Skip to content

Code map

Every package and file of the repository with its types and functions, and the first sentence of each one's doc comment. Unexported (lowercase) names are internal to their package. Test files are listed with their test functions. The architecture chapters explain how these fit together.

Go packages

Package Files Lines What it is
api/v1alpha1 3 292 Package v1alpha1 contains the App API: one App per deployed application.
cmd/rendimiento 2 456 Command rendimiento runs the whole platform in one process: API and UI, CI workers and the App controller.
hack/codemap 1 271 Command codemap writes the book's code reference (docs/content/reference/ code-map.md): every package, file, type and function of the repository, with the first sentence of its doc comment.
hack/undoc 1 53 Command undoc lists exported Go declarations without a doc comment, the ones make docs-codemap would show with an empty summary.
internal/addon 5 1056 Package addon renders add-ons (Helm charts or kustomize folders in git) into Kubernetes objects.
internal/analytics 2 600 Package analytics reads visitor statistics from Umami, so each app's page shows who visits it without leaving rendimiento.
internal/api 14 3344 Package api serves the REST + SSE API, GitHub webhooks, login, one-click GitHub App setup, and the embedded web UI.
internal/catalog 2 887 Package catalog lists the services apps can integrate with: what each one is, where it comes from (a rendimiento app, ArgoCD, Helm, kubectl), what it exposes (addresses, ports, public URLs, LAN IPs), how to call it from rendimiento.yaml, and which workloads already do.
internal/controller 7 2738 Package controller reconciles App objects into running workloads: the GitOps half of rendimiento.
internal/detect 2 430 Package detect inspects a repository tree and guesses how each deployable service in it is built, tested and served.
internal/dns 4 770 Package dns manages the public DNS record for each app domain.
internal/environment 6 1604 Package environment inspects the cluster and integrations rendimiento depends on and reports what is installed, what is missing and how to fix it, plus node and workload health.
internal/events 2 80 Package events fans out live updates (step status, log lines) to UI subscribers over SSE.
internal/generate 2 278 Package generate turns detection results into a proposed rendimiento.yaml plus any files the repo is missing (Dockerfiles).
internal/github 5 1164 Package github talks to GitHub as a GitHub App: short-lived installation tokens instead of personal access tokens, webhooks delivered for every installed repo, check runs for CI status and PRs for onboarding.
internal/i18n 3 727 Package i18n translates the platform's messages for people: the API's answers to a Spanish browser, and alert emails.
internal/logarchive 2 308 Package logarchive moves the step logs of finished CI runs out of Postgres into object storage (MinIO or any S3), gzip-compressed, and reads them back for the UI.
internal/notify 2 447 Package notify emails the platform's owner about what needs attention: releases rolled back by verification, failed runs on the default branch, outages and recoveries.
internal/pipeline 7 1847 Package pipeline plans and executes CI runs.
internal/platform 8 3206 Package platform is the orchestration core: it turns GitHub events into CI runs, successful default-branch runs into releases, and releases into App objects that the controller deploys.
internal/problems 2 278 Package problems keeps the platform's own warnings and errors for the Problems page: a slog handler passes every record on to the real log and also queues warnings and errors; a Recorder stores them, folding repeats of the same problem into one row with a count.
internal/render 3 1169 Package render turns an app's spec plus its released images into the Kubernetes objects that run it.
internal/renovate 2 791 Package renovate is the Renovate add-on: it keeps the dependencies of the apps it is switched on for up to date by running Renovate on a schedule.
internal/ruta 2 910 Package ruta is the MCP endpoint (/mcp) through which agents read and write la Ruta: what the platform's people and agents know, kept in the platform rather than in any one agent's session.
internal/spec 2 1819 Package spec defines rendimiento.yaml, the only file an app repo needs.
internal/store 12 2712 Package store persists apps, CI runs, step logs, releases and sessions in Postgres.
internal/uptime 2 650 Package uptime checks every app's services once a minute and keeps the results: whether each answered, how fast, and when it was down.
templates 1 7 Package templates embeds the Dockerfile templates used for repos that do not ship one.
web 1 22 Package web embeds the built UI (npm run build → web/dist).

api/v1alpha1

Package v1alpha1 contains the App API: one App per deployed application.

api/v1alpha1/addon_types.go

174 lines

Name Kind Summary
AddonSpec struct AddonSpec is software rendimiento installs and keeps in sync, rendered from a Helm chart or from Kubernetes manifests (a kustomize folder) in git.
AddonSource struct AddonSource is exactly one of Helm or Git.
HelmSource struct HelmSource is a chart in a classic (index.yaml) Helm repository.
GitSource struct GitSource is a folder of Kubernetes manifests (or a kustomization) in a GitHub repository.
AddonPhase type AddonPhase summarizes an add-on's state for people: Synced, OutOfSync, Blocked, Error, Suspended.
ObjectRef struct ObjectRef identifies one object the add-on manages.
PreviewItem struct PreviewItem is what syncing would do to one object.
Preview struct Preview is what the next sync would do, from a server-side dry run of every object.
HookInfo struct HookInfo describes one Helm hook of the chart and the events it runs at.
HookRun struct HookRun records one execution of a Helm hook.
AddonStatus struct AddonStatus is what the controller last observed and did.
Addon struct Addon is software installed from a Helm chart or git manifests.
AddonList struct +kubebuilder:object:root=true
init func

api/v1alpha1/app_types.go

102 lines

Name Kind Summary
AppSpec struct AppSpec is the desired state: the repo's rendimiento.yaml plus the release pointer (one image per service) chosen by the pipeline or a rollback.
Phase type Phase summarizes an app's state: WaitingForBuild, Progressing, Healthy, Degraded, Suspended or Error.
ServiceStatus struct ServiceStatus is the observed state of one service (or of a database/cache run for needs:).
AppStatus struct AppStatus is what the controller last observed about an app.
App struct App is one application managed by rendimiento.
AppList struct +kubebuilder:object:root=true
init func

api/v1alpha1/groupversion.go

16 lines

cmd/rendimiento

Command rendimiento runs the whole platform in one process: API and UI, CI workers and the App controller.

cmd/rendimiento/logr.go

9 lines

Name Kind Summary
toLogr func

cmd/rendimiento/main.go

447 lines

Name Kind Summary
env func
main func
run func
ptr func
splitList func splitList splits a comma- or space-separated setting.

hack/codemap

Command codemap writes the book's code reference (docs/content/reference/ code-map.md): every package, file, type and function of the repository, with the first sentence of its doc comment.

hack/codemap/main.go

271 lines

Name Kind Summary
symbol struct
file struct
main func
writeFile func
goFile func
recvType func
tsFile func
firstSentence func firstSentence returns the first sentence of a comment, on one line.
cell func
anchor func

hack/undoc

Command undoc lists exported Go declarations without a doc comment, the ones make docs-codemap would show with an empty summary.

hack/undoc/main.go

53 lines

Name Kind Summary
main func

internal/addon

Package addon renders add-ons (Helm charts or kustomize folders in git) into Kubernetes objects.

internal/addon/catalog.go

89 lines

Name Kind Summary
Field struct Field is one setting a catalog entry offers in its install form.
CatalogEntry struct CatalogEntry is something that can be installed with a few settings.
HelmSourceTemplate struct HelmSourceTemplate is a catalog entry's chart and default version.

internal/addon/gitops.go

375 lines

Name Kind Summary
Definition struct Definition is one add-on as written in addons/.yaml.
ParseDefinition func ParseDefinition reads and validates one addons/.yaml; unknown fields are errors.
(*Definition) Validate method Validate checks names and that exactly one source (helm or git) is set.
(*Definition) Marshal method Marshal writes the definition as it is stored in git.
(*Definition) Spec method Spec is the Addon spec the definition asks for.
GitHubFetcher struct GitHubFetcher reads repositories through the GitHub App.
(GitHubFetcher) Fetch method Fetch implements GitFetcher through the GitHub App installation that owns repo.
Syncer struct Syncer makes the Addon objects match the definitions in the gitops repo.
SyncResult struct SyncResult is the outcome of one pass of Syncer.Sync, shown on the Add-ons page.
(*Syncer) init method
(*Syncer) Trigger method Trigger asks the loop to sync soon (e.g.
(*Syncer) Last method Last returns the most recent sync's outcome.
(*Syncer) Loop method Loop syncs every few minutes and whenever triggered, until ctx ends.
(*Syncer) Sync method Sync makes the Addon objects match the definitions at the head of the gitops repository: it creates and updates them, and deletes those whose file is gone (their software keeps running unless marked for uninstall).
(*Syncer) read method
(*Syncer) apply method apply creates or updates one Addon; it reports whether anything changed.
equalSpec func

internal/addon/render.go

358 lines

Name Kind Summary
GitFetcher interface GitFetcher reads a folder of a GitHub repository at a commit.
Result struct Result is a rendered add-on.
Hook struct Hook is one Helm hook: an object (usually a Job) run at lifecycle events.
(Hook) Has method Has reports whether the hook runs at event.
(Hook) HookPolicy method HookPolicy reports whether the hook has a delete policy; hooks without one get Helm's default, before-hook-creation.
Renderer struct Renderer renders add-ons.
(*Renderer) Render method Render produces the add-on's objects (and hooks) from its Helm or git source.
(*Renderer) renderHelm method
(*Renderer) chart method chart downloads a chart from a classic (index.yaml) Helm repository.
(*Renderer) get method
(*Renderer) renderGit method
Build func Build renders a folder: kustomize if it has a kustomization file, otherwise every YAML file in it.
Decode func Decode splits multi-document YAML into objects, expanding Lists and skipping empty documents.

internal/addon/gitops_test.go

57 lines · tests

Name Kind Summary
TestDefinition func

internal/addon/render_test.go

177 lines · tests

Name Kind Summary
TestRenderHelm func
TestRenderGitKustomize func
TestBuildPlainManifests func

internal/analytics

Package analytics reads visitor statistics from Umami, so each app's page shows who visits it without leaving rendimiento.

internal/analytics/umami.go

456 lines

Name Kind Summary
Umami struct Umami is a client for the Umami API (v2 and v3), signed in as one user.
cached struct
Website struct Website is a site Umami counts visits for.
Stats struct Stats are the totals of a period.
Point struct Point is one bucket of a series: its start and its count.
Metric struct Metric is one row of a top list (a path, a referrer, a country code).
Report struct Report is everything the Visits tab shows for one website.
(*Umami) client method
(*Umami) login method
(*Umami) get method get calls a read-only endpoint, signing in first and again when the token has expired.
remember func remember returns a cached answer for key, or computes and keeps it.
page struct
(*Umami) Websites method Websites lists the sites the user can see: its own and its teams'.
num type num reads a JSON number that may come as a string (bigint columns) or null.
(*num) UnmarshalJSON method
rawStats struct
(rawStats) stats method
xy struct
Period struct Period is the window a report covers, bucketed by hour or by day.
(*Umami) Report method Report gathers a website's numbers for the period, in parallel.
(*Umami) Totals method Totals are a website's numbers for a period and for the one before it: the dashboard's summary, one call per site.
series func series turns Umami's sparse buckets into one point per hour or day of the period, zeros included, so a chart has no holes.
truncate func
next func
parseBucket func parseBucket reads "2026-10-06 13:00:00" (local to the time zone asked for) or "2026-10-06T13:00:00Z" (UTC).
Host func Host normalizes a website domain or an app host for matching: lower case, no scheme, port, path or leading "www.".
Match func Match returns the websites whose domain is one of hosts.

internal/analytics/umami_test.go

144 lines · tests

Name Kind Summary
TestUmamiReport func
TestHost func

internal/api

Package api serves the REST + SSE API, GitHub webhooks, login, one-click GitHub App setup, and the embedded web UI.

internal/api/addons.go

250 lines

Name Kind Summary
addonView struct addonView is an add-on as the UI shows it.
addonApp struct
(*Server) renovateView method
(*Server) listAddons method
(*Server) getAddon method
(*Server) putAddon method
(*Server) startAddonRun method
(*Server) listAddonRuns method
(*Server) getAddonRun method
(*Server) appAddons method appAddons is the app page's view: its switch and what the last run did.
(*Server) putAppAddon method

internal/api/credentials.go

57 lines

Name Kind Summary
SecretCredentials struct SecretCredentials stores the GitHub App credentials in a Kubernetes Secret.
(*SecretCredentials) Load method Load returns the GitHub App's credentials, or nil before setup has run.
(*SecretCredentials) Save method Save stores the GitHub App's credentials (created or replaced).

internal/api/delivery.go

49 lines

Name Kind Summary
DeliveryReport struct DeliveryReport is the dashboard's delivery health: the last 30 days, the 30 before them, and twelve weeks of history.
(*Server) delivery method

internal/api/i18n.go

88 lines

Name Kind Summary
localized func localized translates the JSON answers of /api/ for a browser that asks for Spanish (Accept-Language).
translateJSON func translateJSON walks a decoded JSON value; key is the object key the value sits under (array elements inherit it, so "details": [...] translates).
bufferedWriter struct bufferedWriter holds a handler's answer so it can be translated.
(*bufferedWriter) Header method
(*bufferedWriter) WriteHeader method
(*bufferedWriter) Write method

internal/api/installed.go

343 lines

Name Kind Summary
installedView struct installedView summarizes an installed add-on.
view func
(*Server) addonCatalog method
(*Server) listInstalled method
(*Server) getInstalled method
owner func
(*Server) putInstalled method putInstalled installs or changes an add-on by committing its definition to the gitops repository; the sync then applies it.
(*Server) commitDefinition method
(*Server) gitopsClient method
(*Server) syncInstalled method syncInstalled asks a manual-sync add-on to apply its pending changes.
(*Server) deleteInstalled method deleteInstalled removes the definition from git.
deepMerge func deepMerge copies src into dst, merging nested maps.
(*Server) patchInstalled method patchInstalled flips switches in an add-on's definition (suspend, allow adoption changes) and commits it.

internal/api/logs.go

54 lines

Name Kind Summary
(*Server) archivedLog method archivedLog reads a step log from the log archive, or explains why it cannot: expired by the retention rule, or the archive is unreachable.
(*Server) releaseTaskLog method releaseTaskLog serves the log of a release's post-deploy task.

internal/api/notifications.go

30 lines

Name Kind Summary
(*Server) testNotification method testNotification sends a sample email now, so the setup can be checked from the Environment page.

internal/api/problems.go

61 lines

Name Kind Summary
ProblemList struct ProblemList is the Problems page: what went wrong in the platform in the last 30 days, newest first, and how many problems are open.
(*Server) listProblems method
(*Server) problemCount method problemCount is the navigation badge's number.
(*Server) dismissProblem method

internal/api/public.go

200 lines

Name Kind Summary
(*Server) StatsHandler method StatsHandler serves only GET /api/public/stats: for an internal-only listener (STATS_LISTEN) that the public ingress does not route, so the numbers reach the cluster's own pages but not the internet.
PublicStats struct PublicStats is what GET /api/public/stats returns: aggregate numbers for a public page (a portfolio, a status page).
publicSite struct
publicNode struct
publicCluster struct
publicCache struct publicCache keeps the last answer for a minute, so visitors cannot make the platform recompute it on every page view.
(*Server) publicStats method publicStats serves PublicStats when PublicStats is on (no login needed).
(*Server) buildPublicStats method
PublicActivity struct PublicActivity is what GET /api/public/activity returns, for the welcome page: the runs going on now and the latest releases, by app name only (no repositories, commits, branches, messages or errors).
activityCache struct activityCache keeps the last answer for 15 seconds.
(*Server) publicActivity method

internal/api/reliability.go

77 lines

Name Kind Summary
releaseMark struct
reliabilityView struct
(*Server) reliability method reliability returns an app's uptime checks over a range (24h, 7d or 30d): per check, uptime, response times and chart buckets; its outages; and its releases, to mark on the charts.

internal/api/ruta.go

225 lines

Name Kind Summary
RutaInput struct RutaInput is what a person writes or changes on the Ruta page.
(*RutaInput) check method
(*Server) listRuta method
(*Server) addRuta method
rutaID func
(*Server) updateRuta method
(*Server) archiveRuta method
RutaActivity struct RutaActivity is the agents' side of the Ruta page: their turns and what they did.
(*Server) rutaActivity method
NewAgentKey struct NewAgentKey asks for a key.
CreatedAgentKey struct CreatedAgentKey is the answer: the token appears here once and never again.
(*Server) listAgentKeys method
(*Server) createAgentKey method
(*Server) revokeAgentKey method

internal/api/server.go

1183 lines

Name Kind Summary
CredentialStore interface CredentialStore persists the GitHub App credentials (a Kubernetes Secret in production).
Server struct Server holds everything the HTTP API needs; Handler returns its routes.
Analytics interface Analytics is where visitor numbers come from (Umami).
(*Server) Handler method Handler returns the HTTP handler: public routes (health, webhooks, login, setup), session-protected /api routes and the embedded UI.
(*Server) guard method guard adds security headers and rejects cross-site state changes.
sameOrigin func
hashToken func
randomToken func
(*Server) requireSession method
(*Server) allowed method
(*Server) secureCookies method
(*Server) login method
(*Server) callback method
(*Server) logout method
(*Server) setupStatus method
(*Server) checkSetupToken method
(*Server) setupStart method
(*Server) setupCallback method
(*Server) webhook method
(*Server) installations method
(*Server) repos method
(*Server) zones method
(*Server) propose method
(*Server) services method
(*Server) environment method
(*Server) dnsSync method dnsSync re-detects the public IP now and repoints records that follow it.
(*Server) migration method migration tells the wizard whether an app name matches a namespace that already runs something (so it can be migrated instead of duplicated).
appView struct
(*Server) downChecks method downChecks maps each app to its checks with an open outage.
(*Server) view method
(*Server) listApps method
(*Server) createApp method
(*Server) app method
(*Server) getApp method
(*Server) deleteApp method
(*Server) deleteImpact method
(*Server) disconnectApp method disconnectApp stops managing the app but leaves it running.
(*Server) listRuns method
(*Server) triggerRun method
(*Server) listReleases method
(*Server) rollback method
resourceNode struct Resource tree for the Argo-style view.
(*Server) resources method
deploymentHealth func
podNode func
ptrOr func
(*Server) putSecret method putSecret writes app secret values straight into the app's namespace; they are never stored in git, in Postgres, or returned by the API.
(*Server) runID method
(*Server) getRun method
(*Server) cancelRun method
(*Server) stepLog method
(*Server) runEvents method
(*Server) appEvents method
(*Server) sse method
(*Server) ui method
writeJSON func
writeJSONStatus func writeJSONStatus sets headers before the status line; headers set after WriteHeader are silently dropped.
readJSON func
httpError func

internal/api/visits.go

168 lines

Name Kind Summary
VisitsView struct VisitsView is an app's Visits tab: one report per Umami website whose domain is one of the app's hostnames.
appHosts func appHosts are every hostname an app's services answer on.
(*Server) visitTZ method
umamiError func umamiError answers a failed Umami call: a refused login is a setup problem, anything else that Umami is unreachable.
(*Server) visits method
AppVisits struct AppVisits is one app's line in the dashboard summary.
VisitsSummary struct VisitsSummary is the dashboard's visitors panel: the last 7 days of every app that Umami counts, and the 7 before them.
addStats func
(*Server) visitsSummary method

internal/api/server_test.go

559 lines · tests

Name Kind Summary
TestAuthBoundaries func
TestWebhookSignature func
TestSetupRequiresToken func
TestSecretsAndDelete func
TestUIFallback func
TestJSONStatusKeepsContentType func Regression: 201 responses were sent without Content-Type because the header was set after WriteHeader, and the UI then read them as text.
TestMigrationCheckByName func
TestPublicStats func Public stats are off unless turned on, need no login when on, allow only the configured origins, and say nothing private.
TestDeliveryReport func The dashboard's delivery report needs a login and has both periods and twelve weeks.
TestProblemsAPI func The Problems page needs a login; problems can be listed, counted and dismissed.
TestSpanishAnswers func A browser that asks for Spanish gets the platform's messages in Spanish; names and English requests are left alone.
TestRutaAPI func
TestVisitsAPI func
TestPublicActivity func The welcome page's activity is off unless asked for, and names only the app.

internal/catalog

Package catalog lists the services apps can integrate with: what each one is, where it comes from (a rendimiento app, ArgoCD, Helm, kubectl), what it exposes (addresses, ports, public URLs, LAN IPs), how to call it from rendimiento.yaml, and which workloads already do.

internal/catalog/catalog.go

698 lines

Name Kind Summary
Group type Group is which tab a service appears under on the Services page.
Origin struct Origin says where a service comes from.
Image struct Image is a container image behind a service.
Port struct Port is one port a Service exposes.
Consumer struct Consumer is a workload whose environment points at the service.
Entry struct Entry is one service in the catalog: what it is, where it comes from, what it exposes, how to connect, and who calls it.
Catalog struct Catalog is every service in the cluster, grouped and sorted for the Services page.
Builder struct Builder assembles the catalog from the cluster and caches it for TTL.
(*Builder) Get method Get returns a cached catalog unless it is older than TTL or refresh is set.
snapshot struct
(*Builder) build method
assemble func assemble builds the catalog from a snapshot of the cluster.
appService struct
groupRank func
appOrigin func
foreignOrigin func foreignOrigin works out who deployed something rendimiento does not manage.
metav1Object interface
firstNonEmpty func
guessProtocol func guessProtocol names the protocol from the port name or well-known number.
lanAddress func lanAddress is where a LoadBalancer Service answers on the local network (ip:port, empty until the load balancer assigns an IP), and a link to open when the protocol is a web one.
address func
suggestEnv func
snippet func snippet is the rendimiento.yaml fragment for a service that calls this one.
withCredentials func
publicURLs func
selected func
podReady func
podImages func
imageLink func imageLink points at an image's public page (Docker Hub, Quay, GitHub).
categorize func
imageRepo func imageRepo drops the registry host, tag and digest: what the image is ("dustynv/ollama"), not where it is stored ("registry.example.lan:5000").
workload struct
collectWorkloads func
consumers func consumers finds workloads whose plain environment values point at svc: by its cluster DNS name from anywhere, by its short name from the same namespace, or by its LAN address.

internal/catalog/catalog_test.go

189 lines · tests

Name Kind Summary
TestAssemble func
TestImageLink func
TestCategorize func
TestLANAddress func

internal/controller

Package controller reconciles App objects into running workloads: the GitOps half of rendimiento.

internal/controller/addon_controller.go

506 lines

Name Kind Summary
AddonReconciler struct AddonReconciler installs add-ons and keeps them in sync.
(*AddonReconciler) Reconcile method Reconcile renders an add-on, previews it, applies it (with hooks, on install and upgrade) unless a gate stops it, prunes what left the source, and records the result.
(*AddonReconciler) prepare method prepare sets the namespace of namespaced objects that have none and labels every object with the add-on's name.
(*AddonReconciler) prepareOne method prepareOne namespaces and labels one object.
applyRank func applyRank orders CRDs and namespaces before the objects that need them.
(*AddonReconciler) preview method preview dry-runs every object and records what a sync would change.
normalize func normalize renders an object without the fields that always differ between a live object and a dry run, or that rendimiento adds itself.
unifiedDiff func
(*AddonReconciler) applyAll method applyAll server-side applies the objects in order, waiting for CRDs to be established before the objects that use them.
(*AddonReconciler) waitCRDs method
established func
(*AddonReconciler) prune method prune deletes objects that were in the previous inventory but are no longer rendered, except kinds that must never be deleted.
(*AddonReconciler) deleteRef method
(*AddonReconciler) finalize method finalize runs when an Addon is deleted: by default everything it installed keeps running; with the uninstall annotation it is removed (except kinds that must never be deleted).
(*AddonReconciler) saveStatus method
ref func
refKey func refKey identifies an object regardless of API version.
refs func
fromUnstructured func
(*AddonReconciler) SetupWithManager method SetupWithManager registers the controller; it reacts to spec and annotation changes, and resyncs periodically.

