The dump assumed the official image's environment and the postgres
superuser. Bitnami keeps its passwords in files, and on this cluster the
superuser password no longer matches the database, so the Gitea database
backup would have failed. The collector now resolves the credentials from
either layout, probes them before dumping so a failed login cannot
truncate the archive, and falls back to a single-database dump when only
the application user works. Verified against both databases on the server.
Also adds the Nextcloud manifest that installs it on the cluster.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Trivy scanner adapter (rootfs + image JSON, parsed and deduplicated),
findings repository, scan diff that keeps first_seen, marks disappeared
findings fixed and skips failed targets, vulnerability_scan job (daily by
default), digest mail for new findings at or above a configurable severity,
/api/vulnerabilities routes, Vulnerabilities page with severity tiles,
filters, details and acknowledge, notification threshold in settings.
Deploy script installs Trivy from the Aqua apt repository.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
AES-256-GCM secret storage keyed by MASTER_KEY, SMTP settings with test mail
(lettre), persisted job runs with log and status, JobRunner with per-kind
concurrency guard, 6-field cron schedules with defaults, scheduler loop.
Settings and Jobs pages in the UI. FAKE_HOST mode for dev machines.
Tests: 30 application, 8 infrastructure, 23 API, 16 Vitest, 6 Playwright.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>