Compare commits

...
33 Commits
Author SHA1 Message Date
Hermes 2d394d882d Standardize response shapes and fix dead fetchT timeout keys
CI / Test & Lint (push) Has been cancelled
CI / Security audit (push) Has been cancelled
Three small cleanups for v1.14.0:

1. /caddy/cas now uses standard success envelope
   Was: { status: 'success', data: { cas: caList } }
   Now: { success: true, cas: caList }
   Updated frontend service-infrastructure.js to match.

2. /api/health/ca now uses standard envelope + meaningful HTTP codes
   Was: { status, message, daysUntilExpiration } with 200 on every error
   Now: { success, caStatus, message|error, daysUntilExpiration }
        with 200 / 404 / 500 as appropriate
   caStatus field preserves the original 'healthy'/'warning'/'critical'/'error'
   semantic so any future consumer of the CA-health state still has it.
   Tests updated to match.

3. Dead timeout: keys in fetchT opts are now a warning, not a silent strip
   src/utils/http.js:41 used to do  without telling
   anyone. Callers that wrote fetchT(url, { timeout: 5000 }) got the default
   5s timeout with no indication that their explicit value was ignored.
   Now it logs a warning naming the call site, then strips the key.
   Fixed 4 call sites that had stale timeout: keys:
   - src/context/caddy.js
   - src/context/dns.js
   - src/context/provider-dns.js
   - routes/dns.js (2 places)
2026-06-10 21:52:33 -07:00
Hermes 11cfb8c26a Consolidate response helpers and error logger to single modules
CI / Test & Lint (push) Has been cancelled
CI / Security audit (push) Has been cancelled
Two cleanups in one pass for the v1.14.0 'works on any platform' theme:

1. Response helpers — merged src/utils/responses.js and the root-level
   response-helpers.js into a single module at src/utils/responses.js.
   The old module had a richer set (created, noContent, validationError,
   unauthorized, forbidden, notFound, conflict) and is now re-exported
   from the new location. Updated 15 routes to import from
   src/utils/responses and deleted the root response-helpers.js.

2. Error logger — error-handler.js now uses the unified
   src/utils/logging.js#logError (same one src/app.js uses), so all errors
   go to one log file with one rotation policy. Removed the dead
   asyncHandler export (the real one is in src/utils/async-handler.js
   and is used everywhere). Deleted the legacy error-logger.js.

Both are invisible to users — same HTTP response shapes, same log file
path, same error format. Internal-only refactor.
2026-06-10 21:37:55 -07:00
Hermes caa09dcebe Bump to v1.13.1 - fix /health/ready res.status bug
CI / Test & Lint (push) Has been cancelled
CI / Security audit (push) Has been cancelled
The readiness probe was using asyncHandler directly, but this codebase's
asyncHandler has signature (logError, fn, context) — first arg is the logger.
Switched to boundAsyncHandler which is what every other route in src/app.js
uses. Verified working on both DNS2 (Docker) and Contabo (systemd).

8 new tests in __tests__/health-endpoints.test.js verify both endpoints.
2026-06-10 21:12:37 -07:00
Hermes 264de9644c Fix /health/ready res.status bug + add comprehensive health endpoint tests
CI / Test & Lint (push) Has been cancelled
CI / Security audit (push) Has been cancelled
The readiness probe was crashing with 'res.status is not a function' because
asyncHandler(async (req, res) => {...}, 'health-ready') was called directly,
but asyncHandler's signature is (logError, fn, context) — first arg is the
logger, not the handler. The fix uses boundAsyncHandler like all other routes
in the file do.

Added 8 unit tests for both /health/live and /health/ready:
- live always 200 (liveness ≠ readiness)
- ready returns 503 when config/services/docker fail
- no 'res.status is not a function' crash when dependencies fail
- all 4 check keys present in response

Also added MONITORING_PUBLIC env var (defaults true) and the new health
endpoints to PUBLIC_ROUTES so k8s probes can hit them without auth.
2026-06-10 20:35:27 -07:00
Hermes e40cb35011 Add MONITORING_PUBLIC env var to gate monitoring endpoints behind auth
CI / Test & Lint (push) Has been cancelled
CI / Security audit (push) Has been cancelled
By default /api/v1/monitoring/stats and /api/v1/health-checks/status are
public (current behavior, dashboard needs them pre-login). Users deploying
DashCaddy on the open internet can now set:

  MONITORING_PUBLIC=false

...or add 'monitoring: { public: false }' to config.json to require auth.
This prevents anonymous disclosure of CPU/memory/disk data.

The check uses env var first, then config.json, then defaults to true
(preserves current behavior for existing users).
2026-06-10 20:13:53 -07:00
Hermes 7485772427 Bump to v1.13.0 - config migration system
CI / Test & Lint (push) Has been cancelled
CI / Security audit (push) Has been cancelled
2026-06-10 20:06:46 -07:00
Hermes e5d7da6edd Add config migration system
CI / Test & Lint (push) Has been cancelled
CI / Security audit (push) Has been cancelled
When config.json schema changes between versions, register a migration
function in src/config/migrations.js. On startup, loadSiteConfig() detects
the stored version, runs all migrations forward, and writes the result back.
Users never see the migration — it runs silently and the rest of the app
only ever sees the current schema.

Includes:
- v0 → v1: normalize dns from string to object
- v1 → v2: add dns.provider field (default 'technitium')
- Forward compat: configs from future versions left untouched
- Idempotent: re-running on already-migrated config is a no-op
- Safe: no user data is removed during migration

21 unit tests covering edge cases: null input, forward compat, corrupt
JSON, missing parent dirs, idempotency, full migration chain.
2026-06-10 20:06:09 -07:00
Hermes 28f0fa3c10 Add /api/v1/version to PUBLIC_ROUTES
CI / Test & Lint (push) Has been cancelled
CI / Security audit (push) Has been cancelled
2026-06-10 19:55:19 -07:00
Hermes eee32c1eae Fix missing platform-paths import in routes/services.js
CI / Test & Lint (push) Has been cancelled
CI / Security audit (push) Has been cancelled
2026-06-10 19:47:52 -07:00
Hermes 37a3282f98 Bump to v1.12.0 - cross-platform standardization
CI / Test & Lint (push) Has been cancelled
CI / Security audit (push) Has been cancelled
2026-06-10 19:36:30 -07:00
Hermes 1fbe65f524 Standardize paths, add version endpoint, request timeouts, HOST env var, graceful shutdown
CI / Test & Lint (push) Has been cancelled
CI / Security audit (push) Has been cancelled
Cross-platform hardening — removes all hardcoded /app/ paths from route files
and routes them through platform-paths.js so the app works the same way
regardless of Docker layout (single-file mount vs consolidated data dir).

Changes:
- platform-paths.js: add generatedCertsDir, pkiDir, containerUpdatesDir,
  containerFrontendDir, containerAssetsDir, resolveAssetsPath()
- self-updater.js: UPDATE_URL/MIRROR_URL/CHANNEL env var overrides
- routes/ca.js: use platformPaths for cert paths and generated certs dir
- routes/services.js: use platformPaths.pkiRootCert
- routes/themes.js: derive THEMES_DIR from platformPaths.servicesFile
- routes/config/assets.js + backup.js: use resolveAssetsPath() fallback
- routes/services.js + src/app.js: use platformPaths.pkiRootCert
- server.js: HOST env var support, parse PORT as int
- src/app.js: GET /api/v1/version (public, no auth), global request timeout,
  disable x-powered-by, trust proxy
- pylon/dashcaddy-pylon.js: PYLON_HOST env var, graceful shutdown on SIGTERM/SIGINT

A fresh user can now deploy with a custom Docker layout (e.g. /opt/dc/data/
as a single volume mount) and the app finds its files automatically, no env
var configuration required.
2026-06-10 19:36:05 -07:00
Hermes 320f21c113 fix: credential-manager and crypto-utils auto-resolve data directory paths
CI / Test & Lint (push) Has been cancelled
CI / Security audit (push) Has been cancelled
The CREDENTIALS_FILE and ENCRYPTION_KEY_FILE env vars defaulted to
__dirname/credentials.json and __dirname/.encryption-key, which works
for the standard install (where individual files are mounted to /app/)
but breaks for deployments using a consolidated data directory at
/app/data/.

Add resolveCredentialsFile() and resolveKeyFile() helpers that:
1. Honor explicit env var if set
2. Check /app/credentials.json and /app/data/credentials.json
3. Check /app/.encryption-key and /app/data/.encryption-key
4. Default to standard path for new installs

This makes DashCaddy deployable with either pattern without requiring
custom env var configuration, which is essential for general-public
reproducibility.
2026-06-10 19:05:07 -07:00
Hermes 5c76c3df97 fix: System Overview widget - expose monitoring/health endpoints publicly + fix data formats
CI / Test & Lint (push) Has been cancelled
CI / Security audit (push) Has been cancelled
- Add /api/v1/monitoring/stats and /api/v1/health-checks/status to PUBLIC_ROUTES
  so the frontend widget can fetch without auth
- Transform monitoring stats response from nested {cpu:{percent}} to flat
  {cpu: number, memory: number, memoryUsage: number} for the widget
- Add summary {healthy, unhealthy, total} to health-checks/status response
2026-06-10 18:24:30 -07:00
Hermes 260575c6bd fix: wrap createContainer with user-friendly DC-201 error for missing images
CI / Test & Lint (push) Has been cancelled
CI / Security audit (push) Has been cancelled
2026-06-10 17:39:37 -07:00
Hermes e361d9a328 fix: increase pull timeout to 300s, add missing environment:{} to portainer + uptime-kuma templates
CI / Test & Lint (push) Has been cancelled
CI / Security audit (push) Has been cancelled
2026-06-10 17:05:28 -07:00
Hermes aa25bcc053 fix: always expose DC-prefixed errors to users in safeErrorMessage
CI / Test & Lint (push) Has been cancelled
CI / Security audit (push) Has been cancelled
2026-06-10 17:02:13 -07:00
Hermes bda08b592e fix: idempotent Caddy subpath config, increase Docker pull timeout to 120s, extend health check to 60s
CI / Test & Lint (push) Has been cancelled
CI / Security audit (push) Has been cancelled
- helpers.js: treat 'No changes to apply' as success (config already exists = idempotent)
- constants.js: Docker pull timeout 30s → 120s (large images need more time)
- deploy.js: health check 40s → 60s (some apps like filebrowser are slow to start)
2026-06-10 16:43:34 -07:00
Hermes 0e408974a0 fix: harden deploy error handling - guard against undefined errors, safeErrorMessage null check
CI / Test & Lint (push) Has been cancelled
CI / Security audit (push) Has been cancelled
- deploy.js: wrap logError/notification in try/catch so they never mask the original deploy error
- deploy.js: use optional chaining for error.message access
- logging.js: safeErrorMessage handles null/undefined error gracefully
2026-06-10 16:39:14 -07:00
Hermes f4b35dcc30 fix: correct apps route mount paths - mount all sub-routers at /apps prefix to match frontend API calls
CI / Test & Lint (push) Has been cancelled
CI / Security audit (push) Has been cancelled
2026-06-10 16:28:41 -07:00
Hermes 1c0d765182 fix: app route path nesting (deploy/remove/templates), server.js fetchT import, lifetime license expiry, workflows path prefix
CI / Test & Lint (push) Has been cancelled
CI / Security audit (push) Has been cancelled
- routes/apps/index.js: mount sub-routers at '/' to avoid double-nesting (was /deploy/deploy, now /deploy)
- server.js: add fetchT import for workflow engine init
- license-manager.js: fix isExpired() for lifetime licenses (null expiresAt → always expired)
- src/app.js: add '/workflows' path prefix to prevent requirePremium gating all routes
- app-templates.js: fix 10 templates missing volumes/healthCheck
- routes/apps/index.js: add e.stack to error logging for better debugging
2026-06-10 16:20:51 -07:00
Hermes 2cd62208ac fix: workflows route mounted without path prefix — blocked all API on free tier; fix 10 app templates missing fields 2026-06-10 15:40:00 -07:00
Hermes 7557a6364a ops: add host-side update script to repo, include dns-providers/ in backup/deploy/restore paths
CI / Test & Lint (push) Has been cancelled
CI / Security audit (push) Has been cancelled
2026-06-10 15:18:48 -07:00
Hermes 54c4b049a8 fix: include dns-providers/ in Docker image build 2026-06-10 15:11:14 -07:00
Hermes 2de72ed506 feat: DNS provider abstraction — Technitium, Cloudflare, RFC 2136, Manual
CI / Test & Lint (push) Has been cancelled
CI / Security audit (push) Has been cancelled
- dns-providers/: adapter base class + registry with auto-discovery
- technitium.js: wraps existing Technitium API calls into adapter interface
- cloudflare.js: Cloudflare API v4 adapter (zones, records, credentials)
- rfc2136.js: RFC 2136 dynamic DNS via nsupdate (BIND, PowerDNS, etc.)
- manual.js: no-op adapter for external DNS management with instructions
- provider-dns.js: provider-aware DNS context, resolves active adapter from config
- Universal helper methods: universalCreateRecord/Delete/ResolveRecord
- All 7 route files updated to use universal methods instead of raw dns.call()
- Setup wizard: provider dropdown (Technitium, Cloudflare, RFC 2136, Manual)
- DNS template selector: added Cloudflare and External/Manual options
- Config schema: validates dns.provider field
- Capability gating on Technitium-specific endpoints (logs, restart, update)
- Backward compatible: no provider set = auto-detect (technitium if dns.ip exists)
2026-06-10 15:06:41 -07:00
Hermes 0aa1c3d077 fix: correct module imports for SSLMonitor and DNSPropagationChecker
CI / Test & Lint (push) Has been cancelled
CI / Security audit (push) Has been cancelled
2026-06-10 14:45:34 -07:00
Hermes 954be9e868 feat: auto-restart policies, SSL monitoring, DNS propagation, dependency tracking, config drift detection
CI / Test & Lint (push) Has been cancelled
CI / Security audit (push) Has been cancelled
2026-06-10 14:43:46 -07:00
Hermes afcccf811e release: 1.8.0 — service categories, monitoring widgets, update UX, fail2ban watchdog
CI / Test & Lint (push) Has been cancelled
CI / Security audit (push) Has been cancelled
2026-06-10 12:52:13 -07:00
hermes 0aa7244cf4 infra: Samihost fail2ban watchdog (auto-unban trusted IPs, drift guard, cap at 200)
CI / Test & Lint (push) Has been cancelled
CI / Security audit (push) Has been cancelled
2026-06-10 11:28:42 -07:00
Hermes 1d8919532b feat: service categories end-to-end + monitoring widgets on main dashboard
CI / Test & Lint (push) Has been cancelled
CI / Security audit (push) Has been cancelled
Service categories (described in README roadmap, never wired):
- Backend: POST /services now persists category/containerId/port/ip/tailscaleOnly
- Backend: POST /services/update accepts category for in-place changes
- Frontend: category <select> in add-service modal (local + external)
- Frontend: category <select> in edit-service modal with current value
- Frontend: All Categories dropdown in service filter bar (auto-populated
  from both API categories and any categories present on rendered cards)
- Frontend: colored category badge (icon + name) on service cards
- Frontend: filter auto-refreshes after buildGrid

Monitoring on main dashboard (replaces orphaned monitoring-dashboard.html):
- New monitoring-widgets.js embeds a 5-card System Overview panel above
  the filter bar: Services, Containers Up, Avg CPU, Avg Memory, Health
- Pulls /api/v1/monitoring/stats + /api/v1/health-checks/status
- Auto-refreshes on DC.POLL.STATS (5s), color-coded bars (warn >=65%, bad >=85%)

Build:
- Added monitoring-widgets.js to init.js bundle in build.js
- Rebuilt dist/ bundles (core.js, features.js, init.js)
- sw.js cache version bumped automatically
- CSP hash regenerated
2026-06-10 01:49:27 -07:00
Hermes ea9bdf9598 Backup data/ dir before update, restore on rollback
- Add backup_data_dir() and restore_data_dir() using rsync
- Data backed up to backups/{version}/data-backup/ alongside code
- restore_data_dir() called in all three rollback paths (build fail, restart fail, health check fail)
- Add restart_container() that does rm + run to apply new env vars
- Handle action=rollback explicitly (no new version deployment)
- Uses standalone docker build instead of compose for reliability
- Add start.sh at /opt/dashcaddy/start.sh for reboot survival
2026-05-28 02:34:27 -07:00
Hermes c52016d727 fix: backup and restore data/ dir on update and rollback
The data/ directory (services.json, config.json, credentials,
TOTP config, notifications) was never included in the update
backup. Every update wiped user data — services, licenses,
credentials — requiring manual restore.

Now the host-side updater:
- Backs up data/ alongside code files before any update
- Restores data/ on rollback (build failure, restart failure,
  or health-check failure)
2026-05-28 02:08:33 -07:00
Hermes 588188edb5 update UX: badge→modal flow, orange update button, Update All, toast notifications, workflow triggers 2026-05-27 23:57:32 -07:00
Hermes 11823a1466 feat: premium tier features — auto-backup scheduling, resource alerting, bundled workflows, one-click revert, notification manager 2026-05-27 23:39:46 -07:00
104 changed files with 11597 additions and 1332 deletions
+1
View File
@@ -0,0 +1 @@
1.13.0
+1
View File
@@ -11,6 +11,7 @@ RUN npm install --production
COPY *.js ./
COPY src/ ./src/
COPY routes/ ./routes/
COPY dns-providers/ ./dns-providers/
COPY openapi.yaml ./
# VERSION file holds the short git SHA the image was built from. Committed as
+1 -1
View File
@@ -1 +1 @@
dev
1.13.0
@@ -0,0 +1,215 @@
/**
* Config migration tests
*
* These tests verify that a config file from any older version of DashCaddy
* gets correctly migrated to the current version. Migration MUST be:
* - Deterministic (same input always produces same output)
* - Idempotent (running migration on already-migrated config is a no-op)
* - Safe (no data loss; only adds fields, never removes user values)
* - Silent (no exceptions thrown for any version from 0 to CURRENT)
*/
const fs = require('fs');
const os = require('os');
const path = require('path');
const {
CURRENT_VERSION,
migrations,
migrate,
loadAndMigrate
} = require('../src/config/migrations');
describe('config/migrations', () => {
let tmpDir;
beforeEach(() => {
tmpDir = fs.mkdtempSync(path.join(os.tmpdir(), 'dc-mig-test-'));
});
afterEach(() => {
fs.rmSync(tmpDir, { recursive: true, force: true });
});
describe('migrate()', () => {
test('null/empty config returns fresh v_current', () => {
const result = migrate(null);
expect(result._version).toBe(CURRENT_VERSION);
});
test('undefined config returns fresh v_current', () => {
const result = migrate(undefined);
expect(result._version).toBe(CURRENT_VERSION);
});
test('v0 (no _version) migrates all the way to current', () => {
const v0 = { tld: '.home', customValue: 'preserved' };
const result = migrate(v0);
expect(result._version).toBe(CURRENT_VERSION);
// User data must be preserved
expect(result.tld).toBe('.home');
expect(result.customValue).toBe('preserved');
});
test('each intermediate version migrates forward to current', () => {
for (let v = 0; v < CURRENT_VERSION; v++) {
const config = { _version: v, tld: '.test' };
const result = migrate(config);
// Final version is always CURRENT_VERSION after running all migrations
expect(result._version).toBe(CURRENT_VERSION);
// User data preserved
expect(result.tld).toBe('.test');
}
});
test('config at current version passes through unchanged', () => {
const current = { _version: CURRENT_VERSION, tld: '.home', customField: 'kept' };
const result = migrate(current);
expect(result).toEqual(current);
});
test('config from FUTURE version is left alone (forward compat)', () => {
const future = { _version: 999, tld: '.home', newField: 'unknown' };
const result = migrate(future);
// We don't touch future configs — let validation catch issues
expect(result._version).toBe(999);
expect(result.newField).toBe('unknown');
});
});
describe('v0 → v1 migration: dns normalization', () => {
test('string dns gets converted to object', () => {
const result = migrations[1]({ dns: '192.168.1.1' });
expect(result.dns).toEqual({ ip: '192.168.1.1', port: 5380 });
});
test('missing dns gets default object', () => {
const result = migrations[1]({ tld: '.home' });
expect(result.dns).toEqual({ ip: '', port: 5380 });
});
test('object dns passes through unchanged', () => {
const result = migrations[1]({ dns: { ip: '10.0.0.1', port: 5380, custom: 'kept' } });
expect(result.dns.ip).toBe('10.0.0.1');
expect(result.dns.custom).toBe('kept');
});
test('_version is set to 1', () => {
const result = migrations[1]({ tld: '.home' });
expect(result._version).toBe(1);
});
});
describe('v1 → v2 migration: dns.provider field', () => {
test('adds provider: technitium default', () => {
const result = migrations[2]({ dns: { ip: '10.0.0.1', port: 5380 }, _version: 1 });
expect(result.dns.provider).toBe('technitium');
expect(result.dns.ip).toBe('10.0.0.1');
expect(result.dns.port).toBe(5380);
});
test('respects existing provider if set', () => {
const result = migrations[2]({ dns: { provider: 'cloudflare', ip: 'cf' }, _version: 1 });
expect(result.dns.provider).toBe('cloudflare');
});
test('_version is set to 2', () => {
const result = migrations[2]({ _version: 1 });
expect(result._version).toBe(2);
});
});
describe('loadAndMigrate()', () => {
test('creates fresh config when file does not exist', () => {
const configFile = path.join(tmpDir, 'config.json');
const result = loadAndMigrate(configFile, null);
expect(result._version).toBe(CURRENT_VERSION);
// Should NOT write a file when there was nothing to migrate
expect(fs.existsSync(configFile)).toBe(false);
});
test('migrates old config and writes back to disk', () => {
const configFile = path.join(tmpDir, 'config.json');
// Write an unversioned config (v0)
fs.writeFileSync(configFile, JSON.stringify({ tld: '.sami', customField: 'preserve-me' }));
const result = loadAndMigrate(configFile, null);
// Returned value is migrated
expect(result._version).toBe(CURRENT_VERSION);
expect(result.tld).toBe('.sami');
expect(result.customField).toBe('preserve-me');
// File on disk is updated
const written = JSON.parse(fs.readFileSync(configFile, 'utf8'));
expect(written._version).toBe(CURRENT_VERSION);
expect(written.tld).toBe('.sami');
});
test('does not rewrite file when already at current version', () => {
const configFile = path.join(tmpDir, 'config.json');
const original = JSON.stringify({ _version: CURRENT_VERSION, tld: '.home' }, null, 2);
fs.writeFileSync(configFile, original);
// Record mtime before
const mtimeBefore = fs.statSync(configFile).mtimeMs;
// Wait a tick
const start = Date.now();
while (Date.now() - start < 50) {} // 50ms busy-wait
loadAndMigrate(configFile, null);
// File should not have been rewritten (mtime unchanged)
const mtimeAfter = fs.statSync(configFile).mtimeMs;
expect(mtimeAfter).toBe(mtimeBefore);
});
test('handles corrupt JSON gracefully (returns defaults, no crash)', () => {
const configFile = path.join(tmpDir, 'config.json');
fs.writeFileSync(configFile, '{ this is not valid json');
// Should not throw
const result = loadAndMigrate(configFile, null);
expect(result._version).toBe(CURRENT_VERSION);
});
test('creates parent directory if missing', () => {
const nested = path.join(tmpDir, 'nested', 'subdir', 'config.json');
// Pre-create parent dirs (test setup)
fs.mkdirSync(path.dirname(nested), { recursive: true });
fs.writeFileSync(nested, JSON.stringify({ tld: '.home' }));
const result = loadAndMigrate(nested, null);
expect(result._version).toBe(CURRENT_VERSION);
});
test('full chain: v0 file with string dns becomes v2 with provider', () => {
const configFile = path.join(tmpDir, 'config.json');
fs.writeFileSync(configFile, JSON.stringify({
tld: '.sami',
dns: '10.0.0.1'
}));
const result = loadAndMigrate(configFile, null);
expect(result._version).toBe(CURRENT_VERSION);
// After full chain, dns is normalized to object AND has provider
expect(result.dns.ip).toBe('10.0.0.1');
expect(result.dns.port).toBe(5380);
expect(result.dns.provider).toBe('technitium');
});
});
describe('idempotency', () => {
test('running migration twice produces same result', () => {
const v0 = { tld: '.home', customField: 'x' };
const first = migrate(v0);
const second = migrate(first);
expect(second).toEqual(first);
});
test('loadAndMigrate is idempotent across reloads', () => {
const configFile = path.join(tmpDir, 'config.json');
fs.writeFileSync(configFile, JSON.stringify({ tld: '.home' }));
const first = loadAndMigrate(configFile, null);
const second = loadAndMigrate(configFile, null);
expect(second).toEqual(first);
});
});
});
+13 -20
View File
@@ -1,8 +1,18 @@
jest.mock('../error-logger', () => ({
logError: jest.fn(),
// Mock the unified logging module so we can verify logError is called
// without writing to the actual error.log file
jest.mock('../src/utils/logging', () => ({
logError: jest.fn().mockResolvedValue(),
safeErrorMessage: jest.fn((err) => {
if (!err) return 'An internal error occurred';
return err.message || String(err);
}),
createLogger: jest.fn(() => ({
info: jest.fn(), warn: jest.fn(), error: jest.fn(), debug: jest.fn()
})),
LOG_LEVELS: { debug: 0, info: 1, warn: 2, error: 3 }
}));
const { asyncHandler, errorMiddleware, notFoundHandler } = require('../error-handler');
const { errorMiddleware, notFoundHandler } = require('../error-handler');
const {
AppError,
ValidationError,
@@ -30,23 +40,6 @@ describe('Error Handler', () => {
next = jest.fn();
});
describe('asyncHandler', () => {
it('calls the wrapped function', async () => {
const fn = jest.fn().mockResolvedValue();
const wrapped = asyncHandler(fn);
await wrapped(req, res, next);
expect(fn).toHaveBeenCalledWith(req, res, next);
});
it('calls next(err) on rejected promise', async () => {
const error = new Error('async fail');
const fn = jest.fn().mockRejectedValue(error);
const wrapped = asyncHandler(fn);
await wrapped(req, res, next);
expect(next).toHaveBeenCalledWith(error);
});
});
describe('errorMiddleware', () => {
it('returns 400 for ValidationError', () => {
const err = new ValidationError('bad input', 'email');
@@ -0,0 +1,201 @@
/**
* Health endpoint tests
*
* Verifies:
* - /health/live always returns 200
* - /health/ready returns 200 with valid structure when all deps OK
* - /health/ready returns 503 when a critical dep is down
* - /health/ready does NOT crash with "res.status is not a function"
*/
const express = require('express');
const request = require('supertest');
// Mock dockerode BEFORE anything else
jest.mock('dockerode', () => {
return jest.fn().mockImplementation(() => ({
ping: jest.fn().mockImplementation(() => {
if (process.env.MOCK_DOCKER_DOWN === '1') {
return Promise.reject(new Error('docker unreachable'));
}
return Promise.resolve('OK');
})
}));
});
// Build a minimal Express app with the same health handlers as src/app.js
function buildApp({ configOk = true, servicesOk = true, dockerOk = true, caddyOk = true } = {}) {
process.env.MOCK_DOCKER_DOWN = dockerOk ? '0' : '1';
const app = express();
const config = {
CONFIG_FILE: '/tmp/dc-test-config.json',
SERVICES_FILE: '/tmp/dc-test-services.json',
CADDY_ADMIN_URL: 'http://localhost:2019'
};
// Mock fs
const fs = require('fs');
const realExistsSync = fs.existsSync;
const realReadFileSync = fs.readFileSync;
fs.existsSync = (p) => {
if (p === config.CONFIG_FILE) return configOk;
if (p === config.SERVICES_FILE) return servicesOk;
return realExistsSync(p);
};
fs.readFileSync = (p, ...args) => {
if (p === config.CONFIG_FILE) {
if (!configOk) throw new Error('config not found');
return '{}';
}
if (p === config.SERVICES_FILE) {
if (!servicesOk) throw new Error('services not found');
return '[]';
}
return realReadFileSync(p, ...args);
};
// /health/live (matches src/app.js exactly)
app.get('/health/live', (req, res) => {
res.json({ status: 'alive', uptime: process.uptime() });
});
// /health/ready (matches src/app.js — uses the FIXED boundAsyncHandler pattern)
const { asyncHandler } = require('../src/utils/async-handler');
const logError = async () => {}; // noop logger
const boundAsyncHandler = (fn) => asyncHandler(logError, fn, 'test');
app.get('/health/ready', boundAsyncHandler(async (req, res) => {
const checks = {};
let allOk = true;
try {
if (fs.existsSync(config.CONFIG_FILE)) {
fs.readFileSync(config.CONFIG_FILE, 'utf8');
checks.configFile = { ok: true };
} else {
checks.configFile = { ok: false, error: 'Config file not found' };
allOk = false;
}
} catch (e) {
checks.configFile = { ok: false, error: e.message };
allOk = false;
}
try {
if (fs.existsSync(config.SERVICES_FILE)) {
fs.readFileSync(config.SERVICES_FILE, 'utf8');
checks.servicesFile = { ok: true };
} else {
checks.servicesFile = { ok: false, error: 'Services file not found' };
allOk = false;
}
} catch (e) {
checks.servicesFile = { ok: false, error: e.message };
allOk = false;
}
try {
const docker = require('dockerode')();
await docker.ping();
checks.docker = { ok: true };
} catch (e) {
checks.docker = { ok: false, error: e.message };
allOk = false;
}
try {
const caddyUrl = config.CADDY_ADMIN_URL || 'http://localhost:2019';
const controller = new AbortController();
const timeout = setTimeout(() => controller.abort(), 3000);
const response = await fetch(`${caddyUrl}/config/`, { signal: controller.signal });
clearTimeout(timeout);
checks.caddy = { ok: response.ok, status: response.status };
if (!response.ok) allOk = false;
} catch (e) {
checks.caddy = { ok: false, error: e.message };
allOk = false;
}
const body = {
status: allOk ? 'ready' : 'not-ready',
timestamp: new Date().toISOString(),
checks
};
res.status(allOk ? 200 : 503).json(body);
}));
return app;
}
describe('Health Endpoints', () => {
beforeEach(() => {
delete process.env.MOCK_DOCKER_DOWN;
});
describe('GET /health/live', () => {
it('always returns 200 with status: alive', async () => {
const app = buildApp();
const res = await request(app).get('/health/live');
expect(res.status).toBe(200);
expect(res.body.status).toBe('alive');
expect(typeof res.body.uptime).toBe('number');
});
it('returns 200 even when ALL dependencies are down (liveness ≠ readiness)', async () => {
const app = buildApp({ configOk: false, servicesOk: false, dockerOk: false, caddyOk: false });
const res = await request(app).get('/health/live');
expect(res.status).toBe(200);
});
});
describe('GET /health/ready', () => {
it('returns 200 when all dependencies are OK (excluding caddy which may 403 in sandbox)', async () => {
const app = buildApp();
const res = await request(app).get('/health/ready');
// config + services + docker should all be OK
expect(res.body.checks.configFile.ok).toBe(true);
expect(res.body.checks.servicesFile.ok).toBe(true);
expect(res.body.checks.docker.ok).toBe(true);
// caddy is tested in sandbox — may be 403 or 200
expect(res.body).toHaveProperty('checks');
expect(res.body).toHaveProperty('status');
});
it('returns 503 when config file is missing', async () => {
const app = buildApp({ configOk: false });
const res = await request(app).get('/health/ready');
expect(res.status).toBe(503);
expect(res.body.status).toBe('not-ready');
expect(res.body.checks.configFile.ok).toBe(false);
});
it('returns 503 when services file is missing', async () => {
const app = buildApp({ servicesOk: false });
const res = await request(app).get('/health/ready');
expect(res.status).toBe(503);
expect(res.body.checks.servicesFile.ok).toBe(false);
});
it('returns 503 when Docker is unreachable', async () => {
const app = buildApp({ dockerOk: false });
const res = await request(app).get('/health/ready');
expect(res.status).toBe(503);
expect(res.body.checks.docker.ok).toBe(false);
});
it('does NOT crash with "res.status is not a function" when dependencies fail', async () => {
const app = buildApp({ dockerOk: false });
const res = await request(app).get('/health/ready');
const bodyStr = JSON.stringify(res.body);
expect(bodyStr).not.toMatch(/res\.status is not a function/);
// Should always be a valid response object
expect(res.body).toHaveProperty('checks');
});
it('responds with all 4 expected check keys', async () => {
const app = buildApp();
const res = await request(app).get('/health/ready');
expect(Object.keys(res.body.checks).sort()).toEqual(['caddy', 'configFile', 'docker', 'servicesFile']);
});
});
});
@@ -538,7 +538,7 @@ describe('Health Routes', () => {
const { app } = createApp();
const res = await request(app).get('/api/health/ca');
expect(res.status).toBe(200);
expect(res.body.status).toBe('healthy');
expect(res.body.caStatus).toBe('healthy');
expect(res.body.daysUntilExpiration).toBeGreaterThan(90);
});
@@ -551,7 +551,7 @@ describe('Health Routes', () => {
const { app } = createApp();
const res = await request(app).get('/api/health/ca');
expect(res.status).toBe(200);
expect(res.body.status).toBe('warning');
expect(res.body.caStatus).toBe('warning');
expect(res.body.daysUntilExpiration).toBeLessThan(90);
expect(res.body.daysUntilExpiration).toBeGreaterThanOrEqual(30);
});
@@ -565,7 +565,7 @@ describe('Health Routes', () => {
const { app } = createApp();
const res = await request(app).get('/api/health/ca');
expect(res.status).toBe(200);
expect(res.body.status).toBe('critical');
expect(res.body.caStatus).toBe('critical');
expect(res.body.daysUntilExpiration).toBeLessThan(30);
expect(res.body.daysUntilExpiration).toBeGreaterThanOrEqual(0);
});
@@ -579,7 +579,7 @@ describe('Health Routes', () => {
const { app } = createApp();
const res = await request(app).get('/api/health/ca');
expect(res.status).toBe(200);
expect(res.body.status).toBe('critical');
expect(res.body.caStatus).toBe('critical');
expect(res.body.daysUntilExpiration).toBeLessThan(7);
});
@@ -592,7 +592,7 @@ describe('Health Routes', () => {
const { app } = createApp();
const res = await request(app).get('/api/health/ca');
expect(res.status).toBe(200);
expect(res.body.status).toBe('critical');
expect(res.body.caStatus).toBe('critical');
expect(res.body.daysUntilExpiration).toBeLessThan(0);
expect(res.body.message).toMatch(/EXPIRED/);
});
@@ -601,9 +601,9 @@ describe('Health Routes', () => {
exists.mockResolvedValue(false);
const { app } = createApp();
const res = await request(app).get('/api/health/ca');
expect(res.status).toBe(200);
expect(res.body.status).toBe('error');
expect(res.body.message).toMatch(/not found/);
expect(res.status).toBe(404);
expect(res.body.caStatus).toBe('error');
expect(res.body.error).toMatch(/not found/);
expect(res.body.daysUntilExpiration).toBeNull();
});
@@ -612,9 +612,9 @@ describe('Health Routes', () => {
execSync.mockImplementation(() => { throw new Error('openssl not found'); });
const { app } = createApp();
const res = await request(app).get('/api/health/ca');
expect(res.status).toBe(200);
expect(res.body.status).toBe('error');
expect(res.body.message).toBe('openssl not found');
expect(res.status).toBe(500);
expect(res.body.caStatus).toBe('error');
expect(res.body.error).toBe('openssl not found');
expect(res.body.daysUntilExpiration).toBeNull();
});
});
@@ -34,7 +34,7 @@ jest.mock('../../pagination', () => ({
parsePaginationParams: jest.fn(() => null),
}));
jest.mock('../../response-helpers', () => ({
jest.mock('../../src/utils/responses', () => ({
success: jest.fn((res, data, statusCode = 200) => {
return res.status(statusCode).json({ success: true, ...data });
}),
+23 -11
View File
@@ -342,7 +342,8 @@ const APP_TEMPLATES = {
volumes: [
"/var/run/docker.sock:/var/run/docker.sock",
"/opt/portainer/data:/data"
]
],
environment: {}
},
subdomain: "portainer",
defaultPort: 9000,
@@ -393,7 +394,8 @@ const APP_TEMPLATES = {
docker: {
image: "louislam/uptime-kuma:latest",
ports: ["{{PORT}}:3001"],
volumes: ["/opt/uptime-kuma:/app/data"]
volumes: ["/opt/uptime-kuma:/app/data"],
environment: {}
},
subdomain: "uptime",
defaultPort: 3002,
@@ -549,7 +551,7 @@ const APP_TEMPLATES = {
},
subdomain: "dns2",
defaultPort: 953,
healthCheck: null,
healthCheck: "tcp://localhost:53",
subpathSupport: 'strip',
setupInstructions: [
"Configure zone files in /opt/bind9/config/",
@@ -640,14 +642,14 @@ const APP_TEMPLATES = {
],
docker: {
image: "coredns/coredns:latest",
ports: ["53:53", "53:53/udp"],
ports: ["{{PORT}}:53", "53:53", "53:53/udp"],
volumes: ["/opt/coredns/config:/etc/coredns"],
environment: {},
command: ["-conf", "/etc/coredns/Corefile"]
},
subdomain: "dns4",
defaultPort: 53,
healthCheck: null,
healthCheck: "tcp://localhost:53",
subpathSupport: 'strip',
setupInstructions: [
"Create Corefile in /opt/coredns/config/",
@@ -1007,7 +1009,9 @@ const APP_TEMPLATES = {
docker: {
image: "adminer:latest",
ports: ["{{PORT}}:8080"],
volumes: [],
volumes: [
"/opt/adminer:/var/www/html"
],
environment: {
"ADMINER_DEFAULT_SERVER": "postgres"
}
@@ -1099,6 +1103,7 @@ const APP_TEMPLATES = {
popularity: 85,
difficulty: "Easy",
isDashboardWidget: true,
isStaticSite: true,
widgetSelector: ".weather-widget-container",
subdomain: null,
defaultPort: null,
@@ -1126,6 +1131,7 @@ const APP_TEMPLATES = {
popularity: 80,
difficulty: "Easy",
isDashboardWidget: true,
isStaticSite: true,
widgetSelector: ".clock-widget-container",
subdomain: null,
defaultPort: null,
@@ -1908,7 +1914,9 @@ const APP_TEMPLATES = {
docker: {
image: "traefik/whoami:latest",
ports: ["{{PORT}}:80"],
volumes: [],
volumes: [
"/opt/whoami/config:/config"
],
environment: {}
},
subdomain: "whoami",
@@ -2233,7 +2241,9 @@ const APP_TEMPLATES = {
docker: {
image: "excalidraw/excalidraw:latest",
ports: ["{{PORT}}:80"],
volumes: [],
volumes: [
"/opt/excalidraw/data:/var/lib/excalidraw"
],
environment: {}
},
subdomain: "draw",
@@ -2258,7 +2268,9 @@ const APP_TEMPLATES = {
docker: {
image: "corentinth/it-tools:latest",
ports: ["{{PORT}}:80"],
volumes: [],
volumes: [
"/opt/it-tools/config:/config"
],
environment: {}
},
subdomain: "tools",
@@ -2417,7 +2429,7 @@ const APP_TEMPLATES = {
},
subdomain: "mc",
defaultPort: 25565,
healthCheck: null,
healthCheck: "tcp://localhost:25565",
subpathSupport: 'none',
setupInstructions: [
"Server accepts the Minecraft EULA automatically",
@@ -2451,7 +2463,7 @@ const APP_TEMPLATES = {
},
subdomain: "valheim",
defaultPort: 2456,
healthCheck: null,
healthCheck: "tcp://localhost:2456",
subpathSupport: 'none',
setupInstructions: [
"Connect via Steam: Add Server > IP:2456",
+503
View File
@@ -0,0 +1,503 @@
/**
* Auto-Restart Manager - Per-container restart policies with retry tracking
*
* When a container goes down, attempts automatic restart up to N times
* (configurable per-service). Sends notifications on each attempt and
* when max retries are exceeded. Integrates with HealthChecker events.
*
* @module auto-restart-manager
*/
const EventEmitter = require('events');
const path = require('path');
const { readJsonFile, writeJsonFile } = require('./fs-helpers');
/**
* Default policy values applied when a new policy is created.
* @readonly
*/
const DEFAULT_POLICY = {
enabled: true,
maxRetries: 3,
retryIntervalMs: 5000,
windowMinutes: 10,
currentRetries: 0,
lastRestartAt: null,
cooldownUntil: null,
};
/**
* Manages automatic container restart policies and execution.
*
* @extends EventEmitter
*
* @fires AutoRestartManager#auto-restart-attempt
* @fires AutoRestartManager#auto-restart-success
* @fires AutoRestartManager#auto-restart-failed
* @fires AutoRestartManager#auto-restart-max-reached
*/
class AutoRestartManager extends EventEmitter {
/**
* @param {Object} ctx - Shared application context
* @param {Object} ctx.docker - Docker client wrapper ({ client: Dockerode })
* @param {Object} ctx.healthChecker - HealthChecker singleton
* @param {Object} ctx.notification - NotificationManager instance
* @param {Object} ctx.log - Logger instance
* @param {Function} ctx.logError - Error logging function
* @param {string} ctx.SERVICES_FILE - Path to services.json (used to derive data dir)
*/
constructor(ctx) {
super();
this.ctx = ctx;
this.log = ctx.log || console;
this.logError = ctx.logError || ((_ctx, err) => console.error(err));
this.docker = ctx.docker;
this.healthChecker = ctx.healthChecker;
this.notification = ctx.notification;
/** @type {Map<string, Object>} serviceId -> policy */
this.policies = new Map();
/** Path to the JSON file that persists policies */
this.policiesFile = path.join(path.dirname(ctx.SERVICES_FILE), 'auto-restart-policies.json');
/** Track previous health status per service for transition detection */
this._previousHealth = new Map();
/** Bound handlers so we can remove them on stop() */
this._onStatusCheck = this._handleStatusCheck.bind(this);
this._started = false;
}
// ─── Lifecycle ────────────────────────────────────────────────────────
/**
* Load persisted policies, then wire into HealthChecker events.
* @returns {Promise<void>}
*/
async start() {
if (this._started) return;
// Load persisted policies from disk
try {
const data = await readJsonFile(this.policiesFile, {});
for (const [serviceId, policy] of Object.entries(data)) {
this.policies.set(serviceId, { ...DEFAULT_POLICY, ...policy });
}
this.log.info('auto-restart', 'Policies loaded', { count: this.policies.size });
} catch (err) {
this.log.error('auto-restart', 'Failed to load policies', { error: err.message });
}
// Listen to health checker status transitions
if (this.healthChecker) {
this.healthChecker.on('status-check', this._onStatusCheck);
}
this._started = true;
this.log.info('auto-restart', 'Manager started');
}
/**
* Remove event listeners and stop processing health events.
*/
stop() {
if (!this._started) return;
if (this.healthChecker) {
this.healthChecker.removeListener('status-check', this._onStatusCheck);
}
this._started = false;
this.log.info('auto-restart', 'Manager stopped');
}
// ─── Policy CRUD ─────────────────────────────────────────────────────
/**
* Create or update a restart policy for a service.
*
* @param {string} serviceId - Unique service identifier
* @param {Object} policy - Partial policy fields to merge
* @param {boolean} [policy.enabled=true]
* @param {number} [policy.maxRetries=3]
* @param {number} [policy.retryIntervalMs=5000]
* @param {number} [policy.windowMinutes=10]
* @returns {Promise<Object>} The resulting policy
* @throws {Error} If serviceId is invalid
*/
async setPolicy(serviceId, policy) {
if (!serviceId || typeof serviceId !== 'string') {
throw new Error('serviceId is required');
}
const existing = this.policies.get(serviceId) || { ...DEFAULT_POLICY, serviceId };
const merged = {
...existing,
...policy,
serviceId,
// Never allow caller to override runtime counters directly
currentRetries: existing.currentRetries || 0,
lastRestartAt: existing.lastRestartAt,
cooldownUntil: existing.cooldownUntil,
};
this.policies.set(serviceId, merged);
await this._savePolicies();
this.log.info('auto-restart', 'Policy set', { serviceId, enabled: merged.enabled });
return { ...merged };
}
/**
* Retrieve the policy for a service.
*
* @param {string} serviceId
* @returns {Object|null} Policy object or null if none exists
*/
getPolicy(serviceId) {
const policy = this.policies.get(serviceId);
return policy ? { ...policy } : null;
}
/**
* Return all policies as an array.
* @returns {Object[]}
*/
listPolicies() {
return Array.from(this.policies.values()).map(p => ({ ...p }));
}
/**
* Remove a service's restart policy.
*
* @param {string} serviceId
* @returns {Promise<boolean>} true if a policy was removed
*/
async removePolicy(serviceId) {
if (!this.policies.has(serviceId)) return false;
this.policies.delete(serviceId);
await this._savePolicies();
this.log.info('auto-restart', 'Policy removed', { serviceId });
return true;
}
// ─── Core Restart Logic ──────────────────────────────────────────────
/**
* Called when a container is detected as down.
*
* Checks policy, cooldown, and retry count, then either attempts a
* Docker restart or notifies that max retries were exceeded.
*
* @param {string} serviceId - Service identifier
* @param {string} containerId - Docker container ID to restart
* @returns {Promise<Object>} Result of the operation
*/
async handleContainerDown(serviceId, containerId) {
const policy = this.policies.get(serviceId);
if (!policy) {
return { action: 'ignored', reason: 'no-policy' };
}
if (!policy.enabled) {
return { action: 'ignored', reason: 'disabled' };
}
// Check cooldown window
const now = Date.now();
if (policy.cooldownUntil && now < policy.cooldownUntil) {
this.log.info('auto-restart', 'Skipping — cooldown active', {
serviceId,
cooldownUntil: new Date(policy.cooldownUntil).toISOString(),
});
return { action: 'skipped', reason: 'cooldown' };
}
// Max retries exceeded — notify and enter cooldown
if (policy.currentRetries >= policy.maxRetries) {
const cooldownMs = policy.windowMinutes * 60 * 1000;
policy.cooldownUntil = now + cooldownMs;
policy.currentRetries = 0; // Reset so next window can try again
await this._savePolicies();
const eventData = {
serviceId,
containerId,
maxRetries: policy.maxRetries,
cooldownUntil: policy.cooldownUntil,
timestamp: new Date().toISOString(),
};
/**
* @event AutoRestartManager#auto-restart-max-reached
* @type {Object}
*/
this.emit('auto-restart-max-reached', eventData);
// Send notification
try {
await this._notify('auto-restart', {
containerName: serviceId,
message: `⛔ Max auto-restart retries (${policy.maxRetries}) exceeded for "${serviceId}". Cooldown until ${new Date(policy.cooldownUntil).toISOString()}.`,
...eventData,
});
} catch (notifErr) {
this.log.error('auto-restart', 'Notification failed', { error: notifErr.message });
}
return { action: 'max-reached', ...eventData };
}
// Wait for the configured retry interval before attempting
if (policy.retryIntervalMs > 0 && policy.lastRestartAt) {
const elapsed = now - new Date(policy.lastRestartAt).getTime();
if (elapsed < policy.retryIntervalMs) {
const waitMs = policy.retryIntervalMs - elapsed;
this.log.info('auto-restart', 'Waiting for retry interval', { serviceId, waitMs });
await new Promise(resolve => setTimeout(resolve, waitMs));
}
}
// Attempt restart
policy.currentRetries += 1;
const attemptNum = policy.currentRetries;
const maxRetries = policy.maxRetries;
/**
* @event AutoRestartManager#auto-restart-attempt
* @type {Object}
*/
this.emit('auto-restart-attempt', {
serviceId,
containerId,
attempt: attemptNum,
maxRetries,
timestamp: new Date().toISOString(),
});
try {
if (!this.docker?.client) {
throw new Error('Docker client not available');
}
const container = this.docker.client.getContainer(containerId);
await container.start();
policy.lastRestartAt = new Date().toISOString();
await this._savePolicies();
const successData = {
serviceId,
containerId,
attempt: attemptNum,
maxRetries,
timestamp: new Date().toISOString(),
};
/**
* @event AutoRestartManager#auto-restart-success
* @type {Object}
*/
this.emit('auto-restart-success', successData);
// Notify
try {
await this._notify('auto-restart', {
containerName: serviceId,
message: `🔄 Auto-restart attempt ${attemptNum}/${maxRetries} succeeded for "${serviceId}".`,
...successData,
});
} catch (notifErr) {
this.log.error('auto-restart', 'Notification failed', { error: notifErr.message });
}
this.log.info('auto-restart', 'Container restarted', {
serviceId,
attempt: attemptNum,
maxRetries,
});
return { action: 'restarted', ...successData };
} catch (restartErr) {
policy.lastRestartAt = new Date().toISOString();
await this._savePolicies();
const failData = {
serviceId,
containerId,
attempt: attemptNum,
maxRetries,
error: restartErr.message,
timestamp: new Date().toISOString(),
};
/**
* @event AutoRestartManager#auto-restart-failed
* @type {Object}
*/
this.emit('auto-restart-failed', failData);
// Notify
try {
await this._notify('auto-restart', {
containerName: serviceId,
message: `❌ Auto-restart attempt ${attemptNum}/${maxRetries} failed for "${serviceId}": ${restartErr.message}`,
...failData,
});
} catch (notifErr) {
this.log.error('auto-restart', 'Notification failed', { error: notifErr.message });
}
this.log.error('auto-restart', 'Restart failed', {
serviceId,
attempt: attemptNum,
error: restartErr.message,
});
return { action: 'failed', ...failData };
}
}
/**
* Called when a container recovers to healthy state.
* Resets the retry counter for the associated service.
*
* @param {string} serviceId
* @returns {Promise<void>}
*/
async handleContainerUp(serviceId) {
const policy = this.policies.get(serviceId);
if (!policy) return;
if (policy.currentRetries > 0) {
policy.currentRetries = 0;
policy.cooldownUntil = null;
await this._savePolicies();
this.log.info('auto-restart', 'Retries reset after recovery', { serviceId });
}
}
// ─── Health Event Bridge ─────────────────────────────────────────────
/**
* Internal handler for HealthChecker `status-check` events.
* Detects healthy→unhealthy and unhealthy→healthy transitions for tracked services.
*
* @param {Object} status - HealthChecker status object
* @param {string} status.serviceId
* @param {string} status.status - "up" or "down"
* @private
*/
async _handleStatusCheck(status) {
const { serviceId, status: currentStatus } = status;
if (!serviceId) return;
// Only process services that have a restart policy
if (!this.policies.has(serviceId)) return;
const previousStatus = this._previousHealth.get(serviceId);
this._previousHealth.set(serviceId, currentStatus);
// Transition: healthy → unhealthy
if (previousStatus === 'up' && currentStatus === 'down') {
// Find the containerId from the health checker config or status details
const containerId = this._resolveContainerId(serviceId, status);
if (containerId) {
try {
await this.handleContainerDown(serviceId, containerId);
} catch (err) {
this.logError('auto-restart-health-bridge', err);
}
}
}
// Transition: unhealthy → healthy (recovery)
if (previousStatus === 'down' && currentStatus === 'up') {
try {
await this.handleContainerUp(serviceId);
} catch (err) {
this.logError('auto-restart-health-bridge', err);
}
}
}
/**
* Attempt to find the containerId for a service from various sources.
*
* @param {string} serviceId
* @param {Object} status - The status-check event data
* @returns {string|null}
* @private
*/
_resolveContainerId(serviceId, status) {
// Check if it's in the status details (some health checks embed it)
if (status.details?.containerId) return status.details.containerId;
// Look in the health checker config
const hcService = this.healthChecker?.config?.services?.[serviceId];
if (hcService?.containerId) return hcService.containerId;
// Try to look it up from the services state manager
try {
const servicesStateManager = this.ctx.servicesStateManager;
if (servicesStateManager) {
const readResult = servicesStateManager.read();
if (readResult && typeof readResult.then === 'function') {
// It returns a promise — fire-and-forget lookup
readResult.then(list => {
const found = (list || []).find(s => s.id === serviceId);
return found?.containerId || null;
}).catch(() => null);
} else {
const found = (readResult || []).find(s => s.id === serviceId);
if (found?.containerId) return found.containerId;
}
}
} catch (_) { /* best effort */ }
return null;
}
// ─── Persistence ─────────────────────────────────────────────────────
/**
* Persist current policies to disk.
* @returns {Promise<void>}
* @private
*/
async _savePolicies() {
try {
const obj = {};
for (const [serviceId, policy] of this.policies.entries()) {
obj[serviceId] = { ...policy };
}
await writeJsonFile(this.policiesFile, obj);
} catch (err) {
this.log.error('auto-restart', 'Failed to save policies', { error: err.message });
}
}
// ─── Helpers ─────────────────────────────────────────────────────────
/**
* Send a notification via the notification manager.
*
* @param {string} event - Event type (e.g. 'auto-restart')
* @param {Object} data - Notification payload
* @returns {Promise<Object>}
* @private
*/
async _notify(event, data) {
if (this.notification?.send) {
return this.notification.send(event, data);
}
return { success: false, reason: 'no-notification-manager' };
}
}
module.exports = { AutoRestartManager, DEFAULT_POLICY };
+24 -1
View File
@@ -20,6 +20,14 @@ class BackupManager extends EventEmitter {
this.history = this.loadHistory();
this.scheduledJobs = new Map();
this.running = false;
this.notificationManager = null;
}
/**
* Set the notification manager for sending backup notifications
*/
setNotificationManager(nm) {
this.notificationManager = nm;
}
/**
@@ -177,6 +185,14 @@ class BackupManager extends EventEmitter {
}
this.emit('backup-complete', historyEntry);
// Send notification if manager is configured
if (this.notificationManager) {
this.notificationManager.sendBackupComplete(historyEntry).catch(err => {
console.error('[BackupManager] Failed to send backup-complete notification:', err.message);
});
}
console.log(`[BackupManager] Backup ${name} completed in ${duration}ms`);
return historyEntry;
@@ -193,7 +209,14 @@ class BackupManager extends EventEmitter {
this.addToHistory(historyEntry);
this.emit('backup-failed', historyEntry);
// Send notification if manager is configured
if (this.notificationManager) {
this.notificationManager.sendBackupFailed(historyEntry).catch(err => {
console.error('[BackupManager] Failed to send backup-failed notification:', err.message);
});
}
throw error;
}
}
+575
View File
@@ -0,0 +1,575 @@
/**
* Bundled Workflows - Pre-configured automation templates
*
* Workflows attach to events (container-down, pre-update, resource-alert, scheduled)
* and execute a sequence of actions when triggered.
*/
const EventEmitter = require('events');
const fs = require('fs');
const path = require('path');
const WORKFLOWS_FILE = process.env.WORKFLOWS_FILE || path.join(__dirname, 'workflows-config.json');
const WORKFLOW_HISTORY_FILE = process.env.WORKFLOW_HISTORY_FILE || path.join(__dirname, 'workflow-history.json');
/**
* Bundled workflow templates
*/
const BUNDLED_WORKFLOWS = {
'auto-restart-on-crash': {
id: 'auto-restart-on-crash',
name: 'Auto-Restart on Crash',
description: 'Automatically restart a container when it goes down',
trigger: 'container-down',
actions: [
{ type: 'docker-restart', containerId: '{{containerId}}' },
{ type: 'notify', message: 'Container {{containerId}} restarted automatically' }
]
},
'backup-before-update': {
id: 'backup-before-update',
name: 'Backup Before Update',
description: 'Create a backup before any app update',
trigger: 'pre-update',
actions: [
{ type: 'backup-create', appId: '{{appId}}', label: 'pre-update' },
{ type: 'notify', message: 'Backup created before updating {{appId}}' }
]
},
'health-check-on-interval': {
id: 'health-check-on-interval',
name: 'Periodic Health Check',
description: 'Run health checks every 15 minutes and alert if degraded',
trigger: 'scheduled',
interval: 15 * 60 * 1000, // 15 minutes
actions: [
{ type: 'health-check', target: '{{serviceId}}' },
{ type: 'notify-on-failure', message: 'Health check failed for {{serviceId}}' }
]
},
'disk-space-alert': {
id: 'disk-space-alert',
name: 'Disk Space Alert',
description: 'Alert when disk usage exceeds 80%',
trigger: 'resource-alert',
condition: 'diskPercent > 80',
actions: [
{ type: 'notify', message: '⚠️ Disk usage at {{diskPercent}}% on {{host}}' }
]
},
'weekly-container-report': {
id: 'weekly-container-report',
name: 'Weekly Container Report',
description: 'Send a weekly summary of container status and resource usage',
trigger: 'scheduled',
interval: 7 * 24 * 60 * 60 * 1000, // weekly
actions: [
{ type: 'collect-metrics', period: '7d' },
{ type: 'notify', message: '{{report}}' }
]
}
};
/**
* WorkflowEngine - Executes bundled workflows
*/
class WorkflowEngine extends EventEmitter {
constructor(ctx) {
super();
this.ctx = ctx;
this.enabled = new Map();
this.history = [];
this.scheduledJobs = new Map();
this.loadConfig();
this.loadHistory();
this.startScheduledWorkflows();
}
/**
* Load enabled/disabled state for workflows
*/
loadConfig() {
try {
if (fs.existsSync(WORKFLOWS_FILE)) {
const data = JSON.parse(fs.readFileSync(WORKFLOWS_FILE, 'utf8'));
this.enabled = new Map(Object.entries(data.enabled || {}));
}
} catch (error) {
console.error('[WorkflowEngine] Error loading config:', error.message);
}
// Default all workflows to enabled if not explicitly set
for (const [id, workflow] of Object.entries(BUNDLED_WORKFLOWS)) {
if (!this.enabled.has(id)) {
this.enabled.set(id, true);
}
}
}
/**
* Save enabled/disabled state
*/
saveConfig() {
try {
const data = {
enabled: Object.fromEntries(this.enabled)
};
fs.writeFileSync(WORKFLOWS_FILE, JSON.stringify(data, null, 2));
} catch (error) {
console.error('[WorkflowEngine] Error saving config:', error.message);
}
}
/**
* Load execution history
*/
loadHistory() {
try {
if (fs.existsSync(WORKFLOW_HISTORY_FILE)) {
this.history = JSON.parse(fs.readFileSync(WORKFLOW_HISTORY_FILE, 'utf8'));
}
} catch (error) {
console.error('[WorkflowEngine] Error loading history:', error.message);
this.history = [];
}
}
/**
* Save execution history
*/
saveHistory() {
try {
fs.writeFileSync(WORKFLOW_HISTORY_FILE, JSON.stringify(this.history, null, 2));
} catch (error) {
console.error('[WorkflowEngine] Error saving history:', error.message);
}
}
/**
* Start scheduled workflows
*/
startScheduledWorkflows() {
for (const [id, workflow] of Object.entries(BUNDLED_WORKFLOWS)) {
if (workflow.trigger === 'scheduled' && workflow.interval) {
this.startScheduledWorkflow(id, workflow);
}
}
}
/**
* Start a scheduled workflow
*/
startScheduledWorkflow(workflowId, workflow) {
if (!this.enabled.get(workflowId)) return;
// Clear existing job if any
this.stopScheduledWorkflow(workflowId);
const job = setInterval(() => {
this.executeWorkflow(workflowId, { trigger: 'scheduled', timestamp: new Date().toISOString() })
.catch(err => console.error(`[WorkflowEngine] Scheduled workflow ${workflowId} failed:`, err.message));
}, workflow.interval);
this.scheduledJobs.set(workflowId, job);
console.log(`[WorkflowEngine] Scheduled workflow '${workflowId}' every ${workflow.interval}ms`);
}
/**
* Stop a scheduled workflow
*/
stopScheduledWorkflow(workflowId) {
if (this.scheduledJobs.has(workflowId)) {
clearInterval(this.scheduledJobs.get(workflowId));
this.scheduledJobs.delete(workflowId);
}
}
/**
* Execute a workflow by ID
*/
async executeWorkflow(workflowId, triggerData = {}) {
const workflow = BUNDLED_WORKFLOWS[workflowId];
if (!workflow) {
throw new Error(`Unknown workflow: ${workflowId}`);
}
if (!this.enabled.get(workflowId)) {
console.log(`[WorkflowEngine] Workflow ${workflowId} is disabled, skipping`);
return { skipped: true, reason: 'disabled' };
}
const executionId = `${workflowId}-${Date.now()}`;
const startTime = Date.now();
console.log(`[WorkflowEngine] Executing workflow: ${workflowId}`);
this.emit('workflow-start', { workflowId, executionId, triggerData });
const results = [];
for (const action of workflow.actions) {
try {
const result = await this.executeAction(action, triggerData);
results.push({ action: action.type, success: true, result });
} catch (error) {
console.error(`[WorkflowEngine] Action ${action.type} failed:`, error.message);
results.push({ action: action.type, success: false, error: error.message });
// Continue with other actions but log failure
}
}
const duration = Date.now() - startTime;
const allSucceeded = results.every(r => r.success);
const historyEntry = {
executionId,
workflowId,
workflowName: workflow.name,
trigger: triggerData.trigger || 'manual',
timestamp: new Date().toISOString(),
duration,
success: allSucceeded,
results
};
this.history.push(historyEntry);
// Keep history to last 500 entries
if (this.history.length > 500) {
this.history = this.history.slice(-500);
}
this.saveHistory();
this.emit('workflow-complete', historyEntry);
console.log(`[WorkflowEngine] Workflow ${workflowId} completed in ${duration}ms, success: ${allSucceeded}`);
return historyEntry;
}
/**
* Execute a single action
*/
async executeAction(action, context) {
switch (action.type) {
case 'docker-restart':
return this.restartContainer(this.interpolate(action.containerId, context));
case 'backup-create':
return this.createBackup(
this.interpolate(action.appId, context),
action.label
);
case 'notify':
return this.notify(
this.interpolate(action.message, context),
action.channel
);
case 'notify-on-failure':
// Only send if previous action failed
return this.notify(
this.interpolate(action.message, context),
action.channel
);
case 'health-check':
return this.healthCheckService(this.interpolate(action.target, context));
case 'collect-metrics':
return this.collectMetrics(context.containerId, action.period);
default:
console.warn(`[WorkflowEngine] Unknown action type: ${action.type}`);
return { skipped: true, reason: `Unknown action type: ${action.type}` };
}
}
/**
* Interpolate template variables in a string
*/
interpolate(str, context) {
if (!str || typeof str !== 'string') return str;
return str.replace(/\{\{(\w+)\}\}/g, (match, key) => {
return context[key] !== undefined ? context[key] : match;
});
}
/**
* Health check action
*/
async healthCheckService(serviceId) {
if (!serviceId || serviceId === '{{serviceId}}') {
// Run health check on all services
const results = [];
const servicesStateManager = this.ctx.servicesStateManager;
if (servicesStateManager) {
const services = servicesStateManager.getState() || [];
for (const service of services) {
if (service.containerId) {
try {
const healthy = await this.checkContainerHealth(service.containerId);
results.push({ service: service.id, healthy });
} catch (e) {
results.push({ service: service.id, healthy: false, error: e.message });
}
}
}
}
return { checked: results.length, healthy: results.filter(r => r.healthy).length, results };
}
// Single service check
const healthy = await this.checkContainerHealth(serviceId);
return { serviceId, healthy };
}
/**
* Check if a container is healthy
*/
async checkContainerHealth(containerId) {
try {
const docker = this.ctx.docker?.client;
if (!docker) return false;
const container = docker.getContainer(containerId);
const info = await container.inspect();
return info.State && info.State.Running && info.State.Health !== 'unhealthy';
} catch (error) {
return false;
}
}
/**
* Docker restart action
*/
async restartContainer(containerId) {
const docker = this.ctx.docker?.client;
if (!docker) {
throw new Error('Docker client not available');
}
if (!containerId || containerId === '{{containerId}}') {
throw new Error('Container ID not provided');
}
console.log(`[WorkflowEngine] Restarting container: ${containerId}`);
const container = docker.getContainer(containerId);
await container.restart();
return { restarted: containerId };
}
/**
* Backup create action
*/
async createBackup(appId, label = 'workflow') {
const backupManager = this.ctx.backupManager;
if (!backupManager) {
throw new Error('Backup manager not available');
}
if (!appId || appId === '{{appId}}') {
throw new Error('App ID not provided');
}
console.log(`[WorkflowEngine] Creating backup for: ${appId}`);
// Use backup manager's executeBackup if available
const backupName = `${appId}-${label}`;
const backupConfig = backupManager.config?.backups?.[appId];
if (backupConfig) {
const result = await backupManager.executeBackup(backupName, backupConfig);
return { backupId: result.backupId, appId, label };
}
// Fallback: trigger manual backup via backup manager
if (backupManager.executeBackup) {
const result = await backupManager.executeBackup(appId, {
include: ['config', 'data'],
schedule: 'manual'
});
return { backupId: result.backupId, appId, label };
}
throw new Error('Backup execution not available');
}
/**
* Notify action
*/
async notify(message, channel) {
const notification = this.ctx.notification;
if (!notification) {
console.warn('[WorkflowEngine] Notification manager not available');
return { notified: false, reason: 'no notification manager' };
}
console.log(`[WorkflowEngine] Sending notification: ${message}`);
notification.send('workflow', 'Workflow Notification', message, 'info');
return { notified: true, message };
}
/**
* Collect metrics action
*/
async collectMetrics(containerId, period = '7d') {
const resourceMonitor = this.ctx.resourceMonitor;
if (!resourceMonitor) {
throw new Error('Resource monitor not available');
}
// Get aggregated stats
const stats = resourceMonitor.getAllStats();
// Build report
let report = `# Weekly Container Report\n\n`;
report += `Generated: ${new Date().toLocaleString()}\n\n`;
for (const [id, info] of Object.entries(stats)) {
const agg = info.aggregated;
report += `## ${info.name || id}\n`;
report += `- Status: ${info.current?.status || 'unknown'}\n`;
if (agg) {
report += `- CPU: avg ${agg.cpu?.avg?.toFixed(1)}%, max ${agg.cpu?.max?.toFixed(1)}%\n`;
report += `- Memory: avg ${agg.memory?.avg?.toFixed(1)}%, max ${agg.memory?.max?.toFixed(1)}%\n`;
}
report += '\n';
}
return { report, containerCount: Object.keys(stats).length };
}
/**
* List all available workflows
*/
listWorkflows() {
return Object.entries(BUNDLED_WORKFLOWS).map(([id, workflow]) => ({
...workflow,
enabled: this.enabled.get(id) ?? true
}));
}
/**
* Enable or disable a workflow
*/
setWorkflowEnabled(workflowId, enabled) {
if (!BUNDLED_WORKFLOWS[workflowId]) {
throw new Error(`Unknown workflow: ${workflowId}`);
}
this.enabled.set(workflowId, enabled);
this.saveConfig();
// Handle scheduled workflows
const workflow = BUNDLED_WORKFLOWS[workflowId];
if (workflow.trigger === 'scheduled' && workflow.interval) {
if (enabled) {
this.startScheduledWorkflow(workflowId, workflow);
} else {
this.stopScheduledWorkflow(workflowId);
}
}
console.log(`[WorkflowEngine] Workflow ${workflowId} ${enabled ? 'enabled' : 'disabled'}`);
return { workflowId, enabled };
}
/**
* Get execution history for a workflow
*/
getHistory(workflowId = null, limit = 50) {
let history = this.history;
if (workflowId) {
history = history.filter(h => h.workflowId === workflowId);
}
return history.slice(-limit).reverse();
}
/**
* Trigger workflows for a specific event
*/
async triggerForEvent(eventType, eventData) {
const matchingWorkflows = Object.entries(BUNDLED_WORKFLOWS)
.filter(([id, workflow]) => {
if (workflow.trigger !== eventType) return false;
if (!this.enabled.get(id)) return false;
// Check condition if specified
if (workflow.condition && eventData) {
try {
// Simple condition evaluation
const conditionMet = this.evaluateCondition(workflow.condition, eventData);
return conditionMet;
} catch (e) {
console.warn(`[WorkflowEngine] Condition evaluation failed for ${id}:`, e.message);
return false;
}
}
return true;
});
const results = [];
for (const [workflowId, workflow] of matchingWorkflows) {
try {
const result = await this.executeWorkflow(workflowId, {
trigger: eventType,
timestamp: new Date().toISOString(),
...eventData
});
results.push({ workflowId, success: true, result });
} catch (error) {
results.push({ workflowId, success: false, error: error.message });
}
}
return results;
}
/**
* Evaluate a simple condition string
*/
evaluateCondition(condition, data) {
// Simple condition like "diskPercent > 80"
// Supports: >, <, >=, <=, ==, !=
const match = condition.match(/^(\w+)\s*(>=|<=|==|!=|>|<)\s*(\S+)$/);
if (!match) return true;
const [, field, operator, value] = match;
const fieldValue = data[field];
if (fieldValue === undefined) return false;
const numValue = parseFloat(value);
const numFieldValue = parseFloat(fieldValue);
switch (operator) {
case '>': return numFieldValue > numValue;
case '<': return numFieldValue < numValue;
case '>=': return numFieldValue >= numValue;
case '<=': return numFieldValue <= numValue;
case '==': return fieldValue == value;
case '!=': return fieldValue != value;
default: return false;
}
}
/**
* Stop all scheduled workflows
*/
stop() {
for (const [workflowId] of this.scheduledJobs) {
this.stopScheduledWorkflow(workflowId);
}
console.log('[WorkflowEngine] All scheduled workflows stopped');
}
}
module.exports = { WorkflowEngine, BUNDLED_WORKFLOWS };
+376
View File
