WP-40/41/42: dashboard, security hardening, deployment and operations docs

Dashboard endpoint and page aggregating inventory, vulnerabilities, cluster
health, backups and recent jobs. Security headers (CSP, nosniff, DENY,
referrer policy), 1 MB body limit, configurable login rate limit, audit
steps in CI. Installer script, systemd unit, install/architecture docs.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
Dennis Nemec
2026-09-02 23:26:01 +02:00
parent a89395ae18
commit 9234e1ba47
29 changed files with 851 additions and 21 deletions

View File

@ -372,8 +372,9 @@ mod tests {
#[tokio::test]
async fn image_scan_prefers_local_containerd_when_configured() {
use std::sync::Mutex;
type Call = (Vec<String>, Vec<(String, String)>);
#[derive(Default)]
struct Env(Mutex<Vec<(Vec<String>, Vec<(String, String)>)>>);
struct Env(Mutex<Vec<Call>>);
#[async_trait]
impl CommandRunner for Env {
async fn run(&self, p: &str, a: &[&str]) -> Result<crate::host::Output, DomainError> {