Runs (migration 0011): a run groups the cycles of one launch. It opens when an address enters an idle queue, takes everything submitted or re-checked while it is open and is finalized when all its addresses are done; a re-check after that opens a new run, so results of different runs never mix. check_runs, run_results (one result per address and run, with the verdict and the expected and stored check counts), subnets, run_id on ip_queue and checks. Existing data is split into runs at pauses of more than an hour; ingress checks get the validator that held the address (also at write time from now on). Analytics (internal/analytics): figures computed from the stored checks of the latest cycle of each address in the run, as facts next to the verdict: summary, reasons of partial, data quality, subnets, targets and the subnet x target matrix by check type, ingress by site, error classes, validators, and the address lists behind the indicators and error classes. API: analytics runs, report, lists (JSON or CSV), subnet list; run and subnet filters for the registry. Dashboard: /analytics matching the approved mockup (run selector, indicators with address lists and CSV, error-class dialogs, drill-down to the registry), subnet list on /settings. Sidebar: the control-api link state, theme toggle and logout moved to the top, the three dots next to the logo removed, sections grouped. Rebuilt bin/control-api and bin/admin-dashboard to match. Plan, summary and the updated README, API, USAGE, DASHBOARD and ADMIN_CLEANUP docs are in docs/. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
92 lines
5.1 KiB
Go
92 lines
5.1 KiB
Go
package httpapi
|
|
|
|
import "net/http"
|
|
|
|
// route is one entry of the Control API route table. The access level is
|
|
// mandatory: every route must state who may call it, so a new endpoint cannot
|
|
// be exposed by accident. The same table is used by the tests.
|
|
type route struct {
|
|
Pattern string
|
|
Handler http.HandlerFunc
|
|
Access accessLevel
|
|
}
|
|
|
|
// RouteInfo is the exported, handler-free view of a route table entry.
|
|
type RouteInfo struct {
|
|
Pattern string
|
|
Access string // "open", "agent" or "admin"
|
|
}
|
|
|
|
// Routes returns the access classification of every registered route.
|
|
func (s *Server) Routes() []RouteInfo {
|
|
table := s.routeTable()
|
|
out := make([]RouteInfo, 0, len(table))
|
|
for _, rt := range table {
|
|
out = append(out, RouteInfo{Pattern: rt.Pattern, Access: rt.Access.String()})
|
|
}
|
|
return out
|
|
}
|
|
|
|
func (s *Server) routes(mux *http.ServeMux) {
|
|
for _, rt := range s.routeTable() {
|
|
mux.HandleFunc(rt.Pattern, s.Auth.require(rt.Access, rt.Handler))
|
|
}
|
|
}
|
|
|
|
func (s *Server) routeTable() []route {
|
|
return []route{
|
|
{"GET /healthz", s.handleHealthz, accessOpen},
|
|
{"POST /api/v1/agents/register", s.handleAgentRegister, accessOpen},
|
|
{"POST /api/v1/agents/{id}/heartbeat", s.handleAgentHeartbeat, accessOpen},
|
|
{"GET /api/v1/agents/{id}/assignment", s.handleAgentAssignment, accessOpen},
|
|
{"GET /api/v1/agents/{id}/observed-ip", s.handleAgentObservedIP, accessOpen},
|
|
{"POST /api/v1/agents/{id}/self-check", s.handleAgentSelfCheck, accessAgent},
|
|
{"POST /api/v1/agents/{id}/events", s.handleAgentEvent, accessAgent},
|
|
{"POST /api/v1/agents/{id}/results", s.handleAgentResults, accessAgent},
|
|
{"POST /api/v1/agents/{id}/complete", s.handleAgentComplete, accessAgent},
|
|
{"POST /api/v1/probers/register", s.handleProberRegister, accessOpen},
|
|
