WP-00: project skeleton with three-level test harness
Cargo workspace (domain, application, infrastructure, api), axum health endpoint with SPA fallback, Vue 3 + Tailwind frontend, Vitest, Playwright, Makefile, Gitea Actions CI and README. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
36
ROADMAP.md
36
ROADMAP.md
@ -116,13 +116,13 @@ Each WP follows the same TDD sequence:
|
||||
- Cargo workspace with the four crates, `axum` hello endpoint, `/healthz`
|
||||
- Vue 3 + Vite + Tailwind + TypeScript + Pinia + Router scaffold
|
||||
- SQLite + `sqlx` migrations setup, config loading from env / `.env`
|
||||
- `justfile`/Makefile: `dev`, `build`, `test`, `lint` (clippy, rustfmt, eslint, prettier)
|
||||
- `Makefile`: `dev`, `build`, `test`, `lint` (clippy, rustfmt, eslint, prettier)
|
||||
- CI: GitHub/Gitea Actions running lint + test
|
||||
- Test harness: `cargo test` layout per crate, integration test helper (test app + temp
|
||||
SQLite), Vitest + Vue Test Utils, Playwright with a `just test-ui` target; one sample test
|
||||
SQLite), Vitest + Vue Test Utils, Playwright with a `make test-ui` target; one sample test
|
||||
of each kind runs in CI
|
||||
- README with dev setup and the TDD workflow
|
||||
- **Done when:** `just dev` serves frontend + backend, `just test` runs unit, integration
|
||||
- **Done when:** `make dev` serves frontend + backend, `make test` runs unit, integration
|
||||
and UI tests, CI green
|
||||
|
||||
#### WP-01 Authentication & user management (M)
|
||||
@ -263,13 +263,13 @@ a regular user can log in with restricted rights. Everything else is navigation
|
||||
|
||||
| WP | Scope in this milestone |
|
||||
|----|-------------------------|
|
||||
| WP-00 | Full scope: workspace, frontend scaffold, SQLite + migrations, `justfile`, CI, test harness (cargo test, Vitest, Playwright) |
|
||||
| WP-00 | Full scope: workspace, frontend scaffold, SQLite + migrations, `Makefile`, CI, test harness (cargo test, Vitest, Playwright) |
|
||||
| WP-01 | Full scope: Argon2id, JWT + rotating refresh cookie, roles, bootstrap admin, user CRUD UI, login page, route guards, rate limiting, auth audit log |
|
||||
| WP-02 (partial) | Only the application shell: sidebar navigation with placeholder pages, global error handling, toasts, loading/empty states. Secret storage, scheduler and SMTP stay in Milestone 2 |
|
||||
|
||||
**Deliverables**
|
||||
|
||||
- `just dev` starts backend + frontend; `just test` runs unit, integration and UI tests; CI green
|
||||
- `make dev` starts backend + frontend; `make test` runs unit, integration and UI tests; CI green
|
||||
- Login / logout / token refresh work end to end (Playwright flow)
|
||||
- Admin: list, create, edit, deactivate users, reset password
|
||||
- Non-admin: can log in, sees the shell, gets 403 on admin routes (API and UI)
|
||||
@ -308,22 +308,32 @@ WP-40, WP-41, WP-42.
|
||||
|
||||
## 5. Open questions (answer before the affected WP)
|
||||
|
||||
The server is reachable via `ssh softvisor`. Questions 2, 3 and 6 can be answered by
|
||||
inspecting the host directly (`/etc/os-release`, kubeconfig location, `kubectl get all -A`,
|
||||
`dpkg -l`, `snap list`) instead of asking.