internal/controller/addon_hooks.go

176 lines

Name Kind Summary
lifecycle func lifecycle returns what this sync is in Helm's terms: "install" for the first sync of a new add-on, "upgrade" when the chart, version, values or release name changed since the last apply, and "" otherwise (an adoption of something already installed, or a resync with nothing new).
(*AddonReconciler) runHooks method runHooks runs, in weight order, every hook for event (e.g.
(*AddonReconciler) hookDone method hookDone records a hook's outcome and applies its delete policy.
(*AddonReconciler) waitHook method waitHook waits for a Job to complete or a Pod to succeed; other kinds (a ConfigMap or ServiceAccount a hook Job uses) are done once created.
(*AddonReconciler) deleteAndWait method deleteAndWait removes an object (and a Job's pods) and waits until it is gone.
hookInfo func
countHooks func

internal/controller/app_controller.go

648 lines

Name Kind Summary
AppReconciler struct AppReconciler turns App objects into running workloads, DNS records and status.
(*AppReconciler) Reconcile method Reconcile brings one app's objects in line with its App object, or cleans up after it is deleted.
(*AppReconciler) sync method
(*AppReconciler) checkOwnership method checkOwnership refuses to take over a namespace or hostname that belongs to something else, e.g.
(*AppReconciler) migrate method migrate runs one step of an adoption: new workloads are already applied; once they are ready, traffic moves from the legacy ingresses to ours and the old workloads behind them are removed.
selects func
(*AppReconciler) apply method
(*AppReconciler) applyIngresses method applyIngresses applies ingresses in several passes.
(*AppReconciler) takeover method takeover replaces, once, a same-named object that rendimiento does not manage yet (e.g.
(*AppReconciler) prune method prune deletes workloads, services and ingresses of this app that are no longer in the spec.
appendIfStale func
(*AppReconciler) lanURL method lanURL is where the service's lan: Service answers on the local network, from the address the load balancer assigned ("" until then).
(*AppReconciler) certReady method
(*AppReconciler) finalize method
(*AppReconciler) crashLooping method crashLooping reports a pod of the deployment stuck restarting, e.g.
deploymentCondition func
(*AppReconciler) SetupWithManager method SetupWithManager registers the controller; changes to the objects an app owns trigger a reconcile (self-healing).

internal/controller/needs.go

134 lines

Name Kind Summary
(*AppReconciler) ensureNeedSecrets method ensureNeedSecrets creates the credentials for the app's database and cache the first time they are needed.
(*AppReconciler) ensureSecret method
(*AppReconciler) serviceURLs method serviceURLs looks up the services the app's services need and returns the address to inject for each: its app port (not the port-80 alias), by short name within the app's namespace, by cluster DNS name otherwise.
isOwnService func
address func

internal/controller/addon_controller_test.go

252 lines · tests

Name Kind Summary
TestAddonLifecycle func

internal/controller/addon_hooks_test.go

145 lines · tests

Name Kind Summary
TestAddonHooks func

internal/controller/app_controller_test.go

877 lines · tests

Name Kind Summary
TestAppLifecycle func
TestRefusesForeignNamespaceAndHost func
TestAdoptExistingDeployment func Migration of an app deployed another way (ArgoCD): the namespace and its secret are kept, new pods start next to the old ones, and traffic moves only once they are ready.
TestAdoptStillBlocksOtherNamespaces func Adoption only covers the app's own namespace: a host served elsewhere still blocks.
TestAdoptInPlace func In-place adoption (simplerfc): same-named Deployment, Service and Ingress deployed by ArgoCD are taken over without being recreated; the existing volume claim is reused and nothing the old owner set survives.
TestJobsAdoptAndPrune func Scheduled jobs: an existing CronJob (from ArgoCD) is taken over in place, and a job removed from rendimiento.yaml is pruned.
TestAdoptRenamedIngressWithAliases func stockpulse's ingress: a differently named ingress kept by name, several hosts on two certificates, extra nginx settings; aliases get DNS and count for conflicts.
TestAdoptWithPathRoutes func wellness: /api moves from the website's ingress to the API's ingress; both legacy ingresses are taken over in place under their existing names.
TestDisconnectKeepsDNS func Disconnecting keeps the app's DNS records: its workloads keep serving.
TestStuckRolloutIsNotHealthy func A rollout where the new pod crash-loops while an old pod keeps serving must not be reported Healthy (wellness-api with a broken image).
TestSharedNamespace func jobsentry: the namespace belongs to ArgoCD (linguistic-ai stays there); rendimiento runs its services in it without touching the namespace.
TestAppNeeds func
TestAppLANURL func

internal/detect

Package detect inspects a repository tree and guesses how each deployable service in it is built, tested and served.

internal/detect/detect.go

321 lines

Name Kind Summary
Language type Language is a detected language or runtime family.
Result struct Result describes one deployable service found in the repo.
Detect func Detect returns the services found at the repo root or, when the root is not itself a service, in its immediate subdirectories (monorepos).
detectDir func
detectGo func
packageJSON struct
detectNode func detectNode returns false for packages that are not deployable services (mobile apps, libraries without a start or build script).
nodeMajor func
installCmd func
detectPython func
pythonEntrypoint func
detectJava func
exposedPort func
exists func
detectNeeds func
read func
orNone func

internal/detect/detect_test.go

109 lines · tests

Name Kind Summary
TestDetect func
TestDetectNeeds func

internal/dns

Package dns manages the public DNS record for each app domain.

internal/dns/ddns.go

244 lines

Name Kind Summary
ddnsState struct
DDNSStatus struct DDNSStatus is shown on the environment page.
(*Cloudflare) auto method
(*Cloudflare) DDNSStatus method DDNSStatus reports the last public-IP check and change, for the Environment page.
(*Cloudflare) target method target is what new records point at: the configured value, or the detected public IP in auto mode (detecting it on first use).
SyncResult struct SyncResult reports what one dynamic DNS pass did.
(*Cloudflare) Sync method Sync detects the public IP and repoints every A record that follows it: records rendimiento created and records tagged with DDNSTag.
(*Cloudflare) aRecords method aRecords lists every A record in a zone, following pagination.
(*Cloudflare) Run method Run keeps records following the public IP until ctx ends.
PublicIPv4 func PublicIPv4 returns this network's public IPv4 address.
fetchIP func
ParseIPResponse func ParseIPResponse accepts either a bare address or Cloudflare's trace format, and only returns a public IPv4 address, so a misconfigured proxy or a private address can never be published in DNS.

internal/dns/dns.go

297 lines

Name Kind Summary
Provider interface Provider creates and removes the record pointing a host at the cluster's ingress.
Description struct Description is a provider's self-reported identity and health.
Noop struct Noop is used when no DNS provider is configured; records are managed by hand.
(Noop) Ensure method Ensure does nothing: records are managed by hand.
(Noop) Remove method Remove does nothing.
(Noop) Zones method Zones returns none.
(Noop) Describe method Describe reports that no DNS provider is configured.
Cloudflare struct Cloudflare implements Provider with the Cloudflare v4 API and a scoped API token (Zone:Read + DNS:Edit).
comment func
record struct
(*Cloudflare) recordType method
(*Cloudflare) Ensure method Ensure creates or updates the record for host, marked as managed for app; it refuses to change a record another app or a person created.
(*Cloudflare) Describe method Describe verifies the API token and lists the zones it can manage.
(*Cloudflare) Remove method Remove deletes host's record if it is managed for app.
(*Cloudflare) Zones method Zones lists the zones the token can edit, for the domain picker.
(*Cloudflare) zoneFor method zoneFor finds the most specific zone that contains host.
(*Cloudflare) find method
(*Cloudflare) do method

internal/dns/ddns_test.go

96 lines · tests

Name Kind Summary
TestParseIPResponse func
TestSyncFollowsPublicIP func
TestFixedTargetSyncIsNoop func

internal/dns/dns_test.go

133 lines · tests

Name Kind Summary
TestEnsureCreateUpdateRemove func
TestNeverTouchesForeignRecords func
TestDescribe func

internal/environment

Package environment inspects the cluster and integrations rendimiento depends on and reports what is installed, what is missing and how to fix it, plus node and workload health.

internal/environment/backups.go

161 lines

Name Kind Summary
longhornList func
(*Checker) checkBackups method checkBackups reports which Longhorn volumes a backup job covers, which volumes in use are not covered, and whose last backup is too old.

internal/environment/checks.go

577 lines

Name Kind Summary
checkFunc type
(*Checker) checks method
(*Checker) checkAPI method
checkNodes func
checkMetrics func
imageVersion func imageVersion returns the tag of an image reference, without any digest.
findDeployment func findDeployment returns the first deployment running an image containing substr.
deploymentReady func
firstImage func
(*Checker) checkIngress method
(*Checker) checkCertManager method
(*Checker) checkIssuer method
checkCertificates func
(*Checker) checkStorage method
(*Checker) checkBuildkit method
(*Checker) checkRegistry method
(*Checker) checkBuildNamespace method
(*Checker) checkBuildIsolation method checkBuildIsolation reports whether CI pods, which run repo code, are fenced off from the rest of the cluster by a NetworkPolicy.
(*Checker) checkDNS method
(*Checker) checkLogArchive method
(*Checker) checkAnalytics method
(*Checker) checkNotifications method
(*Checker) checkGitHub method
(*Checker) checkDatabase method
(*Checker) providers method providers describes each swappable slot, its active option and the roadmap.

internal/environment/cluster.go

252 lines

Name Kind Summary
snapshot struct snapshot is read once per report and shared by the checks.
Distribution func Distribution identifies the Kubernetes flavor from the server version and node metadata.
(*Checker) snapshot method
podProblems func podProblems lists pods that are failing or stuck.
(*Checker) certificateProblems method

internal/environment/environment.go

293 lines

Name Kind Summary
Status type Status is the state of one check or provider.
(Status) rank method rank orders statuses from best to worst for roll-ups.
worst func
Category type Category groups checks on the Environment page.
Check struct Check is one requirement and its state.
Option struct Option is one choice for a provider slot; unavailable ones are on the roadmap.
Provider struct Provider is one swappable slot: where apps run, who serves DNS, etc.
Node struct Node is one cluster node with its capacity, usage and health.
Problem struct Problem is an unhealthy workload or certificate somewhere in the cluster.
ClusterInfo struct ClusterInfo summarizes the cluster (version, node and pod counts).
Report struct Report is everything the Environment page shows.
ddnsReporter interface ddnsReporter is implemented by DNS providers that support dynamic DNS.
(*Checker) Invalidate method Invalidate drops the cached report, e.g.
Config struct Config is what the platform expects from the environment.
Pinger interface Pinger is satisfied by the store.
Checker struct Checker builds environment reports and caches them for TTL.
(*Checker) Report method Report returns a fresh or cached environment report.
(*Checker) build method

internal/environment/backups_test.go

70 lines · tests

Name Kind Summary
TestCheckBackups func
TestCheckBackupsWithoutLonghorn func

internal/environment/environment_test.go

251 lines · tests

Name Kind Summary
TestFullyInstalledCluster func
TestBareCluster func
TestReportIsCached func
TestDistribution func

internal/events

Package events fans out live updates (step status, log lines) to UI subscribers over SSE.

internal/events/hub.go

55 lines

Name Kind Summary
Event struct Event is one live update sent to UI subscribers.
Hub struct Hub is an in-process publish/subscribe fan-out keyed by topic ("run/42", "app/shop").
NewHub func NewHub returns an empty hub.
(*Hub) Subscribe method Subscribe returns a channel for topic and a cancel func that must be called.
(*Hub) Publish method Publish sends e to every subscriber of topic without blocking: a subscriber that is behind misses it and refetches on reconnect.

internal/events/hub_test.go

25 lines · tests

Name Kind Summary
TestHub func

internal/generate

Package generate turns detection results into a proposed rendimiento.yaml plus any files the repo is missing (Dockerfiles).

internal/generate/generate.go

197 lines

Name Kind Summary
Input struct Input is what generation works from: the repo, its files and what detection found.
Plan struct Plan is what the wizard shows and, once confirmed, commits in a PR.
Generator interface Generator proposes a rendimiento.yaml and missing files for a repo.
Templates struct Templates is the deterministic, rule-based generator.
(Templates) Generate method Generate proposes one service per detected directory and a Dockerfile from templates for those without one.
pickFrontDoor func pickFrontDoor chooses which service gets the bare . domain: the first UI-like service, else the first service.
sizeFor func
dfData struct
dockerfile func
pythonCmd func pythonCmd returns the container CMD (JSON form) and any server package that must be installed alongside the app's own requirements.
Slug func Slug converts a repo or directory name into a DNS label.

internal/generate/generate_test.go

81 lines · tests

Name Kind Summary
TestGoRepoGetsDockerfile func
TestExistingDockerfileIsKept func
TestMonorepoDomainsAndPython func
TestSlug func

internal/github

Package github talks to GitHub as a GitHub App: short-lived installation tokens instead of personal access tokens, webhooks delivered for every installed repo, check runs for CI status and PRs for onboarding.

internal/github/app.go

289 lines

Name Kind Summary
Credentials struct Credentials are produced once by the manifest flow and stored in a Kubernetes Secret.
App struct App is the GitHub App: it signs JWTs with its private key and exchanges them for installation tokens.
cachedToken struct
New func New parses the App's private key.
(*App) Credentials method Credentials returns what the App was created with.
(*App) base method
(*App) client method
(*App) JWT method JWT authenticates as the app itself (RS256, 9 minute lifetime).
(*App) InstallationToken method InstallationToken returns a cached token for the installation, refreshing it five minutes before expiry.
Installation struct Installation is the App installed on one account (user or organization).
(*App) Installations method Installations lists the accounts the App is installed on.
(*App) Client method Client returns an API client acting as the given installation.
(*App) do method do performs a JSON API call.
APIError struct APIError is a non-2xx response from the GitHub API.
(*APIError) Error method Error implements error.
IsNotFound func IsNotFound reports whether err is a GitHub 404.
VerifyWebhook func VerifyWebhook checks X-Hub-Signature-256 in constant time.
(*App) FreshInstallationToken method FreshInstallationToken mints a new token (valid one hour) instead of reusing a cached one, for jobs that need the full hour, such as Renovate.
(*App) InstallationPermissions method InstallationPermissions are what the account owner granted, e.g.
BotIdentity struct BotIdentity is the app's bot user, as commits and PRs show it: login "[bot]" and a noreply email tied to its user ID.
(*App) Bot method Bot returns the App's bot user, as commits and pull requests show it.

internal/github/client.go

450 lines

Name Kind Summary
Client struct Client makes API calls as one installation.
(*Client) do method
Repo struct Repo is a repository the installation can access.
(*Client) Repos method Repos lists every repo the installation can access.
(*Client) Repo method Repo returns one repository (default branch, visibility).
RepoFS struct RepoFS exposes a commit's tree as a read-only fs.FS.
treeEntry struct
(*Client) FS method FS returns the repository tree at ref as an fs.FS; files are downloaded when opened.
(*RepoFS) Open method Open implements fs.FS.
(*RepoFS) blob method
fileInfo struct
(fileInfo) Name method Name implements fs.FileInfo.
(fileInfo) Size method Size implements fs.FileInfo.
(fileInfo) Mode method Mode implements fs.FileInfo.
(fileInfo) ModTime method ModTime implements fs.FileInfo (unknown, zero).
(fileInfo) IsDir method IsDir implements fs.FileInfo.
(fileInfo) Sys method Sys implements fs.FileInfo.
blobFile struct
(*blobFile) Stat method Stat implements fs.File.
(*blobFile) Read method Read implements fs.File.
(*blobFile) Close method Close implements fs.File.
dirFile struct
(*dirFile) Stat method Stat implements fs.File.
(*dirFile) Read method Read fails: directories cannot be read, only listed.
(*dirFile) Close method Close implements fs.File.
(*dirFile) ReadDir method ReadDir implements fs.ReadDirFile.
PullRequest struct PullRequest is an opened (or existing) pull request.
(*Client) OpenPR method OpenPR commits files on a new branch off base in a single commit and opens a pull request.
CheckRun struct CheckRun is a GitHub check shown on commits and pull requests.
CheckOutput func CheckOutput builds a check run's title and summary.
(*Client) CreateCheckRun method CreateCheckRun starts a check run and returns its ID.
(*Client) UpdateCheckRun method UpdateCheckRun changes a check run's status or conclusion.
(*Client) FileAt method FileAt returns a file at a ref, or IsNotFound.
(*Client) ChangedFiles method ChangedFiles lists files that differ between two commits.
(*Client) BranchSHA method BranchSHA returns the commit a branch points at.
(*Client) PutFile method PutFile creates or updates one file on a branch as a single commit and returns the commit's SHA.
(*Client) DeleteFile method DeleteFile removes one file on a branch as a single commit.
(*Client) fileSHA method

internal/github/holder.go

127 lines

Name Kind Summary
Holder struct Holder holds the current GitHub App, which appears at runtime after the one-click setup, and adapts it to the per-installation calls the platform makes.
(*Holder) Set method Set installs the App (at startup, or after the setup flow).
(*Holder) Get method Get returns the App, or ErrNotConfigured before setup.
(*Holder) client method
(*Holder) FileAt method FileAt reads one file of repo at ref.
(*Holder) RepoFS method RepoFS returns repo's tree at ref as an fs.FS.
(*Holder) OpenPR method OpenPR commits files to branch and opens (or finds) a pull request into base.
(*Holder) CreateCheck method CreateCheck starts a check run on a commit.
(*Holder) UpdateCheck method UpdateCheck updates a check run.
(*Holder) CloneToken method CloneToken returns an installation token for cloning in build pods.
(*Holder) ChangedFiles method ChangedFiles lists files that differ between two commits (for change detection).
(*Holder) BranchSHA method BranchSHA resolves a branch to its head commit.
(*Holder) ForOwner method ForOwner returns an API client for the installation on an account (user or organization), found by the account's login.

internal/github/oauth.go

107 lines

Name Kind Summary
errorsAs func
Manifest func Manifest describes the app GitHub should create.
ConvertManifest func ConvertManifest exchanges the one-time code for the new app's credentials.
(*App) AuthorizeURL method AuthorizeURL is where the login button sends people (GitHub OAuth through the App).
(*App) Login method Login exchanges an OAuth code for the user's login name.
decodeJSON func

internal/github/github_test.go

191 lines · tests

Name Kind Summary
TestJWTIsValidRS256 func
TestInstallationTokenCached func
TestRepoFSDrivesDetection func
TestOpenPRSingleCommit func
TestVerifyWebhook func

internal/i18n

Package i18n translates the platform's messages for people: the API's answers to a Spanish browser, and alert emails.

internal/i18n/es.go

405 lines

internal/i18n/i18n.go

223 lines

Name Kind Summary
Lang type Lang is a language the platform speaks.
M func M formats a message for people.
Parse func Parse reads a language setting or an Accept-Language header: Spanish if it starts with "es", else English.
FromRequest func FromRequest is the language the browser asked for.
pattern struct pattern is one catalog entry, compiled to match finished messages.
verbs func verbs finds the verbs of a format, skipping literal percent signs (%%).
compile func
Translate func Translate returns msg in lang.
sprintfStrings func sprintfStrings formats the Spanish format with values captured as text: every verb becomes %s, so numbers keep the form they had.
TranslateExact func TranslateExact translates only a message the catalog has word for word, never through a pattern.
TranslateLabel func TranslateLabel translates a short label (a name, a title): word for word, or through a pattern with enough fixed text of its own.
(Lang) T method T translates when the language is Spanish; a shorthand for handlers.

internal/i18n/i18n_test.go

99 lines · tests

Name Kind Summary
TestCatalog func Every format the platform passes to M has its Spanish, with as many values; a new message without a translation fails here.
TestTranslate func
TestParse func

internal/logarchive

Package logarchive moves the step logs of finished CI runs out of Postgres into object storage (MinIO or any S3), gzip-compressed, and reads them back for the UI.

internal/logarchive/logarchive.go

204 lines

Name Kind Summary
Objects interface Objects stores and fetches whole objects (MinIO in production).
Store interface Store is what the archiver needs from the database.
Archive struct Archive moves finished runs' step logs to Objects every Every.
(*Archive) Run method Run sweeps until ctx is done.
(*Archive) Sweep method Sweep archives the logs of finished runs, in batches, until none are left or one fails.
Key func Key is a step log's object key.
(*Archive) Read method Read returns an archived log's text.
compress func
MinIO struct MinIO stores objects in one bucket of a MinIO (or other S3) server.
NewMinIO func NewMinIO connects to endpoint (host:port) with an access key.
(*MinIO) Put method Put uploads one object.
(*MinIO) Get method Get downloads one object; ErrExpired when it no longer exists.
(*MinIO) EnsureRetention method EnsureRetention checks the bucket exists and sets its rule: logs under Prefix are deleted days after they were archived.

internal/logarchive/logarchive_test.go

104 lines · tests

Name Kind Summary
TestSweepStopsWithoutProgress func A sweep that cannot mark anything stops instead of uploading forever.
TestSweepAndRead func

internal/notify

Package notify emails the platform's owner about what needs attention: releases rolled back by verification, failed runs on the default branch, outages and recoveries.

internal/notify/notify.go

318 lines

Name Kind Summary
Tone type Tone is a message's severity: it sets its color and label.
Fact struct Fact is one row of a message's details table.
Message struct Message is one notification.
Sender interface Sender delivers a rendered email.
Notifier struct Notifier renders messages and sends them, de-duplicated and rate-limited.
(*Notifier) Enabled method Enabled reports whether messages are actually sent.
(*Notifier) Notify method Notify sends m in the background (a slow mail API never delays the caller).
(*Notifier) allow method
(*Notifier) Send method Send renders and sends m now, without de-duplication (the test email).
Localize func Localize translates a message's text for people into lang: subject, title, summary, facts, details (line by line) and the action.
Render func Render returns m as an email-safe HTML page and as plain text, in English.
render func
Resend struct Resend sends email through Resend's HTTP API (https://resend.com).
(*Resend) Send method Send posts one email to Resend.

internal/notify/notify_test.go

129 lines · tests

Name Kind Summary
TestRender func
TestNotifierDedupAndCap func
TestResend func
TestOnSent func

internal/pipeline

Package pipeline plans and executes CI runs.

internal/pipeline/kube.go

721 lines

Name Kind Summary
KubeExecutor struct KubeExecutor runs each step as a pod in a dedicated namespace.
(*KubeExecutor) defaults method
podName func
randSuffix func
(*KubeExecutor) Cleanup method Cleanup removes pods and clone secrets left by a previous process.
(*KubeExecutor) Execute method Execute runs one step as a pod: a clone secret with a short-lived token, the pod (clone, plan, then the step), its logs streamed to w, and the digest of a build read from the termination message.
(*KubeExecutor) buildkitFor method buildkitFor picks the pool daemon for key by rendezvous hashing: each key has a stable favourite among the ready daemons, and only the keys of a daemon that goes away move elsewhere.
(*KubeExecutor) pod method
(*KubeExecutor) testPostgres method testPostgres is the database of a test with postgres: true: a sidecar (an init container that keeps running) that the tests start after, once it accepts connections, and that stops when they end.
cacheName func cacheName is the volume kept between runs of a test step: one per app and step, e.g.
(*KubeExecutor) ensureCache method ensureCache creates the step's cache volume the first time it runs.
(*KubeExecutor) DeleteCaches method DeleteCaches removes the cache volumes of an app's tests.
sortedEnv func
(*KubeExecutor) waitStarted method waitStarted blocks until the container is running or has terminated, failing fast on image pull errors.
(*KubeExecutor) streamLogs method
(*KubeExecutor) waitDone method
terminationSummary func
(*KubeExecutor) affinity method
transientRetry func transientRetry retries API calls that failed for reasons that pass on their own: an overloaded API server (k3s's SQLite datastore answers "database is locked" under heavy I/O), timeouts, throttling.
isTransient func
ptr func

internal/pipeline/plan.go

172 lines

Name Kind Summary
Kind type Kind is what a step does: test, build, or run a task.
Status type Status is a step's state.
(Status) Done method Done reports whether the step has finished (in any way).
Step struct Step is one node of the run's DAG.
TaskStepID func TaskStepID is the ID of a task's step.
TaskKey func TaskKey is the Service field of a task's step: what change detection and the run page group it by.
Source struct Source identifies the commit being built.
Plan func Plan builds the DAG for a spec: per service, test (if configured) then build; job images; the builds (test, then build); then tasks, after the builds and tasks they name.
testStep func testStep is the test of a service or build named name, whose image key is key.
isTask func

internal/pipeline/run.go

150 lines

Name Kind Summary
StepResult struct StepResult is what an executor reports for one step.
Executor interface Executor runs a single step to completion, writing its logs to w.
Recorder interface Recorder persists step progress and logs (Postgres + SSE fan-out in production).
Runner struct Runner executes run DAGs with a global cap on concurrent steps, because builds on Raspberry Pi nodes are CPU and memory bound.
NewRunner func NewRunner returns a Runner that runs at most maxParallel steps at a time across all runs.
(*Runner) Run method Run executes steps respecting DependsOn and returns each step's result.
validate func validate rejects unknown dependencies and cycles.

