Trivy scanner adapter (rootfs + image JSON, parsed and deduplicated), findings repository, scan diff that keeps first_seen, marks disappeared findings fixed and skips failed targets, vulnerability_scan job (daily by default), digest mail for new findings at or above a configurable severity, /api/vulnerabilities routes, Vulnerabilities page with severity tiles, filters, details and acknowledge, notification threshold in settings. Deploy script installs Trivy from the Aqua apt repository. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
69 lines
2.9 KiB
Bash
Executable File
69 lines
2.9 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
# Deploy a test instance to the Debian server (ssh alias "softvisor") on port 3333.
|
|
# Builds a static x86_64 binary in Docker, ships it with the frontend, installs a
|
|
# systemd unit (scp/tar, the server has no rsync). Safe to re-run: keeps the existing .env (and therefore the DB/admin).
|
|
set -euo pipefail
|
|
cd "$(dirname "$0")/.."
|
|
|
|
HOST=${HOST:-softvisor}
|
|
PORT=${PORT:-3333}
|
|
DIR=/opt/monitoring
|
|
|
|
echo "== build frontend"
|
|
(cd frontend && npm run build >/dev/null)
|
|
echo "== build static linux binary (docker)"
|
|
docker run --rm -v "$PWD/backend":/home/rust/src -v cargo-registry-musl:/root/.cargo/registry \
|
|
messense/rust-musl-cross:x86_64-musl cargo build --release -p api -q
|
|
|
|
echo "== upload"
|
|
ssh "$HOST" "mkdir -p $DIR/data"
|
|
ssh "$HOST" "systemctl stop monitoring.service 2>/dev/null || true"
|
|
scp -q backend/target/x86_64-unknown-linux-musl/release/monitoring-server "$HOST:$DIR/monitoring-server"
|
|
COPYFILE_DISABLE=1 tar --no-xattrs -C frontend/dist -czf - . | ssh "$HOST" "rm -rf $DIR/dist && mkdir -p $DIR/dist && tar -C $DIR/dist -xzf -"
|
|
|
|
echo "== configure (first run only)"
|
|
if ! ssh "$HOST" "test -f $DIR/.env"; then
|
|
ADMIN_PW=$(openssl rand -base64 18 | tr -d '/+=' | head -c 20)
|
|
ssh "$HOST" "umask 077; cat > $DIR/.env" <<ENV
|
|
DATABASE_URL=sqlite://$DIR/data/monitoring.db?mode=rwc
|
|
JWT_SECRET=$(openssl rand -hex 32)
|
|
MASTER_KEY=$(openssl rand -hex 32)
|
|
BIND=0.0.0.0:$PORT
|
|
BOOTSTRAP_ADMIN_EMAIL=admin@softvisor.de
|
|
BOOTSTRAP_ADMIN_PASSWORD=$ADMIN_PW
|
|
COOKIE_SECURE=false
|
|
FRONTEND_DIR=$DIR/dist
|
|
RUST_LOG=info,sqlx=warn
|
|
ENV
|
|
echo "Bootstrap admin: admin@softvisor.de / $ADMIN_PW (change it after first login)"
|
|
fi
|
|
|
|
# add settings introduced later to an existing .env
|
|
ssh "$HOST" "grep -q '^MASTER_KEY=' $DIR/.env || echo MASTER_KEY=$(openssl rand -hex 32) >> $DIR/.env"
|
|
|
|
echo "== trivy (vulnerability scanner)"
|
|
ssh "$HOST" 'command -v trivy >/dev/null || {
|
|
apt-get install -y -q wget apt-transport-https gnupg >/dev/null
|
|
wget -qO- https://aquasecurity.github.io/trivy-repo/deb/public.key | gpg --dearmor -o /usr/share/keyrings/trivy.gpg
|
|
echo "deb [signed-by=/usr/share/keyrings/trivy.gpg] https://aquasecurity.github.io/trivy-repo/deb generic main" > /etc/apt/sources.list.d/trivy.list
|
|
apt-get update -q >/dev/null && apt-get install -y -q trivy >/dev/null
|
|
}; trivy --version | head -1'
|
|
|
|
echo "== systemd"
|
|
ssh "$HOST" "cat > /etc/systemd/system/monitoring.service" <<UNIT
|
|
[Unit]
|
|
Description=SoftVisor Infrastructure Monitoring (test deployment)
|
|
After=network.target
|
|
|
|
[Service]
|
|
WorkingDirectory=$DIR
|
|
EnvironmentFile=$DIR/.env
|
|
ExecStart=$DIR/monitoring-server
|
|
Restart=on-failure
|
|
|
|
[Install]
|
|
WantedBy=multi-user.target
|
|
UNIT
|
|
ssh "$HOST" "systemctl daemon-reload && systemctl enable -q monitoring.service && systemctl restart monitoring.service && sleep 2 && systemctl is-active monitoring.service && curl -s http://127.0.0.1:$PORT/healthz && echo"
|
|
echo "== done: http://$(ssh "$HOST" hostname -I | awk '{print $1}'):$PORT/"
|