|
||||
The server is reachable via `ssh softvisor` (as root). Findings from the inspection on
|
||||
2026-09-02, which answer questions 2, 3, 4 (partly), 6 and 10:
|
||||
|
||||
- Debian 12 (bookworm), kernel 6.1, ~433 dpkg packages, snaps: `microk8s`, `core20`, `snapd`
|
||||
- Kubernetes: **microk8s v1.32** (snap); kubectl via `/snap/bin/microk8s kubectl`;
|
||||
kubeconfig at `/var/snap/microk8s/current/credentials/client.config` (group `microk8s`)
|
||||
- Namespaces: `gitea`, `cert-manager`, `ingress`, `metallb-system`, `inlets`
|
||||
- Gitea: `deployment/gitea` in ns `gitea`, PVC `gitea-shared-storage` (10Gi, hostpath);
|
||||
Postgres: `statefulset/gitea-postgresql`, PVC `data-gitea-postgresql-0`; Valkey
|
||||
`statefulset/gitea-valkey-primary`. Old unused PVCs from a former HA setup exist.
|
||||
All PVCs use `microk8s-hostpath`, so backups can read data from the host filesystem.
|
||||
- Tools present: `smbclient`, `helm` (needs kubeconfig); **Trivy not installed**
|
||||
- Git remote is the company Gitea (`git.dev.softvisor.de`) → CI uses Gitea Actions
|
||||
|
||||
| # | Question | Affects | Assumption if unanswered |
|
||||
|---|----------|---------|--------------------------|
|
||||
| 1 | Does the backend run directly on the Debian host (systemd) or inside the cluster? | WP-00, WP-11, WP-42 | Directly on the host as systemd service |
|
||||
| 2 | Kubernetes distribution (k3s, kubeadm, microk8s)? Path to kubeconfig? | WP-12 | k3s, `/etc/rancher/k3s/k3s.yaml` |
|
||||
| 3 | How is Gitea deployed (Helm chart, plain manifests)? Namespace, PVC names, Postgres in-cluster or external? | WP-12, WP-31 | Helm chart in namespace `gitea`, Postgres as in-cluster StatefulSet |
|
||||
| 4 | Is Trivy acceptable as external dependency (installed on host)? | WP-20 | Yes |
|
||||
| 2 | ~~Kubernetes distribution?~~ **Answered:** microk8s 1.32, kubeconfig `/var/snap/microk8s/current/credentials/client.config` | WP-12 | – |
|
||||
| 3 | ~~How is Gitea deployed?~~ **Answered:** ns `gitea`, `deployment/gitea` + PVC `gitea-shared-storage`, `statefulset/gitea-postgresql` + PVC `data-gitea-postgresql-0`, hostpath storage | WP-12, WP-31 | – |
|
||||
| 4 | Is Trivy acceptable as external dependency? It is **not yet installed** on the host | WP-20 | Yes, installed in WP-20 |
|
||||
| 5 | SMTP relay available for notifications? Sender address? | WP-02, WP-21 | Yes, configured via settings UI |
|
||||
| 6 | "Applications" beyond apt packages: are there non-apt installs (snap, binaries, Docker outside k8s) to inventory? | WP-10 | Only apt packages + k8s workloads |
|
||||
| 6 | ~~Non-apt installs?~~ **Answered:** snaps (`microk8s`, `core20`, `snapd`) and `/usr/local/bin/helm`; snaps will be inventoried in WP-10 | WP-10 | – |
|
||||
| 7 | Is unattended OS major-version upgrade (e.g. Debian 12 → 13) in scope, or only `apt` upgrades within a release? | WP-11 | Only in-release upgrades; major upgrade is documented, not automated |
|
||||
| 8 | Backup encryption required, or is transport encryption to the target enough? | WP-31 | Optional per strategy, off by default |
|
||||
| 9 | Should non-admin users be pure viewers or also able to trigger scans/backups? | WP-01 | Viewers only; all mutating actions are admin |
|
||||
| 10 | Git hosting for this project itself: GitHub or the company Gitea? (affects CI syntax) | WP-00 | Whatever `origin` points to; GitHub Actions syntax, which Gitea Actions also runs |
|
||||
| 10 | ~~Git hosting?~~ **Answered:** company Gitea → Gitea Actions (`.gitea/workflows`) | WP-00 | – |
|
||||
|
||||
---
|
||||
|
||||
|
||||
Reference in New Issue
Block a user