v9.6.0
release-tag / release-image (push) Successful in 2m28s

This commit is contained in:
2026-09-01 22:46:20 +02:00
parent 63d514e50d
commit f3a687543c
18 changed files with 706 additions and 9 deletions
+83
View File
@@ -144,6 +144,9 @@ func New(c config.Config, a *auth.Service, ss *stacks.Service, n *nodes.Manager,
api.Handle("PUT /api/security/auditd", auth.RequireRole("admin", http.HandlerFunc(s.securityApplyAuditd)))
api.Handle("POST /api/security/components/{component}/install", auth.RequireRole("admin", http.HandlerFunc(s.securityInstall)))
api.Handle("POST /api/security/components/{component}/actions/{action}", auth.RequireRole("admin", http.HandlerFunc(s.securityComponentAction)))
api.Handle("GET /api/packages/updates", auth.RequireRole("admin", http.HandlerFunc(s.packageUpdates)))
api.Handle("POST /api/packages/refresh", auth.RequireRole("admin", http.HandlerFunc(s.packageRefresh)))
api.Handle("POST /api/packages/upgrade", auth.RequireRole("admin", http.HandlerFunc(s.packageUpgrade)))
mux.Handle("/api/", a.Middleware(mutationOriginGuard(s.auditMiddleware(api))))
assets, _ := fs.Sub(web.FS, ".")
f := http.FileServer(http.FS(assets))
@@ -181,6 +184,9 @@ func (s *Server) agent(m *http.ServeMux) {
a.HandleFunc("PUT /agent/v1/security/auditd", s.localSecurityApplyAuditd)
a.HandleFunc("POST /agent/v1/security/components/{component}/install", s.localSecurityInstall)
a.HandleFunc("POST /agent/v1/security/components/{component}/actions/{action}", s.localSecurityComponentAction)
a.HandleFunc("GET /agent/v1/packages/updates", s.localPackageUpdates)
a.HandleFunc("POST /agent/v1/packages/refresh", s.localPackageRefresh)
a.HandleFunc("POST /agent/v1/packages/upgrade", s.localPackageUpgrade)
a.HandleFunc("GET /agent/v1/stacks", s.localList)
a.HandleFunc("GET /agent/v1/stacks/{name}", s.localGet)
a.HandleFunc("PUT /agent/v1/stacks/{name}", s.localSave)
@@ -1443,6 +1449,83 @@ func (s *Server) proxyTerminal(w http.ResponseWriter, r *http.Request, id int64)
}
}
func (s *Server) packageUpdates(w http.ResponseWriter, r *http.Request) {
if id := nodeID(r); id > 0 {
s.relayWithTimeout(w, r, id, http.MethodGet, "/agent/v1/packages/updates", nil, 2*time.Minute)
return
}
s.localPackageUpdates(w, r)
}
func (s *Server) localPackageUpdates(w http.ResponseWriter, r *http.Request) {
if s.security == nil {
http.Error(w, "host package service unavailable", http.StatusServiceUnavailable)
return
}
v, e := s.security.PackageUpdates(r.Context())
if e != nil {
http.Error(w, e.Error(), http.StatusBadRequest)
return
}
jsonOut(w, http.StatusOK, v)
}
func (s *Server) packageRefresh(w http.ResponseWriter, r *http.Request) {
if id := nodeID(r); id > 0 {
s.relayWithTimeout(w, r, id, http.MethodPost, "/agent/v1/packages/refresh", map[string]any{}, 12*time.Minute)
return
}
s.localPackageRefresh(w, r)
}
func (s *Server) localPackageRefresh(w http.ResponseWriter, r *http.Request) {
if s.security == nil {
http.Error(w, "host package service unavailable", http.StatusServiceUnavailable)
return
}
v, e := s.security.RefreshPackageMetadata(r.Context())
if e != nil {
http.Error(w, e.Error(), http.StatusBadRequest)
return
}
jsonOut(w, http.StatusOK, v)
}
func (s *Server) packageUpgrade(w http.ResponseWriter, r *http.Request) {
var in hostsecurity.PackageUpgradeInput
if e := read(r, &in); e != nil {
http.Error(w, e.Error(), http.StatusBadRequest)
return
}
if id := nodeID(r); id > 0 {
s.relayWithTimeout(w, r, id, http.MethodPost, "/agent/v1/packages/upgrade", in, 50*time.Minute)
return
}
s.packageUpgradeLocal(w, r, in)
}
func (s *Server) localPackageUpgrade(w http.ResponseWriter, r *http.Request) {
var in hostsecurity.PackageUpgradeInput
if e := read(r, &in); e != nil {
http.Error(w, e.Error(), http.StatusBadRequest)
return
}
s.packageUpgradeLocal(w, r, in)
}
func (s *Server) packageUpgradeLocal(w http.ResponseWriter, r *http.Request, in hostsecurity.PackageUpgradeInput) {
if s.security == nil {
http.Error(w, "host package service unavailable", http.StatusServiceUnavailable)
return
}
v, e := s.security.UpgradePackages(r.Context(), in)
if e != nil {
http.Error(w, e.Error(), http.StatusBadRequest)
return
}
jsonOut(w, http.StatusOK, v)
}
func (s *Server) securityStatus(w http.ResponseWriter, r *http.Request) {
if id := nodeID(r); id > 0 {
s.relay(w, r, id, http.MethodGet, "/agent/v1/security/status", nil)