{"POST /api/v1/probers/{site_id}/heartbeat", s.handleProberHeartbeat, accessOpen},
|
|
{"GET /api/v1/probers/{site_id}/assignments", s.handleProberAssignments, accessOpen},
|
|
{"POST /api/v1/probers/{site_id}/results", s.handleProberResults, accessAgent},
|
|
{"GET /api/v1/admin/status", s.handleAdminStatus, accessAdmin},
|
|
{"GET /api/v1/admin/ips", s.handleAdminIPs, accessAdmin},
|
|
{"POST /api/v1/admin/ips", s.handleAdminSubmitIPs, accessAdmin},
|
|
{"POST /api/v1/admin/ips/scan", s.handleAdminScanFloatingIPs, accessAdmin},
|
|
{"GET /api/v1/admin/ips/scan", s.handleAdminScanStatus, accessAdmin},
|
|
{"GET /api/v1/admin/ips/{ip}", s.handleAdminIPDetail, accessAdmin},
|
|
{"POST /api/v1/admin/ips/{ip}/cancel", s.handleAdminCancelIP, accessAdmin},
|
|
{"DELETE /api/v1/admin/ips/{ip}", s.handleAdminDeleteIP, accessAdmin},
|
|
{"POST /api/v1/admin/ips/delete", s.handleAdminDeleteIPs, accessAdmin},
|
|
{"POST /api/v1/admin/ips/clear", s.handleAdminClearQueue, accessAdmin},
|
|
{"GET /api/v1/admin/validators", s.handleAdminValidators, accessAdmin},
|
|
{"GET /api/v1/admin/auto-cycle", s.handleAdminGetAutoCycle, accessAdmin},
|
|
{"PUT /api/v1/admin/auto-cycle", s.handleAdminPutAutoCycle, accessAdmin},
|
|
{"POST /api/v1/admin/auto-cycle/start", s.handleAdminStartAutoCycle, accessAdmin},
|
|
{"POST /api/v1/admin/auto-cycle/stop", s.handleAdminStopAutoCycle, accessAdmin},
|
|
{"GET /api/v1/admin/registry", s.handleAdminRegistry, accessAdmin},
|
|
{"GET /api/v1/admin/registry/{ip}", s.handleAdminRegistryHistory, accessAdmin},
|
|
{"GET /api/v1/admin/analytics/runs", s.handleAnalyticsRuns, accessAdmin},
|
|
{"GET /api/v1/admin/analytics/runs/{id}", s.handleAnalyticsRun, accessAdmin},
|
|
{"GET /api/v1/admin/analytics/runs/{id}/lists/{kind}", s.handleAnalyticsList, accessAdmin},
|
|
{"GET /api/v1/admin/config/subnets", s.handleConfigGetSubnets, accessAdmin},
|
|
{"PUT /api/v1/admin/config/subnets", s.handleConfigPutSubnets, accessAdmin},
|
|
{"GET /api/v1/admin/config/validators", s.handleConfigListValidators, accessAdmin},
|
|
{"POST /api/v1/admin/config/validators", s.handleConfigCreateValidator, accessAdmin},
|
|
{"PUT /api/v1/admin/config/validators/{id}", s.handleConfigUpdateValidator, accessAdmin},
|
|
{"DELETE /api/v1/admin/config/validators/{id}", s.handleConfigDeleteValidator, accessAdmin},
|
|
{"GET /api/v1/admin/config/sites", s.handleConfigListSites, accessAdmin},
|
|
{"PUT /api/v1/admin/config/sites/{index}", s.handleConfigPutSite, accessAdmin},
|
|
{"DELETE /api/v1/admin/config/sites/{index}", s.handleConfigDeleteSite, accessAdmin},
|
|
{"GET /api/v1/admin/config/targets", s.handleConfigListTargets, accessAdmin},
|
|
{"PUT /api/v1/admin/config/targets/{group}", s.handleConfigPutTargetGroup, accessAdmin},
|
|
{"DELETE /api/v1/admin/config/targets/{group}", s.handleConfigDeleteTargetGroup, accessAdmin},
|
|
{"GET /api/v1/admin/config/check-types", s.handleConfigListCheckTypes, accessAdmin},
|
|
{"PUT /api/v1/admin/config/check-types/{name}", s.handleConfigPutCheckType, accessAdmin},
|
|
{"DELETE /api/v1/admin/config/check-types/{name}", s.handleConfigDeleteCheckType, accessAdmin},
|
|
{"GET /api/v1/admin/config/orchestrator", s.handleConfigGetOrchestratorSettings, accessAdmin},
|
|
{"PUT /api/v1/admin/config/orchestrator", s.handleConfigPutOrchestratorSettings, accessAdmin},
|
|
{"GET /api/v1/admin/config/inbound-checks", s.handleConfigGetInboundChecks, accessAdmin},
|
|
{"PUT /api/v1/admin/config/inbound-checks", s.handleConfigPutInboundChecks, accessAdmin},
|
|
}
|
|
}
|