Commit Graph

27 Commits

Author SHA1 Message Date
1339ae864e Dump PostgreSQL pods whatever image they run
The dump assumed the official image's environment and the postgres
superuser. Bitnami keeps its passwords in files, and on this cluster the
superuser password no longer matches the database, so the Gitea database
backup would have failed. The collector now resolves the credentials from
either layout, probes them before dumping so a failed login cannot
truncate the archive, and falls back to a single-database dump when only
the application user works. Verified against both databases on the server.

Also adds the Nextcloud manifest that installs it on the cluster.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-03 21:32:43 +02:00
51364fdd76 Discover applications on the cluster and the host for backups
Kubernetes workloads are grouped by their Helm instance label into
applications, each offering what is worth backing up: data volumes, a
PostgreSQL dump instead of the database's own volume, and optionally the
namespace manifests. Caches are listed but not preselected. Host
applications come from running systemd services that declare a state or
working directory. Selecting components creates one strategy each.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-03 20:50:11 +02:00
44b7a56573 Actually use the tested token parser for the registry challenge
The call site still deserialized into a struct whose serde alias breaks
on Docker Hub, which sends token and access_token; every Hub image
therefore reported that no token was returned. The integration test now
answers with both fields so the call site is covered.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-03 20:28:17 +02:00
5ea7e7dd67 Drop a redundant map in a registry test
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-03 20:25:34 +02:00
b161bf9cbd Fix Docker Hub authentication and reject build-id tags as candidates
Docker Hub answers with both token and access_token, which made the
serde alias fail as a duplicate field, so every Hub image reported that
no token was returned. Candidates now also have to match the shape of
the running tag; cert-manager v1.14.5 was otherwise offered an upgrade
to the build id 608111629.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-03 20:24:50 +02:00
214cd1506b Page through large registry tag lists
Gitea publishes thousands of tags; the client stopped after ten pages of
200 and never saw a version newer than the running one.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-03 20:21:14 +02:00
b984cc8c9f Link image findings to their workloads and suggest a fixing image update
Container findings now name the workloads that run the image and link
into the Kubernetes view, which highlights them. An update check asks the
registry for newer tags of the same variant, scans the newest one and
records which of the open findings are gone in it. The image row then
shows the candidate tag, how many findings it fixes and how many remain,
marks those CVEs in the expanded list, and offers to roll every workload
over to it. The check runs as a job, nightly for all running images or on
demand for one.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-03 20:19:12 +02:00
278b5e47a3 Roll findings up per package and image, expandable to their CVEs
The findings table listed every CVE, which is thousands of rows on a real
host. It now shows one row per affected package (host) or image
(containers) with its severity split, how many findings it has and how
many of them have a fix. Clicking a row loads and shows the CVEs of that
group; collapsing keeps them cached.

The rollup is a GROUP BY in SQLite behind a new groups endpoint, so the
page loads a few dozen rows instead of the full finding list, and the
flat list gained a package filter to expand one group.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-03 20:02:25 +02:00
70cf25fc7f Refresh scanner details of findings that are seen again
A rescan only touched the timestamp of findings it had seen before, so a
newly published fix version, a changed severity and the package source
never reached existing rows. The repository now updates those fields
while keeping first_seen and the status the user set.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-03 19:50:18 +02:00
aba2c69416 Split the vulnerability view into host and container categories
The findings of the Debian host (OS packages and applications found in the
root filesystem) and of the container images in the cluster were mixed in
one flat table. They are now two prominent categories: a card each with its
own severity split and target count, acting as the primary selector, and a
table that adapts to the selection. Host findings show the package source
reported by the scanner (debian, gobinary, node-pkg …) instead of the
target, container findings show the image.