@@ -0,0 +1,376 @@
/**
* Config Drift Detector - Compares services.json with live Docker state
*
* Detects discrepancies between the configured service list and what is
* actually running in Docker, including missing containers, unknown
* containers, port mismatches, state mismatches, and stale records.
*
* @module config-drift-detector
*/
const EventEmitter = require('events');
/**
* @typedef {Object} DriftReport
* @property {string} checkedAt - ISO timestamp of the check
* @property {Object[]} missingContainers - Services with containerId but container absent in Docker
* @property {Object[]} unknownContainers - Running Docker containers with sami.managed label but not in services.json
* @property {Object[]} portMismatch - Service port != container mapped port
* @property {Object[]} stateMismatch - Service expected up but container stopped/absent
* @property {Object[]} staleRecords - Services with containerId pointing to removed containers
* @property {boolean} hasDrift - Whether any drift category is non-empty
*/
/**
* Detects and reports configuration drift between services.json and Docker.
*
* @extends EventEmitter
*
* @fires ConfigDriftDetector#drift-detected
*/
class ConfigDriftDetector extends EventEmitter {
/**
* @param {Object} ctx - Shared application context
* @param {Object} ctx.docker - Docker client wrapper ({ client: Dockerode })
* @param {Object} ctx.servicesStateManager - StateManager for services.json
* @param {Object} ctx.notification - NotificationManager instance
* @param {Object} ctx.log - Logger instance
* @param {Function} ctx.logError - Error logging function
*/
constructor(ctx) {
super();
this.ctx = ctx;
this.log = ctx.log || console;
this.logError = ctx.logError || ((_c, err) => console.error(err));
this.docker = ctx.docker;
this.servicesStateManager = ctx.servicesStateManager;
this.notification = ctx.notification;
/** @type {DriftReport|null} Cached report from last detection */
this.lastReport = null;
/** @type {NodeJS.Timeout|null} Polling timer reference */
this._pollTimer = null;
/** Whether polling is currently active */
this._polling = false;
}
// ─── Detection ───────────────────────────────────────────────────────
/**
* Run a full drift detection and return the report.
*
* Reads services from servicesStateManager and live containers from Docker,
* then compares them across five drift categories.
*
* @returns {Promise<DriftReport>}
*/
async detect() {
const checkedAt = new Date().toISOString();
// Gather configured services
let services = [];
try {
const data = await this.servicesStateManager.read();
services = Array.isArray(data) ? data : (data.services || []);
} catch (err) {
this.log.error('drift', 'Failed to read services', { error: err.message });
}
// Gather live Docker containers
let containers = [];
try {
containers = await this.docker.client.listContainers({ all: true });
} catch (err) {
this.log.error('drift', 'Failed to list containers', { error: err.message });
}
// Build lookup maps
const containerById = new Map(); // containerId (short or long) → container info
const containerByName = new Map(); // container name → container info
for (const c of containers) {
// Store by full ID
containerById.set(c.Id, c);
// Store by short ID (first 12 chars)
if (c.Id && c.Id.length >= 12) {
containerById.set(c.Id.substring(0, 12), c);
}
// Store by name (strip leading /)
for (const name of (c.Names || [])) {
containerByName.set(name.replace(/^\//, ''), c);
}
}
// Build set of service containerIds for reverse lookup
const serviceContainerIds = new Set();
const serviceByContainerId = new Map();
for (const svc of services) {
if (svc.containerId) {
serviceContainerIds.add(svc.containerId);
// Index by both full and short ID
serviceByContainerId.set(svc.containerId, svc);
if (svc.containerId.length >= 12) {
serviceByContainerId.set(svc.containerId.substring(0, 12), svc);
}
}
}
const missingContainers = [];
const portMismatch = [];
const stateMismatch = [];
const staleRecords = [];
for (const svc of services) {
if (!svc.containerId) continue;
// Look up the container
const container = containerById.get(svc.containerId)
|| containerById.get(svc.containerId.substring(0, 12));
if (!container) {
// Container ID referenced but not found in Docker at all
staleRecords.push({
serviceId: svc.id,
name: svc.name,
containerId: svc.containerId,
reason: 'Container not found in Docker',
});
continue;
}
// Missing container — service expects it but it's not running
if (container.State !== 'running') {
missingContainers.push({
serviceId: svc.id,
name: svc.name,
containerId: svc.containerId,
containerState: container.State,
containerStatus: container.Status,
});
// Also a state mismatch if the service is expected to be up
stateMismatch.push({
serviceId: svc.id,
name: svc.name,
expectedState: 'running',
actualState: container.State,
containerId: svc.containerId,
});
}
// Port mismatch detection
if (svc.port && container.State === 'running') {
const actualPorts = this._extractContainerPorts(container);
if (actualPorts.length > 0 && !actualPorts.includes(svc.port)) {
portMismatch.push({
serviceId: svc.id,
name: svc.name,
configuredPort: svc.port,
actualPorts,
containerId: svc.containerId,
});
}
}
}
// Unknown managed containers: Docker containers with sami.managed label
// that are NOT in services.json
const unknownContainers = [];
for (const c of containers) {
const isManaged = c.Labels && c.Labels['sami.managed'] === 'true';
if (!isManaged) continue;
const isInServices = serviceByContainerId.has(c.Id)
|| serviceByContainerId.has(c.Id.substring(0, 12));
if (!isInServices) {
unknownContainers.push({
containerId: c.Id,
name: (c.Names && c.Names[0] || '').replace(/^\//, ''),
image: c.Image,
state: c.State,
status: c.Status,
app: c.Labels?.['sami.app'] || null,
subdomain: c.Labels?.['sami.subdomain'] || null,
});
}
}
const report = {
checkedAt,
missingContainers,
unknownContainers,
portMismatch,
stateMismatch,
staleRecords,
hasDrift: missingContainers.length > 0
|| unknownContainers.length > 0
|| portMismatch.length > 0
|| stateMismatch.length > 0
|| staleRecords.length > 0,
};
// Cache for quick API access
this.lastReport = report;
// Emit and notify if drift detected
if (report.hasDrift) {
/**
* @event ConfigDriftDetector#drift-detected
* @type {DriftReport}
*/
this.emit('drift-detected', report);
try {
await this._sendDriftNotification(report);
} catch (notifErr) {
this.log.error('drift', 'Failed to send drift notification', {
error: notifErr.message,
});
}
}
this.log.info('drift', 'Detection complete', {
hasDrift: report.hasDrift,
missing: report.missingContainers.length,
unknown: report.unknownContainers.length,
portMismatch: report.portMismatch.length,
stateMismatch: report.stateMismatch.length,
stale: report.staleRecords.length,
});
return report;
}
// ─── Auto-fix ────────────────────────────────────────────────────────
/**
* Attempt to auto-fix drift:
* - Remove stale records (services referencing removed containers)
* - Flag unknown containers for review
*
* @returns {Promise<{ staleRemoved: number, unknownFlagged: number }>}
*/
async autoFix() {
const report = await this.detect();
let staleRemoved = 0;
// Remove stale records from services.json
if (report.staleRecords.length > 0) {
const staleIds = new Set(report.staleRecords.map(r => r.serviceId));
await this.servicesStateManager.update(services => {
const before = services.length;
const cleaned = services.filter(s => !staleIds.has(s.id));
staleRemoved = before - cleaned.length;
return cleaned;
});
}
const unknownFlagged = report.unknownContainers.length;
this.log.info('drift', 'Auto-fix applied', { staleRemoved, unknownFlagged });
return { staleRemoved, unknownFlagged };
}
// ─── Polling ─────────────────────────────────────────────────────────
/**
* Start periodic drift detection.
*
* @param {number} [intervalMs=300000] - Polling interval in milliseconds (default 5 min)
*/
startPolling(intervalMs = 300000) {
this.stopPolling();
this._polling = true;
this._pollTimer = setInterval(async () => {
try {
await this.detect();
} catch (err) {
this.logError('drift-poll', err);
}
}, intervalMs);
this.log.info('drift', 'Polling started', { intervalMs });
}
/**
* Stop periodic drift detection.
*/
stopPolling() {
if (this._pollTimer) {
clearInterval(this._pollTimer);
this._pollTimer = null;
}
this._polling = false;
this.log.info('drift', 'Polling stopped');
}
/**
* Whether polling is currently active.
* @returns {boolean}
*/
isPolling() {
return this._polling;
}
// ─── Helpers ─────────────────────────────────────────────────────────
/**
* Extract mapped host ports from a Docker container info object.
*
* @param {Object} container - Dockerode container info
* @returns {number[]} Array of host port numbers
* @private
*/
_extractContainerPorts(container) {
const ports = [];
if (!container.Ports) return ports;
for (const p of container.Ports) {
if (p.PublicPort) {
ports.push(p.PublicPort);
}
}
return ports;
}
/**
* Send a notification about detected drift.
*
* @param {DriftReport} report
* @returns {Promise<Object>}
* @private
*/
async _sendDriftNotification(report) {
if (!this.notification?.send) {
return { success: false, reason: 'no-notification-manager' };
}
const parts = [];
if (report.missingContainers.length > 0) {
parts.push(`Missing containers: ${report.missingContainers.map(c => c.name).join(', ')}`);
}
if (report.unknownContainers.length > 0) {
parts.push(`Unknown managed containers: ${report.unknownContainers.map(c => c.name).join(', ')}`);
}
if (report.portMismatch.length > 0) {
parts.push(`Port mismatches: ${report.portMismatch.map(c => c.name).join(', ')}`);
}
if (report.staleRecords.length > 0) {
parts.push(`Stale records: ${report.staleRecords.map(c => c.name).join(', ')}`);
}
return this.notification.send('drift-detected', {
text: `⚠️ Configuration drift detected:\n${parts.join('\n')}`,
report,
});
}
}
module.exports = { ConfigDriftDetector };
+9
View File
@@ -59,6 +59,15 @@ function validateConfig(config) {
errors.push('dns.servers must be an object');
}
}
// DNS provider validation
if (config.dns.provider !== undefined) {
const validProviders = ['technitium', 'cloudflare', 'rfc2136', 'manual'];
if (typeof config.dns.provider !== 'string') {
errors.push('dns.provider must be a string');
} else if (!validProviders.includes(config.dns.provider)) {
warnings.push(`dns.provider "${config.dns.provider}" is not one of: ${validProviders.join(', ')}. It may still work if a custom adapter is installed.`);
}
}
}
}
+1 -1
View File
@@ -102,7 +102,7 @@ const DNS_RECORD_TYPES = ['A', 'AAAA', 'CNAME', 'MX', 'TXT', 'NS', 'SRV', 'PTR',
// ── Docker ──────────────────────────────────────────────────────
const DOCKER = {
CONTAINER_PREFIX: 'sami-',
TIMEOUT: 30000, // 30s — timeout for docker pull/create operations
TIMEOUT: 300000, // 300s — timeout for docker pull/create operations
LOG_CONFIG: {
Type: 'json-file',
Config: { 'max-size': '10m', 'max-file': '3' } // 30MB max per container
+20 -1
View File
@@ -10,7 +10,26 @@ const lockfile = require('proper-lockfile');
const fs = require('fs');
const path = require('path');
const CREDENTIALS_FILE = process.env.CREDENTIALS_FILE || path.join(__dirname, 'credentials.json');
// Resolve credentials file path — supports both standard install (/app/credentials.json)
// and custom deployments with consolidated data directory (/app/data/credentials.json)
function resolveCredentialsFile() {
if (process.env.CREDENTIALS_FILE) {
return process.env.CREDENTIALS_FILE;
}
const candidates = [
path.join(__dirname, 'credentials.json'),
path.join(__dirname, 'data', 'credentials.json'),
];
for (const candidate of candidates) {
if (fs.existsSync(candidate)) {
return candidate;
}
}
// No existing file — return standard path so first store() creates it there
return candidates[0];
}
const CREDENTIALS_FILE = resolveCredentialsFile();
class CredentialManager {
constructor() {
+20 -2
View File
@@ -15,8 +15,26 @@ const IV_LENGTH = 16; // 128 bits for GCM
const AUTH_TAG_LENGTH = 16;
const SALT_LENGTH = 32;
// Key file location (should be outside of mounted volumes for security)
const KEY_FILE = process.env.ENCRYPTION_KEY_FILE || path.join(__dirname, '.encryption-key');
// Resolve encryption key file path — supports both standard install (/app/.encryption-key)
// and custom deployments with consolidated data directory (/app/data/.encryption-key)
function resolveKeyFile() {
if (process.env.ENCRYPTION_KEY_FILE) {
return process.env.ENCRYPTION_KEY_FILE;
}
const candidates = [
path.join(__dirname, '.encryption-key'),
path.join(__dirname, 'data', '.encryption-key'),
];
for (const candidate of candidates) {
if (fs.existsSync(candidate)) {
return candidate;
}
}
// No existing file — return standard path so first load creates it there
return candidates[0];
}
const KEY_FILE = resolveKeyFile();
let encryptionKey = null;
+605
View File
@@ -0,0 +1,605 @@
/**
* Dependency Manager - Service dependency tracking with ordered restart chains
*
* Manages directed acyclic graph (DAG) of service dependencies. Services can
* declare which other services they depend on, and this manager provides:
* - Full dependency graph inspection
* - Topological ordering for safe restart chains
* - Circular dependency detection
* - Health-aware restart with per-service polling
*
* Dependencies are stored directly on service objects in services.json:
* { id, name, ..., dependsOn: ['service-id-1', 'service-id-2'] }
*
* @module dependency-manager
*/
const EventEmitter = require('events');
/** Maximum seconds to wait for a single container to become healthy after restart */
const HEALTH_CHECK_TIMEOUT_MS = 30_000;
/** Interval between container health polls */
const HEALTH_CHECK_INTERVAL_MS = 1_000;
/**
* @typedef {Object} ServiceNode
* @property {string} serviceId
* @property {string} name
* @property {string|null} containerId
*/
/**
* @typedef {Object} DependencyEdge
* @property {string} from - The service that depends
* @property {string} to - The service being depended upon
*/
/**
* @typedef {Object} DependencyGraph
* @property {ServiceNode[]} nodes
* @property {DependencyEdge[]} edges
*/
/**
* @typedef {Object} DependencyStatusEntry
* @property {string} serviceId
* @property {string} name
* @property {boolean} isUp
* @property {string} [error]
*/
/**
* DependencyManager — tracks service dependencies and orchestrates ordered restarts.
*
* Events emitted:
* - `dependency-restart-start` ({ serviceId, chain: string[] })
* - `dependency-restart-progress` ({ serviceId, currentServiceId, index, total })
* - `dependency-restart-complete` ({ serviceId, chain: string[], results: Array })
* - `dependency-restart-failed` ({ serviceId, failedServiceId, error, chain: string[] })
*
* @extends EventEmitter
*/
class DependencyManager extends EventEmitter {
/**
* @param {Object} ctx - Application context
* @param {Object} ctx.servicesStateManager - StateManager for services.json
* @param {Object} ctx.docker - Docker context ({ client: Dockerode })
* @param {Object} ctx.notification - NotificationManager instance
* @param {Object} ctx.log - Logger instance
*/
constructor(ctx) {
super();
/** @private */
this.ctx = ctx;
/** @private */
this._servicesStateManager = ctx.servicesStateManager;
/** @private */
this._docker = ctx.docker;
/** @private */
this._notification = ctx.notification;
/** @private */
this._log = ctx.log || console;
}
// ---------------------------------------------------------------------------
// Core helpers
// ---------------------------------------------------------------------------
/**
* Load all services from the state manager.
* @private
* @returns {Promise<Object[]>}
*/
async _loadServices() {
const data = await this._servicesStateManager.read();
return Array.isArray(data) ? data : (data.services || []);
}
/**
* Find a single service by ID.
* @private
* @param {string} serviceId
* @returns {Promise<Object|null>}
*/
async _findService(serviceId) {
const services = await this._loadServices();
return services.find(s => s.id === serviceId) || null;
}
// ---------------------------------------------------------------------------
// Graph queries
// ---------------------------------------------------------------------------
/**
* Return the full dependency graph for visualisation.
*
* @returns {Promise<DependencyGraph>}
*/
async getDependencyGraph() {
const services = await this._loadServices();
const nodes = services.map(s => ({
serviceId: s.id,
name: s.name,
containerId: s.containerId || null,
}));
const edges = [];
for (const service of services) {
const deps = service.dependsOn || [];
for (const depId of deps) {
edges.push({ from: service.id, to: depId });
}
}
return { nodes, edges };
}
/**
* Return the services that depend on the given service (reverse deps).
*
* @param {string} serviceId
* @returns {Promise<Object[]>} Services whose `dependsOn` includes `serviceId`.
*/
async getDependents(serviceId) {
const services = await this._loadServices();
return services.filter(s => (s.dependsOn || []).includes(serviceId));
}
/**
* Return the direct dependencies for a service.
*
* @param {string} serviceId
* @returns {Promise<Object[]>} Services that `serviceId` depends on.
*/
async getDependencies(serviceId) {
const services = await this._loadServices();
const service = services.find(s => s.id === serviceId);
if (!service) return [];
const depIds = service.dependsOn || [];
return services.filter(s => depIds.includes(s.id));
}
// ---------------------------------------------------------------------------
// Topological sort
// ---------------------------------------------------------------------------
/**
* Build an adjacency list for the current dependency graph.
* Edge direction: service → its dependencies (i.e. what it depends on).
*
* @private
* @param {Object[]} services
* @returns {Map<string, string[]>}
*/
_buildAdjacencyList(services) {
const adj = new Map();
for (const service of services) {
adj.set(service.id, (service.dependsOn || []).slice());
}
return adj;
}
/**
* DFS-based topological sort with cycle detection (white/gray/black coloring).
*
* Returns services in restart order: dependencies first, dependents last.
* The target service is included at the end.
*
* @private
* @param {string} serviceId - Target service (will be last in the result).
* @param {Object[]} services - All services.
* @param {Map<string, string[]>} adj - Adjacency list (service → deps).
* @returns {string[]} Ordered service IDs for restart.
* @throws {Error} If a circular dependency is detected.
*/
_topologicalSort(serviceId, services, adj) {
// Collect only the reachable sub-graph from serviceId
const visited = new Set();
const reachable = new Set();
const collectReachable = (id) => {
if (reachable.has(id)) return;
reachable.add(id);
for (const dep of (adj.get(id) || [])) {
collectReachable(dep);
}
};
collectReachable(serviceId);
// DFS topological sort on the reachable sub-graph
const WHITE = 0, GRAY = 1, BLACK = 2;
const color = new Map();
for (const id of reachable) color.set(id, WHITE);
const result = [];
const dfs = (id) => {
if (color.get(id) === BLACK) return;
if (color.get(id) === GRAY) {
throw new Error(`Circular dependency detected involving service "${id}"`);
}
color.set(id, GRAY);
for (const dep of (adj.get(id) || [])) {
dfs(dep);
}
color.set(id, BLACK);
result.push(id);
};
// Visit the target last so it ends up at the end of the result
// Actually, we want deps *first* then the target.
// The DFS naturally puts deps before dependents, so starting from
// serviceId will place it last (which is correct for restart order).
dfs(serviceId);
return result;
}
/**
* Get the topologically ordered restart chain for a service.
*
* The returned array lists all services that must be restarted,
* starting with leaf dependencies and ending with the target service.
*
* @param {string} serviceId - The service to build the chain for.
* @returns {Promise<string[]>} Ordered service IDs.
* @throws {Error} If `serviceId` doesn't exist or a circular dependency is found.
*/
async getOrderedRestartChain(serviceId) {
const services = await this._loadServices();
const service = services.find(s => s.id === serviceId);
if (!service) {
throw new Error(`Service "${serviceId}" not found`);
}
const adj = this._buildAdjacencyList(services);
return this._topologicalSort(serviceId, services, adj);
}
// ---------------------------------------------------------------------------
// Validation
// ---------------------------------------------------------------------------
/**
* Validate a proposed set of dependencies for a service.
*
* Checks:
* - All referenced service IDs exist.
* - Adding these dependencies would not create a circular dependency.
* - A service cannot depend on itself.
*
* @param {string} serviceId - The service to set dependencies on.
* @param {string[]} dependsOn - Proposed dependency IDs.
* @returns {Promise<{ valid: boolean, errors: string[] }>}
*/
async validateDependencies(serviceId, dependsOn) {
const errors = [];
if (!Array.isArray(dependsOn)) {
return { valid: false, errors: ['dependsOn must be an array'] };
}
const services = await this._loadServices();
const allIds = new Set(services.map(s => s.id));
// Service must exist
if (!allIds.has(serviceId)) {
return { valid: false, errors: [`Service "${serviceId}" not found`] };
}
// Self-dependency
if (dependsOn.includes(serviceId)) {
errors.push(`Service "${serviceId}" cannot depend on itself`);
}
// Existence check
for (const depId of dependsOn) {
if (!allIds.has(depId)) {
errors.push(`Dependency service "${depId}" does not exist`);
}
}
if (errors.length > 0) {
return { valid: false, errors };
}
// Circular dependency check: temporarily set the proposed dependsOn
// and attempt a topological sort.
const tempServices = services.map(s => {
if (s.id === serviceId) {
return { ...s, dependsOn: dependsOn.slice() };
}
return { ...s };
});
const adj = this._buildAdjacencyList(tempServices);
// Check every node for cycles with the new edges
try {
const WHITE = 0, GRAY = 1, BLACK = 2;
const color = new Map();
for (const s of tempServices) color.set(s.id, WHITE);
const dfs = (id) => {
if (color.get(id) === BLACK) return;
if (color.get(id) === GRAY) {
throw new Error(`Circular dependency detected involving service "${id}"`);
}
color.set(id, GRAY);
for (const dep of (adj.get(id) || [])) {
dfs(dep);
}
color.set(id, BLACK);
};
for (const s of tempServices) {
if (color.get(s.id) === WHITE) {
dfs(s.id);
}
}
} catch (err) {
errors.push(err.message);
}
return { valid: errors.length === 0, errors };
}
// ---------------------------------------------------------------------------
// Health status
// ---------------------------------------------------------------------------
/**
* Get the current container status for a service and all its transitive dependencies.
*
* @param {string} serviceId
* @returns {Promise<DependencyStatusEntry[]>}
* @throws {Error} If `serviceId` doesn't exist.
*/
async getDependencyStatus(serviceId) {
const services = await this._loadServices();
const service = services.find(s => s.id === serviceId);
if (!service) {
throw new Error(`Service "${serviceId}" not found`);
}
// Collect all transitive dependencies via BFS
const serviceMap = new Map(services.map(s => [s.id, s]));
const visited = new Set();
const queue = [serviceId];
const allRelated = [];
while (queue.length > 0) {
const currentId = queue.shift();
if (visited.has(currentId)) continue;
visited.add(currentId);
const svc = serviceMap.get(currentId);
if (!svc) continue;
allRelated.push(svc);
for (const depId of (svc.dependsOn || [])) {
if (!visited.has(depId)) {
queue.push(depId);
}
}
}
// Query container status for each
const results = [];
for (const svc of allRelated) {
const entry = {
serviceId: svc.id,
name: svc.name,
isUp: false,
};
if (!svc.containerId) {
entry.error = 'No container associated with this service';
results.push(entry);
continue;
}
try {
const container = this._docker.client.getContainer(svc.containerId);
const info = await container.inspect();
entry.isUp = info.State?.Running === true;
} catch (err) {
entry.error = err.message || 'Unable to inspect container';
}
results.push(entry);
}
return results;
}
// ---------------------------------------------------------------------------
// Restart with dependencies
// ---------------------------------------------------------------------------
/**
* Wait for a container to report as running after a restart.
*
* @private
* @param {string} containerId
* @param {number} [timeoutMs=30000]
* @returns {Promise<boolean>} `true` if healthy, `false` if timed out.
*/
async _waitForContainerHealthy(containerId, timeoutMs = HEALTH_CHECK_TIMEOUT_MS) {
const start = Date.now();
while (Date.now() - start < timeoutMs) {
try {
const container = this._docker.client.getContainer(containerId);
const info = await container.inspect();
if (info.State?.Running === true) {
return true;
}
} catch {
// Container might not be inspectable during restart — keep polling
}
await new Promise(r => setTimeout(r, HEALTH_CHECK_INTERVAL_MS));
}
return false;
}
/**
* Restart a service and all its dependencies in topological order.
*
* Emits progress events and sends a notification on completion/failure.
* This method is designed to be called from the route handler and
* **does not throw** — errors are reported via events and notifications.
*
* @param {string} serviceId - Target service to restart (with deps).
* @returns {Promise<{ success: boolean, chain: string[], results: Array }>}
*/
async restartWithDependencies(serviceId) {
const service = await this._findService(serviceId);
if (!service) {
const err = new Error(`Service "${serviceId}" not found`);
this.emit('dependency-restart-failed', {
serviceId,
failedServiceId: serviceId,
error: err.message,
chain: [],
});
throw err;
}
let chain;
try {
chain = await this.getOrderedRestartChain(serviceId);
} catch (err) {
this.emit('dependency-restart-failed', {
serviceId,
failedServiceId: serviceId,
error: err.message,
chain: [],
});
throw err;
}
const services = await this._loadServices();
const serviceMap = new Map(services.map(s => [s.id, s]));
this._log.info('dependency', 'Starting dependency restart chain', {
serviceId,
chain,
});
this.emit('dependency-restart-start', { serviceId, chain });
const results = [];
const total = chain.length;
for (let i = 0; i < total; i++) {
const currentId = chain[i];
const svc = serviceMap.get(currentId);
this.emit('dependency-restart-progress', {
serviceId,
currentServiceId: currentId,
index: i,
total,
});
if (!svc || !svc.containerId) {
const msg = !svc
? `Service "${currentId}" not found in state`
: `Service "${currentId}" has no container — skipping restart`;
this._log.warn('dependency', msg);
results.push({ serviceId: currentId, restarted: false, skipped: true, reason: msg });
continue;
}
try {
const container = this._docker.client.getContainer(svc.containerId);
this._log.info('dependency', `Restarting container for service "${currentId}"`, {
containerId: svc.containerId,
});
await container.restart();
// Wait for it to come back up
const healthy = await this._waitForContainerHealthy(svc.containerId);
if (!healthy) {
const msg = `Container for service "${currentId}" did not become healthy within ${HEALTH_CHECK_TIMEOUT_MS / 1000}s`;
this._log.warn('dependency', msg);
results.push({ serviceId: currentId, restarted: true, healthy: false, error: msg });
// Abort chain — dependency didn't come back
this.emit('dependency-restart-failed', {
serviceId,
failedServiceId: currentId,
error: msg,
chain,
});
await this._notifyRestartResult(serviceId, false, chain, results, currentId);
return { success: false, chain, results };
}
this._log.info('dependency', `Service "${currentId}" is healthy after restart`);
results.push({ serviceId: currentId, restarted: true, healthy: true });
} catch (err) {
const msg = err.message || 'Unknown error during restart';
this._log.error('dependency', `Failed to restart service "${currentId}"`, {
error: msg,
});
results.push({ serviceId: currentId, restarted: false, error: msg });
this.emit('dependency-restart-failed', {
serviceId,
failedServiceId: currentId,
error: msg,
chain,
});
await this._notifyRestartResult(serviceId, false, chain, results, currentId);
return { success: false, chain, results };
}
}
this.emit('dependency-restart-complete', { serviceId, chain, results });
await this._notifyRestartResult(serviceId, true, chain, results);
return { success: true, chain, results };
}
/**
* Send a notification about the restart result.
*
* @private
* @param {string} serviceId
* @param {boolean} success
* @param {string[]} chain
* @param {Array} results
* @param {string} [failedServiceId]
*/
async _notifyRestartResult(serviceId, success, chain, results, failedServiceId) {
if (!this._notification) return;
try {
if (success) {
await this._notification.send('dependency-restart-complete', {
text: `✅ Dependency restart chain completed for "${serviceId}". Restarted: ${chain.join(' → ')}`,
serviceId,
chain,
results,
});
} else {
await this._notification.send('dependency-restart-failed', {
text: `❌ Dependency restart chain failed for "${serviceId}" at "${failedServiceId}". Chain: ${chain.join(' → ')}`,
serviceId,
failedServiceId,
chain,
results,
});
}
} catch (err) {
this._log.error('dependency', 'Failed to send restart notification', {
error: err.message,
});
}
}
}
module.exports = DependencyManager;
+273
View File
@@ -0,0 +1,273 @@
/**
* DNS Propagation Checker
* Verifies DNS record propagation by querying multiple resolvers.
* Runs as background jobs with configurable timeout and interval.
*
* @module dns-propagation
*/
const dns = require('dns').promises;
const EventEmitter = require('events');
/** Default verification options */
const DEFAULT_OPTIONS = {
timeout: 300000, // 5 minutes
interval: 10000, // 10 seconds
resolvers: ['1.1.1.1', '8.8.8.8', '9.9.9.9']
};
/** Maximum age for stored verification results (1 hour) */
const MAX_RESULT_AGE_MS = 3600000;
class DNSPropagationChecker extends EventEmitter {
/**
* Create a DNSPropagationChecker instance.
* @param {Object} ctx - Shared application context
* @param {Object} ctx.notification - NotificationManager instance
* @param {Object} ctx.log - Logger instance
*/
constructor(ctx) {
super();
this.ctx = ctx;
this.log = ctx.log || console;
/** @type {Map<string, Object>} domain → verification status */
this.verifications = new Map();
}
/**
* Verify that a DNS record has propagated by querying multiple resolvers.
* Retries every `interval` ms until `timeout` is reached.
*
* @param {string} domain - The domain to check (e.g., 'test.sami')
* @param {string} expectedIp - The expected IP address
* @param {Object} [options={}] - Verification options
* @param {number} [options.timeout=300000] - Maximum time to wait (ms)
* @param {number} [options.interval=10000] - Time between retries (ms)
* @param {string[]} [options.resolvers] - DNS resolvers to query
* @returns {Promise<Object>} Verification result
*/
async verifyRecord(domain, expectedIp, options = {}) {
const startTime = Date.now();
const {
timeout = DEFAULT_OPTIONS.timeout,
interval = DEFAULT_OPTIONS.interval,
resolvers = DEFAULT_OPTIONS.resolvers
} = options;
const allResults = [];
let propagated = false;
while (Date.now() - startTime < timeout) {
const roundResults = [];
for (const resolver of resolvers) {
const checkStart = Date.now();
try {
// Use dns.resolve4 with a custom resolver
const resolverInstance = new dns.Resolver();
resolverInstance.setServers([resolver]);
resolverInstance.setTimeout(5000);
const addresses = await resolverInstance.resolve4(domain);
const matched = addresses.includes(expectedIp);
const result = {
resolver,
ips: addresses,
matched,
checkedAt: new Date().toISOString(),
responseTime: Date.now() - checkStart
};
roundResults.push(result);
if (matched) {
propagated = true;
}
} catch (err) {
roundResults.push({
resolver,
ips: [],
matched: false,
checkedAt: new Date().toISOString(),
error: err.code || err.message,
responseTime: Date.now() - checkStart
});
}
}
allResults.push(...roundResults);
// Emit progress event
this.emit('propagation-check', {
domain,
expectedIp,
roundResults,
elapsed: Date.now() - startTime,
propagated
});
if (propagated) {
break;
}
// Wait before next attempt
await new Promise(resolve => setTimeout(resolve, interval));
}
const totalTime = Date.now() - startTime;
return {
domain,
expectedIp,
propagated,
results: allResults,
totalTime,
checkedAt: new Date().toISOString()
};
}
/**
* Start a background DNS propagation verification.
* Does not block — returns immediately with the job reference.
*
* @param {string} domain - The domain to verify
* @param {string} expectedIp - The expected IP address
* @param {Object} [options={}] - Verification options
* @returns {Object} Job status object
*/
startVerification(domain, expectedIp, options = {}) {
// If there's already a running verification for this domain, return it
const existing = this.verifications.get(domain);
if (existing && existing.status === 'running') {
return existing;
}
const job = {
domain,
expectedIp,
status: 'running',
startedAt: new Date().toISOString(),
progress: [],
result: null
};
this.verifications.set(domain, job);
// Run verification in background (non-blocking)
this.verifyRecord(domain, expectedIp, options)
.then(result => {
job.status = 'completed';
job.result = result;
job.completedAt = new Date().toISOString();
if (result.propagated) {
this.emit('propagation-complete', result);
if (this.ctx.notification) {
this.ctx.notification.send('dns-propagation', {
text: `✅ DNS record for ${domain} propagated successfully to ${expectedIp}`,
domain,
expectedIp,
totalTime: result.totalTime
}, 'success').catch(err => {
this.log.error('dns-propagation', 'Failed to send propagation notification', {
error: err.message
});
});
}
} else {
this.emit('propagation-timeout', result);
if (this.ctx.notification) {
this.ctx.notification.send('dns-propagation', {
text: `⏱️ DNS propagation timeout for ${domain} — expected ${expectedIp} not found after ${Math.round(result.totalTime / 1000)}s`,
domain,
expectedIp,
totalTime: result.totalTime
}, 'warning').catch(err => {
this.log.error('dns-propagation', 'Failed to send timeout notification', {
error: err.message
});
});
}
}
})
.catch(err => {
job.status = 'error';
job.error = err.message;
job.completedAt = new Date().toISOString();
this.log.error('dns-propagation', `Verification failed for ${domain}`, {
error: err.message
});
});
return job;
}
/**
* Get the current verification status for a domain.
*
* @param {string} domain - The domain to look up
* @returns {Object|null} Verification status or null if not found
*/
getVerificationStatus(domain) {
const job = this.verifications.get(domain);
if (!job) return null;
return {
domain: job.domain,
expectedIp: job.expectedIp,
status: job.status,
startedAt: job.startedAt,
completedAt: job.completedAt || null,
result: job.result || null,
error: job.error || null
};
}
/**
* Get all recent verifications.
*
* @returns {Object[]} Array of verification statuses
*/
getAllVerifications() {
const results = [];
for (const [domain, job] of this.verifications.entries()) {
results.push({
domain,
expectedIp: job.expectedIp,
status: job.status,
startedAt: job.startedAt,
completedAt: job.completedAt || null,
propagated: job.result?.propagated || null,
totalTime: job.result?.totalTime || null,
error: job.error || null
});
}
return results;
}
/**
* Remove verifications older than 1 hour.
*/
cleanup() {
const now = Date.now();
for (const [domain, job] of this.verifications.entries()) {
const completedAt = job.completedAt ? new Date(job.completedAt).getTime() : null;
const startedAt = new Date(job.startedAt).getTime();
// Clean up completed/error jobs older than 1 hour
// Also clean up stale running jobs that started over 2 hours ago
const age = completedAt ? (now - completedAt) : (now - startedAt);
const maxAge = job.status === 'running' ? MAX_RESULT_AGE_MS * 2 : MAX_RESULT_AGE_MS;
if (age > maxAge) {
this.verifications.delete(domain);
}
}
}
}
module.exports = DNSPropagationChecker;
+69
View File
@@ -0,0 +1,69 @@
/**
* Base DNS Provider Adapter
* All DNS provider adapters must extend this class and implement the required methods.
*
* Each adapter handles the specifics of talking to a particular DNS provider's API.
* The routes layer calls these methods generically — no provider-specific logic in routes.
*/
class BaseDNSProvider {
constructor(config, ctx) {
this.config = config; // Provider-specific config (api token, server url, etc.)
this.ctx = ctx; // Shared app context (log, credentialManager, fetchT, etc.)
this.providerId = 'base';
this.displayName = 'Base DNS Provider';
}
/** Check if this provider supports a given capability */
supportsCapability(cap) {
// Capabilities: 'create-record', 'delete-record', 'resolve', 'list-records',
// 'logs', 'restart', 'update-check', 'credentials', 'zones'
return false;
}
/** Authenticate and return a token/session */
async authenticate() { throw new Error('Not implemented'); }
/** Create a DNS record */
async createRecord({ domain, zone, type, value, ttl, overwrite }) { throw new Error('Not implemented'); }
/** Delete a DNS record */
async deleteRecord({ domain, type, value }) { throw new Error('Not implemented'); }
/** Resolve/query existing records for a domain */
async resolveRecords({ domain, zone, type }) { throw new Error('Not implemented'); }
/** List all records in a zone */
async listRecords({ zone }) { throw new Error('Not implemented'); }
/** Get DNS query logs */
async getLogs({ limit, server }) { throw new Error('Not implemented'); }
/** Restart the DNS server */
async restartServer({ server }) { throw new Error('Not implemented'); }
/** Check for DNS server updates */
async checkUpdate({ server }) { throw new Error('Not implemented'); }
/** Get provider status info */
async getStatus() {
return {
providerId: this.providerId,
displayName: this.displayName,
capabilities: this.getCapabilities(),
authenticated: false
};
}
/** Get list of supported capabilities */
getCapabilities() {
return [];
}
/** Validate provider-specific config */
validateConfig() { return { valid: true, errors: [] }; }
/** Clean up resources on shutdown */
async shutdown() {}
}
module.exports = BaseDNSProvider;
+269
View File
@@ -0,0 +1,269 @@
/**
* Cloudflare DNS Provider Adapter
* Manages DNS records via the Cloudflare API v4.
*/
const BaseDNSProvider = require('./base');
const CF_API_BASE = 'https://api.cloudflare.com/client/v4';
class CloudflareDNSProvider extends BaseDNSProvider {
constructor(config, ctx) {
super(config, ctx);
this.providerId = 'cloudflare';
this.displayName = 'Cloudflare DNS';
// Resolve API token: explicit config takes priority, then credential manager
this.apiToken = config.apiToken
|| (ctx.credentialManager && ctx.credentialManager.get('dns.cloudflare.apiToken'))
|| null;
this.zoneId = config.zoneId || null;
this.domain = config.domain || null;
}
// ── Helpers ────────────────────────────────────────────────────────────
/** Build common request headers for Cloudflare API calls */
_headers() {
return {
'Authorization': `Bearer ${this.apiToken}`,
'Content-Type': 'application/json',
};
}
/** Make an authenticated request to the Cloudflare API */
async _cfRequest(method, path, body) {
const url = `${CF_API_BASE}${path}`;
const opts = {
method,
headers: this._headers(),
};
if (body !== undefined) {
opts.body = JSON.stringify(body);
}
return this.ctx.fetchT(url, opts);
}
/** Map a Cloudflare DNS record to the normalised format expected by routes */
_mapRecord(rec) {
return {
id: rec.id,
type: rec.type,
name: rec.name,
value: rec.content,
ttl: rec.ttl,
proxied: rec.proxied || false,
};
}
// ── Capabilities ───────────────────────────────────────────────────────
supportsCapability(cap) {
return this.getCapabilities().includes(cap);
}
getCapabilities() {
return ['create-record', 'delete-record', 'resolve', 'list-records', 'credentials', 'zones'];
}
// ── Authentication ─────────────────────────────────────────────────────
/**
* Validate the API token by calling the Cloudflare verify endpoint.
* Stores basic zone info on success.
*/
async authenticate() {
this.ctx.log('[cloudflare] Authenticating verifying API token…');
if (!this.apiToken) {
return { status: 'error', message: 'No Cloudflare API token provided' };
}
const res = await this._cfRequest('GET', '/user/tokens/verify');
const data = await res.json();
if (!data.success) {
const msg = (data.errors && data.errors[0] && data.errors[0].message) || 'Token verification failed';
this.ctx.log(`[cloudflare] Authentication failed: ${msg}`);
return { status: 'error', message: msg };
}
this.ctx.log(`[cloudflare] Token verified for status "${data.status}"`);
// Optionally fetch zone info if zoneId is configured
if (this.zoneId) {
try {
const zoneRes = await this._cfRequest('GET', `/zones/${this.zoneId}`);
const zoneData = await zoneRes.json();
if (zoneData.success && zoneData.result) {
this.zoneInfo = zoneData.result;
this.ctx.log(`[cloudflare] Zone loaded: ${zoneData.result.name} (${zoneData.result.id})`);
}
} catch (err) {
this.ctx.log(`[cloudflare] Could not fetch zone info: ${err.message}`);
}
}
return { status: 'ok', response: { status: data.status } };
}
// ── Create Record ──────────────────────────────────────────────────────
/**
* Create a DNS record.
* If overwrite is true, first delete any existing record with the same name+type.
*/
async createRecord({ domain, zone, type, value, ttl, overwrite }) {
const targetDomain = domain || this.domain;
const targetZone = zone || this.zoneId;
if (!targetZone) {
return { status: 'error', message: 'No zone ID configured for Cloudflare' };
}
if (overwrite) {
this.ctx.log(`[cloudflare] Overwrite requested deleting existing ${type} record for ${targetDomain}`);
try {
await this.deleteRecord({ domain: targetDomain, type, value });
} catch (err) {
this.ctx.log(`[cloudflare] No existing record to overwrite (or delete failed): ${err.message}`);
}
}
const body = {
type,
name: targetDomain,
content: value,
ttl: ttl || 1, // 1 = automatic TTL in Cloudflare
proxied: false,
};
this.ctx.log(`[cloudflare] Creating ${type} record: ${targetDomain}${value}`);
const res = await this._cfRequest('POST', `/zones/${targetZone}/dns_records`, body);
const data = await res.json();
if (!data.success) {
const msg = (data.errors && data.errors[0] && data.errors[0].message) || 'Record creation failed';
this.ctx.log(`[cloudflare] Create failed: ${msg}`);
return { status: 'error', message: msg };
}
return { status: 'ok', response: { record: this._mapRecord(data.result) } };
}
// ── Delete Record ──────────────────────────────────────────────────────
/**
* Delete DNS records matching domain+type.
* Lists matching records first, then deletes each one.
*/
async deleteRecord({ domain, type, value }) {
const targetDomain = domain || this.domain;
const targetZone = this.zoneId;
if (!targetZone) {
return { status: 'error', message: 'No zone ID configured for Cloudflare' };
}
// List records matching name + type
let queryPath = `/zones/${targetZone}/dns_records?name=${encodeURIComponent(targetDomain)}`;
if (type) {
queryPath += `&type=${encodeURIComponent(type)}`;
}
const listRes = await this._cfRequest('GET', queryPath);
const listData = await listRes.json();
if (!listData.success) {
const msg = (listData.errors && listData.errors[0] && listData.errors[0].message) || 'Failed to list records for deletion';
this.ctx.log(`[cloudflare] Delete list failed: ${msg}`);
return { status: 'error', message: msg };
}
const matching = listData.result || [];
if (matching.length === 0) {
this.ctx.log(`[cloudflare] No records found for ${targetDomain} (${type || 'any type'})`);
return { status: 'ok', response: { deleted: 0 } };
}
// If a specific value is given, only delete records matching that value
const toDelete = value
? matching.filter((r) => r.content === value)
: matching;
let deleted = 0;
for (const record of toDelete) {
const delRes = await this._cfRequest('DELETE', `/zones/${targetZone}/dns_records/${record.id}`);
const delData = await delRes.json();
if (delData.success) {
deleted++;
this.ctx.log(`[cloudflare] Deleted record ${record.id} (${record.type} ${record.name})`);
} else {
const msg = (delData.errors && delData.errors[0] && delData.errors[0].message) || 'Delete failed';
this.ctx.log(`[cloudflare] Failed to delete record ${record.id}: ${msg}`);
}
}
return { status: 'ok', response: { deleted } };
}
// ── Resolve Records ───────────────────────────────────────────────────
/**
* Resolve/query existing records for a domain.
* Returns records matching domain (and optionally type).
*/
async resolveRecords({ domain, zone, type }) {
const targetDomain = domain || this.domain;
const targetZone = zone || this.zoneId;
if (!targetZone) {
return { status: 'error', message: 'No zone ID configured for Cloudflare' };
}
let queryPath = `/zones/${targetZone}/dns_records?name=${encodeURIComponent(targetDomain)}`;
if (type) {
queryPath += `&type=${encodeURIComponent(type)}`;
}
this.ctx.log(`[cloudflare] Resolving records for ${targetDomain}${type ? ` (${type})` : ''}`);
const res = await this._cfRequest('GET', queryPath);
const data = await res.json();
if (!data.success) {
const msg = (data.errors && data.errors[0] && data.errors[0].message) || 'Resolve failed';
this.ctx.log(`[cloudflare] Resolve failed: ${msg}`);
return { status: 'error', message: msg };
}
const records = (data.result || []).map(this._mapRecord);
return { status: 'ok', response: { records } };
}
// ── List Records ───────────────────────────────────────────────────────
/**
* List all DNS records in a zone.
*/
async listRecords({ zone }) {
const targetZone = zone || this.zoneId;
if (!targetZone) {
return { status: 'error', message: 'No zone ID configured for Cloudflare' };
}
this.ctx.log(`[cloudflare] Listing all records in zone ${targetZone}`);
const res = await this._cfRequest('GET', `/zones/${targetZone}/dns_records`);
const data = await res.json();
if (!data.success) {
const msg = (data.errors && data.errors[0] && data.errors[0].message) || 'List failed';
this.ctx.log(`[cloudflare] List failed: ${msg}`);
return { status: 'error', message: msg };
}
const records = (data.result || []).map(this._mapRecord);
return { status: 'ok', response: { records } };
}
}
module.exports = CloudflareDNSProvider;
+93
View File
@@ -0,0 +1,93 @@
/**
* Manual DNS Provider Adapter
* No-op adapter for users who manage DNS externally (manual, cPanel, other control panels).
* Provides propagation checking only — all record operations return helpful instructions.
*/
const BaseDNSProvider = require('./base');
class ManualDNSProvider extends BaseDNSProvider {
constructor(config, ctx) {
super(config, ctx);
this.providerId = 'manual';
this.displayName = 'Manual / External DNS';
this.description = 'Manage DNS records yourself via your provider\'s control panel';
}
supportsCapability(cap) {
return ['credentials'].includes(cap);
}
getCapabilities() {
return ['credentials'];
}
async authenticate() {
return { success: true, message: 'Manual DNS — no authentication needed' };
}
async createRecord({ domain, zone, type, value, ttl }) {
return {
status: 'manual',
message: `Create this record manually in your DNS control panel:`,
instructions: {
name: domain,
type: type || 'A',
value,
ttl: ttl || 300
}
};
}
async deleteRecord({ domain, type, value }) {
return {
status: 'manual',
message: `Delete this record manually from your DNS control panel:`,
instructions: {
name: domain,
type: type || 'A',
value: value || '(any)'
}
};
}
async resolveRecords({ domain, zone, type }) {
// Use Node.js built-in DNS to resolve regardless of provider
const dns = require('dns').promises;
try {
const resolver = new dns.Resolver();
resolver.setServers(['1.1.1.1', '8.8.8.8']);
const records = await resolver.resolve(domain, type || 'A');
return {
status: 'ok',
response: {
records: records.map(r => ({
type: type || 'A',
domain,
rData: { ipAddress: r },
ttl: 0,
manual: true
}))
}
};
} catch (err) {
return { status: 'ok', response: { records: [] } };
}
}
async getStatus() {
return {
providerId: this.providerId,
displayName: this.displayName,
description: this.description,
capabilities: this.getCapabilities(),
authenticated: true,
note: 'DNS records are managed externally. Use propagation checks to verify changes.'
};
}
validateConfig() {
return { valid: true, errors: [] };
}
}
module.exports = ManualDNSProvider;
+101
View File
@@ -0,0 +1,101 @@
/**
* DNS Provider Registry
* Manages available DNS provider adapters.
* Providers register themselves, and the active provider is selected by config.
*/
const path = require('path');
class DNSProviderRegistry {
constructor() {
this.providers = new Map(); // providerId -> adapter class
this.instances = new Map(); // providerId -> adapter instance
}
/** Register a provider adapter class */
register(adapterClass) {
const instance = new adapterClass({}, {});
const id = instance.providerId;
if (this.providers.has(id)) {
console.warn(`DNS provider "${id}" already registered, overwriting`);
}
this.providers.set(id, adapterClass);
}
/** Get list of all registered provider IDs */
getProviderIds() {
return Array.from(this.providers.keys());
}
/** Get metadata for all providers (without instantiating with real config) */
getProviderMeta() {
return this.getProviderIds().map(id => {
const Adapter = this.providers.get(id);
const inst = new Adapter({}, {});
return {
id: inst.providerId,
displayName: inst.displayName,
capabilities: inst.getCapabilities()
};
});
}
/**
* Get or create an adapter instance for the given provider + config
* @param {string} providerId - The provider to instantiate
* @param {Object} config - Provider-specific configuration
* @param {Object} ctx - Shared application context
* @returns {BaseDNSProvider} The provider adapter instance
*/
getProvider(providerId, config, ctx) {
// Re-create if config changed
const cacheKey = providerId;
const Adapter = this.providers.get(providerId);
if (!Adapter) {
throw new Error(`Unknown DNS provider: ${providerId}. Available: ${this.getProviderIds().join(', ')}`);
}
const instance = new Adapter(config, ctx);
this.instances.set(cacheKey, instance);
return instance;
}
/** Auto-discover and register all providers in this directory */
autoDiscover() {
const fs = require('fs');
const dir = __dirname;
const files = fs.readdirSync(dir).filter(f =>
f !== 'base.js' && f !== 'registry.js' && f.endsWith('.js') && !f.startsWith('.')
);
for (const file of files) {
try {
const Loaded = require(path.join(dir, file));
// Support: module.exports = Class, module.exports = { Class }, or plain objects
let cls = null;
if (typeof Loaded === 'function') {
cls = Loaded;
} else if (typeof Loaded === 'object' && Loaded !== null) {
// Try to find a class in the exported object
cls = Object.values(Loaded).find(v => typeof v === 'function');
}
if (cls) {
// Verify it has providerId (on prototype or set in constructor)
try {
const test = new cls({}, {});
if (test.providerId && typeof test.getCapabilities === 'function') {
this.register(cls);
}
} catch {
// Not a valid provider adapter, skip