internal/pipeline/task.go

165 lines

Name Kind Summary
(*KubeExecutor) taskSecrets method taskSecrets reads the secrets a task step uses from its app's namespace.
maskSecrets func maskSecrets replaces secret values in a task's log with ***.
maskingWriter struct
(*maskingWriter) Write method Write masks p and passes it on, reporting all of p as written.
(*maskingWriter) Close method Close closes the underlying writer when it is a closer (the step's log).
taskResources func taskResources turns a size preset (with its overrides) into requests and limits.

internal/pipeline/kube_integration_test.go

130 lines · tests

Name Kind Summary
TestBuildOnCluster func TestBuildOnCluster clones a public Go repo, builds it with the cluster's buildkitd and pushes it to the registry.
TestRailpackBuildOnCluster func TestRailpackBuildOnCluster builds a repo without using its Dockerfile: the railpack CLI writes a plan and BuildKit's railpack frontend builds it.

internal/pipeline/run_test.go

383 lines · tests

Name Kind Summary
TestPlan func
TestPlanSkipsReadyMadeImages func
TestPlanBuildsJobImages func
TestBuildPodsAvoidExcludedNodes func
TestTransientRetry func
TestRunnerFailureSkipsDependents func
TestValidateCycle func
TestBuildPodPicksBuilder func
TestPlanScript func TestPlanScript runs the real plan script with a stub railpack CLI.
TestBuildkitPool func
TestPlanBuilds func
TestTestPod func
TestTestCaches func

internal/pipeline/task_test.go

126 lines · tests

Name Kind Summary
TestPlanTasks func
TestTaskPod func
TestTaskSecrets func
TestMaskSecrets func

internal/platform

Package platform is the orchestration core: it turns GitHub events into CI runs, successful default-branch runs into releases, and releases into App objects that the controller deploys.

internal/platform/platform.go

1029 lines

Name Kind Summary
GitHub interface GitHub is the subset of the GitHub App the platform needs; faked in tests.
Config struct Config is the platform's cluster-level settings.
Platform struct Platform connects GitHub, the store, CI and the cluster: webhooks become runs, runs become releases, releases become App objects.
Proposal struct Proposal is what the wizard shows before anything is written anywhere.
Migration struct Migration describes what is running in a namespace rendimiento would adopt.
(*Platform) namespaceServing method namespaceServing returns the namespace of an ingress not managed by rendimiento that serves one of the spec's hosts, or "".
argoApp func argoApp returns the ArgoCD Application tracking an object: the tracking-id annotation (Argo CD 2.x annotation mode and 3.x default) or the legacy instance label.
(*Platform) InspectNamespace method InspectNamespace reports what already runs in ns (nil if it does not exist), so the wizard can offer a migration for any app name.
(*Platform) inspectNamespace method inspectNamespace reports what already runs in ns, or nil if it does not exist.
(*Platform) Propose method Propose inspects a repo and proposes how to deploy it: its rendimiento.yaml if it has one, otherwise a generated one, plus what is already running in the namespace it would use.
OnboardRequest struct OnboardRequest is what the New app wizard submits.
OnboardResult struct OnboardResult is the created app and either the onboarding PR or the first run.
(*Platform) Onboard method Onboard registers the app, creates its App object (waiting for a build) and either opens the onboarding PR or, if the repo already carries a rendimiento.yaml, queues the first build right away.
(*Platform) DeleteApp method DeleteApp removes the App object (the controller then removes DNS and, through owner references, the namespace) and the app's records.
Impact struct Impact describes what deleting an app would destroy.
(*Platform) DeleteImpact method DeleteImpact lists what deleting an app would remove (namespace, volumes, secrets), shown before deleting.
(*Platform) DisconnectApp method DisconnectApp stops managing an app but leaves everything running: the namespace and its objects lose rendimiento's ownership (so deleting the App garbage-collects nothing) and labels, DNS records stay, and the App and its history are removed.
release func release removes owner references to the App and rendimiento's top-level labels from one object.
PushEvent struct PushEvent is the part of a GitHub push webhook the platform uses.
(*Platform) HandlePush method HandlePush queues a run for every app deployed from the repo.
(*Platform) QueueRun method QueueRun reads rendimiento.yaml at the commit, plans the steps and queues the run.
(*Platform) rejectRun method rejectRun records a push whose rendimiento.yaml is invalid as a failed run, so it shows where pushes are looked for: on the app page, as a red check on the commit in GitHub and, for the default branch, in an email.
(*Platform) Work method Work claims queued runs until ctx ends.
(*Platform) Cancel method Cancel stops a run in progress in this process; it reports whether one was found.
(*Platform) execute method
(*Platform) release method
errPreDeploy struct errPreDeploy means a release was recorded but not deployed: a required pre-deploy task failed.
(errPreDeploy) Error method
(*Platform) preDeploy method preDeploy runs the release's pre-deploy tasks before it is rolled out.
(*Platform) changes method changes lists the files changed since the latest release, for a push to the default branch.
touched func touched reports whether any of files is under dir or a watched path.
reusable func reusable decides which built services, jobs and builds can keep the image from the latest release because nothing they are built from changed since.
skippedTasks func skippedTasks returns the task steps that do not run this time, with why: deploy-only tasks on branch and pull request runs (they may read secrets), and tasks whose path and watch paths are unchanged since the latest release.
(*Platform) Rollback method Rollback creates a new release that restores an earlier one's images and spec (the Rollback button).
(*Platform) rollbackTo method rollbackTo releases an earlier release's images and spec again, as a new release whose verification is recorded as skipped with note.
(*Platform) pointApp method pointApp writes the release into the App object; the controller does the rest.
(*Platform) startCheck method
(*Platform) finishCheck method
appTopic func
RunTopic func RunTopic is the events topic for a run's live updates.
AppTopic func AppTopic is the events topic for an app's live updates.
(*Platform) publishRun method
installationKey struct
withInstallation func
(*Platform) CloneToken method CloneToken is plugged into the executor: it mints a token for the installation carried in the run's context.

internal/platform/posttask.go

408 lines

Name Kind Summary
stageTasks func stageTasks are the release's tasks of one stage (pre- or post-deploy).
postDeployTasks func postDeployTasks are the release's post-deploy tasks.
(*Platform) runPostDeploy method runPostDeploy runs a release's post-deploy tasks (see runStage).
(*Platform) runStage method runStage runs a release's tasks of one stage, each once its after: tasks succeeded (a task whose dependency failed is skipped), and records each one's state as it goes.
(*Platform) saveTask method
judgeTasks func judgeTasks folds post-deploy results into a verification: a failed required task fails the release; a failed optional one is a warning.
taskJob func taskJob builds the Job for a post-deploy task.
(*Platform) runTaskJob method runTaskJob runs one post-deploy task as a Job and waits for it, keeping its log.
(*Platform) waitTaskPod method waitTaskPod returns the name of a Job's pod once it has started (or finished), or "" if it never does.
jobFailed func
jobFailure func
lastLines func
lockedWriter struct
(*lockedWriter) Write method Write appends b under the lock (the log stream and the reader share the buffer).

internal/platform/recorder.go

99 lines

Name Kind Summary
(*Platform) StepUpdate method StepUpdate implements pipeline.Recorder: persist, then notify the UI.
(*Platform) StepLog method StepLog implements pipeline.Recorder.
logWriter struct
(*logWriter) Write method Write buffers step output and flushes it to the store and live subscribers.
(*logWriter) flush method
(*logWriter) flushLoop method
(*logWriter) Close method Close flushes what is left.

internal/platform/verify.go

540 lines

Name Kind Summary
VerifySettings struct VerifySettings configure release verification: after a release is live, its services are checked for Window; a release that breaks a service that worked before it is rolled back to the last good release.
RolloutState type RolloutState is where a release's rollout stands.
(*Platform) startVerification method startVerification watches a new release in the background.
(*Platform) stopVerification method stopVerification ends an app's running verification as superseded (a newer release, or a rollback by hand, replaced the release).
(*Platform) verify method
(*Platform) verificationFailed method verificationFailed rolls back to the last good release, or only reports when rollback is off or there is nothing to return to.
(*Platform) verifyMessage method verifyMessage is the email for a release that failed verification: rolled back (to = {good release, new release number}) or kept (why).
shortSHA func
(*Platform) lastGoodRelease method lastGoodRelease is the newest release before number that did not fail verification (releases from before verification existed count as good).
(*Platform) waitRollout method waitRollout waits until the release is fully rolled out and healthy, it fails, or RolloutTimeout passes.
(*Platform) rolloutState method rolloutState reads the App object: healthy once the controller reports the release Healthy, failed when it reports it Degraded or in Error.
windowStats struct windowStats accumulates one check's results during a verification window.
(*windowStats) add method
(*windowStats) p95 method
judge func judge decides a verification.
(*Platform) setVerification method setVerification records the state and tells open App pages.
(*Platform) ResumeVerifications method ResumeVerifications restarts verifications interrupted by a restart: a release that is still the app's current one is watched again from the start; an older one is marked superseded.
fmtDur func
fmtMS func
(*Platform) notifyRunFailed method notifyRunFailed emails a failed run of the default branch: nothing was released.
(*Platform) postDeployOnly method postDeployOnly runs a release's post-deploy tasks without verification (it is off): once the rollout is healthy, results are recorded only.

internal/platform/platform_test.go

703 lines · tests

Name Kind Summary
TestOnboardPushDeployRollback func
TestProposeDetectsExistingDeployment func
TestChangeDetection func Only what changed since the last release is tested, built and rolled.
TestTasks func
TestDisconnectAndSuggestedName func Disconnect leaves everything running and unowned; the wizard suggests the namespace that already serves a repo's hosts.
TestInvalidSpecIsAFailedRun func A push whose rendimiento.yaml is invalid is a failed run with the reason, a failed check on the commit and an email; the app's spec is unchanged and nothing is built.

internal/platform/posttask_test.go

251 lines · tests

Name Kind Summary
TestTaskJob func
TestPostDeployVerification func A required post-deploy task that fails fails verification and rolls the release back; an optional one is only reported; one waiting on a failed task is skipped.
TestPreDeployJobUsesTheNewImage func
TestPreDeploy func Pre-deploy tasks are skipped on an app's first release, run before the rollout afterwards, and a failed one stops the release from deploying.

internal/platform/reuse_test.go

19 lines · tests

Name Kind Summary
TestReusableBuilds func

internal/platform/verify_test.go

157 lines · tests

Name Kind Summary
TestJudge func
TestReleaseVerification func A release that breaks its service is rolled back to the last good one; a healthy release passes.

internal/problems

Package problems keeps the platform's own warnings and errors for the Problems page: a slog handler passes every record on to the real log and also queues warnings and errors; a Recorder stores them, folding repeats of the same problem into one row with a count.