Backend: findings carry the scanner's package source, the list endpoint
takes ?scope=host|container, and the targets endpoint reports each target
with its category and open count.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-03 19:47:47 +02:00
21098cadf6 Failing tests for splitting vulnerabilities into host and container scopes
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-03 19:38:04 +02:00
a146f09935 Use production-sized identifiers in the vulnerability fixture data
The dev fixtures only had short package and version strings, so the
layout tests never exercised the widths that made the real findings
table overflow.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-03 19:32:18 +02:00
9234e1ba47 WP-40/41/42: dashboard, security hardening, deployment and operations docs
Dashboard endpoint and page aggregating inventory, vulnerabilities, cluster
health, backups and recent jobs. Security headers (CSP, nosniff, DENY,
referrer policy), 1 MB body limit, configurable login rate limit, audit
steps in CI. Installer script, systemd unit, install/architecture docs.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-02 23:26:01 +02:00
a89395ae18 Trivy: scan images from the local containerd store before the registry
Some checks failed
CI / backend (push) Has been cancelled
CI / frontend (push) Has been cancelled
CI / ui (push) Has been cancelled
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-02 23:18:05 +02:00
6134a47ff2 WP-30/31/32: backup targets, strategies and execution
Some checks failed
CI / backend (push) Has been cancelled
CI / frontend (push) Has been cancelled
CI / ui (push) Has been cancelled
SMB (smbclient) and FTP/FTPS (curl with netrc) targets with encrypted
credentials and connection test; strategies with cron schedule, retention,
optional openssl AES-256 encryption; sources: PVC hostpath tar, pg_dumpall
in the Postgres pod, namespace manifests, host directory. Backup job
collects, encrypts, uploads, verifies size, records sha256 and applies
retention on the target; scheduler starts due strategies. Backups page
with target/strategy forms, run now and history. Restore guide in docs.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-02 23:15:38 +02:00
39af18b336 WP-30/31/32: contract and failing tests for backup management; OS scan skips container dirs
Some checks failed
CI / backend (push) Has been cancelled
CI / frontend (push) Has been cancelled
CI / ui (push) Has been cancelled
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-02 23:05:22 +02:00
5026ce22de Implement Trivy adapter, contain job panics, fail interrupted runs on startup
Some checks failed
CI / backend (push) Has been cancelled
CI / frontend (push) Has been cancelled
CI / ui (push) Has been cancelled
The Trivy scanner still had unimplemented stubs, which panicked the scan
task in the deployed test instance and left the run in 'running' forever.
JobRunner now runs handlers in their own task and marks a panic as a
failed run; on startup runs left 'running' by a previous process are
marked failed.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-02 22:58:16 +02:00
5c6e09ad10 WP-20/21: contract and failing tests for vulnerability management
Some checks failed
CI / backend (push) Has been cancelled
CI / frontend (push) Has been cancelled
CI / ui (push) Has been cancelled
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-02 22:40:48 +02:00
8f36a54da0 WP-12: Kubernetes overview and workload actions
Some checks failed
CI / backend (push) Has been cancelled
CI / frontend (push) Has been cancelled
CI / ui (push) Has been cancelled
kube-rs gateway (nodes, namespaces, deployments/statefulsets/daemonsets with
images, PVCs; rollout restart, scale, set image via patches) using the
microk8s kubeconfig by default, fake gateway for dev, /api/cluster routes,
Kubernetes page with node cards, workload table with admin actions and PVC
list. Also implements the streaming command runner that WP-11 relied on.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-02 22:33:57 +02:00
684695e71a WP-11: package and OS updates from the UI
Some checks failed
CI / backend (push) Has been cancelled
CI / frontend (push) Has been cancelled
CI / ui (push) Has been cancelled
package_upgrade job streams apt-get output into the job log (streaming
CommandRunner, DebianUpdater with dist-upgrade or --only-upgrade), refreshes
the inventory afterwards and flags reboot-required. POST /api/system/upgrade
(admin), package name validation, selectable package table with confirm
dialog and live log on the Updates page. Fake updater for dev.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-02 22:27:28 +02:00
1f56f015a2 WP-11: contract and failing tests for package upgrades
Some checks failed
CI / backend (push) Has been cancelled
CI / frontend (push) Has been cancelled
CI / ui (push) Has been cancelled
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-02 22:24:40 +02:00
b6ddb8889d WP-10: OS and package inventory
Some checks failed
CI / backend (push) Has been cancelled
CI / frontend (push) Has been cancelled
CI / ui (push) Has been cancelled
Debian inspector (dpkg-query, apt-get -s upgrade, snap list, os-release,
reboot-required) behind a CommandRunner port with tested parsers, fake
inspector for dev, persisted inventory snapshot, package_refresh job,
/api/system/inventory, Updates page with OS card, summary and filterable
package table.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-02 22:21:46 +02:00
7b6d242988 WP-10: contract and failing tests for OS and package inventory
Some checks failed
CI / backend (push) Has been cancelled
CI / frontend (push) Has been cancelled
CI / ui (push) Has been cancelled
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-02 22:19:25 +02:00
b6c3ddf040 Use is_multiple_of in hex decoder (clippy)
Some checks failed
CI / backend (push) Has been cancelled
CI / frontend (push) Has been cancelled
CI / ui (push) Has been cancelled
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-02 22:17:15 +02:00
fa9ac9a6bc WP-02: encrypted settings, SMTP mail, job runner and cron scheduler
Some checks failed
CI / backend (push) Has been cancelled
CI / frontend (push) Has been cancelled
CI / ui (push) Has been cancelled
AES-256-GCM secret storage keyed by MASTER_KEY, SMTP settings with test mail
(lettre), persisted job runs with log and status, JobRunner with per-kind
concurrency guard, 6-field cron schedules with defaults, scheduler loop.
Settings and Jobs pages in the UI. FAKE_HOST mode for dev machines.

Tests: 30 application, 8 infrastructure, 23 API, 16 Vitest, 6 Playwright.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-02 22:16:56 +02:00
f1136fdf3d WP-01: authentication, user management and application shell
Some checks failed
CI / backend (push) Has been cancelled
CI / frontend (push) Has been cancelled
CI / ui (push) Has been cancelled
Argon2id password hashing, JWT access tokens with rotating HttpOnly refresh
cookies and reuse detection, login rate limiting, auth audit log, bootstrap
admin, admin-only user CRUD and password reset, OpenAPI spec. Vue login page,
auth store with automatic token refresh, route guards, sidebar shell with
toasts and placeholder pages, user management page.

All tests green: 40 backend, 12 Vitest, 4 Playwright.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-02 21:37:14 +02:00
780c84098b WP-00: project skeleton with three-level test harness
Some checks failed
CI / backend (push) Has been cancelled
CI / frontend (push) Has been cancelled
CI / ui (push) Has been cancelled
Cargo workspace (domain, application, infrastructure, api), axum health endpoint
with SPA fallback, Vue 3 + Tailwind frontend, Vitest, Playwright, Makefile,
Gitea Actions CI and README.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-02 21:28:21 +02:00