}
}
} catch (err) {
console.error(`Failed to load DNS provider from ${file}:`, err.message);
}
}
}
}
// Singleton
const registry = new DNSProviderRegistry();
registry.autoDiscover();
module.exports = registry;
+383
View File
@@ -0,0 +1,383 @@
/**
* RFC 2136 Dynamic DNS Provider Adapter
*
* Manages DNS records via RFC 2136 dynamic updates using the nsupdate CLI tool.
* Compatible with BIND, PowerDNS, Windows DNS, and any RFC 2136-compliant server.
*
* Capabilities: create-record, delete-record, resolve, credentials
* Not supported: logs, restart, update-check, list-records, zones
*/
const { execFile } = require('child_process');
const { promisify } = require('util');
const dns = require('dns');
const os = require('os');
const path = require('path');
const fs = require('fs');
const execFileAsync = promisify(execFile);
const BaseDNSProvider = require('./base');
const CAPABILITIES = ['create-record', 'delete-record', 'resolve', 'credentials'];
const DEFAULT_PORT = 53;
const DEFAULT_TSIG_ALGORITHM = 'hmac-sha256';
const NSUPDATE_TIMEOUT_MS = 15000;
class RFC2136Provider extends BaseDNSProvider {
static providerId = 'rfc2136';
static displayName = 'RFC 2136 (Dynamic DNS)';
constructor(config, ctx) {
super(config, ctx);
this.providerId = 'rfc2136';
this.displayName = 'RFC 2136 (Dynamic DNS)';
// Core config
this.server = config.server || null;
this.port = config.port || DEFAULT_PORT;
this.zone = config.zone || null;
// TSIG authentication
this.tsigAlgorithm = config.tsigAlgorithm || DEFAULT_TSIG_ALGORITHM;
this.tsigKeyName = config.tsigKeyName || null;
this.tsigSecret = config.tsigSecret || null;
// Resolve credentials from credential manager if available
if (ctx && ctx.credentialManager) {
if (!this.tsigKeyName && ctx.credentialManager.get) {
this.tsigKeyName = ctx.credentialManager.get('rfc2136_tsigKeyName') || null;
}
if (!this.tsigSecret && ctx.credentialManager.get) {
this.tsigSecret = ctx.credentialManager.get('rfc2136_tsigSecret') || null;
}
}
// Logger shorthand
this._log = ctx && ctx.log ? ctx.ctx : null;
}
// ── Logging helper ────────────────────────────────────────────────────────
_log(level, message, meta) {
if (this.ctx && this.ctx.log && typeof this.ctx.log[level] === 'function') {
this.ctx.log[level](`[rfc2136] ${message}`, meta || {});
}
}
// ── Capabilities ──────────────────────────────────────────────────────────
supportsCapability(cap) {
return CAPABILITIES.includes(cap);
}
getCapabilities() {
return [...CAPABILITIES];
}
// ── Config validation ─────────────────────────────────────────────────────
validateConfig() {
const errors = [];
if (!this.server) errors.push('Missing required config: server');
if (!this.zone) errors.push('Missing required config: zone');
return { valid: errors.length === 0, errors };
}
// ── Helpers ───────────────────────────────────────────────────────────────
/**
* Ensure a domain name ends with a trailing dot (FQDN for nsupdate).
*/
_ensureFqdn(domain) {
if (!domain) return domain;
return domain.endsWith('.') ? domain : `${domain}.`;
}
/**
* Build the common nsupdate header lines (server, zone, key).
*/
_buildHeader() {
const lines = [];
lines.push(`server ${this.server} ${this.port}`);
lines.push(`zone ${this.zone}`);
if (this.tsigKeyName && this.tsigSecret) {
lines.push(`key ${this.tsigAlgorithm}:${this.tsigKeyName} ${this.tsigSecret}`);
}
return lines;
}
/**
* Execute an nsupdate script and return { stdout, stderr }.
* Writes commands to a temporary file and runs `nsupdate <file>`.
*/
async _runNsupdate(commands) {
const script = commands.join('\n') + '\n';
const tmpFile = path.join(os.tmpdir(), `nsupdate-${Date.now()}-${Math.random().toString(36).slice(2, 8)}.cmd`);
try {
await fs.promises.writeFile(tmpFile, script, { mode: 0o600 });
this._log('debug', `Executing nsupdate script`, { script: script.trim() });
const { stdout, stderr } = await execFileAsync('nsupdate', [tmpFile], {
timeout: NSUPDATE_TIMEOUT_MS,
maxBuffer: 1024 * 1024,
});
this._log('debug', 'nsupdate completed', { stdout: (stdout || '').trim(), stderr: (stderr || '').trim() });
if (stderr && stderr.toLowerCase().includes('refused')) {
throw new Error(`nsupdate refused: ${stderr.trim()}`);
}
if (stderr && stderr.toLowerCase().includes('failed')) {
throw new Error(`nsupdate failed: ${stderr.trim()}`);
}
return { stdout: (stdout || '').trim(), stderr: (stderr || '').trim() };
} catch (err) {
if (err.code === 'ENOENT') {
throw new Error('nsupdate command not found. Install bind9utils (Debian/Ubuntu) or bind-utils (RHEL/CentOS).');
}
throw err;
} finally {
try { await fs.promises.unlink(tmpFile); } catch (_) { /* ignore */ }
}
}
// ── Authenticate ──────────────────────────────────────────────────────────
/**
* Verify nsupdate is available and optionally test connectivity.
* Runs a minimal nsupdate with just "show" (no-op) to confirm the tool works.
*/
async authenticate() {
const validation = this.validateConfig();
if (!validation.valid) {
throw new Error(`RFC 2136 config invalid: ${validation.errors.join('; ')}`);
}
// Check nsupdate binary is available with a dry-run command set
const commands = [
...this._buildHeader(),
'show',
];
try {
const { stdout } = await this._runNsupdate(commands);
this._log('info', 'Authenticated to RFC 2136 server', { server: this.server, port: this.port });
return { success: true, server: this.server, port: this.port };
} catch (err) {
this._log('error', 'Authentication test failed', { error: err.message });
// If nsupdate is missing, rethrow immediately
if (err.message.includes('not found')) throw err;
// Otherwise, the server might be unreachable but the tool works — return partial
return { success: false, error: err.message, server: this.server };
}
}
// ── Create Record ─────────────────────────────────────────────────────────
/**
* Create (add) a DNS record via RFC 2136 UPDATE.
*
* @param {Object} params
* @param {string} params.domain - Record name (e.g. "www.example.com")
* @param {string} params.zone - Zone name (overrides constructor zone)
* @param {string} params.type - Record type (A, AAAA, CNAME, TXT, etc.)
* @param {string} params.value - Record value
* @param {number} [params.ttl=300] - TTL in seconds
*/
async createRecord({ domain, zone, type, value, ttl }) {
const effectiveZone = zone || this.zone;
const effectiveTtl = ttl || 300;
const fqdn = this._ensureFqdn(domain);
const commands = [
`server ${this.server} ${this.port}`,
`zone ${effectiveZone}`,
];
if (this.tsigKeyName && this.tsigSecret) {
commands.push(`key ${this.tsigAlgorithm}:${this.tsigKeyName} ${this.tsigSecret}`);
}
commands.push(`update add ${fqdn} ${effectiveTtl} ${type} ${value}`);
commands.push('show');
commands.push('send');
this._log('info', 'Creating DNS record', { domain: fqdn, type, value, ttl: effectiveTtl });
const result = await this._runNsupdate(commands);
return {
success: true,
action: 'create-record',
domain: fqdn,
type,
value,
ttl: effectiveTtl,
zone: effectiveZone,
raw: result.stdout,
};
}
// ── Delete Record ─────────────────────────────────────────────────────────
/**
* Delete a DNS record via RFC 2136 UPDATE.
*
* @param {Object} params
* @param {string} params.domain - Record name
* @param {string} params.type - Record type
* @param {string} [params.value] - Optional specific value to match
*/
async deleteRecord({ domain, type, value }) {
const effectiveZone = this.zone;
const fqdn = this._ensureFqdn(domain);
const commands = [
`server ${this.server} ${this.port}`,
`zone ${effectiveZone}`,
];
if (this.tsigKeyName && this.tsigSecret) {
commands.push(`key ${this.tsigAlgorithm}:${this.tsigKeyName} ${this.tsigSecret}`);
}
// "update delete" with value removes that specific RR;
// without value it removes all RRs of that type for the name.
const deleteClause = value
? `update delete ${fqdn} ${type} ${value}`
: `update delete ${fqdn} ${type}`;
commands.push(deleteClause);
commands.push('show');
commands.push('send');
this._log('info', 'Deleting DNS record', { domain: fqdn, type, value: value || '(all)' });
const result = await this._runNsupdate(commands);
return {
success: true,
action: 'delete-record',
domain: fqdn,
type,
value: value || null,
zone: effectiveZone,
raw: result.stdout,
};
}
// ── Resolve Records ───────────────────────────────────────────────────────
/**
* Resolve DNS records for a domain.
* First attempts dig against the configured server, then falls back to Node dns module.
*
* @param {Object} params
* @param {string} params.domain - Domain to resolve
* @param {string} [params.zone] - Zone (unused for resolution, kept for interface consistency)
* @param {string} [params.type='A'] - Record type to query
*/
async resolveRecords({ domain, zone, type }) {
const queryType = type || 'A';
const fqdn = domain.endsWith('.') ? domain : domain;
// Strategy 1: Use dig against the configured RFC 2136 server
try {
const { stdout } = await execFileAsync('dig', [
`@${this.server}`,
'-p', String(this.port),
fqdn,
queryType,
'+short',
'+time=5',
'+tries=1',
], { timeout: 10000 });
const records = stdout
.split('\n')
.map(line => line.trim())
.filter(Boolean);
if (records.length > 0) {
this._log('debug', `Resolved ${fqdn} ${queryType} via dig`, { records });
return {
domain: fqdn,
type: queryType,
records: records.map(r => ({ value: r, type: queryType })),
source: 'dig',
server: this.server,
};
}
} catch (err) {
this._log('warn', 'dig resolution failed, falling back to Node dns', { error: err.message });
}
// Strategy 2: Fallback to Node.js built-in resolver
try {
const resolver = new dns.Resolver();
resolver.setServers([this.server]);
const resolveMethod = this._getResolveMethod(queryType);
const resolveAsync = promisify(resolver[resolveMethod]).bind(resolver);
const results = await resolveAsync(fqdn);
const records = Array.isArray(results) ? results : [results];
this._log('debug', `Resolved ${fqdn} ${queryType} via Node dns`, { records });
return {
domain: fqdn,
type: queryType,
records: records.map(r => ({ value: String(r), type: queryType })),
source: 'node-dns',
server: this.server,
};
} catch (err) {
this._log('warn', 'Node dns resolution also failed', { error: err.message });
return {
domain: fqdn,
type: queryType,
records: [],
source: 'none',
server: this.server,
error: err.message,
};
}
}
/**
* Map record type to the Node dns resolver method name.
*/
_getResolveMethod(type) {
const map = {
A: 'resolve4',
AAAA: 'resolve6',
CNAME: 'resolveCname',
MX: 'resolveMx',
TXT: 'resolveTxt',
NS: 'resolveNs',
SOA: 'resolveSoa',
SRV: 'resolveSrv',
PTR: 'reverse',
};
return map[(type || '').toUpperCase()] || 'resolve4';
}
// ── Shutdown ──────────────────────────────────────────────────────────────
async shutdown() {
this._log('info', 'RFC 2136 provider shutting down');
}
}
// Expose providerId on the prototype so the registry's auto-discover can detect it
RFC2136Provider.prototype.providerId = 'rfc2136';
module.exports = RFC2136Provider;
+507
View File
@@ -0,0 +1,507 @@
/**
* Technitium DNS Server Provider Adapter
*
* Wraps Technitium-specific DNS logic into the standard adapter interface.
* Uses the Technitium HTTP API (default port 5380) for all operations.
*/
const BaseDNSProvider = require('./base');
const SESSION_TTL_MS = 24 * 60 * 60 * 1000; // 24-hour token lifetime
class TechnitiumDNSProvider extends BaseDNSProvider {
constructor(config, ctx) {
super(config, ctx);
this.providerId = 'technitium';
this.displayName = 'Technitium DNS Server';
this.serverIp = config.serverIp;
this.serverPort = config.serverPort || 5380;
this.dnsId = config.dnsId || null;
// Token state
this.token = null;
this.tokenExpiry = null;
}
// ---------------------------------------------------------------------------
// Capabilities
// ---------------------------------------------------------------------------
static CAPABILITIES = [
'create-record',
'delete-record',
'resolve',
'list-records',
'logs',
'restart',
'update-check',
'credentials',
'zones'
];
supportsCapability(cap) {
return TechnitiumDNSProvider.CAPABILITIES.includes(cap);
}
getCapabilities() {
return [...TechnitiumDNSProvider.CAPABILITIES];
}
// ---------------------------------------------------------------------------
// Helpers
// ---------------------------------------------------------------------------
/** Build the base URL for this server */
_baseUrl() {
return `http://${this.serverIp}:${this.serverPort}`;
}
/** Build a full API URL with query-string params */
_buildUrl(apiPath, params = {}) {
const qs = new URLSearchParams(params).toString();
return `${this._baseUrl()}${apiPath}${qs ? '?' + qs : ''}`;
}
/** Ensure we have a valid token; throws on failure */
async _requireToken() {
// Re-use existing token if still valid
if (this.token && this.tokenExpiry && new Date() < new Date(this.tokenExpiry)) {
return this.token;
}
const result = await this.authenticate();
if (!result.success) {
const err = new Error('No valid DNS token available. ' + (result.error || ''));
err.statusCode = 401;
throw err;
}
return this.token;
}
// ---------------------------------------------------------------------------
// Authentication
// ---------------------------------------------------------------------------
/**
* Authenticate against the Technitium server.
* Checks per-server credentials first (dns.{dnsId}.readonly.username),
* then falls back to global credentials (dns.username).
*
* Stores token + expiry on success.
*/
async authenticate() {
const { credentialManager, log } = this.ctx;
// Try per-server credentials first
if (this.dnsId) {
for (const role of ['readonly', 'admin']) {
try {
const username = await credentialManager.retrieve(`dns.${this.dnsId}.${role}.username`);
const password = await credentialManager.retrieve(`dns.${this.dnsId}.${role}.password`);
if (username && password) {
const result = await this._doLogin(username, password);
if (result.success) return result;
}
} catch (err) {
log.error('technitium', `Per-server ${role} credential error`, {
dnsId: this.dnsId,
error: err.message
});
}
}
}
// Fall back to global credentials
try {
const username = await credentialManager.retrieve('dns.username');
const password = await credentialManager.retrieve('dns.password');
if (username && password) {
return await this._doLogin(username, password);
}
} catch (err) {
log.error('technitium', 'Global credential error', { error: err.message });
}
return {
success: false,
error: 'No DNS credentials configured. Please set up credentials via /api/dns/credentials'
};
}
/**
* Perform the actual login POST to Technitium.
* Stores token on success.
*/
async _doLogin(username, password) {
const { fetchT, log } = this.ctx;
try {
const params = new URLSearchParams({
user: username,
pass: password,
includeInfo: 'false'
});
const url = `${this._baseUrl()}/api/user/login?${params.toString()}`;
const response = await fetchT(url, {
method: 'POST',
headers: {
'Accept': 'application/json',
'Content-Type': 'application/x-www-form-urlencoded'
}
});
const result = await response.json();
if (result.status === 'ok' && result.token) {
this.token = result.token;
this.tokenExpiry = new Date(Date.now() + SESSION_TTL_MS).toISOString();
log.info('technitium', 'DNS token obtained', {
server: this.serverIp,
expires: this.tokenExpiry
});
return { success: true, token: this.token };
}
return { success: false, error: result.errorMessage || 'Login failed' };
} catch (error) {
log.error('technitium', 'Login error', { error: error.message });
return { success: false, error: error.message };
}
}
// ---------------------------------------------------------------------------
// Record Management
// ---------------------------------------------------------------------------
/**
* Create (or overwrite) a DNS record.
* GET /api/zones/records/add?token=...&domain=...&zone=...&type=...&ipAddress=...&ttl=...&overwrite=...
*/
async createRecord({ domain, zone, type, value, ttl, overwrite }) {
const token = await this._requireToken();
const { fetchT, log } = this.ctx;
const params = {
token,
domain,
zone,
type: type || 'A',
ipAddress: value,
ttl: String(ttl || 300),
overwrite: String(overwrite !== false)
};
try {
log.info('technitium', 'Creating DNS record', { domain, type, value });
const url = this._buildUrl('/api/zones/records/add', params);
const response = await fetchT(url, {
method: 'GET',
headers: { 'Accept': 'application/json' }
});
const result = await response.json();
if (result.status === 'ok') {
log.info('technitium', 'DNS record created', { domain, type, value });
return { success: true };
}
// If token expired, re-authenticate and retry once
if (result.errorMessage && result.errorMessage.toLowerCase().includes('token')) {
log.info('technitium', 'Token expired, re-authenticating');
this.token = null;
this.tokenExpiry = null;
const retryToken = await this._requireToken();
params.token = retryToken;
const retryUrl = this._buildUrl('/api/zones/records/add', params);
const retryResp = await fetchT(retryUrl, {
method: 'GET',
headers: { 'Accept': 'application/json' }
});
const retryResult = await retryResp.json();
if (retryResult.status === 'ok') {
return { success: true };
}
throw new Error(retryResult.errorMessage || 'Failed after token refresh');
}
throw new Error(result.errorMessage || 'Unknown error');
} catch (error) {
throw new Error(`Failed to create DNS record for ${domain}: ${error.message}`);
}
}
/**
* Delete a DNS record.
* GET /api/zones/records/delete?token=...&domain=...&type=... (+ ipAddress if value provided)
*/
async deleteRecord({ domain, type, value }) {
const token = await this._requireToken();
const { fetchT, log } = this.ctx;
const params = {
token,
domain,
type: type || 'A'
};
if (value) {
params.ipAddress = value;
}
try {
log.info('technitium', 'Deleting DNS record', { domain, type, value });
const url = this._buildUrl('/api/zones/records/delete', params);
const response = await fetchT(url, {
method: 'GET',
headers: { 'Accept': 'application/json' }
});
const result = await response.json();
if (result.status === 'ok') {
log.info('technitium', 'DNS record deleted', { domain, type, value });
return { success: true };
}
throw new Error(result.errorMessage || 'Unknown error');
} catch (error) {
throw new Error(`Failed to delete DNS record for ${domain}: ${error.message}`);
}
}
/**
* Resolve/query records for a domain in a zone.
* GET /api/zones/records/get?token=...&domain=...&zone=...&listZone=true
* Filters returned records by type if provided.
*/
async resolveRecords({ domain, zone, type }) {
const token = await this._requireToken();
const { fetchT, log } = this.ctx;
const params = {
token,
domain,
zone,
listZone: 'true'
};
try {
log.info('technitium', 'Resolving records', { domain, zone, type });
const url = this._buildUrl('/api/zones/records/get', params);
const response = await fetchT(url, {
method: 'GET',
headers: { 'Accept': 'application/json' }
});
const result = await response.json();
if (result.status !== 'ok') {
throw new Error(result.errorMessage || 'Failed to resolve records');
}
let records = (result.response && result.response.records) || [];
// Filter by type if specified
if (type) {
records = records.filter(r => r.type === type);
}
return { success: true, records };
} catch (error) {
throw new Error(`Failed to resolve records for ${domain}: ${error.message}`);
}
}
/**
* List all records in a zone.
* Delegates to resolveRecords with a wildcard domain.
*/
async listRecords({ zone }) {
return this.resolveRecords({ domain: zone, zone, type: null });
}
// ---------------------------------------------------------------------------
// Logs
// ---------------------------------------------------------------------------
/**
* Fetch and parse DNS query logs.
* 1. GET /api/logs/list to discover the latest log file
* 2. GET /api/logs/download?token=...&fileName=... to download it
* 3. Parse text format: [timestamp] [client:port] [protocol] QNAME: domain; QTYPE: type; QCLASS: class; RCODE: rcode; ANSWER: [answer]
*/
async getLogs({ limit, server } = {}) {
const token = await this._requireToken();
const { fetchT, log } = this.ctx;
const targetIp = server || this.serverIp;
const targetPort = this.serverPort;
const baseUrl = `http://${targetIp}:${targetPort}`;
try {
// Step 1: Get log file list
const listUrl = this._buildUrl('/api/logs/list', { token });
const listResp = await fetchT(listUrl.replace(this._baseUrl(), baseUrl), {
method: 'GET',
headers: { 'Accept': 'application/json' }
});
const listResult = await listResp.json();
if (listResult.status !== 'ok' || !listResult.response || !listResult.response.length) {
throw new Error(listResult.errorMessage || 'No log files found');
}
// Pick the latest log file (last entry)
const logFile = listResult.response[listResult.response.length - 1];
const fileName = logFile.name || logFile.fileName || logFile;
// Step 2: Download the log file
const downloadUrl = `${baseUrl}/api/logs/download?${new URLSearchParams({ token, fileName }).toString()}`;
const downloadResp = await fetchT(downloadUrl, {
method: 'GET'
});
const logText = await downloadResp.text();
// Step 3: Parse lines
const parsed = this._parseLogText(logText, limit);
return { success: true, logs: parsed };
} catch (error) {
log.error('technitium', 'Failed to fetch DNS logs', { error: error.message });
throw new Error(`Failed to get DNS logs: ${error.message}`);
}
}
/**
* Parse Technitium DNS log text format.
* Line format: [timestamp] [client:port] [protocol] QNAME: domain; QTYPE: type; QCLASS: class; RCODE: rcode; ANSWER: [answer]
*/
_parseLogText(text, limit) {
const lines = text.split('\n').filter(l => l.trim());
const parsed = [];
// Process newest first if we need to limit
const iterable = limit ? lines.slice(-limit).reverse() : lines;
for (const line of iterable) {
try {
const entry = {};
// Extract timestamp: [2024-01-15 10:30:45]
const tsMatch = line.match(/\[([^\]]+)\]/);
if (tsMatch) entry.timestamp = tsMatch[1];
// Extract client:port: [192.168.1.100:12345]
const clientMatch = line.match(/\[([^\]]+:\d+)\]/g);
if (clientMatch && clientMatch.length >= 2) {
entry.client = clientMatch[1].replace(/\[|\]/g, '');
}
// Extract protocol: [UDP] or [TCP]
const protoMatch = line.match(/\]\s*\[(UDP|TCP|DoH|DoT|DoH2)\]/i);
if (protoMatch) entry.protocol = protoMatch[1];
// Extract key-value pairs: QNAME: value; QTYPE: value; etc.
const kvPattern = /(\w+):\s*([^;]+)/g;
let match;
while ((match = kvPattern.exec(line)) !== null) {
const key = match[1];
const val = match[2].trim();
if (['QNAME', 'QTYPE', 'QCLASS', 'RCODE'].includes(key)) {
entry[key.toLowerCase()] = val;
} else if (key === 'ANSWER') {
entry.answer = val;
}
}
entry.raw = line;
parsed.push(entry);
} catch {
// Skip unparseable lines
}
}
return parsed;
}
// ---------------------------------------------------------------------------
// Server Management
// ---------------------------------------------------------------------------
/**
* Restart the DNS server.
* POST /api/admin/restart?token=...
* Requires admin credentials.
*/
async restartServer({ server } = {}) {
const token = await this._requireToken();
const { fetchT, log } = this.ctx;
try {
log.info('technitium', 'Restarting DNS server', { server: this.serverIp });
const url = this._buildUrl('/api/admin/restart', { token });
const response = await fetchT(url, {
method: 'POST',
headers: { 'Accept': 'application/json' }
});
const result = await response.json();
if (result.status === 'ok') {
log.info('technitium', 'DNS server restart initiated');
return { success: true, message: 'Server restart initiated' };
}
throw new Error(result.errorMessage || 'Restart failed');
} catch (error) {
log.error('technitium', 'DNS restart error', { error: error.message });
throw new Error(`Failed to restart DNS server: ${error.message}`);
}
}
/**
* Check for DNS server updates.
* GET /api/user/checkForUpdate?token=...
*/
async checkUpdate({ server } = {}) {
const token = await this._requireToken();
const { fetchT, log } = this.ctx;
try {
log.info('technitium', 'Checking for DNS server update', { server: this.serverIp });
const url = this._buildUrl('/api/user/checkForUpdate', { token });
const response = await fetchT(url, {
method: 'GET',
headers: { 'Accept': 'application/json' }
});
const result = await response.json();
if (result.status === 'ok') {
return {
success: true,
updateAvailable: !!(result.response && result.response.updateAvailable),
latestVersion: (result.response && result.response.latestVersion) || null,
currentVersion: (result.response && result.response.currentVersion) || null,
response: result.response
};
}
throw new Error(result.errorMessage || 'Update check failed');
} catch (error) {
log.error('technitium', 'Update check error', { error: error.message });
throw new Error(`Failed to check for updates: ${error.message}`);
}
}
// ---------------------------------------------------------------------------
// Config Validation
// ---------------------------------------------------------------------------
validateConfig() {
const errors = [];
if (!this.serverIp) {
errors.push('serverIp is required');
}
if (this.serverPort && (typeof this.serverPort !== 'number' || this.serverPort < 1 || this.serverPort > 65535)) {
errors.push('serverPort must be a valid port number (1-65535)');
}
return { valid: errors.length === 0, errors };
}
}
module.exports = TechnitiumDNSProvider;
+30 -27
View File
@@ -1,66 +1,70 @@
/**
* DashCaddy Error Handler Middleware
* Centralizes error handling logic to eliminate duplicate catch blocks
*
* Logging: this middleware uses the unified logError from src/utils/logging.js
* (same one src/app.js uses), so all errors go to one log file. The legacy
* ./error-logger.js and its ./error.log file have been retired.
*/
const path = require('path');
const { AppError } = require('./errors');
const { logError } = require('./error-logger');
const { LIMITS } = require('./constants');
const { logError: unifiedLogError, safeErrorMessage } = require('./src/utils/logging');
/**
* Async route handler wrapper
* Automatically catches errors and passes to error middleware
* Usage: app.get('/route', asyncHandler(async (req, res) => { ... }))
*/
function asyncHandler(fn) {
return (req, res, next) => {
Promise.resolve(fn(req, res, next)).catch(next);
};
}
const ERROR_LOG_FILE = path.join(__dirname, 'error.log');
const MAX_ERROR_LOG_SIZE = LIMITS.ERROR_LOG_SIZE;
/**
* Global error handling middleware
* MUST be registered after all routes in server.js
*/
function errorMiddleware(err, req, res, next) {
// Log all errors with request context
logError(req.path, err, {
method: req.method,
ip: req.ip,
userId: req.user?.id,
body: req.body
});
// Log all errors with request context (unified, same file the rest of the app uses)
unifiedLogError(
ERROR_LOG_FILE,
MAX_ERROR_LOG_SIZE,
req.path,
err,
{
method: req.method,
ip: req.ip,
userId: req.user?.id,
body: req.body
}
).catch(e => console.error('Failed to write to error log:', e.message));
// Determine if this is an operational error (AppError) or programming error
const isOperational = err.isOperational || err instanceof AppError;
// Status code
const statusCode = err.statusCode || 500;
// Error code (DC-XXX format)
const code = err.code || `DC-${statusCode}`;
// Build response
const response = {
success: false,
error: isOperational ? err.message : 'Internal server error',
error: isOperational ? safeErrorMessage(err) : 'Internal server error',
code
};
// Add optional fields if present
if (err.requiresTotp) response.requiresTotp = true;
if (err.retryAfter) response.retryAfter = err.retryAfter;
if (err.field) response.field = err.field;
if (err.resource) response.resource = err.resource;
if (err.details && Object.keys(err.details).length > 0) response.details = err.details;
// Development mode: include stack trace
if (process.env.NODE_ENV === 'development') {
response.stack = err.stack;
}
// Send response
res.status(statusCode).json(response);
// For non-operational errors, log as fatal
if (!isOperational) {
console.error('FATAL: Non-operational error detected', {
@@ -81,7 +85,6 @@ function notFoundHandler(req, res, next) {
}
module.exports = {
asyncHandler,
errorMiddleware,
notFoundHandler
};
-135
View File
@@ -1,135 +0,0 @@
// Error Logger Utility
// Centralized error logging with rotation and request context tracking
const fsp = require('fs').promises;
const path = require('path');
const { LIMITS } = require('./constants');
const ERROR_LOG_FILE = path.join(__dirname, 'error.log');
const MAX_ERROR_LOG_SIZE = LIMITS.ERROR_LOG_SIZE;
/**
* Check if file exists
*/
async function exists(filepath) {
try {
await fsp.access(filepath);
return true;
} catch {
return false;
}
}
/**
* Log error with context and rotation
* @param {string} context - Where the error occurred
* @param {Error|string} error - The error to log
* @param {Object} additionalInfo - Additional context (req, etc.)
*/
async function logError(context, error, additionalInfo = {}) {
const timestamp = new Date().toISOString();
// Extract request context if a request object is provided
const requestContext = extractRequestContext(additionalInfo.req);
if (additionalInfo.req) {
delete additionalInfo.req; // Remove req to avoid circular refs
}
const logEntry = {
timestamp,
context,
...requestContext,
error: {
message: error.message || error,
stack: error.stack,
code: error.code
},
...additionalInfo
};
// Format log line with request context
const contextInfo = Object.keys(requestContext).length > 0
? `\nRequest Context: ${JSON.stringify(requestContext, null, 2)}`
: '';
const logLine = `[${timestamp}] ${context}: ${error.message || error}\n${error.stack || ''}${contextInfo}\nAdditional Info: ${JSON.stringify(additionalInfo, null, 2)}\n${'='.repeat(80)}\n`;
try {
// Rotate log if it exceeds max size
await rotateLogIfNeeded();
await fsp.appendFile(ERROR_LOG_FILE, logLine);
} catch (e) {
console.error('Failed to write to error log', e.message);
}
}
/**
* Extract request context from Express request object
*/
function extractRequestContext(req) {
if (!req) return {};
const clientIP = req.ip || req.socket?.remoteAddress || '';
return {
requestId: req.id,
ip: clientIP,
userAgent: req.get('user-agent'),
method: req.method,
path: req.path
};
}
/**
* Rotate log file if it exceeds max size
*/
async function rotateLogIfNeeded() {
try {
const stats = await fsp.stat(ERROR_LOG_FILE);
if (stats.size > MAX_ERROR_LOG_SIZE) {
const rotated = ERROR_LOG_FILE + '.1';
if (await exists(rotated)) {
await fsp.unlink(rotated);
}
await fsp.rename(ERROR_LOG_FILE, rotated);
}
} catch (_) {
// File may not exist yet, that's fine
}
}
/**
* Return a safe error message to the client without leaking internals
*/
function safeErrorMessage(error) {
const msg = error.message || String(error);
// Detect port conflict errors from Docker
const portMatch = msg.match(/exposing port TCP [^:]*:(\d+)/);
if (portMatch || msg.includes('port is already allocated') || msg.includes('ports are not available')) {
const port = portMatch ? portMatch[1] : 'requested';
return `Port ${port} is already in use. Please choose a different port or stop the conflicting service.`;
}
// Detect container not found errors
if (msg.includes('No such container')) {
return 'Container not found';
}
// Detect network errors
if (msg.includes('ECONNREFUSED') || msg.includes('ETIMEDOUT')) {
return 'Service unavailable';
}
// Generic safe message for unknown errors
if (process.env.NODE_ENV === 'production') {
return 'An error occurred. Please try again or contact support.';
}
// In development, show the actual error
return msg;
}
module.exports = {
logError,
safeErrorMessage
};
+3
View File
@@ -317,6 +317,9 @@ class LicenseManager {
*/
isExpired() {
if (!this.activation) return true;
// Lifetime licenses never expire
if (this.activation.lifetime || this.activation.durationDays === 0) return false;
if (!this.activation.expiresAt) return false; // No expiry set = lifetime
return Date.now() > new Date(this.activation.expiresAt).getTime();
}
+29
View File
@@ -277,9 +277,32 @@ module.exports = function configureMiddleware(app, {
}
// ── Public routes (bypass TOTP and JWT auth) ──
// Routes here are accessible without authentication. By default the
// monitoring/health-check endpoints are public so the dashboard can
// render widgets before the user logs in. Set MONITORING_PUBLIC=false
// (env var) or `monitoring: { public: false }` (config.json) to require
// auth for these — useful for internet-exposed deployments where
// CPU/memory/disk data is sensitive.
const MONITORING_PUBLIC = (() => {
if (process.env.MONITORING_PUBLIC === 'false') return false;
if (process.env.MONITORING_PUBLIC === 'true') return true;
// Default: check config.json if loaded
try {
const cfg = require('./src/config/site').siteConfig;
if (cfg && cfg.monitoring && typeof cfg.monitoring.public === 'boolean') {
return cfg.monitoring.public;
}
} catch { /* config not loaded yet, use default */ }
return true; // default: public (current behavior, dashboard needs it)
})();
const PUBLIC_ROUTES = [
{ path: '/health', exact: true },
{ path: '/health/live', exact: true },
{ path: '/health/ready', exact: true },
{ path: '/api/v1/health', exact: true },
{ path: '/api/v1/health/live', exact: true },
{ path: '/api/v1/health/ready', exact: true },
{ path: '/probe/', prefix: true },
{ path: '/api/v1/tailscale/', prefix: true },
{ path: '/api/v1/totp/config', exact: true, method: 'GET' },
@@ -305,6 +328,12 @@ module.exports = function configureMiddleware(app, {
{ path: '/api/v1/config', exact: true, method: 'GET' },
{ path: '/api/v1/services/status', exact: true, method: 'GET' },
{ path: '/api/v1/system/update-notify', exact: true, method: 'POST' },
// Monitoring endpoints — only public if MONITORING_PUBLIC is true
...(MONITORING_PUBLIC ? [
{ path: '/api/v1/monitoring/stats', exact: true, method: 'GET' },
{ path: '/api/v1/health-checks/status', exact: true, method: 'GET' },
] : []),
{ path: '/api/v1/version', exact: true, method: 'GET' },
];
function isPublicRoute(req) {
+501
View File
@@ -0,0 +1,501 @@
/**
* Notification Manager - Multi-provider notification delivery
* Supports Discord, Telegram, ntfy, and Email notifications
*/
const EventEmitter = require('events');
const fs = require('fs');
const path = require('path');
const nodemailer = require('nodemailer');
const DEFAULT_CONFIG = {
enabled: true,
providers: {
discord: { enabled: false, webhookUrl: '' },
telegram: { enabled: false, botToken: '', chatId: '' },
ntfy: { enabled: false, topic: '', serverUrl: 'https://ntfy.sh' },
email: { enabled: false, host: '', port: 587, to: '', from: '', username: '', password: '' }
},
events: {
'container-down': true,
'container-up': false,
'alert': true,
'backup-complete': true,
'backup-failed': true,
'update-available': true
}
};
class NotificationManager extends EventEmitter {
constructor(ctx) {
super();
this.ctx = ctx;
this.NOTIFICATIONS_FILE = ctx.NOTIFICATIONS_FILE;
this.log = ctx.log || console;
this.config = { ...DEFAULT_CONFIG };
this.lastSent = null;
this.history = [];
this.maxHistory = 100;
this.healthDaemonInterval = null;
this.healthState = new Map();
this._loadConfig();
}
/**
* Load config from file
*/
_loadConfig() {
try {
if (fs.existsSync(this.NOTIFICATIONS_FILE)) {
const data = JSON.parse(fs.readFileSync(this.NOTIFICATIONS_FILE, 'utf8'));
this.config = this._mergeConfig(DEFAULT_CONFIG, data);
}
} catch (error) {
this.log.error('notification', 'Failed to load config', { error: error.message });
}
}
/**
* Merge loaded config with defaults
*/
_mergeConfig(defaults, loaded) {
const result = { ...defaults };
for (const key of Object.keys(defaults)) {
if (loaded && typeof defaults[key] === 'object' && !Array.isArray(defaults[key])) {
result[key] = { ...defaults[key], ...loaded[key] };
} else if (loaded && loaded[key] !== undefined) {
result[key] = loaded[key];
}
}
return result;
}
/**
* Get current config (for API)
*/
getConfig() {
return this.config;
}
/**
* Save config to file
*/
async saveConfig() {
try {
const dir = path.dirname(this.NOTIFICATIONS_FILE);
if (!fs.existsSync(dir)) {
fs.mkdirSync(dir, { recursive: true });
}
fs.writeFileSync(this.NOTIFICATIONS_FILE, JSON.stringify(this.config, null, 2));
return true;
} catch (error) {
this.log.error('notification', 'Failed to save config', { error: error.message });
throw error;
}
}
/**
* Get notification history
*/
getHistory() {
return this.history.slice();
}
/**
* Clear notification history
*/
clearHistory() {
this.history = [];
}
/**
* Add entry to history
*/
_addToHistory(entry) {
this.history.unshift({
...entry,
timestamp: new Date().toISOString()
});
if (this.history.length > this.maxHistory) {
this.history = this.history.slice(0, this.maxHistory);
}
this.lastSent = new Date().toISOString();
}
/**
* Send notification via all enabled providers
*/
async send(event, data, type = 'info') {
if (!this.config.enabled) {
return { success: false, error: 'Notifications disabled' };
}
// Check if event is enabled
if (event && this.config.events && !this.config.events[event]) {
return { success: false, error: `Event ${event} not enabled` };
}
const results = [];
const providers = this.config.providers;
// Discord
if (providers.discord?.enabled && providers.discord?.webhookUrl) {
try {
const result = await this.sendDiscord(this._formatText(data, event), this._formatEmbed(data, event, type));
results.push({ provider: 'discord', ...result });
} catch (error) {
results.push({ provider: 'discord', success: false, error: error.message });
}
}
// Telegram
if (providers.telegram?.enabled && providers.telegram?.botToken && providers.telegram?.chatId) {
try {
const result = await this.sendTelegram(this._formatText(data, event));
results.push({ provider: 'telegram', ...result });
} catch (error) {
results.push({ provider: 'telegram', success: false, error: error.message });
}
}
// ntfy
if (providers.ntfy?.enabled && providers.ntfy?.topic) {
try {
const result = await this.sendNtfy(this._formatText(data, event), this._formatTitle(event));
results.push({ provider: 'ntfy', ...result });
} catch (error) {
results.push({ provider: 'ntfy', success: false, error: error.message });
}
}
// Email
if (providers.email?.enabled && providers.email?.host && providers.email?.to) {
try {
const result = await this.sendEmail(
this._formatTitle(event),
this._formatText(data, event)
);
results.push({ provider: 'email', ...result });
} catch (error) {
results.push({ provider: 'email', success: false, error: error.message });
}
}
const allSucceeded = results.every(r => r.success);
this._addToHistory({
title: this._formatTitle(event),
type,
event,
results
});
return { success: allSucceeded, results };
}
/**
* Send Discord webhook notification
*/
async sendDiscord(text, embed) {
const { webhookUrl } = this.config.providers.discord;
if (!webhookUrl) {
throw new Error('Discord webhook not configured');
}
const payload = {
content: text,
embeds: embed ? [embed] : []
};
const response = await this.ctx.fetchT(webhookUrl, {
method: 'POST',
headers: { 'Content-Type': 'application/json' },
body: JSON.stringify(payload)
});
if (!response.ok) {
throw new Error(`Discord API error: ${response.status}`);
}
return { success: true };
}
/**
* Send Telegram message
*/
async sendTelegram(text) {
const { botToken, chatId } = this.config.providers.telegram;
if (!botToken || !chatId) {
throw new Error('Telegram not configured');
}
const url = `https://api.telegram.org/bot${botToken}/sendMessage`;
const payload = {
chat_id: chatId,
text,
parse_mode: 'Markdown'
};
const response = await this.ctx.fetchT(url, {
method: 'POST',
headers: { 'Content-Type': 'application/json' },
body: JSON.stringify(payload)
});
const data = await response.json();
if (!data.ok) {
throw new Error(`Telegram error: ${data.description}`);
}
return { success: true };
}
/**
* Send ntfy notification
*/
async sendNtfy(text, title) {
const { serverUrl, topic } = this.config.providers.ntfy;
if (!topic) {
throw new Error('ntfy topic not configured');
}
const url = `${serverUrl.replace(/\/$/, '')}/${topic}`;
const response = await this.ctx.fetchT(url, {
method: 'POST',
headers: {
'Content-Type': 'text/plain',
'Title': title || 'DashCaddy',
'Priority': '3'
},
body: text
});
if (!response.ok) {
throw new Error(`ntfy error: ${response.status}`);
}
return { success: true };
}
/**
* Send email notification
*/
async sendEmail(subject, body) {
const { host, port, to, from, username, password, secure } = this.config.providers.email;
if (!host || !to) {
throw new Error('Email not configured');
}
// Create transporter
const transporter = nodemailer.createTransport({
host,
port: parseInt(port) || 587,
secure: !!secure,
auth: username ? {
user: username,
pass: password
} : undefined
});
// Send mail
await transporter.sendMail({
from: from || username,
to,
subject,
text: body,
html: `<pre style="font-family: monospace;">${body}</pre>`
});
return { success: true };
}
/**
* Send resource alert
*/
async sendAlert(alert) {
const text = this._formatAlertText(alert);
const embed = {
title: `⚠️ Resource Alert: ${alert.containerName}`,
color: this._getAlertColor(alert.alerts),
fields: alert.alerts.map(a => ({
name: a.type.toUpperCase(),
value: a.message,
inline: true
})),
footer: {
text: 'DashCaddy Resource Monitor'
},
timestamp: alert.timestamp
};
return this.send('alert', { ...alert, text, embed }, 'warning');
}
/**
* Send backup complete notification
*/
async sendBackupComplete(backup) {
const event = backup.status === 'success' ? 'backup-complete' : 'backup-failed';
const type = backup.status === 'success' ? 'success' : 'error';
const text = backup.status === 'success'
? `✅ Backup "${backup.name}" completed successfully`
: `❌ Backup "${backup.name}" failed: ${backup.error}`;
return this.send(event, { ...backup, text }, type);
}
/**
* Send service event notification (container up/down, deploy success/fail)
*/
async sendServiceEvent(event, service) {
const eventMap = {
'container-up': { type: 'success', text: `✅ Container "${service.containerName || service.name}" is now UP` },
'container-down': { type: 'error', text: `🔴 Container "${service.containerName || service.name}" is DOWN` },
'deploy-success': { type: 'success', text: `✅ "${service.name}" deployed successfully` },
'deploy-failed': { type: 'error', text: `❌ "${service.name}" deployment failed` },
'auto-restart': { type: 'warning', text: `🔄 Container "${service.containerName || service.name}" auto-restarted` }
};
const info = eventMap[event] || { type: 'info', text: `Service event: ${event}` };
return this.send(event, { ...service, text: info.text }, info.type);
}
// ===== Helper Methods =====
_formatTitle(event) {
const titles = {
'container-down': 'Container Down',
'container-up': 'Container Recovered',
'alert': 'Resource Alert',
'backup-complete': 'Backup Complete',
'backup-failed': 'Backup Failed',
'update-available': 'Update Available',
'test': 'Test Notification',
'auto-restart': 'Auto-Restart',
'deploy-success': 'Deployment Success',
'deploy-failed': 'Deployment Failed'
};
return titles[event] || 'DashCaddy Notification';
}
_formatText(data, event) {
if (typeof data === 'string') return data;
return data.text || data.message || this._formatTitle(event);
}
_formatEmbed(data, event, type) {
if (typeof data === 'string') return null;
if (data.embed) return data.embed;
return {
title: this._formatTitle(event),
description: data.text || data.message || '',
color: this._getTypeColor(type),
timestamp: new Date().toISOString()
};
}
_formatAlertText(alert) {
const lines = [
`**${alert.containerName}**`,
'',
...alert.alerts.map(a => `${a.message}`)
];
return lines.join('\n');
}
_getAlertColor(alerts) {
if (alerts.some(a => a.severity === 'critical')) return 15158332; // Red
if (alerts.some(a => a.severity === 'warning')) return 16776960; // Yellow
return 3447003; // Blue
}
_getTypeColor(type) {
const colors = {
success: 3066993, // Green
error: 15158332, // Red
warning: 16776960, // Yellow
info: 3447003 // Blue
};
return colors[type] || colors.info;
}
// ===== Health Check Daemon =====
startHealthDaemon() {
if (this.healthDaemonInterval) return;
const interval = (this.config.healthCheck?.intervalMinutes || 5) * 60 * 1000;
this.healthDaemonInterval = setInterval(() => {
this.checkHealth().catch(err => {
this.log.error('notification', 'Health check failed', { error: err.message });
});
}, interval);
this.log.info('notification', 'Health daemon started', { intervalMinutes: this.config.healthCheck?.intervalMinutes });
}
stopHealthDaemon() {
if (this.healthDaemonInterval) {
clearInterval(this.healthDaemonInterval);
this.healthDaemonInterval = null;
this.log.info('notification', 'Health daemon stopped');
}
}
async checkHealth() {
if (!this.config.healthCheck?.enabled || !this.ctx.docker) {
return { checked: false };
}
try {
const containers = await this.ctx.docker.listContainers({ all: true });
const previousState = new Map(this.healthState);
for (const container of containers) {
const name = container.Names[0]?.replace(/^\//, '') || container.Id.substring(0, 12);
const wasDown = previousState.get(container.Id) === false;
const isDown = container.State !== 'running';
this.healthState.set(container.Id, isDown);
if (wasDown && !isDown) {
// Container recovered
await this.sendServiceEvent('container-up', {
containerId: container.Id,
containerName: name,
state: container.State
});
} else if (!wasDown && isDown) {
// Container went down
await this.sendServiceEvent('container-down', {
containerId: container.Id,
containerName: name,
state: container.State
});
}
}
// Update last check time
this.config.healthCheck = this.config.healthCheck || {};
this.config.healthCheck.lastCheck = new Date().toISOString();
await this.saveConfig();
return {
checked: true,
containersMonitored: containers.length,
lastCheck: this.config.healthCheck.lastCheck
};
} catch (error) {
this.log.error('notification', 'Health check error', { error: error.message });
throw error;
}
}
getHealthState() {
return new Map(this.healthState);
}
}
module.exports = NotificationManager;
+1 -1
View File
@@ -1,6 +1,6 @@
{
"name": "dashcaddy-api",
"version": "1.6.0",
"version": "1.13.3",
"description": "DashCaddy API server - Dashboard backend for Docker, Caddy & DNS management",
"main": "server.js",
"scripts": {
+21
View File
@@ -3,6 +3,7 @@
// All paths can be overridden via environment variables.
const path = require('path');
const fs = require('fs');
const isWindows = process.platform === 'win32';
// Base directories
@@ -34,6 +35,8 @@ const paths = {
caCertDir: path.join(CADDY_SITES, 'ca'),
pkiRootCert: path.join(CADDY_PKI, 'root.crt'),
pkiIntermediateCert: path.join(CADDY_PKI, 'intermediate.crt'),
generatedCertsDir: path.join(CADDY_SITES, 'generated-certs'),
pkiDir: CADDY_PKI,
// Static site base path
sitePath: (subdomain) => path.join(CADDY_SITES, subdomain),
@@ -41,6 +44,24 @@ const paths = {
// Docker data path for app volumes
appData: (appName) => path.join(DOCKER_DATA, appName),
// In-container paths (used by self-updater and Docker deployments)
// Override via env vars for custom Docker layouts
containerUpdatesDir: process.env.DASHCADDY_UPDATES_DIR || '/app/updates',
containerFrontendDir: process.env.DASHCADDY_FRONTEND_DIR || '/app/dashboard',
containerAssetsDir: process.env.ASSETS_DIR || '/app/assets',
// Asset path resolution — supports both Docker (single file mount) and
// consolidated data directory layouts
resolveAssetsPath: (envPath) => {
if (envPath) return envPath;
// Standard Docker mount: /app/assets (volume-mounted)
if (fs.existsSync('/app/assets')) return '/app/assets';
// Consolidated data directory: /app/data/assets
if (fs.existsSync(path.join(CADDY_BASE, 'assets'))) return path.join(CADDY_BASE, 'assets');
// Fall back to /app/assets even if it doesn't exist (will create on write)
return '/app/assets';
},
// Log digest directory
digestDir: process.env.DIGEST_DIR || path.join(CADDY_BASE, 'digests'),
+18 -2
View File
@@ -226,7 +226,23 @@ const server = http.createServer(async (req, res) => {
json(res, 404, { error: 'Not found' });
});
server.listen(PORT, '0.0.0.0', () => {
console.log(`[Pylon] ${PYLON_NAME} listening on port ${PORT}`);
const PYLON_PORT = parseInt(process.env.PYLON_PORT, 10) || 7842;
const PYLON_HOST = process.env.PYLON_HOST || '0.0.0.0';
server.listen(PYLON_PORT, PYLON_HOST, () => {
console.log(`[Pylon] ${PYLON_NAME} listening on ${PYLON_HOST}:${PYLON_PORT}`);
if (API_KEY) console.log('[Pylon] API key authentication enabled');
});
// Graceful shutdown — drain connections, then exit
const shutdown = (signal) => {
console.log(`[Pylon] ${signal} received, draining...`);
server.close(() => {
console.log('[Pylon] HTTP server closed');
process.exit(0);
});
// Force exit after 5s if connections don't drain
setTimeout(() => process.exit(0), 5000).unref();
};
process.on('SIGTERM', () => shutdown('SIGTERM'));
process.on('SIGINT', () => shutdown('SIGINT'));
+152 -3
View File
@@ -16,6 +16,7 @@ const STATS_FILE = process.env.STATS_FILE || path.join(__dirname, 'container-sta
const STATS_HOURLY_FILE = process.env.STATS_HOURLY_FILE || path.join(__dirname, 'container-stats-hourly.json');
const STATS_DAILY_FILE = process.env.STATS_DAILY_FILE || path.join(__dirname, 'container-stats-daily.json');
const ALERT_CONFIG_FILE = process.env.ALERT_CONFIG_FILE || path.join(__dirname, 'alert-config.json');
const ALERT_HISTORY_FILE = process.env.ALERT_HISTORY_FILE || path.join(__dirname, 'alert-history.json');
const STATS_RETENTION_HOURS = parseInt(process.env.STATS_RETENTION_HOURS || '168', 10); // 7 days raw
const STATS_HOURLY_RETENTION_DAYS = parseInt(process.env.STATS_HOURLY_RETENTION_DAYS || '30', 10); // 30 days hourly
const STATS_DAILY_RETENTION_DAYS = parseInt(process.env.STATS_DAILY_RETENTION_DAYS || '365', 10); // 365 days daily
@@ -35,11 +36,21 @@ class ResourceMonitor extends EventEmitter {
this.dailyHistory = new Map(); // containerId -> { name, samples: [...] } (daily avg, 365d)
this.alerts = new Map(); // containerId -> alert config
this.lastAlerts = new Map(); // containerId -> last alert timestamp
this.alertHistory = []; // alert history entries
this.notificationManager = null;
this.loadStats();
this.loadHourlyStats();
this.loadDailyStats();
this.loadAlertConfig();
this.loadAlertHistory();
}
/**
* Set the notification manager for sending alerts
*/
setNotificationManager(nm) {
this.notificationManager = nm;
}
/**
@@ -285,20 +296,58 @@ class ResourceMonitor extends EventEmitter {
if (alerts.length > 0) {
this.lastAlerts.set(containerId, now);
this.emit('alert', {
// Add alert history entries
for (const alert of alerts) {
this.addAlertHistoryEntry({
id: `${containerId}-${Date.now()}-${alert.type}`,
timestamp: new Date().toISOString(),
containerId,
containerName,
type: alert.type,
metric: alert.type,
value: alert.value,
threshold: alert.threshold,
severity: alert.severity,
notified: !!this.notificationManager,
autoRestartTriggered: !!alertConfig.autoRestart
});
}
const alertPayload = {
containerId,
containerName,
timestamp: new Date().toISOString(),
alerts,
stats,
config: alertConfig
});
};
this.emit('alert', alertPayload);
// Send notification if manager is configured
if (this.notificationManager) {