internal/problems/problems.go

191 lines

Name Kind Summary
Recorder struct Recorder queues problems from its Handler and stores them in Run.
NewRecorder func NewRecorder returns a Recorder that buffers up to 256 problems until Run starts storing them; beyond that, problems are counted and dropped rather than ever slowing the logging caller.
(*Recorder) Handler method Handler wraps h: every record still goes to h, and warnings and errors are also queued for the Problems page.
(*Recorder) Run method Run stores queued problems until ctx ends, and deletes the ones older than Keep every hour.
(*Recorder) add method
handler struct
(*handler) Enabled method
(*handler) WithAttrs method
(*handler) WithGroup method
(*handler) Handle method
prefixed func
FromRecord func FromRecord turns a warning or error into a Problem; ok is false for the routine ones that are not worth showing.
ignored func ignored are warnings and errors that are routine or shown elsewhere: - optimistic-concurrency conflicts, which the controllers retry at once; - services going down, which the Reliability tab already tracks as outages; - work stopped because the platform is shutting down.
normalize func
clip func

internal/problems/problems_test.go

87 lines · tests

Name Kind Summary
TestHandlerQueuesWarningsAndErrors func Warnings and errors are queued with their app, component and error; everything still reaches the real log.
TestFingerprintFoldsRepeats func Repeats that differ only in numbers or hashes share a fingerprint; a different app or message does not.
TestIgnoresRoutineRecords func Routine conflicts and outages (shown on the Reliability tab) are not problems.
TestGroupsAndFullQueue func Fields inside a group keep the group's name; a full queue drops instead of blocking.

internal/render

Package render turns an app's spec plus its released images into the Kubernetes objects that run it.

internal/render/needs.go

145 lines

Name Kind Summary
NeedServices func NeedServices are the services rendimiento runs for the app's needs: one Postgres and one Redis per app, shared by every service that needs them.
needKind func
orDefault func
withNeeds func withNeeds adds the need services and, to every service that needs something, the variables to reach it.
copyMap func
NeedRefs func NeedRefs lists the other services an app's services need, as written ("namespace/name" or a same-app "name"), sorted and unique.

internal/render/render.go

589 lines

Name Kind Summary
Options struct Options carries cluster-level settings, so nothing is hardcoded per app.
GPUProfile struct GPUProfile is how this cluster attaches a GPU to a pod.
DefaultOptions func DefaultOptions are this cluster's defaults: ingress-nginx, letsencrypt-prod, Longhorn.
Input struct Input is one app release: its spec and the image reference for each service.
Objects struct Objects returns the namespace first, then each service's objects in a stable order.
Render func Render returns every object an app release needs: namespace, deployments, services, ingresses, volumes and cron jobs, including the database and cache its needs ask for.
jobImage func jobImage resolves a job's image: its service's, its own build, or as given.
cronJob func
appLabels func
svcLabels func
selector func
deployment func
attachGPU func
lanService func lanService exposes a service on the local network: a LoadBalancer Service (MetalLB gives it an address from its pool, the requested one if set).
env func
service func service exposes port 80 and, when different, the app's own port, so other services can keep calling it as before (e.g.
merge func
ingress func
tls func
requirements func requirements builds requests and limits, leaving out unset ("") values.
rules func
volume func
ptr func
(*Objects) List method List returns every object in apply order: namespace, volumes, workloads, services, ingresses.
(*Objects) YAML method YAML renders all objects as a multi-document manifest (for previews and tests).

internal/render/render_test.go

435 lines · tests

Name Kind Summary
TestRenderGolden func
TestRenderMissingImage func
TestRenderAdoptedSelectorAndExistingClaim func An adopted Deployment keeps its immutable selector; pods carry both label sets and the Service selects the old one, so old and new pods overlap.
TestRenderPodoi func
TestRenderJobs func
TestRenderStockpulse func
TestRenderRoutes func
TestRenderGPU func
TestRenderNeeds func
TestRenderLAN func

internal/renovate

Package renovate is the Renovate add-on: it keeps the dependencies of the apps it is switched on for up to date by running Renovate on a schedule.

internal/renovate/renovate.go

698 lines

Name Kind Summary
Settings struct Settings are the add-on's configuration.
DefaultSettings func DefaultSettings are the add-on's settings before anyone changes them.
(Settings) Validate method Validate checks the schedule, image, repositories and config.
(Settings) Next method Next is the first scheduled time after t.
Load func Load returns the add-on's state, with defaults if it was never set up.
Runner struct Runner starts Renovate runs on schedule or on request, one at a time.
(*Runner) Loop method Loop starts scheduled runs until ctx ends.
(*Runner) tick method
target struct
(*Runner) Repos method Repos lists what a run would cover: apps with Renovate switched on, plus the extra repositories.
(*Runner) Start method Start begins a run in the background and returns its record.
(*Runner) targets method targets groups repositories by the GitHub App installation that can reach them.
(*Runner) execute method
MissingPermissions func MissingPermissions lists what the installation still lacks.
(*Runner) Problems method Problems explains what would stop a run right now, such as permissions the GitHub App's installations have not been granted yet.
RepoResult struct RepoResult is what one run did to one repository.
summarize func
(*Runner) runPod method
(*Runner) pod method
(*Runner) wait method
(*Runner) collect method collect reads the pod's JSON log into readable text and per-repo results.
Parse func Parse turns Renovate's JSON log (LOG_FORMAT=json) into readable lines and a result per repository.
extraFields func extraFields renders a log entry's remaining fields (e.g.
firstNonEmpty func
truncate func truncate keeps the start and end of a long log.
(*Runner) cleanup method
(*Runner) Running method Running reports whether a run is in progress in this process.
ptr func

internal/renovate/renovate_test.go

93 lines · tests

Name Kind Summary
TestParse func
TestSettings func
TestPod func
TestParseKeepsErrorDetails func
TestMissingPermissions func

internal/ruta

Package ruta is the MCP endpoint (/mcp) through which agents read and write la Ruta: what the platform's people and agents know, kept in the platform rather than in any one agent's session.

internal/ruta/ruta.go

577 lines

Name Kind Summary
Backend interface Backend is the storage the endpoint needs; *store.Store implements it.
NewToken func NewToken returns a fresh agent key and the hash to store.
HashToken func HashToken is how agent keys are stored and looked up.
Server struct Server serves /mcp.
keyInfo struct
(*Server) Handler method Handler returns the /mcp handler: bearer-token auth, then a stateless MCP server with the tools the key may use.
(*Server) verify method
keyFrom func
Summary struct Summary is an entry without its full body.
Entry struct Entry is a full entry.
CargoOut struct CargoOut is a cargo as agents see it.
empty struct
InicioOut struct InicioOut is ruta_inicio's answer.
buscarIn struct
listaOut struct
leerIn struct
tomarIn struct
tomarOut struct
anotarIn struct
actualizarIn struct
entregarIn struct
summary func
summaries func
cargoOut func
LooksSecret func LooksSecret reports whether text seems to contain a credential.
checkText func
(*Server) newServer method
addTool func addTool registers a tool whose every call is recorded in the audit log.
(*Server) audit method
(*Server) lastHandovers method
(*Server) inicio method
(*Server) buscar method
(*Server) leer method
(*Server) cargoFor method writing needs a write key and an open cargo.
(*Server) tomar method
cleanTags func
(*Server) anotar method
(*Server) actualizar method
(*Server) entregar method

internal/ruta/ruta_test.go

333 lines · tests

Name Kind Summary
TestRutaAuth func
TestRutaCargoFlow func
TestLooksSecret func

internal/spec

Package spec defines rendimiento.yaml, the only file an app repo needs.

internal/spec/spec.go

1341 lines

Name Kind Summary
Spec struct Spec is a parsed rendimiento.yaml.
Verify struct Verify configures release verification: after a release is live, its services are checked for a while, and a release that breaks a service that worked before is rolled back to the last good release.
(*Verify) AutoRollback method AutoRollback reports whether a release that fails verification is rolled back.
Task struct Task is a command run as a step of every CI run: the commit is checked out, and the command runs in Image from Path.
(Task) PostDeploy method PostDeploy reports whether the task runs after the release is live.
(Task) PreDeploy method PreDeploy reports whether the task runs before the release is rolled out.
(Task) Deploys method Deploys reports whether the task runs around a deploy (pre or post), in the app's namespace, rather than as a CI step.
(Task) SecretNames method SecretNames lists every secret the task reads.
(Spec) SecretNames method SecretNames lists every secret the app's services, jobs and tasks read: the ones that can be set from the app's settings.
PostgresOptions struct PostgresOptions configure the app's database (one per app, shared by every service that needs it).
RedisOptions struct RedisOptions configure the app's cache (one per app, shared by every service that needs it).
Need struct Need is something a service depends on: rendimiento provides it and injects how to reach it.
(*Need) UnmarshalJSON method UnmarshalJSON accepts a word ("postgres") or an object ({service: ns/name, env: VAR}).
(Need) MarshalJSON method MarshalJSON writes the short form when it can, so generated files stay readable.
(Need) EnvName method EnvName is the variable a need's address is injected into.
(*Spec) Needs method Needs reports whether any service of the app needs kind.
Job struct Job is a scheduled task.
Touches func Touches reports whether a change to repo file f affects something built from dir or any of the watch paths ("." means the whole repo).
(Job) ImageKey method ImageKey is the key of a built job's image in a release's image map.
ImageBuild struct ImageBuild is an image built from a folder of the repo on every run, like a service's, but not deployed: its digest is kept in the release.
(ImageBuild) ImageKey method ImageKey is the key of the image in a release's image map.
Service struct Service is one deployable part of an app: built from a folder of the repo (or a ready-made image) and run as a Deployment with a Service.
LANOptions struct LANOptions expose a service on the local network.
Catalog struct Catalog is what the Services page shows about a service besides what it can work out itself (addresses, ports, origin, who uses it).
ResourceOverride struct ResourceOverride replaces individual values of the size preset.
IngressOptions struct IngressOptions fine-tune the ingress of a service with a domain.
ResourcesFor func ResourcesFor resolves the service's requests and limits ("" = unset).
override func
Route struct Route is one host + path prefix a service answers on.
ParseRoute func ParseRoute splits "host/path" (path defaults to "/").
(Service) AllRoutes method AllRoutes is everything the service's ingress routes to it: "/" on its domain and aliases, then its extra routes.
(Service) HasIngress method HasIngress reports whether the service is reachable from outside.
(Service) IngressName method IngressName is the name of the service's ingress.
(Service) TLSGroups method TLSGroups returns the service's hosts grouped by certificate secret, in host order: [{secret, hosts}].
ConfigFile struct ConfigFile mounts an existing ConfigMap as read-only files.
SecretFile struct SecretFile mounts an existing Secret as read-only files.
(Service) SecretNames method SecretNames lists every secret the service reads, however it reads it.
secretNames func secretNames is the sorted, de-duplicated set of secrets named whole, in NAME: secret/key references, or as mounted files.
(Service) TLSSecretName method TLSSecretName is the certificate secret for the service's domain.
Build struct Build says how a service's image is built.
(Build) validate method
Test struct Test is a command run in a container image before the build; a failure stops the build.
(Test) Requests method Requests resolves the test's requests and limits ("" = unset).
(Test) validate method
Health struct Health is the readiness and liveness check of a service.
Volume struct Volume gives a service persistent storage (a Longhorn volume by default).
(Service) VolumeFSGroup method VolumeFSGroup is the pod fsGroup for the service's volume, or nil.
(Service) Hosts method Hosts are every hostname the service answers on: domain, then aliases.
(Service) ClaimName method ClaimName is the PersistentVolumeClaim the service mounts.
Size type Size is a preset of CPU and memory requests and limits, sized for Raspberry Pi nodes.
Resources struct Resources are requests/limits for a size, sized for Raspberry Pi nodes.
(Size) Resources method Resources returns the size's requests and limits.
Parse func Parse reads rendimiento.yaml, applies defaults and validates it.
(*Spec) Marshal method Marshal writes the spec as YAML.
(*Spec) Default method Default fills in defaults (path, port, size, replicas, Dockerfile) in place.
(*Spec) Validate method Validate reports every problem in the spec at once, each with its path (services[1].port …).
(*Spec) validateBuilds method
(*Spec) validateTasks method
(*Spec) validateNeeds method
validateResources func
resourceQuantity func
(*Spec) validateRoutes method
(*Spec) validateJobs method

internal/spec/spec_test.go

478 lines · tests

Name Kind Summary
TestParseDefaults func
TestParseFull func
TestValidateErrors func
TestSecplusShape func secplus as it runs today: env from one key, the whole secret as files, streaming.
TestExistingClaim func
TestPodoiShape func podoi as it runs today: a built website on two hosts, and Postgres from a ready-made image on its existing volume.
TestJobs func
TestStockpulseShape func stockpulse as it runs today.
TestTouches func
TestRoutes func wellness: /api on the website's hosts goes to the API.
TestValidateBuildGPUCatalog func
TestNeeds func
TestTasks func
TestPostDeployTasks func
TestBuilds func

internal/store

Package store persists apps, CI runs, step logs, releases and sessions in Postgres.

