WP-40/41/42: dashboard, security hardening, deployment and operations docs

Dashboard endpoint and page aggregating inventory, vulnerabilities, cluster
health, backups and recent jobs. Security headers (CSP, nosniff, DENY,
referrer policy), 1 MB body limit, configurable login rate limit, audit
steps in CI. Installer script, systemd unit, install/architecture docs.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
Dennis Nemec
2026-09-02 23:26:01 +02:00
parent a89395ae18
commit 9234e1ba47
29 changed files with 851 additions and 21 deletions

View File

@ -39,6 +39,11 @@ Every feature starts with its tests:
3. Implement the smallest code that makes them pass, then refactor.
4. Commit and push.
## Deployment
See [docs/install.md](docs/install.md) (release build, `deploy/install.sh`, systemd unit) and
[docs/restore.md](docs/restore.md) for restoring backups. `docs/architecture.md` describes the layers.
## First admin
On start the backend creates an admin user from `BOOTSTRAP_ADMIN_EMAIL` /