Compare commits
11
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
4b2b1cf411 | ||
|
|
db9c4054a5 | ||
|
|
be7762e369 | ||
|
|
34d8b5a299 | ||
|
|
cf3e12e9d2 | ||
|
|
5cfa95b0b4 | ||
|
|
aabe0b9fd3 | ||
|
|
5532eda43a | ||
|
|
08438b2252 | ||
|
|
49d96722cb | ||
|
|
db265f22a5 |
No files matched your search
@@ -0,0 +1,112 @@
|
|||||||
|
name: Build and Deploy
|
||||||
|
|
||||||
|
on:
|
||||||
|
push:
|
||||||
|
branches: [main]
|
||||||
|
tags: ["v*"]
|
||||||
|
workflow_dispatch:
|
||||||
|
|
||||||
|
env:
|
||||||
|
REGISTRY: git.k2patel.in
|
||||||
|
IMAGE_NAME: k2patel/apcupsd-client
|
||||||
|
HELM_RELEASE: apcupsd-client
|
||||||
|
HELM_NAMESPACE: apcupsd
|
||||||
|
CHART_PATH: ./chart
|
||||||
|
IMAGE_PULL_SECRET: gitea-registry
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
build-and-deploy:
|
||||||
|
runs-on: docker
|
||||||
|
steps:
|
||||||
|
- name: Checkout
|
||||||
|
shell: bash
|
||||||
|
run: |
|
||||||
|
git init .
|
||||||
|
git remote add origin "ssh://git@git.k2patel.in:2222/k2patel/apcupsd-client.git"
|
||||||
|
git -c protocol.version=2 fetch --no-tags --prune --depth=1 origin +refs/heads/main:refs/remotes/origin/main
|
||||||
|
git checkout --force refs/remotes/origin/main
|
||||||
|
|
||||||
|
- name: Determine image tag
|
||||||
|
id: tag
|
||||||
|
shell: bash
|
||||||
|
run: |
|
||||||
|
if [[ "${{ gitea.ref }}" == refs/tags/v* ]]; then
|
||||||
|
echo "tag=${{ gitea.ref_name }}" >> "$GITHUB_OUTPUT"
|
||||||
|
else
|
||||||
|
echo "tag=$(printf '%s' '${{ gitea.sha }}' | cut -c1-12)" >> "$GITHUB_OUTPUT"
|
||||||
|
fi
|
||||||
|
|
||||||
|
- name: Login to Gitea registry
|
||||||
|
shell: bash
|
||||||
|
run: |
|
||||||
|
echo "${{ secrets.CONTAINER_TOKEN }}" | docker login "${{ env.REGISTRY }}" \
|
||||||
|
--username "${{ vars.CONTAINER_USER }}" \
|
||||||
|
--password-stdin
|
||||||
|
|
||||||
|
- name: Build image
|
||||||
|
shell: bash
|
||||||
|
run: |
|
||||||
|
docker build \
|
||||||
|
-t "${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:${{ steps.tag.outputs.tag }}" \
|
||||||
|
-t "${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:latest" \
|
||||||
|
.
|
||||||
|
|
||||||
|
- name: Push image
|
||||||
|
shell: bash
|
||||||
|
run: |
|
||||||
|
docker push "${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:${{ steps.tag.outputs.tag }}"
|
||||||
|
docker push "${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:latest"
|
||||||
|
|
||||||
|
- name: Install Kubernetes tools
|
||||||
|
shell: bash
|
||||||
|
run: |
|
||||||
|
curl -fsSL -o kubectl "https://dl.k8s.io/release/$(curl -fsSL https://dl.k8s.io/release/stable.txt)/bin/linux/amd64/kubectl"
|
||||||
|
chmod +x kubectl
|
||||||
|
sudo mv kubectl /usr/local/bin/
|
||||||
|
curl -fsSL https://raw.githubusercontent.com/helm/helm/main/scripts/get-helm-3 | bash
|
||||||
|
|
||||||
|
- name: Deploy Helm chart
|
||||||
|
shell: bash
|
||||||
|
env:
|
||||||
|
KUBECONFIG_DATA: ${{ secrets.KUBECONFIG_DATA }}
|
||||||
|
CONTAINER_USER: ${{ vars.CONTAINER_USER }}
|
||||||
|
CONTAINER_TOKEN: ${{ secrets.CONTAINER_TOKEN }}
|
||||||
|
run: |
|
||||||
|
if [[ -z "$KUBECONFIG_DATA" ]]; then
|
||||||
|
echo "::error::KUBECONFIG_DATA secret is not configured for this repository"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
if printf '%s' "$KUBECONFIG_DATA" | tr -d '\r\n ' | base64 -d > /tmp/kubeconfig 2>/tmp/kubeconfig-decode.err; then
|
||||||
|
echo "Decoded KUBECONFIG_DATA as base64"
|
||||||
|
else
|
||||||
|
echo "KUBECONFIG_DATA is not base64; using it as raw kubeconfig content"
|
||||||
|
printf '%s' "$KUBECONFIG_DATA" > /tmp/kubeconfig
|
||||||
|
fi
|
||||||
|
chmod 600 /tmp/kubeconfig
|
||||||
|
export KUBECONFIG=/tmp/kubeconfig
|
||||||
|
|
||||||
|
kubectl create namespace "$HELM_NAMESPACE" \
|
||||||
|
--dry-run=client \
|
||||||
|
-o yaml | kubectl apply -f -
|
||||||
|
|
||||||
|
kubectl create secret docker-registry "$IMAGE_PULL_SECRET" \
|
||||||
|
--docker-server="$REGISTRY" \
|
||||||
|
--docker-username="$CONTAINER_USER" \
|
||||||
|
--docker-password="$CONTAINER_TOKEN" \
|
||||||
|
--namespace "$HELM_NAMESPACE" \
|
||||||
|
--dry-run=client \
|
||||||
|
-o yaml | kubectl apply -f -
|
||||||
|
|
||||||
|
if ! helm status "$HELM_RELEASE" --namespace "$HELM_NAMESPACE" >/dev/null 2>&1; then
|
||||||
|
echo "::error::Helm release $HELM_RELEASE is not installed. Bootstrap it with chart secrets before enabling automated image deploys."
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
helm upgrade "$HELM_RELEASE" "$CHART_PATH" \
|
||||||
|
--namespace "$HELM_NAMESPACE" \
|
||||||
|
--reuse-values \
|
||||||
|
--set app.image="${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:${{ steps.tag.outputs.tag }}" \
|
||||||
|
--set app.imagePullPolicy=IfNotPresent \
|
||||||
|
--set "app.imagePullSecrets[0].name=$IMAGE_PULL_SECRET"
|
||||||
|
rm -f /tmp/kubeconfig
|
||||||
@@ -18,14 +18,13 @@ jobs:
|
|||||||
- name: Set up Python
|
- name: Set up Python
|
||||||
uses: actions/setup-python@v5
|
uses: actions/setup-python@v5
|
||||||
with:
|
with:
|
||||||
python-version: '3.12'
|
python-version: '3.14'
|
||||||
cache: pip
|
cache: pip
|
||||||
|
|
||||||
- name: Install dependencies
|
- name: Install dependencies
|
||||||
run: |
|
run: |
|
||||||
python -m pip install --upgrade pip
|
python -m pip install --upgrade pip
|
||||||
pip install -r requirements.txt
|
pip install --require-hashes -r requirements.dev.txt
|
||||||
pip install coverage
|
|
||||||
|
|
||||||
- name: Ruff lint
|
- name: Ruff lint
|
||||||
run: ruff check .
|
run: ruff check .
|
||||||
@@ -43,6 +42,13 @@ jobs:
|
|||||||
contents: read
|
contents: read
|
||||||
packages: write
|
packages: write
|
||||||
id-token: write
|
id-token: write
|
||||||
|
strategy:
|
||||||
|
matrix:
|
||||||
|
include:
|
||||||
|
- image_tag: ghcr.io/k2patel/apcupsd-client:latest
|
||||||
|
melange_config: melange.yaml
|
||||||
|
- image_tag: ghcr.io/k2patel/apcupsd-client-dev:latest
|
||||||
|
melange_config: melange.dev.yaml
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout code
|
- name: Checkout code
|
||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
@@ -55,7 +61,7 @@ jobs:
|
|||||||
|
|
||||||
- name: Build package with melange
|
- name: Build package with melange
|
||||||
run: |
|
run: |
|
||||||
melange build melange.yaml \
|
melange build ${{ matrix.melange_config }} \
|
||||||
--signing-key melange.rsa \
|
--signing-key melange.rsa \
|
||||||
--arch x86_64,aarch64
|
--arch x86_64,aarch64
|
||||||
|
|
||||||
@@ -71,6 +77,5 @@ jobs:
|
|||||||
with:
|
with:
|
||||||
config: apko.yaml
|
config: apko.yaml
|
||||||
archs: x86_64,aarch64
|
archs: x86_64,aarch64
|
||||||
tag: ghcr.io/k2patel/apcupsd-client:latest
|
tag: ${{ matrix.image_tag }}
|
||||||
keyring-append: melange.rsa.pub
|
keyring-append: melange.rsa.pub
|
||||||
|
|
||||||
+3
-2
@@ -52,8 +52,9 @@ Thumbs.db
|
|||||||
*.tmp
|
*.tmp
|
||||||
*.temp
|
*.temp
|
||||||
|
|
||||||
# Kubernetes secrets (sops-encrypted original stays local)
|
# Helm values (contain environment-specific config)
|
||||||
k8s/secret.yaml
|
chart/values.yaml
|
||||||
|
chart/values-secret.yaml
|
||||||
|
|
||||||
# Melange / apko build artifacts
|
# Melange / apko build artifacts
|
||||||
packages/
|
packages/
|
||||||
|
|||||||
+10
-6
@@ -1,7 +1,10 @@
|
|||||||
# syntax=docker/dockerfile:1.6
|
# syntax=docker/dockerfile:1.6
|
||||||
# NOTE: The primary build method is now melange + apko (see melange.yaml / apko.yaml).
|
# NOTE: The primary build method is now melange + apko (see melange.yaml / apko.yaml).
|
||||||
# This Dockerfile is kept for local dev and Docker Compose backward compatibility.
|
# This Dockerfile is kept for local dev and Docker Compose backward compatibility.
|
||||||
FROM python:3.12.7-slim AS builder
|
ARG PYTHON_IMAGE=python:3.14.5-slim@sha256:c845af9399020c7e562969a13689e929074a10fd057acd1b1fad06a2fb068e97
|
||||||
|
ARG REQUIREMENTS_FILE=requirements.txt
|
||||||
|
FROM ${PYTHON_IMAGE} AS builder
|
||||||
|
ARG REQUIREMENTS_FILE
|
||||||
|
|
||||||
ENV PYTHONDONTWRITEBYTECODE=1 \
|
ENV PYTHONDONTWRITEBYTECODE=1 \
|
||||||
PYTHONUNBUFFERED=1 \
|
PYTHONUNBUFFERED=1 \
|
||||||
@@ -13,11 +16,12 @@ RUN apt-get update \
|
|||||||
&& apt-get install -y --no-install-recommends build-essential gcc \
|
&& apt-get install -y --no-install-recommends build-essential gcc \
|
||||||
&& rm -rf /var/lib/apt/lists/*
|
&& rm -rf /var/lib/apt/lists/*
|
||||||
|
|
||||||
COPY requirements.txt ./
|
COPY ${REQUIREMENTS_FILE} requirements.txt
|
||||||
RUN pip install --upgrade pip && pip wheel --wheel-dir /wheels -r requirements.txt
|
RUN pip install --upgrade pip && pip wheel --require-hashes --wheel-dir /wheels -r requirements.txt
|
||||||
|
|
||||||
|
|
||||||
FROM python:3.12.7-slim AS runtime
|
FROM ${PYTHON_IMAGE} AS runtime
|
||||||
|
ARG REQUIREMENTS_FILE
|
||||||
|
|
||||||
ENV PYTHONDONTWRITEBYTECODE=1 \
|
ENV PYTHONDONTWRITEBYTECODE=1 \
|
||||||
PYTHONUNBUFFERED=1 \
|
PYTHONUNBUFFERED=1 \
|
||||||
@@ -33,8 +37,8 @@ RUN apt-get update \
|
|||||||
&& useradd --system --uid 10001 --gid 10001 --home /app --shell /usr/sbin/nologin appuser
|
&& useradd --system --uid 10001 --gid 10001 --home /app --shell /usr/sbin/nologin appuser
|
||||||
|
|
||||||
COPY --from=builder /wheels /wheels
|
COPY --from=builder /wheels /wheels
|
||||||
COPY requirements.txt ./
|
COPY ${REQUIREMENTS_FILE} requirements.txt
|
||||||
RUN pip install --no-index --find-links=/wheels -r requirements.txt \
|
RUN pip install --no-index --find-links=/wheels --require-hashes -r requirements.txt \
|
||||||
&& rm -rf /wheels
|
&& rm -rf /wheels
|
||||||
|
|
||||||
COPY app ./app
|
COPY app ./app
|
||||||
|
|||||||
@@ -23,7 +23,7 @@ A production-ready FastAPI + Redis dashboard for monitoring multiple APC UPS dev
|
|||||||
- SSRF host validation (rejects loopback/link-local; private IPs gated by `ALLOW_PRIVATE_IPS`)
|
- SSRF host validation (rejects loopback/link-local; private IPs gated by `ALLOW_PRIVATE_IPS`)
|
||||||
- SMTP password **only** from env — never persisted to Redis
|
- SMTP password **only** from env — never persisted to Redis
|
||||||
- Subprocess timeout on `apcaccess` (10s), rate-limiting on auth/config, security headers + CSP
|
- Subprocess timeout on `apcaccess` (10s), rate-limiting on auth/config, security headers + CSP
|
||||||
- Non-root container (UID 10001), pinned `python:3.12.7-slim` multi-stage build
|
- Non-root container (UID 10001), digest-pinned `python:3.14.5-slim` multi-stage build
|
||||||
- `/healthz`, `/readyz`, `/metrics` (Prometheus), JSON structured logs with request-ID correlation
|
- `/healthz`, `/readyz`, `/metrics` (Prometheus), JSON structured logs with request-ID correlation
|
||||||
- GitHub Actions pipeline runs ruff + pytest before building/publishing the image
|
- GitHub Actions pipeline runs ruff + pytest before building/publishing the image
|
||||||
|
|
||||||
@@ -82,9 +82,12 @@ Your remote APC UPS hosts must run `apcupsd` with the Network Information Server
|
|||||||
|
|
||||||
## Development
|
## Development
|
||||||
|
|
||||||
|
Production Docker builds install `requirements.txt`; local development and CI use
|
||||||
|
`requirements.dev.txt`.
