WP-40/41/42: dashboard, security hardening, deployment and operations docs

Dashboard endpoint and page aggregating inventory, vulnerabilities, cluster
health, backups and recent jobs. Security headers (CSP, nosniff, DENY,
referrer policy), 1 MB body limit, configurable login rate limit, audit
steps in CI. Installer script, systemd unit, install/architecture docs.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
Dennis Nemec
2026-09-02 23:26:01 +02:00
parent a89395ae18
commit 9234e1ba47
29 changed files with 851 additions and 21 deletions

View File

@ -25,7 +25,7 @@ test('admin logs in, manages users, logs out; user has no admin access', async (
await expect(page.getByRole('heading', { name: 'Dashboard' })).toBeVisible()
// create a user
await page.getByRole('link', { name: 'Users' }).click()
await page.getByRole('navigation').getByRole('link', { name: 'Users' }).click()
await page.getByRole('button', { name: 'New user' }).click()
const email = `e2e-${Date.now()}@example.com`
await page.getByLabel('Email').fill(email)
@ -48,7 +48,7 @@ test('admin logs in, manages users, logs out; user has no admin access', async (
// the new user can log in but not manage users
await login(page, email, 'user-password-123')
await expect(page.getByRole('heading', { name: 'Dashboard' })).toBeVisible()
await expect(page.getByRole('link', { name: 'Users' })).toHaveCount(0)
await expect(page.getByRole('navigation').getByRole('link', { name: 'Users' })).toHaveCount(0)
await page.goto('/users')
await expect(page.getByText('You do not have permission')).toBeVisible()
})

View File

@ -5,7 +5,7 @@ test('admin creates a target and a strategy, runs it and sees the backup', async
await page.getByLabel('Email').fill('admin@example.com')
await page.getByLabel('Password').fill('admin-password-123')
await page.getByRole('button', { name: 'Sign in' }).click()
await page.getByRole('link', { name: 'Backups' }).click()
await page.getByRole('navigation').getByRole('link', { name: 'Backups' }).click()
await page.getByRole('button', { name: 'New target' }).click()
const name = `NAS ${Date.now()}`

View File

@ -7,7 +7,7 @@ test('cluster page shows node, workloads and lets an admin restart a workload',
await page.getByLabel('Email').fill('admin@example.com')
await page.getByLabel('Password').fill('admin-password-123')
await page.getByRole('button', { name: 'Sign in' }).click()
await page.getByRole('link', { name: 'Kubernetes' }).click()
await page.getByRole('navigation').getByRole('link', { name: 'Kubernetes' }).click()
await expect(page.getByTestId('node-version')).toContainText('v1.32')
const row = page.getByRole('row', { name: /^gitea gitea-postgresql statefulset/ })

View File

@ -0,0 +1,14 @@
import { test, expect } from '@playwright/test'
test('dashboard shows the overview tiles after login', async ({ page }) => {
await page.goto('/login')
await page.getByLabel('Email').fill('admin@example.com')
await page.getByLabel('Password').fill('admin-password-123')
await page.getByRole('button', { name: 'Sign in' }).click()
await expect(page.getByRole('heading', { name: 'Dashboard' })).toBeVisible()
await expect(page.getByTestId('tile-workloads')).toContainText('5')
await expect(page.getByTestId('tile-critical')).toBeVisible()
await expect(page.getByRole('heading', { name: 'Backups' })).toBeVisible()
await page.getByTestId('tile-workloads').click()
await expect(page).toHaveURL(/\/cluster/)
})

View File

@ -10,7 +10,7 @@ async function loginAdmin(page: Page) {
test('admin saves SMTP settings and a schedule', async ({ page }) => {
await loginAdmin(page)
await page.getByRole('link', { name: 'Settings' }).click()
await page.getByRole('navigation').getByRole('link', { name: 'Settings' }).click()
await page.getByLabel('SMTP host').fill('mail.example.com')
await page.getByLabel('Port').fill('587')
await page.getByLabel('Username').fill('bot')
@ -31,7 +31,7 @@ test('admin saves SMTP settings and a schedule', async ({ page }) => {
test('admin runs a job manually and sees the log', async ({ page }) => {
await loginAdmin(page)
await page.getByRole('link', { name: 'Jobs' }).click()
await page.getByRole('navigation').getByRole('link', { name: 'Jobs' }).click()
await page.getByLabel('Job').selectOption('package_refresh')
await page.getByRole('button', { name: 'Run now' }).click()
const row = page.getByRole('row', { name: /package_refresh/ }).first()

View File

@ -5,7 +5,7 @@ test('updates page shows OS info and packages after a refresh', async ({ page })
await page.getByLabel('Email').fill('admin@example.com')
await page.getByLabel('Password').fill('admin-password-123')
await page.getByRole('button', { name: 'Sign in' }).click()
await page.getByRole('link', { name: 'Updates' }).click()
await page.getByRole('navigation').getByRole('link', { name: 'Updates' }).click()
await page.getByRole('button', { name: 'Refresh inventory' }).click()
await expect(page.getByTestId('os-name')).toContainText('Debian', { timeout: 15_000 })

View File

@ -5,7 +5,7 @@ test('admin updates a selected package and sees the live log', async ({ page })
await page.getByLabel('Email').fill('admin@example.com')
await page.getByLabel('Password').fill('admin-password-123')
await page.getByRole('button', { name: 'Sign in' }).click()
await page.getByRole('link', { name: 'Updates' }).click()
await page.getByRole('navigation').getByRole('link', { name: 'Updates' }).click()
await page.getByRole('button', { name: 'Refresh inventory' }).click()
await expect(page.getByTestId('os-name')).toContainText('Debian', { timeout: 15_000 })

View File

@ -5,7 +5,7 @@ test('admin runs a scan, filters findings and acknowledges one', async ({ page }
await page.getByLabel('Email').fill('admin@example.com')
await page.getByLabel('Password').fill('admin-password-123')
await page.getByRole('button', { name: 'Sign in' }).click()
await page.getByRole('link', { name: 'Vulnerabilities' }).click()
await page.getByRole('navigation').getByRole('link', { name: 'Vulnerabilities' }).click()
await page.getByRole('button', { name: 'Scan now' }).click()
await expect(page.getByTestId('count-critical')).not.toHaveText('0', { timeout: 20_000 })
@ -29,7 +29,7 @@ test('notification threshold can be changed in settings', async ({ page }) => {
await page.getByLabel('Email').fill('admin@example.com')
await page.getByLabel('Password').fill('admin-password-123')
await page.getByRole('button', { name: 'Sign in' }).click()
await page.getByRole('link', { name: 'Settings' }).click()
await page.getByRole('navigation').getByRole('link', { name: 'Settings' }).click()
await page.getByLabel('Notify from severity').selectOption('medium')
await page.getByRole('button', { name: 'Save notifications' }).click()
await expect(page.getByRole('status')).toContainText('Notification settings saved')