{"id":31559560,"url":"https://github.com/doodlescheduling/neo4j-aura-controller","last_synced_at":"2026-04-17T02:31:12.642Z","repository":{"id":316586399,"uuid":"1063893777","full_name":"DoodleScheduling/neo4j-aura-controller","owner":"DoodleScheduling","description":"Kubernetes controller for managing Neo4j Aura","archived":false,"fork":false,"pushed_at":"2025-10-02T13:24:41.000Z","size":179,"stargazers_count":0,"open_issues_count":7,"forks_count":0,"subscribers_count":0,"default_branch":"master","last_synced_at":"2025-10-02T15:22:56.111Z","etag":null,"topics":["aura","kubernetes-controller","neo4j"],"latest_commit_sha":null,"homepage":"","language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/DoodleScheduling.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":"CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":null,"codeowners":"CODEOWNERS","security":"SECURITY.md","support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2025-09-25T09:00:51.000Z","updated_at":"2025-10-02T13:23:59.000Z","dependencies_parsed_at":"2025-09-29T19:00:40.913Z","dependency_job_id":null,"html_url":"https://github.com/DoodleScheduling/neo4j-aura-controller","commit_stats":null,"previous_names":["doodlescheduling/neo4j-aura-controller"],"tags_count":1,"template":false,"template_full_name":null,"purl":"pkg:github/DoodleScheduling/neo4j-aura-controller","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/DoodleScheduling%2Fneo4j-aura-controller","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/DoodleScheduling%2Fneo4j-aura-controller/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/DoodleScheduling%2Fneo4j-aura-controller/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/DoodleScheduling%2Fneo4j-aura-controller/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/DoodleScheduling","download_url":"https://codeload.github.com/DoodleScheduling/neo4j-aura-controller/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/DoodleScheduling%2Fneo4j-aura-controller/sbom","scorecard":{"id":1238125,"data":{"date":"2025-09-25T12:13:30Z","repo":{"name":"github.com/DoodleScheduling/neo4j-aura-controller","commit":"ff62b56cea94499fa18c271738cda2e97e48d54c"},"scorecard":{"version":"v5.1.1","commit":"cd152cb6742c5b8f2f3d2b5193b41d9c50905198"},"score":6.3,"checks":[{"name":"Security-Policy","score":10,"reason":"security policy file detected","details":["Info: security policy file detected: SECURITY.md:1","Info: Found linked content: SECURITY.md:1","Info: Found disclosure, vulnerability, and/or timelines in security policy: SECURITY.md:1","Info: Found text in security policy: SECURITY.md:1"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/cd152cb6742c5b8f2f3d2b5193b41d9c50905198/docs/checks.md#security-policy"}},{"name":"Maintained","score":0,"reason":"project was created in last 90 days. please review its contents carefully","details":["Warn: Repository was created in last 90 days."],"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/cd152cb6742c5b8f2f3d2b5193b41d9c50905198/docs/checks.md#maintained"}},{"name":"Code-Review","score":0,"reason":"Found 0/3 approved changesets -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/cd152cb6742c5b8f2f3d2b5193b41d9c50905198/docs/checks.md#code-review"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/cd152cb6742c5b8f2f3d2b5193b41d9c50905198/docs/checks.md#binary-artifacts"}},{"name":"Dependency-Update-Tool","score":10,"reason":"update tool detected","details":["Info: detected update tool: RenovateBot: renovate.json:1"],"documentation":{"short":"Determines if the project uses a dependency update tool.","url":"https://github.com/ossf/scorecard/blob/cd152cb6742c5b8f2f3d2b5193b41d9c50905198/docs/checks.md#dependency-update-tool"}},{"name":"Token-Permissions","score":10,"reason":"GitHub workflow tokens follow principle of least privilege","details":["Warn: jobLevel 'contents' permission set to 'write': .github/workflows/rebase.yaml:16","Info: jobLevel 'contents' permission set to 'read': .github/workflows/scan.yaml:17","Info: found token with 'none' permissions: .github/workflows/main.yaml:1","Info: topLevel 'contents' permission set to 'read': .github/workflows/pr-actions.yaml:4","Info: found token with 'none' permissions: .github/workflows/pr-build.yaml:1","Info: found token with 'none' permissions: .github/workflows/pr-goreleaser.yaml:1","Info: found token with 'none' permissions: .github/workflows/pr-label.yaml:1","Info: found token with 'none' permissions: .github/workflows/pr-stale.yaml:1","Info: found token with 'none' permissions: .github/workflows/pr-trivy.yaml:1","Info: found token with 'none' permissions: .github/workflows/rebase.yaml:1","Info: found token with 'none' permissions: .github/workflows/release.yaml:1","Info: found token with 'none' permissions: .github/workflows/report-on-vulnerabilities.yaml:1","Info: found token with 'none' permissions: .github/workflows/scan.yaml:1","Info: found token with 'none' permissions: .github/workflows/scorecard.yaml:1"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/cd152cb6742c5b8f2f3d2b5193b41d9c50905198/docs/checks.md#token-permissions"}},{"name":"Pinned-Dependencies","score":10,"reason":"all dependencies are pinned","details":["Info:  35 out of  35 GitHub-owned GitHubAction dependencies pinned","Info:  40 out of  40 third-party GitHubAction dependencies pinned","Info:   1 out of   1 containerImage dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/cd152cb6742c5b8f2f3d2b5193b41d9c50905198/docs/checks.md#pinned-dependencies"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/cd152cb6742c5b8f2f3d2b5193b41d9c50905198/docs/checks.md#dangerous-workflow"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: Apache License 2.0: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/cd152cb6742c5b8f2f3d2b5193b41d9c50905198/docs/checks.md#license"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/cd152cb6742c5b8f2f3d2b5193b41d9c50905198/docs/checks.md#cii-best-practices"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/cd152cb6742c5b8f2f3d2b5193b41d9c50905198/docs/checks.md#packaging"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/cd152cb6742c5b8f2f3d2b5193b41d9c50905198/docs/checks.md#signed-releases"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/cd152cb6742c5b8f2f3d2b5193b41d9c50905198/docs/checks.md#fuzzing"}},{"name":"SAST","score":7,"reason":"SAST tool detected but not run on all commits","details":["Info: SAST configuration detected: CodeQL","Warn: 0 commits out of 1 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/cd152cb6742c5b8f2f3d2b5193b41d9c50905198/docs/checks.md#sast"}},{"name":"Branch-Protection","score":0,"reason":"branch protection not enabled on development/release branches","details":["Warn: branch protection not enabled for branch 'master'"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/cd152cb6742c5b8f2f3d2b5193b41d9c50905198/docs/checks.md#branch-protection"}},{"name":"CI-Tests","score":10,"reason":"1 out of 1 merged PRs checked by a CI test -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project runs tests before pull requests are merged.","url":"https://github.com/ossf/scorecard/blob/cd152cb6742c5b8f2f3d2b5193b41d9c50905198/docs/checks.md#ci-tests"}},{"name":"Vulnerabilities","score":10,"reason":"0 existing vulnerabilities detected","details":null,"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/cd152cb6742c5b8f2f3d2b5193b41d9c50905198/docs/checks.md#vulnerabilities"}},{"name":"Contributors","score":0,"reason":"project has 0 contributing companies or organizations -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project has a set of contributors from multiple organizations (e.g., companies).","url":"https://github.com/ossf/scorecard/blob/cd152cb6742c5b8f2f3d2b5193b41d9c50905198/docs/checks.md#contributors"}}]},"last_synced_at":"2025-09-25T14:33:52.164Z","repository_id":316586399,"created_at":"2025-09-25T14:33:52.165Z","updated_at":"2025-09-25T14:33:52.165Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":278399690,"owners_count":25980332,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","status":"online","status_checked_at":"2025-10-04T02:00:05.491Z","response_time":63,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["aura","kubernetes-controller","neo4j"],"created_at":"2025-10-05T01:54:08.222Z","updated_at":"2025-10-05T01:54:13.626Z","avatar_url":"https://github.com/DoodleScheduling.png","language":"Go","funding_links":[],"categories":[],"sub_categories":[],"readme":"# neo4j-aura-controller\n\n[![release](https://img.shields.io/github/release/DoodleScheduling/neo4j-aura-controller/all.svg)](https://github.com/DoodleScheduling/neo4j-aura-controller/releases)\n[![release](https://github.com/DoodleScheduling/neo4j-aura-controller/actions/workflows/release.yaml/badge.svg)](https://github.com/DoodleScheduling/neo4j-aura-controller/actions/workflows/release.yaml)\n[![report](https://goreportcard.com/badge/github.com/DoodleScheduling/neo4j-aura-controller)](https://goreportcard.com/report/github.com/DoodleScheduling/neo4j-aura-controller)\n[![OpenSSF Scorecard](https://api.securityscorecards.dev/projects/github.com/DoodleScheduling/neo4j-aura-controller/badge)](https://api.securityscorecards.dev/projects/github.com/DoodleScheduling/neo4j-aura-controller)\n[![Coverage Status](https://coveralls.io/repos/github/DoodleScheduling/neo4j-aura-controller/badge.svg?branch=master)](https://coveralls.io/github/DoodleScheduling/neo4j-aura-controller?branch=master)\n[![license](https://img.shields.io/github/license/DoodleScheduling/neo4j-aura-controller.svg)](https://github.com/DoodleScheduling/neo4j-aura-controller/blob/master/LICENSE)\n\nKubernetes controller for managing Neo4j Aura.