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
python3.12 -m venv .venv && . .venv/bin/activate
|
python3.14 -m venv .venv && . .venv/bin/activate
|
||||||
pip install -r requirements.txt
|
pip install -r requirements.dev.txt
|
||||||
|
|
||||||
# Run tests (uses fakeredis)
|
# Run tests (uses fakeredis)
|
||||||
pytest tests/
|
pytest tests/
|
||||||
|
|||||||
@@ -1,13 +1,14 @@
|
|||||||
"""Authentication endpoints: login, logout, first-run setup."""
|
"""Authentication endpoints: login, logout, first-run setup."""
|
||||||
import re
|
import re
|
||||||
|
|
||||||
from fastapi import APIRouter, HTTPException, Request, Response
|
from fastapi import APIRouter, Depends, HTTPException, Request, Response
|
||||||
from pydantic import BaseModel, Field
|
from pydantic import BaseModel, Field
|
||||||
|
|
||||||
from ..auth import (
|
from ..auth import (
|
||||||
clear_auth_cookies,
|
clear_auth_cookies,
|
||||||
get_stored_admin,
|
get_stored_admin,
|
||||||
is_admin_configured,
|
is_admin_configured,
|
||||||
|
require_session_and_csrf,
|
||||||
set_auth_cookies,
|
set_auth_cookies,
|
||||||
store_admin,
|
store_admin,
|
||||||
verify_password,
|
verify_password,
|
||||||
@@ -43,7 +44,7 @@ async def api_login(request: Request, response: Response, payload: LoginRequest)
|
|||||||
|
|
||||||
|
|
||||||
@router.post("/api/logout")
|
@router.post("/api/logout")
|
||||||
async def api_logout(response: Response):
|
async def api_logout(response: Response, user=Depends(require_session_and_csrf)):
|
||||||
clear_auth_cookies(response)
|
clear_auth_cookies(response)
|
||||||
return {"ok": True}
|
return {"ok": True}
|
||||||
|
|
||||||
|
|||||||
+18
-8
@@ -5,6 +5,7 @@ from fastapi.templating import Jinja2Templates
|
|||||||
|
|
||||||
from ..auth import CSRF_COOKIE, current_user, is_admin_configured, make_csrf_token
|
from ..auth import CSRF_COOKIE, current_user, is_admin_configured, make_csrf_token
|
||||||
from ..config import load_config
|
from ..config import load_config
|
||||||
|
from ..settings import settings
|
||||||
|
|
||||||
router = APIRouter()
|
router = APIRouter()
|
||||||
templates = Jinja2Templates(directory="app/templates")
|
templates = Jinja2Templates(directory="app/templates")
|
||||||
@@ -15,7 +16,12 @@ def _ensure_csrf(request: Request, response):
|
|||||||
if not token:
|
if not token:
|
||||||
token = make_csrf_token()
|
token = make_csrf_token()
|
||||||
response.set_cookie(
|
response.set_cookie(
|
||||||
CSRF_COOKIE, token, httponly=False, samesite="lax", path="/"
|
CSRF_COOKIE,
|
||||||
|
token,
|
||||||
|
httponly=False,
|
||||||
|
samesite="lax",
|
||||||
|
secure=settings.trust_proxy,
|
||||||
|
path="/",
|
||||||
)
|
)
|
||||||
return token
|
return token
|
||||||
|
|
||||||
@@ -37,9 +43,9 @@ async def dashboard(request: Request):
|
|||||||
cfg = load_config()
|
cfg = load_config()
|
||||||
user = current_user(request)
|
user = current_user(request)
|
||||||
response = templates.TemplateResponse(
|
response = templates.TemplateResponse(
|
||||||
|
request,
|
||||||
"dashboard.html",
|
"dashboard.html",
|
||||||
{
|
{
|
||||||
"request": request,
|
|
||||||
"ups_list": cfg.ups,
|
"ups_list": cfg.ups,
|
||||||
"ui_cfg": cfg.ui.model_dump(),
|
"ui_cfg": cfg.ui.model_dump(),
|
||||||
"current_user": user,
|
"current_user": user,
|
||||||
@@ -56,8 +62,9 @@ async def config_page(request: Request):
|
|||||||
if redirect:
|
if redirect:
|
||||||
return redirect
|
return redirect
|
||||||
response = templates.TemplateResponse(
|
response = templates.TemplateResponse(
|
||||||
|
request,
|
||||||
"config.html",
|
"config.html",
|
||||||
{"request": request, "current_user": current_user(request), "active_nav": "config"},
|
{"current_user": current_user(request), "active_nav": "config"},
|
||||||
)
|
)
|
||||||
_ensure_csrf(request, response)
|
_ensure_csrf(request, response)
|
||||||
return response
|
return response
|
||||||
@@ -69,8 +76,9 @@ async def events_page(request: Request):
|
|||||||
if redirect:
|
if redirect:
|
||||||
return redirect
|
return redirect
|
||||||
response = templates.TemplateResponse(
|
response = templates.TemplateResponse(
|
||||||
|
request,
|
||||||
"events.html",
|
"events.html",
|
||||||
{"request": request, "current_user": current_user(request), "active_nav": "events"},
|
{"current_user": current_user(request), "active_nav": "events"},
|
||||||
)
|
)
|
||||||
_ensure_csrf(request, response)
|
_ensure_csrf(request, response)
|
||||||
return response
|
return response
|
||||||
@@ -82,8 +90,9 @@ async def alerts_page(request: Request):
|
|||||||
if redirect:
|
if redirect:
|
||||||
return redirect
|
return redirect
|
||||||
response = templates.TemplateResponse(
|
response = templates.TemplateResponse(
|
||||||
|
request,
|
||||||
"alerts.html",
|
"alerts.html",
|
||||||
{"request": request, "current_user": current_user(request), "active_nav": "alerts"},
|
{"current_user": current_user(request), "active_nav": "alerts"},
|
||||||
)
|
)
|
||||||
_ensure_csrf(request, response)
|
_ensure_csrf(request, response)
|
||||||
return response
|
return response
|
||||||
@@ -95,8 +104,9 @@ async def settings_page(request: Request):
|
|||||||
if redirect:
|
if redirect:
|
||||||
return redirect
|
return redirect
|
||||||
response = templates.TemplateResponse(
|
response = templates.TemplateResponse(
|
||||||
|
request,
|
||||||
"settings.html",
|
"settings.html",
|
||||||
{"request": request, "current_user": current_user(request), "active_nav": "settings"},
|
{"current_user": current_user(request), "active_nav": "settings"},
|
||||||
)
|
)
|
||||||
_ensure_csrf(request, response)
|
_ensure_csrf(request, response)
|
||||||
return response
|
return response
|
||||||
@@ -108,11 +118,11 @@ async def login_page(request: Request):
|
|||||||
return RedirectResponse("/setup", status_code=302)
|
return RedirectResponse("/setup", status_code=302)
|
||||||
if current_user(request):
|
if current_user(request):
|
||||||
return RedirectResponse("/", status_code=302)
|
return RedirectResponse("/", status_code=302)
|
||||||
return templates.TemplateResponse("login.html", {"request": request})
|
return templates.TemplateResponse(request, "login.html")
|
||||||
|
|
||||||
|
|
||||||
@router.get("/setup", response_class=HTMLResponse)
|
@router.get("/setup", response_class=HTMLResponse)
|
||||||
async def setup_page(request: Request):
|
async def setup_page(request: Request):
|
||||||
if is_admin_configured():
|
if is_admin_configured():
|
||||||
return RedirectResponse("/login", status_code=302)
|
return RedirectResponse("/login", status_code=302)
|
||||||
return templates.TemplateResponse("setup.html", {"request": request})
|
return templates.TemplateResponse(request, "setup.html")
|
||||||
+9
-2
@@ -12,14 +12,16 @@ from .settings import settings
|
|||||||
|
|
||||||
CSP_DIRECTIVES = (
|
CSP_DIRECTIVES = (
|
||||||
"default-src 'self'; "
|
"default-src 'self'; "
|
||||||
"script-src 'self' https://cdn.jsdelivr.net 'unsafe-inline'; "
|
"script-src 'self' https://cdn.jsdelivr.net; "
|
||||||
"style-src 'self' 'unsafe-inline'; "
|
"style-src 'self' 'unsafe-inline'; "
|
||||||
"img-src 'self' data:; "
|
"img-src 'self' data:; "
|
||||||
"font-src 'self' data:; "
|
"font-src 'self' data:; "
|
||||||
"connect-src 'self'; "
|
"connect-src 'self'; "
|
||||||
"base-uri 'self'; "
|
"base-uri 'self'; "
|
||||||
"form-action 'self'; "
|
"form-action 'self'; "
|
||||||
"frame-ancestors 'none'"
|
"frame-ancestors 'none'; "
|
||||||
|
"object-src 'none'; "
|
||||||
|
"upgrade-insecure-requests"
|
||||||
)
|
)
|
||||||
|
|
||||||
|
|
||||||
@@ -33,6 +35,11 @@ class SecurityHeadersMiddleware(BaseHTTPMiddleware):
|
|||||||
response.headers.setdefault("X-Frame-Options", "DENY")
|
response.headers.setdefault("X-Frame-Options", "DENY")
|
||||||
response.headers.setdefault("Referrer-Policy", "same-origin")
|
response.headers.setdefault("Referrer-Policy", "same-origin")
|
||||||
response.headers.setdefault("Content-Security-Policy", CSP_DIRECTIVES)
|
response.headers.setdefault("Content-Security-Policy", CSP_DIRECTIVES)
|
||||||
|
response.headers.setdefault(
|
||||||
|
"Permissions-Policy",
|
||||||
|
"camera=(), microphone=(), geolocation=(), payment=()",
|
||||||
|
)
|
||||||
|
response.headers.setdefault("Cross-Origin-Opener-Policy", "same-origin")
|
||||||
if settings.trust_proxy:
|
if settings.trust_proxy:
|
||||||
response.headers.setdefault(
|
response.headers.setdefault(
|
||||||
"Strict-Transport-Security",
|
"Strict-Transport-Security",
|
||||||
|
|||||||
+130
-36
@@ -1,34 +1,34 @@
|
|||||||
/* ========================================================================
|
/* ========================================================================
|
||||||
Design Tokens — dark theme (slate/indigo)
|
Design Tokens — power operations console
|
||||||
======================================================================== */
|
======================================================================== */
|
||||||
:root {
|
:root {
|
||||||
/* Surfaces */
|
/* Surfaces */
|
||||||
--bg: #0b1220;
|
--bg: #0d0f12;
|
||||||
--surface: #131c2e;
|
--surface: #15191e;
|
||||||
--surface-2: #1a2540;
|
--surface-2: #1d2329;
|
||||||
--surface-3: #223052;
|
--surface-3: #273039;
|
||||||
--border: #263654;
|
--border: #303942;
|
||||||
--border-hi: #36507d;
|
--border-hi: #50606e;
|
||||||
|
|
||||||
/* Text */
|
/* Text */
|
||||||
--text: #e6edf7;
|
--text: #f2f4ef;
|
||||||
--text-muted: #9fb0cb;
|
--text-muted: #b6c0b9;
|
||||||
--text-dim: #6c7fa2;
|
--text-dim: #7f8b88;
|
||||||
|
|
||||||
/* Brand / accent */
|
/* Brand / accent */
|
||||||
--accent: #60a5fa;
|
--accent: #f4b860;
|
||||||
--accent-hover: #3b82f6;
|
--accent-hover: #d9922e;
|
||||||
--accent-dim: #1e3a8a;
|
--accent-dim: #49331a;
|
||||||
|
|
||||||
/* Semantic */
|
/* Semantic */
|
||||||
--success: #10b981;
|
--success: #38d07a;
|
||||||
--success-bg: #053b2d;
|
--success-bg: #102f21;
|
||||||
--warning: #f59e0b;
|
--warning: #f4b860;
|
||||||
--warning-bg: #3a2608;
|
--warning-bg: #3d2a12;
|
||||||
--danger: #ef4444;
|
--danger: #ff5a5f;
|
||||||
--danger-bg: #3b0f0f;
|
--danger-bg: #3e181b;
|
||||||
--info: #38bdf8;
|
--info: #4cc9c0;
|
||||||
--info-bg: #052b3a;
|
--info-bg: #102f31;
|
||||||
|
|
||||||
/* Elevation */
|
/* Elevation */
|
||||||
--shadow-sm: 0 1px 2px rgba(0,0,0,.3);
|
--shadow-sm: 0 1px 2px rgba(0,0,0,.3);
|
||||||
@@ -38,7 +38,7 @@
|
|||||||
/* Radii & spacing */
|
/* Radii & spacing */
|
||||||
--radius-sm: 4px;
|
--radius-sm: 4px;
|
||||||
--radius-md: 6px;
|
--radius-md: 6px;
|
||||||
--radius-lg: 10px;
|
--radius-lg: 8px;
|
||||||
|
|
||||||
/* Typography */
|
/* Typography */
|
||||||
--font: -apple-system, BlinkMacSystemFont, "Segoe UI", Roboto, "Helvetica Neue", Arial, sans-serif;
|
--font: -apple-system, BlinkMacSystemFont, "Segoe UI", Roboto, "Helvetica Neue", Arial, sans-serif;
|
||||||
@@ -55,7 +55,10 @@ body {
|
|||||||
font-family: var(--font);
|
font-family: var(--font);
|
||||||
font-size: 14px;
|
font-size: 14px;
|
||||||
line-height: 1.5;
|
line-height: 1.5;
|
||||||
background: var(--bg);
|
background:
|
||||||
|
linear-gradient(90deg, rgba(244, 184, 96, .045) 1px, transparent 1px) 0 0 / 56px 56px,
|
||||||
|
linear-gradient(0deg, rgba(76, 201, 192, .035) 1px, transparent 1px) 0 0 / 56px 56px,
|
||||||
|
linear-gradient(180deg, #101317 0%, var(--bg) 42%);
|
||||||
color: var(--text);
|
color: var(--text);
|
||||||
-webkit-font-smoothing: antialiased;
|
-webkit-font-smoothing: antialiased;
|
||||||
}
|
}
|
||||||
@@ -79,20 +82,49 @@ code, pre { font-family: var(--font-mono); }
|
|||||||
display: flex;
|
display: flex;
|
||||||
align-items: center;
|
align-items: center;
|
||||||
gap: 24px;
|
gap: 24px;
|
||||||
padding: 10px 24px;
|
padding: 12px 24px;
|
||||||
background: var(--surface);
|
background: rgba(21, 25, 30, .94);
|
||||||
border-bottom: 1px solid var(--border);
|
border-bottom: 1px solid var(--border);
|
||||||
box-shadow: var(--shadow-sm);
|
box-shadow: var(--shadow-sm);
|
||||||
position: sticky;
|
position: sticky;
|
||||||
top: 0;
|
top: 0;
|
||||||
z-index: 100;
|
z-index: 100;
|
||||||
|
backdrop-filter: blur(12px);
|
||||||
}
|
}
|
||||||
.site-header .brand a {
|
.site-header .brand a {
|
||||||
color: var(--text);
|
color: var(--text);
|
||||||
font-weight: 600;
|
display: inline-flex;
|
||||||
font-size: 16px;
|
align-items: center;
|
||||||
|
gap: 10px;
|
||||||
|
}
|
||||||
|
.site-header .brand a:hover { text-decoration: none; color: var(--text); }
|
||||||
|
.brand-mark {
|
||||||
|
display: inline-flex;
|
||||||
|
align-items: center;
|
||||||
|
justify-content: center;
|
||||||
|
width: 38px;
|
||||||
|
height: 26px;
|
||||||
|
border: 1px solid rgba(244, 184, 96, .65);
|
||||||
|
border-radius: var(--radius-sm);
|
||||||
|
color: var(--accent);
|
||||||
|
background: rgba(244, 184, 96, .08);
|
||||||
|
font-family: var(--font-mono);
|
||||||
|
font-size: 11px;
|
||||||
|
font-weight: 700;
|
||||||
|
}
|
||||||
|
.brand-copy {
|
||||||
|
display: flex;
|
||||||
|
flex-direction: column;
|
||||||
|
line-height: 1.05;
|
||||||
|
}
|
||||||
|
.brand-title { font-weight: 700; font-size: 15px; }
|
||||||
|
.brand-subtitle {
|
||||||
|
color: var(--text-dim);
|
||||||
|
font-size: 10px;
|
||||||
|
text-transform: uppercase;
|
||||||
|
letter-spacing: .8px;
|
||||||
|
margin-top: 4px;
|
||||||
}
|
}
|
||||||
.site-header .brand a:hover { text-decoration: none; color: var(--accent); }
|
|
||||||
|
|
||||||
.main-nav {
|
.main-nav {
|
||||||
display: flex;
|
display: flex;
|
||||||
@@ -114,8 +146,9 @@ code, pre { font-family: var(--font-mono); }
|
|||||||
text-decoration: none;
|
text-decoration: none;
|
||||||
}
|
}
|
||||||
.main-nav a.active {
|
.main-nav a.active {
|
||||||
background: var(--accent-dim);
|
background: rgba(244, 184, 96, .12);
|
||||||
color: var(--text);
|
color: var(--accent);
|
||||||
|
box-shadow: inset 0 0 0 1px rgba(244, 184, 96, .25);
|
||||||
}
|
}
|
||||||
|
|
||||||
.user-menu { display: flex; align-items: center; gap: 10px; }
|
.user-menu { display: flex; align-items: center; gap: 10px; }
|
||||||
@@ -142,7 +175,7 @@ code, pre { font-family: var(--font-mono); }
|
|||||||
border-color: var(--danger);
|
border-color: var(--danger);
|
||||||
}
|
}
|
||||||
|
|
||||||
.site-main { padding: 20px 24px; max-width: 1600px; margin: 0 auto; }
|
.site-main { padding: 22px 24px 32px; max-width: 1600px; margin: 0 auto; }
|
||||||
|
|
||||||
/* ========================================================================
|
/* ========================================================================
|
||||||
Page scaffolding
|
Page scaffolding
|
||||||
@@ -157,6 +190,56 @@ code, pre { font-family: var(--font-mono); }
|
|||||||
}
|
}
|
||||||
.page-header h1 { margin: 0; font-size: 22px; }
|
.page-header h1 { margin: 0; font-size: 22px; }
|
||||||
|
|
||||||
|
.dashboard-header {
|
||||||
|
display: flex;
|
||||||
|
align-items: end;
|
||||||
|
justify-content: space-between;
|
||||||
|
gap: 16px;
|
||||||
|
margin-bottom: 16px;
|
||||||
|
}
|
||||||
|
.dashboard-header h1 {
|
||||||
|
margin: 0;
|
||||||
|
font-size: 26px;
|
||||||
|
line-height: 1.15;
|
||||||
|
}
|
||||||
|
.eyebrow {
|
||||||
|
margin: 0 0 4px;
|
||||||
|
color: var(--accent);
|
||||||
|
font-size: 11px;
|
||||||
|
font-weight: 700;
|
||||||
|
letter-spacing: .8px;
|
||||||
|
text-transform: uppercase;
|
||||||
|
}
|
||||||
|
.dashboard-clock {
|
||||||
|
display: inline-flex;
|
||||||
|
align-items: center;
|
||||||
|
gap: 8px;
|
||||||
|
min-height: 32px;
|
||||||
|
padding: 6px 10px;
|
||||||
|
border: 1px solid var(--border);
|
||||||
|
border-radius: var(--radius-md);
|
||||||
|
background: rgba(21, 25, 30, .86);
|
||||||
|
color: var(--text-muted);
|
||||||
|
font-family: var(--font-mono);
|
||||||
|
font-size: 12px;
|
||||||
|
}
|
||||||
|
.pulse-dot {
|
||||||
|
width: 8px;
|
||||||
|
height: 8px;
|
||||||
|
border-radius: 50%;
|
||||||
|
background: var(--text-dim);
|
||||||
|
box-shadow: 0 0 0 0 rgba(76, 201, 192, .35);
|
||||||
|
}
|
||||||
|
.dashboard-clock.live .pulse-dot {
|
||||||
|
background: var(--success);
|
||||||
|
animation: statusPulse 1.8s ease-out infinite;
|
||||||
|
}
|
||||||
|
@keyframes statusPulse {
|
||||||
|
0% { box-shadow: 0 0 0 0 rgba(56, 208, 122, .32); }
|
||||||
|
70% { box-shadow: 0 0 0 8px rgba(56, 208, 122, 0); }
|
||||||
|
100% { box-shadow: 0 0 0 0 rgba(56, 208, 122, 0); }
|
||||||
|
}
|
||||||
|
|
||||||
.filters { display: flex; gap: 8px; flex-wrap: wrap; }
|
.filters { display: flex; gap: 8px; flex-wrap: wrap; }
|
||||||
.filters select, .filters input {
|
.filters select, .filters input {
|
||||||
padding: 7px 10px;
|
padding: 7px 10px;
|
||||||
@@ -377,16 +460,24 @@ code, pre { font-family: var(--font-mono); }
|
|||||||
======================================================================== */
|
======================================================================== */
|
||||||
.fleet-overview { margin-bottom: 20px; }
|
.fleet-overview { margin-bottom: 20px; }
|
||||||
.fleet-card {
|
.fleet-card {
|
||||||
background: var(--surface);
|
background: linear-gradient(180deg, rgba(29, 35, 41, .94), rgba(21, 25, 30, .94));
|
||||||
border: 1px solid var(--border);
|
border: 1px solid var(--border);
|
||||||
border-radius: var(--radius-md);
|
border-radius: var(--radius-md);
|
||||||
padding: 18px 22px;
|
padding: 18px 20px;
|
||||||
display: grid;
|
display: grid;
|
||||||
grid-template-columns: repeat(auto-fit, minmax(140px, 1fr));
|
grid-template-columns: repeat(auto-fit, minmax(140px, 1fr));
|
||||||
gap: 20px;
|
gap: 0;
|
||||||
box-shadow: var(--shadow-sm);
|
box-shadow: var(--shadow-sm);
|
||||||
}
|
}
|
||||||
.fleet-stat { display: flex; flex-direction: column; gap: 4px; min-width: 0; }
|
.fleet-stat {
|
||||||
|
display: flex;
|
||||||
|
flex-direction: column;
|
||||||
|
gap: 4px;
|
||||||
|
min-width: 0;
|
||||||
|
padding: 2px 18px;
|
||||||
|
border-left: 1px solid rgba(80, 96, 110, .42);
|
||||||
|
}
|
||||||
|
.fleet-stat:first-child { border-left: 0; padding-left: 0; }
|
||||||
.fleet-stat-label {
|
.fleet-stat-label {
|
||||||
color: var(--text-dim);
|
color: var(--text-dim);
|
||||||
font-size: 11px;
|
font-size: 11px;
|
||||||
@@ -451,6 +542,9 @@ code, pre { font-family: var(--font-mono); }
|
|||||||
.site-header { flex-direction: column; align-items: flex-start; gap: 12px; padding: 12px 16px; }
|
.site-header { flex-direction: column; align-items: flex-start; gap: 12px; padding: 12px 16px; }
|
||||||
.main-nav { width: 100%; }
|
.main-nav { width: 100%; }
|
||||||
.site-main { padding: 16px; }
|
.site-main { padding: 16px; }
|
||||||
.fleet-card { grid-template-columns: repeat(auto-fit, minmax(110px, 1fr)); gap: 14px; padding: 14px 16px; }
|
.dashboard-header { align-items: flex-start; flex-direction: column; }
|
||||||
|
.dashboard-header h1 { font-size: 22px; }
|
||||||
|
.fleet-card { grid-template-columns: repeat(auto-fit, minmax(110px, 1fr)); padding: 14px 16px; }
|
||||||
|
.fleet-stat { border-left: 0; padding: 8px 0; }
|
||||||
.fleet-stat-value { font-size: 20px; }
|
.fleet-stat-value { font-size: 20px; }
|
||||||
}
|
}
|
||||||
@@ -0,0 +1,64 @@
|
|||||||
|
// Login and first-run setup handlers. Kept external so CSP can block inline JS.
|
||||||
|
(function () {
|
||||||
|
async function parseError(resp, fallback) {
|
||||||
|
const err = await resp.json().catch(() => ({}));
|
||||||
|
return err.detail || fallback;
|
||||||
|
}
|
||||||
|
|
||||||
|
function showError(id, message) {
|
||||||
|
const errBox = document.getElementById(id);
|
||||||
|
if (!errBox) return;
|
||||||
|
errBox.textContent = message;
|
||||||
|
errBox.hidden = false;
|
||||||
|
}
|
||||||
|
|
||||||
|
const loginForm = document.getElementById('login-form');
|
||||||
|
if (loginForm) {
|
||||||
|
loginForm.addEventListener('submit', async (e) => {
|
||||||
|
e.preventDefault();
|
||||||
|
const errBox = document.getElementById('login-error');
|
||||||
|
if (errBox) errBox.hidden = true;
|
||||||
|
const resp = await fetch('/api/login', {
|
||||||
|
method: 'POST',
|
||||||
|
headers: { 'Content-Type': 'application/json' },
|
||||||
|
body: JSON.stringify({
|
||||||
|
username: document.getElementById('username').value,
|
||||||
|
password: document.getElementById('password').value,
|
||||||
|
}),
|
||||||
|
});
|
||||||
|
if (resp.ok) {
|
||||||
|
window.location.href = '/';
|
||||||
|
} else {
|
||||||
|
showError('login-error', await parseError(resp, 'Login failed'));
|
||||||
|
}
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
const setupForm = document.getElementById('setup-form');
|
||||||
|
if (setupForm) {
|
||||||
|
setupForm.addEventListener('submit', async (e) => {
|
||||||
|
e.preventDefault();
|
||||||
|
const errBox = document.getElementById('setup-error');
|
||||||
|
if (errBox) errBox.hidden = true;
|
||||||
|
const pw = document.getElementById('password').value;
|
||||||
|
const pw2 = document.getElementById('password2').value;
|
||||||
|
if (pw !== pw2) {
|
||||||
|
showError('setup-error', 'Passwords do not match');
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
const resp = await fetch('/api/setup', {
|
||||||
|
method: 'POST',
|
||||||
|
headers: { 'Content-Type': 'application/json' },
|
||||||
|
body: JSON.stringify({
|
||||||
|
username: document.getElementById('username').value,
|
||||||
|
password: pw,
|
||||||
|
}),
|
||||||
|
});
|
||||||
|
if (resp.ok) {
|
||||||
|
window.location.href = '/';
|
||||||
|
} else {
|
||||||
|
showError('setup-error', await parseError(resp, 'Setup failed'));
|
||||||
|
}
|
||||||
|
});
|
||||||
|
}
|
||||||
|
})();
|
||||||
+67
-29
@@ -1,6 +1,6 @@
|
|||||||
// Debug configuration
|
// Debug configuration
|
||||||
const DEBUG_ENABLED = localStorage.getItem('ups_debug') === 'true' ||
|
const DEBUG_ENABLED = localStorage.getItem('ups_debug') === 'true' ||
|
||||||
new URLSearchParams(window.location.search).get('debug') === 'true' || true; // Temporarily enable debug
|
new URLSearchParams(window.location.search).get('debug') === 'true';
|
||||||
|
|
||||||
// Debug logging helper
|
// Debug logging helper
|
||||||
function debugLog(...args) {
|
function debugLog(...args) {
|
||||||
@@ -39,6 +39,31 @@ window.upsDebug = {
|
|||||||
const evtSource = new EventSource('/api/stream');
|
const evtSource = new EventSource('/api/stream');
|
||||||
const charts = {};
|
const charts = {};
|
||||||
|
|
||||||
|
function escapeHtml(value) {
|
||||||
|
return String(value ?? '').replace(/[&<>"']/g, (ch) => ({
|
||||||
|
'&': '&',
|
||||||
|
'<': '<',
|
||||||
|
'>': '>',
|
||||||
|
'"': '"',
|
||||||
|
"'": '''
|
||||||
|
}[ch]));
|
||||||
|
}
|
||||||
|
|
||||||
|
function apiUpsPath(name, suffix = '') {
