4 Commits
Author SHA1 Message Date
ayurishchevandClaude Sonnet 5.5 debf2afed2 Add authentication: admin/agent bearer tokens for the API, login for the dashboard
control-api: every route now carries a mandatory access level (admin / agent /
open) in a route table. All /api/v1/admin/* require the admin token; the
write calls of validator-agent and prober (self-check, events, results,
complete) require a separate static agent token; register, heartbeat and
fetching the assignment stay open. Tokens come from env vars, are compared in
constant time and never logged. An empty token leaves that level open with a
startup warning (backward compatible).

validator-agent / prober: apiclient sends the agent token only to control-api.

admin-dashboard: login/password (from env) with a stateless HMAC session
cookie, Origin-based CSRF check, per-IP brute-force throttle, HX-Redirect for
htmx polls, logout in the sidebar; the dashboard calls control-api with the
admin token. Login page layout fixed after review.

Also: env plumbing in docker-compose/rxprod-compose/systemd/config examples,
e2e script with token assertions, tests, docs (API, SETUP, USAGE, DASHBOARD,
README), plan and review under docs/changes/, bin/ rebuilt with new
SHA256SUMS.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-10-01 11:35:24 +03:00
ayurishchevandClaude Sonnet 5.5 7b34b640f5 rxprod-compose: publish admin-dashboard on host port 8091
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-10-01 10:44:31 +03:00
ayurishchevandClaude Sonnet 5 6117c044b5 Point rxprod-compose at prebuilt images and its own control-api.yaml/capi-db
docker-compose.yml now runs from prebuilt images (civ-capi/civ-adash/
civ-prober) instead of building from source, mounts this host's own
rxprod-compose/control-api.yaml and capi-db/ (both local, gitignored
except control-api.yaml itself which is now committed), and moves
control-api off port 8080 onto 8081.

rxprod-compose/sources/ carries local copies of the example configs
(admin-dashboard/control-api/prober/validator-agent) plus .env.example,
moved here from rxprod-compose/.env.example, for reference alongside
this specific deployment's docker-compose.yml.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-18 10:58:00 +03:00
ayurishchevandClaude Sonnet 5 399c64e801 Add a simple, single-file docker-compose for the control-plane/dashboard/prober host
The existing deploy/docker/docker-compose.yml (+ override/prod, Compose
profiles) is flexible but requires understanding profiles and file
layering. For a server that only ever runs these three fixed roles
against a real OpenStack (VK Cloud) deployment, rxprod-compose/ adds a
single flat docker-compose.yml with no profiles — control-api,
admin-dashboard and prober wired together directly, both ports published
on the host (control-api needs to be reachable by validator-agent running
separately on real cloud VMs). OpenStack credentials and the prober's
site_id come from a local .env (gitignored; .env.example is the
template).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NeVbMVEiE7XQAkBd7HQgj6
2026-09-14 23:15:30 +03:00