[glm-grade=B] feat(monitoring): host journald log viewer (DC-055)
Adds a dedicated dashboard surface for host journald logs (caddy, docker,
dashcaddy-api, ssh, ...) via a read-only bind-mount of /var/log/journal +
journalctl. Closes queue item #2: the only way to see the recurring
'100.120.159.34:5000 i/o timeout' spam in Caddy's health_checker logs was
SSH into DNS2.
Backend (dashcaddy-api/):
- src/monitoring/journald-reader.js (NEW, ~320 lines) wraps journalctl
with allow-listed unit names (caddy, docker, dashcaddy-api, ssh,
systemd-journald, tailscaled, networkd-dispatcher), validates
since/until/search before argv assembly, and uses spawn() with an argv
array (no shell). Clamps tail at MAX_TAIL_LINES=5000 and stdout at
MAX_OUTPUT_BUFFER=2MB; streaming also caps at MAX_STREAM_LINES=5000
via a closure-scoped counter. Maps ENOENT cleanly to 'journalctl
unavailable'.
- routes/logs.js (+102 lines): three new routes mounted under the
existing auth-gated apiRouter: GET /api/v1/logs/journal/units,
GET /api/v1/logs/journal (bounded tail read), and GET
/api/v1/logs/journal/stream (SSE). Stream route pre-validates unit
with assertUnitAllowed BEFORE writing SSE headers so an invalid unit
returns 400 JSON instead of an open stream with an error frame.
- 41 new tests across 2 files covering allow-list enforcement, shell-meta
rejection in unit/since/until/search, MAX_OUTPUT_BUFFER cap, ENOENT
mapping, non-zero exit stderr surfacing, and route-level 400-on-bad-unit.
Full local suite 1831/1831 (+41 net).
Container plumbing (start.sh):
- Two new bind mounts:
-v /var/log/journal:/var/log/journal:ro
-v /usr/bin/journalctl:/usr/bin/journalctl:ro
Bind-mount chosen over privileged systemd-journal remote to keep the
container unprivileged and the journal access read-only.
Frontend (status/js/):
- journald.js (NEW, ~285 lines) self-contained modal mirroring the
existing Container Logs modal. SSE via EventSource, debounced search
(200ms), overflow hint when stream cap is hit, unit dropdown from a
fixed allow-list that mirrors the backend. Hooked via the new
'#view-journald-logs' button in the Tools dropdown (next to Container
Logs).
- build.js (+4 lines) adds journald.js to the features bundle. Bundle
rebuild succeeded (features.js 27 files, 466 KB raw / 1229 KB min).
CSP hash unchanged (no inline script changes).
GLM judge (round 1, 178s, 14 tool calls, cold diff + 8 file reads):
GRADE=B. Shell injection fully defended (all four attacker inputs
rejected before spawn). Route-level allow-list holds (streamEntries not
called for bad unit). SSE cleanup correct. Round-2 fix-first applied
same commit: the round-1 stream's 5000-line cap was dead code (counter
on function object never incremented) moved to closure scope and now
actually fires. Also dropped deprecated req.on('aborted') listener
(Node 18+ fires 'close' for both clean and abort).
Container live HEAD 901df86 [glm-grade=B]; deploy via start.sh atomic
swap. Live verify: status.sami=200, container Up + healthy, the new
bundle and index.html served.
This commit is contained in:
@@ -6,6 +6,15 @@ const { exists } = require('../src/utilities/fs-helpers');
|
||||
const { paginate, parsePaginationParams } = require('../src/utilities/pagination');
|
||||
const { NotFoundError, ValidationError, ForbiddenError } = require('../src/utilities/errors');
|
||||
const { ok } = require('../src/utils/responses');
|
||||
const journald = require('../src/monitoring/journald-reader');
|
||||
|
||||
const journaldAvailable = (() => {
|
||||
try {
|
||||
return fs.existsSync('/var/log/journal') && fs.existsSync('/usr/bin/journalctl');
|
||||
} catch (_) {
|
||||
return false;
|
||||
}
|
||||
})();
|
||||
|
||||
/**
|
||||
* Logs route factory
|
||||
@@ -218,6 +227,99 @@ module.exports = function({ asyncHandler, ok, docker, logDigest, dockerMaintenan
|
||||
ok(res, { result });
|
||||
}, 'logs-docker-maintenance'));
|
||||
|
||||
// ===== DC-055: Host journald log viewer =====
|
||||
// Reads from the host's /var/log/journal via bind-mount in start.sh.
