WP-40/41/42: dashboard, security hardening, deployment and operations docs

Dashboard endpoint and page aggregating inventory, vulnerabilities, cluster
health, backups and recent jobs. Security headers (CSP, nosniff, DENY,
referrer policy), 1 MB body limit, configurable login rate limit, audit
steps in CI. Installer script, systemd unit, install/architecture docs.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
Dennis Nemec
2026-09-02 23:26:01 +02:00
parent a89395ae18
commit 9234e1ba47
29 changed files with 851 additions and 21 deletions

View File

@ -20,6 +20,8 @@ pub struct Config {
pub bind: SocketAddr,
pub bootstrap_admin: Option<(String, String)>,
pub cookie_secure: bool,
/// Login attempts per IP and minute.
pub login_rate_limit: u32,
pub frontend_dir: String,
}
@ -69,6 +71,9 @@ impl Config {
.parse()?,
bootstrap_admin: env("BOOTSTRAP_ADMIN_EMAIL").zip(env("BOOTSTRAP_ADMIN_PASSWORD")),
cookie_secure: env("COOKIE_SECURE").is_some_and(|v| v == "true" || v == "1"),
login_rate_limit: env("LOGIN_RATE_LIMIT")
.and_then(|v| v.parse().ok())
.unwrap_or(10),
frontend_dir: env("FRONTEND_DIR").unwrap_or_else(|| "../frontend/dist".into()),
})
}