Dashboard endpoint and page aggregating inventory, vulnerabilities, cluster health, backups and recent jobs. Security headers (CSP, nosniff, DENY, referrer policy), 1 MB body limit, configurable login rate limit, audit steps in CI. Installer script, systemd unit, install/architecture docs. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
23 lines
1010 B
Plaintext
23 lines
1010 B
Plaintext
# Backend configuration (copy to backend/.env for local development)
|
|
DATABASE_URL=sqlite://data/monitoring.db?mode=rwc
|
|
JWT_SECRET=change-me-to-a-long-random-string
|
|
# 64 hex characters (openssl rand -hex 32); encrypts stored secrets such as SMTP passwords
|
|
MASTER_KEY=change-me-64-hex-characters
|
|
# true on dev machines without apt/kubectl: uses fake host adapters with sample data
|
|
FAKE_HOST=false
|
|
BIND=127.0.0.1:8080
|
|
# Created on first start if no user exists
|
|
BOOTSTRAP_ADMIN_EMAIL=admin@example.com
|
|
BOOTSTRAP_ADMIN_PASSWORD=change-me-min-12-chars
|
|
# Login attempts per IP and minute (default 10)
|
|
#LOGIN_RATE_LIMIT=10
|
|
# Set to true behind HTTPS so the refresh cookie is marked Secure
|
|
COOKIE_SECURE=false
|
|
# Directory with the built frontend (served as SPA fallback)
|
|
FRONTEND_DIR=../frontend/dist
|
|
RUST_LOG=info,sqlx=warn
|
|
# kubectl invocation used for backups (default: microk8s kubectl if present)
|
|
#KUBECTL=/snap/bin/microk8s kubectl
|
|
# scratch directory for backup archives (default: data/work)
|
|
#WORK_DIR=data/work
|