Files
Dennis Nemec 872f4373ff
Some checks failed
CI / backend (push) Has been cancelled
CI / frontend (push) Has been cancelled
CI / ui (push) Has been cancelled
WP-20/21: vulnerability management with Trivy and mail notifications
Trivy scanner adapter (rootfs + image JSON, parsed and deduplicated),
findings repository, scan diff that keeps first_seen, marks disappeared
findings fixed and skips failed targets, vulnerability_scan job (daily by
default), digest mail for new findings at or above a configurable severity,
/api/vulnerabilities routes, Vulnerabilities page with severity tiles,
filters, details and acknowledge, notification threshold in settings.
Deploy script installs Trivy from the Aqua apt repository.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-02 22:45:57 +02:00

69 lines
2.9 KiB
Bash
Executable File

#!/usr/bin/env bash
# Deploy a test instance to the Debian server (ssh alias "softvisor") on port 3333.
# Builds a static x86_64 binary in Docker, ships it with the frontend, installs a
# systemd unit (scp/tar, the server has no rsync). Safe to re-run: keeps the existing .env (and therefore the DB/admin).
set -euo pipefail
cd "$(dirname "$0")/.."
HOST=${HOST:-softvisor}
PORT=${PORT:-3333}
DIR=/opt/monitoring
echo "== build frontend"
(cd frontend && npm run build >/dev/null)
echo "== build static linux binary (docker)"
docker run --rm -v "$PWD/backend":/home/rust/src -v cargo-registry-musl:/root/.cargo/registry \
messense/rust-musl-cross:x86_64-musl cargo build --release -p api -q
echo "== upload"
ssh "$HOST" "mkdir -p $DIR/data"
ssh "$HOST" "systemctl stop monitoring.service 2>/dev/null || true"
scp -q backend/target/x86_64-unknown-linux-musl/release/monitoring-server "$HOST:$DIR/monitoring-server"
COPYFILE_DISABLE=1 tar --no-xattrs -C frontend/dist -czf - . | ssh "$HOST" "rm -rf $DIR/dist && mkdir -p $DIR/dist && tar -C $DIR/dist -xzf -"
echo "== configure (first run only)"
if ! ssh "$HOST" "test -f $DIR/.env"; then
ADMIN_PW=$(openssl rand -base64 18 | tr -d '/+=' | head -c 20)
ssh "$HOST" "umask 077; cat > $DIR/.env" <<ENV
DATABASE_URL=sqlite://$DIR/data/monitoring.db?mode=rwc
JWT_SECRET=$(openssl rand -hex 32)
MASTER_KEY=$(openssl rand -hex 32)
BIND=0.0.0.0:$PORT
BOOTSTRAP_ADMIN_EMAIL=admin@softvisor.de
BOOTSTRAP_ADMIN_PASSWORD=$ADMIN_PW
COOKIE_SECURE=false
FRONTEND_DIR=$DIR/dist
RUST_LOG=info,sqlx=warn
ENV
echo "Bootstrap admin: admin@softvisor.de / $ADMIN_PW (change it after first login)"
fi
# add settings introduced later to an existing .env
ssh "$HOST" "grep -q '^MASTER_KEY=' $DIR/.env || echo MASTER_KEY=$(openssl rand -hex 32) >> $DIR/.env"
echo "== trivy (vulnerability scanner)"
ssh "$HOST" 'command -v trivy >/dev/null || {
apt-get install -y -q wget apt-transport-https gnupg >/dev/null
wget -qO- https://aquasecurity.github.io/trivy-repo/deb/public.key | gpg --dearmor -o /usr/share/keyrings/trivy.gpg
echo "deb [signed-by=/usr/share/keyrings/trivy.gpg] https://aquasecurity.github.io/trivy-repo/deb generic main" > /etc/apt/sources.list.d/trivy.list
apt-get update -q >/dev/null && apt-get install -y -q trivy >/dev/null
}; trivy --version | head -1'
echo "== systemd"
ssh "$HOST" "cat > /etc/systemd/system/monitoring.service" <<UNIT
[Unit]
Description=SoftVisor Infrastructure Monitoring (test deployment)
After=network.target
[Service]
WorkingDirectory=$DIR
EnvironmentFile=$DIR/.env
ExecStart=$DIR/monitoring-server
Restart=on-failure
[Install]
WantedBy=multi-user.target
UNIT
ssh "$HOST" "systemctl daemon-reload && systemctl enable -q monitoring.service && systemctl restart monitoring.service && sleep 2 && systemctl is-active monitoring.service && curl -s http://127.0.0.1:$PORT/healthz && echo"
echo "== done: http://$(ssh "$HOST" hostname -I | awk '{print $1}'):$PORT/"