|
||||
// Returns 503 if the bind-mount isn't present (dev containers, Windows).
|
||||
|
||||
// Allow-list of units the dashboard can stream. Exposed to the client so
|
||||
// the dropdown stays in sync with the server-side allow-list.
|
||||
router.get('/logs/journal/units', asyncHandler(async (req, res) => {
|
||||
if (!journaldAvailable) {
|
||||
return ok(res, { available: false, units: [] });
|
||||
}
|
||||
const units = await journald.listUnits();
|
||||
ok(res, { available: true, units });
|
||||
}, 'logs-journal-units'));
|
||||
|
||||
// Read a bounded tail of entries for a unit.
|
||||
router.get('/logs/journal', asyncHandler(async (req, res) => {
|
||||
if (!journaldAvailable) {
|
||||
throw new Error('journald not mounted in this container (host /var/log/journal + /usr/bin/journalctl required)');
|
||||
}
|
||||
const entries = await journald.readEntries({
|
||||
unit: req.query.unit,
|
||||
tail: req.query.tail,
|
||||
since: req.query.since,
|
||||
until: req.query.until,
|
||||
search: req.query.search,
|
||||
});
|
||||
ok(res, { entries, count: entries.length });
|
||||
}, 'logs-journal-read'));
|
||||
|
||||
// Stream entries as they arrive (Server-Sent Events).
|
||||
router.get('/logs/journal/stream', asyncHandler(async (req, res) => {
|
||||
if (!journaldAvailable) {
|
||||
res.statusCode = 503;
|
||||
res.setHeader('Content-Type', 'text/event-stream');
|
||||
res.write(`data: ${JSON.stringify({ error: 'journald not mounted in this container' })}\n\n`);
|
||||
res.end();
|
||||
return;
|
||||
}
|
||||
|
||||
// Validate BEFORE writing SSE headers — once headers go out we
|
||||
// can't change statusCode. The reader does the same validation but
|
||||
// we want to short-circuit here so the response status reflects the
|
||||
// right category (400 for validation, 503 for bind-mount missing).
|
||||
try {
|
||||
journald.assertUnitAllowed(req.query.unit);
|
||||
if (req.query.since) journald.parseTimestamp(req.query.since, 'since');
|
||||
} catch (err) {
|
||||
// Pass through the global error middleware so the response status
|
||||
// + shape matches every other validation error in the API.
|
||||
throw err;
|
||||
}
|
||||
|
||||
// SSE headers — same convention as /logs/stream/:id.
|
||||
res.setHeader('Content-Type', 'text/event-stream');
|
||||
res.setHeader('Cache-Control', 'no-cache');
|
||||
res.setHeader('Connection', 'keep-alive');
|
||||
res.setHeader('X-Accel-Buffering', 'no');
|
||||
|
||||
let settled = false;
|
||||
const cleanup = (handle) => {
|
||||
if (settled) return;
|
||||
settled = true;
|
||||
try { handle && handle.kill(); } catch (_) { /* already dead */ }
|
||||
try { res.end(); } catch (_) { /* already closed */ }
|
||||
};
|
||||
|
||||
let handle;
|
||||
try {
|
||||
handle = journald.streamEntries(
|
||||
{ unit: req.query.unit, since: req.query.since, search: req.query.search },
|
||||
{
|
||||
onData(entry) {
|
||||
if (settled) return;
|
||||
res.write(`data: ${JSON.stringify(entry)}\n\n`);
|
||||
},
|
||||
onError(err) {
|
||||
if (settled) return;
|
||||
res.write(`data: ${JSON.stringify({ error: err.message || String(err) })}\n\n`);
|
||||
cleanup(handle);
|
||||
},
|
||||
}
|
||||
);
|
||||
} catch (err) {
|
||||
res.write(`data: ${JSON.stringify({ error: (err && err.message) || 'stream failed' })}\n\n`);
|
||||
try { res.end(); } catch (_) { /* ignore */ }
|
||||
return;
|
||||
}
|
||||
|
||||
// Modern Node fires 'close' for both clean disconnects and aborts;
|
||||
// the separate 'aborted' listener is deprecated as of Node 18.
|
||||
req.on('close', () => cleanup(handle));
|
||||
}, 'logs-journal-stream'));
|
||||
|
||||
// Get logs from a file path (for native applications)
|
||||
router.get('/logs/file', asyncHandler(async (req, res) => {
|
||||
const { path: logPath, tail = 100 } = req.query;
|
||||
|
||||
Reference in New Issue
Block a user