Files
Infrastruktur-Monitoring-Sy…/docs/architecture.md
Dennis Nemec 9234e1ba47 WP-40/41/42: dashboard, security hardening, deployment and operations docs
Dashboard endpoint and page aggregating inventory, vulnerabilities, cluster
health, backups and recent jobs. Security headers (CSP, nosniff, DENY,
referrer policy), 1 MB body limit, configurable login rate limit, audit
steps in CI. Installer script, systemd unit, install/architecture docs.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-02 23:26:01 +02:00

28 lines
1.6 KiB
Markdown

# Architecture
Single Rust binary (axum) serving the API and the built Vue SPA; SQLite for state; host tools
(`apt-get`, `dpkg-query`, `snap`, `microk8s kubectl`, `trivy`, `smbclient`, `curl`, `tar`,
`openssl`) are invoked as subprocesses behind ports so every use case is testable with fakes.
```
backend/crates/
domain/ entities, validation, ports (traits) no I/O
application/ use cases: auth, users, settings, jobs, depends on domain
scheduler, inventory, upgrade, cluster,
vulnerabilities, backups
infrastructure/ SQLite repos, Argon2/JWT/AES-GCM, lettre, implements the ports
Debian inspector/updater, kube-rs gateway,
Trivy, smbclient/curl storage, collectors
api/ axum routes, auth extractors, OpenAPI, wires everything
security headers, config, main
frontend/ Vue 3 + TypeScript + Tailwind, Pinia stores, Playwright e2e
```
Cross-cutting: a `JobRunner` executes long-running work (refresh, upgrade, scan, backup) as
persisted job runs with live logs; a `Scheduler` ticks every 30 s and starts due jobs from cron
expressions (settings) and backup strategies. Secrets at rest are AES-256-GCM encrypted with
`MASTER_KEY`. Authentication: Argon2id passwords, 15-minute JWT access tokens, rotating refresh
tokens in an HttpOnly, SameSite=Strict cookie scoped to `/api/auth`, reuse detection revokes the
token family. `FAKE_HOST=true` swaps all host/cluster/scanner/storage adapters for fakes so the
app runs on a developer machine and in the UI tests.