WP-40/41/42: dashboard, security hardening, deployment and operations docs
Dashboard endpoint and page aggregating inventory, vulnerabilities, cluster health, backups and recent jobs. Security headers (CSP, nosniff, DENY, referrer policy), 1 MB body limit, configurable login rate limit, audit steps in CI. Installer script, systemd unit, install/architecture docs. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
@ -9,6 +9,8 @@ BIND=127.0.0.1:8080
|
||||
# Created on first start if no user exists
|
||||
BOOTSTRAP_ADMIN_EMAIL=admin@example.com
|
||||
BOOTSTRAP_ADMIN_PASSWORD=change-me-min-12-chars
|
||||
# Login attempts per IP and minute (default 10)
|
||||
#LOGIN_RATE_LIMIT=10
|
||||
# Set to true behind HTTPS so the refresh cookie is marked Secure
|
||||
COOKIE_SECURE=false
|
||||
# Directory with the built frontend (served as SPA fallback)
|
||||
|
||||
Reference in New Issue
Block a user