WP-40/41/42: dashboard, security hardening, deployment and operations docs
Dashboard endpoint and page aggregating inventory, vulnerabilities, cluster health, backups and recent jobs. Security headers (CSP, nosniff, DENY, referrer policy), 1 MB body limit, configurable login rate limit, audit steps in CI. Installer script, systemd unit, install/architecture docs. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
52
deploy/install.sh
Executable file
52
deploy/install.sh
Executable file
@ -0,0 +1,52 @@
|
||||
#!/usr/bin/env bash
|
||||
# Server-side installer/updater. Run as root on the Debian host with the release
|
||||
# archive (monitoring-server binary + dist/) in the current directory:
|
||||
# ./install.sh [--port 8080]
|
||||
set -euo pipefail
|
||||
DIR=/opt/monitoring
|
||||
PORT=${PORT:-8080}
|
||||
[[ "${1:-}" == "--port" ]] && PORT=$2
|
||||
|
||||
echo "== dependencies"
|
||||
apt-get install -y -q smbclient curl gzip tar openssl >/dev/null
|
||||
if ! command -v trivy >/dev/null; then
|
||||
apt-get install -y -q wget apt-transport-https gnupg >/dev/null
|
||||
wget -qO- https://aquasecurity.github.io/trivy-repo/deb/public.key | gpg --dearmor -o /usr/share/keyrings/trivy.gpg
|
||||
echo "deb [signed-by=/usr/share/keyrings/trivy.gpg] https://aquasecurity.github.io/trivy-repo/deb generic main" > /etc/apt/sources.list.d/trivy.list
|
||||
apt-get update -q >/dev/null && apt-get install -y -q trivy >/dev/null
|
||||
fi
|
||||
|
||||
echo "== files"
|
||||
mkdir -p "$DIR/data"
|
||||
systemctl stop monitoring.service 2>/dev/null || true
|
||||
install -m 0755 monitoring-server "$DIR/monitoring-server"
|
||||
rm -rf "$DIR/dist" && cp -r dist "$DIR/dist"
|
||||
install -m 0644 monitoring.service /etc/systemd/system/monitoring.service
|
||||
|
||||
if [[ ! -f "$DIR/.env" ]]; then
|
||||
echo "== first run: creating $DIR/.env"
|
||||
ADMIN_PW=$(openssl rand -base64 18 | tr -d '/+=' | head -c 20)
|
||||
umask 077
|
||||
cat > "$DIR/.env" <<ENV
|
||||
DATABASE_URL=sqlite://$DIR/data/monitoring.db?mode=rwc
|
||||
JWT_SECRET=$(openssl rand -hex 32)
|
||||
MASTER_KEY=$(openssl rand -hex 32)
|
||||
BIND=0.0.0.0:$PORT
|
||||
BOOTSTRAP_ADMIN_EMAIL=admin@softvisor.de
|
||||
BOOTSTRAP_ADMIN_PASSWORD=$ADMIN_PW
|
||||
COOKIE_SECURE=false
|
||||
FRONTEND_DIR=$DIR/dist
|
||||
WORK_DIR=$DIR/data/work
|
||||
RUST_LOG=info,sqlx=warn
|
||||
ENV
|
||||
echo "Bootstrap admin: admin@softvisor.de / $ADMIN_PW (change it after the first login)"
|
||||
fi
|
||||
grep -q '^MASTER_KEY=' "$DIR/.env" || echo "MASTER_KEY=$(openssl rand -hex 32)" >> "$DIR/.env"
|
||||
|
||||
echo "== service"
|
||||
systemctl daemon-reload
|
||||
systemctl enable -q monitoring.service
|
||||
systemctl restart monitoring.service
|
||||
sleep 2
|
||||
systemctl is-active monitoring.service
|
||||
curl -s "http://127.0.0.1:$PORT/healthz" && echo
|
||||
Reference in New Issue
Block a user