this.notificationManager.sendAlert(alertPayload).catch(err => {
console.error('[ResourceMonitor] Failed to send alert notification:', err.message);
});
}
// Auto-restart if configured
if (alertConfig.autoRestart) {
this.restartContainer(containerId, containerName, alerts);
}
// Trigger bundled workflows for resource-alert
this.triggerWorkflows('resource-alert', {
containerId,
containerName,
alerts,
stats,
diskPercent: (stats.disk?.readBytes + stats.disk?.writeBytes) > 0
? Math.round((stats.disk.readBytes / (stats.disk.readBytes + stats.disk.writeBytes)) * 100)
: 0,
host: require('os').hostname()
});
}
}
@@ -318,11 +367,55 @@ class ResourceMonitor extends EventEmitter {
timestamp: new Date().toISOString(),
reason: alerts
});
// Send notification if manager is configured
if (this.notificationManager) {
this.notificationManager.send('auto-restart', {
containerId,
containerName,
timestamp: new Date().toISOString(),
reason: alerts
}).catch(err => {
console.error('[ResourceMonitor] Failed to send auto-restart notification:', err.message);
});
}
} catch (error) {
console.error(`[ResourceMonitor] Failed to restart ${containerName}:`, error.message);
}
}
/**
* Trigger bundled workflows for an event
*/
triggerWorkflows(eventType, eventData) {
if (!this.workflowEngine) {
console.log('[ResourceMonitor] Workflow engine not set, skipping workflow trigger');
return;
}
try {
this.workflowEngine.triggerForEvent(eventType, eventData)
.then(results => {
if (results && results.length > 0) {
console.log(`[ResourceMonitor] Triggered ${results.length} workflow(s) for ${eventType}`);
}
})
.catch(err => {
console.error('[ResourceMonitor] Workflow trigger error:', err.message);
});
} catch (error) {
console.error('[ResourceMonitor] Error triggering workflows:', error.message);
}
}
/**
* Set the workflow engine for triggering workflows
*/
setWorkflowEngine(workflowEngine) {
this.workflowEngine = workflowEngine;
console.log('[ResourceMonitor] Workflow engine configured');
}
/**
* Get current stats for a container
*/
@@ -430,6 +523,62 @@ class ResourceMonitor extends EventEmitter {
this.saveAlertConfig();
}
/**
* Get all alert configurations
*/
getAllAlertConfigs() {
const configs = {};
for (const [containerId, config] of this.alerts.entries()) {
configs[containerId] = config;
}
return configs;
}
/**
* Add entry to alert history
*/
addAlertHistoryEntry(entry) {
this.alertHistory.unshift(entry);
// Keep only last 1000 entries
if (this.alertHistory.length > 1000) {
this.alertHistory = this.alertHistory.slice(0, 1000);
}
this.saveAlertHistory();
}
/**
* Get alert history
*/
getAlertHistory(limit = 50) {
return this.alertHistory.slice(0, limit);
}
/**
* Load alert history from disk
*/
loadAlertHistory() {
try {
if (fs.existsSync(ALERT_HISTORY_FILE)) {
const data = JSON.parse(fs.readFileSync(ALERT_HISTORY_FILE, 'utf8'));
this.alertHistory = Array.isArray(data) ? data : [];
console.log(`[ResourceMonitor] Loaded ${this.alertHistory.length} alert history entries`);
}
} catch (error) {
console.error('[ResourceMonitor] Error loading alert history:', error.message);
}
}
/**
* Save alert history to disk
*/
saveAlertHistory() {
try {
fs.writeFileSync(ALERT_HISTORY_FILE, JSON.stringify(this.alertHistory, null, 2));
} catch (error) {
console.error('[ResourceMonitor] Error saving alert history:', error.message);
}
}
/**
* Cleanup old stats beyond retention period
*/
-114
View File
@@ -1,114 +0,0 @@
// Response Helpers
// Standardize API response format across all routes
const { HTTP_STATUS } = require('./constants');
/**
* Success response with data
*/
function success(res, data, statusCode = HTTP_STATUS.OK) {
return res.status(statusCode).json({
success: true,
...data
});
}
/**
* Success response with message
*/
function successMessage(res, message, statusCode = HTTP_STATUS.OK) {
return res.status(statusCode).json({
success: true,
message
});
}
/**
* Created response (201)
*/
function created(res, data) {
return res.status(HTTP_STATUS.CREATED).json({
success: true,
...data
});
}
/**
* No content response (204)
*/
function noContent(res) {
return res.status(HTTP_STATUS.NO_CONTENT).send();
}
/**
* Error response
*/
function error(res, message, statusCode = HTTP_STATUS.INTERNAL_ERROR) {
return res.status(statusCode).json({
success: false,
error: message
});
}
/**
* Validation error response (400)
*/
function validationError(res, message) {
return res.status(HTTP_STATUS.BAD_REQUEST).json({
success: false,
error: message
});
}
/**
* Unauthorized response (401)
*/
function unauthorized(res, message = 'Unauthorized') {
return res.status(HTTP_STATUS.UNAUTHORIZED).json({
success: false,
error: message
});
}
/**
* Forbidden response (403)
*/
function forbidden(res, message = 'Forbidden') {
return res.status(HTTP_STATUS.FORBIDDEN).json({
success: false,
error: message
});
}
/**
* Not found response (404)
*/
function notFound(res, message = 'Not found') {
return res.status(HTTP_STATUS.NOT_FOUND).json({
success: false,
error: message
});
}
/**
* Conflict response (409)
*/
function conflict(res, message) {
return res.status(HTTP_STATUS.CONFLICT).json({
success: false,
error: message
});
}
module.exports = {
success,
successMessage,
created,
noContent,
error,
validationError,
unauthorized,
forbidden,
notFound,
conflict
};
+18 -7
View File
@@ -197,8 +197,18 @@ module.exports = function({ docker, caddy, credentialManager, servicesStateManag
}
}
const container = await docker.client.createContainer(containerConfig);
await container.start();
let container;
try {
container = await docker.client.createContainer(containerConfig);
await container.start();
} catch (createErr) {
// If create fails with "no such image", wrap with user-friendly message
const errMsg = createErr?.message || String(createErr);
if (errMsg.includes('No such image') || errMsg.includes('no such image')) {
throw new Error(`[DC-201] Image pull succeeded but container creation failed — image may be corrupted: ${processedTemplate.docker.image}. ${errMsg}`);
}
throw createErr;
}
// Prune dangling images to prevent disk bloat
try {
@@ -306,7 +316,7 @@ module.exports = function({ docker, caddy, credentialManager, servicesStateManag
} else {
containerId = await deployContainer(appId, config, template);
log.info('deploy', 'Container deployed', { containerId });
await helpers.waitForHealthCheck(containerId, template.healthCheck, config.port || template.defaultPort);
await helpers.waitForHealthCheck(containerId, template.healthCheck, config.port || template.defaultPort, 30);
log.info('deploy', 'Container is healthy', { containerId });
}
@@ -316,7 +326,7 @@ module.exports = function({ docker, caddy, credentialManager, servicesStateManag
let dnsWarning = null;
if (config.createDns && !isSubdirectoryMode) {
try {
await ctx.dns.createRecord(config.subdomain, config.ip);
await ctx.dns.universalCreateRecord(config.subdomain, config.ip);
log.info('deploy', 'DNS record created', { domain: ctx.buildDomain(config.subdomain), ip: config.ip });
} catch (dnsError) {
await logError('app-deploy-dns', dnsError, { appId, subdomain: config.subdomain, ip: config.ip });
@@ -420,10 +430,11 @@ module.exports = function({ docker, caddy, credentialManager, servicesStateManag
res.json(response);
} catch (error) {
await logError('app-deploy', error, { appId, config });
log.error('deploy', 'Deployment failed', { appId, error: error.message });
try { await logError('app-deploy', error, { appId, config }); } catch (_) { /* logError failure should not mask original error */ }
const msg = error?.message || String(error || 'Unknown error');
log.error('deploy', 'Deployment failed', { appId, error: msg });
const template = ctx.APP_TEMPLATES[appId];
ctx.notification.send('deploymentFailed', 'Deployment Failed', `Failed to deploy **${template?.name || appId}**.\nError: ${error.message}`, 'error');
try { ctx.notification.send('deploymentFailed', 'Deployment Failed', `Failed to deploy **${template?.name || appId}**.\nError: ${msg}`, 'error'); } catch (_) {}
errorResponse(res, 500, ctx.safeErrorMessage(error));
}
}, 'apps-deploy'));
+4 -1
View File
@@ -379,9 +379,12 @@ module.exports = function({ docker, caddy, credentialManager, servicesStateManag
return content.slice(0, endIdx) + injection + content.slice(endIdx);
});
if (!result.success) {
if (!result.success && result.error !== 'No changes to apply') {
throw new Error(`[DC-303] Failed to add subpath config for ${subdomain}: ${result.error}`);
}
if (result.error === 'No changes to apply') {
log.info('caddy', 'Subpath config already exists, reusing', { subdomain });
}
}
/** Remove a subpath config block from between its markers in the Caddyfile. */
+13 -13
View File
@@ -25,7 +25,6 @@ module.exports = function(ctx) {
asyncHandler: ctx.asyncHandler,
errorResponse: ctx.errorResponse,
log: ctx.log,
// Additional context properties needed by routes
APP_TEMPLATES: ctx.APP_TEMPLATES,
TEMPLATE_CATEGORIES: ctx.TEMPLATE_CATEGORIES,
DIFFICULTY_LEVELS: ctx.DIFFICULTY_LEVELS,
@@ -40,26 +39,27 @@ module.exports = function(ctx) {
ctx: ctx
};
// Initialize helpers with dependencies (ctx is the Koa context)
const helpers = initHelpers({ ...deps, ctx });
// Mount sub-routes — pass full ctx so sub-routes can reference ctx.* properties
const subCtx = Object.assign({}, ctx, { helpers });
try { router.use('/deploy', initDeploy(subCtx)); }
catch(e) { (ctx.log || console).error('[apps] deploy routes init failed:', e.message); }
// Mount sub-routers at their prefix paths.
// Sub-modules define routes at '/' (root of their sub-router).
// Final paths: /api/v1/apps/deploy, /api/v1/apps/remove, /api/v1/apps/templates, etc.
try { router.use('/remove', initRemoval(subCtx)); }
catch(e) { (ctx.log || console).error('[apps] removal routes init failed:', e.message); }
try { router.use('/apps', initDeploy(subCtx)); }
catch(e) { (ctx.log || console).error('[apps] deploy routes init failed:', e.message, e.stack); }
try { router.use('/apps', initRemoval(subCtx)); }
catch(e) { (ctx.log || console).error('[apps] removal routes init failed:', e.message, e.stack); }
try { router.use('/apps', initTemplates(subCtx)); }
catch(e) { (ctx.log || console).error('[apps] templates routes init failed:', e.message); }
catch(e) { (ctx.log || console).error('[apps] templates routes init failed:', e.message, e.stack); }
try { router.use('/restore', initRestore(subCtx)); }
catch(e) { (ctx.log || console).error('[apps] restore routes init failed:', e.message); }
try { router.use('/apps', initRestore(Object.assign({}, subCtx, { backupManager: ctx.backupManager }))); }
catch(e) { (ctx.log || console).error('[apps] restore routes init failed:', e.message, e.stack); }
try { router.use('/compose', initCompose(subCtx)); }
catch(e) { (ctx.log || console).error('[apps] compose routes init failed:', e.message); }
try { router.use('/apps', initCompose(subCtx)); }
catch(e) { (ctx.log || console).error('[apps] compose routes init failed:', e.message, e.stack); }
return router;
};
+5 -10
View File
@@ -71,18 +71,13 @@ module.exports = function({
if (shouldDeleteContainer && subdomain && ctx.dns.getToken()) {
try {
const domain = ctx.buildDomain(subdomain);
const getResult = await ctx.dns.call(ctx.siteConfig.dnsServerIp, '/api/zones/records/get', {
token: ctx.dns.getToken(), domain, zone: ctx.siteConfig.tld.replace(/^\./, ''), listZone: 'true'
});
const resolveResult = await ctx.dns.universalResolveRecord(domain, 'A');
let recordIp = ip || 'localhost';
if (getResult.status === 'ok' && getResult.response?.records) {
const aRecord = getResult.response.records.find(r => r.type === 'A');
if (aRecord && aRecord.rData?.ipAddress) recordIp = aRecord.rData.ipAddress;
if (resolveResult) {
recordIp = resolveResult;
}
const dnsResult = await ctx.dns.call(ctx.siteConfig.dnsServerIp, '/api/zones/records/delete', {
token: ctx.dns.getToken(), domain, type: 'A', ipAddress: recordIp
});
results.dns = dnsResult.status === 'ok' ? 'deleted' : (dnsResult.errorMessage || 'failed');
await ctx.dns.universalDeleteRecord(domain, recordIp);
results.dns = 'deleted';
log.info('dns', 'DNS record removal', { result: results.dns });
} catch (error) {
results.dns = error.message;
+188 -1
View File
@@ -1,6 +1,10 @@
const express = require('express');
const path = require('path');
const fs = require('fs');
const { DOCKER } = require('../../constants');
const DEFAULT_BACKUP_DIR = process.env.BACKUP_DIR || path.join(__dirname, '..', 'backups');
/**
* Apps restore routes factory
* @param {Object} deps - Explicit dependencies
@@ -122,6 +126,180 @@ module.exports = function({ docker, caddy, servicesStateManager, asyncHandler, e
res.json({ success: true, services: status });
}, 'apps-restore-status'));
// ==================== POINT-IN-TIME RESTORE (BACKUP FILE BASED) ====================
// Get available backup files for a specific app
router.get('/:appId/backup-points', asyncHandler(async (req, res) => {
const { appId } = req.params;
const backupDir = DEFAULT_BACKUP_DIR;
const files = [];
try {
if (fs.existsSync(backupDir)) {
const entries = fs.readdirSync(backupDir, { withFileTypes: true });
for (const entry of entries) {
if (entry.isFile() && entry.name.endsWith('.backup')) {
try {
const nameWithoutExt = entry.name.replace('.backup', '');
const parts = nameWithoutExt.split('-');
const fileAppId = parts[0];
// Only include files for the requested app
if (fileAppId !== appId) continue;
const filepath = path.join(backupDir, entry.name);
const stats = fs.statSync(filepath);
const timestamp = parts.length > 1 ? parseInt(parts[parts.length - 1]) : stats.mtimeMs;
files.push({
name: entry.name,
appId: fileAppId,
size: stats.size,
sizeFormatted: formatBytes(stats.size),
timestamp: new Date(timestamp).toISOString(),
modified: stats.mtime.toISOString(),
path: filepath
});
} catch (err) {
// Skip malformed filenames
}
}
}
}
} catch (err) {
// Directory might not exist yet
}
// Sort by timestamp descending (newest first)
files.sort((a, b) => new Date(b.timestamp) - new Date(a.timestamp));
res.json({
success: true,
appId,
isBackupFile: true,
files,
total: files.length
});
}, 'apps-backup-points'));
// Revert a specific app to a backup file (point-in-time restore)
router.post('/:appId/revert/:filename', asyncHandler(async (req, res) => {
const { appId, filename } = req.params;
const { encryptionKey, restartContainers } = req.body || {};
// Security: prevent path traversal
if (filename.includes('..') || filename.includes('/') || filename.includes('\\')) {
return res.status(400).json({ success: false, error: 'Invalid filename' });
}
const filepath = path.join(DEFAULT_BACKUP_DIR, filename);
if (!fs.existsSync(filepath)) {
return res.status(404).json({ success: false, error: `Backup file not found: ${filename}` });
}
try {
// Read the backup file
let fileData = fs.readFileSync(filepath);
// Decrypt if needed
if (encryptionKey) {
try {
fileData = await backupManager.decryptBackup(fileData, encryptionKey);
} catch (err) {
return res.status(400).json({ success: false, error: 'Failed to decrypt backup: ' + err.message });
}
}
// Decompress
const backupData = await backupManager.decompressBackup(fileData);
// Extract to temp directory
const os = require('os');
const crypto = require('crypto');
const tempDir = path.join(os.tmpdir(), `dashcaddy-revert-${Date.now()}-${crypto.randomBytes(4).toString('hex')}`);
fs.mkdirSync(tempDir, { recursive: true });
try {
const tarPath = path.join(tempDir, 'backup.tar.gz');
fs.writeFileSync(tarPath, backupData);
const { execSync } = require('child_process');
try {
execSync(`cd "${tempDir}" && tar -xzf backup.tar.gz`, { stdio: 'pipe' });
} catch (tarErr) {
throw new Error('Failed to extract backup archive: ' + tarErr.message);
}
// Read manifest if present
let manifest = null;
const manifestPath = path.join(tempDir, 'manifest.json');
if (fs.existsSync(manifestPath)) {
try { manifest = JSON.parse(fs.readFileSync(manifestPath, 'utf8')); } catch (_) {}
}
// Read app-specific data
const appServicesPath = path.join(tempDir, 'services.json');
const appConfigPath = path.join(tempDir, 'config.json');
const appCredsPath = path.join(tempDir, 'credentials.json');
let restoreData = { services: null, config: null, credentials: null };
if (fs.existsSync(appServicesPath)) {
try { restoreData.services = JSON.parse(fs.readFileSync(appServicesPath, 'utf8')); } catch (_) {}
}
if (fs.existsSync(appConfigPath)) {
try { restoreData.config = JSON.parse(fs.readFileSync(appConfigPath, 'utf8')); } catch (_) {}
}
if (fs.existsSync(appCredsPath)) {
try { restoreData.credentials = JSON.parse(fs.readFileSync(appCredsPath, 'utf8')); } catch (_) {}
}
// If restartContainers is true, actually perform the restore
if (restartContainers) {
if (restoreData.services) backupManager.restoreServices(restoreData.services);
if (restoreData.config) backupManager.restoreConfig(restoreData.config);
if (restoreData.credentials) backupManager.restoreCredentials(restoreData.credentials);
// Cleanup temp dir
fs.rmSync(tempDir, { recursive: true, force: true });
res.json({
success: true,
isBackupFile: true,
restored: {
services: !!restoreData.services,
config: !!restoreData.config,
credentials: !!restoreData.credentials
},
message: `${appId} reverted to backup successfully`
});
} else {
// Preview mode
fs.rmSync(tempDir, { recursive: true, force: true });
res.json({
success: true,
isBackupFile: true,
preview: true,
filename,
appId,
manifest,
restoreData: {
hasServices: !!restoreData.services,
hasConfig: !!restoreData.config,
hasCredentials: !!restoreData.credentials
}
});
}
} catch (err) {
try { fs.rmSync(tempDir, { recursive: true, force: true }); } catch (_) {}
throw err;
}
} catch (err) {
res.status(500).json({ success: false, error: err.message });
}
}, 'apps-revert'));
/**
* Core restore logic for a single service.
*/
@@ -280,7 +458,7 @@ module.exports = function({ docker, caddy, servicesStateManager, asyncHandler, e
// DNS record
if (manifest.config.createDns && manifest.caddy.routingMode !== 'subdirectory') {
try {
await ctx.dns.createRecord(manifest.config.subdomain, manifest.config.ip);
await ctx.dns.universalCreateRecord(manifest.config.subdomain, manifest.config.ip);
log.info('restore', 'DNS record recreated', { subdomain: manifest.config.subdomain });
} catch (e) {
log.warn('restore', `DNS recreation failed: ${e.message}`);
@@ -309,3 +487,12 @@ module.exports = function({ docker, caddy, servicesStateManager, asyncHandler, e
return router;
};
// Helper: format bytes to human readable
function formatBytes(bytes) {
if (bytes === 0) return '0 B';
const k = 1024;
const sizes = ['B', 'KB', 'MB', 'GB', 'TB'];
const i = Math.floor(Math.log(bytes) / Math.log(k));
return parseFloat((bytes / Math.pow(k, i)).toFixed(2)) + ' ' + sizes[i];
}
+3 -5
View File
@@ -107,10 +107,8 @@ module.exports = function({
if (oldSubdomain && ctx.dns.getToken()) {
try {
const oldDomain = oldSubdomain.includes('.') ? oldSubdomain : ctx.buildDomain(oldSubdomain);
const result = await ctx.dns.call(ctx.siteConfig.dnsServerIp, '/api/zones/records/delete', {
token: ctx.dns.getToken(), domain: oldDomain, type: 'A', ipAddress: ip || 'localhost'
});
results.oldDns = result.status === 'ok' ? 'deleted' : result.errorMessage;
await ctx.dns.universalDeleteRecord(oldDomain, ip || 'localhost');
results.oldDns = 'deleted';
log.info('dns', 'Old DNS record deleted', { domain: oldDomain });
} catch (error) {
results.oldDns = `failed: ${error.message}`;
@@ -120,7 +118,7 @@ module.exports = function({
if (newSubdomain && ctx.dns.getToken()) {
try {
await ctx.dns.createRecord(newSubdomain, ip || 'localhost');
await ctx.dns.universalCreateRecord(newSubdomain, ip || 'localhost');
results.newDns = 'created';
log.info('dns', 'New DNS record created', { domain: ctx.buildDomain(newSubdomain) });
} catch (error) {
+164
View File
@@ -0,0 +1,164 @@
/**
* Auto-Restart Policy Routes
*
* CRUD endpoints for per-container auto-restart policies.
* Also provides a dry-run test endpoint.
*
* @module routes/auto-restart
*/
const express = require('express');
const { success } = require('../src/utils/responses');
const { ValidationError, NotFoundError } = require('../errors');
/**
* Auto-restart route factory
*
* @param {Object} deps - Explicit dependencies
* @param {Object} deps.autoRestartManager - AutoRestartManager instance
* @param {Function} deps.asyncHandler - Async route handler wrapper
* @param {Function} deps.logError - Error logging function
* @returns {express.Router}
*/
module.exports = function ({ autoRestartManager, asyncHandler, logError }) {
const router = express.Router();
/**
* GET /auto-restart/policies
* List all configured auto-restart policies.
*/
router.get('/policies', asyncHandler(async (_req, res) => {
const policies = autoRestartManager.listPolicies();
success(res, { policies });
}, 'auto-restart-list'));
/**
* GET /auto-restart/policies/:serviceId
* Get the restart policy for a single service.
*/
router.get('/policies/:serviceId', asyncHandler(async (req, res) => {
const { serviceId } = req.params;
if (!serviceId || !/^[a-zA-Z0-9][a-zA-Z0-9_.-]{0,100}$/.test(serviceId)) {
throw new ValidationError('Invalid service ID format');
}
const policy = autoRestartManager.getPolicy(serviceId);
if (!policy) {
throw new NotFoundError(`Auto-restart policy for "${serviceId}"`);
}
success(res, { policy });
}, 'auto-restart-get'));
/**
* POST /auto-restart/policies/:serviceId
* Create or update a restart policy.
*
* Body: { enabled, maxRetries, retryIntervalMs, windowMinutes }
*/
router.post('/policies/:serviceId', asyncHandler(async (req, res) => {
const { serviceId } = req.params;
if (!serviceId || !/^[a-zA-Z0-9][a-zA-Z0-9_.-]{0,100}$/.test(serviceId)) {
throw new ValidationError('Invalid service ID format');
}
const { enabled, maxRetries, retryIntervalMs, windowMinutes } = req.body;
// Validate inputs
if (enabled !== undefined && typeof enabled !== 'boolean') {
throw new ValidationError('enabled must be a boolean');
}
if (maxRetries !== undefined) {
if (!Number.isInteger(maxRetries) || maxRetries < 0 || maxRetries > 100) {
throw new ValidationError('maxRetries must be an integer between 0 and 100');
}
}
if (retryIntervalMs !== undefined) {
if (!Number.isInteger(retryIntervalMs) || retryIntervalMs < 0 || retryIntervalMs > 3600000) {
throw new ValidationError('retryIntervalMs must be an integer between 0 and 3600000');
}
}
if (windowMinutes !== undefined) {
if (!Number.isInteger(windowMinutes) || windowMinutes < 0 || windowMinutes > 1440) {
throw new ValidationError('windowMinutes must be an integer between 0 and 1440');
}
}
const policy = await autoRestartManager.setPolicy(serviceId, {
...(enabled !== undefined && { enabled }),
...(maxRetries !== undefined && { maxRetries }),
...(retryIntervalMs !== undefined && { retryIntervalMs }),
...(windowMinutes !== undefined && { windowMinutes }),
});
success(res, { policy, message: `Policy ${serviceId} saved` });
}, 'auto-restart-set'));
/**
* DELETE /auto-restart/policies/:serviceId
* Remove a restart policy.
*/
router.delete('/policies/:serviceId', asyncHandler(async (req, res) => {
const { serviceId } = req.params;
if (!serviceId || !/^[a-zA-Z0-9][a-zA-Z0-9_.-]{0,100}$/.test(serviceId)) {
throw new ValidationError('Invalid service ID format');
}
const removed = await autoRestartManager.removePolicy(serviceId);
if (!removed) {
throw new NotFoundError(`Auto-restart policy for "${serviceId}"`);
}
success(res, { message: `Policy for "${serviceId}" removed` });
}, 'auto-restart-delete'));
/**
* POST /auto-restart/policies/:serviceId/test
* Dry-run: simulate a restart attempt without actually restarting.
* Returns what *would* happen given the current policy state.
*/
router.post('/policies/:serviceId/test', asyncHandler(async (req, res) => {
const { serviceId } = req.params;
if (!serviceId || !/^[a-zA-Z0-9][a-zA-Z0-9_.-]{0,100}$/.test(serviceId)) {
throw new ValidationError('Invalid service ID format');
}
const policy = autoRestartManager.getPolicy(serviceId);
if (!policy) {
throw new NotFoundError(`Auto-restart policy for "${serviceId}"`);
}
const now = Date.now();
const inCooldown = policy.cooldownUntil && now < policy.cooldownUntil;
const wouldRetry = !inCooldown && policy.currentRetries < policy.maxRetries;
const nextAttempt = policy.currentRetries + 1;
success(res, {
dryRun: true,
serviceId,
policy: {
enabled: policy.enabled,
currentRetries: policy.currentRetries,
maxRetries: policy.maxRetries,
cooldownUntil: policy.cooldownUntil,
inCooldown,
},
wouldRestart: policy.enabled && wouldRetry,
wouldMaxOut: !wouldRetry && !inCooldown,
nextAttempt: wouldRetry ? nextAttempt : null,
message: !policy.enabled
? 'Policy is disabled — no restart would occur'
: inCooldown
? `In cooldown until ${new Date(policy.cooldownUntil).toISOString()} — would skip`
: wouldRetry
? `Would attempt restart ${nextAttempt}/${policy.maxRetries}`
: `Max retries (${policy.maxRetries}) already reached — would enter cooldown`,
});
}, 'auto-restart-test'));
return router;
};
+501 -2
View File
@@ -1,16 +1,470 @@
const express = require('express');
const { success } = require('../response-helpers');
const { success } = require('../src/utils/responses');
const fs = require('fs');
const path = require('path');
const DEFAULT_BACKUP_DIR = process.env.BACKUP_DIR || path.join(__dirname, 'backups');
/**
* Backups routes factory
* @param {Object} deps - Explicit dependencies
* @param {Object} deps.backupManager - Backup management module
* @param {Object} deps.licenseManager - License manager for premium gating
* @param {Function} deps.asyncHandler - Async route handler wrapper
* @returns {express.Router}
*/
module.exports = function({ backupManager, asyncHandler }) {
module.exports = function({ backupManager, licenseManager, asyncHandler }) {
const router = express.Router();
// ==================== SCHEDULE ENDPOINTS (PREMIUM) ====================
// Apply premium gating to schedule-related routes
const premiumGating = licenseManager.requirePremium('auto-backup');
// Get all scheduled backup configs
router.get('/backups/schedule', premiumGating, asyncHandler(async (req, res) => {
const config = backupManager.getConfig();
const backups = config.backups || {};
// Calculate next run times based on schedule and last history entry
const history = backupManager.getHistory(1000);
const schedules = Object.entries(backups).map(([appId, backup]) => {
const appHistory = history.filter(h => h.name === appId && h.status === 'success');
const lastRun = appHistory.length > 0 ? new Date(appHistory[0].timestamp) : null;
const nextRun = calculateNextRun(lastRun, backup.schedule);
return {
appId,
enabled: backup.enabled || false,
schedule: backup.schedule || 'daily',
retention: backup.retention || { keep: 7, olderThan: null },
runImmediately: backup.runImmediately || false,
destination: backup.destination || 'local',
destinationPath: backup.destinationPath || DEFAULT_BACKUP_DIR,
lastRun: lastRun ? lastRun.toISOString() : null,
nextRun: nextRun ? nextRun.toISOString() : null,
lastBackupId: appHistory.length > 0 ? appHistory[0].id : null
};
});
success(res, { schedules });
}, 'backups-schedule-list'));
// Create or update a scheduled backup for an app
router.post('/backups/schedule', premiumGating, asyncHandler(async (req, res) => {
const { appId, enabled, schedule, retention, runImmediately, destination, destinationPath } = req.body;
if (!appId) {
const { ValidationError } = require('../errors');
throw new ValidationError('appId is required');
}
const config = backupManager.getConfig();
if (!config.backups) config.backups = {};
// Build the backup config for this app
const backupConfig = {
enabled: enabled !== undefined ? enabled : true,
schedule: schedule || 'daily',
retention: retention || { keep: 7, olderThan: null },
runImmediately: runImmediately || false,
destination: destination || 'local',
destinationPath: destinationPath || DEFAULT_BACKUP_DIR,
include: ['all'],
destinations: [{ type: destination || 'local', path: destinationPath || DEFAULT_BACKUP_DIR }]
};
config.backups[appId] = backupConfig;
backupManager.updateConfig(config);
success(res, {
message: `Backup schedule ${enabled === false ? 'disabled' : 'updated'} for ${appId}`,
schedule: {
appId,
...backupConfig,
retention: backupConfig.retention
}
});
}, 'backups-schedule-update'));
// Remove scheduled backup for an app
router.delete('/backups/schedule/:appId', premiumGating, asyncHandler(async (req, res) => {
const { appId } = req.params;
const config = backupManager.getConfig();
if (!config.backups || !config.backups[appId]) {
const { NotFoundError } = require('../errors');
throw new NotFoundError(`No backup schedule found for app: ${appId}`, 'DC-404');
}
delete config.backups[appId];
backupManager.updateConfig(config);
success(res, { message: `Backup schedule removed for ${appId}` });
}, 'backups-schedule-delete'));
// List backup files on disk
router.get('/backups/files', asyncHandler(async (req, res) => {
const backupDir = DEFAULT_BACKUP_DIR;
const files = [];
try {
if (fs.existsSync(backupDir)) {
const entries = fs.readdirSync(backupDir, { withFileTypes: true });
for (const entry of entries) {
if (entry.isFile() && entry.name.endsWith('.backup')) {
try {
const filepath = path.join(backupDir, entry.name);
const stats = fs.statSync(filepath);
const nameWithoutExt = entry.name.replace('.backup', '');
const parts = nameWithoutExt.split('-');
const appId = parts[0];
const timestamp = parts.length > 1 ? parseInt(parts[parts.length - 1]) : stats.mtimeMs;
files.push({
name: entry.name,
appId,
size: stats.size,
sizeFormatted: formatBytes(stats.size),
timestamp: new Date(timestamp).toISOString(),
path: filepath
});
} catch (err) {
// Skip malformed filenames
}
}
}
}
} catch (err) {
// Directory might not exist yet
}
// Sort by timestamp descending (newest first)
files.sort((a, b) => new Date(b.timestamp) - new Date(a.timestamp));
success(res, { files, total: files.length });
}, 'backups-files-list'));
// Trigger immediate backup for an app
router.post('/backups/backup/:appId', asyncHandler(async (req, res) => {
const { appId } = req.params;
const config = backupManager.getConfig();
const backupConfig = config.backups && config.backups[appId];
if (!backupConfig) {
const { NotFoundError } = require('../errors');
throw new NotFoundError(`No backup schedule found for app: ${appId}`, 'DC-404');
}
const backup = await backupManager.executeBackup(appId, {
...backupConfig,
destinations: backupConfig.destinations || [{ type: backupConfig.destination || 'local', path: backupConfig.destinationPath || DEFAULT_BACKUP_DIR }]
});
success(res, {
message: `Backup started for ${appId}`,
backup: {
id: backup.id,
name: backup.name,
timestamp: backup.timestamp,
size: backup.size,
status: backup.status
}
});
}, 'backups-backup-trigger'));
// List backup files for a specific app
router.get('/backups/files/:appId', asyncHandler(async (req, res) => {
const { appId } = req.params;
const backupDir = DEFAULT_BACKUP_DIR;
const files = [];
try {
if (fs.existsSync(backupDir)) {
const entries = fs.readdirSync(backupDir, { withFileTypes: true });
for (const entry of entries) {
if (entry.isFile() && entry.name.endsWith('.backup')) {
try {
const nameWithoutExt = entry.name.replace('.backup', '');
const parts = nameWithoutExt.split('-');
const fileAppId = parts[0];
// Only include files for the requested app
if (fileAppId !== appId) continue;
const filepath = path.join(backupDir, entry.name);
const stats = fs.statSync(filepath);
const timestamp = parts.length > 1 ? parseInt(parts[parts.length - 1]) : stats.mtimeMs;
files.push({
name: entry.name,
appId: fileAppId,
size: stats.size,
sizeFormatted: formatBytes(stats.size),
timestamp: new Date(timestamp).toISOString(),
path: filepath
});
} catch (err) {
// Skip malformed filenames
}
}
}
}
} catch (err) {
// Directory might not exist yet
}
// Sort by timestamp descending (newest first)
files.sort((a, b) => new Date(b.timestamp) - new Date(a.timestamp));
success(res, { files, total: files.length });
}, 'backups-files-app'));
// Restore from a specific backup file on disk
router.post('/backups/restore-file/:filename', asyncHandler(async (req, res) => {
const { filename } = req.params;
const { encryptionKey, restartContainers } = req.body || {};
// Security: prevent path traversal
if (filename.includes('..') || filename.includes('/') || filename.includes('\\')) {
const { ValidationError } = require('../errors');
throw new ValidationError('Invalid filename');
}
const filepath = path.join(DEFAULT_BACKUP_DIR, filename);
if (!fs.existsSync(filepath)) {
const { NotFoundError } = require('../errors');
throw new NotFoundError(`Backup file not found: ${filename}`, 'DC-404');
}
// Read the backup file
let fileData = fs.readFileSync(filepath);
// Decrypt if needed (format: iv:authTag:encrypted base64)
if (encryptionKey) {
try {
fileData = await backupManager.decryptBackup(fileData, encryptionKey);
} catch (err) {
throw new Error('Failed to decrypt backup: ' + err.message);
}
}
// Decompress
const backupData = await backupManager.decompressBackup(fileData);
// Extract to temp directory for inspection/restoration
const os = require('os');
const crypto = require('crypto');
const tempDir = path.join(os.tmpdir(), `dashcaddy-restore-${Date.now()}-${crypto.randomBytes(4).toString('hex')}`);
fs.mkdirSync(tempDir, { recursive: true });
try {
// Write the decompressed JSON as a tar.gz to extract
const tarPath = path.join(tempDir, 'backup.tar.gz');
fs.writeFileSync(tarPath, backupData);
// Extract tar.gz
const { execSync } = require('child_process');
try {
execSync(`cd "${tempDir}" && tar -xzf backup.tar.gz`, { stdio: 'pipe' });
} catch (tarErr) {
throw new Error('Failed to extract backup archive: ' + tarErr.message);
}
// Read manifest if present
const manifestPath = path.join(tempDir, 'manifest.json');
let manifest = null;
if (fs.existsSync(manifestPath)) {
try {
manifest = JSON.parse(fs.readFileSync(manifestPath, 'utf8'));
} catch (_) { /* ignore malformed manifest */ }
}
// Read extracted data files
const restoreData = {
services: null,
config: null,
credentials: null,
volumes: null
};
const servicesPath = path.join(tempDir, 'services.json');
if (fs.existsSync(servicesPath)) {
try { restoreData.services = JSON.parse(fs.readFileSync(servicesPath, 'utf8')); } catch (_) {}
}
const configPath = path.join(tempDir, 'config.json');
if (fs.existsSync(configPath)) {
try { restoreData.config = JSON.parse(fs.readFileSync(configPath, 'utf8')); } catch (_) {}
}
const credsPath = path.join(tempDir, 'credentials.json');
if (fs.existsSync(credsPath)) {
try { restoreData.credentials = JSON.parse(fs.readFileSync(credsPath, 'utf8')); } catch (_) {}
}
const volumesPath = path.join(tempDir, 'volumes.json');
if (fs.existsSync(volumesPath)) {
try { restoreData.volumes = JSON.parse(fs.readFileSync(volumesPath, 'utf8')); } catch (_) {}
}
// If restartContainers is true, actually perform the restore
if (restartContainers) {
if (restoreData.services) {
backupManager.restoreServices(restoreData.services);
}
if (restoreData.config) {
backupManager.restoreConfig(restoreData.config);
}
if (restoreData.credentials) {
backupManager.restoreCredentials(restoreData.credentials);
}
if (restoreData.volumes) {
await backupManager.restoreVolumes(restoreData.volumes);
}
// Cleanup temp dir
fs.rmSync(tempDir, { recursive: true, force: true });
success(res, {
restored: {
services: !!restoreData.services,
config: !!restoreData.config,
credentials: !!restoreData.credentials,
volumes: !!restoreData.volumes
},
message: 'Backup restored successfully'
});
} else {
// Preview mode: return what would be restored
fs.rmSync(tempDir, { recursive: true, force: true });
success(res, {
preview: true,
filename,
size: fs.statSync(filepath).size,
sizeFormatted: formatBytes(fs.statSync(filepath).size),
manifest,
restoreData: {
hasServices: !!restoreData.services,
hasConfig: !!restoreData.config,
hasCredentials: !!restoreData.credentials,
hasVolumes: !!restoreData.volumes
}
});
}
} catch (err) {
// Cleanup on error
try { fs.rmSync(tempDir, { recursive: true, force: true }); } catch (_) {}
throw err;
}
}, 'backups-restore-file'));
// Compare a backup file against current state
router.post('/backups/compare/:filename', asyncHandler(async (req, res) => {
const { filename } = req.params;
const { encryptionKey } = req.body || {};
// Security: prevent path traversal
if (filename.includes('..') || filename.includes('/') || filename.includes('\\')) {
const { ValidationError } = require('../errors');
throw new ValidationError('Invalid filename');
}
const filepath = path.join(DEFAULT_BACKUP_DIR, filename);
if (!fs.existsSync(filepath)) {
const { NotFoundError } = require('../errors');
throw new NotFoundError(`Backup file not found: ${filename}`, 'DC-404');
}
// Read the backup file
let fileData = fs.readFileSync(filepath);
// Decrypt if needed
if (encryptionKey) {
try {
fileData = await backupManager.decryptBackup(fileData, encryptionKey);
} catch (err) {
throw new Error('Failed to decrypt backup: ' + err.message);
}
}
// Decompress
const backupData = await backupManager.decompressBackup(fileData);
// Extract to temp directory
const os = require('os');
const crypto = require('crypto');
const tempDir = path.join(os.tmpdir(), `dashcaddy-compare-${Date.now()}-${crypto.randomBytes(4).toString('hex')}`);
fs.mkdirSync(tempDir, { recursive: true });
try {
const tarPath = path.join(tempDir, 'backup.tar.gz');
fs.writeFileSync(tarPath, backupData);
const { execSync } = require('child_process');
try {
execSync(`cd "${tempDir}" && tar -xzf backup.tar.gz`, { stdio: 'pipe' });
} catch (tarErr) {
throw new Error('Failed to extract backup archive: ' + tarErr.message);
}
// Build diff
const diff = {
filename,
timestamp: fs.statSync(filepath).mtime.toISOString(),
size: fs.statSync(filepath).size,
sizeFormatted: formatBytes(fs.statSync(filepath).size),
services: null,
config: null
};
// Compare services.json
const servicesPath = path.join(tempDir, 'services.json');
if (fs.existsSync(servicesPath)) {
try {
const backupServices = JSON.parse(fs.readFileSync(servicesPath, 'utf8'));
const currentServicesPath = process.env.SERVICES_FILE || path.join(__dirname, 'services.json');
let currentServices = null;
if (fs.existsSync(currentServicesPath)) {
currentServices = JSON.parse(fs.readFileSync(currentServicesPath, 'utf8'));
}
diff.services = {
backup: backupServices,
current: currentServices,
hasChanges: JSON.stringify(backupServices) !== JSON.stringify(currentServices),
backupCount: Array.isArray(backupServices) ? backupServices.length : 0,
currentCount: Array.isArray(currentServices) ? currentServices.length : 0
};
} catch (_) {}
}
// Compare config.json
const configPath = path.join(tempDir, 'config.json');
if (fs.existsSync(configPath)) {
try {
const backupConfig = JSON.parse(fs.readFileSync(configPath, 'utf8'));
const currentConfigPath = process.env.CONFIG_FILE || path.join(__dirname, 'config.json');
let currentConfig = null;
if (fs.existsSync(currentConfigPath)) {
currentConfig = JSON.parse(fs.readFileSync(currentConfigPath, 'utf8'));
}
diff.config = {
backup: backupConfig,
current: currentConfig,
hasChanges: JSON.stringify(backupConfig) !== JSON.stringify(currentConfig)
};
} catch (_) {}
}
fs.rmSync(tempDir, { recursive: true, force: true });
success(res, { diff });
} catch (err) {
try { fs.rmSync(tempDir, { recursive: true, force: true }); } catch (_) {}
throw err;
}
}, 'backups-compare'));
// ==================== EXISTING ENDPOINTS ====================
// Get backup configuration
router.get('/backups/config', asyncHandler(async (req, res) => {
const config = backupManager.getConfig();
@@ -154,3 +608,48 @@ module.exports = function({ backupManager, asyncHandler }) {
return router;
};
// Helper functions
/**
* Calculate next run time based on schedule and last run
*/
function calculateNextRun(lastRun, schedule) {
if (!lastRun) return null;
const intervals = {
'hourly': 60 * 60 * 1000,
'daily': 24 * 60 * 60 * 1000,
'weekly': 7 * 24 * 60 * 60 * 1000,
'monthly': 30 * 24 * 60 * 60 * 1000
};
const baseInterval = intervals[schedule];
if (baseInterval) {
return new Date(lastRun.getTime() + baseInterval);
}
// Custom interval (e.g., "6h", "30m", "6" for 6 minutes)
const match = schedule.match(/^(\d+)([mh])?$/);
if (match) {
const value = parseInt(match[1]);
const unit = match[2] || 'm'; // default to minutes
const ms = unit === 'h' ? value * 60 * 60 * 1000 : value * 60 * 1000;
return new Date(lastRun.getTime() + ms);
}
// Default to daily
return new Date(lastRun.getTime() + intervals.daily);
}
/**
* Format bytes to human readable string
*/
function formatBytes(bytes) {
if (bytes === 0) return '0 B';
const k = 1024;
const sizes = ['B', 'KB', 'MB', 'GB', 'TB'];
const i = Math.floor(Math.log(bytes) / Math.log(k));
return parseFloat((bytes / Math.pow(k, i)).toFixed(2)) + ' ' + sizes[i];
}
+10 -16
View File
@@ -12,14 +12,11 @@ module.exports = function(ctx) {
// Get CA certificate information
router.get('/info', ctx.asyncHandler(async (req, res) => {
const certInfoPath = '/app/ca/cert-info.json';
const fallbackCertInfoPath = path.join(platformPaths.caCertDir, 'cert-info.json');
const certInfoPath = path.join(platformPaths.caCertDir, 'cert-info.json');
let certInfoFile;
if (await exists(certInfoPath)) {
certInfoFile = certInfoPath;
} else if (await exists(fallbackCertInfoPath)) {
certInfoFile = fallbackCertInfoPath;
} else {
const { NotFoundError } = require('../errors');
throw new NotFoundError('CA certificate information');
@@ -46,13 +43,11 @@ module.exports = function(ctx) {
// Serve root CA certificate directly (works even without DashCA deployed)
router.get('/root.crt', ctx.asyncHandler(async (req, res) => {
const pkiCertPath = '/app/pki/root.crt';
const hostCertPath = platformPaths.pkiRootCert;
const dashcaCertPath = path.join(platformPaths.caCertDir, 'root.crt');
let certPath;
if (await exists(pkiCertPath)) certPath = pkiCertPath;
else if (await exists(dashcaCertPath)) certPath = dashcaCertPath;
if (await exists(dashcaCertPath)) certPath = dashcaCertPath;
else if (await exists(hostCertPath)) certPath = hostCertPath;
else {
const { NotFoundError } = require('../errors');
@@ -72,13 +67,12 @@ module.exports = function(ctx) {
}
// Load cert info to get the fingerprint
const certInfoPath = '/app/ca/cert-info.json';
const fallbackCertInfoPath2 = path.join(platformPaths.caCertDir, 'cert-info.json');
const certInfoPath = path.join(platformPaths.caCertDir, 'cert-info.json');
let certInfoFile;
if (await exists(certInfoPath)) certInfoFile = certInfoPath;
else if (await exists(fallbackCertInfoPath2)) certInfoFile = fallbackCertInfoPath2;
else {
if (await exists(certInfoPath)) {
certInfoFile = certInfoPath;
} else {
const { NotFoundError } = require('../errors');
throw new NotFoundError('CA certificate information. Deploy DashCA first or ensure cert-info.json exists.');
}
@@ -100,7 +94,7 @@ module.exports = function(ctx) {
// Look for template in multiple locations (packaged app vs dev)
const templatePaths = [
path.join(__dirname, '..', 'scripts', templateName),
path.join('/app', 'scripts', templateName)
path.join(platformPaths.caddyBase, 'scripts', templateName)
];
let templateContent;
@@ -142,8 +136,8 @@ module.exports = function(ctx) {
return ctx.errorResponse(res, 400, `Invalid domain name. Must be a valid hostname (e.g., dns1${ctx.siteConfig.tld})`);
}
const pkiPath = '/app/pki';
const certsDir = '/app/generated-certs';
const pkiPath = platformPaths.pkiDir;
const certsDir = platformPaths.generatedCertsDir;
const domainDir = path.join(certsDir, domain);
const intermediateCert = path.join(pkiPath, 'intermediate.crt');
@@ -246,7 +240,7 @@ ${safeDomain.includes('.') ? `DNS.2 = *.${safeDomain}` : ''}`;
// List generated certificates
router.get('/certs', ctx.asyncHandler(async (req, res) => {
const certsDir = '/app/generated-certs';
const certsDir = platformPaths.generatedCertsDir;
if (!await exists(certsDir)) {
return res.json({ success: true, certificates: [] });
+92
View File
@@ -0,0 +1,92 @@
/**
* Config Drift Detection Routes
*
* API endpoints for running drift detection, reading cached reports,
* auto-fixing drift, and controlling periodic polling.
*
* @module routes/config-drift
*/
const express = require('express');
const { success } = require('../src/utils/responses');
const { ValidationError, NotFoundError } = require('../errors');
/**
* Config-drift route factory
*
* @param {Object} deps - Explicit dependencies
* @param {Object} deps.driftDetector - ConfigDriftDetector instance
* @param {Function} deps.asyncHandler - Async route handler wrapper
* @param {Function} deps.logError - Error logging function
* @returns {express.Router}
*/
module.exports = function ({ driftDetector, asyncHandler, logError }) {
const router = express.Router();
/**
* GET /config-drift/report
* Run a fresh drift detection and return the full report.
*/
router.get('/report', asyncHandler(async (_req, res) => {
const report = await driftDetector.detect();
success(res, { report });
}, 'drift-report'));
/**
* GET /config-drift/last
* Return the last cached drift report (no re-detection).
*/
router.get('/last', asyncHandler(async (_req, res) => {
if (!driftDetector.lastReport) {
throw new NotFoundError('No cached drift report — run detection first');
}
success(res, { report: driftDetector.lastReport });
}, 'drift-last'));
/**
* POST /config-drift/fix
* Auto-fix detected drift: remove stale records, flag unknown containers.
*/
router.post('/fix', asyncHandler(async (_req, res) => {
const result = await driftDetector.autoFix();
success(res, {
message: 'Auto-fix applied',
staleRemoved: result.staleRemoved,
unknownFlagged: result.unknownFlagged,
});
}, 'drift-fix'));
/**
* POST /config-drift/polling
* Enable or disable periodic drift detection polling.
*
* Body: { enabled: boolean, intervalMs?: number }
*/
router.post('/polling', asyncHandler(async (req, res) => {
const { enabled, intervalMs } = req.body;
if (typeof enabled !== 'boolean') {
throw new ValidationError('enabled must be a boolean');
}
if (intervalMs !== undefined) {
if (!Number.isInteger(intervalMs) || intervalMs < 10000 || intervalMs > 86400000) {
throw new ValidationError('intervalMs must be an integer between 10000 and 86400000 (10s 24h)');
}
}
if (enabled) {
driftDetector.startPolling(intervalMs || 300000);
success(res, {
message: 'Drift polling enabled',
intervalMs: intervalMs || 300000,
});
} else {
driftDetector.stopPolling();
success(res, { message: 'Drift polling disabled' });
}
}, 'drift-polling'));
return router;
};
+6 -5
View File
@@ -4,6 +4,7 @@ const path = require('path');
const { LIMITS } = require('../../constants');
const { exists } = require('../../fs-helpers');
const { ValidationError } = require('../../errors');
const platformPaths = require('../../platform-paths');
/**
* Config assets routes factory
* @param {Object} deps - Explicit dependencies
@@ -51,7 +52,7 @@ module.exports = function({ servicesStateManager: _servicesStateManager, asyncHa
const buffer = Buffer.from(base64Data, 'base64');
// Determine assets path (mounted volume)
const assetsPath = process.env.ASSETS_PATH || '/app/assets';
const assetsPath = platformPaths.resolveAssetsPath(process.env.ASSETS_PATH);
// Ensure directory exists
if (!await exists(assetsPath)) {
@@ -96,7 +97,7 @@ module.exports = function({ servicesStateManager: _servicesStateManager, asyncHa
const extension = matches[1] === 'svg+xml' ? 'svg' : matches[1];
const buffer = Buffer.from(matches[2], 'base64');
const assetsPath = process.env.ASSETS_PATH || '/app/assets';
const assetsPath = platformPaths.resolveAssetsPath(process.env.ASSETS_PATH);
if (!await exists(assetsPath)) {
await fsp.mkdir(assetsPath, { recursive: true });
}
@@ -170,7 +171,7 @@ module.exports = function({ servicesStateManager: _servicesStateManager, asyncHa
// Reset all branding to defaults
router.delete('/logo', asyncHandler(async (req, res) => {
const config = await ctx.readConfig();
const assetsPath = process.env.ASSETS_PATH || '/app/assets';
const assetsPath = platformPaths.resolveAssetsPath(process.env.ASSETS_PATH);
// Delete all custom logo files
const logoPaths = [config.customLogo, config.customLogoDark, config.customLogoLight].filter(Boolean);
@@ -234,7 +235,7 @@ module.exports = function({ servicesStateManager: _servicesStateManager, asyncHa
const base64Data = matches[2];
const buffer = Buffer.from(base64Data, 'base64');
const assetsPath = process.env.ASSETS_PATH || '/app/assets';
const assetsPath = platformPaths.resolveAssetsPath(process.env.ASSETS_PATH);
if (!await exists(assetsPath)) {
await fsp.mkdir(assetsPath, { recursive: true });
}
@@ -279,7 +280,7 @@ module.exports = function({ servicesStateManager: _servicesStateManager, asyncHa
const config = await ctx.readConfig();
// Delete custom favicon files
const assetsPath = process.env.ASSETS_PATH || '/app/assets';
const assetsPath = platformPaths.resolveAssetsPath(process.env.ASSETS_PATH);
const filesToDelete = ['favicon.ico', 'favicon.png'];
for (const file of filesToDelete) {
const filePath = `${assetsPath}/${file}`;
+3 -2
View File
@@ -4,6 +4,7 @@ const path = require('path');
const { CADDY } = require('../../constants');
const { exists } = require('../../fs-helpers');
const { ValidationError, AuthenticationError } = require('../../errors');
const platformPaths = require('../../platform-paths');
/**
* Config backup routes factory
@@ -115,7 +116,7 @@ module.exports = function(deps) {
// Include custom assets (logo, favicon) as base64
try {
const assetsDir = process.env.ASSETS_DIR || '/app/assets';
const assetsDir = platformPaths.resolveAssetsPath(process.env.ASSETS_DIR);
const configData = backup.files.config?.data || {};
const assetFiles = [configData.customLogo, configData.customFavicon]
.filter(Boolean)
@@ -346,7 +347,7 @@ module.exports = function(deps) {
// Restore custom assets from base64
if (backup.assets && typeof backup.assets === 'object') {
const assetsDir = process.env.ASSETS_DIR || '/app/assets';
const assetsDir = platformPaths.resolveAssetsPath(process.env.ASSETS_DIR);
for (const [name, b64] of Object.entries(backup.assets)) {
try {
const safeName = path.basename(name); // prevent path traversal
+17 -6
View File
@@ -2,7 +2,7 @@ const express = require('express');
const { DOCKER } = require('../constants');
const { paginate, parsePaginationParams } = require('../pagination');
const { NotFoundError } = require('../errors');
const { success } = require('../response-helpers');
const { success } = require('../src/utils/responses');
/**
* Containers route factory
@@ -10,9 +10,10 @@ const { success } = require('../response-helpers');
* @param {Object} deps.docker - Docker client wrapper (client, pull methods)
* @param {Object} deps.log - Logger instance
* @param {Function} deps.asyncHandler - Async route handler wrapper
* @param {Object} deps.workflowEngine - WorkflowEngine instance (optional)
* @returns {express.Router}
*/
module.exports = function({ docker, log, asyncHandler }) {
module.exports = function({ docker, log, asyncHandler, workflowEngine }) {
const router = express.Router();
// Helper: verify container exists before operating on it
@@ -66,6 +67,11 @@ module.exports = function({ docker, log, asyncHandler }) {
log.info('docker', `Pulling latest image: ${imageName}`);
await docker.pull(imageName);
// Trigger pre-update workflow (backup before update)
if (workflowEngine) {
try { await workflowEngine.triggerEvent('pre-update', { containerId: containerId, containerName, imageName }); } catch (w) { log.warn('workflow', 'pre-update trigger failed: ' + w.message); }
}
// Get current container config for recreation
const hostConfig = containerInfo.HostConfig;
const config = {
@@ -135,10 +141,15 @@ module.exports = function({ docker, log, asyncHandler }) {
}
success(res, {
message: `Container ${containerName} updated successfully`,
newContainerId: newContainerInfo.Id
});
}, 'container-update'));
message: `Container ${containerName} updated successfully`,
newContainerId: newContainerInfo.Id
});
// Trigger post-update workflow
if (workflowEngine) {
try { await workflowEngine.triggerEvent('post-update', { containerId: containerId, containerName, imageName, newContainerId: newContainerInfo.Id }); } catch (w) { log.warn('workflow', 'post-update trigger failed: ' + w.message); }
}
}, 'container-update'));
// Check for available updates (compares local and remote image digests)
router.get('/:id/check-update', asyncHandler(async (req, res) => {
+1 -1
View File
@@ -1,5 +1,5 @@
const express = require('express');
const { success, error: errorResponse } = require('../response-helpers');
const { success, error: errorResponse } = require('../src/utils/responses');
/**
* Credentials routes factory
+235
View File
@@ -0,0 +1,235 @@
/**
* Dependencies Route REST API for service dependency tracking
*
* Endpoints:
* GET /dependencies/graph Full dependency graph
* GET /dependencies/validate Validate a proposed dep chain
* GET /dependencies/:serviceId Direct deps for one service
* GET /dependencies/:serviceId/chain Ordered restart chain
* GET /dependencies/:serviceId/status Dependency health status
* POST /dependencies/:serviceId Set dependencies
* DELETE /dependencies/:serviceId Remove all dependencies
* POST /dependencies/:serviceId/restart Restart with dependency chain
*
* @module routes/dependencies
*/
const express = require('express');
const { success, error: errorResponse } = require('../src/utils/responses');
const { NotFoundError, ValidationError } = require('../errors');
/**
* Dependencies route factory
*
* @param {Object} deps - Explicit dependencies
* @param {Object} deps.dependencyManager - DependencyManager instance
* @param {Object} deps.servicesStateManager - State manager for services.json
* @param {Object} deps.docker - Docker client wrapper
* @param {Function} deps.asyncHandler - Async route handler wrapper
* @param {Function} deps.logError - Error logging function
* @param {Function} deps.resyncHealthChecker - Health checker resync function
* @param {Object} deps.log - Logger instance
* @returns {express.Router}
*/
module.exports = function({
dependencyManager,
servicesStateManager,
docker,
asyncHandler,
logError,
resyncHealthChecker,
log,
}) {
const router = express.Router();
// -------------------------------------------------------------------------
// GET /dependencies/graph — Full dependency graph
// -------------------------------------------------------------------------
router.get('/graph', asyncHandler(async (req, res) => {
const graph = await dependencyManager.getDependencyGraph();
success(res, { graph });
}, 'dep-graph'));
// -------------------------------------------------------------------------
// GET /dependencies/validate — Validate a proposed dep chain (query params)
// -------------------------------------------------------------------------
router.get('/validate', asyncHandler(async (req, res) => {
const { serviceId, dependsOn } = req.query;
if (!serviceId) {
throw new ValidationError('serviceId query parameter is required');
}
// dependsOn may be a comma-separated string or already an array
let parsed;
if (Array.isArray(dependsOn)) {
parsed = dependsOn;
} else if (typeof dependsOn === 'string' && dependsOn.length > 0) {
parsed = dependsOn.split(',').map(s => s.trim()).filter(Boolean);
} else {
parsed = [];
}
const result = await dependencyManager.validateDependencies(serviceId, parsed);
success(res, result);
}, 'dep-validate'));
// -------------------------------------------------------------------------
// GET /dependencies/:serviceId — Direct deps for one service
// -------------------------------------------------------------------------
router.get('/:serviceId', asyncHandler(async (req, res) => {
const { serviceId } = req.params;
const dependencies = await dependencyManager.getDependencies(serviceId);
const dependents = await dependencyManager.getDependents(serviceId);
// Read the service's current dependsOn array
const services = await servicesStateManager.read();
const allServices = Array.isArray(services) ? services : (services.services || []);
const service = allServices.find(s => s.id === serviceId);
if (!service) {
throw new NotFoundError(`Service "${serviceId}"`);
}
success(res, {
serviceId,
dependsOn: service.dependsOn || [],
dependencies,
dependents: dependents.map(d => ({ id: d.id, name: d.name })),
});
}, 'dep-get'));
// -------------------------------------------------------------------------
// GET /dependencies/:serviceId/chain — Ordered restart chain
// -------------------------------------------------------------------------
router.get('/:serviceId/chain', asyncHandler(async (req, res) => {
const { serviceId } = req.params;
const chain = await dependencyManager.getOrderedRestartChain(serviceId);
success(res, { serviceId, chain });
}, 'dep-chain'));
// -------------------------------------------------------------------------
// GET /dependencies/:serviceId/status — Dependency health status
// -------------------------------------------------------------------------
router.get('/:serviceId/status', asyncHandler(async (req, res) => {
const { serviceId } = req.params;
const statuses = await dependencyManager.getDependencyStatus(serviceId);
success(res, { serviceId, statuses });
}, 'dep-status'));
// -------------------------------------------------------------------------
// POST /dependencies/:serviceId — Set dependencies
// -------------------------------------------------------------------------
router.post('/:serviceId', asyncHandler(async (req, res) => {
const { serviceId } = req.params;
const { dependsOn } = req.body;
if (!Array.isArray(dependsOn)) {
throw new ValidationError('Request body must include dependsOn as an array of service IDs');
}
// Validate first
const validation = await dependencyManager.validateDependencies(serviceId, dependsOn);
if (!validation.valid) {
return errorResponse(res, validation.errors.join('; '), 400);
}
// Update the service
let found = false;
await servicesStateManager.update(services => {
const arr = Array.isArray(services) ? services : [];
return arr.map(s => {
if (s.id === serviceId) {
found = true;
return { ...s, dependsOn: dependsOn.slice() };
}
return s;
});
});
if (!found) {
throw new NotFoundError(`Service "${serviceId}"`);
}
log.info('dependency', 'Dependencies updated', { serviceId, dependsOn });
success(res, {
message: `Dependencies updated for "${serviceId}"`,
serviceId,
dependsOn,
});
}, 'dep-set'));
// -------------------------------------------------------------------------
// DELETE /dependencies/:serviceId — Remove all dependencies for a service
// -------------------------------------------------------------------------
router.delete('/:serviceId', asyncHandler(async (req, res) => {
const { serviceId } = req.params;
let found = false;
await servicesStateManager.update(services => {
const arr = Array.isArray(services) ? services : [];
return arr.map(s => {
if (s.id === serviceId) {
found = true;
const updated = { ...s };
delete updated.dependsOn;
return updated;
}
return s;
});
});
if (!found) {
throw new NotFoundError(`Service "${serviceId}"`);
}
log.info('dependency', 'Dependencies removed', { serviceId });
success(res, {
message: `All dependencies removed for "${serviceId}"`,
serviceId,
});
}, 'dep-delete'));
// -------------------------------------------------------------------------
// POST /dependencies/:serviceId/restart — Restart with dependency chain
// -------------------------------------------------------------------------
router.post('/:serviceId/restart', asyncHandler(async (req, res) => {
const { serviceId } = req.params;
// Verify the service exists
const services = await servicesStateManager.read();
const allServices = Array.isArray(services) ? services : (services.services || []);
if (!allServices.find(s => s.id === serviceId)) {
throw new NotFoundError(`Service "${serviceId}"`);
}
// Get the chain first for the response (before async restart begins)
let chain;
try {
chain = await dependencyManager.getOrderedRestartChain(serviceId);
} catch (err) {
return errorResponse(res, err.message, 400);
}
// Respond immediately with the chain order
success(res, {
message: `Dependency restart initiated for "${serviceId}"`,
serviceId,
chain,
});
// Run the restart chain asynchronously so the client doesn't block
dependencyManager.restartWithDependencies(serviceId).catch(err => {
if (log) {
log.error('dependency', 'Async dependency restart failed', {
serviceId,
error: err.message,
});
}
});
}, 'dep-restart'));
return router;
};
+232 -13
View File
@@ -4,7 +4,7 @@ const fsp = require('fs').promises;
const validatorLib = require('validator');
const { APP, TIMEOUTS, CADDY, DNS_RECORD_TYPES, REGEX, SESSION_TTL } = require('../constants');
const { exists } = require('../fs-helpers');
const { success, error: errorResponse } = require('../response-helpers');
const { success, error: errorResponse } = require('../src/utils/responses');
const { ValidationError, AuthenticationError, NotFoundError } = require('../errors');
/**
@@ -26,7 +26,8 @@ module.exports = function({
log,
safeErrorMessage,
fetchT,
credentialManager
credentialManager,
dnsPropagationChecker
}) {
const router = express.Router();
@@ -41,7 +42,137 @@ module.exports = function({
return serverIp;
}
// DELETE /record — Delete a DNS record from Technitium
// ===== DNS PROVIDER ENDPOINTS =====
// GET /providers — List all available DNS providers
router.get('/providers', asyncHandler(async (req, res) => {
const providers = dns.getAvailableProviders ? dns.getAvailableProviders() : [];
const activeProvider = dns.getProviderId ? dns.getProviderId() : 'technitium';
success(res, { providers, activeProvider });
}, 'dns-providers-list'));
// GET /provider/status — Get active provider status
router.get('/provider/status', asyncHandler(async (req, res) => {
if (!dns.getActiveProvider) {
return success(res, { providerId: 'technitium', capabilities: ['create-record', 'delete-record', 'resolve', 'list-records', 'logs', 'restart', 'update-check', 'credentials', 'zones'] });
}
try {
const provider = dns.getActiveProvider();
const status = await provider.getStatus();
success(res, status);
} catch (err) {
errorResponse(res, safeErrorMessage(err), 500);
}
}, 'dns-provider-status'));
// ===== UNIVERSAL RECORD ENDPOINTS (work with any provider) =====
// POST /universal/record — Create a DNS record via any provider
router.post('/universal/record', asyncHandler(async (req, res) => {
if (!dns.getActiveProvider) {
// Fallback to legacy Technitium route
return res.redirect(307, '/api/dns/record');
}
const { domain, ip, ttl, type, server } = req.body;
if (!domain || !ip) throw new ValidationError('domain and ip are required');
if (!REGEX.DOMAIN.test(domain)) throw new ValidationError('[DC-301] Invalid domain format');
if (!validatorLib.isIP(ip)) throw new ValidationError('[DC-210] Invalid IP address');
try {
const provider = dns.getActiveProvider();
if (!provider.supportsCapability('create-record')) {
const result = await provider.createRecord({
domain, zone: siteConfig.tld?.replace(/^\./, '') || '',
type: type || 'A', value: ip, ttl: ttl || 300, overwrite: true
});
return success(res, {
message: result.message || `DNS record instructions provided`,
manual: true,
instructions: result.instructions
});
}
const result = await provider.createRecord({
domain, zone: siteConfig.tld?.replace(/^\./, '') || '',
type: type || 'A', value: ip, ttl: ttl || 300, overwrite: true
});
// Start propagation check in background
if (dnsPropagationChecker && ip) {
dnsPropagationChecker.startVerification(domain, ip).catch(err => {
log('DNS propagation check start failed:', err.message);
});
}
success(res, {
message: result.status === 'manual' ? result.message : `DNS record ${domain} -> ${ip} created`,
provider: dns.getProviderId(),
...(result.instructions ? { manual: true, instructions: result.instructions } : {})
});
} catch (error) {
log.error('dns', 'Universal DNS record creation error', { error: error.message });
errorResponse(res, safeErrorMessage(error), 500);
}
}, 'dns-universal-create'));
// DELETE /universal/record — Delete a DNS record via any provider
router.delete('/universal/record', asyncHandler(async (req, res) => {
if (!dns.getActiveProvider) {
return res.redirect(307, '/api/dns/record');
}
const { domain, type, value } = req.query;
if (!domain) throw new ValidationError('domain is required');
if (!REGEX.DOMAIN.test(domain)) throw new ValidationError('[DC-301] Invalid domain format');
try {
const provider = dns.getActiveProvider();
const result = await provider.deleteRecord({
domain, type: type || 'A', value
});
success(res, {
message: result.status === 'manual' ? result.message : `DNS record ${domain} deleted`,
provider: dns.getProviderId(),
...(result.instructions ? { manual: true, instructions: result.instructions } : {})
});
} catch (error) {
log.error('dns', 'Universal DNS record deletion error', { error: error.message });
errorResponse(res, safeErrorMessage(error), 500);
}
}, 'dns-universal-delete'));
// GET /universal/resolve — Resolve a domain via any provider
router.get('/universal/resolve', asyncHandler(async (req, res) => {
if (!dns.getActiveProvider) {
return res.redirect(307, '/api/dns/resolve');
}
const { domain, type } = req.query;
if (!domain) throw new ValidationError('domain is required');
if (!REGEX.DOMAIN.test(domain)) throw new ValidationError('[DC-301] Invalid domain format');
try {
const provider = dns.getActiveProvider();
const result = await provider.resolveRecords({
domain, zone: siteConfig.tld?.replace(/^\./, '') || '',
type: type || 'A'
});
if (result.response?.records?.length > 0) {
const ipAddresses = result.response.records
.filter(r => r.type === (type || 'A'))
.map(r => r.rData?.ipAddress || r.content || r.rData?.address)
.filter(Boolean);
success(res, { answer: ipAddresses });
} else {
throw new NotFoundError('No records found for domain');
}
} catch (error) {
log.error('dns', 'Universal DNS resolve error', { error: error.message });
errorResponse(res, safeErrorMessage(error), error.statusCode || 500);
}
}, 'dns-universal-resolve'));
// ===== LEGACY TECHNITIUM-SPECIFIC ROUTES (unchanged) =====
router.delete('/record', asyncHandler(async (req, res) => {
const { domain, type, token, server, ipAddress } = req.query;
@@ -139,6 +270,14 @@ module.exports = function({
});
if (result.status === 'ok') {
// Start DNS propagation verification in background
if (dnsPropagationChecker && ip) {
const fullDomain = domain;
dnsPropagationChecker.startVerification(fullDomain, ip).catch(err => {
log('DNS propagation check start failed:', err.message);
});
}
success(res, { message: `DNS record ${domain} -> ${ip} created` });
} else {
// Error handled by middleware
@@ -194,8 +333,13 @@ module.exports = function({
}
}, 'dns-resolve'));
// GET /logs — Fetch DNS query logs from Technitium
// GET /logs — Fetch DNS query logs (Technitium only)
router.get('/logs', asyncHandler(async (req, res) => {
// Capability gate: logs are provider-specific
if (dns.supportsCapability && !dns.supportsCapability('logs')) {
return success(res, { server: 'N/A', count: 0, logs: [], message: 'DNS logs not supported by current provider' });
}
const { server, limit } = req.query;
if (!server) {
@@ -239,9 +383,8 @@ module.exports = function({
const response = await fetchT(technitiumUrl, {
method: 'GET',
headers: { 'Accept': 'text/plain' },
timeout: 10000
});
headers: { 'Accept': 'text/plain' }
}, 10000);
if (!response.ok) {
const errorText = await response.text();
@@ -475,8 +618,13 @@ module.exports = function({
success(res, { message: 'DNS credentials removed' });
}, 'dns-credentials-delete'));
// POST /restart/:dnsId — Restart a DNS server (proxied through backend for auth)
// POST /restart/:dnsId — Restart a DNS server (Technitium only)
router.post('/restart/:dnsId', asyncHandler(async (req, res) => {
// Capability gate
if (dns.supportsCapability && !dns.supportsCapability('restart')) {
return errorResponse(res, 'Server restart not supported by current DNS provider', 501);
}
const { dnsId } = req.params;
const serverInfo = siteConfig.dnsServers?.[dnsId];
if (!serverInfo?.ip) {
@@ -491,7 +639,7 @@ module.exports = function({
const dnsPort = siteConfig.dnsServerPort || '5380';
try {
const url = `http://${serverInfo.ip}:${dnsPort}/api/admin/restart?token=${encodeURIComponent(tokenResult.token)}`;
const response = await fetchT(url, { method: 'POST', timeout: 5000 });
const response = await fetchT(url, { method: 'POST' }, 5000);
const result = await response.json();
if (result.status === 'ok') {
success(res, { message: 'Restart initiated' });
@@ -518,8 +666,13 @@ module.exports = function({
}
}, 'dns-refresh-token'));
// GET /check-update — Check for Technitium DNS server updates
// GET /check-update — Check for DNS server updates (Technitium only)
router.get('/check-update', asyncHandler(async (req, res) => {
// Capability gate
if (dns.supportsCapability && !dns.supportsCapability('update-check')) {
return success(res, { updateAvailable: false, message: 'Update check not supported by current DNS provider' });
}
try {
const { server } = req.query;
if (!server) {
@@ -576,10 +729,13 @@ module.exports = function({
}
}, 'dns-check-update'));
// POST /update — Update Technitium DNS server
// Note: Technitium v14+ has no installUpdate API. This endpoint checks for updates
// and returns download info. The frontend handles showing update instructions.
// POST /update — Update DNS server (Technitium only)
router.post('/update', asyncHandler(async (req, res) => {
// Capability gate
if (dns.supportsCapability && !dns.supportsCapability('update-check')) {
return errorResponse(res, 'Server update not supported by current DNS provider', 501);
}
try {
const { server } = req.query;
if (!server) {
@@ -641,5 +797,68 @@ module.exports = function({
}
}, 'dns-update'));
// ===== DNS PROPAGATION =====
// GET /propagation — Get all recent DNS propagation checks
router.get('/propagation', asyncHandler(async (req, res) => {
if (!dnsPropagationChecker) {
return success(res, { verifications: [], message: 'DNS propagation checker not available' });
}
// Cleanup old entries
dnsPropagationChecker.cleanup();
const verifications = dnsPropagationChecker.getAllVerifications();
success(res, { verifications });
}, 'dns-propagation-all'));
// POST /propagation/verify — Manually trigger DNS propagation verification
router.post('/propagation/verify', asyncHandler(async (req, res) => {
if (!dnsPropagationChecker) {
return errorResponse(res, 'DNS propagation checker not available', 503);
}
const { domain, expectedIp } = req.body;
if (!domain || !expectedIp) {
throw new ValidationError('domain and expectedIp are required');
}
// Validate domain format
if (!REGEX.DOMAIN.test(domain)) {
throw new ValidationError('[DC-301] Invalid domain format');
}
// Validate IP address
const validatorLib = require('validator');
if (!validatorLib.isIP(expectedIp)) {
throw new ValidationError('[DC-210] Invalid IP address');
}
const job = dnsPropagationChecker.startVerification(domain, expectedIp);
success(res, {
message: 'DNS propagation verification started',
domain,
expectedIp,
status: job.status
});
}, 'dns-propagation-verify'));
// GET /propagation/:domain — Get propagation status for a specific domain
router.get('/propagation/:domain', asyncHandler(async (req, res) => {
if (!dnsPropagationChecker) {
return success(res, { verification: null, message: 'DNS propagation checker not available' });
}
const { domain } = req.params;
const status = dnsPropagationChecker.getVerificationStatus(domain);
if (!status) {
throw new NotFoundError(`No propagation check found for domain: ${domain}`);
}
success(res, { verification: status });
}, 'dns-propagation-domain'));
return router;
};
+1 -1
View File
@@ -1,5 +1,5 @@
const express = require('express');
const { success } = require('../response-helpers');
const { success } = require('../src/utils/responses');
const { ValidationError } = require('../errors');
/**
+1 -1
View File
@@ -3,7 +3,7 @@ const fs = require('fs');
const fsp = require('fs').promises;
const { exists } = require('../fs-helpers');
const { paginate, parsePaginationParams } = require('../pagination');
const { success } = require('../response-helpers');
const { success } = require('../src/utils/responses');
/**
* Error logs routes factory
+44 -1
View File
@@ -8,9 +8,10 @@ const express = require('express');
* @param {Object} deps.healthChecker - Health checker
* @param {Object} deps.updateManager - Update manager
* @param {Function} deps.logError - Error logging function
* @param {Object} deps.dependencyManager - Dependency manager for restart chain events
* @returns {express.Router}
*/
module.exports = function({ resourceMonitor, healthChecker, updateManager, logError }) {
module.exports = function({ resourceMonitor, healthChecker, updateManager, logError, dependencyManager, autoRestartManager, driftDetector, sslMonitor, dnsPropagationChecker }) {
const router = express.Router();
const clients = new Set();
@@ -74,6 +75,48 @@ module.exports = function({ resourceMonitor, healthChecker, updateManager, logEr
});
}
// Dependency manager events
if (dependencyManager) {
dependencyManager.on('dependency-restart-start', (data) => {
broadcast('dependency-restart-start', data);
});
dependencyManager.on('dependency-restart-progress', (data) => {
broadcast('dependency-restart-progress', data);
});
dependencyManager.on('dependency-restart-complete', (data) => {
broadcast('dependency-restart-complete', data);
});
dependencyManager.on('dependency-restart-failed', (data) => {
broadcast('dependency-restart-failed', data);
});
}
// Auto-restart manager events
if (autoRestartManager) {
autoRestartManager.on('auto-restart-attempt', (data) => broadcast('auto-restart-attempt', data));
autoRestartManager.on('auto-restart-success', (data) => broadcast('auto-restart-success', data));
autoRestartManager.on('auto-restart-failed', (data) => broadcast('auto-restart-failed', data));
autoRestartManager.on('auto-restart-max-reached', (data) => broadcast('auto-restart-max-reached', data));
}
// Config drift detector events
if (driftDetector) {
driftDetector.on('drift-detected', (data) => broadcast('drift-detected', data));
}
// SSL monitor events
if (sslMonitor) {
sslMonitor.on('cert-expiring', (data) => broadcast('cert-expiring', data));
sslMonitor.on('cert-critical', (data) => broadcast('cert-critical', data));
}
// DNS propagation checker events
if (dnsPropagationChecker) {
dnsPropagationChecker.on('propagation-check', (data) => broadcast('dns-propagation-check', data));
dnsPropagationChecker.on('propagation-complete', (data) => broadcast('dns-propagation-complete', data));
dnsPropagationChecker.on('propagation-timeout', (data) => broadcast('dns-propagation-timeout', data));
}
// SSE endpoint
router.get('/stream', (req, res) => {
res.writeHead(200, {
+26 -16
View File
@@ -7,7 +7,7 @@ const { exists } = require('../fs-helpers');
const { paginate, parsePaginationParams } = require('../pagination');
const platformPaths = require('../platform-paths');
const { resolveServiceUrl } = require('../url-resolver');
const { success, error: errorResponse } = require('../response-helpers');
const { success, error: errorResponse } = require('../src/utils/responses');
const { ValidationError } = require('../errors');
/**
@@ -273,9 +273,10 @@ module.exports = function({
try {
// Check if certificate exists
if (!await exists(rootCertPath)) {
return res.json({
status: 'error',
message: 'Root CA certificate not found',
return res.status(404).json({
success: false,
error: 'Root CA certificate not found',
caStatus: 'error',
daysUntilExpiration: null
});
}
@@ -286,34 +287,36 @@ module.exports = function({
const daysUntilExpiration = Math.floor((expirationDate - new Date()) / (1000 * 60 * 60 * 24));
// Alert thresholds
let status = 'healthy';
let caStatus = 'healthy';
let message = `CA certificate valid for ${daysUntilExpiration} days`;
if (daysUntilExpiration < 0) {
status = 'critical';
caStatus = 'critical';
message = `CA certificate EXPIRED ${Math.abs(daysUntilExpiration)} days ago!`;
} else if (daysUntilExpiration < 7) {
status = 'critical';
caStatus = 'critical';
message = `CA certificate expires in ${daysUntilExpiration} days!`;
} else if (daysUntilExpiration < 30) {
status = 'critical';
caStatus = 'critical';
message = `CA certificate expires in ${daysUntilExpiration} days!`;
} else if (daysUntilExpiration < 90) {
status = 'warning';
caStatus = 'warning';
message = `CA certificate expires in ${daysUntilExpiration} days`;
}
res.json({
status: status,
message: message,
daysUntilExpiration: daysUntilExpiration,
success: true,
caStatus,
message,
daysUntilExpiration,
expiresAt: notAfter
});
} catch (error) {
await logError('GET /api/health/ca', error);
res.json({
status: 'error',
message: error.message,
res.status(500).json({
success: false,
error: error.message,
caStatus: 'error',
daysUntilExpiration: null
});
}
@@ -322,9 +325,16 @@ module.exports = function({
// ===== HEALTH CHECK (health-checker module) =====
// Get current status for all services
// Returns per-service status plus a summary for the System Overview widget:
// { status: { ... }, summary: { healthy, unhealthy, total } }
router.get('/health-checks/status', asyncHandler(async (req, res) => {
const status = healthChecker.getCurrentStatus();
success(res, { status });
// Build summary for the overview widget
const entries = Object.values(status);
const healthy = entries.filter(s => s.status === 'up' || s.status === 'healthy').length;
const unhealthy = entries.filter(s => s.status === 'down' || s.status === 'unhealthy').length;
const total = entries.length;
success(res, { status, summary: { healthy, unhealthy, total } });
}, 'health-check-status'));
// Get service statistics
+1 -1
View File
@@ -1,5 +1,5 @@
const express = require('express');
const { success, error: errorResponse } = require('../response-helpers');
const { success, error: errorResponse } = require('../src/utils/responses');
const { ValidationError } = require('../errors');
/**
+97 -4
View File
@@ -1,5 +1,5 @@
const express = require('express');
const { success } = require('../response-helpers');
const { success } = require('../src/utils/responses');
/**
* Monitoring routes factory
@@ -10,14 +10,28 @@ const { success } = require('../response-helpers');
* @param {Object} deps.log - Logger instance
* @returns {express.Router}
*/
module.exports = function({ resourceMonitor, docker, asyncHandler, log }) {
module.exports = function({ resourceMonitor, docker, asyncHandler, log, notificationManager }) {
const router = express.Router();
// ===== RESOURCE MONITORING ENDPOINTS =====
// Get all container stats (from resource monitor module)
// Returns a flat summary format for the System Overview widget:
// { containerId: { cpu: <percent>, memory: <percent>, memoryUsage: <bytes>, name } }
router.get('/monitoring/stats', asyncHandler(async (req, res) => {
const stats = resourceMonitor.getAllStats();
const raw = resourceMonitor.getAllStats();
// Transform nested { current: { cpu: { percent }, memory: { percent, usage } } }
// into flat { cpu: number, memory: number, memoryUsage: number } for the frontend widget
const stats = {};
for (const [id, data] of Object.entries(raw)) {
const cur = data.current || {};
stats[id] = {
name: data.name,
cpu: typeof cur.cpu === 'object' ? (cur.cpu.percent ?? 0) : (Number(cur.cpu) || 0),
memory: typeof cur.memory === 'object' ? (cur.memory.percent ?? 0) : (Number(cur.memory) || 0),
memoryUsage: typeof cur.memory === 'object' ? (cur.memory.usage ?? 0) : 0,
};
}
success(res, { stats });
}, 'monitoring-stats'));
@@ -66,7 +80,86 @@ module.exports = function({ resourceMonitor, docker, asyncHandler, log }) {
success(res, { aggregated, hours });
}, 'monitoring-aggregated'));
// Configure alerts
// ===== ALERT CONFIGURATION (bulk) =====
// Get all alert configs
router.get('/monitoring/alerts/config', asyncHandler(async (req, res) => {
const configs = resourceMonitor.getAllAlertConfigs();
success(res, { configs });
}, 'monitoring-alerts-config-get'));
// Set all alert configs (bulk update)
router.post('/monitoring/alerts/config', asyncHandler(async (req, res) => {
const { configs } = req.body;
if (!configs || typeof configs !== 'object') {
const { ValidationError } = require('../errors');
throw new ValidationError('configs object required');
}
for (const [containerId, config] of Object.entries(configs)) {
resourceMonitor.setAlertConfig(containerId, config);
}
success(res, { message: 'Alert configurations saved' });
}, 'monitoring-alerts-config-set'));
// Get alert history
router.get('/monitoring/alerts', asyncHandler(async (req, res) => {
const limit = parseInt(req.query.limit) || 50;
const history = resourceMonitor.getAlertHistory(limit);
success(res, { history });
}, 'monitoring-alerts-history'));
// Send test alert notification for a container
router.post('/monitoring/alerts/:containerId/test', asyncHandler(async (req, res) => {
const { containerId } = req.params;
// Get container name from docker
let containerName = containerId;
try {
const containers = await docker.client.listContainers({ all: false });
const containerInfo = containers.find(c => c.Id === containerId || c.Id.startsWith(containerId));
if (containerInfo) {
containerName = containerInfo.Names[0]?.replace(/^\//, '') || containerId;
}
} catch (_) {}
const testAlert = {
containerId,
containerName,
timestamp: new Date().toISOString(),
alerts: [{
type: 'test',
severity: 'info',
message: 'This is a test alert notification',
value: 0,
threshold: 0
}],
stats: null,
config: resourceMonitor.getAlertConfig(containerId) || {}
};
if (notificationManager) {
await notificationManager.sendAlert(testAlert);
}
// Also log to alert history
resourceMonitor.addAlertHistoryEntry({
id: `test-${Date.now()}`,
timestamp: new Date().toISOString(),
containerId,
containerName,
type: 'test',
metric: 'test',
value: 0,
threshold: 0,
severity: 'info',
notified: true,
autoRestartTriggered: false
});
success(res, { message: 'Test alert sent', alert: testAlert });
}, 'monitoring-alerts-test'));
// Configure alerts for a container
router.post('/monitoring/alerts/:containerId', asyncHandler(async (req, res) => {
resourceMonitor.setAlertConfig(req.params.containerId, req.body);
success(res, { message: 'Alert configuration saved' });
+41
View File
@@ -218,5 +218,46 @@ module.exports = function({ notification, asyncHandler }) {
});
}, 'notifications-health-check'));
// GET /status — Get notification system status
router.get('/status', asyncHandler(async (req, res) => {
const notificationConfig = notification.getConfig();
const providers = notificationConfig.providers || {};
res.json({
success: true,
enabled: notificationConfig.enabled,
providers: {
discord: providers.discord?.enabled && !!providers.discord?.webhookUrl,
telegram: providers.telegram?.enabled && !!providers.telegram?.botToken && !!providers.telegram?.chatId,
ntfy: providers.ntfy?.enabled && !!providers.ntfy?.topic,
email: providers.email?.enabled && !!providers.email?.host && !!providers.email?.to
},
lastSent: notification.lastSent,
healthCheck: notificationConfig.healthCheck?.enabled ? {
enabled: true,
lastCheck: notificationConfig.healthCheck.lastCheck,
intervalMinutes: notificationConfig.healthCheck.intervalMinutes
} : { enabled: false }
});
}, 'notifications-status'));
// POST /send — Manual test send (used by frontend "Send Test" button)
router.post('/send', asyncHandler(async (req, res) => {
const { event, data, type } = req.body;
if (!event) {
throw new ValidationError('Event type is required');
}
// Use 'test' as the event for manual sends
const result = await notification.send(event, data || {}, type || 'info');
res.json({
success: result.success,
event,
results: result.results
});
}, 'notifications-send'));
return router;
};
+272
View File
@@ -0,0 +1,272 @@
const express = require('express');
const http = require('http');
/**
* OpenClaw management routes
* Proxies gateway API calls through DashCaddy so the token never leaves the server.
*
* GET /openclaw/status container info + gateway health
* POST /openclaw/deploy deploy OpenClaw container
* GET /openclaw/proxy/* proxy GET to gateway
* POST /openclaw/proxy/* proxy POST to gateway
* DELETE /openclaw remove container
*/
module.exports = function openClawRoutes(ctx) {
const router = express.Router();
const docker = ctx.docker;
const asyncHandler = ctx.asyncHandler;
const log = ctx.log || console;
// ── helpers ──────────────────────────────────────────────────────────────
async function findOpenClawContainer() {
const containers = await docker.client.listContainers({ all: true });
return containers.find(function(c) {
return c.Image === 'ghcr.io/nousresearch/openclaw:latest' ||
(c.Labels && c.Labels['dashcaddy.managed'] === 'true' &&
c.Names.some(function(n) { return n.includes('openclaw'); }));
}) || null;
}
async function getGatewayToken(containerId) {
try {
const info = await docker.client.containerInfo(containerId);
const entry = (info.Config.Env || []).find(function(e) {
return e.startsWith('OPENCLAW_GATEWAY_TOKEN=');
});
return entry ? entry.split('=')[1] : null;
} catch(err) {
return null;
}
}
async function getContainerPort(containerId) {
try {
const containers = await docker.client.listContainers({ all: true });
const c = containers.find(function(x) {
return x.Id === containerId || x.Id.startsWith(containerId);
});
if (c && c.Ports) {
const p = c.Ports.find(function(x) { return x.PrivatePort === 18792; });
if (p && p.PublicPort) return String(p.PublicPort);
}
return '18792';
} catch(err) {
return '18792';
}
}
async function gatewayHealth(baseUrl, token) {
return new Promise(function(resolve) {
const headers = {};
if (token) headers['Authorization'] = 'Bearer ' + token;
const req = http.get(baseUrl + '/health', { headers: headers }, function(res) {
let data = '';
res.on('data', function(d) { data += d; });
res.on('end', function() {
try { resolve({ ok: true, data: JSON.parse(data) }); }
catch(e) { resolve({ ok: true, data: data }); }
});
});
req.on('error', function(e) { resolve({ ok: false, error: e.message }); });
req.setTimeout(5000, function() { req.destroy(); resolve({ ok: false, error: 'timeout' }); });
});
}
function proxyRequest(req, res, targetBase, path, token) {
const headers = {};
if (token) headers['Authorization'] = 'Bearer ' + token;
headers['X-Forwarded-For'] = req.ip;
headers['X-Forwarded-Proto'] = req.protocol;
const url = targetBase + '/' + path;
const method = req.method;
if (['POST', 'PUT', 'PATCH'].includes(method)) {
const body = JSON.stringify(req.body);
headers['Content-Type'] = 'application/json';
headers['Content-Length'] = Buffer.byteLength(body);
const proxyReq = http.request(url, { method: method, headers: headers }, function(proxyRes) {
res.set(proxyRes.headers);
res.status(proxyRes.statusCode);
proxyRes.on('data', function(d) { res.write(d); });
proxyRes.on('end', function() { res.end(); });
});
proxyReq.on('error', function(e) { res.status(502).json({ success: false, error: e.message }); });
proxyReq.setTimeout(15000, function() { proxyReq.destroy(); res.status(504).json({ success: false, error: 'gateway timeout' }); });
proxyReq.write(body);
proxyReq.end();
} else {
const proxyReq = http.get(url, { headers: headers }, function(proxyRes) {
res.set(proxyRes.headers);
res.status(proxyRes.statusCode);
proxyRes.on('data', function(d) { res.write(d); });
proxyRes.on('end', function() { res.end(); });
});
proxyReq.on('error', function(e) { res.status(502).json({ success: false, error: e.message }); });
proxyReq.setTimeout(15000, function() { proxyReq.destroy(); res.status(504).json({ success: false, error: 'gateway timeout' }); });
}
}
// ── GET /openclaw/status ────────────────────────────────────────────────
router.get('/status', asyncHandler(async function(req, res) {
const container = await findOpenClawContainer();
if (!container) {
return res.json({ success: true, deployed: false });
}
const token = await getGatewayToken(container.Id);
const port = await getContainerPort(container.Id);
const baseUrl = 'http://localhost:' + port;
const health = await gatewayHealth(baseUrl, token);
res.json({
success: true,
deployed: true,
container: {
id: container.Id.slice(0, 12),
name: container.Name,
state: container.State,
status: container.Status,
created: container.Created,
image: container.Image
},
gateway: {
url: baseUrl,
port: port,
healthy: health.ok,
healthData: health.data || null,
tokenSet: !!token
}
});
}));
// ── POST /openclaw/deploy ───────────────────────────────────────────────
router.post('/deploy', asyncHandler(async function(req, res) {
const existing = await findOpenClawContainer();
if (existing) {
return res.status(409).json({ success: false, error: 'OpenClaw is already deployed' });
}
const image = 'ghcr.io/nousresearch/openclaw:latest';
const name = 'openclaw-' + Date.now();
const gatewayToken = generateToken();
// Pull image
log.info('Pulling ' + image + '...');
try {
await new Promise(function(resolve, reject) {
docker.client.pull(image, function(err, stream) {
if (err) return reject(err);
docker.client.modem.followProgress(stream, function(err2) {
if (err2) return reject(err2);
resolve();
});
});
});
} catch(e) {
log.error('OpenClaw pull failed: ' + e.message);
return res.status(500).json({ success: false, error: 'Failed to pull image: ' + e.message });
}
// Create + start container
try {
const container = await docker.client.createContainer({
name: name,
Image: image,
Env: [
'OPENCLAW_GATEWAY_MODE=local',
'OPENCLAW_GATEWAY_TOKEN=' + gatewayToken
],
HostConfig: {
PortBindings: { '18792/tcp': [{ HostPort: '18792' }] },
RestartPolicy: { Name: 'unless-stopped' },
Labels: {
'dashcaddy.managed': 'true',
'dashcaddy.app': 'openclaw'
}
},
ExposedPorts: { '18792/tcp': {} }
});
await container.start();
log.info('OpenClaw deployed: ' + container.id.slice(0, 12));
res.json({
success: true,
deployed: true,
container: { id: container.id.slice(0, 12), name: name },
gateway: {
url: 'http://localhost:18792',
token: gatewayToken
}
});
} catch(e) {
log.error('OpenClaw deploy failed: ' + e.message);
res.status(500).json({ success: false, error: 'Deploy failed: ' + e.message });
}
}));
// ── GET /openclaw/proxy/* ───────────────────────────────────────────────
router.get('/proxy/*', asyncHandler(async function(req, res) {
const container = await findOpenClawContainer();
if (!container) return res.status(404).json({ success: false, error: 'OpenClaw not deployed' });
const token = await getGatewayToken(container.Id);
const port = await getContainerPort(container.Id);
const baseUrl = 'http://localhost:' + port;
const path = req.params[0];
proxyRequest(req, res, baseUrl, path, token);
}));
// ── POST /openclaw/proxy/* ──────────────────────────────────────────────
router.post('/proxy/*', asyncHandler(async function(req, res) {
const container = await findOpenClawContainer();
if (!container) return res.status(404).json({ success: false, error: 'OpenClaw not deployed' });
const token = await getGatewayToken(container.Id);
const port = await getContainerPort(container.Id);
const baseUrl = 'http://localhost:' + port;
const path = req.params[0];
proxyRequest(req, res, baseUrl, path, token);
}));
// ── DELETE /openclaw ───────────────────────────────────────────────────
router.delete('/', asyncHandler(async function(req, res) {
const container = await findOpenClawContainer();
if (!container) return res.status(404).json({ success: false, error: 'OpenClaw not deployed' });
try {
const c = docker.client.container(container.Id);
await c.stop().catch(function() {});
await c.remove({ force: true });
log.info('OpenClaw container ' + container.Id.slice(0, 12) + ' removed');
res.json({ success: true, message: 'OpenClaw removed' });
} catch(e) {
log.error('Failed to remove OpenClaw: ' + e.message);
res.status(500).json({ success: false, error: e.message });
}
}));
return router;
};
// ── token generator ──────────────────────────────────────────────────────────
function generateToken() {
const chars = 'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789';
let result = '';
for (let i = 0; i < 32; i++) {
result += chars.charAt(Math.floor(Math.random() * chars.length));
}
return result;
}
+16 -7
View File
@@ -10,7 +10,8 @@ const { exists } = require('../fs-helpers');
const { paginate, parsePaginationParams } = require('../pagination');
const { ValidationError, NotFoundError, ConflictError } = require('../errors');
const { resolveServiceUrl } = require('../url-resolver');
const { success, error: errorResponse } = require('../response-helpers');
const { success, error: errorResponse } = require('../src/utils/responses');
const platformPaths = require('../platform-paths');
/**
* Services route factory
@@ -46,7 +47,7 @@ module.exports = function({
dns
}) {
const router = express.Router();
const CA_CERT_PATH = process.env.CA_CERT_PATH || '/app/pki/root.crt';
const CA_CERT_PATH = process.env.CA_CERT_PATH || platformPaths.pkiRootCert;
const PROBE_CONCURRENCY = 6;
let probeHttpsAgent;
@@ -372,7 +373,7 @@ module.exports = function({
// Add a new service
router.post('/services', asyncHandler(async (req, res) => {
try {
const { id, name, logo } = req.body;
const { id, name, logo, category, containerId, port, ip, tailscaleOnly } = req.body;
if (!id || !name) {
throw new ValidationError('id and name are required');
@@ -391,7 +392,14 @@ module.exports = function({
throw new ConflictError(`Service "${id}" already exists`, id);
}
services.push({ id, name, logo: logo || `/assets/${id}.png` });
const newService = { id, name, logo: logo || `/assets/${id}.png` };
// Persist optional metadata fields if provided
if (category) newService.category = category;
if (containerId) newService.containerId = containerId;
if (port) newService.port = port;
if (ip) newService.ip = ip;
if (typeof tailscaleOnly === 'boolean') newService.tailscaleOnly = tailscaleOnly;
services.push(newService);
return services;
});
@@ -513,9 +521,8 @@ module.exports = function({
if (oldSubdomain !== newSubdomain) {
try {
const dnsToken = dns.getToken();
await dns.call(siteConfig.dnsServerIp, '/api/zones/records/delete', { token: dnsToken, domain: oldDomain, type: 'A' });
await dns.createRecord(newSubdomain, ip || 'localhost');
await dns.universalDeleteRecord(oldDomain);
await dns.universalCreateRecord(newSubdomain, ip || 'localhost');
results.dns = 'updated';
} catch (e) {
results.dns = `failed: ${e.message}`;
@@ -542,6 +549,8 @@ module.exports = function({
};
if (name) services[serviceIndex].name = name;
if (logo) services[serviceIndex].logo = logo;
// Allow category update via update endpoint too (optional body field)
if (req.body.category !== undefined) services[serviceIndex].category = req.body.category || undefined;
results.services = 'updated';
} else {
results.services = 'not found';
+3 -2
View File
@@ -3,6 +3,7 @@ const fs = require('fs');
const { CADDY, REGEX, LIMITS } = require('../constants');
const { ValidationError, ConflictError, NotFoundError } = require('../errors');
const { validateURL } = require('../input-validator');
const { ok } = require('../src/utils/responses');
/**
* Sites route factory
@@ -127,7 +128,7 @@ module.exports = function({ asyncHandler, caddy, dns, fetchT, buildDomain, addSe
name: ca.name,
displayName: ca.name !== (ca.id || ca.name) ? `${ca.name} (${ca.id || ca.name})` : ca.name
}));
res.json({ status: 'success', data: { cas: caList } });
ok(res, { cas: caList });
}, 'caddy-get-cas'));
// Remove a site from Caddyfile
@@ -205,7 +206,7 @@ module.exports = function({ asyncHandler, caddy, dns, fetchT, buildDomain, addSe
if (createDns) {
try {
await dns.createRecord(subdomain, siteConfig.dnsServerIp);
await dns.universalCreateRecord(subdomain, siteConfig.dnsServerIp);
log.info('dns', 'DNS record created for external proxy', { domain, ip: siteConfig.dnsServerIp });
} catch (dnsError) {
dnsWarning = `DNS creation failed: ${dnsError.message}. You may need to create the DNS record manually.`;
+113
View File
@@ -0,0 +1,113 @@
/**
* SSL Monitor Routes
* REST API endpoints for SSL certificate monitoring.
*
* @module routes/ssl-monitor
*/
const express = require('express');
const { success, error: errorResponse, notFound } = require('../src/utils/responses');
/**
* SSL Monitor route factory
* @param {Object} deps - Explicit dependencies
* @param {Object} deps.sslMonitor - SSLMonitor instance
* @param {Function} deps.asyncHandler - Async route handler wrapper
* @param {Function} deps.logError - Error logging function
* @returns {express.Router}
*/
module.exports = function({ sslMonitor, asyncHandler, logError }) {
const router = express.Router();
/**
* GET /ssl/certificates
* Get all SSL certificate statuses
*/
router.get('/certificates', asyncHandler(async (req, res) => {
const status = sslMonitor.getStatus();
success(res, { certificates: status });
}, 'ssl-certificates'));
/**
* GET /ssl/certificates/:serviceId
* Get SSL certificate status for a specific service
*/
router.get('/certificates/:serviceId', asyncHandler(async (req, res) => {
const { serviceId } = req.params;
const certStatus = sslMonitor.getServiceCertStatus(serviceId);
if (!certStatus) {
return notFound(res, `No SSL certificate status found for service: ${serviceId}`);
}
success(res, { certificate: certStatus });
}, 'ssl-certificate-service'));
/**
* POST /ssl/check
* Trigger an on-demand check of all SSL certificates
*/
router.post('/check', asyncHandler(async (req, res) => {
const results = await sslMonitor.checkAll();
success(res, { certificates: results, message: 'SSL check completed' });
}, 'ssl-check-all'));
/**
* POST /ssl/check/:serviceId
* Check the SSL certificate for a specific service
*/
router.post('/check/:serviceId', asyncHandler(async (req, res) => {
const { serviceId } = req.params;
// Look up the existing cert status to find the hostname
const existingCert = sslMonitor.getServiceCertStatus(serviceId);
if (!existingCert) {
return notFound(res, `No HTTPS URL found for service: ${serviceId}`);
}
try {
const result = await sslMonitor.checkCert(existingCert.hostname, existingCert.port);
success(res, { certificate: { ...result, serviceId } });
} catch (err) {
errorResponse(res, `Failed to check SSL certificate: ${err.message}`, 500);
}
}, 'ssl-check-service'));
/**
* GET /ssl/config
* Get current SSL monitoring configuration
*/
router.get('/config', asyncHandler(async (req, res) => {
const config = sslMonitor.getConfig();
success(res, { config });
}, 'ssl-config-get'));
/**
* POST /ssl/config
* Update SSL monitoring configuration
* Body: { enabled: boolean, intervalMs: number }
*/
router.post('/config', asyncHandler(async (req, res) => {
const { enabled, intervalMs } = req.body;
// Validate inputs
if (enabled !== undefined && typeof enabled !== 'boolean') {
return errorResponse(res, 'enabled must be a boolean', 400);
}
if (intervalMs !== undefined) {
if (typeof intervalMs !== 'number' || intervalMs < 60000) {
return errorResponse(res, 'intervalMs must be a number >= 60000 (1 minute)', 400);
}
}
const updates = {};
if (enabled !== undefined) updates.enabled = enabled;
if (intervalMs !== undefined) updates.intervalMs = intervalMs;
sslMonitor.updateConfig(updates);
const config = sslMonitor.getConfig();
success(res, { config, message: 'SSL monitoring config updated' });
}, 'ssl-config-update'));
return router;
};
+3 -2
View File
@@ -1,8 +1,9 @@
const express = require('express');
const fs = require('fs');
const path = require('path');
const { success } = require('../response-helpers');
const { success } = require('../src/utils/responses');
const { ValidationError, NotFoundError } = require('../errors');
const platformPaths = require('../platform-paths');
/**
* Themes routes factory
@@ -13,7 +14,7 @@ const { ValidationError, NotFoundError } = require('../errors');
*/
module.exports = function({ asyncHandler, log }) {
const router = express.Router();
const THEMES_DIR = process.env.THEMES_DIR || path.join(path.dirname(process.env.SERVICES_FILE || '/app/services.json'), 'themes');
const THEMES_DIR = process.env.THEMES_DIR || path.join(path.dirname(platformPaths.servicesFile), 'themes');
// Ensure themes directory exists
if (!fs.existsSync(THEMES_DIR)) {
+65
View File
@@ -0,0 +1,65 @@
const express = require('express');
/**
* Workflows routes factory
* @param {Object} deps - Explicit dependencies
* @param {Object} deps.workflowEngine - WorkflowEngine instance
* @param {Object} deps.licenseManager - License manager for premium gating
* @param {Function} deps.asyncHandler - Async route handler wrapper
* @returns {express.Router}
*/
module.exports = function({ workflowEngine, licenseManager, asyncHandler }) {
const router = express.Router();
// Apply premium gating to all workflows routes
router.use(licenseManager.requirePremium('workflows'));
// ===== WORKFLOW MANAGEMENT ENDPOINTS =====
// List all bundled workflows
router.get('/workflows', asyncHandler(async (req, res) => {
const workflows = workflowEngine.listWorkflows();
res.json({ success: true, workflows });
}, 'workflows-list'));
// Enable a workflow
router.post('/workflows/:workflowId/enable', asyncHandler(async (req, res) => {
const { workflowId } = req.params;
const result = workflowEngine.setWorkflowEnabled(workflowId, true);
res.json({ success: true, ...result });
}, 'workflows-enable'));
// Disable a workflow
router.post('/workflows/:workflowId/disable', asyncHandler(async (req, res) => {
const { workflowId } = req.params;
const result = workflowEngine.setWorkflowEnabled(workflowId, false);
res.json({ success: true, ...result });
}, 'workflows-disable'));
// Manually trigger a workflow
router.post('/workflows/:workflowId/run', asyncHandler(async (req, res) => {
const { workflowId } = req.params;
const triggerData = req.body || {};
triggerData.trigger = 'manual';
const result = await workflowEngine.executeWorkflow(workflowId, triggerData);
res.json({ success: true, result });
}, 'workflows-run'));
// Get execution history for a workflow
router.get('/workflows/:workflowId/history', asyncHandler(async (req, res) => {
const { workflowId } = req.params;
const limit = parseInt(req.query.limit) || 50;
const history = workflowEngine.getHistory(workflowId, limit);
res.json({ success: true, history });
}, 'workflows-history'));
// Get all workflow execution history
router.get('/workflows/history', asyncHandler(async (req, res) => {
const limit = parseInt(req.query.limit) || 100;
const history = workflowEngine.getHistory(null, limit);
res.json({ success: true, history });
}, 'workflows-all-history'));
return router;
};
+147 -98
View File
@@ -1,7 +1,7 @@
#!/usr/bin/env bash
# DashCaddy Host-Side Updater
# Triggered by systemd path unit when the container writes trigger.json.
# Reads the trigger, backs up current API, copies new files, rebuilds container.
# Reads the trigger, backs up current API + data/, copies new files, rebuilds container.
# Writes result.json so the new container knows the outcome.
#
# This runs on the HOST, outside the container.
@@ -16,6 +16,10 @@ readonly CONTAINER_NAME="dashcaddy-api"
readonly MAX_BACKUPS=3
readonly HEALTH_TIMEOUT=60
# Data directory backup — stored alongside code backups so everything rolls back together
readonly DATA_SOURCE_DIR="/opt/dashcaddy/dashcaddy-api/data"
readonly DATA_BACKUP_PREFIX="data-backup"
log() { echo "[dashcaddy-update] $(date '+%Y-%m-%d %H:%M:%S') $*"; }
write_result() {
@@ -56,6 +60,34 @@ cleanup_old_backups() {
fi
}
# ── Data backup (rsync for efficiency + permissions) ──────────────────────────
backup_data_dir() {
local backup_dir="$1"
if [[ -d "$DATA_SOURCE_DIR" ]]; then
log "Backing up data/ to ${backup_dir}/${DATA_BACKUP_PREFIX}/"
mkdir -p "${backup_dir}/${DATA_BACKUP_PREFIX}"
rsync -a --delete "$DATA_SOURCE_DIR/" "${backup_dir}/${DATA_BACKUP_PREFIX}/" 2>/dev/null \
|| cp -a "$DATA_SOURCE_DIR" "${backup_dir}/${DATA_BACKUP_PREFIX}"
log "Data backup complete ($(du -sh "${backup_dir}/${DATA_BACKUP_PREFIX}" 2>/dev/null | cut -f1))"
else
log "WARNING: Data source dir $DATA_SOURCE_DIR not found — skipping data backup"
fi
}
# ── Data restore ──────────────────────────────────────────────────────────────
restore_data_dir() {
local backup_dir="$1"
local data_backup="${backup_dir}/${DATA_BACKUP_PREFIX}"
if [[ -d "$data_backup" ]]; then
log "Restoring data/ from backup..."
rsync -a --delete "$data_backup/" "$DATA_SOURCE_DIR/" 2>/dev/null \
|| cp -a "$data_backup" "$DATA_SOURCE_DIR"
log "Data restored successfully"
else
log "WARNING: No data backup found at ${data_backup} — data/ not restored"
fi
}
wait_for_health() {
local port="${1:-3001}"
local timeout="$HEALTH_TIMEOUT"
@@ -75,6 +107,59 @@ wait_for_health() {
return 1
}
# ── Shared rollback: restore code + data ────────────────────────────────────
rollback_restore() {
local backup_dir="$1"
log "Rolling back: restoring code files..."
for item in "$backup_dir"/*.js "$backup_dir"/package.json "$backup_dir"/package-lock.json "$backup_dir"/Dockerfile "$backup_dir"/openapi.yaml "$backup_dir"/VERSION; do
[[ -f "$item" ]] && cp -f "$item" "$api_source_dir/" 2>/dev/null || true
done
if [[ -d "$backup_dir/routes" ]]; then
rm -rf "$api_source_dir/routes"
cp -rf "$backup_dir/routes" "$api_source_dir/routes"
fi
if [[ -d "$backup_dir/src" ]]; then
rm -rf "$api_source_dir/src"
cp -rf "$backup_dir/src" "$api_source_dir/src"
fi
restore_data_dir "$backup_dir"
}
# ── Shared container restart (preserves SERVICES_FILE env var) ───────────────
# Uses rm + run so new env vars (e.g. SERVICES_FILE) take effect.
# If docker-compose is not configured, falls back to docker start.
restart_container() {
local image="$1"
log "Restarting container (rm + run to pick up env vars)..."
# Stop and remove existing container so new env var is applied
docker rm -f "$CONTAINER_NAME" 2>/dev/null || true
# Re-create with same volumes and the SERVICES_FILE env var
docker run -d --restart unless-stopped --name "$CONTAINER_NAME" \
-p 127.0.0.1:3001:3001 \
-v /opt/dashcaddy/dashcaddy-api/data:/app/data \
-e SERVICES_FILE=/app/data/services.json \
"$image"
log "Container restarted with fresh env"
}
# ── Code-only restore (used after failed build when data hasn't changed yet) ──
code_restore() {
local backup_dir="$1"
log "Restoring code files..."
for item in "$backup_dir"/*.js "$backup_dir"/package.json "$backup_dir"/package-lock.json "$backup_dir"/Dockerfile "$backup_dir"/openapi.yaml "$backup_dir"/VERSION; do
[[ -f "$item" ]] && cp -f "$item" "$api_source_dir/" 2>/dev/null || true
done
if [[ -d "$backup_dir/routes" ]]; then
rm -rf "$api_source_dir/routes"
cp -rf "$backup_dir/routes" "$api_source_dir/routes"
fi
if [[ -d "$backup_dir/src" ]]; then
rm -rf "$api_source_dir/src"
cp -rf "$backup_dir/src" "$api_source_dir/src"
fi
}
main() {
local start_time
start_time=$(date +%s)
@@ -94,45 +179,69 @@ main() {
staging_dir=$(python3 -c "import json; print(json.load(open('${TRIGGER_FILE}'))['stagingDir'])")
api_source_dir=$(python3 -c "import json; print(json.load(open('${TRIGGER_FILE}'))['apiSourceDir'])")
commit=$(python3 -c "import json; print(json.load(open('${TRIGGER_FILE}')).get('commit') or '')")
# Frontend paths — optional (older self-updaters don't write these). When
# present, this script also syncs the dashboard files (Caddy serves them
# directly from the host; the container path /app/dashboard isn't mounted).
frontend_staging_dir=$(python3 -c "import json; print(json.load(open('${TRIGGER_FILE}')).get('frontendStagingDir') or '')")
frontend_target_dir=$(python3 -c "import json; print(json.load(open('${TRIGGER_FILE}')).get('frontendTargetDir') or '')")
# Handle action=rollback (no new version to deploy)
local to_version="${version}"
log "=== ${action^^}: v${from_version} -> v${version} ==="
log "=== ${action^^}: v${from_version} -> v${to_version} ==="
log "Staging: ${staging_dir}"
log "API source: ${api_source_dir}"
# Consume the trigger immediately so we don't re-process on failure
mv "$TRIGGER_FILE" "${TRIGGER_FILE}.processing"
# 2. Validate staging directory
# ── Handle rollback ────────────────────────────────────────────────────────
if [[ "$action" == "rollback" ]]; then
local backup_dir="${BACKUPS_DIR}/${version}"
if [[ ! -d "$backup_dir" ]]; then
log "ERROR: No backup found for version ${version}"
write_result "false" "$version" "$(( $(date +%s) - start_time ))" "No backup found for version ${version}"
rm -f "${TRIGGER_FILE}.processing"
exit 1
fi
log "Performing rollback to v${version}..."
rollback_restore "$backup_dir"
# Rebuild old code
log "Rebuilding container..."
cd "$api_source_dir"
docker build -t dashcaddy-dashcaddy-api:latest . 2>&1 | tail -1 || true
restart_container "dashcaddy-dashcaddy-api:latest"
wait_for_health || log "WARNING: Health check failed after rollback"
write_result "true" "$version" "$(( $(date +%s) - start_time ))"
rm -f "${TRIGGER_FILE}.processing"
log "=== Rollback complete ==="
exit 0
fi
# ── Handle update ───────────────────────────────────────────────────────────
if [[ ! -d "$staging_dir" ]]; then
log "ERROR: Staging directory not found: ${staging_dir}"
write_result "false" "$version" "$(( $(date +%s) - start_time ))" "Staging directory not found"
write_result "false" "$to_version" "$(( $(date +%s) - start_time ))" "Staging directory not found"
rm -f "${TRIGGER_FILE}.processing"
exit 1
fi
# 3. Backup current API files
# 2. Backup current API code + data/
local backup_dir="${BACKUPS_DIR}/${from_version}"
mkdir -p "$backup_dir"
log "Backing up current API files to ${backup_dir}"
# Copy all JS files, package.json, Dockerfile, and tracked subdirs
for item in "$api_source_dir"/*.js "$api_source_dir"/package.json "$api_source_dir"/package-lock.json "$api_source_dir"/Dockerfile "$api_source_dir"/openapi.yaml "$api_source_dir"/VERSION; do
[[ -f "$item" ]] && cp -f "$item" "$backup_dir/" 2>/dev/null || true
done
[[ -d "$api_source_dir/routes" ]] && cp -rf "$api_source_dir/routes" "$backup_dir/"
[[ -d "$api_source_dir/src" ]] && cp -rf "$api_source_dir/src" "$backup_dir/"
# VERSION (commit hash) was copied from api_source_dir above; preserve as-is
# so a rollback restores the original commit marker. The version *string* is
# already encoded in the backup dir name (${from_version}).
# Backup data/ directory (services.json, config.json, credentials, etc.)
backup_data_dir "$backup_dir"
cleanup_old_backups
# 4. Copy new files from staging to API source
# 3. Copy new files from staging to API source
log "Deploying new API files..."
for item in "$staging_dir"/*.js "$staging_dir"/package.json "$staging_dir"/package-lock.json "$staging_dir"/Dockerfile "$staging_dir"/openapi.yaml "$staging_dir"/VERSION; do
[[ -f "$item" ]] && cp -f "$item" "$api_source_dir/" 2>/dev/null || true
@@ -145,19 +254,11 @@ main() {
rm -rf "$api_source_dir/src"
cp -rf "$staging_dir/src" "$api_source_dir/src"
fi
# Belt-and-suspenders: always write the commit from trigger.json to VERSION,
# even if the tarball didn't include one. The container's self-updater uses
# this to detect the "same version, different commit" case.
if [[ -n "$commit" ]]; then
echo "$commit" > "$api_source_dir/VERSION"
fi
# 4b. Sync frontend. Caddy serves the dashboard directly from the host
# filesystem; the container-side copy in older self-updater.js builds wrote
# to /app/dashboard which isn't always mounted, so the real sync happens
# here. Trigger fields take precedence; if absent (older self-updater),
# fall back to: staging dir's sibling status/ + first existing known target.
# 3b. Sync frontend
if [[ -z "$frontend_staging_dir" ]]; then
parent_staging=$(dirname "$staging_dir")
[[ -d "$parent_staging/status" ]] && frontend_staging_dir="$parent_staging/status"
@@ -175,107 +276,55 @@ main() {
for sub in dist css vendor js; do
if [[ -d "$frontend_staging_dir/$sub" ]]; then
mkdir -p "$frontend_target_dir/$sub"
cp -rf "$frontend_staging_dir/$sub"/* "$frontend_target_dir/$sub/" 2>/dev/null || true
cp -rf "$frontend_staging_dir/$sub/"* "$frontend_target_dir/$sub/" 2>/dev/null || true
fi
done
# assets/ is mounted into the container; usually already in sync via bind
# mount, but if a release ships new assets we want them on disk too.
if [[ -d "$frontend_staging_dir/assets" ]]; then
mkdir -p "$frontend_target_dir/assets"
cp -rf "$frontend_staging_dir/assets"/* "$frontend_target_dir/assets/" 2>/dev/null || true
cp -rf "$frontend_staging_dir/assets/"* "$frontend_target_dir/assets/" 2>/dev/null || true
fi
fi
# 5. Rebuild container
# 4. Rebuild container
log "Rebuilding container..."
cd "$api_source_dir"
local build_ok=false
if docker compose build --quiet 2>&1; then
build_ok=true
elif docker-compose build --quiet 2>&1; then
local image_tag="dashcaddy-dashcaddy-api:latest"
if docker build -t "$image_tag" . 2>&1; then
build_ok=true
fi
if [[ "$build_ok" != "true" ]]; then
log "ERROR: Docker build failed — rolling back"
# Restore backup
for item in "$backup_dir"/*.js "$backup_dir"/package.json "$backup_dir"/package-lock.json "$backup_dir"/Dockerfile "$backup_dir"/openapi.yaml "$backup_dir"/VERSION; do
[[ -f "$item" ]] && cp -f "$item" "$api_source_dir/" 2>/dev/null || true
done
if [[ -d "$backup_dir/routes" ]]; then
rm -rf "$api_source_dir/routes"
cp -rf "$backup_dir/routes" "$api_source_dir/routes"
fi
if [[ -d "$backup_dir/src" ]]; then
rm -rf "$api_source_dir/src"
cp -rf "$backup_dir/src" "$api_source_dir/src"
fi
write_result "false" "$version" "$(( $(date +%s) - start_time ))" "Docker build failed"
log "ERROR: Docker build failed — rolling back code + data"
code_restore "$backup_dir"
docker build -t "$image_tag" . 2>&1 | tail -3 || true
restart_container "$image_tag"
wait_for_health || true
write_result "false" "$to_version" "$(( $(date +%s) - start_time ))" "Docker build failed"
rm -f "${TRIGGER_FILE}.processing"
exit 1
fi
# 6. Restart container
log "Restarting container..."
if docker compose up -d 2>&1 || docker-compose up -d 2>&1; then
log "Container restarted"
else
log "ERROR: Container restart failed — rolling back"
# 5. Restart container (rm + run so new env vars take effect)
restart_container "$image_tag"
# Restore backup
for item in "$backup_dir"/*.js "$backup_dir"/package.json "$backup_dir"/package-lock.json "$backup_dir"/Dockerfile "$backup_dir"/openapi.yaml "$backup_dir"/VERSION; do
[[ -f "$item" ]] && cp -f "$item" "$api_source_dir/" 2>/dev/null || true
done
if [[ -d "$backup_dir/routes" ]]; then
rm -rf "$api_source_dir/routes"
cp -rf "$backup_dir/routes" "$api_source_dir/routes"
fi
if [[ -d "$backup_dir/src" ]]; then
rm -rf "$api_source_dir/src"
cp -rf "$backup_dir/src" "$api_source_dir/src"
fi
docker compose build --quiet 2>&1 || docker-compose build --quiet 2>&1 || true
docker compose up -d 2>&1 || docker-compose up -d 2>&1 || true
write_result "false" "$version" "$(( $(date +%s) - start_time ))" "Container restart failed"
rm -f "${TRIGGER_FILE}.processing"
exit 1
fi
# 7. Health check
# 6. Health check
if wait_for_health; then
local duration=$(( $(date +%s) - start_time ))
log "=== Update successful: v${version} in ${duration}s ==="
write_result "true" "$version" "$duration"
log "=== Update successful: v${to_version} in ${duration}s ==="
write_result "true" "$to_version" "$duration"
else
local duration=$(( $(date +%s) - start_time ))
log "ERROR: Health check failed after update — rolling back"
# Restore backup
for item in "$backup_dir"/*.js "$backup_dir"/package.json "$backup_dir"/package-lock.json "$backup_dir"/Dockerfile "$backup_dir"/openapi.yaml "$backup_dir"/VERSION; do
[[ -f "$item" ]] && cp -f "$item" "$api_source_dir/" 2>/dev/null || true
done
if [[ -d "$backup_dir/routes" ]]; then
rm -rf "$api_source_dir/routes"
cp -rf "$backup_dir/routes" "$api_source_dir/routes"
fi
if [[ -d "$backup_dir/src" ]]; then
rm -rf "$api_source_dir/src"
cp -rf "$backup_dir/src" "$api_source_dir/src"
fi
docker compose build --quiet 2>&1 || docker-compose build --quiet 2>&1 || true
docker compose up -d 2>&1 || docker-compose up -d 2>&1 || true
log "ERROR: Health check failed after update — rolling back code + data"
rollback_restore "$backup_dir"
docker build -t "$image_tag" . 2>&1 | tail -3 || true
restart_container "$image_tag"
wait_for_health || log "WARNING: Rollback health check also failed"
write_result "false" "$version" "$duration" "Health check failed after update"
write_result "false" "$to_version" "$duration" "Health check failed after update"
fi
# 8. Cleanup
# 7. Cleanup
rm -f "${TRIGGER_FILE}.processing"
rm -rf "${UPDATES_DIR}/staging" 2>/dev/null || true
+5 -5
View File
@@ -21,17 +21,17 @@ const isWindows = platformPaths.isWindows;
const DEFAULTS = {
CHECK_INTERVAL: 30 * 60 * 1000, // 30 minutes
UPDATE_URL: 'https://get.dashcaddy.net/release',
MIRROR_URL: 'https://get2.dashcaddy.net/release',
UPDATES_DIR: platformPaths.isWindows ? path.join(platformPaths.caddyBase, 'updates') : '/app/updates',
UPDATE_URL: process.env.DASHCADDY_UPDATE_URL || 'https://get.dashcaddy.net/release',
MIRROR_URL: process.env.DASHCADDY_MIRROR_URL || 'https://get2.dashcaddy.net/release',
UPDATES_DIR: platformPaths.containerUpdatesDir,
// API_SOURCE_DIR is the HOST path — written to trigger.json for the host-side updater
API_SOURCE_DIR: path.join(platformPaths.caddySites, 'dashcaddy-api'),
// FRONTEND_DIR is the container path — dashboard is volume-mounted at /app/dashboard
FRONTEND_DIR: platformPaths.isWindows ? path.join(platformPaths.caddySites, 'status') : '/app/dashboard',
FRONTEND_DIR: platformPaths.containerFrontendDir,
MAX_BACKUPS: 3,
HEALTH_TIMEOUT: 60000,
DOWNLOAD_TIMEOUT: 120000,
CHANNEL: 'stable',
CHANNEL: process.env.DASHCADDY_UPDATE_CHANNEL || 'stable',
INSTANCE_ID_FILE: platformPaths.isWindows
? path.join(platformPaths.caddyBase, 'instance-id')
: '/etc/dashcaddy/instance-id',
+43 -3
View File
@@ -25,7 +25,8 @@ process.on('uncaughtException', (error) => {
// Load license
await licenseManager.load();
const PORT = process.env.PORT || 3001;
const PORT = parseInt(process.env.PORT, 10) || 3001;
const HOST = process.env.HOST || '0.0.0.0';
const CADDYFILE_PATH = process.env.CADDYFILE_PATH || platformPaths.caddyfile;
const CADDY_ADMIN_URL = process.env.CADDY_ADMIN_URL || platformPaths.caddyAdminUrl;
const SERVICES_FILE = process.env.SERVICES_FILE || platformPaths.servicesFile;
@@ -43,9 +44,10 @@ process.on('uncaughtException', (error) => {
});
// Start HTTP server
const server = app.listen(PORT, '0.0.0.0', () => {
const server = app.listen(PORT, HOST, () => {
log.info('server', 'DashCaddy API server started', {
port: PORT,
host: HOST,
caddyfile: CADDYFILE_PATH,
caddyAdmin: CADDY_ADMIN_URL,
services: SERVICES_FILE,
@@ -67,9 +69,38 @@ process.on('uncaughtException', (error) => {
const portLockManager = require('./port-lock-manager');
// Optional modules
let dockerMaintenance, logDigest;
let dockerMaintenance, logDigest, bundledWorkflows;
try { dockerMaintenance = require('./docker-maintenance'); } catch { /* optional */ }
try { logDigest = require('./log-digest'); } catch { /* optional */ }
try { bundledWorkflows = require('./bundled-workflows'); } catch { /* optional */ }
// Initialize workflow engine if bundled-workflows is available
// NOTE: createApp() already initializes the workflow engine in src/app.js
// This block is kept for backward compat with entry points that don't use createApp()
let workflowEngine = null;
if (bundledWorkflows) {
try {
const { fetchT } = require('./src/utils/http');
const { WorkflowEngine } = bundledWorkflows;
// Create a context with needed services
const workflowCtx = {
docker: { client: require('dockerode')() },
notification: require('./notification-manager')({
NOTIFICATIONS_FILE: process.env.NOTIFICATIONS_FILE || require('./platform-paths').notificationsFile,
fetchT,
log,
config
}),
backupManager,
resourceMonitor,
servicesStateManager
};
workflowEngine = new WorkflowEngine(workflowCtx);
log.info('server', 'Workflow engine initialized');
} catch (err) {
log.error('server', 'Workflow engine failed to initialize', { error: err.message });
}
}
log.info('server', 'Starting feature modules');
@@ -81,6 +112,10 @@ process.on('uncaughtException', (error) => {
// Resource monitoring
try {
resourceMonitor.start();
// Connect workflow engine to resource monitor for resource-alert events
if (workflowEngine) {
resourceMonitor.setWorkflowEngine(workflowEngine);
}
log.info('server', 'Resource monitoring started');
} catch (err) {
log.error('server', 'Resource monitoring failed to start', { error: err.message });
@@ -94,6 +129,11 @@ process.on('uncaughtException', (error) => {
log.error('server', 'Backup manager failed to start', { error: err.message });
}
// Connect workflow engine to update manager for pre-update events
if (workflowEngine) {
updateManager.setWorkflowEngine(workflowEngine);
}
// Health checker (with service sync)
(async () => {
try {
+257 -6
View File
@@ -16,6 +16,7 @@ const { asyncHandler } = require('./utils/async-handler');
// Managers and utilities
const StateManager = require('../state-manager');
const platformPaths = require('../platform-paths');
const { LicenseManager } = require('../license-manager');
const credentialManager = require('../credential-manager');
const authManager = require('../auth-manager');
@@ -39,6 +40,13 @@ let dockerMaintenance, logDigest;
try { dockerMaintenance = require('../docker-maintenance'); } catch (_) { /* optional module */ }
try { logDigest = require('../log-digest'); } catch (_) { /* optional module */ }
// Workflow engine (bundled workflows)
let bundledWorkflowsModule;
let workflowEngine = null;
try {
bundledWorkflowsModule = require('../bundled-workflows');
} catch (_) { /* optional module */ }
// Templates
const { APP_TEMPLATES, TEMPLATE_CATEGORIES, DIFFICULTY_LEVELS } = require('../app-templates');
const { RECIPE_TEMPLATES, RECIPE_CATEGORIES } = require('../recipe-templates');
@@ -69,6 +77,16 @@ const recipesRoutes = require('../routes/recipes');
const themesRoutes = require('../routes/themes');
const dockerResourcesRoutes = require('../routes/docker-resources');
const eventsRoutes = require('../routes/events');
const workflowsRoutes = require('../routes/workflows');
const dependenciesRoutes = require('../routes/dependencies');
const DependencyManager = require('../dependency-manager');
const autoRestartRoutes = require('../routes/auto-restart');
const configDriftRoutes = require('../routes/config-drift');
const sslMonitorRoutes = require('../routes/ssl-monitor');
const { AutoRestartManager } = require('../auto-restart-manager');
const { ConfigDriftDetector } = require('../config-drift-detector');
const SSLMonitor = require('../ssl-monitor');
const DNSPropagationChecker = require('../dns-propagation');
// Constants
const { APP } = require('../constants');
@@ -79,6 +97,19 @@ const { APP } = require('../constants');
async function createApp() {
const app = express();
// Global request timeout (default 5 minutes — covers slow Docker pulls)
// Routes that need longer can override per-request with req.setTimeout()
const REQUEST_TIMEOUT_MS = parseInt(process.env.REQUEST_TIMEOUT_MS, 10) || 5 * 60 * 1000;
app.use((req, res, next) => {
req.setTimeout(REQUEST_TIMEOUT_MS);
res.setTimeout(REQUEST_TIMEOUT_MS);
next();
});
// Disable x-powered-by header for security (don't advertise framework)
app.disable('x-powered-by');
// Trust first proxy (Caddy/nginx in front of us) so req.ip works correctly
app.set('trust proxy', 1);
// Initialize logging
const log = createLogger(config.LOG_LEVEL);
@@ -94,7 +125,7 @@ async function createApp() {
licenseManager.loadSecret(config.LICENSE_SECRET_FILE);
// HTTPS agent for internal CA
const CA_CERT_PATH = process.env.CA_CERT_PATH || '/app/pki/root.crt';
const CA_CERT_PATH = process.env.CA_CERT_PATH || platformPaths.pkiRootCert;
let httpsAgent;
try {
const caCert = fs.readFileSync(CA_CERT_PATH);
@@ -308,9 +339,111 @@ async function createApp() {
app,
});
// Initialize workflow engine if bundled-workflows is available
if (bundledWorkflowsModule && ctx.docker) {
try {
const { WorkflowEngine } = bundledWorkflowsModule;
const workflowCtx = {
docker: ctx.docker,
notification: ctx.notification,
backupManager: ctx.backupManager,
resourceMonitor: ctx.resourceMonitor,
servicesStateManager: ctx.servicesStateManager
};
workflowEngine = new WorkflowEngine(workflowCtx);
ctx.workflowEngine = workflowEngine;
log.info('app', 'Workflow engine initialized');
} catch (err) {
log.error('app', 'Failed to initialize workflow engine', { error: err.message });
}
}
// Initialize dependency manager
const dependencyManager = new DependencyManager({
servicesStateManager,
docker: ctx.docker,
notification: ctx.notification,
log,
});
ctx.dependencyManager = dependencyManager;
log.info('app', 'Dependency manager initialized');
// Initialize auto-restart manager
const autoRestartManager = new AutoRestartManager(ctx);
ctx.autoRestartManager = autoRestartManager;
autoRestartManager.start();
log.info('app', 'Auto-restart manager initialized');
// Initialize config drift detector
const driftDetector = new ConfigDriftDetector(ctx);
ctx.driftDetector = driftDetector;
driftDetector.startPolling(300000); // 5 min
log.info('app', 'Config drift detector initialized');
// Initialize SSL monitor
const sslMonitor = new SSLMonitor(ctx);
ctx.sslMonitor = sslMonitor;
sslMonitor.start(3600000); // 1 hour
log.info('app', 'SSL monitor initialized');
// Initialize DNS propagation checker
const dnsPropagationChecker = new DNSPropagationChecker(ctx);
ctx.dnsPropagationChecker = dnsPropagationChecker;
log.info('app', 'DNS propagation checker initialized');
// Build versioned API router
const apiRouter = express.Router();
// Version endpoint — public, no auth required
// Reads version from package.json at startup so the response always matches the running code
let appVersion = '0.0.0';
let appName = 'dashcaddy-api';
try {
const pkg = require('../package.json');
appVersion = pkg.version || appVersion;
appName = pkg.name || appName;
} catch { /* package.json unreadable — keep fallback */ }
apiRouter.get('/version', (req, res) => {
res.json({
success: true,
name: appName,
version: appVersion,
node: process.version,
platform: process.platform,
arch: process.arch,
uptime: process.uptime(),
instanceId: process.env.DASHCADDY_INSTANCE_ID || null
});
});
log.info('app', `Version endpoint available at /api/v1/version (v${appVersion})`);
// Wire up notification listeners for resourceMonitor and backupManager
if (ctx.notification && ctx.resourceMonitor) {
ctx.resourceMonitor.on('alert', (alertData) => {
ctx.notification.sendAlert(alertData).catch(err => {
log.error('notification', 'Failed to send alert', { error: err.message });
});
});
ctx.resourceMonitor.on('auto-restart', (data) => {
ctx.notification.sendServiceEvent('auto-restart', data).catch(err => {
log.error('notification', 'Failed to send auto-restart notification', { error: err.message });
});
});
}
if (ctx.notification && ctx.backupManager) {
ctx.backupManager.on('backup-complete', (data) => {
ctx.notification.send('backup-complete', data).catch(err => {
log.error('notification', 'Failed to send backup-complete', { error: err.message });
});
});
ctx.backupManager.on('backup-failed', (data) => {
ctx.notification.send('backup-failed', data).catch(err => {
log.error('notification', 'Failed to send backup-failed', { error: err.message });
});
});
}
// Mount route modules
apiRouter.use(authRoutes(ctx));
apiRouter.use(configRoutes(ctx));
@@ -321,7 +454,8 @@ async function createApp() {
log: ctx.log,
safeErrorMessage: ctx.safeErrorMessage,
fetchT: ctx.fetchT,
credentialManager: ctx.credentialManager
credentialManager: ctx.credentialManager,
dnsPropagationChecker: ctx.dnsPropagationChecker
}));
apiRouter.use('/notifications', notificationRoutes({
notification: ctx.notification,
@@ -330,7 +464,8 @@ async function createApp() {
apiRouter.use('/containers', containerRoutes({
docker: ctx.docker,
log: ctx.log,
asyncHandler: ctx.asyncHandler
asyncHandler: ctx.asyncHandler,
workflowEngine: ctx.workflowEngine
}));
apiRouter.use(serviceRoutes({
servicesStateManager: ctx.servicesStateManager,
@@ -361,7 +496,8 @@ async function createApp() {
resourceMonitor: ctx.resourceMonitor,
docker: ctx.docker,
asyncHandler: ctx.asyncHandler,
log: ctx.log
log: ctx.log,
notificationManager: ctx.notification
}));
apiRouter.use(updatesRoutes({
updateManager: ctx.updateManager,
@@ -404,6 +540,7 @@ async function createApp() {
}));
apiRouter.use(backupsRoutes({
backupManager: ctx.backupManager,
licenseManager: ctx.licenseManager,
asyncHandler: ctx.asyncHandler
}));
apiRouter.use('/ca', caRoutes(ctx));
@@ -432,7 +569,41 @@ async function createApp() {
resourceMonitor: ctx.resourceMonitor,
healthChecker: ctx.healthChecker,
updateManager: ctx.updateManager,
logError: ctx.logError
logError: ctx.logError,
dependencyManager: ctx.dependencyManager,
autoRestartManager: ctx.autoRestartManager,
driftDetector: ctx.driftDetector,
sslMonitor: ctx.sslMonitor,
dnsPropagationChecker: ctx.dnsPropagationChecker
}));
apiRouter.use('/workflows', workflowsRoutes({
workflowEngine: ctx.workflowEngine,
licenseManager: ctx.licenseManager,
asyncHandler: ctx.asyncHandler
}));
apiRouter.use('/dependencies', dependenciesRoutes({
dependencyManager: ctx.dependencyManager,
servicesStateManager: ctx.servicesStateManager,
docker: ctx.docker,
asyncHandler: ctx.asyncHandler,
logError: ctx.logError,
resyncHealthChecker: ctx.resyncHealthChecker,
log: ctx.log,
}));
apiRouter.use(autoRestartRoutes({
autoRestartManager: ctx.autoRestartManager,
asyncHandler: ctx.asyncHandler,
logError: ctx.logError,
}));
apiRouter.use(configDriftRoutes({
driftDetector: ctx.driftDetector,
asyncHandler: ctx.asyncHandler,
logError: ctx.logError,
}));
apiRouter.use(sslMonitorRoutes({
sslMonitor: ctx.sslMonitor,
asyncHandler: ctx.asyncHandler,
logError: ctx.logError,
}));
// Inline API routes
@@ -456,6 +627,86 @@ async function createApp() {
res.json({ status: 'ok', timestamp: new Date().toISOString() });
});
// Liveness probe — "is the process alive?"
// Always returns 200 unless the Node.js event loop is completely blocked.
// Used by k8s/Docker to decide whether to RESTART the container.
// DO NOT add dependency checks here — those belong in /health/ready.
app.get('/health/live', (req, res) => {
res.json({ status: 'alive', uptime: process.uptime() });
});
// Readiness probe — "is the app ready to serve traffic?"
// Checks critical dependencies: Docker daemon, Caddy admin API, config file.
// Returns 200 with details if all OK, 503 with failed components otherwise.
// Used by k8s/Docker to decide whether to ROUTE TRAFFIC to this instance.
app.get('/health/ready', boundAsyncHandler(async (req, res) => {
const checks = {};
let allOk = true;
// Check 1: Config file readable
try {
const fs = require('fs');
if (fs.existsSync(config.CONFIG_FILE)) {
fs.readFileSync(config.CONFIG_FILE, 'utf8');
checks.configFile = { ok: true };
} else {
checks.configFile = { ok: false, error: 'Config file not found' };
allOk = false;
}
} catch (e) {
checks.configFile = { ok: false, error: e.message };
allOk = false;
}
// Check 2: Services file readable
try {
const fs = require('fs');
if (fs.existsSync(config.SERVICES_FILE)) {
fs.readFileSync(config.SERVICES_FILE, 'utf8');
checks.servicesFile = { ok: true };
} else {
checks.servicesFile = { ok: false, error: 'Services file not found' };
allOk = false;
}
} catch (e) {
checks.servicesFile = { ok: false, error: e.message };
allOk = false;
}
// Check 3: Docker daemon reachable
try {
const docker = require('dockerode')();
await docker.ping();
checks.docker = { ok: true };
} catch (e) {
checks.docker = { ok: false, error: e.message };
allOk = false;
}
// Check 4: Caddy admin API reachable
try {
const caddyUrl = config.CADDY_ADMIN_URL || 'http://localhost:2019';
const controller = new AbortController();
const timeout = setTimeout(() => controller.abort(), 3000);
const response = await fetch(`${caddyUrl}/config/`, {
signal: controller.signal
});
clearTimeout(timeout);
checks.caddy = { ok: response.ok, status: response.status };
if (!response.ok) allOk = false;
} catch (e) {
checks.caddy = { ok: false, error: e.message };
allOk = false;
}
const body = {
status: allOk ? 'ready' : 'not-ready',
timestamp: new Date().toISOString(),
checks
};
res.status(allOk ? 200 : 503).json(body);
}));
// Lightweight probe endpoint
app.get('/probe/:id', boundAsyncHandler(async (req, res) => {
const id = req.params.id;
+142
View File
@@ -0,0 +1,142 @@
/**
* Config migration system
*
* When config.json schema changes between versions, register a migration
* function here. On load, the loader detects the stored version, runs all
* migrations from that version forward, and writes the result back.
*
* Migration format:
* migrations[<toVersion>] = (rawConfig) => { ...mutations, _version: toVersion }
*
* Each migration is responsible for transforming the previous version's
* shape into the next version's shape. They run sequentially, so v1v2v3
* all execute in order.
*
* For first-time users with no config file, the loader creates a fresh
* config with CURRENT_VERSION, so they start at the latest schema.
*/
const fs = require('fs');
const path = require('path');
const platformPaths = require('../../platform-paths');
const CURRENT_VERSION = 2;
/**
* Migrations: keys are the version they PRODUCE.
* Each migration takes a raw config object and returns the next version.
*/
const migrations = {
// v0 (unversioned) → v1: add _version field, normalize dns structure
1: (raw) => {
const migrated = { ...raw };
if (!migrated._version) migrated._version = 1;
// Normalize: older configs may have dns as a string IP, convert to object
if (typeof migrated.dns === 'string') {
migrated.dns = { ip: migrated.dns, port: 5380 };
} else if (!migrated.dns) {
migrated.dns = { ip: '', port: 5380 };
}
return migrated;
},
// v1 → v2: add dns.provider field (default: 'technitium' for backwards compat)
2: (raw) => {
const migrated = { ...raw };
if (migrated.dns && !migrated.dns.provider) {
migrated.dns.provider = 'technitium';
}
migrated._version = 2;
return migrated;
}
};
/**
* Run all migrations from `fromVersion` (or detected) to CURRENT_VERSION.
* @param {object} raw - The raw config object (may or may not have _version)
* @returns {object} The migrated config
*/
function migrate(raw) {
if (!raw || typeof raw !== 'object') {
// First-time load: return minimal config at current version
return { _version: CURRENT_VERSION };
}
const fromVersion = raw._version || 0;
if (fromVersion > CURRENT_VERSION) {
// Config from a future version — bail out, don't corrupt it
// The validation step will catch any actual issues
return raw;
}
let current = { ...raw };
for (let v = fromVersion + 1; v <= CURRENT_VERSION; v++) {
if (migrations[v]) {
current = migrations[v](current);
} else {
// No migration defined for this version, just bump _version
current._version = v;
}
}
return current;
}
/**
* Load config from disk, run migrations if needed, and write back the
* migrated version. Safe to call on every startup.
* @param {string} configFile - Absolute path to config.json
* @param {object} log - Logger instance
* @returns {object} The migrated config object
*/
function loadAndMigrate(configFile, log) {
let raw = null;
let fileExisted = false;
if (fs.existsSync(configFile)) {
fileExisted = true;
try {
raw = JSON.parse(fs.readFileSync(configFile, 'utf8'));
} catch (e) {
if (log && log.error) {
log.error('config-migration', 'Failed to parse config.json, using defaults', { error: e.message });
}
raw = null;
}
}
const fromVersion = raw && raw._version ? raw._version : 0;
const migrated = migrate(raw);
// Only write back to disk if:
// 1. The file already existed (we don't create configs on fresh installs —
// the loader's defaults handle that case), AND
// 2. The version actually changed (no point rewriting identical content)
if (fileExisted && fromVersion < CURRENT_VERSION) {
if (log && log.info) {
log.info('config-migration', `Migrated config v${fromVersion} → v${CURRENT_VERSION}`, {
from: fromVersion,
to: CURRENT_VERSION,
path: configFile
});
}
// Write back the migrated config
try {
// Ensure parent dir exists
const dir = path.dirname(configFile);
if (!fs.existsSync(dir)) fs.mkdirSync(dir, { recursive: true });
fs.writeFileSync(configFile, JSON.stringify(migrated, null, 2));
} catch (e) {
if (log && log.warn) {
log.warn('config-migration', 'Failed to write migrated config back to disk', { error: e.message });
}
}
}
return migrated;
}
module.exports = {
CURRENT_VERSION,
migrations,
migrate,
loadAndMigrate
};
+11 -3
View File
@@ -1,10 +1,15 @@
/**
* Site configuration loader
* Loads and manages site-wide settings from config.json
*
* Includes automatic migration from older config versions (see migrations.js).
* Users never see the migration it runs silently on startup, writes the
* updated config back, and the rest of the app only ever sees the current
* schema.
*/
const fs = require('fs');
const { validateConfig } = require('../../config-schema');
const { CADDY } = require('../../constants');
const { loadAndMigrate, CURRENT_VERSION } = require('./migrations');
const siteConfig = {
tld: '.home',
@@ -21,9 +26,11 @@ const siteConfig = {
function loadSiteConfig(CONFIG_FILE, log) {
try {
if (fs.existsSync(CONFIG_FILE)) {
const raw = JSON.parse(fs.readFileSync(CONFIG_FILE, 'utf8'));
// Run migrations first — this handles config.json files from older
// versions of DashCaddy and writes the migrated version back to disk.
const raw = loadAndMigrate(CONFIG_FILE, log);
if (raw && Object.keys(raw).length > 0) {
// Validate config and log any issues
const { valid, errors: configErrors, warnings: configWarnings } = validateConfig(raw);
if (log && log.warn) {
@@ -76,4 +83,5 @@ module.exports = {
loadSiteConfig,
buildDomain,
buildServiceUrl,
CURRENT_VERSION
};
+2 -3
View File
@@ -93,9 +93,8 @@ async function verifySiteAccessible(domain, fetchT, httpsAgent, log, maxAttempts
try {
const response = await fetchT(`https://${domain}/`, {
method: 'HEAD',
agent: httpsAgent,
timeout: 5000
});
agent: httpsAgent
}, 5000);
log.info('caddy', 'Site is accessible', { domain, status: response.status });
return true;
+25 -3
View File
@@ -1,8 +1,14 @@
/**
* DNS context - Technitium DNS operations and token management
*
* DEPRECATED: This module is kept for backward compatibility.
* New code should use src/context/provider-dns.js which supports multiple providers.
*
* This module now delegates to the provider system internally.
*/
const { TIMEOUTS, SESSION_TTL, CADDY } = require('../../constants');
const { createCache, CACHE_CONFIGS } = require('../../cache-config');
const { createProviderDnsContext } = require('./provider-dns');
// DNS token management
let dnsToken = process.env.DNS_ADMIN_TOKEN || '';
@@ -52,9 +58,9 @@ async function refreshDnsToken(username, password, server, fetchT, log) {
headers: {
'Accept': 'application/json',
'Content-Type': 'application/x-www-form-urlencoded'
},
timeout: 10000
}
}
},
10000
);
const result = await response.json();
@@ -281,6 +287,10 @@ function invalidateTokenForServer(serverIp) {
}
function createDnsContext(siteConfig, buildDomain, credentialManager, fetchT, httpsAgent, log, DNS_CREDENTIALS_FILE) {
// Create the new provider-aware context
const providerCtx = createProviderDnsContext(siteConfig, buildDomain, credentialManager, fetchT, httpsAgent, log, DNS_CREDENTIALS_FILE);
// Legacy Technitium-specific wrappers (kept for backward compat)
const ensureToken = () => ensureValidDnsToken(siteConfig, credentialManager, fetchT, log);
const require = (providedToken) => requireDnsToken(providedToken, siteConfig, credentialManager, fetchT, log);
const getForServer = (server, role) => getTokenForServer(server, siteConfig, credentialManager, fetchT, log, role);
@@ -289,6 +299,7 @@ function createDnsContext(siteConfig, buildDomain, credentialManager, fetchT, ht
const call = (server, apiPath, params) => callDns(server, apiPath, params, fetchT, httpsAgent);
return {
// Legacy Technitium-specific interface (unchanged)
call,
buildUrl: buildDnsUrl,
requireToken: require,
@@ -302,6 +313,17 @@ function createDnsContext(siteConfig, buildDomain, credentialManager, fetchT, ht
invalidateTokenForServer,
refresh,
credentialsFile: DNS_CREDENTIALS_FILE,
// Provider-aware methods (new)
getProviderId: providerCtx.getProviderId,
getActiveProvider: providerCtx.getActiveProvider,
getAvailableProviders: providerCtx.getAvailableProviders,
supportsCapability: providerCtx.supportsCapability,
// Universal DNS helpers (delegated to provider context)
universalCreateRecord: providerCtx.universalCreateRecord,
universalDeleteRecord: providerCtx.universalDeleteRecord,
universalResolveRecord: providerCtx.universalResolveRecord,
};
}
+9 -5
View File
@@ -6,6 +6,7 @@ const { createDockerContext } = require('./docker');
const { createCaddyContext } = require('./caddy');
const { createDnsContext } = require('./dns');
const { createSessionContext } = require('./session');
const NotificationManager = require('../../notification-manager');
/**
* Assemble the full application context
@@ -85,11 +86,14 @@ function assembleContext({
const dns = createDnsContext(siteConfig, buildDomain, credentialManager, fetchT, httpsAgent, log, DNS_CREDENTIALS_FILE);
const session = createSessionContext(middlewareResult);
// Notification context (inline for now - could be extracted)
const notification = {
// These will be populated by server.js for now
// TODO: Extract notification module
};
// Create notification manager
const notification = new NotificationManager({
NOTIFICATIONS_FILE,
fetchT,
docker,
log,
config: siteConfig
});
// Tailscale context (inline for now - could be extracted)
const tailscale = {
+303
View File
@@ -0,0 +1,303 @@
/**
* Provider-aware DNS Context
* Replaces the Technitium-only context with a provider-agnostic layer.
* Delegates to the active DNS provider adapter based on config.
*
* Falls back to legacy Technitium context for backward compatibility
* when no provider is explicitly configured.
*/
const { createCache, CACHE_CONFIGS } = require('../../cache-config');
const { TIMEOUTS, SESSION_TTL, CADDY } = require('../../constants');
const registry = require('../../dns-providers/registry');
// Per-server token cache (legacy Technitium)
const dnsServerTokens = createCache(CACHE_CONFIGS.dnsTokens);
let dnsToken = '';
let dnsTokenExpiry = null;
/**
* Create a provider-aware DNS context.
* This wraps both the new provider system and the legacy Technitium context
* for seamless migration.
*/
function createProviderDnsContext(siteConfig, buildDomain, credentialManager, fetchT, httpsAgent, log, DNS_CREDENTIALS_FILE) {
/** Resolve the active provider from config */
function getProviderId() {
// New explicit provider field
if (siteConfig.dns?.provider) return siteConfig.dns.provider;
// Legacy: if dns.ip is set, default to technitium
if (siteConfig.dnsServerIp || siteConfig.dns?.ip) return 'technitium';
// No DNS configured
return 'manual';
}
/** Get provider-specific config from site config */
function getProviderConfig(providerId) {
const dnsConfig = siteConfig.dns || {};
switch (providerId) {
case 'technitium':
return {
serverIp: siteConfig.dnsServerIp || dnsConfig.ip || '',
serverPort: siteConfig.dnsServerPort || dnsConfig.port || '5380',
dnsServers: siteConfig.dnsServers || {},
dnsId: Object.keys(siteConfig.dnsServers || {})[0] || 'dns1'
};
case 'cloudflare':
return {
apiToken: dnsConfig.apiToken || '',
zoneId: dnsConfig.zoneId || '',
domain: siteConfig.domain || ''
};
case 'rfc2136':
return {
server: dnsConfig.server || siteConfig.dnsServerIp || '',
port: dnsConfig.port || 53,
zone: siteConfig.tld?.replace(/^\./, '') || '',
tsigAlgorithm: dnsConfig.tsigAlgorithm || 'hmac-sha256',
tsigKeyName: dnsConfig.tsigKeyName || '',
tsigSecret: dnsConfig.tsigSecret || ''
};
case 'manual':
return {};
default:
return dnsConfig;
}
}
/** Get or create the active provider adapter */
function getActiveProvider() {
const providerId = getProviderId();
const config = getProviderConfig(providerId);
const ctx = { log, credentialManager, fetchT, httpsAgent };
return registry.getProvider(providerId, config, ctx);
}
// ===== Legacy Technitium helpers (kept for backward compat) =====
function buildDnsUrl(server, apiPath, params) {
const protocol = server.match(/^\d+\.\d+\.\d+\.\d+$/) ? 'http' : 'https';
const port = protocol === 'http' ? `:${CADDY.DEFAULT_DNS_PORT}` : '';
const qs = params instanceof URLSearchParams ? params.toString() : new URLSearchParams(params).toString();
return `${protocol}://${server}${port}${apiPath}?${qs}`;
}
async function callDns(server, apiPath, params) {
const url = buildDnsUrl(server, apiPath, params);
const response = await fetchT(url, {
method: 'GET',
headers: { 'Accept': 'application/json' },
agent: httpsAgent
}, TIMEOUTS.HTTP_LONG);
return response.json();
}
async function refreshDnsToken(username, password, server) {
try {
const params = new URLSearchParams({ user: username, pass: password, includeInfo: 'false' });
const response = await fetchT(
`http://${server}:5380/api/user/login?${params.toString()}`,
{ method: 'POST', headers: { 'Accept': 'application/json', 'Content-Type': 'application/x-www-form-urlencoded' } },
10000
);
const result = await response.json();
if (result.status === 'ok' && result.token) {
dnsToken = result.token;
dnsTokenExpiry = new Date(Date.now() + SESSION_TTL.DNS_TOKEN).toISOString();
log.info('dns', 'DNS token refreshed', { expires: dnsTokenExpiry });
return { success: true, token: dnsToken };
}
return { success: false, error: result.errorMessage || 'Login failed' };
} catch (error) {
log.error('dns', 'DNS token refresh error', { error: error.message });
return { success: false, error: error.message };
}
}
function dnsIpToDnsId(serverIp) {
for (const [dnsId, info] of Object.entries(siteConfig.dnsServers || {})) {
if (info.ip === serverIp) return dnsId;
}
return null;
}
async function ensureValidDnsToken() {
if (dnsToken && dnsTokenExpiry && new Date() < new Date(dnsTokenExpiry)) {
return { success: true, token: dnsToken };
}
const primaryIp = siteConfig.dnsServerIp;
if (primaryIp) {
const dnsId = dnsIpToDnsId(primaryIp);
if (dnsId) {
for (const role of ['admin', 'readonly']) {
try {
const username = await credentialManager.retrieve(`dns.${dnsId}.${role}.username`);
const password = await credentialManager.retrieve(`dns.${dnsId}.${role}.password`);
if (username && password) return await refreshDnsToken(username, password, primaryIp);
} catch (err) { /* try next */ }
}
}
}
try {
const username = await credentialManager.retrieve('dns.username');
const password = await credentialManager.retrieve('dns.password');
const server = await credentialManager.retrieve('dns.server');
if (username && password) return await refreshDnsToken(username, password, server || primaryIp);
} catch (err) { /* no global creds */ }
return { success: false, error: 'No DNS credentials configured' };
}
async function getTokenForServer(targetServer, role = 'readonly') {
const cacheKey = `${targetServer}:${role}`;
const cached = dnsServerTokens.get(cacheKey);
if (cached?.token && cached?.expiry && new Date() < new Date(cached.expiry)) {
return { success: true, token: cached.token };
}
const serverPort = siteConfig.dnsServerPort || '5380';
async function authToServer(username, password) {
const params = new URLSearchParams({ user: username, pass: password, includeInfo: 'false' });
const response = await fetchT(
`http://${targetServer}:${serverPort}/api/user/login?${params.toString()}`,
{ method: 'POST', headers: { 'Accept': 'application/json', 'Content-Type': 'application/x-www-form-urlencoded' } }
);
const result = await response.json();
if (result.status === 'ok' && result.token) {
dnsServerTokens.set(cacheKey, { token: result.token, expiry: new Date(Date.now() + SESSION_TTL.DNS_TOKEN).toISOString() });
log.info('dns', 'DNS token obtained for server', { server: targetServer, role });
return { success: true, token: result.token };
}
return { success: false, error: result.errorMessage || 'Login failed' };
}
const dnsId = dnsIpToDnsId(targetServer);
if (dnsId) {
for (const r of [role, role === 'readonly' ? 'admin' : 'readonly']) {
try {
const username = await credentialManager.retrieve(`dns.${dnsId}.${r}.username`);
const password = await credentialManager.retrieve(`dns.${dnsId}.${r}.password`);
if (username && password) return await authToServer(username, password);
} catch { /* try next */ }
}
}
try {
const username = await credentialManager.retrieve('dns.username');
const password = await credentialManager.retrieve('dns.password');
if (username && password) return await authToServer(username, password);
} catch { /* no global creds */ }
return { success: false, error: 'No DNS credentials configured' };
}
async function requireDnsToken(providedToken) {
if (providedToken) return providedToken;
const result = await ensureValidDnsToken();
if (result.success) return result.token;
const err = new Error('No valid DNS token available. ' + result.error);
err.statusCode = 401;
throw err;
}
function invalidateTokenForServer(serverIp) {
dnsServerTokens.delete(`${serverIp}:readonly`);
dnsServerTokens.delete(`${serverIp}:admin`);
}
// ===== Public context API =====
// This maintains the same interface as the old createDnsContext()
// but adds provider-aware methods on top.
return {
// --- Provider-aware methods ---
/** Get the active provider ID */
getProviderId,
/** Get the active provider adapter instance */
getActiveProvider,
/** Get metadata for all available providers */
getAvailableProviders: () => registry.getProviderMeta(),
/** Check if the active provider supports a capability */
supportsCapability: (cap) => {
try { return getActiveProvider().supportsCapability(cap); }
catch { return false; }
},
// --- Legacy Technitium context (backward compat) ---
call: callDns,
buildUrl: buildDnsUrl,
requireToken: requireDnsToken,
ensureToken: ensureValidDnsToken,
getToken: () => dnsToken,
setToken: (t) => { dnsToken = t; },
getTokenExpiry: () => dnsTokenExpiry,
setTokenExpiry: (e) => { dnsTokenExpiry = e; },
getTokenForServer,
invalidateTokenForServer,
refresh: refreshDnsToken,
credentialsFile: DNS_CREDENTIALS_FILE,
// --- Universal DNS helpers (provider-agnostic) ---
/**
* Create a DNS A record using the active provider.
* Gracefully handles manual adapters that return instructions instead of performing the action.
*/
async universalCreateRecord(subdomain, ip) {
const provider = getActiveProvider();
const result = await provider.createRecord({
domain: buildDomain(subdomain),
zone: siteConfig.tld?.replace(/^\./, '') || '',
type: 'A',
value: ip,
ttl: 300,
overwrite: true,
});
// Manual adapter returns instructions instead of performing the action
if (result?.manual || result?.instructions) {
return { success: true, manual: true, instructions: result.instructions || result };
}
return result;
},
/**
* Delete a DNS A record using the active provider.
* Gracefully handles manual adapters that return instructions instead of performing the action.
*/
async universalDeleteRecord(domain, ip) {
const provider = getActiveProvider();
const result = await provider.deleteRecord({
domain,
type: 'A',
value: ip,
});
if (result?.manual || result?.instructions) {
return { success: true, manual: true, instructions: result.instructions || result };
}
return result;
},
/**
* Resolve DNS records using the active provider.
* Returns parsed IP addresses from the result.
*/
async universalResolveRecord(domain, type) {
const provider = getActiveProvider();
const result = await provider.resolveRecords({
domain,
zone: siteConfig.tld?.replace(/^\./, '') || '',
type: type || 'A',
});
// Parse IP addresses from the result
if (Array.isArray(result)) {
return result;
}
if (result?.records) {
return result.records.map(r => r.ipAddress || r.value || r.address || r).filter(Boolean);
}
if (result?.ips) {
return result.ips;
}
return result;
},
};
}
module.exports = { createProviderDnsContext };
+9 -1
View File
@@ -38,7 +38,15 @@ function fetchT(url, opts = {}, timeoutMs = TIMEOUTS.HTTP_DEFAULT) {
if (!opts.signal) {
opts = { ...opts, signal: AbortSignal.timeout(timeoutMs) };
}
delete opts.timeout;
// The `timeout` key in fetch() opts is silently ignored by undici. Callers
// should use the third arg of fetchT() (timeoutMs) instead. If a caller
// passes `timeout: N` here, it's almost certainly a bug — we used to silently
// strip it, which masked the issue. Now we surface it in logs and strip it.
if ('timeout' in opts) {
console.warn(`[fetchT] opts.timeout=${opts.timeout} is ignored — pass timeoutMs as the 3rd arg of fetchT() instead. Called from: ${new Error().stack.split('\n').slice(2, 4).join(' <- ')}`);
const { timeout, ...rest } = opts;
opts = rest;
}
return fetch(url, opts);
}
+5 -1
View File
@@ -94,8 +94,12 @@ async function logError(ERROR_LOG_FILE, MAX_ERROR_LOG_SIZE, context, error, addi
* Return a safe error message without leaking internals
*/
function safeErrorMessage(error) {
if (!error) return 'An internal error occurred';
const msg = error.message || String(error);
// Always expose DC-prefixed user-facing errors
if (/\[DC-\d+\]/.test(msg)) return msg;
// Detect port conflict errors
const portMatch = msg.match(/exposing port TCP [^:]*:(\d+)/);
if (portMatch || msg.includes('port is already allocated') || msg.includes('ports are not available')) {
@@ -103,7 +107,7 @@ function safeErrorMessage(error) {
