Dashboard endpoint and page aggregating inventory, vulnerabilities, cluster health, backups and recent jobs. Security headers (CSP, nosniff, DENY, referrer policy), 1 MB body limit, configurable login rate limit, audit steps in CI. Installer script, systemd unit, install/architecture docs. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
1.6 KiB
Architecture
Single Rust binary (axum) serving the API and the built Vue SPA; SQLite for state; host tools
(apt-get, dpkg-query, snap, microk8s kubectl, trivy, smbclient, curl, tar,
openssl) are invoked as subprocesses behind ports so every use case is testable with fakes.
backend/crates/
domain/ entities, validation, ports (traits) no I/O
application/ use cases: auth, users, settings, jobs, depends on domain
scheduler, inventory, upgrade, cluster,
vulnerabilities, backups
infrastructure/ SQLite repos, Argon2/JWT/AES-GCM, lettre, implements the ports
Debian inspector/updater, kube-rs gateway,
Trivy, smbclient/curl storage, collectors
api/ axum routes, auth extractors, OpenAPI, wires everything
security headers, config, main
frontend/ Vue 3 + TypeScript + Tailwind, Pinia stores, Playwright e2e
Cross-cutting: a JobRunner executes long-running work (refresh, upgrade, scan, backup) as
persisted job runs with live logs; a Scheduler ticks every 30 s and starts due jobs from cron
expressions (settings) and backup strategies. Secrets at rest are AES-256-GCM encrypted with
MASTER_KEY. Authentication: Argon2id passwords, 15-minute JWT access tokens, rotating refresh
tokens in an HttpOnly, SameSite=Strict cookie scoped to /api/auth, reuse detection revokes the
token family. FAKE_HOST=true swaps all host/cluster/scanner/storage adapters for fakes so the
app runs on a developer machine and in the UI tests.