Skip to content

chore: remove unused dependencies across the workspace - #623

Merged
moonming merged 1 commit into
mainfrom
chore/prune-unused-deps
Jun 16, 2026
Merged

chore: remove unused dependencies across the workspace#623
moonming merged 1 commit into
mainfrom
chore/prune-unused-deps

Conversation

@moonming

@moonming moonming commented Jun 16, 2026

Copy link
Copy Markdown
Collaborator

What

Removes dependencies that are declared but never referenced, found with cargo-machete and confirmed by per-crate source verification.

  • Unused per-crate deps across 15 crates (51 entries).
  • 20 [workspace.dependencies] declarations left without any consumer: 4 that were never used (including a vestigial tiktoken-rs scaffold dep carried since PR PR #1: Scaffold Cargo workspace, UI skeleton, and CI pipeline #1), plus 16 orphaned once the per-crate consumers were removed.

Net: +4 / −395 lines, including a large Cargo.lock reduction (the now-unreachable transitive crates are pruned too).

Why these were genuinely unused (not macro/derive false positives)

Every cargo-machete hit was checked against the crate's source before removal:

  • aisix-obs hand-rolls its OTLP/HTTP export (reqwest + serde_json), so the opentelemetry, opentelemetry_sdk, opentelemetry-otlp, opentelemetry-semantic-conventions and tracing-opentelemetry crates were never linked — only mentioned in a doc comment.
  • The provider crates (openai, azure-openai, vertex, bedrock) share an error type and don't log directly, so their per-crate thiserror / tracing entries were unused.
  • aisix-proxy reaches http types through axum::http, so its direct http and hyper deps were redundant.
  • aisix-ratelimit / aisix-cache declared serde but never derive/use it (they use serde_json on types owned elsewhere); aisix-cache's direct aisix-core path-dep is reached via aisix-gateway.
  • Dev-deps insta / rstest / serde_yaml (core) and rstest (ratelimit) are not referenced by any test.

aws-smithy-types in aisix-guardrails was optional behind the bedrock feature; the bedrock path only uses aws_smithy_runtime_api / aws_smithy_async, so the dep and its dep: feature entry were both dropped.

Verification

  • cargo check --workspace --all-targetsgreen (covers all test targets, so the dev-dep removals are exercised; default features include the bedrock guardrail, so the aws-smithy-types removal is compiled).
  • No behavior change — every removed crate was unreferenced.
  • CI runs the full test matrix on top of this.

Summary by CodeRabbit

  • Chores

    • Streamlined workspace dependencies by consolidating and removing unused libraries across all components.
    • Reorganized runtime and testing dependencies to improve build efficiency and maintainability.
    • Removed obsolete observability and telemetry integrations.
  • Refactor

    • Updated internal dependency structure for improved code organization and reduced compilation footprint.

@coderabbitai

coderabbitai Bot commented Jun 16, 2026

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

@moonming, we couldn't start this review because you've reached your PR review rate limit.

More reviews will be available in 6 minutes and 12 seconds. Learn how PR review limits work.

Your organization has used up its prepaid credits, and credit purchases are no longer available. Enable the review add-on in the billing tab to keep reviews running — you're only billed for reviews past your plan's rate limits ($0.25/file).

⌛ How to resolve this issue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans include higher PR review limits than trial, open-source, and free plans. In all cases, reviews become available again over time. During sustained high-volume PR review activity, CodeRabbit may temporarily slow when the next review becomes available.

Please see our Fair Usage Limits Policy for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Free

Run ID: d54480c0-9c2d-4fdd-926f-9a3526410f50

📥 Commits

Reviewing files that changed from the base of the PR and between b0ba662 and 19469d7.

⛔ Files ignored due to path filters (1)
  • Cargo.lock is excluded by !**/*.lock
📒 Files selected for processing (16)
  • Cargo.toml
  • crates/aisix-admin/Cargo.toml
  • crates/aisix-cache/Cargo.toml
  • crates/aisix-core/Cargo.toml
  • crates/aisix-etcd/Cargo.toml
  • crates/aisix-gateway/Cargo.toml
  • crates/aisix-guardrails/Cargo.toml
  • crates/aisix-obs/Cargo.toml
  • crates/aisix-provider-anthropic/Cargo.toml
  • crates/aisix-provider-azure-openai/Cargo.toml
  • crates/aisix-provider-bedrock/Cargo.toml
  • crates/aisix-provider-openai/Cargo.toml
  • crates/aisix-provider-vertex/Cargo.toml
  • crates/aisix-proxy/Cargo.toml
  • crates/aisix-ratelimit/Cargo.toml
  • crates/aisix-server/Cargo.toml
📝 Walkthrough

Walkthrough

Removes unused and replaced Cargo dependencies across the root workspace manifest and all 15 crate manifests. Dropped crates include the full HTTP/TLS stack (hyper, tokio-rustls, etc.), OpenTelemetry exporters, chrono, anyhow, thiserror (from providers), and test utilities (rstest, insta, serde_yaml). Replacement additions include futures, metrics, testcontainers, and tempfile.