internal/store/addons.go

174 lines

Name Kind Summary
Addon struct Addon is an optional platform feature and its settings (JSON, per add-on).
(*Store) GetAddon method GetAddon returns the add-on's row, or ErrNotFound if it was never set up.
(*Store) PutAddon method PutAddon creates or replaces an add-on's switch and settings.
(*Store) ClaimSchedule method ClaimSchedule records a scheduled start at at unless another worker already did (last_scheduled moved on).
(*Store) AppAddons method AppAddons returns the app's per-add-on switches.
(*Store) SetAppAddon method SetAppAddon switches an add-on on or off for one app.
(*Store) AppsWithAddon method AppsWithAddon lists apps that have the add-on switched on.
AddonRun struct AddonRun is one execution of an add-on (e.g.
(*Store) CreateAddonRun method CreateAddonRun records a run as started and fills in its ID.
(*Store) FinishAddonRun method FinishAddonRun records a run's outcome, per-repository results and log.
(*Store) FailRunningAddonRuns method FailRunningAddonRuns closes runs a previous process left behind.
scanAddonRun func
(*Store) ListAddonRuns method ListAddonRuns returns the most recent runs, newest first, without their logs.
(*Store) GetAddonRun method GetAddonRun returns one run with its log.
prefixed func prefixed qualifies a column list with a table alias ("a.id, a.name").

internal/store/problems.go

110 lines

Name Kind Summary
Problem struct Problem is one of the platform's own warnings or errors, with its repeats folded in.
(*Store) RecordProblem method RecordProblem adds an occurrence: a new row, or one more on the row with the same fingerprint, which also undoes a dismissal or resolution.
(*Store) ListProblems method ListProblems returns problems that happened since since, newest first; app filters to one app ("" for all), and dismissed ones are left out unless asked for.
(*Store) OpenProblems method OpenProblems counts problems that happened within ProblemOpenFor and are neither dismissed nor resolved.
(*Store) DismissProblem method DismissProblem hides a problem until it happens again.
(*Store) PruneProblems method PruneProblems deletes problems that last happened before before.
ProblemMatch struct ProblemMatch picks the problems a fix resolves: same message, and the same app (when set) and attribute (when set, e.g.
(*Store) ResolveProblems method ResolveProblems marks the unresolved problems matching m as resolved, saying what fixed them; it returns how many it resolved.

internal/store/release_tasks.go

81 lines

Name Kind Summary
ReleaseTask struct ReleaseTask is one post-deploy task of a release (see spec.Task).
(*Store) SaveReleaseTask method SaveReleaseTask records a post-deploy task's state (and the tail of its log).
(*Store) ReleaseTasks method ReleaseTasks returns the post-deploy tasks of the given releases, by release ID, without their logs.
(*Store) ReleaseTaskLog method ReleaseTaskLog returns the log of one post-deploy task of an app's release.

internal/store/ruta.go

354 lines

Name Kind Summary
AgentKey struct AgentKey is a bearer token for the MCP endpoint (the token itself is never stored).
(AgentKey) Usable method Usable reports whether the key may be used now.
Cargo struct Cargo is an agent's turn of work.
RutaEntry struct RutaEntry is one thing the platform knows: a decision, a manual, a pending task, a note, or something a person lived.
AgentAction struct AgentAction is one tool call made through the MCP endpoint.
(*Store) CreateAgentKey method CreateAgentKey stores a new key by its token's hash.
scanAgentKey func
(*Store) AgentKeyByHash method AgentKeyByHash finds a key by its token's hash, and notes that it was used (at most once a minute, to keep writes down).
(*Store) AgentKey method AgentKey returns one key.
(*Store) ListAgentKeys method ListAgentKeys returns every key, newest first.
(*Store) RevokeAgentKey method RevokeAgentKey stops a key from working, and closes its open cargo.
scanCargo func
(*Store) TakeCargo method TakeCargo opens a cargo for a key; ErrCargoOpen if it already has one.
(*Store) Cargo method Cargo returns one cargo.
(*Store) OpenCargo method OpenCargo returns a key's open cargo, or ErrNotFound.
(*Store) HandOver method HandOver closes a cargo with its entrega and what is left.
(*Store) ListCargos method ListCargos returns cargos, newest first.
scanRuta func
(*Store) AddRuta method AddRuta stores a new entry.
(*Store) Ruta method Ruta returns one entry.
(*Store) UpdateRuta method UpdateRuta replaces an entry's title, body, tags and done, keeping the previous version in ruta_history.
(*Store) ArchiveRuta method ArchiveRuta hides an entry from lists (it is never deleted).
(*Store) SearchRuta method SearchRuta lists entries that are not archived, newest change first.
(*Store) RecordAgentAction method RecordAgentAction notes one tool call.
AgentActionRow struct AgentActionRow is a recorded tool call, for the UI.
(*Store) ListAgentActions method ListAgentActions returns the latest tool calls, newest first.

internal/store/stats.go

271 lines

Name Kind Summary
DeliveryStats struct DeliveryStats summarize how the platform shipped over a period: the public stats page's headline numbers.
Count struct Count is a number for a day.
(*Store) Delivery method Delivery computes DeliveryStats for the days since days ago, with days counted in time zone tz (an IANA name).
(*Store) DeliveryBetween method DeliveryBetween computes the summary numbers of DeliveryStats for what happened in [from, to); DeploysPerDay is left empty.
DeliveryWeek struct DeliveryWeek is one week of DeliveryStats' headline numbers, for trends.
(*Store) DeliveryWeeks method DeliveryWeeks returns weeks seven-day windows ending at now, oldest first.
SiteStats struct SiteStats is the public view of one app's public URL check.
DayRatio struct DayRatio is a day's share of successful checks (nil: no checks that day).
(*Store) PublicSites method PublicSites returns every public URL check with its uptime over 24 hours and 30 days, its typical response time and its daily uptime for days days (days counted in time zone tz).
ReleaseEvent struct ReleaseEvent is one release, for the public activity feed.
(*Store) RecentReleases method RecentReleases lists the newest releases across all apps.
ActiveRun struct ActiveRun is a run waiting or in progress, as the welcome page shows it: which app, and since when; nothing about the commit.
(*Store) ActiveRuns method ActiveRuns lists the runs queued or running, oldest first.

internal/store/store.go

639 lines

Name Kind Summary
Store struct Store is the platform's Postgres database.
Open func Open connects to Postgres; call Migrate before use.
(*Store) Close method Close releases the connection pool.
(*Store) Migrate method Migrate applies embedded migrations in filename order, each once.
App struct App is an onboarded application: its repo, installation and the rendimiento.yaml of its default branch.
scanApp func
(*Store) CreateApp method CreateApp inserts an app; names are unique.
(*Store) UpdateAppSpec method UpdateAppSpec stores the latest rendimiento.yaml of the default branch.
(*Store) GetApp method GetApp returns an app by name, or ErrNotFound.
(*Store) GetAppByID method GetAppByID returns an app by ID, or ErrNotFound.
(*Store) AppsForRepo method AppsForRepo returns every app deployed from a repo (webhooks fan out to them).
(*Store) ListApps method ListApps returns every app, by name.
(*Store) ListReleasedApps method ListReleasedApps lists the apps with at least one release: the ones that have been live.
(*Store) listApps method
(*Store) DeleteApp method DeleteApp removes an app and, through foreign keys, its runs and releases.
Run struct Run is one CI run: a commit of an app built (and on the default branch, released).
Step struct Step is one test or build step of a run, with its result.
scanRun func
(*Store) CreateRun method CreateRun queues a run with its planned steps.
(*Store) ClaimRun method ClaimRun takes the oldest queued run and marks it running.
(*Store) RequeueOrphans method RequeueOrphans handles runs left "running" by a process that died: they are queued again from scratch (builds are repeatable), up to maxAttempts, after which they are marked failed.
(*Store) SetCheckRun method SetCheckRun remembers the GitHub check run that mirrors a run.
(*Store) CreateRejectedRun method CreateRejectedRun records a run that failed before it could start (its rendimiento.yaml was invalid): it is created finished, with no steps, so no worker ever claims it.
(*Store) FinishRun method FinishRun records a run's outcome and closes any step still pending or running.
(*Store) CancelQueued method CancelQueued cancels queued runs of an app on a branch (superseded by a newer push).
(*Store) GetRun method GetRun returns a run with its steps.
(*Store) ListRuns method ListRuns returns an app's most recent runs, newest first.
(*Store) UpdateStep method UpdateStep records a step's status, digest, message and times.
(*Store) AppendLog method AppendLog adds output to a step's log, keeping at most maxLog bytes (the tail, where errors are).
(*Store) StepLog method StepLog returns a step's stored log, or, once archived, the key of its object in the log archive (and an empty log).
ArchivableStep struct ArchivableStep is a finished run's step whose log is still in Postgres.
(*Store) UnarchivedSteps method UnarchivedSteps lists up to limit steps with a log in Postgres, of runs that finished before before (their logs are complete), oldest first.
(*Store) MarkArchived method MarkArchived records that a step's log (bytes long, in bytes) is stored under ref and empties the column.
(*Store) ArchiveStats method ArchiveStats counts archived logs and their size, and logs waiting to be archived.
Release struct Release is what was deployed: the images (by digest) and spec of one successful run, or of a rollback.
(*Store) SetVerification method SetVerification records a release's verification state and message.
(*Store) VerifyingReleases method VerifyingReleases lists releases whose verification was interrupted (the process stopped while watching them).
(*Store) CreateRelease method CreateRelease assigns the next release number for the app.
scanRelease func
(*Store) GetRelease method GetRelease returns an app's release by number.
(*Store) LatestRelease method LatestRelease returns the app's newest release, or ErrNotFound.
(*Store) ListReleases method ListReleases returns an app's most recent releases, newest first.
(*Store) CreateSession method CreateSession stores a login session by the hash of its token.
(*Store) SessionLogin method SessionLogin returns the GitHub login of a valid session, or ErrNotFound.
(*Store) DeleteSession method DeleteSession ends a session and removes expired ones.
nullTime func
IsUniqueViolation func IsUniqueViolation reports a duplicate key (e.g.
(*Store) ResetForTests method ResetForTests drops every table.
(*Store) Ping method Ping checks the database connection.

internal/store/uptime.go

287 lines

Name Kind Summary
Probe struct Probe is one uptime check of one service: inside the cluster ("internal") or through its public URL ("public").
Incident struct Incident is an outage of one check: from its first failed check until the next successful one (EndedAt is nil while it lasts).
(*Store) RecordProbes method RecordProbes saves a round of checks.
(*Store) OpenIncident method OpenIncident records the start of an outage and returns its ID.
(*Store) CloseIncident method CloseIncident records the end of an outage.
(*Store) OpenIncidents method OpenIncidents lists the outages still going on, across all apps: what a restarted prober picks up.
(*Store) Incidents method Incidents lists an app's outages that overlap [since, now], newest first.
(*Store) incidents method
(*Store) RollupProbes method RollupProbes (re)computes the hourly summaries of every hour from since's hour on.
(*Store) PruneProbes method PruneProbes deletes checks older than 7 days and summaries older than 400 days (the hourly summaries keep the long-range charts).
UptimeBucket struct UptimeBucket is one point of a chart: the checks in [At, At+bucket).
UptimeSeries struct UptimeSeries is one check's history over a range: totals, response time percentiles (of successful checks) and the chart's buckets.
(*Store) Uptime method Uptime returns every check of an app over [since, now] in buckets of the given size.
(*Store) UptimeSummary method UptimeSummary is the share of successful checks per app since a time: the dashboard's uptime badges.
CheckStats struct CheckStats summarizes one check's results over a period.
(*Store) ProbeStats method ProbeStats summarizes an app's checks in [from, to), per service and check kind: the baseline a new release is compared with.

internal/store/logarchive_test.go

46 lines · tests

Name Kind Summary
TestLogArchiveBookkeeping func

internal/store/ruta_test.go

100 lines · tests

Name Kind Summary
TestRuta func

internal/store/stats_test.go

181 lines · tests

Name Kind Summary
TestDeliveryAndPublicStats func
TestProblems func Repeats fold into one problem with a count; dismissing hides it until it happens again; old ones are pruned.
TestResolveProblems func A fix resolves matching problems (by message, app and attribute); a resolved problem is not open, and reopens if it happens again.

internal/store/store_test.go

368 lines · tests

Name Kind Summary
TestAppsRunsReleases func
TestConcurrentClaimsAndReleaseNumbers func
TestSessionsAndLogCap func
TestRequeueOrphansRetriesThenGivesUp func
TestFinishAndCancelCloseSteps func
TestAddons func

internal/store/uptime_test.go

101 lines · tests

Name Kind Summary
TestUptime func

internal/uptime

Package uptime checks every app's services once a minute and keeps the results: whether each answered, how fast, and when it was down.

internal/uptime/uptime.go

455 lines

Name Kind Summary
Target struct Target is one check: a URL to GET, or a host:port to connect to.
Targets func Targets lists the checks for a set of apps.
Checker struct Checker runs single checks.
NewChecker func NewChecker returns a Checker that does not follow redirects (a redirect, say to a login page, means the service answered) and gives each check timeout to complete.
(*Checker) Check method Check runs one check.
shortError func shortError keeps the useful end of an error (Go wraps URLs and addresses around the cause).
Recorder interface Recorder is what the prober stores results in (the store in production).
Prober struct Prober checks every target once per Interval and records the results.
checkState struct
change struct change is an outage that started or ended, for the round's emails.
key func
(*Prober) Run method Run checks until ctx is done.
(*Prober) Round method Round checks every target once, records the results and updates outages.
(*Prober) notifyChanges method notifyChanges sends one email per app for the outages that started, and one for those that ended, this round.
checkName func
joinAnd func joinAnd lists names as "a and b and c", one translatable pair at a time.
outageMessage func
recoveryMessage func
humanDuration func
(*Prober) observe method observe updates a target's streak, its metrics, and opens or closes its outage.
Register func Register adds the uptime metrics to a Prometheus registry (the controller-runtime one, served on METRICS_ADDR).

internal/uptime/uptime_test.go

195 lines · tests

Name Kind Summary
TestTargets func
TestCheck func
TestIncidents func
TestRound func

templates

Package templates embeds the Dockerfile templates used for repos that do not ship one.

templates/embed.go

7 lines

web

Package web embeds the built UI (npm run build → web/dist).

web/embed.go

22 lines

Name Kind Summary
Dist func Dist returns the built UI, or nil when the binary was built without it.

Web UI (TypeScript / React)

web/src/api.ts

807 lines

Name Kind Summary
Size type Typed client for the rendimiento API.
Need type A need: "postgres", "redis", or another service to call.
Service interface
secretNames function Every secret a service reads (envFrom, single keys, or files).
Job interface
Spec interface
Task interface A command run as a CI step (mobile builds, smoke tests, release scripts).
appSecretNames function Every secret an app reads: its services', jobs' and tasks'.
Detected interface
Proposal interface
Step interface
Run interface
ServiceStatus interface
AppStatus interface
App interface
RutaKind type ---- la Ruta (what people and agents know; agents reach it over /mcp) ----
RutaEntry interface
RutaInput interface
Cargo interface
AgentAction interface
AgentKey interface
CreatedAgentKey interface
Problem interface ---- problems (the platform's own warnings and errors) ----
ProblemList interface
DeliveryStats interface ---- delivery (the dashboard's DORA numbers) ----
DeliveryWeek interface
DeliveryReport interface
VisitRange type ---- visits (Umami) ----
VisitStats interface
VisitPoint interface
VisitMetric interface
VisitReport interface
Visits interface
VisitsSummary interface
ReliabilityRange type ---- reliability (uptime checks) ----
CheckKind type
UptimeBucket interface
Probe interface
UptimeSeries interface
Incident interface
Reliability interface
Release interface
ReleaseTask interface A post-deploy task of a release: a command run against it once live.
VerifyStatus type What release verification concluded ("" for releases from before it existed).
ResourceNode interface
Installation interface
Repo interface
request function
api const
subscribe function Subscribes to server-sent events; returns an unsubscribe function.
PublicActivity interface The welcome page's "right now": runs going on and the latest releases, by app name only.
timeAgo function
duration function
EnvStatus type ---- environment ----
EnvCheck interface
EnvProvider interface
EnvNode interface
EnvProblem interface
EnvReport interface
envApi const
CatalogGroup type ---- services catalog ----
CatalogEntry interface
Catalog interface
catalogApi const
RenovateSettings interface ---- add-ons ----
RenovateRepoResult interface
AddonRun interface
Addon interface
AppAddons interface
addonsApi const
AddonObjectRef interface ---- installed add-ons (Helm charts / git manifests) ----
AddonPreview interface
AddonSource interface
AddonPhase type
InstalledAddon interface
CatalogField interface
AddonCatalogEntry interface
AddonDefinition interface
installedApi const

web/src/components/ambiente.tsx

176 lines

Name Kind Summary
Tema type ---- day / night and movement ----
guardar function
temaActual function The theme in effect: the one picked, else the device's.
TemaSwitch component Día / Noche: switches the theme and remembers it in this browser.
MovimientoSwitch component Movement on / off (the papel picado, the flowers, the candles).
Techo component Roof tiles and papel picado; at night every fourth flag is a farol.
Cielo component Stars and the moon behind everything; shown only at night.
Guardapolvo component The guardapolvo band at the foot of every page.
FlorEstado type ---- the cempasúchil ----
Flor component A cempasúchil: alive (it breathes), withered (it droops and drops
LluviaDePetalos component A burst of petals over the page, for a release that just went live.

web/src/components/delivery.tsx

187 lines

Name Kind Summary
fmtSec function Seconds as the largest sensible unit.
fmtWeek function
Tile type
trend function "↓ 40% vs the previous 30 days, better": direction in words, never color alone.
tiles function
Spark component Twelve weeks as a line; gaps where a week has no data; a dot on the last.
DeliveryPanel component

web/src/components/marca.tsx

23 lines

Name Kind Summary
Logo component
LangSwitch component EN/ES: shows the other language, in that language.

web/src/components/reliability.tsx

392 lines

Name Kind Summary
kindLabel const
fmtPct function
fmtMs function
fmtDuration function
BucketState type
stateLabel const
stateColor const
bucketState function
timeline function Every bucket of the range, including the ones without checks.
fmtWhen function
checksOf function
ReliabilityTab component
CheckCard component
Tile component
Tip type
TipBox component
StatusStrip component Was it up? One cell per bucket, in the reserved status colors, with a legend.
niceMax function
LatencyChart component Response times: p95 and p50 per bucket, release markers, crosshair tooltip.
DataTable component The same numbers without hovering: the table view.
Incidents component

web/src/components/ui.tsx

206 lines

Name Kind Summary
Tone type
phaseTone const
phaseLabel const
statusText function A status word from the API (a phase, a run or step status, a health), in the UI's language.
PhaseBadge component
runTone const
RunBadge component
HealthBadge component
ErrorBox component
usePoll function Loads data and refreshes it every intervalMs (0 = once).
ResourceTree component
TreeNode component
stepColors const
PipelineGraph component
Switch component An on/off switch (a button with role="switch").

web/src/components/visits.tsx

284 lines

Name Kind Summary
fmtN const
bounceRate function
avgVisit function
fmtVisitTime function
change function "↑ 40% vs the previous period, better": direction in words.
Tile component
niceMax function
VisitChart component Visitors and page views per hour or day, with a crosshair tooltip.
countryName function
Top component A top list: the value, a bar for its share, the count.
ReportView component
VisitsTab component
VisitsPanel component The dashboard's visitors panel: the last 7 days, all apps Umami counts.

web/src/i18n.ts

50 lines

Name Kind Summary
Lang type
initial function
setLang function Switches the language and reloads, so every page renders in it.
t function The phrase in the current language, with {name} placeholders filled in.
tn function t() for a count: one when n is 1, else other; {n} is filled in.

web/src/i18n/es.ts

772 lines

Name Kind Summary
es const Spanish for every phrase in the UI, keyed by its English text (see ../i18n.ts).

web/src/main.tsx

100 lines

Name Kind Summary
Shell component

web/src/pages/Addons.tsx

191 lines

Name Kind Summary
Addons component
RenovateCard component
RunRow component

web/src/pages/AppPage.tsx

462 lines

Name Kind Summary
AppPage component
Overview component
needTitle const
ProvidedNeeds component The database and cache rendimiento runs because the app's services need them.
DependencyUpdates component The app's Renovate switch and what the last run did for its repo.
Runs component
Releases component
taskBadge const
PostDeployTask component One post-deploy task under its release: status, duration, and its log on demand.
verifyBadge const
VerifyBadge component What release verification concluded, with its message on hover.
VerificationBanner component A banner while the newest release is verified, or after it was rolled back.
Settings component
DangerZone component
SecretForm component

web/src/pages/Bienvenida.tsx

210 lines

Name Kind Summary
BookLinks interface
Monarca component A monarch butterfly, the Ruta's emblem.
EnEsteMomento component "Right now": what rendimiento is doing, refreshed every 20 seconds.
Bienvenida component

web/src/pages/Dashboard.tsx

111 lines

Name Kind Summary
marchita function An app is withered while one of its checks is in an outage, or its
Dashboard component

web/src/pages/Environment.tsx

257 lines

Name Kind Summary
tone const
label const
StatusBadge component
Environment component
DynamicDNS component
ProviderCard component
CheckRow component
TestEmail component Sends a sample notification now, and says what happened.
Meter component
gib const
cores const
NodeCard component

web/src/pages/Installed.tsx

407 lines

Name Kind Summary
phaseTone const
phaseLabel const Translated where shown.
AddonPhaseBadge component
sourceLabel function
useLANByAddon function The add-ons' services reachable on the local network, by add-on name.
LANLinks component Links to an add-on's UIs on the local network (plain addresses for non-web services).
InstalledSection component Installed add-ons, the catalog and its install form.
fieldDefault function
setPath function
InstallForm component
AddonDetail component One installed add-on: status, what a sync would change, and actions.

web/src/pages/NewApp.tsx

399 lines

Name Kind Summary
langBadge const
Result type
NewApp component
Needs component What a service depends on: rendimiento runs it (database, cache) or
ServiceForm component

web/src/pages/Problems.tsx

128 lines

Name Kind Summary
isOpen function
headline function "rendimiento.yaml rejected; the push was not built: services[0]: …"
resolutionText function The server's note on what fixed a problem, e.g.
ProblemCard component
Problems component
AppProblems component Open problems about one app, as a banner on its page.
ProblemsNavLink component The navigation link, with the number of open problems.

web/src/pages/RunPage.tsx

106 lines

Name Kind Summary
RunPage component
formatLog function Drops the ::group:: markers the executor uses to separate clone and step output.

web/src/pages/Ruta.tsx

337 lines

Name Kind Summary
Tab type
kindLabel const
Monarca component A monarch, which no single one of makes the whole journey.
Tags component
Author component
EntryForm component
EntryCard component
Entries component
Vivido component
Cargos component
NewKey component
Connect component
Keys component
Ruta component

web/src/pages/Services.tsx

306 lines

Name Kind Summary
categoryLabel const
originLabel const
Services component
ServiceCard component
Copyable component
DocsHint component

web/src/pages/Setup.tsx

30 lines

Name Kind Summary
Setup component First-run page: creates the GitHub App through GitHub's manifest flow.

web/vite.config.ts

8 lines