|
||||||
|
return `/api/ups/${encodeURIComponent(name)}${suffix}`;
|
||||||
|
}
|
||||||
|
|
||||||
|
function getCard(name) {
|
||||||
|
return document.getElementById(`card-${name}`);
|
||||||
|
}
|
||||||
|
|
||||||
|
function setDashboardSyncState(message, live = false) {
|
||||||
|
const el = document.getElementById('dashboard-sync-state');
|
||||||
|
const wrapper = el?.closest('.dashboard-clock');
|
||||||
|
if (el) el.textContent = message;
|
||||||
|
if (wrapper) wrapper.classList.toggle('live', live);
|
||||||
|
}
|
||||||
|
|
||||||
// -------- Fleet overview poller --------
|
// -------- Fleet overview poller --------
|
||||||
async function refreshFleetOverview() {
|
async function refreshFleetOverview() {
|
||||||
try {
|
try {
|
||||||
@@ -53,7 +78,7 @@ async function refreshFleetOverview() {
|
|||||||
setText('fleet-watts', d.total_watts != null ? Math.round(d.total_watts) : '—');
|
setText('fleet-watts', d.total_watts != null ? Math.round(d.total_watts) : '—');
|
||||||
const minRT = d.min_timeleft_minutes;
|
const minRT = d.min_timeleft_minutes;
|
||||||
setText('fleet-min-runtime', minRT != null ? `${Math.round(minRT)} m` : '—');
|
setText('fleet-min-runtime', minRT != null ? `${Math.round(minRT)} m` : '—');
|
||||||
} catch (e) { /* silent */ }
|
} catch (e) { setDashboardSyncState('Fleet summary unavailable', false); }
|
||||||
}
|
}
|
||||||
refreshFleetOverview();
|
refreshFleetOverview();
|
||||||
setInterval(refreshFleetOverview, 10000);
|
setInterval(refreshFleetOverview, 10000);
|
||||||
@@ -142,7 +167,7 @@ function toggleTileSelection(tile, additive) {
|
|||||||
// --- Redis-backed tile layout persistence ---
|
// --- Redis-backed tile layout persistence ---
|
||||||
async function loadServerTileConfig(name) {
|
async function loadServerTileConfig(name) {
|
||||||
try {
|
try {
|
||||||
const resp = await fetch(`/api/ups/${name}/ui_tiles`);
|
const resp = await fetch(apiUpsPath(name, '/ui_tiles'));
|
||||||
if (!resp.ok) return null;
|
if (!resp.ok) return null;
|
||||||
return await resp.json();
|
return await resp.json();
|
||||||
} catch { return null; }
|
} catch { return null; }
|
||||||
@@ -164,13 +189,13 @@ async function loadServerTileConfig(name) {
|
|||||||
saveToStorage(CARD_SIZE_KEY, savedCardSizes);
|
saveToStorage(CARD_SIZE_KEY, savedCardSizes);
|
||||||
// Clear server layout
|
// Clear server layout
|
||||||
try {
|
try {
|
||||||
await window.apiFetch(`/api/ups/${name}/ui_tiles`, { method:'DELETE' });
|
await window.apiFetch(apiUpsPath(name, '/ui_tiles'), { method:'DELETE' });
|
||||||
debugLog(`Cleared server layout for ${name}`);
|
debugLog(`Cleared server layout for ${name}`);
|
||||||
} catch(err) {
|
} catch(err) {
|
||||||
debugWarn(`Failed to clear server layout for ${name}:`, err);
|
debugWarn(`Failed to clear server layout for ${name}:`, err);
|
||||||
}
|
}
|
||||||
// Rebuild grid with defaults then cascade layout
|
// Rebuild grid with defaults then cascade layout
|
||||||
const card = document.getElementById(`card-${name}`);
|
const card = getCard(name);
|
||||||
if (!card) return;
|
if (!card) return;
|
||||||
const grid = card.querySelector('[data-tile-grid]');
|
const grid = card.querySelector('[data-tile-grid]');
|
||||||
if (!grid) return;
|
if (!grid) return;
|
||||||
@@ -276,7 +301,7 @@ function autoArrangeTiles(name, grid) {
|
|||||||
));
|
));
|
||||||
|
|
||||||
// Auto-size the UPS card
|
// Auto-size the UPS card
|
||||||
const card = document.getElementById(`card-${name}`);
|
const card = getCard(name);
|
||||||
if (card) {
|
if (card) {
|
||||||
const cardWidth = Math.max(maxX + padding, 400);
|
const cardWidth = Math.max(maxX + padding, 400);
|
||||||
const cardHeight = Math.max(maxY + padding + 50, 300); // +50 for header
|
const cardHeight = Math.max(maxY + padding + 50, 300); // +50 for header
|
||||||
@@ -300,7 +325,7 @@ function persistCardSize(name, width, height) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
function restoreCardSize(name) {
|
function restoreCardSize(name) {
|
||||||
const card = document.getElementById(`card-${name}`);
|
const card = getCard(name);
|
||||||
const grid = card?.querySelector('[data-tile-grid]');
|
const grid = card?.querySelector('[data-tile-grid]');
|
||||||
if (!card || !grid) return false;
|
if (!card || !grid) return false;
|
||||||
|
|
||||||
@@ -326,7 +351,7 @@ async function saveServerTileConfig(name) {
|
|||||||
const positions = savedTilePos[name] || {};
|
const positions = savedTilePos[name] || {};
|
||||||
const card_size = savedCardSizes[name] || null;
|
const card_size = savedCardSizes[name] || null;
|
||||||
try {
|
try {
|
||||||
await window.apiFetch(`/api/ups/${name}/ui_tiles`, {
|
await window.apiFetch(apiUpsPath(name, '/ui_tiles'), {
|
||||||
method: 'POST',
|
method: 'POST',
|
||||||
body: JSON.stringify({ types, order, hidden: hiddenArr, custom, positions, card_size })
|
body: JSON.stringify({ types, order, hidden: hiddenArr, custom, positions, card_size })
|
||||||
});
|
});
|
||||||
@@ -334,7 +359,7 @@ async function saveServerTileConfig(name) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
function ensureUpsCard(name) {
|
function ensureUpsCard(name) {
|
||||||
let card = document.getElementById(`card-${name}`);
|
let card = getCard(name);
|
||||||
if (card) {
|
if (card) {
|
||||||
// Ensure add metric listener attached (server-rendered cards bypass creation path)
|
// Ensure add metric listener attached (server-rendered cards bypass creation path)
|
||||||
const addBtn = card.querySelector('[data-add-metric]');
|
const addBtn = card.querySelector('[data-add-metric]');
|
||||||
@@ -388,7 +413,7 @@ function ensureUpsCard(name) {
|
|||||||
}
|
}
|
||||||
div.innerHTML = `
|
div.innerHTML = `
|
||||||
<div class="card-header">
|
<div class="card-header">
|
||||||
<h2>${name}</h2>
|
<h2><span class="state-dot" data-state-dot></span>${escapeHtml(name)}</h2>
|
||||||
<div class="ups-connection" data-field-conn></div>
|
<div class="ups-connection" data-field-conn></div>
|
||||||
${uiCfg.allow_resize ? '<button class="mode-toggle" data-mode-btn title="Toggle compact view">⇳</button>' : ''}
|
${uiCfg.allow_resize ? '<button class="mode-toggle" data-mode-btn title="Toggle compact view">⇳</button>' : ''}
|
||||||
<button class="add-metric-btn" data-add-metric title="Add metric tile">+</button>
|
<button class="add-metric-btn" data-add-metric title="Add metric tile">+</button>
|
||||||
@@ -476,7 +501,7 @@ function initTilesFor(name, grid) {
|
|||||||
// Default cascade layout before positions applied
|
// Default cascade layout before positions applied
|
||||||
tile.style.left = (10 + (idx * 20)) + 'px';
|
tile.style.left = (10 + (idx * 20)) + 'px';
|
||||||
tile.style.top = (10 + (idx * 20)) + 'px';
|
tile.style.top = (10 + (idx * 20)) + 'px';
|
||||||
tile.innerHTML = `<div class="tile-controls">${renderTileSelect(name, tileDef)}</div><h4>${tileDef.short || tileDef.label}</h4><div class="tile-body"></div>`;
|
tile.innerHTML = `<div class="tile-controls">${renderTileSelect(name, tileDef)}</div><h4>${escapeHtml(tileDef.short || tileDef.label)}</h4><div class="tile-body"></div>`;
|
||||||
if (savedTileHidden[name] && savedTileHidden[name][tileDef.id]) tile.classList.add('hidden');
|
if (savedTileHidden[name] && savedTileHidden[name][tileDef.id]) tile.classList.add('hidden');
|
||||||
const resizeHandle = document.createElement('div');
|
const resizeHandle = document.createElement('div');
|
||||||
resizeHandle.className = 'tile-resize';
|
resizeHandle.className = 'tile-resize';
|
||||||
@@ -502,8 +527,8 @@ function initTilesFor(name, grid) {
|
|||||||
function renderTileSelect(name, tileDef) {
|
function renderTileSelect(name, tileDef) {
|
||||||
if (tileDef.types.length <= 1) return '';
|
if (tileDef.types.length <= 1) return '';
|
||||||
const cur = savedTileTypes[name]?.[tileDef.id] || tileDef.defaultType;
|
const cur = savedTileTypes[name]?.[tileDef.id] || tileDef.defaultType;
|
||||||
return `<select data-tile-select data-name="${name}" data-tile-id="${tileDef.id}">` +
|
return `<select data-tile-select data-name="${escapeHtml(name)}" data-tile-id="${escapeHtml(tileDef.id)}">` +
|
||||||
tileDef.types.map(t => `<option value="${t}" ${t===cur?'selected':''}>${t}</option>`).join('') + '</select>';
|
tileDef.types.map(t => `<option value="${escapeHtml(t)}" ${t===cur?'selected':''}>${escapeHtml(t)}</option>`).join('') + '</select>';
|
||||||
}
|
}
|
||||||
|
|
||||||
function attachTileBehavior(name, tile, tileDef) {
|
function attachTileBehavior(name, tile, tileDef) {
|
||||||
@@ -638,7 +663,7 @@ function buildCustomTileVisualization(name, tileEl, tileCfg) {
|
|||||||
const ctx = document.getElementById(canvasId).getContext('2d');
|
const ctx = document.getElementById(canvasId).getContext('2d');
|
||||||
charts[canvasId] = new Chart(ctx, {
|
charts[canvasId] = new Chart(ctx, {
|
||||||
type: tileCfg.chart === 'bar' ? 'bar' : 'line',
|
type: tileCfg.chart === 'bar' ? 'bar' : 'line',
|
||||||
data: { labels: [], datasets: [{ label: tileCfg.metric, data: [], borderColor: '#9f7aea', backgroundColor: 'rgba(159,122,234,0.25)', tension: 0.25 }]},
|
data: { labels: [], datasets: [{ label: String(tileCfg.metric || ''), data: [], borderColor: '#4cc9c0', backgroundColor: 'rgba(76,201,192,0.20)', tension: 0.25 }]},
|
||||||
options: { animation:false, responsive:true, maintainAspectRatio:false, scales:{ y:{ beginAtZero:true } } }
|
options: { animation:false, responsive:true, maintainAspectRatio:false, scales:{ y:{ beginAtZero:true } } }
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
@@ -651,7 +676,7 @@ function createCustomTile(name, grid, tileCfg) {
|
|||||||
tile.dataset.tile = `custom-${tileCfg.id}`;
|
tile.dataset.tile = `custom-${tileCfg.id}`;
|
||||||
tile.setAttribute('draggable','true');
|
tile.setAttribute('draggable','true');
|
||||||
const headerLabel = METRIC_LABELS[tileCfg.metric] ? METRIC_LABELS[tileCfg.metric] : tileCfg.metric;
|
const headerLabel = METRIC_LABELS[tileCfg.metric] ? METRIC_LABELS[tileCfg.metric] : tileCfg.metric;
|
||||||
tile.innerHTML = `<div class="tile-controls"><button data-remove-tile title="Remove">✕</button></div><h4>${headerLabel}</h4><div class="tile-body"></div>`;
|
tile.innerHTML = `<div class="tile-controls"><button data-remove-tile title="Remove">✕</button></div><h4>${escapeHtml(headerLabel)}</h4><div class="tile-body"></div>`;
|
||||||
grid.appendChild(tile);
|
grid.appendChild(tile);
|
||||||
buildCustomTileVisualization(name, tile, tileCfg);
|
buildCustomTileVisualization(name, tile, tileCfg);
|
||||||
const removeBtn = tile.querySelector('[data-remove-tile]');
|
const removeBtn = tile.querySelector('[data-remove-tile]');
|
||||||
@@ -662,7 +687,7 @@ function createCustomTile(name, grid, tileCfg) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
function rebuildAllTiles(name) {
|
function rebuildAllTiles(name) {
|
||||||
const card = document.getElementById(`card-${name}`);
|
const card = getCard(name);
|
||||||
if (!card) return;
|
if (!card) return;
|
||||||
const grid = card.querySelector('[data-tile-grid]');
|
const grid = card.querySelector('[data-tile-grid]');
|
||||||
if (!grid) return;
|
if (!grid) return;
|
||||||
@@ -689,7 +714,7 @@ function removeCustomTile(name, id, tileEl) {
|
|||||||
|
|
||||||
function seedHistoricalData(name, tileCfg) {
|
function seedHistoricalData(name, tileCfg) {
|
||||||
if (tileCfg.source !== 'history') return;
|
if (tileCfg.source !== 'history') return;
|
||||||
fetch(`/api/ups/${name}/metric/${tileCfg.metric}?limit=120`).then(r=>r.json()).then(points => {
|
fetch(apiUpsPath(name, `/metric/${encodeURIComponent(tileCfg.metric)}?limit=120`)).then(r=>r.json()).then(points => {
|
||||||
const canvasId = `tile-${name}-custom-${tileCfg.id}`;
|
const canvasId = `tile-${name}-custom-${tileCfg.id}`;
|
||||||
if (tileCfg.chart === 'gauge') return; // gauge only shows live
|
if (tileCfg.chart === 'gauge') return; // gauge only shows live
|
||||||
const c = charts[canvasId];
|
const c = charts[canvasId];
|
||||||
@@ -705,7 +730,7 @@ function loadTileHistoricalData(name, metric, canvasId) {
|
|||||||
// For other metrics, use smaller dataset
|
// For other metrics, use smaller dataset
|
||||||
const limit = metric === 'DERIVED_WATTS' ? 4320 : 60;
|
const limit = metric === 'DERIVED_WATTS' ? 4320 : 60;
|
||||||
|
|
||||||
fetch(`/api/ups/${name}/metric/${metric}?limit=${limit}`).then(r=>r.json()).then(points => {
|
fetch(apiUpsPath(name, `/metric/${encodeURIComponent(metric)}?limit=${limit}`)).then(r=>r.json()).then(points => {
|
||||||
const c = charts[canvasId];
|
const c = charts[canvasId];
|
||||||
if (!c) return;
|
if (!c) return;
|
||||||
|
|
||||||
@@ -823,7 +848,7 @@ function openMetricModal(name) {
|
|||||||
savedCustomTiles[name] = savedCustomTiles[name] || [];
|
savedCustomTiles[name] = savedCustomTiles[name] || [];
|
||||||
savedCustomTiles[name].push(cfg);
|
savedCustomTiles[name].push(cfg);
|
||||||
try { localStorage.setItem(CUSTOM_TILES_KEY, JSON.stringify(savedCustomTiles)); } catch(_) {}
|
try { localStorage.setItem(CUSTOM_TILES_KEY, JSON.stringify(savedCustomTiles)); } catch(_) {}
|
||||||
const card = document.getElementById(`card-${name}`);
|
const card = getCard(name);
|
||||||
const grid = card.querySelector('[data-tile-grid]');
|
const grid = card.querySelector('[data-tile-grid]');
|
||||||
createCustomTile(name, grid, cfg);
|
createCustomTile(name, grid, cfg);
|
||||||
persistTileOrder(name, grid);
|
persistTileOrder(name, grid);
|
||||||
@@ -936,13 +961,17 @@ function updateStaleStatuses() {
|
|||||||
const now = Date.now() / 1000;
|
const now = Date.now() / 1000;
|
||||||
Object.entries(lastUpdateTs).forEach(([name, ts]) => {
|
Object.entries(lastUpdateTs).forEach(([name, ts]) => {
|
||||||
if (now - ts > UPS_STALE_SECONDS) {
|
if (now - ts > UPS_STALE_SECONDS) {
|
||||||
const card = document.getElementById(`card-${name}`);
|
const card = getCard(name);
|
||||||
if (card) {
|
if (card) {
|
||||||
const statusElement = card.querySelector('.ups-status');
|
const statusElement = card.querySelector('.ups-status');
|
||||||
if (statusElement) {
|
if (statusElement) {
|
||||||
statusElement.textContent = 'STALE';
|
statusElement.textContent = 'STALE';
|
||||||
statusElement.className = 'ups-status unknown';
|
statusElement.className = 'ups-status unknown';
|
||||||
}
|
}
|
||||||
|
const stateDot = card.querySelector('[data-state-dot]');
|
||||||
|
if (stateDot) {
|
||||||
|
stateDot.className = 'state-dot';
|
||||||
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
@@ -961,6 +990,7 @@ evtSource.onmessage = (e) => {
|
|||||||
|
|
||||||
const snapshots = payload.snapshots || {};
|
const snapshots = payload.snapshots || {};
|
||||||
const upsMeta = payload.upsMeta || [];
|
const upsMeta = payload.upsMeta || [];
|
||||||
|
setDashboardSyncState(`Live telemetry ${new Date().toLocaleTimeString()}`, true);
|
||||||
|
|
||||||
// Reconcile cards: add new, remove stale
|
// Reconcile cards: add new, remove stale
|
||||||
const desiredNames = new Set(upsMeta.map(m => m.name));
|
const desiredNames = new Set(upsMeta.map(m => m.name));
|
||||||
@@ -1018,6 +1048,10 @@ evtSource.onmessage = (e) => {
|
|||||||
statusElement.textContent = status;
|
statusElement.textContent = status;
|
||||||
statusElement.className = 'ups-status ' + getStatusClass(status);
|
statusElement.className = 'ups-status ' + getStatusClass(status);
|
||||||
}
|
}
|
||||||
|
const stateDot = card.querySelector('[data-state-dot]');
|
||||||
|
if (stateDot) {
|
||||||
|
stateDot.className = 'state-dot ' + getStatusClass(status);
|
||||||
|
}
|
||||||
|
|
||||||
const load = parseFloat(snap['LOADPCT']) || 0;
|
const load = parseFloat(snap['LOADPCT']) || 0;
|
||||||
const batt = parseFloat(snap['BCHARGE']) || 0;
|
const batt = parseFloat(snap['BCHARGE']) || 0;
|
||||||
@@ -1056,7 +1090,7 @@ evtSource.onmessage = (e) => {
|
|||||||
let metricVal;
|
let metricVal;
|
||||||
try { metricVal = parseFloat(String(metricValRaw).split(/\s+/)[0]); } catch(_) { return; }
|
try { metricVal = parseFloat(String(metricValRaw).split(/\s+/)[0]); } catch(_) { return; }
|
||||||
if (ct.chart === 'gauge') {
|
if (ct.chart === 'gauge') {
|
||||||
const gauge = document.querySelector(`#card-${name} [data-tile-grid] .tile[data-tile="custom-${ct.id}"] [data-custom-gauge]`);
|
const gauge = card?.querySelector(`[data-tile-grid] .tile[data-tile="custom-${ct.id}"] [data-custom-gauge]`);
|
||||||
if (gauge) {
|
if (gauge) {
|
||||||
const fill = gauge.querySelector('.gauge-fill');
|
const fill = gauge.querySelector('.gauge-fill');
|
||||||
const text = gauge.querySelector('.gauge-text');
|
const text = gauge.querySelector('.gauge-text');
|
||||||
@@ -1121,8 +1155,8 @@ evtSource.onmessage = (e) => {
|
|||||||
// Fetch events & energy asynchronously (tiles)
|
// Fetch events & energy asynchronously (tiles)
|
||||||
upsMeta.forEach(meta => {
|
upsMeta.forEach(meta => {
|
||||||
if (uiCfg.show_events === false) return;
|
if (uiCfg.show_events === false) return;
|
||||||
fetch(`/api/ups/${meta.name}/events`).then(r => r.json()).then(events => {
|
fetch(apiUpsPath(meta.name, '/events')).then(r => r.json()).then(events => {
|
||||||
const card = document.getElementById(`card-${meta.name}`);
|
const card = getCard(meta.name);
|
||||||
if (!card) return;
|
if (!card) return;
|
||||||
const list = card.querySelector('[data-events]');
|
const list = card.querySelector('[data-events]');
|
||||||
if (!list) return;
|
if (!list) return;
|
||||||
@@ -1141,9 +1175,9 @@ evtSource.onmessage = (e) => {
|
|||||||
});
|
});
|
||||||
}).catch(()=>{});
|
}).catch(()=>{});
|
||||||
if (uiCfg.show_energy) {
|
if (uiCfg.show_energy) {
|
||||||
fetch(`/api/ups/${meta.name}/energy`).then(r => r.json()).then(data => {
|
fetch(apiUpsPath(meta.name, '/energy')).then(r => r.json()).then(data => {
|
||||||
if (!data || data.kwh_today == null) return;
|
if (!data || data.kwh_today == null) return;
|
||||||
const card = document.getElementById(`card-${meta.name}`);
|
const card = getCard(meta.name);
|
||||||
if (!card) return;
|
if (!card) return;
|
||||||
const energyVal = card.querySelector('[data-energy-val]');
|
const energyVal = card.querySelector('[data-energy-val]');
|
||||||
if (energyVal) energyVal.textContent = data.kwh_today.toFixed(2) + ' kWh';
|
if (energyVal) energyVal.textContent = data.kwh_today.toFixed(2) + ' kWh';
|
||||||
@@ -1156,12 +1190,12 @@ evtSource.onmessage = (e) => {
|
|||||||
|
|
||||||
async function updateEventFooter(name) {
|
async function updateEventFooter(name) {
|
||||||
try {
|
try {
|
||||||
const resp = await fetch(`/api/ups/${name}/events`);
|
const resp = await fetch(apiUpsPath(name, '/events'));
|
||||||
if (!resp.ok) return;
|
if (!resp.ok) return;
|
||||||
const events = await resp.json();
|
const events = await resp.json();
|
||||||
if (!Array.isArray(events) || events.length === 0) return;
|
if (!Array.isArray(events) || events.length === 0) return;
|
||||||
const latest = events[0];
|
const latest = events[0];
|
||||||
const card = document.getElementById(`card-${name}`);
|
const card = getCard(name);
|
||||||
if (!card) return;
|
if (!card) return;
|
||||||
const footer = card.querySelector('[data-ups-footer]');
|
const footer = card.querySelector('[data-ups-footer]');
|
||||||
if (!footer) return;
|
if (!footer) return;
|
||||||
@@ -1173,7 +1207,11 @@ async function updateEventFooter(name) {
|
|||||||
} else {
|
} else {
|
||||||
text = latest.detail || latest.msg || latest.raw || '';
|
text = latest.detail || latest.msg || latest.raw || '';
|
||||||
}
|
}
|
||||||
footer.innerHTML = `<span class="event-marquee">${text}</span>`;
|
footer.textContent = '';
|
||||||
|
const marquee = document.createElement('span');
|
||||||
|
marquee.className = 'event-marquee';
|
||||||
|
marquee.textContent = text;
|
||||||
|
footer.appendChild(marquee);
|
||||||
} catch {}
|
} catch {}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -1289,7 +1327,7 @@ function persistTilePositions(name, grid) {
|
|||||||
// Only grow the card if tiles overflow its current bounds. Never shrink
|
// Only grow the card if tiles overflow its current bounds. Never shrink
|
||||||
// the user's manually-sized card.
|
// the user's manually-sized card.
|
||||||
if (maxX > 0 && maxY > 0) {
|
if (maxX > 0 && maxY > 0) {
|
||||||
const card = document.getElementById(`card-${name}`);
|
const card = getCard(name);
|
||||||
if (card) {
|
if (card) {
|
||||||
const neededW = maxX + 20; // 20px right padding
|
const neededW = maxX + 20; // 20px right padding
|
||||||
const neededH = maxY + 70; // 70px for header + bottom padding
|
const neededH = maxY + 70; // 70px for header + bottom padding
|
||||||
|
|||||||
+11
-3
@@ -5,13 +5,21 @@
|
|||||||
<meta name="viewport" content="width=device-width, initial-scale=1" />
|
<meta name="viewport" content="width=device-width, initial-scale=1" />
|
||||||
<title>{% block title %}UPS Dashboard{% endblock %}</title>
|
<title>{% block title %}UPS Dashboard{% endblock %}</title>
|
||||||
<meta name="csrf-token" content="{{ request.cookies.get('csrf_token', '') }}" />
|
<meta name="csrf-token" content="{{ request.cookies.get('csrf_token', '') }}" />
|
||||||
<link rel="stylesheet" href="/static/css/base.css?v=4" />
|
<link rel="stylesheet" href="/static/css/base.css?v=5" />
|
||||||
<link rel="stylesheet" href="/static/css/style.css?v=4" />
|
<link rel="stylesheet" href="/static/css/style.css?v=5" />
|
||||||
{% block head_extra %}{% endblock %}
|
{% block head_extra %}{% endblock %}
|
||||||
</head>
|
</head>
|
||||||
<body>
|
<body>
|
||||||
<header class="site-header">
|
<header class="site-header">
|
||||||
<div class="brand"><a href="/">⚡ APC UPS Dashboard</a></div>
|
<div class="brand">
|
||||||
|
<a href="/">
|
||||||
|
<span class="brand-mark" aria-hidden="true">APC</span>
|
||||||
|
<span class="brand-copy">
|
||||||
|
<span class="brand-title">UPS Dashboard</span>
|
||||||
|
<span class="brand-subtitle">Power continuity</span>
|
||||||
|
</span>
|
||||||
|
</a>
|
||||||
|
</div>
|
||||||
<nav class="main-nav">
|
<nav class="main-nav">
|
||||||
<a href="/" class="{% if active_nav == 'dashboard' %}active{% endif %}">Dashboard</a>
|
<a href="/" class="{% if active_nav == 'dashboard' %}active{% endif %}">Dashboard</a>
|
||||||
<a href="/events" class="{% if active_nav == 'events' %}active{% endif %}">Events</a>
|
<a href="/events" class="{% if active_nav == 'events' %}active{% endif %}">Events</a>
|
||||||
|
|||||||
@@ -4,6 +4,17 @@
|
|||||||
<script src="https://cdn.jsdelivr.net/npm/chart.js"></script>
|
<script src="https://cdn.jsdelivr.net/npm/chart.js"></script>
|
||||||
{% endblock %}
|
{% endblock %}