Changes

Workspace Dependency Cleanup

Layer / File(s) Summary
Root workspace dependency declarations
Cargo.toml
Removes tokio-stream, tokio-util, futures-util, hyper, hyper-util, mime, tokio-rustls, rustls-pemfile, serde_yaml, full OpenTelemetry stack, tiktoken-rs, humantime, rstest, insta; adds futures, testcontainers, tempfile.
Core and infrastructure crate manifests
crates/aisix-core/Cargo.toml, crates/aisix-etcd/Cargo.toml, crates/aisix-server/Cargo.toml
aisix-core removes uuid, chrono, tracing, humantime-serde, regex, and test deps (insta, rstest, serde_yaml), adds tempfile dev-dep. aisix-etcd replaces tokio-stream/tokio-util/futures-util/anyhow with futures, async-trait, serde, serde_json, thiserror. aisix-server drops hyper, tower, tower-http, http, tokio-rustls, rustls-pemfile, thiserror, chrono.
Provider crate manifests
crates/aisix-provider-anthropic/Cargo.toml, crates/aisix-provider-azure-openai/Cargo.toml, crates/aisix-provider-bedrock/Cargo.toml, crates/aisix-provider-openai/Cargo.toml, crates/aisix-provider-vertex/Cargo.toml
Anthropic drops base64. Azure-OpenAI and OpenAI drop thiserror. Bedrock drops thiserror and tracing. Vertex drops thiserror and tracing, adds reqwest, serde, serde_json, tokio, http.
Gateway, proxy, cache, ratelimit, obs, guardrails, admin manifests
crates/aisix-gateway/Cargo.toml, crates/aisix-proxy/Cargo.toml, crates/aisix-cache/Cargo.toml, crates/aisix-ratelimit/Cargo.toml, crates/aisix-obs/Cargo.toml, crates/aisix-guardrails/Cargo.toml, crates/aisix-admin/Cargo.toml
Gateway replaces tokio-stream/futures-util/eventsource-stream/anyhow/tracing with futures, async-trait, reqwest, bytes, serde, serde_json, thiserror. Proxy drops hyper, http, futures-util. Cache swaps dependency on aisix-core for aisix-gateway. Ratelimit swaps serde/serde_json/chrono for thiserror/tracing/async-trait/redis/uuid. Obs drops full OpenTelemetry stack, adds metrics, metrics-exporter-prometheus, and related crates. Guardrails removes aws-smithy-types and its feature gate. Admin removes tower-http and chrono.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes


Note

🎁 Summarized by CodeRabbit Free

Your organization has reached its limit of developer seats under the Pro Plan. For new users, CodeRabbit will generate a high-level summary and a walkthrough for each pull request. For a comprehensive line-by-line review, please add seats to your subscription by visiting https://app.coderabbit.ai/login.If you believe this is a mistake and have available seats, please assign one to the pull request author through the subscription management page using the link above.

Comment @coderabbitai help to get the list of available commands and usage tips.

cargo-machete plus per-crate source verification surfaced dependencies
declared but never referenced. Removed and verified green with
`cargo check --workspace --all-targets`:

- Unused per-crate deps in 15 crates. aisix-obs hand-rolls its OTLP/HTTP
  export so the opentelemetry-* SDK crates were dead; the provider crates
  share an error type so their per-crate thiserror/tracing entries were
  unused; aisix-proxy reaches http types via axum::http so its direct
  http/hyper deps were redundant.
- 20 [workspace.dependencies] entries left without any consumer (4 never
  used, including a vestigial tiktoken-rs scaffold dep; 16 orphaned by the
  per-crate removals).

No behavior change; every removed crate was unreferenced. Prunes ~395
lines including a large Cargo.lock reduction.
@moonming
moonming force-pushed the chore/prune-unused-deps branch from b0ba662 to 19469d7 Compare June 16, 2026 07:19
@moonming
moonming merged commit b756939 into main Jun 16, 2026
11 checks passed
@moonming
moonming deleted the chore/prune-unused-deps branch June 16, 2026 07:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant