Docs

Configuration

Most repositories need none. The first start detects your applications and writes them to .codiluce/config.yml, which you can then adjust.

Detection

A directory is an application when a manifest there declares one. Codiluce looks two levels deep, so a monorepo with frontend/ and backend/ is found as two applications. An application may contain another.

EcosystemManifests
nodepackage.json
phpcomposer.json
pythonpyproject.toml, requirements*.txt, Pipfile, setup.py, manage.py
rubyGemfile, *.gemspec
gogo.mod
rustCargo.toml
jvmpom.xml, build.gradle(.kts), build.sbt
dotnet*.csproj, *.fsproj, *.vbproj
swift / xcodePackage.swift, *.xcodeproj
nativeCMakeLists.txt, meson.build
shopifylayout/theme.liquid

Each manifest also names the frameworks an application is built on. TypeScript and JavaScript are analyzed down to calls and requests in any application, and supported frameworks down to routes, commands and tables. Every file in a known language is named, measured and highlighted: TypeScript, JavaScript, PHP, Python, Go, Rust, Java, Kotlin, Scala, C#, F#, VB.NET, Ruby, C, C++, Objective-C, Swift, Vue, Svelte, Astro, Liquid and Razor.

config.yml

.codiluce/config.yml
repository:
  name: example-repository
  # Optional stable namespace shared across renamed or relocated checkouts:
  # id: my-example-repository
applications:
  - name: frontend
    path: frontend
    frameworks: [react]
  - name: backend
    path: backend
    frameworks: [express]
    apiOrigins:
      - https://api.example.test
    # Environment variables the frontend reads its API base URL from:
    apiOriginEnv:
      - API_BASE_URL
ignore:
  - "**/custom-generated/**"
maxFileBytes: 1048576
  • applications: explicit applications replace detection. Paths are relative to the repository and must stay inside it. Configured frameworks come first; the first one says what the application is.
  • apiOrigins: the absolute origins an application answers on. A frontend request to one of them is linked to that application’s routes.
  • apiOriginEnv: the environment variables your code reads its API base URL from. This is an assumption you declare, so every request linked through one carries it as evidence.
  • ignore: extra patterns (*, **, ?) on top of safe defaults. Git-ignored files are skipped too, and so are symlinks, secret-like files, generated output and binaries.
  • repository.id: keeps entity identities stable when two repositories share a name. Changing it changes every ID.

How requests are linked

A request URL is linked to an endpoint only when every value its base can take is proven. The analyzer follows template literals, concatenation, constants (also imported ones), class properties, local functions, new URL(…), ||, ?? and conditionals, through axios instances and wrapper functions, down to a configured origin or a declared variable.

A dynamic value may fill a whole path segment (users/${id} matches only a route parameter) or sit in the query string. Anything else, such as a forgotten http://localhost:8000 or an undeclared variable, stays an unresolved-http-call finding whose reason names it.

Keep state private. The state directory holds paths, symbols and routes of your code. Keep it in .codiluce/ and add that to .gitignore, or put it outside the repository with --state-dir. Share only sanitized configuration.