Registry and Analytics: run, subnet, direction and protocol filters, successes-by-target chart

Registry (/registry):
- filters by run (slice by the address's cycle in that run), subnet
  (drop-down of configured subnets), direction (egress/ingress) and
  protocol (icmp, tcp, ssh, https, tls); status in scope is computed over
  the narrowed checks
- chart "successful checks per target (egress) / site (ingress)" when both
  direction and protocol are chosen; a row opens the list of addresses
  (dialog, CSV)
- API: direction/protocol parameters and run in GET /admin/registry,
  GET /admin/registry/breakdown and /breakdown/list
- subnet filter passes ids as one JSON parameter (SQLite variable limit)

Analytics (/analytics):
- subnet filter recomputes the whole page over the addresses of the run
  inside the subnet; only their checks are read; cache per run and subnet
- direction and protocol focus the page; with both set the registry chart
  is shown
- subnet parameter in GET /admin/analytics/runs/{id} and lists (JSON, CSV)

Docs: plans and summaries in docs/changes, README, API, USAGE.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
This commit is contained in:
ayurishchevandClaude Sonnet 5.5 committed 2026-10-06 14:23:48 +03:00
1 parent 068c10ea1c
commit ded196ec8d
40 files changed
+2545 -188

No files matched your search

+49 -7
View File
@@ -20,6 +20,7 @@
{{if .HasRun}}
<script type="application/json" id="analytics-data">{{.DataJSON}}</script>
<script src="/static/analytics-dialog.js"></script>
<script src="/static/registry.js"></script>
<script src="/static/analytics.js"></script>
{{end}}
</body>
@@ -38,22 +39,62 @@
<p class="an-note">Запусков проверки пока нет. Они появляются, когда адреса ставятся в очередь на странице <a href="/ips">«Очередь IP»</a> или запускается автоматический цикл.</p>
</section>
{{else}}
<section class="an-panel" aria-label="Выбор запуска">
<section class="an-panel" aria-label="Выбор запуска и фильтры">
<form id="an-filter" action="/analytics" method="get" onsubmit="return false">
{{/* a change goes to the page of the new filter; empty values stay out of the address */}}
<script>function anGo(f) { var q = new URLSearchParams(); new FormData(f).forEach(function (v, k) { if (v) q.set(k, v); }); location.href = '/analytics?' + q; }</script>
<div class="an-runbar">
<label for="an-run">Запуск</label>
{{if .PrevURL}}<a class="an-btn" href="{{.PrevURL}}" aria-label="Предыдущий запуск">◀</a>{{else}}<span class="an-btn" aria-disabled="true" style="opacity:.4">◀</span>{{end}}
<select id="an-run" onchange="if (this.value) location.href = '/analytics?run=' + encodeURIComponent(this.value)">
<select id="an-run" name="run" onchange="if (this.value) anGo(this.form)">
{{range .Runs}}<option value="{{.ID}}"{{if .Selected}} selected{{end}}{{if .Disabled}} disabled{{end}}>{{.Label}}</option>
{{end}}
</select>
{{if .NextURL}}<a class="an-btn" href="{{.NextURL}}" aria-label="Следующий запуск">▶</a>{{else}}<span class="an-btn" aria-disabled="true" style="opacity:.4">▶</span>{{end}}
{{if .HasRun}}<a class="an-btn" href="/analytics/compare?target={{.RunID}}">Сравнить с другим запуском</a>{{end}}
{{if .HasRun}}<a class="an-btn" href="{{.CompareURL}}">Сравнить с другим запуском</a>{{end}}
</div>
{{if .HasRun}}<p class="an-note" id="an-runnote"></p>{{else}}<p class="an-note">Завершённых запусков пока нет: данные появятся, когда все адреса запуска получат итог.</p>{{end}}
{{if .HasRun}}
<div class="an-fields">
<div class="an-field">
<label for="an-subnet">Подсеть</label>
<select id="an-subnet" name="subnet" onchange="anGo(this.form)"{{if not .SubnetOptions}} disabled{{end}}>
<option value="">Все подсети</option>
{{range .SubnetOptions}}<option value="{{.CIDR}}"{{if .Selected}} selected{{end}}>{{.Text}}</option>
