- Profiler: when not root, render server.conf to the staging dir and let the root helper validate (directive allowlist) and install it; control the openvpn service through the helper (doas, fixed commands). - Add ovpmon-helper and doas rules under DOCS/General/privilege-separation. - Document the design, rollout, results and limitations. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
1.8 KiB
1.8 KiB
OpenVPN Monitor & Profiler Documentation
Welcome to the documentation for the OpenVPN Monitor suite.
📚 General
- Deployment: Docker: containers with docker-compose.
- Deployment: system services: systemd/OpenRC, HTTPS, host hardening.
- Deployment Guide: generic native install notes.
- Service Management: Setting up systemd/OpenRC services.
- Nginx Configuration
- Security Architecture: Details on Authentication, 2FA, and Security features.
🛠 Changes and results
- Security hardening (2026-09-30)
- Admin username change (2026-09-30)
- Settings validation (2026-09-30)
- Privilege separation (2026-09-30)
- Egress via Hysteria2 (2026-09-30)
🔍 Core Monitoring (APP_CORE)
The core module responsible for log parsing, real-time statistics, and the primary API.
- API Reference: Endpoints for monitoring data.
- Authentication: How the Login and 2FA flows work.
- Data Architecture: Internals of the Data Gatherer and TSDB.
⚙️ Profiler Management (APP_PROFILER)
The management module for PKI, Certificates, and User Profiles.
- Overview: Features and usage of the Profiler API.
💻 User Interface (APP_UI)
The Vue.js frontend application.
- Architecture: UI Tech stack and project structure.