metadata API; Added new E2E test app 'hellodapr' for Dapr integration testing; Added performance test for actor activation; Added performance test for actor reminder registration; Added performance test for gRPC state get operations; Added performance test for pub/sub publish via gRPC; Added performance test infrastructure for benchmarking; Added performance test utility helpers; Added performance testing infrastructure for Dapr; Added performance tests for gRPC service invocation and HTTP state get operations; Added resiliency test apps for HTTP, gRPC, and pub/sub scenarios; Added state actor service for load testing; Added telemetry client for actor load testing; Added test app for input bindings; Added test application for injector validation; Added test apps for runtime and runtime\_init; Added test infrastructure for the E2E test runner; Added test utility functions for HTTP, gRPC, and TLS; Added tests for placement service high availability and membership management; New Azure test infrastructure templates and setup scripts; New E2E test utility helpers for HTTP, logging, and data generation; New Kubernetes test platform utilities for E2E testing.
Dependencies
Updated Go tooling and test app dependencies
The build tools module (\.build-tools/go.mod\) was created with Go 1.19 and updated dependencies including \go-containerregistry\ and \cobra\. The main \go.mod\ was updated to Go 1.19 and refreshed with the latest \components-contrib\ (v1.8.0-rc.1) and various other Go dependencies. Additionally, the .NET and Java test apps (CarActor and actorjava) were updated to use Dapr SDK version 1.0.0-rc02, and the Go-based actor load test app was updated to Go 1.19 with refreshed dependencies.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Baseline
- First survey — no prior run to compare against. CAI 54.
Lenses
- Code Health 87
- Architecture 54
- Maturity 62
- Readiness 67
- Security 45
Changes since last survey
- 300 commits — 228 feature/other, 72 fixes
By area
- (repo) — 95 commits
- (root) — 31 commits
- pkg/runtime — 18 commits
- pkg/http — 16 commits
- pkg/grpc — 15 commits
- tests/apps — 12 commits
- .github/workflows — 11 commits
- pkg/resiliency — 9 commits
- pkg/injector — 8 commits
- docs/release_notes — 7 commits
- tests/perf — 7 commits
- charts/dapr — 6 commits
- pkg/diagnostics — 6 commits
- tests/test-infra — 6 commits
- pkg/actors — 5 commits
- pkg/operator — 5 commits
- tests/e2e — 5 commits
- pkg/channel — 4 commits
- pkg/components — 4 commits
- cmd/daprd — 3 commits
Notable commits
- fix: Attempting to fix #4784 Or at least add some more logging!
- fix: Block calls from sidecar to app when app is not healthy - fix 4883 (#4990)
- fix: Fix 2 flaky unit tests (#5012)
- fix: Fix cleanup pipeline (#4762)
- fix: Fix component name for aws dynamodb (#5095)
- fix: Fix data race in state config (#5143)
- fix: Fix dead letter topic keeping message in original topic (#4783)
- fix: Fix failing UT for configuration api Unsubscribe (#5186)
- fix: Fix log format (#4885)
- fix: Fix missing OwnerReference when updating dapr service (#4850)
- fix: Fix missing components in Metadata API result. (#5052)
- fix: Fix mtlsWorkloadCertRotated metric
- fix: Fix perf tests not building (#5096)
- fix: Fix release noted to include 1845 from contrib (#4888)
- fix: Fix resiliency for .NET Actor invocation (#4838)
- fix: Fix resiliency for .NET Actor invocation (#4838)
- fix: Fix resiliency logic in gRPC proxying (#4829)
- fix: Fix resiliency logic in gRPC proxying (#4829)
- fix: Fix resiliency parsing and add logging (#4806)
- fix: Fix some method comments (#4918)
- …and 280 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
flawlesscode254/dapr was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 5 August 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit e899c5340f3e071d31baa073c9b672cc67821eb7 — the exact code this score is about.
- Scored under rubric-2026.08.19 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer latest.