|
||||||
{% block content %}
|
{% block content %}
|
||||||
|
<section class="dashboard-header" aria-labelledby="dashboard-title">
|
||||||
|
<div>
|
||||||
|
<p class="eyebrow">Live fleet status</p>
|
||||||
|
<h1 id="dashboard-title">Power continuity dashboard</h1>
|
||||||
|
</div>
|
||||||
|
<div class="dashboard-clock" aria-live="polite">
|
||||||
|
<span class="pulse-dot" aria-hidden="true"></span>
|
||||||
|
<span id="dashboard-sync-state">Waiting for UPS telemetry</span>
|
||||||
|
</div>
|
||||||
|
</section>
|
||||||
|
|
||||||
<section class="fleet-overview" id="fleet-overview">
|
<section class="fleet-overview" id="fleet-overview">
|
||||||
<div class="fleet-card">
|
<div class="fleet-card">
|
||||||
<div class="fleet-stat">
|
<div class="fleet-stat">
|
||||||
|
|||||||
@@ -8,8 +8,10 @@
|
|||||||
<link rel="stylesheet" href="/static/css/login.css" />
|
<link rel="stylesheet" href="/static/css/login.css" />
|
||||||
</head>
|
</head>
|
||||||
<body class="auth-body">
|
<body class="auth-body">
|
||||||
<div class="auth-card">
|
<div class="auth-card" data-auth-card="login">
|
||||||
|
<div class="auth-mark">APC</div>
|
||||||
<h1>UPS Dashboard</h1>
|
<h1>UPS Dashboard</h1>
|
||||||
|
<p class="muted">Sign in to monitor runtime, load, transfers, and alerts.</p>
|
||||||
<form id="login-form">
|
<form id="login-form">
|
||||||
<div class="form-field">
|
<div class="form-field">
|
||||||
<label for="username">Username</label>
|
<label for="username">Username</label>
|
||||||
@@ -23,27 +25,6 @@
|
|||||||
<div id="login-error" class="login-error" hidden></div>
|
<div id="login-error" class="login-error" hidden></div>
|
||||||
</form>
|
</form>
|
||||||
</div>
|
</div>
|
||||||
<script>
|
<script src="/static/js/auth.js?v=1"></script>
|
||||||
document.getElementById('login-form').addEventListener('submit', async (e) => {
|
|
||||||
e.preventDefault();
|
|
||||||
const errBox = document.getElementById('login-error');
|
|
||||||
errBox.hidden = true;
|
|
||||||
const resp = await fetch('/api/login', {
|
|
||||||
method: 'POST',
|
|
||||||
headers: { 'Content-Type': 'application/json' },
|
|
||||||
body: JSON.stringify({
|
|
||||||
username: document.getElementById('username').value,
|
|
||||||
password: document.getElementById('password').value,
|
|
||||||
}),
|
|
||||||
});
|
|
||||||
if (resp.ok) {
|
|
||||||
window.location.href = '/';
|
|
||||||
} else {
|
|
||||||
const err = await resp.json().catch(() => ({}));
|
|
||||||
errBox.textContent = err.detail || 'Login failed';
|
|
||||||
errBox.hidden = false;
|
|
||||||
}
|
|
||||||
});
|
|
||||||
</script>
|
|
||||||
</body>
|
</body>
|
||||||
</html>
|
</html>
|
||||||
@@ -8,9 +8,10 @@
|
|||||||
<link rel="stylesheet" href="/static/css/login.css" />
|
<link rel="stylesheet" href="/static/css/login.css" />
|
||||||
</head>
|
</head>
|
||||||
<body class="auth-body">
|
<body class="auth-body">
|
||||||
<div class="auth-card wide">
|
<div class="auth-card wide" data-auth-card="setup">
|
||||||
|
<div class="auth-mark">APC</div>
|
||||||
<h1>First-run Setup</h1>
|
<h1>First-run Setup</h1>
|
||||||
<p class="muted">Create the admin account. Passwords must be at least 8 characters.</p>
|
<p class="muted">Create the admin account before exposing UPS controls.</p>
|
||||||
<form id="setup-form">
|
<form id="setup-form">
|
||||||
<div class="form-field">
|
<div class="form-field">
|
||||||
<label for="username">Admin username</label>
|
<label for="username">Admin username</label>
|
||||||
@@ -27,36 +28,8 @@
|
|||||||
<button type="submit" class="btn-primary btn-block">Create admin account</button>
|
<button type="submit" class="btn-primary btn-block">Create admin account</button>
|
||||||
<div id="setup-error" class="login-error" hidden></div>
|
<div id="setup-error" class="login-error" hidden></div>
|
||||||
</form>
|
</form>
|
||||||
<p class="muted" style="margin-top:16px;">After setup you'll be redirected to the dashboard. Configure UPS devices and SMTP from the nav.</p>
|
<p class="muted auth-note">After setup you will be redirected to the dashboard. Configure UPS devices and SMTP from the nav.</p>
|
||||||
</div>
|
</div>
|
||||||
<script>
|
<script src="/static/js/auth.js?v=1"></script>
|
||||||
document.getElementById('setup-form').addEventListener('submit', async (e) => {
|
|
||||||
e.preventDefault();
|
|
||||||
const errBox = document.getElementById('setup-error');
|
|
||||||
errBox.hidden = true;
|
|
||||||
const pw = document.getElementById('password').value;
|
|
||||||
const pw2 = document.getElementById('password2').value;
|
|
||||||
if (pw !== pw2) {
|
|
||||||
errBox.textContent = 'Passwords do not match';
|
|
||||||
errBox.hidden = false;
|
|
||||||
return;
|
|
||||||
}
|
|
||||||
const resp = await fetch('/api/setup', {
|
|
||||||
method: 'POST',
|
|
||||||
headers: { 'Content-Type': 'application/json' },
|
|
||||||
body: JSON.stringify({
|
|
||||||
username: document.getElementById('username').value,
|
|
||||||
password: pw,
|
|
||||||
}),
|
|
||||||
});
|
|
||||||
if (resp.ok) {
|
|
||||||
window.location.href = '/';
|
|
||||||
} else {
|
|
||||||
const err = await resp.json().catch(() => ({}));
|
|
||||||
errBox.textContent = err.detail || 'Setup failed';
|
|
||||||
errBox.hidden = false;
|
|
||||||
}
|
|
||||||
});
|
|
||||||
</script>
|
|
||||||
</body>
|
</body>
|
||||||
</html>
|
</html>
|
||||||
@@ -0,0 +1,6 @@
|
|||||||
|
apiVersion: v2
|
||||||
|
name: apcupsd-client
|
||||||
|
description: FastAPI + Redis UPS monitoring dashboard
|
||||||
|
type: application
|
||||||
|
version: 1.0.0
|
||||||
|
appVersion: "1.0.0"
|
||||||
+110
@@ -0,0 +1,110 @@
|
|||||||
|
# Helm Deployment Setup
|
||||||
|
|
||||||
|
## Prerequisites
|
||||||
|
|
||||||
|
- helm v3
|
||||||
|
- sops
|
||||||
|
- age (for key generation)
|
||||||
|
- kubectl with cluster access
|
||||||
|
|
||||||
|
## 1. Install helm-secrets plugin
|
||||||
|
|
||||||
|
The plugin must register as `getter/v1` type so it works via the `secrets://` protocol handler.
|
||||||
|
|
||||||
|
```bash
|
||||||
|
# Install helm-secrets as a getter/downloader plugin
|
||||||
|
helm plugin install https://github.com/jkroepke/helm-secrets --verify=false
|
||||||
|
```
|
||||||
|
|
||||||
|
Verify it registered correctly:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
helm plugin list
|
||||||
|
```
|
||||||
|
|
||||||
|
Expected output:
|
||||||
|
|
||||||
|
```
|
||||||
|
NAME VERSION TYPE ...
|
||||||
|
secrets 4.x.x getter/v1 ...
|
||||||
|
```
|
||||||
|
|
||||||
|
The `getter/v1` type means helm-secrets acts as a protocol handler.
|
||||||
|
Use `secrets://` prefix on encrypted value files instead of `helm secrets <command>`:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
# Correct usage with getter/v1
|
||||||
|
helm install my-release ./chart -f values.yaml -f secrets://values-secret.yaml
|
||||||
|
|
||||||
|
# NOT: helm secrets install ... (that requires wrapper type, not getter)
|
||||||
|
```
|
||||||
|
|
||||||
|
## 2. Generate an age key
|
||||||
|
|
||||||
|
```bash
|
||||||
|
age-keygen -o ~/.config/sops/age/keys.txt
|
||||||
|
```
|
||||||
|
|
||||||
|
Note the public key from the output (starts with `age1...`).
|
||||||
|
|
||||||
|
## 3. Configure sops
|
||||||
|
|
||||||
|
Create `.sops.yaml` in the repo root:
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
creation_rules:
|
||||||
|
- path_regex: values-secret\.yaml$
|
||||||
|
age: age1yourpublickeyhere
|
||||||
|
```
|
||||||
|
|
||||||
|
## 4. Create values files
|
||||||
|
|
||||||
|
```bash
|
||||||
|
cp chart/values.yaml.example chart/values.yaml
|
||||||
|
cp chart/values-secret.yaml.example chart/values-secret.yaml
|
||||||
|
```
|
||||||
|
|
||||||
|
Edit `chart/values.yaml` with your environment config (non-sensitive).
|
||||||
|
|
||||||
|
Edit `chart/values-secret.yaml` with sensitive values:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
# Generate a session secret
|
||||||
|
python -c "import secrets; print(secrets.token_urlsafe(32))"
|
||||||
|
|
||||||
|
# Generate an admin password hash
|
||||||
|
python -c "from passlib.hash import argon2; print(argon2.hash('yourpassword'))"
|
||||||
|
```
|
||||||
|
|
||||||
|
## 5. Encrypt secrets
|
||||||
|
|
||||||
|
```bash
|
||||||
|
sops -e -i chart/values-secret.yaml
|
||||||
|
```
|
||||||
|
|
||||||
|
To edit later:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
sops chart/values-secret.yaml # opens in $EDITOR, re-encrypts on save
|
||||||
|
```
|
||||||
|
|
||||||
|
Or decrypt/encrypt in place:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
sops -d -i chart/values-secret.yaml # decrypt
|
||||||
|
# edit the file
|
||||||
|
sops -e -i chart/values-secret.yaml # re-encrypt
|
||||||
|
```
|
||||||
|
|
||||||
|
## 6. Deploy
|
||||||
|
|
||||||
|
```bash
|
||||||
|
./deploy.sh install # first time
|
||||||
|
./deploy.sh upgrade # subsequent deploys
|
||||||
|
./deploy.sh diff # preview changes (requires helm-diff plugin)
|
||||||
|
./deploy.sh template # render manifests locally
|
||||||
|
./deploy.sh status # show running pods/services
|
||||||
|
./deploy.sh logs # tail app logs
|
||||||
|
./deploy.sh restart # rolling restart
|
||||||
|
./deploy.sh destroy # uninstall
|
||||||
|
```
|
||||||
@@ -0,0 +1,20 @@
|
|||||||
|
{{- define "app.labels" -}}
|
||||||
|
app.kubernetes.io/name: {{ .Chart.Name }}
|
||||||
|
app.kubernetes.io/part-of: {{ .Chart.Name }}
|
||||||
|
app.kubernetes.io/version: {{ .Chart.AppVersion | quote }}
|
||||||
|
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{- define "app.selectorLabels" -}}
|
||||||
|
app.kubernetes.io/name: {{ .Chart.Name }}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{- define "redis.labels" -}}
|
||||||
|
app.kubernetes.io/name: redis
|
||||||
|
app.kubernetes.io/part-of: {{ .Chart.Name }}
|
||||||
|
app.kubernetes.io/managed-by: {{ .Release.Service }}
|
||||||
|
{{- end -}}
|
||||||
|
|
||||||
|
{{- define "redis.selectorLabels" -}}
|
||||||
|
app.kubernetes.io/name: redis
|
||||||
|
{{- end -}}
|
||||||
@@ -0,0 +1,11 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: ConfigMap
|
||||||
|
metadata:
|
||||||
|
name: {{ .Chart.Name }}-config
|
||||||
|
namespace: {{ .Values.namespace }}
|
||||||
|
labels:
|
||||||
|
{{- include "app.labels" . | nindent 4 }}
|
||||||
|
data:
|
||||||
|
{{- range $key, $val := .Values.config }}
|
||||||
|
{{ $key }}: {{ $val | quote }}
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,70 @@
|
|||||||
|
apiVersion: apps/v1
|
||||||
|
kind: Deployment
|
||||||
|
metadata:
|
||||||
|
name: {{ .Chart.Name }}
|
||||||
|
namespace: {{ .Values.namespace }}
|
||||||
|
labels:
|
||||||
|
{{- include "app.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
replicas: {{ .Values.app.replicas }}
|
||||||
|
strategy:
|
||||||
|
type: RollingUpdate
|
||||||
|
rollingUpdate:
|
||||||
|
maxUnavailable: 0
|
||||||
|
maxSurge: 1
|
||||||
|
selector:
|
||||||
|
matchLabels:
|
||||||
|
{{- include "app.selectorLabels" . | nindent 6 }}
|
||||||
|
template:
|
||||||
|
metadata:
|
||||||
|
labels:
|
||||||
|
{{- include "app.selectorLabels" . | nindent 8 }}
|
||||||
|
spec:
|
||||||
|
{{- with .Values.app.imagePullSecrets }}
|
||||||
|
imagePullSecrets:
|
||||||
|
{{- toYaml . | nindent 8 }}
|
||||||
|
{{- end }}
|
||||||
|
securityContext:
|
||||||
|
runAsUser: {{ .Values.app.securityContext.runAsUser }}
