WP-40/41/42: dashboard, security hardening, deployment and operations docs

Dashboard endpoint and page aggregating inventory, vulnerabilities, cluster
health, backups and recent jobs. Security headers (CSP, nosniff, DENY,
referrer policy), 1 MB body limit, configurable login rate limit, audit
steps in CI. Installer script, systemd unit, install/architecture docs.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
Dennis Nemec
2026-09-02 23:26:01 +02:00
parent a89395ae18
commit 9234e1ba47
29 changed files with 851 additions and 21 deletions

View File

@ -15,6 +15,9 @@ jobs:
with: { workspaces: backend }
- run: cd backend && cargo fmt --check && cargo clippy --workspace --all-targets -- -D warnings
- run: cd backend && cargo test --workspace
- uses: rustsec/audit-check@v2
with: { token: ${{ secrets.GITHUB_TOKEN }} }
continue-on-error: true
frontend:
runs-on: ubuntu-latest
@ -24,6 +27,8 @@ jobs:
with: { node-version: 22, cache: npm, cache-dependency-path: frontend/package-lock.json }
- run: cd frontend && npm ci
- run: cd frontend && npm run lint && npm run typecheck && npm test
- run: cd frontend && npm audit --audit-level=high
continue-on-error: true
ui:
runs-on: ubuntu-latest