Dashboard endpoint and page aggregating inventory, vulnerabilities, cluster health, backups and recent jobs. Security headers (CSP, nosniff, DENY, referrer policy), 1 MB body limit, configurable login rate limit, audit steps in CI. Installer script, systemd unit, install/architecture docs. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
28 lines
1.6 KiB
Markdown
28 lines
1.6 KiB
Markdown
# Architecture
|
|
|
|
Single Rust binary (axum) serving the API and the built Vue SPA; SQLite for state; host tools
|
|
(`apt-get`, `dpkg-query`, `snap`, `microk8s kubectl`, `trivy`, `smbclient`, `curl`, `tar`,
|
|
`openssl`) are invoked as subprocesses behind ports so every use case is testable with fakes.
|
|
|
|
```
|
|
backend/crates/
|
|
domain/ entities, validation, ports (traits) no I/O
|
|
application/ use cases: auth, users, settings, jobs, depends on domain
|
|
scheduler, inventory, upgrade, cluster,
|
|
vulnerabilities, backups
|
|
infrastructure/ SQLite repos, Argon2/JWT/AES-GCM, lettre, implements the ports
|
|
Debian inspector/updater, kube-rs gateway,
|
|
Trivy, smbclient/curl storage, collectors
|
|
api/ axum routes, auth extractors, OpenAPI, wires everything
|
|
security headers, config, main
|
|
frontend/ Vue 3 + TypeScript + Tailwind, Pinia stores, Playwright e2e
|
|
```
|
|
|
|
Cross-cutting: a `JobRunner` executes long-running work (refresh, upgrade, scan, backup) as
|
|
persisted job runs with live logs; a `Scheduler` ticks every 30 s and starts due jobs from cron
|
|
expressions (settings) and backup strategies. Secrets at rest are AES-256-GCM encrypted with
|
|
`MASTER_KEY`. Authentication: Argon2id passwords, 15-minute JWT access tokens, rotating refresh
|
|
tokens in an HttpOnly, SameSite=Strict cookie scoped to `/api/auth`, reuse detection revokes the
|
|
token family. `FAKE_HOST=true` swaps all host/cluster/scanner/storage adapters for fakes so the
|
|
app runs on a developer machine and in the UI tests.
|