WP-40/41/42: dashboard, security hardening, deployment and operations docs

Dashboard endpoint and page aggregating inventory, vulnerabilities, cluster
health, backups and recent jobs. Security headers (CSP, nosniff, DENY,
referrer policy), 1 MB body limit, configurable login rate limit, audit
steps in CI. Installer script, systemd unit, install/architecture docs.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
Dennis Nemec
2026-09-02 23:26:01 +02:00
parent a89395ae18
commit 9234e1ba47
29 changed files with 851 additions and 21 deletions

52
deploy/install.sh Executable file
View File

@ -0,0 +1,52 @@
#!/usr/bin/env bash
# Server-side installer/updater. Run as root on the Debian host with the release
# archive (monitoring-server binary + dist/) in the current directory:
# ./install.sh [--port 8080]
set -euo pipefail
DIR=/opt/monitoring
PORT=${PORT:-8080}
[[ "${1:-}" == "--port" ]] && PORT=$2
echo "== dependencies"
apt-get install -y -q smbclient curl gzip tar openssl >/dev/null
if ! command -v trivy >/dev/null; then
apt-get install -y -q wget apt-transport-https gnupg >/dev/null
wget -qO- https://aquasecurity.github.io/trivy-repo/deb/public.key | gpg --dearmor -o /usr/share/keyrings/trivy.gpg
echo "deb [signed-by=/usr/share/keyrings/trivy.gpg] https://aquasecurity.github.io/trivy-repo/deb generic main" > /etc/apt/sources.list.d/trivy.list
apt-get update -q >/dev/null && apt-get install -y -q trivy >/dev/null
fi
echo "== files"
mkdir -p "$DIR/data"
systemctl stop monitoring.service 2>/dev/null || true
install -m 0755 monitoring-server "$DIR/monitoring-server"
rm -rf "$DIR/dist" && cp -r dist "$DIR/dist"
install -m 0644 monitoring.service /etc/systemd/system/monitoring.service
if [[ ! -f "$DIR/.env" ]]; then
echo "== first run: creating $DIR/.env"
ADMIN_PW=$(openssl rand -base64 18 | tr -d '/+=' | head -c 20)
umask 077
cat > "$DIR/.env" <<ENV
DATABASE_URL=sqlite://$DIR/data/monitoring.db?mode=rwc
JWT_SECRET=$(openssl rand -hex 32)
MASTER_KEY=$(openssl rand -hex 32)
BIND=0.0.0.0:$PORT
BOOTSTRAP_ADMIN_EMAIL=admin@softvisor.de
BOOTSTRAP_ADMIN_PASSWORD=$ADMIN_PW
COOKIE_SECURE=false
FRONTEND_DIR=$DIR/dist
WORK_DIR=$DIR/data/work
RUST_LOG=info,sqlx=warn
ENV
echo "Bootstrap admin: admin@softvisor.de / $ADMIN_PW (change it after the first login)"
fi
grep -q '^MASTER_KEY=' "$DIR/.env" || echo "MASTER_KEY=$(openssl rand -hex 32)" >> "$DIR/.env"
echo "== service"
systemctl daemon-reload
systemctl enable -q monitoring.service
systemctl restart monitoring.service
sleep 2
systemctl is-active monitoring.service
curl -s "http://127.0.0.1:$PORT/healthz" && echo