|
||||||
|
runAsGroup: {{ .Values.app.securityContext.runAsGroup }}
|
||||||
|
runAsNonRoot: true
|
||||||
|
fsGroup: {{ .Values.app.securityContext.runAsGroup }}
|
||||||
|
containers:
|
||||||
|
- name: web
|
||||||
|
image: {{ .Values.app.image | quote }}
|
||||||
|
imagePullPolicy: {{ .Values.app.imagePullPolicy | default "Always" }}
|
||||||
|
ports:
|
||||||
|
- containerPort: {{ .Values.app.port }}
|
||||||
|
protocol: TCP
|
||||||
|
envFrom:
|
||||||
|
- configMapRef:
|
||||||
|
name: {{ .Chart.Name }}-config
|
||||||
|
- secretRef:
|
||||||
|
name: {{ .Chart.Name }}-secret
|
||||||
|
livenessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: {{ .Values.app.probes.liveness.path }}
|
||||||
|
port: {{ .Values.app.port }}
|
||||||
|
initialDelaySeconds: {{ .Values.app.probes.liveness.initialDelaySeconds }}
|
||||||
|
periodSeconds: {{ .Values.app.probes.liveness.periodSeconds }}
|
||||||
|
timeoutSeconds: 5
|
||||||
|
failureThreshold: 3
|
||||||
|
readinessProbe:
|
||||||
|
httpGet:
|
||||||
|
path: {{ .Values.app.probes.readiness.path }}
|
||||||
|
port: {{ .Values.app.port }}
|
||||||
|
initialDelaySeconds: {{ .Values.app.probes.readiness.initialDelaySeconds }}
|
||||||
|
periodSeconds: {{ .Values.app.probes.readiness.periodSeconds }}
|
||||||
|
timeoutSeconds: 5
|
||||||
|
failureThreshold: 3
|
||||||
|
resources:
|
||||||
|
{{- toYaml .Values.app.resources | nindent 12 }}
|
||||||
|
securityContext:
|
||||||
|
readOnlyRootFilesystem: true
|
||||||
|
allowPrivilegeEscalation: false
|
||||||
|
volumeMounts:
|
||||||
|
- name: tmp
|
||||||
|
mountPath: /tmp
|
||||||
|
volumes:
|
||||||
|
- name: tmp
|
||||||
|
emptyDir: {}
|
||||||
@@ -0,0 +1,18 @@
|
|||||||
|
{{- if .Values.redis.enabled }}
|
||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: redis
|
||||||
|
namespace: {{ .Values.namespace }}
|
||||||
|
labels:
|
||||||
|
{{- include "redis.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
type: ClusterIP
|
||||||
|
selector:
|
||||||
|
{{- include "redis.selectorLabels" . | nindent 4 }}
|
||||||
|
ports:
|
||||||
|
- name: redis
|
||||||
|
protocol: TCP
|
||||||
|
port: {{ .Values.redis.port }}
|
||||||
|
targetPort: {{ .Values.redis.port }}
|
||||||
|
{{- end }}
|
||||||
@@ -1,29 +1,29 @@
|
|||||||
|
{{- if .Values.redis.enabled }}
|
||||||
apiVersion: apps/v1
|
apiVersion: apps/v1
|
||||||
kind: StatefulSet
|
kind: StatefulSet
|
||||||
metadata:
|
metadata:
|
||||||
name: redis
|
name: redis
|
||||||
namespace: apcupsd
|
namespace: {{ .Values.namespace }}
|
||||||
labels:
|
labels:
|
||||||
app.kubernetes.io/name: redis
|
{{- include "redis.labels" . | nindent 4 }}
|
||||||
app.kubernetes.io/part-of: apcupsd-client
|
|
||||||
spec:
|
spec:
|
||||||
serviceName: redis
|
serviceName: redis
|
||||||
replicas: 1
|
replicas: 1
|
||||||
selector:
|
selector:
|
||||||
matchLabels:
|
matchLabels:
|
||||||
app.kubernetes.io/name: redis
|
{{- include "redis.selectorLabels" . | nindent 6 }}
|
||||||
template:
|
template:
|
||||||
metadata:
|
metadata:
|
||||||
labels:
|
labels:
|
||||||
app.kubernetes.io/name: redis
|
{{- include "redis.selectorLabels" . | nindent 8 }}
|
||||||
spec:
|
spec:
|
||||||
securityContext:
|
securityContext:
|
||||||
runAsUser: 999
|
runAsUser: {{ .Values.redis.securityContext.runAsUser }}
|
||||||
runAsGroup: 999
|
runAsGroup: {{ .Values.redis.securityContext.runAsGroup }}
|
||||||
fsGroup: 999
|
fsGroup: {{ .Values.redis.securityContext.runAsGroup }}
|
||||||
containers:
|
containers:
|
||||||
- name: redis
|
- name: redis
|
||||||
image: redis:7-alpine
|
image: {{ .Values.redis.image }}
|
||||||
command:
|
command:
|
||||||
- redis-server
|
- redis-server
|
||||||
- --appendonly
|
- --appendonly
|
||||||
@@ -31,7 +31,7 @@ spec:
|
|||||||
- --appendfsync
|
- --appendfsync
|
||||||
- everysec
|
- everysec
|
||||||
ports:
|
ports:
|
||||||
- containerPort: 6379
|
- containerPort: {{ .Values.redis.port }}
|
||||||
protocol: TCP
|
protocol: TCP
|
||||||
livenessProbe:
|
livenessProbe:
|
||||||
exec:
|
exec:
|
||||||
@@ -52,12 +52,7 @@ spec:
|
|||||||
timeoutSeconds: 3
|
timeoutSeconds: 3
|
||||||
failureThreshold: 3
|
failureThreshold: 3
|
||||||
resources:
|
resources:
|
||||||
requests:
|
{{- toYaml .Values.redis.resources | nindent 12 }}
|
||||||
memory: "64Mi"
|
|
||||||
cpu: "50m"
|
|
||||||
limits:
|
|
||||||
memory: "128Mi"
|
|
||||||
cpu: "250m"
|
|
||||||
volumeMounts:
|
volumeMounts:
|
||||||
- name: redis-data
|
- name: redis-data
|
||||||
mountPath: /data
|
mountPath: /data
|
||||||
@@ -69,4 +64,5 @@ spec:
|
|||||||
- ReadWriteOnce
|
- ReadWriteOnce
|
||||||
resources:
|
resources:
|
||||||
requests:
|
requests:
|
||||||
storage: 1Gi
|
storage: {{ .Values.redis.storage }}
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,12 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Secret
|
||||||
|
metadata:
|
||||||
|
name: {{ .Chart.Name }}-secret
|
||||||
|
namespace: {{ .Values.namespace }}
|
||||||
|
labels:
|
||||||
|
{{- include "app.labels" . | nindent 4 }}
|
||||||
|
type: Opaque
|
||||||
|
stringData:
|
||||||
|
{{- range $key, $val := .Values.secrets }}
|
||||||
|
{{ $key }}: {{ $val | quote }}
|
||||||
|
{{- end }}
|
||||||
@@ -0,0 +1,16 @@
|
|||||||
|
apiVersion: v1
|
||||||
|
kind: Service
|
||||||
|
metadata:
|
||||||
|
name: {{ .Chart.Name }}
|
||||||
|
namespace: {{ .Values.namespace }}
|
||||||
|
labels:
|
||||||
|
{{- include "app.labels" . | nindent 4 }}
|
||||||
|
spec:
|
||||||
|
type: {{ .Values.service.type }}
|
||||||
|
selector:
|
||||||
|
{{- include "app.selectorLabels" . | nindent 4 }}
|
||||||
|
ports:
|
||||||
|
- name: http
|
||||||
|
protocol: TCP
|
||||||
|
port: {{ .Values.service.port }}
|
||||||
|
targetPort: {{ .Values.app.port }}
|
||||||
@@ -0,0 +1,7 @@
|
|||||||
|
secrets:
|
||||||
|
# Generate with: python -c "import secrets; print(secrets.token_urlsafe(32))"
|
||||||
|
SESSION_SECRET: ""
|
||||||
|
# Generate with: python -c "from passlib.hash import argon2; print(argon2.hash('yourpassword'))"
|
||||||
|
ADMIN_PASSWORD_HASH: ""
|
||||||
|
# Optional SMTP password
|
||||||
|
SMTP_PASSWORD: ""
|
||||||
@@ -0,0 +1,58 @@
|
|||||||
|
namespace: apcupsd
|
||||||
|
|
||||||
|
app:
|
||||||
|
image: ghcr.io/k2patel/apcupsd-client:latest
|
||||||
|
imagePullPolicy: IfNotPresent
|
||||||
|
imagePullSecrets: []
|
||||||
|
replicas: 1
|
||||||
|
port: 8000
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
memory: "128Mi"
|
||||||
|
cpu: "100m"
|
||||||
|
limits:
|
||||||
|
memory: "256Mi"
|
||||||
|
cpu: "500m"
|
||||||
|
securityContext:
|
||||||
|
runAsUser: 10001
|
||||||
|
runAsGroup: 10001
|
||||||
|
probes:
|
||||||
|
liveness:
|
||||||
|
path: /healthz
|
||||||
|
initialDelaySeconds: 15
|
||||||
|
periodSeconds: 30
|
||||||
|
readiness:
|
||||||
|
path: /readyz
|
||||||
|
initialDelaySeconds: 5
|
||||||
|
periodSeconds: 10
|
||||||
|
|
||||||
|
service:
|
||||||
|
type: LoadBalancer
|
||||||
|
port: 80
|
||||||
|
|
||||||
|
redis:
|
||||||
|
enabled: true
|
||||||
|
image: redis:7-alpine
|
||||||
|
port: 6379
|
||||||
|
resources:
|
||||||
|
requests:
|
||||||
|
memory: "64Mi"
|
||||||
|
cpu: "50m"
|
||||||
|
limits:
|
||||||
|
memory: "128Mi"
|
||||||
|
cpu: "250m"
|
||||||
|
storage: 1Gi
|
||||||
|
securityContext:
|
||||||
|
runAsUser: 999
|
||||||
|
runAsGroup: 999
|
||||||
|
|
||||||
|
config:
|
||||||
|
ADMIN_USERNAME: "admin"
|
||||||
|
REDIS_URL: "redis://redis:6379/0"
|
||||||
|
ALLOW_PRIVATE_IPS: "true"
|
||||||
|
TRUST_PROXY: "false"
|
||||||
|
LOG_LEVEL: "INFO"
|
||||||
|
RATE_LIMIT_ENABLED: "true"
|
||||||
|
SESSION_MAX_AGE_SECONDS: "1209600"
|
||||||
|
TZ: "UTC"
|
||||||
|
UPS_CONFIG_PATH: "/config/ups.yaml"
|
||||||
@@ -1,21 +0,0 @@
|
|||||||
ups:
|
|
||||||
- name: ups1
|
|
||||||
host: 192.168.1.10
|
|
||||||
port: 3551
|
|
||||||
interval_seconds: 30
|
|
||||||
alert_loadpct_high: 80
|
|
||||||
alert_bcharge_low: 40
|
|
||||||
alert_on_battery: true
|
|
||||||
alert_runtime_low_minutes: 10
|
|
||||||
|
|
||||||
smtp:
|
|
||||||
host: 192.168.1.50
|
|
||||||
port: 25
|
|
||||||
username: ""
|
|
||||||
password: "" # or set env SMTP_PASSWORD
|
|
||||||
use_tls: false
|
|
||||||
use_ssl: false
|
|
||||||
from_addr: ups-monitor@example.local
|
|
||||||
to_addrs:
|
|
||||||
- admin@example.local
|
|
||||||
subject_prefix: "[UPS]"
|
|
||||||
@@ -0,0 +1,97 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
|
# Deploy apcupsd-client via Helm with sops-encrypted secrets
|
||||||
|
# Usage: ./deploy.sh [install|upgrade|diff|destroy|status|logs|restart]
|
||||||
|
|
||||||
|
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
||||||
|
CHART_DIR="${SCRIPT_DIR}/chart"
|
||||||
|
RELEASE="apcupsd-client"
|
||||||
|
NAMESPACE="apcupsd"
|
||||||
|
VALUES="${CHART_DIR}/values.yaml"
|
||||||
|
SECRETS="secrets://${CHART_DIR}/values-secret.yaml"
|
||||||
|
ACTION="${1:-upgrade}"
|
||||||
|
|
||||||
|
# Preflight checks
|
||||||
|
for cmd in helm sops; do
|
||||||
|
if ! command -v "$cmd" &>/dev/null; then
|
||||||
|
echo "ERROR: $cmd not found in PATH" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
done
|
||||||
|
|
||||||
|
# Verify helm-secrets plugin is available
|
||||||
|
if ! helm plugin list | grep -q secrets; then
|
||||||
|
echo "ERROR: helm-secrets plugin not installed. Install with: helm plugin install https://github.com/jkroepke/helm-secrets" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
# Check if secrets file exists
|
||||||
|
if [[ ! -f "${CHART_DIR}/values-secret.yaml" ]]; then
|
||||||
|
echo "ERROR: values-secret.yaml not found. Copy values-secret.yaml.example and encrypt with sops." >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
case "$ACTION" in
|
||||||
|
install)
|
||||||
|
echo "--- Installing ${RELEASE} ---"
|
||||||
|
helm install "$RELEASE" "$CHART_DIR" \
|
||||||
|
-n "$NAMESPACE" --create-namespace \
|
||||||
|
-f "$VALUES" \
|
||||||
|
-f "$SECRETS"
|
||||||
|
echo "--- Install complete ---"
|
||||||
|
kubectl -n "$NAMESPACE" get pods
|
||||||
|
;;
|
||||||
|
|
||||||
|
upgrade)
|
||||||
|
echo "--- Upgrading ${RELEASE} ---"
|
||||||
|
helm upgrade "$RELEASE" "$CHART_DIR" \
|
||||||
|
-n "$NAMESPACE" --create-namespace --install \
|
||||||
|
-f "$VALUES" \
|
||||||
|
-f "$SECRETS"
|
||||||
|
echo "--- Upgrade complete ---"
|
||||||
|
kubectl -n "$NAMESPACE" get pods
|
||||||
|
;;
|
||||||
|
|
||||||
|
diff)
|
||||||
|
if ! helm plugin list | grep -q diff; then
|
||||||
|
echo "ERROR: helm-diff plugin not installed. Install with: helm plugin install https://github.com/databus23/helm-diff" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
helm diff upgrade "$RELEASE" "$CHART_DIR" \
|
||||||
|
-n "$NAMESPACE" \
|
||||||
|
-f "$VALUES" \
|
||||||
|
-f "$SECRETS" || true
|
||||||
|
;;
|
||||||
|
|
||||||
|
template)
|
||||||
|
helm template "$RELEASE" "$CHART_DIR" \
|
||||||
|
-n "$NAMESPACE" \
|
||||||
|
-f "$VALUES" \
|
||||||
|
-f "$SECRETS"
|
||||||
|
;;
|
||||||
|
|
||||||
|
destroy)
|
||||||
|
echo "--- Uninstalling ${RELEASE} ---"
|
||||||
|
helm uninstall "$RELEASE" -n "$NAMESPACE" --ignore-not-found
|
||||||
|
echo "--- Destroyed ---"
|
||||||
|
;;
|
||||||
|
|
||||||
|
status)
|
||||||
|
kubectl -n "$NAMESPACE" get all
|
||||||
|
;;
|
||||||
|
|
||||||
|
logs)
|
||||||
|
kubectl -n "$NAMESPACE" logs -l app.kubernetes.io/name=apcupsd-client -f --tail=50
|
||||||
|
;;
|
||||||