{{end}}
</select>
{{if not .SubnetOptions}}<span class="an-note">Подсети не настроены — <a href="/settings">добавить в настройках</a></span>{{end}}
</div>
<div class="an-field">
<label for="an-direction">Направление</label>
<select id="an-direction" name="direction" onchange="anGo(this.form)">
<option value="">Все</option>
<option value="egress"{{if eq .Direction "egress"}} selected{{end}}>Egress</option>
<option value="ingress"{{if eq .Direction "ingress"}} selected{{end}}>Ingress</option>
</select>
</div>
<div class="an-field">
<label for="an-protocol">Протокол</label>
<select id="an-protocol" name="protocol" onchange="anGo(this.form)">
<option value="">Все</option>
{{$pr := .Protocol}}
{{range $p := .Protocols}}<option value="{{$p}}"{{if eq $p $pr}} selected{{end}}>{{$p}}</option>
{{end}}
</select>
</div>
{{if .Filtered}}<a class="an-btn an-reset" href="/analytics?run={{.RunID}}">сбросить фильтры</a>{{end}}
</div>
{{end}}
</form>
{{if .HasRun}}<p class="an-note" id="an-runnote"></p>
<p class="an-note">Подсеть пересчитывает все блоки страницы по её адресам. Направление и протокол задают фокус: скрывают блоки другого уровня и выбирают тип проверки, а вердикты и «Качество данных» остаются по всем проверкам запуска. С направлением и протоколом сразу показывается чарт.{{if .Breakdown}} Чарт считает проверки цикла запуска, в том числе пришедшие после вердикта, а плитки ниже берут вердикты запуска, поэтому числа могут расходиться.{{end}}</p>
{{else}}<p class="an-note">Завершённых запусков пока нет: данные появятся, когда все адреса запуска получат итог.</p>{{end}}
</section>
{{end}}
{{if .HasRun}}
{{with .Breakdown}}{{template "registry_breakdown" .}}{{end}}
<p class="an-note" id="an-empty" hidden></p>
<div class="an-body" id="an-body">
<div class="an-kpis" id="an-kpis"></div>
<div class="an-cols">
@@ -84,7 +125,7 @@
<p class="an-note">Строка ведёт в «Реестр» с фильтром по запуску и подсети.</p>
</section>
<section class="an-panel" aria-labelledby="an-h-eg">
<section class="an-panel" id="an-sec-eg" aria-labelledby="an-h-eg">
<div class="an-head">
<h2 id="an-h-eg">Egress по целям</h2>
<div class="an-tabs" role="group" aria-label="Тип проверки" id="an-types"></div>
@@ -98,7 +139,7 @@
<p class="an-note" id="an-matrixnote"></p>
</section>
<div class="an-cols">
<div class="an-cols" id="an-sec-in">
<section class="an-panel" aria-labelledby="an-h-in">
<h2 id="an-h-in">Ingress по площадкам</h2>
<div class="an-scroll"><table id="an-sites"></table></div>
@@ -109,12 +150,13 @@
</section>
</div>
<section class="an-panel" aria-labelledby="an-h-val">
<section class="an-panel" id="an-sec-val" aria-labelledby="an-h-val">
<h2 id="an-h-val">Валидаторы: доля провалов egress https</h2>
<div class="an-vals" id="an-vals" role="img" aria-label="Доля проваленных https-проверок по валидаторам"></div>
<div class="an-vlab"><span id="an-vfirst"></span><span id="an-vavg"></span><span id="an-vlast"></span></div>
<p class="an-note">Ровная полоса значит: проблема зависит от подсети адреса, а не от валидатора.</p>
</section>
</div>
{{template "analytics_dialog"}}
{{end}}
+86 -13
View File
@@ -1,7 +1,9 @@
{{define "registry_page"}}
<!doctype html>
<html lang="ru">
<head>{{template "html_head" .}}</head>
<head>{{template "html_head" .}}
<link rel="stylesheet" href="/static/analytics.css">
</head>
<body>
<div class="bg-grid"></div>
<input type="checkbox" id="nav-toggle" class="nav-toggle">
@@ -15,6 +17,10 @@
</main>
</div>
</div>
{{/* The list behind a row of the chart opens in the analytics dialog. */}}
<div class="an">{{template "analytics_dialog"}}</div>
<script src="/static/analytics-dialog.js"></script>
<script src="/static/registry.js"></script>
</body>
</html>
{{end}}
@@ -26,13 +32,6 @@