\n\n## Quickstart\n\n### Usage Example\n\n```yaml\napiVersion: neo4j.infra.doodle.com/v1beta1\nkind: AuraInstance\nmetadata:\n  name: my-instance\nspec:\n  cloudProvider: gcp\n  memory: 4GB\n  region: eu-central-1\n  tier: free-db\n  tenantID: xxx-xxx-xx\n  neo4jVersion: \"5\"\n  secret:\n    name: neo4j-project-admin\n---\napiVersion: v1\ndata:\n  clientID: c2VjcmV0=\n  clientSecret: c2VjcmV0=\nkind: Secret\nmetadata:\n  name: neo4j-project-admin\ntype: Opaque\n```\n#### Custom Secret Key Mapping\n\nIf your secret uses different key names (e.g., `clientId` instead of `clientID`), you can specify custom key mappings:\n\n```yaml\napiVersion: v1\nkind: Secret\nmetadata:\n  name: neo4j-aura-api-custom\n  namespace: default\ndata:\n  clientId: \u003cbase64-encoded-client-id\u003e \n  clientSecret: \u003cbase64-encoded-client-secret\u003e\n---\napiVersion: neo4j.infra.doodle.com/v1beta1\nkind: AuraInstance\nmetadata:\n  name: my-neo4j-instance\n  namespace: default\nspec:\n  tier: professional-db\n  region: eu-central-1\n  cloudProvider: aws\n  neo4jVersion: \"5\"\n  tenantID: 928f3731-1111-5ffd-a2f7-3602aafb304b\n  memory: 8GB\n  secret:\n    name: neo4j-aura-api-custom\n    clientIDKey: clientId         # Map to the actual key in the secret\n    clientSecretKey: clientSecret # Map to the actual key in the secret\n```\n\n## Observe reconciliation\n\nEach resource reports various conditions in `.status.conditions` which will give the necessary insight about the \ncurrent state of the resource.\n\n```yaml\nstatus:\n  conditions:\n  - lastTransitionTime: \"2023-11-30T12:01:52Z\"\n    message: random cloud error\n    observedGeneration: 32\n    reason: ReconciliationFailed\n    status: \"False\"\n    type: Ready\n```\n\n## Installation\n\n### Helm\n\nPlease see [chart/neo4j-aura-controller](https://github.com/DoodleScheduling/neo4j-aura-controller/tree/master/chart/neo4j-aura-controller) for the helm chart docs.\n\n### Manifests/kustomize\n\nAlternatively you may get the bundled manifests in each release to deploy it using kustomize or use them directly.\n\n## Configuration\nThe controller can be configured using cmd args:\n```\n      --base-url string                           The base API URL for neo4j Aura. (default \"https://api.neo4j.io/v1\")\n      --concurrent int                            The number of concurrent reconciles. (default 4)\n      --enable-leader-election                    Enable leader election for controller manager. Enabling this will ensure there is only one active controller manager.\n      --graceful-shutdown-timeout duration        The duration given to the reconciler to finish before forcibly stopping. (default 10m0s)\n      --health-addr string                        The address the health endpoint binds to. (default \":9557\")\n      --insecure-kubeconfig-exec                  Allow use of the user.exec section in kubeconfigs provided for remote apply.\n      --insecure-kubeconfig-tls                   Allow that kubeconfigs provided for remote apply can disable TLS verification.\n      --kube-api-burst int                        The maximum burst queries-per-second of requests sent to the Kubernetes API. (default 300)\n      --kube-api-qps float32                      The maximum queries-per-second of requests sent to the Kubernetes API. (default 50)\n      --leader-election-lease-duration duration   Interval at which non-leader candidates will wait to force acquire leadership (duration string). (default 35s)\n      --leader-election-release-on-cancel         Defines if the leader should step down voluntarily on controller manager shutdown. (default true)\n      --leader-election-renew-deadline duration   Duration that the leading controller manager will retry refreshing leadership before giving up (duration string). (default 30s)\n      --leader-election-retry-period duration     Duration the LeaderElector clients should wait between tries of actions (duration string). (default 5s)\n      --log-encoding string                       Log encoding format. Can be 'json' or 'console'. (default \"json\")\n      --log-level string                          Log verbosity level. Can be one of 'trace', 'debug', 'info', 'error'. (default \"info\")\n      --max-retry-delay duration                  The maximum amount of time for which an object being reconciled will have to wait before a retry. (default 15m0s)\n      --metrics-addr string                       The address the metric endpoint binds to. (default \":9556\")\n      --min-retry-delay duration                  The minimum amount of time for which an object being reconciled will have to wait before a retry. (default 750ms)\n      --token-url string                          The OAuth2 token endpoint URL for neo4j Aura. Use for the client credentials flow. (default \"https://api.neo4j.io/oauth/token\")\n      --watch-all-namespaces                      Watch for resources in all namespaces, if set to false it will only watch the runtime namespace. (default true)\n      --watch-label-selector string               Watch for resources with matching labels e.g. 'sharding.fluxcd.io/shard=shard1'.\n```\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fdoodlescheduling%2Fneo4j-aura-controller","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fdoodlescheduling%2Fneo4j-aura-controller","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fdoodlescheduling%2Fneo4j-aura-controller/lists"}