|
|
||||||
|
restart)
|
||||||
|
kubectl -n "$NAMESPACE" rollout restart deployment/apcupsd-client
|
||||||
|
kubectl -n "$NAMESPACE" rollout status deployment/apcupsd-client --timeout=120s
|
||||||
|
;;
|
||||||
|
|
||||||
|
*)
|
||||||
|
echo "Usage: $0 {install|upgrade|diff|template|destroy|status|logs|restart}" >&2
|
||||||
|
exit 1
|
||||||
|
;;
|
||||||
|
esac
|
||||||
@@ -1,69 +0,0 @@
|
|||||||
apiVersion: apps/v1
|
|
||||||
kind: Deployment
|
|
||||||
metadata:
|
|
||||||
name: apcupsd-client
|
|
||||||
namespace: apcupsd
|
|
||||||
labels:
|
|
||||||
app.kubernetes.io/name: apcupsd-client
|
|
||||||
app.kubernetes.io/part-of: apcupsd-client
|
|
||||||
spec:
|
|
||||||
replicas: 1
|
|
||||||
strategy:
|
|
||||||
type: RollingUpdate
|
|
||||||
rollingUpdate:
|
|
||||||
maxUnavailable: 0
|
|
||||||
maxSurge: 1
|
|
||||||
selector:
|
|
||||||
matchLabels:
|
|
||||||
app.kubernetes.io/name: apcupsd-client
|
|
||||||
template:
|
|
||||||
metadata:
|
|
||||||
labels:
|
|
||||||
app.kubernetes.io/name: apcupsd-client
|
|
||||||
spec:
|
|
||||||
securityContext:
|
|
||||||
runAsUser: 10001
|
|
||||||
runAsGroup: 10001
|
|
||||||
runAsNonRoot: true
|
|
||||||
fsGroup: 10001
|
|
||||||
containers:
|
|
||||||
- name: web
|
|
||||||
image: ghcr.io/k2patel/apcupsd-client:latest
|
|
||||||
ports:
|
|
||||||
- containerPort: 8000
|
|
||||||
protocol: TCP
|
|
||||||
envFrom:
|
|
||||||
- secretRef:
|
|
||||||
name: apcupsd-client-secret
|
|
||||||
livenessProbe:
|
|
||||||
httpGet:
|
|
||||||
path: /healthz
|
|
||||||
port: 8000
|
|
||||||
initialDelaySeconds: 15
|
|
||||||
periodSeconds: 30
|
|
||||||
timeoutSeconds: 5
|
|
||||||
failureThreshold: 3
|
|
||||||
readinessProbe:
|
|
||||||
httpGet:
|
|
||||||
path: /readyz
|
|
||||||
port: 8000
|
|
||||||
initialDelaySeconds: 5
|
|
||||||
periodSeconds: 10
|
|
||||||
timeoutSeconds: 5
|
|
||||||
failureThreshold: 3
|
|
||||||
resources:
|
|
||||||
requests:
|
|
||||||
memory: "128Mi"
|
|
||||||
cpu: "100m"
|
|
||||||
limits:
|
|
||||||
memory: "256Mi"
|
|
||||||
cpu: "500m"
|
|
||||||
securityContext:
|
|
||||||
readOnlyRootFilesystem: true
|
|
||||||
allowPrivilegeEscalation: false
|
|
||||||
volumeMounts:
|
|
||||||
- name: tmp
|
|
||||||
mountPath: /tmp
|
|
||||||
volumes:
|
|
||||||
- name: tmp
|
|
||||||
emptyDir: {}
|
|
||||||
@@ -1,10 +0,0 @@
|
|||||||
apiVersion: kustomize.config.k8s.io/v1beta1
|
|
||||||
kind: Kustomization
|
|
||||||
|
|
||||||
resources:
|
|
||||||
- namespace.yaml
|
|
||||||
- secret.yaml
|
|
||||||
- redis-statefulset.yaml
|
|
||||||
- redis-service.yaml
|
|
||||||
- deployment.yaml
|
|
||||||
- service.yaml
|
|
||||||
@@ -1,6 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Namespace
|
|
||||||
metadata:
|
|
||||||
name: apcupsd
|
|
||||||
labels:
|
|
||||||
app.kubernetes.io/part-of: apcupsd-client
|
|
||||||
@@ -1,17 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: redis
|
|
||||||
namespace: apcupsd
|
|
||||||
labels:
|
|
||||||
app.kubernetes.io/name: redis
|
|
||||||
app.kubernetes.io/part-of: apcupsd-client
|
|
||||||
spec:
|
|
||||||
type: ClusterIP
|
|
||||||
selector:
|
|
||||||
app.kubernetes.io/name: redis
|
|
||||||
ports:
|
|
||||||
- name: redis
|
|
||||||
protocol: TCP
|
|
||||||
port: 6379
|
|
||||||
targetPort: 6379
|
|
||||||
@@ -1,31 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Secret
|
|
||||||
metadata:
|
|
||||||
name: apcupsd-client-secret
|
|
||||||
namespace: apcupsd
|
|
||||||
labels:
|
|
||||||
app.kubernetes.io/name: apcupsd-client
|
|
||||||
app.kubernetes.io/part-of: apcupsd-client
|
|
||||||
type: Opaque
|
|
||||||
stringData:
|
|
||||||
# Auth (required in production)
|
|
||||||
# Generate with: python -c "import secrets; print(secrets.token_urlsafe(32))"
|
|
||||||
SESSION_SECRET: ""
|
|
||||||
ADMIN_USERNAME: "admin"
|
|
||||||
# Generate with: python -c "from passlib.hash import argon2; print(argon2.hash('yourpassword'))"
|
|
||||||
ADMIN_PASSWORD_HASH: ""
|
|
||||||
SESSION_MAX_AGE_SECONDS: "1209600"
|
|
||||||
TRUST_PROXY: "false"
|
|
||||||
# Redis
|
|
||||||
REDIS_URL: "redis://redis:6379/0"
|
|
||||||
# SMTP (optional)
|
|
||||||
SMTP_PASSWORD: ""
|
|
||||||
# Network
|
|
||||||
ALLOW_PRIVATE_IPS: "true"
|
|
||||||
# Observability
|
|
||||||
LOG_LEVEL: "INFO"
|
|
||||||
RATE_LIMIT_ENABLED: "true"
|
|
||||||
# Locale
|
|
||||||
TZ: "UTC"
|
|
||||||
# Legacy migration (unused unless /config is mounted)
|
|
||||||
UPS_CONFIG_PATH: "/config/ups.yaml"
|
|
||||||
@@ -1,17 +0,0 @@
|
|||||||
apiVersion: v1
|
|
||||||
kind: Service
|
|
||||||
metadata:
|
|
||||||
name: apcupsd-client
|
|
||||||
namespace: apcupsd
|
|
||||||
labels:
|
|
||||||
app.kubernetes.io/name: apcupsd-client
|
|
||||||
app.kubernetes.io/part-of: apcupsd-client
|
|
||||||
spec:
|
|
||||||
type: LoadBalancer
|
|
||||||
selector:
|
|
||||||
app.kubernetes.io/name: apcupsd-client
|
|
||||||
ports:
|
|
||||||
- name: http
|
|
||||||
protocol: TCP
|
|
||||||
port: 10280
|
|
||||||
targetPort: 8000
|
|
||||||
@@ -0,0 +1,70 @@
|
|||||||
|
package:
|
||||||
|
name: apcupsd-client-build
|
||||||
|
version: 1.0.0
|
||||||
|
epoch: 0
|
||||||
|
description: Build stage for apcupsd-client dev image (not installed directly)
|
||||||
|
copyright:
|
||||||
|
- license: MIT
|
||||||
|
|
||||||
|
environment:
|
||||||
|
contents:
|
||||||
|
repositories:
|
||||||
|
- https://dl-cdn.alpinelinux.org/alpine/v3.21/main
|
||||||
|
- https://dl-cdn.alpinelinux.org/alpine/v3.21/community
|
||||||
|
packages:
|
||||||
|
- alpine-baselayout
|
||||||
|
- busybox
|
||||||
|
- python3
|
||||||
|
- py3-pip
|
||||||
|
- py3-virtualenv
|
||||||
|
|
||||||
|
pipeline:
|
||||||
|
- name: Create virtualenv and install dependencies
|
||||||
|
runs: |
|
||||||
|
set -ex
|
||||||
|
mkdir -p "${{targets.destdir}}/app"
|
||||||
|
python3 -m virtualenv "${{targets.destdir}}/app/.venv"
|
||||||
|
"${{targets.destdir}}/app/.venv/bin/pip" install \
|
||||||
|
--no-cache-dir \
|
||||||
|
--only-binary :all: \
|
||||||
|
--require-hashes \
|
||||||
|
-r requirements.dev.txt
|
||||||
|
|
||||||
|
- name: Copy application source
|
||||||
|
runs: |
|
||||||
|
set -ex
|
||||||
|
cp -r app/ "${{targets.destdir}}/app/app/"
|
||||||
|
|
||||||
|
- name: Fix virtualenv shebangs
|
||||||
|
runs: |
|
||||||
|
set -ex
|
||||||
|
find "${{targets.destdir}}/app/.venv/bin" -type f -exec \
|
||||||
|
sed -i "s|${{targets.destdir}}||g" {} +
|
||||||
|
|
||||||
|
- name: Strip build artifacts from virtualenv
|
||||||
|
runs: |
|
||||||
|
set -ex
|
||||||
|
rm -rf "${{targets.destdir}}/app/.venv/bin/pip"*
|
||||||
|
rm -rf "${{targets.destdir}}/app/.venv/bin/wheel"*
|
||||||
|
rm -rf "${{targets.destdir}}/app/.venv/lib/python*/site-packages/pip"
|
||||||
|
rm -rf "${{targets.destdir}}/app/.venv/lib/python*/site-packages/pip-*"
|
||||||
|
rm -rf "${{targets.destdir}}/app/.venv/lib/python*/site-packages/setuptools"
|
||||||
|
rm -rf "${{targets.destdir}}/app/.venv/lib/python*/site-packages/setuptools-*"
|
||||||
|
rm -rf "${{targets.destdir}}/app/.venv/lib/python*/site-packages/wheel"
|
||||||
|
rm -rf "${{targets.destdir}}/app/.venv/lib/python*/site-packages/wheel-*"
|
||||||
|
find "${{targets.destdir}}/app/.venv" -name "__pycache__" -type d -exec rm -rf {} + 2>/dev/null || true
|
||||||
|
find "${{targets.destdir}}/app/.venv" -name "*.pyc" -delete 2>/dev/null || true
|
||||||
|
|
||||||
|
subpackages:
|
||||||
|
- name: apcupsd-client
|
||||||
|
description: FastAPI + Redis UPS monitoring dashboard with dev dependencies
|
||||||
|
options:
|
||||||
|
no-depends: true
|
||||||
|
dependencies:
|
||||||
|
runtime:
|
||||||
|
- python3
|
||||||
|
pipeline:
|
||||||
|
- runs: |
|
||||||
|
set -ex
|
||||||
|
mkdir -p "${{targets.subpkgdir}}"
|
||||||
|
mv "${{targets.destdir}}/app" "${{targets.subpkgdir}}/app"
|
||||||
+2
-1
@@ -27,7 +27,8 @@ pipeline:
|
|||||||
"${{targets.destdir}}/app/.venv/bin/pip" install \
|
"${{targets.destdir}}/app/.venv/bin/pip" install \
|
||||||
--no-cache-dir \
|
--no-cache-dir \
|
||||||
--only-binary :all: \
|
--only-binary :all: \
|
||||||
-r requirements.prod.txt
|
--require-hashes \
|
||||||
|
-r requirements.txt
|
||||||
|
|
||||||
- name: Copy application source
|
- name: Copy application source
|
||||||
runs: |
|
runs: |
|
||||||
|
|||||||
+2
-2
@@ -2,7 +2,7 @@
|
|||||||
name = "apcupsd-client"
|
name = "apcupsd-client"
|
||||||
version = "0.2.0"
|
version = "0.2.0"
|
||||||
description = "FastAPI + Redis dashboard for monitoring multiple APC UPS devices via apcupsd NIS"
|
description = "FastAPI + Redis dashboard for monitoring multiple APC UPS devices via apcupsd NIS"
|
||||||
requires-python = ">=3.12"
|
requires-python = ">=3.14"
|
||||||
readme = "README.md"
|
readme = "README.md"
|
||||||
license = { text = "MIT" }
|
license = { text = "MIT" }
|
||||||
|
|
||||||
@@ -17,7 +17,7 @@ filterwarnings = [
|
|||||||
|
|
||||||
[tool.ruff]
|
[tool.ruff]
|
||||||
line-length = 100
|
line-length = 100
|
||||||
target-version = "py312"
|
target-version = "py314"
|
||||||
extend-exclude = [".venv", "app/static"]
|
extend-exclude = [".venv", "app/static"]
|
||||||
|
|
||||||
[tool.ruff.lint]
|
[tool.ruff.lint]
|
||||||
|
|||||||
@@ -0,0 +1,9 @@
|
|||||||
|
-r requirements.in
|
||||||
|
|
||||||
|
# Dev / test dependencies
|
||||||
|
coverage
|
||||||
|
pytest
|
||||||
|
pytest-asyncio
|
||||||
|
httpx
|
||||||
|
fakeredis
|
||||||
|
ruff
|
||||||
File diff suppressed because it is too large.
Load diff
@@ -0,0 +1,15 @@
|
|||||||
|
fastapi
|
||||||
|
uvicorn[standard]
|
||||||
|
pyyaml
|
||||||
|
redis
|
||||||
|
pydantic
|
||||||
|
pydantic-settings
|
||||||
|
jinja2
|
||||||
|
python-multipart
|
||||||
|
orjson
|
||||||
|
passlib[argon2]
|
||||||
|
itsdangerous
|
||||||
|
slowapi
|
||||||
|
python-json-logger
|
||||||
|
tenacity
|
||||||
|
prometheus-client
|
||||||
@@ -1,15 +0,0 @@
|
|||||||
fastapi==0.115.0
|
|
||||||
uvicorn[standard]==0.30.6
|
|
||||||
pyyaml==6.0.2
|
|
||||||
redis==5.0.7
|
|
||||||
pydantic==2.9.2
|
|
||||||
pydantic-settings==2.5.2
|
|
||||||
jinja2==3.1.4
|
|
||||||
python-multipart==0.0.9
|
|
||||||
orjson==3.10.7
|
|
||||||
passlib[argon2]==1.7.4
|
|
||||||
itsdangerous==2.2.0
|
|
||||||
slowapi==0.1.9
|
|
||||||
python-json-logger==2.0.7
|
|
||||||
tenacity==9.0.0
|
|
||||||
prometheus-client==0.21.0
|
|
||||||
+980
-22
File diff suppressed because it is too large.
Load diff
@@ -52,6 +52,19 @@ def test_login_rejects_before_setup(app_client, fake_redis):
|
|||||||
assert r.status_code == 409
|
assert r.status_code == 409
|
||||||
|
|
||||||
|
|
||||||
|
def test_login_page_renders_when_configured(app_client, fake_redis):
|
||||||
|
store_admin("admin", "testpassword123")
|
||||||
|
r = app_client.get("/login")
|
||||||
|
assert r.status_code == 200
|
||||||
|
assert "text/html" in r.headers["content-type"]
|
||||||
|
|
||||||
|
|
||||||
|
def test_setup_page_renders_before_configured(app_client, fake_redis):
|
||||||
|
r = app_client.get("/setup")
|
||||||
|
assert r.status_code == 200
|
||||||
|
assert "text/html" in r.headers["content-type"]
|
||||||
|
|
||||||
|
|
||||||
def test_login_happy_path(app_client, fake_redis):
|
def test_login_happy_path(app_client, fake_redis):
|
||||||
store_admin("admin", "testpassword123")
|
store_admin("admin", "testpassword123")
|
||||||
r = app_client.post(
|
r = app_client.post(
|
||||||
|
|||||||
Reference in new issue
Block a user