Глубина хранимой истории на адрес настраивается на <a href="/settings">странице настроек</a>.</p>
<form id="registry-filter" class="panel" onsubmit="return false" style="margin-bottom:16px">
{{if .Run}}<input type="hidden" name="run" value="{{.Run}}">{{end}}
{{if .Subnet}}<input type="hidden" name="subnet" value="{{.Subnet}}">{{end}}
{{if or .Run .Subnet}}<div class="panel-body" style="padding-bottom:0">
<span class="pill pill-info">Из аналитики:{{if .Run}} запуск {{.Run}}{{end}}{{if .Subnet}} · подсеть {{.Subnet}}{{end}}</span>
<a href="/registry" style="margin-left:10px">сбросить фильтр</a>
{{if .Run}}<a href="/analytics?run={{.Run}}" style="margin-left:10px">к аналитике</a>{{end}}
</div>{{end}}
<div class="panel-body field-row">
<div class="field" style="flex:1 1 260px">
<label for="registry-q">Поиск по IP</label>
@@ -41,6 +40,52 @@
hx-include="#registry-filter" hx-trigger="input changed delay:300ms"
hx-replace-url="true" hx-sync="#registry-table-wrap:queue last">
</div>
<div class="field" style="flex:1 1 300px">
<label for="registry-run">Запуск</label>
<select id="registry-run" name="run"
hx-get="/registry" hx-select="#registry-table-wrap" hx-target="#registry-table-wrap" hx-swap="outerHTML"
hx-include="#registry-filter" hx-trigger="change"
hx-replace-url="true" hx-sync="#registry-table-wrap:queue last">
<option value="">Последний цикл (по умолчанию)</option>
{{range .Runs}}<option value="{{.ID}}" {{if .Selected}}selected{{end}}>{{.Label}}</option>
{{end}}
</select>
</div>
<div class="field" style="flex:1 1 200px">
<label for="registry-subnet">Подсеть</label>
<select id="registry-subnet" name="subnet" {{if not .SubnetOptions}}disabled{{end}}
hx-get="/registry" hx-select="#registry-table-wrap" hx-target="#registry-table-wrap" hx-swap="outerHTML"
hx-include="#registry-filter" hx-trigger="change"
hx-replace-url="true" hx-sync="#registry-table-wrap:queue last">
<option value="">Все подсети</option>
{{range .SubnetOptions}}<option value="{{.CIDR}}" {{if .Selected}}selected{{end}}>{{.Text}}</option>
{{end}}
</select>
{{if not .SubnetOptions}}<span class="muted" style="font-size:12px">Подсети не настроены — <a href="/settings">добавить в настройках</a></span>{{end}}
</div>
<div class="field">
<label for="registry-direction">Направление</label>
<select id="registry-direction" name="direction"
hx-get="/registry" hx-select="#registry-table-wrap" hx-target="#registry-table-wrap" hx-swap="outerHTML"
hx-include="#registry-filter" hx-trigger="change"
hx-replace-url="true" hx-sync="#registry-table-wrap:queue last">
<option value="">Все</option>
<option value="egress" {{if eq .Direction "egress"}}selected{{end}}>Egress</option>
<option value="ingress" {{if eq .Direction "ingress"}}selected{{end}}>Ingress</option>
</select>
</div>
<div class="field">
<label for="registry-protocol">Протокол</label>
<select id="registry-protocol" name="protocol"
hx-get="/registry" hx-select="#registry-table-wrap" hx-target="#registry-table-wrap" hx-swap="outerHTML"
hx-include="#registry-filter" hx-trigger="change"
hx-replace-url="true" hx-sync="#registry-table-wrap:queue last">
<option value="">Все</option>
{{$pr := .Protocol}}
{{range $p := .Protocols}}<option value="{{$p}}" {{if eq $p $pr}}selected{{end}}>{{$p}}</option>
{{end}}
</select>
</div>
<div class="field">
<label for="registry-status">Статус</label>
<select id="registry-status" name="status"
@@ -66,6 +111,12 @@
</select>
</div>
</div>
<div class="panel-body muted" style="padding-top:0;font-size:12.5px">
Запуск задаёт срез: результат берётся по циклу адреса в этом запуске, а статус — по вердикту запуска.
Направление и протокол оставляют только такие проверки, и статус тогда считается по ним, а не по общему вердикту.
tls проверяется только на входе (Ingress).
<a href="/registry" style="margin-left:10px">сбросить фильтры</a>
</div>
</form>
<div id="registry-table-wrap">
@@ -82,12 +133,34 @@
</div>
{{end}}
{{define "registry_breakdown"}}
{{if .Hint}}<p class="muted" style="margin-bottom:12px">{{.Hint}}</p>
{{else}}
<div class="an bd-wrap">
<section class="an-panel" id="registry-breakdown" aria-labelledby="registry-breakdown-h" data-qs="{{.QS}}" data-scope="{{.Scope}}" data-slice="{{.Slice}}">
<h2 id="registry-breakdown-h">{{.Title}} · {{.Scope}}</h2>
{{if .Err}}<p class="an-note">{{.Err}}</p>
{{else if not .Rows}}<p class="an-note">Для этого сочетания проверок нет.</p>
{{else}}
<div class="an-rows">
{{range .Rows}}<button type="button" class="an-bar-row" data-bd-key="{{.Key}}" data-bd-label="{{.Label}}" aria-haspopup="dialog" data-tip="{{.Tip}}" aria-label="{{.Tip}}"><span class="an-n">{{.Label}}</span><div class="an-track"><div class="an-fill" style="width:{{.Width}}%"></div></div><span class="an-num">{{.Text}}</span></button>
{{end}}
</div>
<p class="an-note">Адресов под фильтром: {{.Addresses}}. Срез: {{.Slice}}. Строки идут от большего числа успешных проверок к меньшему. Считаются проверки, а не адреса: у tcp и tls на ingress у адреса может быть по проверке на каждую площадку и порт (22, 443). Строка открывает список адресов.</p>
{{end}}
</section>
</div>
{{end}}
{{end}}
{{define "registry_table"}}
{{with .Breakdown}}{{template "registry_breakdown" .}}{{end}}
{{if or .Items .Run}}<p class="muted" style="margin-bottom:8px">Найдено адресов: {{.Total}}{{if .Run}} · <a href="{{.AnalyticsURL}}">к аналитике запуска {{.Run}}</a>{{end}}</p>{{end}}
{{if .Items}}
<div class="panel">
<div class="table-scroll">
<table>
<thead><tr><th>Адрес</th><th>Впервые замечен</th><th>Последний раз замечен</th><th>Циклов</th><th>Последний результат</th><th>Сейчас в очереди</th></tr></thead>
<thead><tr><th>Адрес</th><th>Впервые замечен</th><th>Последний раз замечен</th><th>Циклов</th><th>{{if .Run}}Результат в запуске {{.Run}}{{else}}Последний результат{{end}}</th><th>Сейчас в очереди</th></tr></thead>
<tbody>
{{range .Items}}
<tr>
@@ -95,15 +168,15 @@
<td data-label="Впервые замечен">{{fmtTime .FirstSeenAt}}</td>
<td data-label="Последний раз замечен">{{fmtTime .LastSeenAt}}</td>
<td class="num" data-label="Циклов">{{.TotalCycles}}</td>
<td data-label="Последний результат">
<td data-label="{{if $.Run}}Результат в запуске {{$.Run}}{{else}}Последний результат{{end}}">
{{if eq .LastResult "pass"}}<span class="pill pill-success">pass</span>
{{else if eq .LastResult "partial"}}<span class="pill pill-warning">partial</span>
{{else if eq .LastResult "fail"}}<span class="pill pill-danger">fail</span>
{{else if eq .LastResult "cancelled"}}<span class="pill pill-cancel">cancelled</span>
{{else}}<span class="pill pill-neutral">—</span>{{end}}
{{if .LastCycleID}}<div class="levels" title="Считаются записанные проверки цикла {{.LastCycleID}}; вердикт учитывает ещё и недостающие результаты.">
{{template "registry_level" dict "Name" "Egress" "L" .Egress}}
{{template "registry_level" dict "Name" "Ingress" "L" .Ingress}}
{{if or (not $.Scoped) .Egress.Total}}{{template "registry_level" dict "Name" "Egress" "L" .Egress}}{{end}}
{{if or (not $.Scoped) .Ingress.Total}}{{template "registry_level" dict "Name" "Ingress" "L" .Ingress}}{{end}}
</div>{{end}}
</td>
<td data-label="Сейчас в очереди">
@@ -116,6 +189,6 @@
</div>
{{template "pager" .Pager}}
</div>
{{else if or .Query .StatusFilter}}<p class="muted">Ничего не найдено по текущему фильтру.</p>
{{else if or .Query .StatusFilter .Run .Subnet .Direction .Protocol}}<p class="muted">Ничего не найдено по текущему фильтру.</p>
{{else}}<p class="muted">Реестр пуст — ни один адрес ещё не ставился на проверку.</p>{{end}}
{{end}}