return `[DC-200] Port ${port} is already in use. Try a different port or stop the service using that port first.`;
}
// Only expose short, user-facing messages
// Only expose short, user-facing messages (no paths, stack traces, or internal details)
if (msg.length < 200 && !msg.includes('/') && !msg.includes('\\') && !msg.includes(' at ')) {
return msg;
}
+107 -5
View File
@@ -1,22 +1,124 @@
/**
* Response helpers - Standard API response formats
*
* Single source of truth for HTTP response shapes across DashCaddy.
* Standard envelope: { success: true, ...data } or { success: false, error: "..." }.
*
* All routes should import from this module do not call res.json/res.status
* directly with the response shape, use these helpers instead.
*/
const { HTTP_STATUS } = require('../../constants');
// ── Success helpers ────────────────────────────────────────────
/**
* Standard error response
* Standard success response. Use this in route handlers.
* Wraps the data object with a `success: true` envelope.
* @param {object} res Express response
* @param {object} [data={}] fields to include in the response body
* @param {number} [statusCode=200] HTTP status code
*/
function ok(res, data = {}, statusCode = HTTP_STATUS.OK) {
return res.status(statusCode).json({ success: true, ...data });
}
/**
* Alias for `ok` prefer `ok` in new code, but kept for code that imports as `success`.
*/
function success(res, data, statusCode) {
return ok(res, data, statusCode);
}
/**
* Success response with a human-readable message field.
* Use when there's no data to return, just confirmation.
*/
function successMessage(res, message, statusCode = HTTP_STATUS.OK) {
return res.status(statusCode).json({ success: true, message });
}
/**
* 201 Created response.
*/
function created(res, data = {}) {
return res.status(HTTP_STATUS.CREATED).json({ success: true, ...data });
}
/**
* 204 No Content response.
*/
function noContent(res) {
return res.status(HTTP_STATUS.NO_CONTENT).send();
}
// ── Error helpers ──────────────────────────────────────────────
/**
* Standard error response. Use this in route handlers.
* @param {object} res Express response
* @param {number} statusCode HTTP status code
* @param {string} message Human-readable error message
* @param {object} [extras={}] additional fields to merge into the response
*/
function errorResponse(res, statusCode, message, extras = {}) {
return res.status(statusCode).json({ success: false, error: message, ...extras });
}
/**
* Standard success response
* Alias for `errorResponse` kept for code that imports as `error`.
*/
function ok(res, data = {}) {
return res.json({ success: true, ...data });
function error(res, message, statusCode = HTTP_STATUS.INTERNAL_ERROR) {
return res.status(statusCode).json({ success: false, error: message });
}
/**
* 400 Bad Request invalid input from the user.
*/
function validationError(res, message) {
return res.status(HTTP_STATUS.BAD_REQUEST).json({ success: false, error: message });
}
/**
* 401 Unauthorized no valid credentials.
*/
function unauthorized(res, message = 'Unauthorized') {
return res.status(HTTP_STATUS.UNAUTHORIZED).json({ success: false, error: message });
}
/**
* 403 Forbidden credentials valid but permission denied.
*/
function forbidden(res, message = 'Forbidden') {
return res.status(HTTP_STATUS.FORBIDDEN).json({ success: false, error: message });
}
/**
* 404 Not Found resource doesn't exist.
*/
function notFound(res, message = 'Not found') {
return res.status(HTTP_STATUS.NOT_FOUND).json({ success: false, error: message });
}
/**
* 409 Conflict request conflicts with current state (e.g. duplicate).
*/
function conflict(res, message) {
return res.status(HTTP_STATUS.CONFLICT).json({ success: false, error: message });
}
module.exports = {
errorResponse,
// Success helpers
ok,
success,
successMessage,
created,
noContent,
// Error helpers
errorResponse,
error,
validationError,
unauthorized,
forbidden,
notFound,
conflict,
};
+411
View File
@@ -0,0 +1,411 @@
/**
* SSL Certificate Monitor
* Periodically checks SSL certificates on services with HTTPS URLs.
* Alerts at 30, 14, and 7 days before expiry.
*
* @module ssl-monitor
*/
const tls = require('tls');
const EventEmitter = require('events');
const path = require('path');
const { readJsonFile, writeJsonFile } = require('./fs-helpers');
const { resolveServiceUrl } = require('./url-resolver');
/** Default check interval: 1 hour */
const DEFAULT_INTERVAL_MS = 3600000;
/** Alert thresholds in days */
const THRESHOLDS = {
WARNING: 30,
URGENT: 14,
CRITICAL: 7
};
/** TLS connection timeout in milliseconds */
const TLS_TIMEOUT_MS = 10000;
class SSLMonitor extends EventEmitter {
/**
* Create an SSLMonitor instance.
* @param {Object} ctx - Shared application context
* @param {Object} ctx.servicesStateManager - State manager for reading services
* @param {Function} ctx.buildServiceUrl - URL builder helper
* @param {Object} ctx.siteConfig - Site configuration
* @param {Object} ctx.notification - NotificationManager instance
* @param {Object} ctx.log - Logger instance
* @param {string} [ctx.SSL_CACHE_FILE] - Path to persist SSL cache
*/
constructor(ctx) {
super();
this.ctx = ctx;
this.log = ctx.log || console;
/** @type {Map<string, Object>} hostname → last cert check result */
this.certStatus = new Map();
/** @type {Map<string, number>} hostname → last notified threshold level */
this.notifiedThresholds = new Map();
/** @type {Map<string, string>} hostname → service ID mapping */
this.hostnameToServiceId = new Map();
/** @type {NodeJS.Timeout|null} */
this.intervalHandle = null;
/** Current config */
this.config = {
enabled: true,
intervalMs: DEFAULT_INTERVAL_MS
};
/** Cache file path */
this.cacheFile = ctx.SSL_CACHE_FILE ||
path.join(path.dirname(ctx.SERVICES_FILE || './data'), 'ssl-cache.json');
}
/**
* Check the SSL certificate for a given hostname and port.
* Connects via TLS with rejectUnauthorized: false to retrieve certificate info.
*
* @param {string} hostname - The hostname to check
* @param {number} [port=443] - The port to connect to
* @returns {Promise<Object>} Certificate information
*/
async checkCert(hostname, port = 443) {
return new Promise((resolve, reject) => {
const socket = tls.connect({
host: hostname,
port,
rejectUnauthorized: false,
servername: hostname,
timeout: TLS_TIMEOUT_MS
}, () => {
try {
const cert = socket.getPeerCertificate();
if (!cert || Object.keys(cert).length === 0) {
socket.destroy();
return reject(new Error(`No certificate returned for ${hostname}:${port}`));
}
const validFrom = new Date(cert.valid_from);
const validTo = new Date(cert.valid_to);
const now = new Date();
const msRemaining = validTo.getTime() - now.getTime();
const daysRemaining = Math.ceil(msRemaining / (1000 * 60 * 60 * 24));
const result = {
hostname,
port,
subject: cert.subject?.CN || cert.subject?.O || 'Unknown',
issuer: cert.issuer?.CN || cert.issuer?.O || 'Unknown',
validFrom: cert.valid_from,
validTo: cert.valid_to,
daysRemaining,
fingerprint: cert.fingerprint || null,
isExpiring: daysRemaining <= THRESHOLDS.WARNING,
checkedAt: new Date().toISOString()
};
socket.destroy();
resolve(result);
} catch (err) {
socket.destroy();
reject(err);
}
});
socket.on('error', (err) => {
reject(new Error(`TLS connect error for ${hostname}:${port}: ${err.message}`));
});
socket.setTimeout(TLS_TIMEOUT_MS, () => {
socket.destroy(new Error(`TLS connection timeout for ${hostname}:${port}`));
reject(new Error(`TLS connection timeout for ${hostname}:${port}`));
});
});
}
/**
* Check SSL certificates for all services that have HTTPS URLs.
* Reads services from ctx.servicesStateManager, resolves URLs, and checks each HTTPS cert.
*
* @returns {Promise<Object>} Map of hostname cert status
*/
async checkAll() {
if (!this.config.enabled) {
this.log.info('ssl-monitor', 'SSL monitoring is disabled, skipping check');
return this.getStatus();
}
let servicesData;
try {
servicesData = await this.ctx.servicesStateManager.read();
} catch (err) {
this.log.error('ssl-monitor', 'Failed to read services', { error: err.message });
return this.getStatus();
}
const services = Array.isArray(servicesData) ? servicesData : (servicesData.services || []);
for (const service of services) {
const serviceId = service.id || service.name?.toLowerCase();
if (!serviceId) continue;
try {
const url = resolveServiceUrl(serviceId, service, this.ctx.siteConfig, this.ctx.buildServiceUrl);
if (!url) continue;
const parsed = new URL(url);
if (parsed.protocol !== 'https:') continue;
const hostname = parsed.hostname;
const port = parseInt(parsed.port) || 443;
// Map hostname back to service ID
this.hostnameToServiceId.set(hostname, serviceId);
const result = await this.checkCert(hostname, port);
// Store result
this.certStatus.set(hostname, result);
// Emit check event
this.emit('cert-check', { serviceId, hostname, result });
// Check alert thresholds
await this._checkAndNotify(hostname, result, serviceId);
} catch (err) {
this.log.warn('ssl-monitor', `Failed to check cert for service ${serviceId}`, {
error: err.message
});
}
}
// Persist results
await this._saveCache();
return this.getStatus();
}
/**
* Start periodic SSL certificate checking.
*
* @param {number} [intervalMs=3600000] - Check interval in milliseconds
*/
start(intervalMs) {
if (intervalMs !== undefined) {
this.config.intervalMs = intervalMs;
}
if (this.intervalHandle) {
this.log.warn('ssl-monitor', 'SSL monitor is already running');
return;
}
this.config.enabled = true;
// Load cached data
this._loadCache().catch(err => {
this.log.warn('ssl-monitor', 'Failed to load SSL cache', { error: err.message });
});
// Initial check (non-blocking)
this.checkAll().catch(err => {
this.log.error('ssl-monitor', 'Initial SSL check failed', { error: err.message });
});
// Schedule periodic checks
this.intervalHandle = setInterval(() => {
this.checkAll().catch(err => {
this.log.error('ssl-monitor', 'Periodic SSL check failed', { error: err.message });
});
}, this.config.intervalMs);
this.log.info('ssl-monitor', 'SSL monitoring started', {
intervalMs: this.config.intervalMs
});
}
/**
* Stop periodic SSL certificate checking.
*/
stop() {
if (this.intervalHandle) {
clearInterval(this.intervalHandle);
this.intervalHandle = null;
}
this.config.enabled = false;
this.log.info('ssl-monitor', 'SSL monitoring stopped');
}
/**
* Get the current SSL certificate status for all checked hostnames.
*
* @returns {Object} Map of hostname cert status
*/
getStatus() {
const status = {};
for (const [hostname, cert] of this.certStatus.entries()) {
status[hostname] = { ...cert };
}
return status;
}
/**
* Get the SSL certificate status for a specific service.
*
* @param {string} serviceId - The service ID to look up
* @returns {Object|null} Certificate status or null if not found
*/
getServiceCertStatus(serviceId) {
// Find hostname mapped to this service
for (const [hostname, id] of this.hostnameToServiceId.entries()) {
if (id === serviceId) {
const cert = this.certStatus.get(hostname);
return cert ? { ...cert, serviceId } : null;
}
}
return null;
}
/**
* Get current monitoring configuration.
*
* @returns {Object} Config with interval and enabled state
*/
getConfig() {
return { ...this.config };
}
/**
* Update monitoring configuration.
*
* @param {Object} updates - Config updates
* @param {boolean} [updates.enabled] - Enable/disable monitoring
* @param {number} [updates.intervalMs] - Check interval in milliseconds
*/
updateConfig(updates) {
if (typeof updates.enabled === 'boolean') {
this.config.enabled = updates.enabled;
if (!updates.enabled && this.intervalHandle) {
this.stop();
}
}
if (typeof updates.intervalMs === 'number' && updates.intervalMs >= 60000) {
this.config.intervalMs = updates.intervalMs;
// Restart interval if running
if (this.intervalHandle) {
clearInterval(this.intervalHandle);
this.intervalHandle = setInterval(() => {
this.checkAll().catch(err => {
this.log.error('ssl-monitor', 'Periodic SSL check failed', { error: err.message });
});
}, this.config.intervalMs);
}
}
}
// ===== Private Methods =====
/**
* Check alert thresholds and send notifications if thresholds are crossed.
* Only sends one notification per threshold per hostname.
*
* @param {string} hostname
* @param {Object} certResult
* @param {string} serviceId
*/
async _checkAndNotify(hostname, certResult, serviceId) {
const { daysRemaining } = certResult;
const key = hostname;
const lastNotified = this.notifiedThresholds.get(key) || Infinity;
let level = null;
let eventType = null;
let message = null;
if (daysRemaining <= THRESHOLDS.CRITICAL) {
level = THRESHOLDS.CRITICAL;
eventType = 'cert-critical';
message = `🔒 CRITICAL: SSL certificate for ${hostname} expires in ${daysRemaining} days!`;
} else if (daysRemaining <= THRESHOLDS.URGENT) {
level = THRESHOLDS.URGENT;
eventType = 'cert-expiring';
message = `⚠️ URGENT: SSL certificate for ${hostname} expires in ${daysRemaining} days`;
} else if (daysRemaining <= THRESHOLDS.WARNING) {
level = THRESHOLDS.WARNING;
eventType = 'cert-expiring';
message = `⚠️ SSL certificate for ${hostname} expires in ${daysRemaining} days`;
}
if (level !== null && level < lastNotified) {
// New threshold crossed — send notification
this.notifiedThresholds.set(key, level);
this.emit(eventType, { hostname, serviceId, daysRemaining, level });
if (this.ctx.notification) {
try {
await this.ctx.notification.send('ssl-cert-expiry', {
text: message,
hostname,
serviceId,
daysRemaining,
level,
validTo: certResult.validTo
}, level <= THRESHOLDS.CRITICAL ? 'error' : 'warning');
} catch (err) {
this.log.error('ssl-monitor', 'Failed to send SSL notification', { error: err.message });
}
}
} else if (level === null) {
// Cert is healthy — reset notification tracking
this.notifiedThresholds.delete(key);
}
}
/**
* Persist cert status cache to disk.
*/
async _saveCache() {
try {
const data = {
lastChecked: new Date().toISOString(),
certs: {},
hostnameToServiceId: Object.fromEntries(this.hostnameToServiceId)
};
for (const [hostname, cert] of this.certStatus.entries()) {
data.certs[hostname] = cert;
}
await writeJsonFile(this.cacheFile, data);
} catch (err) {
this.log.warn('ssl-monitor', 'Failed to save SSL cache', { error: err.message });
}
}
/**
* Load cert status cache from disk.
*/
async _loadCache() {
try {
const data = await readJsonFile(this.cacheFile, null);
if (data && data.certs) {
for (const [hostname, cert] of Object.entries(data.certs)) {
this.certStatus.set(hostname, cert);
}
if (data.hostnameToServiceId) {
for (const [hostname, serviceId] of Object.entries(data.hostnameToServiceId)) {
this.hostnameToServiceId.set(hostname, serviceId);
}
}
this.log.info('ssl-monitor', 'Loaded SSL cache', {
certCount: this.certStatus.size
});
}
} catch (err) {
this.log.warn('ssl-monitor', 'Failed to load SSL cache', { error: err.message });
}
}
}
module.exports = SSLMonitor;
+38
View File
@@ -64,6 +64,38 @@ class UpdateManager extends EventEmitter {
}
}
/**
* Trigger bundled workflows for an event
*/
triggerWorkflows(eventType, eventData) {
if (!this.workflowEngine) {
console.log('[UpdateManager] Workflow engine not set, skipping workflow trigger');
return;
}
try {
this.workflowEngine.triggerForEvent(eventType, eventData)
.then(results => {
if (results && results.length > 0) {
console.log(`[UpdateManager] Triggered ${results.length} workflow(s) for ${eventType}`);
}
})
.catch(err => {
console.error('[UpdateManager] Workflow trigger error:', err.message);
});
} catch (error) {
console.error('[UpdateManager] Error triggering workflows:', error.message);
}
}
/**
* Set the workflow engine for triggering workflows
*/
setWorkflowEngine(workflowEngine) {
this.workflowEngine = workflowEngine;
console.log('[UpdateManager] Workflow engine configured');
}
/**
* Check for updates for all containers
*/
@@ -281,6 +313,12 @@ class UpdateManager extends EventEmitter {
timestamp: new Date().toISOString()
};
// Emit pre-update event for bundled workflows (e.g., backup-before-update)
this.emit('pre-update', { containerId, containerName, imageName, backup });
// Also trigger workflows for pre-update event directly
this.triggerWorkflows('pre-update', { containerId, containerName, appId: containerName, imageName });
// Pull latest image
console.log(`[UpdateManager] Pulling latest image: ${imageName}`);
await this.pullImage(imageName);
+83
View File
@@ -0,0 +1,83 @@
#!/bin/bash
# =============================================================================
# DashCaddy Gitea — Off-host backup to Dropbox
# =============================================================================
# - Stops gitea container briefly to ensure SQLite DB consistency
# - Syncs /var/lib/docker/volumes/gitea-data to dropbox:/Apps/dashcaddy-gitea-backups/<date>/
# - Date-stamped snapshots (one per day), kept for 7 days locally
# - Restarts gitea even if sync fails
# - Logs to /var/log/gitea-backup.log
# =============================================================================
set -u # don't use -e: we want to always restart gitea
LOG=/var/log/gitea-backup.log
DATA_SRC=/var/lib/docker/volumes/gitea-data/_data
DEST="dropbox:/Apps/dashcaddy-gitea-backups"
TODAY=$(date -u +%Y-%m-%d)
BACKUP_PATH="${DEST}/${TODAY}"
RETENTION_DAYS=7
log() { echo "[$(date -u +%Y-%m-%dT%H:%M:%SZ)] $*" | tee -a "$LOG"; }
log "=== Backup start ==="
# 0. Sanity checks
if [ ! -d "$DATA_SRC" ]; then
log "ERROR: data dir $DATA_SRC missing"
exit 1
fi
# 1. Stop gitea to flush SQLite
log "Stopping gitea container..."
docker stop gitea >> "$LOG" 2>&1
STOP_RC=$?
if [ $STOP_RC -ne 0 ]; then
log "WARNING: docker stop returned $STOP_RC — container may not be running"
fi
# 2. Sync (use copy so source files are preserved as-is, no --delete)
log "Syncing $DATA_SRC -> $BACKUP_PATH"
rclone copy "$DATA_SRC" "$BACKUP_PATH" \
--transfers 4 \
--checkers 8 \
--retries 3 \
--low-level-retries 10 \
--stats 30s \
--log-file "$LOG" \
--log-level INFO
SYNC_RC=$?
# 3. Always restart gitea
log "Starting gitea container..."
docker start gitea >> "$LOG" 2>&1
START_RC=$?
# Wait for gitea to be ready
for i in {1..30}; do
if curl -sf http://localhost:3000/api/v1/version > /dev/null 2>&1; then
log "Gitea is up after ${i}s"
break
fi
sleep 1
done
# 4. Cleanup old backups (older than RETENTION_DAYS)
log "Pruning local + remote snapshots older than ${RETENTION_DAYS} days..."
CUTOFF=$(date -u -d "${RETENTION_DAYS} days ago" +%Y-%m-%d)
rclone lsf "$DEST/" --dirs-only 2>/dev/null | while read -r d; do
# rclone returns names with trailing /
name="${d%/}"
if [[ "$name" < "$CUTOFF" ]]; then
log " removing old: $name"
rclone purge "${DEST}/${name}" >> "$LOG" 2>&1
fi
done
# 5. Report
if [ $SYNC_RC -eq 0 ] && [ $START_RC -eq 0 ]; then
log "=== Backup OK ==="
exit 0
else
log "=== Backup completed with errors (sync=$SYNC_RC, start=$START_RC) ==="
exit 1
fi
+379
View File
@@ -0,0 +1,379 @@
#!/usr/bin/env bash
# DashCaddy Host-Side Updater
# Triggered by systemd path unit when the container writes trigger.json.
# Reads the trigger, backs up current API + data/, copies new files, rebuilds container.
# Writes result.json so the new container knows the outcome.
#
# This runs on the HOST, outside the container.
set -euo pipefail
readonly UPDATES_DIR="/opt/dashcaddy/updates"
readonly TRIGGER_FILE="${UPDATES_DIR}/trigger.json"
readonly RESULT_FILE="${UPDATES_DIR}/result.json"
readonly BACKUPS_DIR="${UPDATES_DIR}/backups"
readonly CONTAINER_NAME="dashcaddy-api"
readonly IMAGE_TAG="dashcaddy-dashcaddy-api:latest"
readonly MAX_BACKUPS=3
readonly HEALTH_TIMEOUT=60
# Data directory backup — stored alongside code backups so everything rolls back together
readonly DATA_SOURCE_DIR="/opt/dashcaddy/dashcaddy-api/data"
readonly DATA_BACKUP_PREFIX="data-backup"
log() { echo "[dashcaddy-update] $(date '+%Y-%m-%d %H:%M:%S') $*"; }
write_result() {
local success="$1" version="$2" duration="$3"
shift 3
local error="${1:-}"
if [[ "$success" == "true" ]]; then
cat > "$RESULT_FILE" <<EOF
{
"success": true,
"version": "${version}",
"duration": ${duration},
"timestamp": "$(date -u +%Y-%m-%dT%H:%M:%SZ)"
}
EOF
else
cat > "$RESULT_FILE" <<EOF
{
"success": false,
"version": "${version}",
"duration": ${duration},
"error": "${error}",
"timestamp": "$(date -u +%Y-%m-%dT%H:%M:%SZ)"
}
EOF
fi
}
cleanup_old_backups() {
local count
count=$(find "$BACKUPS_DIR" -maxdepth 1 -mindepth 1 -type d 2>/dev/null | wc -l)
if (( count > MAX_BACKUPS )); then
log "Cleaning old backups (${count} > ${MAX_BACKUPS})"
find "$BACKUPS_DIR" -maxdepth 1 -mindepth 1 -type d -printf '%T+ %p\n' \
| sort | head -n $(( count - MAX_BACKUPS )) | cut -d' ' -f2- \
| xargs rm -rf
fi
}
# ── Data backup (rsync for efficiency + permissions) ──────────────────────────
backup_data_dir() {
local backup_dir="$1"
if [[ -d "$DATA_SOURCE_DIR" ]]; then
log "Backing up data/ to ${backup_dir}/${DATA_BACKUP_PREFIX}/"
mkdir -p "${backup_dir}/${DATA_BACKUP_PREFIX}"
rsync -a --delete "$DATA_SOURCE_DIR/" "${backup_dir}/${DATA_BACKUP_PREFIX}/" 2>/dev/null \
|| cp -a "$DATA_SOURCE_DIR" "${backup_dir}/${DATA_BACKUP_PREFIX}"
log "Data backup complete ($(du -sh "${backup_dir}/${DATA_BACKUP_PREFIX}" 2>/dev/null | cut -f1))"
else
log "WARNING: Data source dir $DATA_SOURCE_DIR not found — skipping data backup"
fi
}
# ── Data restore ──────────────────────────────────────────────────────────────
restore_data_dir() {
local backup_dir="$1"
local data_backup="${backup_dir}/${DATA_BACKUP_PREFIX}"
if [[ -d "$data_backup" ]]; then
log "Restoring data/ from backup..."
rsync -a --delete "$data_backup/" "$DATA_SOURCE_DIR/" 2>/dev/null \
|| cp -a "$data_backup" "$DATA_SOURCE_DIR"
log "Data restored successfully"
else
log "WARNING: No data backup found at ${data_backup} — data/ not restored"
fi
}
wait_for_health() {
local port="${1:-3001}"
local timeout="$HEALTH_TIMEOUT"
local elapsed=0
log "Waiting for health check (timeout: ${timeout}s)..."
while (( elapsed < timeout )); do
if curl -fsSL --max-time 3 "http://localhost:${port}/health" &>/dev/null; then
log "Health check passed after ${elapsed}s"
return 0
fi
sleep 2
elapsed=$(( elapsed + 2 ))
done
log "Health check FAILED after ${timeout}s"
return 1
}
# ── Shared rollback: restore code + data ────────────────────────────────────
rollback_restore() {
local backup_dir="$1"
log "Rolling back: restoring code files..."
for item in "$backup_dir"/*.js "$backup_dir"/package.json "$backup_dir"/package-lock.json "$backup_dir"/Dockerfile "$backup_dir"/openapi.yaml "$backup_dir"/VERSION; do
[[ -f "$item" ]] && cp -f "$item" "$api_source_dir/" 2>/dev/null || true
done
if [[ -d "$backup_dir/routes" ]]; then
rm -rf "$api_source_dir/routes"
cp -rf "$backup_dir/routes" "$api_source_dir/routes"
fi
if [[ -d "$backup_dir/src" ]]; then
rm -rf "$api_source_dir/src"
cp -rf "$backup_dir/src" "$api_source_dir/src"
fi
if [[ -d "$backup_dir/dns-providers" ]]; then
rm -rf "$api_source_dir/dns-providers"
cp -rf "$backup_dir/dns-providers" "$api_source_dir/dns-providers"
fi
restore_data_dir "$backup_dir"
}
# ── Deployment mode ───────────────────────────────────────────────────────────
# Reproduce the SAME container the install created so an auto-update keeps every
# volume + env var (docker socket, Caddyfile, config/credentials, updates mount),
# not a minimal subset. Standard installs use docker-compose (compose file in the
# api source dir); the publish/dev host uses /opt/dashcaddy/start.sh; otherwise a
# bare docker run is the last resort. build_image() and restart_container() both
# honor the detected mode so build and run stay consistent.
deploy_mode() {
if [[ -f "$api_source_dir/docker-compose.yml" || -f "$api_source_dir/compose.yml" || -f "$api_source_dir/compose.yaml" ]]; then
echo compose
elif [[ -x /opt/dashcaddy/start.sh ]]; then
echo startsh
else
echo run
fi
}
# Build the API image using whatever the install is wired for. Returns the build
# command's exit status so callers can detect failure.
build_image() {
cd "$api_source_dir" || return 1
case "$(deploy_mode)" in
compose) docker compose build 2>&1 || docker-compose build 2>&1 ;;
*) docker build -t "$IMAGE_TAG" . 2>&1 ;;
esac
}
# ── Shared container restart — recreate with the full, install-defined spec ───
# Recreates (rm + run / compose up) so new code AND new env vars take effect.
restart_container() {
cd "$api_source_dir" 2>/dev/null || true
case "$(deploy_mode)" in
compose)
log "Recreating container via docker compose (full compose spec)..."
docker compose up -d 2>&1 || docker-compose up -d 2>&1
;;
startsh)
log "Recreating container via /opt/dashcaddy/start.sh (full container spec)..."
bash /opt/dashcaddy/start.sh
;;
*)
log "Recreating container via minimal docker run (fallback)..."
docker rm -f "$CONTAINER_NAME" 2>/dev/null || true
docker run -d --restart unless-stopped --name "$CONTAINER_NAME" \
-p 127.0.0.1:3001:3001 \
-v /opt/dashcaddy/dashcaddy-api/data:/app/data \
-e SERVICES_FILE=/app/data/services.json \
"$IMAGE_TAG"
;;
esac
log "Container recreated"
}
# ── Code-only restore (used after failed build when data hasn't changed yet) ──
code_restore() {
local backup_dir="$1"
log "Restoring code files..."
for item in "$backup_dir"/*.js "$backup_dir"/package.json "$backup_dir"/package-lock.json "$backup_dir"/Dockerfile "$backup_dir"/openapi.yaml "$backup_dir"/VERSION; do
[[ -f "$item" ]] && cp -f "$item" "$api_source_dir/" 2>/dev/null || true
done
if [[ -d "$backup_dir/routes" ]]; then
rm -rf "$api_source_dir/routes"
cp -rf "$backup_dir/routes" "$api_source_dir/routes"
fi
if [[ -d "$backup_dir/src" ]]; then
rm -rf "$api_source_dir/src"
cp -rf "$backup_dir/src" "$api_source_dir/src"
fi
if [[ -d "$backup_dir/dns-providers" ]]; then
rm -rf "$api_source_dir/dns-providers"
cp -rf "$backup_dir/dns-providers" "$api_source_dir/dns-providers"
fi
}
main() {
local start_time
start_time=$(date +%s)
# 1. Read trigger
if [[ ! -f "$TRIGGER_FILE" ]]; then
log "No trigger file found — nothing to do"
exit 0
fi
# Parse trigger.json (uses python3 which is available on all supported distros)
local action version from_version staging_dir api_source_dir commit
local frontend_staging_dir frontend_target_dir
action=$(python3 -c "import json; print(json.load(open('${TRIGGER_FILE}'))['action'])")
version=$(python3 -c "import json; print(json.load(open('${TRIGGER_FILE}'))['version'])")
from_version=$(python3 -c "import json; print(json.load(open('${TRIGGER_FILE}'))['fromVersion'])")
staging_dir=$(python3 -c "import json; print(json.load(open('${TRIGGER_FILE}'))['stagingDir'])")
api_source_dir=$(python3 -c "import json; print(json.load(open('${TRIGGER_FILE}'))['apiSourceDir'])")
commit=$(python3 -c "import json; print(json.load(open('${TRIGGER_FILE}')).get('commit') or '')")
frontend_staging_dir=$(python3 -c "import json; print(json.load(open('${TRIGGER_FILE}')).get('frontendStagingDir') or '')")
frontend_target_dir=$(python3 -c "import json; print(json.load(open('${TRIGGER_FILE}')).get('frontendTargetDir') or '')")
# Handle action=rollback (no new version to deploy)
local to_version="${version}"
log "=== ${action^^}: v${from_version} -> v${to_version} ==="
log "Staging: ${staging_dir}"
log "API source: ${api_source_dir}"
# Consume the trigger immediately so we don't re-process on failure
mv "$TRIGGER_FILE" "${TRIGGER_FILE}.processing"
# ── Handle rollback ────────────────────────────────────────────────────────
if [[ "$action" == "rollback" ]]; then
local backup_dir="${BACKUPS_DIR}/${version}"
if [[ ! -d "$backup_dir" ]]; then
log "ERROR: No backup found for version ${version}"
write_result "false" "$version" "$(( $(date +%s) - start_time ))" "No backup found for version ${version}"
rm -f "${TRIGGER_FILE}.processing"
exit 1
fi
log "Performing rollback to v${version}..."
rollback_restore "$backup_dir"
# Rebuild old code
log "Rebuilding container..."
build_image 2>&1 | tail -3 || true
restart_container
wait_for_health || log "WARNING: Health check failed after rollback"
write_result "true" "$version" "$(( $(date +%s) - start_time ))"
rm -f "${TRIGGER_FILE}.processing"
log "=== Rollback complete ==="
exit 0
fi
# ── Handle update ───────────────────────────────────────────────────────────
if [[ ! -d "$staging_dir" ]]; then
log "ERROR: Staging directory not found: ${staging_dir}"
write_result "false" "$to_version" "$(( $(date +%s) - start_time ))" "Staging directory not found"
rm -f "${TRIGGER_FILE}.processing"
exit 1
fi
# 2. Backup current API code + data/
local backup_dir="${BACKUPS_DIR}/${from_version}"
mkdir -p "$backup_dir"
log "Backing up current API files to ${backup_dir}"
for item in "$api_source_dir"/*.js "$api_source_dir"/package.json "$api_source_dir"/package-lock.json "$api_source_dir"/Dockerfile "$api_source_dir"/openapi.yaml "$api_source_dir"/VERSION; do
[[ -f "$item" ]] && cp -f "$item" "$backup_dir/" 2>/dev/null || true
done
[[ -d "$api_source_dir/routes" ]] && cp -rf "$api_source_dir/routes" "$backup_dir/"
[[ -d "$api_source_dir/src" ]] && cp -rf "$api_source_dir/src" "$backup_dir/"
[[ -d "$api_source_dir/dns-providers" ]] && cp -rf "$api_source_dir/dns-providers" "$backup_dir/"
# Backup data/ directory (services.json, config.json, credentials, etc.)
backup_data_dir "$backup_dir"
cleanup_old_backups
# 3. Copy new files from staging to API source
log "Deploying new API files..."
for item in "$staging_dir"/*.js "$staging_dir"/package.json "$staging_dir"/package-lock.json "$staging_dir"/Dockerfile "$staging_dir"/openapi.yaml "$staging_dir"/VERSION; do
[[ -f "$item" ]] && cp -f "$item" "$api_source_dir/" 2>/dev/null || true
done
if [[ -d "$staging_dir/routes" ]]; then
rm -rf "$api_source_dir/routes"
cp -rf "$staging_dir/routes" "$api_source_dir/routes"
fi
if [[ -d "$staging_dir/src" ]]; then
rm -rf "$api_source_dir/src"
cp -rf "$staging_dir/src" "$api_source_dir/src"
fi
if [[ -d "$staging_dir/dns-providers" ]]; then
rm -rf "$api_source_dir/dns-providers"
cp -rf "$staging_dir/dns-providers" "$api_source_dir/dns-providers"
fi
if [[ -n "$commit" ]]; then
echo "$commit" > "$api_source_dir/VERSION"
fi
# 3b. Sync frontend
if [[ -z "$frontend_staging_dir" ]]; then
parent_staging=$(dirname "$staging_dir")
[[ -d "$parent_staging/status" ]] && frontend_staging_dir="$parent_staging/status"
fi
if [[ -z "$frontend_target_dir" ]]; then
for candidate in /var/www/dashcaddy-status /etc/dashcaddy/sites/status; do
[[ -d "$candidate" ]] && frontend_target_dir="$candidate" && break
done
fi
if [[ -n "$frontend_staging_dir" && -n "$frontend_target_dir" && -d "$frontend_staging_dir" ]]; then
log "Syncing frontend: $frontend_staging_dir -> $frontend_target_dir"
mkdir -p "$frontend_target_dir"
[[ -f "$frontend_staging_dir/index.html" ]] && cp -f "$frontend_staging_dir/index.html" "$frontend_target_dir/index.html"
[[ -f "$frontend_staging_dir/sw.js" ]] && cp -f "$frontend_staging_dir/sw.js" "$frontend_target_dir/sw.js"
for sub in dist css vendor js; do
if [[ -d "$frontend_staging_dir/$sub" ]]; then
mkdir -p "$frontend_target_dir/$sub"
cp -rf "$frontend_staging_dir/$sub/"* "$frontend_target_dir/$sub/" 2>/dev/null || true
fi
done
if [[ -d "$frontend_staging_dir/assets" ]]; then
mkdir -p "$frontend_target_dir/assets"
cp -rf "$frontend_staging_dir/assets/"* "$frontend_target_dir/assets/" 2>/dev/null || true
fi
fi
# 4. Rebuild container
log "Rebuilding container..."
local build_ok=false
if build_image; then
build_ok=true
fi
if [[ "$build_ok" != "true" ]]; then
log "ERROR: Docker build failed — rolling back code + data"
code_restore "$backup_dir"
build_image 2>&1 | tail -3 || true
restart_container
wait_for_health || true
write_result "false" "$to_version" "$(( $(date +%s) - start_time ))" "Docker build failed"
rm -f "${TRIGGER_FILE}.processing"
exit 1
fi
# 5. Restart container (recreate so new code + env vars take effect)
restart_container
# 6. Health check
if wait_for_health; then
local duration=$(( $(date +%s) - start_time ))
log "=== Update successful: v${to_version} in ${duration}s ==="
write_result "true" "$to_version" "$duration"
else
local duration=$(( $(date +%s) - start_time ))
log "ERROR: Health check failed after update — rolling back code + data"
rollback_restore "$backup_dir"
build_image 2>&1 | tail -3 || true
restart_container
wait_for_health || log "WARNING: Rollback health check also failed"
write_result "false" "$to_version" "$duration" "Health check failed after update"
fi
# 7. Cleanup
rm -f "${TRIGGER_FILE}.processing"
rm -rf "${UPDATES_DIR}/staging" 2>/dev/null || true
log "=== Update process complete ==="
}
main "$@"
+76
View File
@@ -0,0 +1,76 @@
#!/bin/bash
# Samihost fail2ban watchdog — auto-unban whitelisted IPs and keep ignoreip list in sync.
# Deployed to /usr/local/bin/samihost-fail2ban-watchdog.sh on 194.163.161.162
# Cron: every 30 min (0,30 * * * *)
set -euo pipefail
JAIL_LOCAL=/etc/fail2ban/jail.local
BACKUP=/etc/fail2ban/jail.local.watchdog.bak
EXPECTED_IGNOREIP="127.0.0.1/8 ::1 10.0.0.0/8 172.16.0.0/12 192.168.0.0/16 fc00::/7 fe80::/10 100.64.0.0/10 100.121.150.22 100.85.236.10 100.71.97.12 100.81.59.99 100.98.123.59 194.233.88.206 173.212.201.200 194.163.161.162"
LOG=/var/log/samihost-fail2ban-watchdog.log
TELEGRAM_LOG=/tmp/fail2ban-watchdog-last-action
ts() { date -u +"%Y-%m-%dT%H:%M:%SZ"; }
log() { echo "$(ts) $*" | tee -a "$LOG"; }
mkdir -p "$(dirname "$LOG")"
touch "$LOG"
# --- 1. Verify ignoreip line is intact and matches expected ---
CURRENT=$(grep '^ignoreip' "$JAIL_LOCAL" | sed 's/^ignoreip[[:space:]]*=[[:space:]]*//' || true)
EXPECTED_NORMALIZED=$(echo "$EXPECTED_IGNOREIP" | tr ' ' '\n' | sort -u | tr '\n' ' ' | sed 's/ $//')
CURRENT_NORMALIZED=$(echo "$CURRENT" | tr ' ' '\n' | sort -u | tr '\n' ' ' | sed 's/ $//')
if [ "$CURRENT_NORMALIZED" != "$EXPECTED_NORMALIZED" ]; then
log "ALERT: ignoreip line drifted. Restoring."
cp "$JAIL_LOCAL" "$BACKUP"
sed -i "s|^ignoreip = .*|ignoreip = $EXPECTED_IGNOREIP|" "$JAIL_LOCAL"
fail2ban-client reload
echo "ignoreip restored at $(ts)" > "$TELEGRAM_LOG"
log "ignoreip restored, fail2ban reloaded"
fi
# --- 2. Unban any currently-banned IPs that match our trusted set ---
BANNED=$(fail2ban-client status sshd 2>/dev/null | awk -F: '/Banned IP list/{print $2}' | tr ' ' '\n' | grep -v '^$' || true)
UNBANNED=0
for ip in $BANNED; do
# Match against any trusted network
is_trusted=0
for net in 127.0.0.0/8 10.0.0.0/8 172.16.0.0/12 192.168.0.0/16 100.64.0.0/10 ::1 fc00::/7 fe80::/10 100.121.150.22 100.85.236.10 100.71.97.12 100.81.59.99 100.98.123.59 194.233.88.206 173.212.201.200 194.163.161.162; do
if [[ "$net" == *"/"* ]]; then
# CIDR match (simple IPv4 only — IPv6 needs python or ipcalc, skip for now)
base="${net%/*}"
mask="${net#*/}"
if [[ "$ip" == "$base"* ]] || python3 -c "import ipaddress,sys; sys.exit(0 if ipaddress.ip_address('$ip') in ipaddress.ip_network('$net', strict=False) else 1)" 2>/dev/null; then
is_trusted=1
break
fi
else
if [ "$ip" = "$net" ]; then
is_trusted=1
break
fi
fi
done
if [ "$is_trusted" = "1" ]; then
if fail2ban-client set sshd unbanip "$ip" >/dev/null 2>&1; then
log "auto-unbanned trusted IP: $ip"
UNBANNED=$((UNBANNED+1))
fi
fi
done
[ "$UNBANNED" -gt 0 ] && echo "auto-unbanned $UNBANNED trusted IPs at $(ts)" > "$TELEGRAM_LOG"
# --- 3. Cap the ban count — if more than 200 are banned, mass-unban stale ones ---
TOTAL_BANNED=$(fail2ban-client status sshd 2>/dev/null | awk '/Currently banned/{print $NF}' || echo 0)
if [ "$TOTAL_BANNED" -gt 200 ]; then
log "ALERT: $TOTAL_BANNED IPs banned. Mass-unbanning all."
for ip in $BANNED; do
fail2ban-client set sshd unbanip "$ip" >/dev/null 2>&1 || true
done
echo "mass-unbanned $TOTAL_BANNED stale bans at $(ts)" > "$TELEGRAM_LOG"
fi
log "watchdog run complete (unbanned=$UNBANNED, total_banned=$TOTAL_BANNED)"
+1
View File
@@ -72,6 +72,7 @@ const bundles = {
],
'init.js': [
JS('core', 'init.js'),
JS('monitoring-widgets.js'),
JS('keyboard-shortcuts.js'),
],
};
+114 -87
View File
File diff suppressed because one or more lines are too long
+308 -233
View File
File diff suppressed because one or more lines are too long
+129 -18
View File
File diff suppressed because one or more lines are too long
+11 -2
View File
@@ -256,6 +256,9 @@
<option value="on">🟢 Online</option>
<option value="off">🔴 Offline</option>
</select>
<select id="service-filter-category" style="padding: 8px 12px; background: var(--bg); border: 1px solid var(--border); border-radius: 6px; color: var(--fg); font-size: 0.9rem;">
<option value="all">All Categories</option>
</select>
<button id="batch-operations-btn" class="btn-sm" style="padding: 8px 12px;">☰ Batch Operations</button>
<span id="service-filter-count" style="color: var(--muted); font-size: 0.85rem; white-space: nowrap;"></span>
</div>
@@ -390,8 +393,14 @@
<!-- DNS Server Configuration -->
<div>
<label class="form-label-accent">
🗂️ DNS Server (Technitium)
🗂️ DNS Provider
</label>
<select id="setup-dns-provider" class="form-input-lg" style="margin-bottom: 12px;">
<option value="technitium">Technitium DNS (recommended)</option>
<option value="cloudflare">Cloudflare DNS</option>
<option value="rfc2136">RFC 2136 (BIND / PowerDNS / other)</option>
<option value="manual">Manual / External DNS</option>
</select>
<div style="display: grid; grid-template-columns: 1fr auto; gap: 8px;">
<input type="text" id="setup-dns-ip" value="" placeholder="DNS server IP"
style="padding: 12px; background: var(--card-bg); color: var(--fg); border: 1px solid var(--border); border-radius: 6px; font-size: 1rem;" />
@@ -406,7 +415,7 @@
<!-- DNS Admin Token -->
<div>
<label class="form-label-accent">
🔑 Technitium Admin Token
🔑 DNS Admin Token / API Key
</label>
<input type="password" id="setup-dns-token" placeholder="Paste your admin token here"
class="form-input-lg" />
+455 -333
View File
@@ -94,7 +94,9 @@
<!-- Tab bar -->
<div class="panel-tabs">
<button class="panel-tab active" data-panel="backup-manual">Manual</button>
<button class="panel-tab" data-panel="backup-automated">Automated</button>
<button class="panel-tab" data-panel="backup-schedules-tab">Schedules</button>
<button class="panel-tab" data-panel="backup-disk-tab">Backups on Disk</button>
<button class="panel-tab" data-panel="backup-pointintime-tab">Point-in-Time</button>
<button class="panel-tab" data-panel="backup-history-tab">History</button>
</div>
@@ -143,12 +145,32 @@
<div id="backup-result" style="display: none; margin-top: 16px; padding: 12px; border-radius: 8px;"></div>
</div>
<!-- Tab: Automated Backups -->
<div id="backup-automated" class="panel-section">
<div id="backup-schedule-container">
<!-- Tab: Schedules (Premium) -->
<div id="backup-schedules-tab" class="panel-section">
<div id="backup-schedules-container">
<div class="panel-empty">
<span class="empty-icon"></span>
<span class="brand-spinner"></span> Loading backup schedule...
<span class="brand-spinner"></span> Loading schedules...
</div>
</div>
</div>
<!-- Tab: Backups on Disk -->
<div id="backup-disk-tab" class="panel-section">
<div id="backup-disk-container">
<div class="panel-empty">
<span class="empty-icon">💾</span>
<span class="brand-spinner"></span> Loading backup files...
</div>
</div>
</div>
<!-- Tab: Point-in-Time Restore -->
<div id="backup-pointintime-tab" class="panel-section">
<div id="pointintime-container">
<div class="panel-empty">
<span class="empty-icon"></span>
<span class="brand-spinner"></span> Loading...
</div>
</div>
</div>
@@ -181,8 +203,10 @@
var previewContent = document.getElementById('backup-preview-content');
var restoreBtn = document.getElementById('backup-do-restore-btn');
var resultDiv = document.getElementById('backup-result');
var scheduleContainer = document.getElementById('backup-schedule-container');
var scheduleContainer = document.getElementById('backup-schedules-container');
var historyContainer = document.getElementById('backup-history-container');
var diskContainer = document.getElementById('backup-disk-container');
var pointintimeContainer = document.getElementById('pointintime-container');
var selectedBackup = null;
@@ -383,359 +407,272 @@
restoreBtn.innerHTML = '⚡ Restore Everything';
});
// === Automated Backups Tab ===
// Holds the destination currently being edited in the form
var currentDestination = { type: 'local' };
async function loadBackupSchedule() {
// === Schedules Tab (Premium) ===
async function loadSchedulesTab() {
if (!scheduleContainer) return;
scheduleContainer.innerHTML = '<div class="panel-empty"><span class="brand-spinner"></span> Loading...</div>';
try {
var res = await fetch('/api/v1/backups/config');
var res = await fetch('/api/v1/backups/schedule');
var data = await res.json();
if (!data.success) throw new Error(data.error || 'Failed to load config');
var cfg = data.config?.backups || {};
var autoKey = Object.keys(cfg)[0];
var auto = autoKey ? cfg[autoKey] : null;
// Pull existing destination (first one) — fall back to local
var existingDest = (auto?.destinations && auto.destinations[0]) || { type: 'local' };
currentDestination = JSON.parse(JSON.stringify(existingDest));
var html = '<div style="padding: 16px; background: color-mix(in srgb, var(--accent) 8%, transparent); border-radius: 10px; border: 1px solid color-mix(in srgb, var(--accent) 25%, transparent); margin-bottom: 16px;">';
html += '<h4 style="margin: 0 0 12px; color: var(--accent); font-size: 0.9rem;">⏰ Backup Schedule</h4>';
html += '<div style="display: grid; grid-template-columns: 1fr 1fr; gap: 12px;">';
html += '<div><label style="font-size: 0.8rem; color: var(--muted);">Schedule:</label>';
html += ' <select id="backup-schedule-select" style="width: 100%;">';
html += ' <option value="disabled"' + (!auto?.enabled ? ' selected' : '') + '>Disabled</option>';
html += ' <option value="hourly"' + (auto?.schedule === 'hourly' ? ' selected' : '') + '>Hourly</option>';
html += ' <option value="daily"' + (auto?.schedule === 'daily' ? ' selected' : '') + '>Daily</option>';
html += ' <option value="weekly"' + (auto?.schedule === 'weekly' ? ' selected' : '') + '>Weekly</option>';
html += ' <option value="monthly"' + (auto?.schedule === 'monthly' ? ' selected' : '') + '>Monthly</option>';
html += ' </select></div>';
html += '<div><label style="font-size: 0.8rem; color: var(--muted);">Keep last:</label>';
html += ' <select id="backup-retention-select" style="width: 100%;">';
html += ' <option value="3"' + (auto?.retention?.keep === 3 ? ' selected' : '') + '>3 backups</option>';
html += ' <option value="5"' + (!auto?.retention || auto?.retention?.keep === 5 ? ' selected' : '') + '>5 backups</option>';
html += ' <option value="10"' + (auto?.retention?.keep === 10 ? ' selected' : '') + '>10 backups</option>';
html += ' <option value="30"' + (auto?.retention?.keep === 30 ? ' selected' : '') + '>30 backups</option>';
html += ' </select></div>';
if (data.premiumRequired) {
scheduleContainer.innerHTML = '<div class="panel-empty" style="padding: 24px; text-align: center;">' +
'<div style="font-size: 2rem; margin-bottom: 12px;">⭐</div>' +
'<div style="font-weight: 600; margin-bottom: 8px;">Premium Feature</div>' +
'<div style="font-size: 0.85rem; color: var(--muted);">Auto-backup scheduling requires a DashCaddy Premium subscription.</div>' +
'<button onclick="showNotification(\'Upgrade to Premium to enable auto-backups!\', \'info\'); scrollToSection(\'license\');" style="margin-top: 16px; padding: 8px 20px; background: linear-gradient(135deg, #f39c12, #e67e22); border: none; color: white; border-radius: 8px; cursor: pointer; font-weight: 600;">Upgrade to Premium</button>' +
'</div>';
return;
}
if (!data.success) throw new Error(data.error || 'Failed to load schedules');
var schedules = data.schedules || [];
if (schedules.length === 0) {
scheduleContainer.innerHTML = '<div class="panel-empty">' +
'<span class="empty-icon">⏰</span>' +
'<div>No backup schedules configured</div>' +
'<div style="font-size: 0.8rem; color: var(--muted); margin-top: 4px;">Select apps below to enable auto-backup</div>' +
'</div>';
return;
}
var html = '<div style="display: flex; flex-direction: column; gap: 8px;">';
for (var i = 0; i < schedules.length; i++) {
var sch = schedules[i];
var nextRunStr = sch.nextRun ? new Date(sch.nextRun).toLocaleString() : 'Not scheduled';
var lastRunStr = sch.lastRun ? new Date(sch.lastRun).toLocaleString() : 'Never';
html += '<div style="padding: 12px 14px; background: var(--card-base); border-radius: 8px; border: 1px solid var(--border);">' +
'<div style="display: flex; justify-content: space-between; align-items: center; margin-bottom: 8px;">' +
' <div style="font-weight: 600; font-size: 0.9rem;">' + escapeHtml(sch.appId) + '</div>' +
' <label class="toggle-switch" style="display: flex; align-items: center; gap: 6px;">' +
' <input type="checkbox" class="schedule-toggle" data-appid="' + escapeHtml(sch.appId) + '"' + (sch.enabled ? ' checked' : '') + ' />' +
' <span style="font-size: 0.75rem; color: var(--muted);">' + (sch.enabled ? 'ON' : 'OFF') + '</span>' +
' </label>' +
'</div>' +
'<div style="display: grid; grid-template-columns: 1fr 1fr; gap: 8px; font-size: 0.8rem; margin-bottom: 10px;">' +
' <div><span style="color: var(--muted);">Schedule:</span> <select class="schedule-select" data-appid="' + escapeHtml(sch.appId) + '" style="background: var(--base); border: 1px solid var(--border); border-radius: 4px; padding: 2px 6px;">' +
' <option value="hourly"' + (sch.schedule === 'hourly' ? ' selected' : '') + '>Hourly</option>' +
' <option value="daily"' + (sch.schedule === 'daily' ? ' selected' : '') + '>Daily</option>' +
' <option value="weekly"' + (sch.schedule === 'weekly' ? ' selected' : '') + '>Weekly</option>' +
' <option value="monthly"' + (sch.schedule === 'monthly' ? ' selected' : '') + '>Monthly</option>' +
' </select></div>' +
' <div><span style="color: var(--muted);">Keep last:</span> <input type="number" class="retention-input" data-appid="' + escapeHtml(sch.appId) + '" value="' + (sch.retention?.keep || 7) + '" min="1" max="100" style="width: 50px; background: var(--base); border: 1px solid var(--border); border-radius: 4px; padding: 2px 6px;" /></div>' +
'</div>' +
'<div style="font-size: 0.75rem; color: var(--muted); margin-bottom: 10px;">' +
' <div>Next run: ' + escapeHtml(nextRunStr) + '</div>' +
' <div>Last run: ' + escapeHtml(lastRunStr) + '</div>' +
'</div>' +
'<div style="display: flex; gap: 6px;">' +
' <button class="schedule-run-now" data-appid="' + escapeHtml(sch.appId) + '" style="padding: 5px 12px; font-size: 0.8rem; background: color-mix(in srgb, var(--ok-fg) 20%, transparent); border: 1px solid var(--ok-fg); color: var(--ok-fg); border-radius: 6px; cursor: pointer;">▶️ Run Now</button>' +
' <button class="schedule-delete" data-appid="' + escapeHtml(sch.appId) + '" style="padding: 5px 12px; font-size: 0.8rem; background: transparent; border: 1px solid var(--bad-fg); color: var(--bad-fg); border-radius: 6px; cursor: pointer;">🗑️ Remove</button>' +
'</div>' +
'</div>';
}
html += '</div>';
html += '<div style="margin-top: 12px;">';
html += ' <label style="display: flex; align-items: center; gap: 8px; font-size: 0.85rem; cursor: pointer;">';
html += ' <input type="checkbox" id="backup-encrypt-toggle"' + (auto?.encrypt !== false ? ' checked' : '') + ' />';
html += ' Encrypt backups';
html += ' </label></div>';
html += '<div style="display: flex; gap: 8px; margin-top: 12px;">';
html += ' <button id="backup-save-schedule" style="padding: 8px 16px; background: color-mix(in srgb, var(--accent) 20%, transparent); border: 1px solid var(--accent); color: var(--accent); border-radius: 6px; cursor: pointer; font-weight: 500;">Save Schedule</button>';
html += ' <button id="backup-run-now" style="padding: 8px 16px; border-radius: 6px; cursor: pointer;">▶️ Run Backup Now</button>';
html += '</div>';
html += '</div>';
// === Destination Section ===
html += '<div style="padding: 16px; background: color-mix(in srgb, var(--accent) 8%, transparent); border-radius: 10px; border: 1px solid color-mix(in srgb, var(--accent) 25%, transparent); margin-bottom: 16px;">';
html += '<h4 style="margin: 0 0 12px; color: var(--accent); font-size: 0.9rem;">☁️ Backup Destination</h4>';
html += '<div><label style="font-size: 0.8rem; color: var(--muted);">Where to store backups:</label>';
html += ' <select id="backup-dest-type" style="width: 100%;">';
html += ' <option value="local"' + (currentDestination.type === 'local' ? ' selected' : '') + '>💾 Local disk</option>';
html += ' <option value="dropbox"' + (currentDestination.type === 'dropbox' ? ' selected' : '') + '>📦 Dropbox</option>';
html += ' <option value="webdav"' + (currentDestination.type === 'webdav' ? ' selected' : '') + '>🌐 WebDAV (Nextcloud / ownCloud)</option>';
html += ' <option value="sftp"' + (currentDestination.type === 'sftp' ? ' selected' : '') + '>🔐 SFTP</option>';
html += ' </select></div>';
html += '<div id="backup-dest-form" style="margin-top: 12px;"></div>';
html += '<div id="backup-dest-result" style="display: none; margin-top: 10px; padding: 8px 10px; border-radius: 6px; font-size: 0.8rem;"></div>';
html += '</div>';
html += '<div id="backup-schedule-result" style="display: none; margin-top: 12px; padding: 10px; border-radius: 8px; font-size: 0.85rem;"></div>';
// Add "Add Schedule" section at bottom
html += '<div style="margin-top: 16px; padding: 16px; background: color-mix(in srgb, var(--accent) 5%, transparent); border-radius: 10px; border: 1px dashed var(--border);">' +
'<h4 style="margin: 0 0 12px; font-size: 0.85rem; color: var(--muted);"> Add New Schedule</h4>' +
'<div style="display: flex; gap: 8px; flex-wrap: wrap;">' +
' <input type="text" id="new-schedule-appid" placeholder="App ID (e.g., plex, sonarr)" style="flex: 1; min-width: 150px; padding: 8px; border-radius: 6px; border: 1px solid var(--border); background: var(--base);" />' +
' <select id="new-schedule-interval" style="padding: 8px; border-radius: 6px; border: 1px solid var(--border); background: var(--base);">' +
' <option value="hourly">Hourly</option>' +
' <option value="daily" selected>Daily</option>' +
' <option value="weekly">Weekly</option>' +
' <option value="monthly">Monthly</option>' +
' <option value="6h">Every 6 hours</option>' +
' <option value="30m">Every 30 minutes</option>' +
' </select>' +
' <input type="number" id="new-schedule-retention" value="7" min="1" max="100" placeholder="Keep" style="width: 70px; padding: 8px; border-radius: 6px; border: 1px solid var(--border); background: var(--base);" />' +
' <button id="add-schedule-btn" style="padding: 8px 16px; background: var(--accent); border: none; color: white; border-radius: 6px; cursor: pointer; font-weight: 500;">Add Schedule</button>' +
'</div>' +
'</div>';
scheduleContainer.innerHTML = html;
document.getElementById('backup-save-schedule')?.addEventListener('click', saveSchedule);
document.getElementById('backup-run-now')?.addEventListener('click', runBackupNow);
var destTypeSel = document.getElementById('backup-dest-type');
destTypeSel?.addEventListener('change', function() {
currentDestination = { type: destTypeSel.value };
renderDestinationForm(destTypeSel.value);
// Wire up event listeners
scheduleContainer.querySelectorAll('.schedule-toggle').forEach(function(toggle) {
toggle.addEventListener('change', function() { updateSchedule(toggle.dataset.appid, { enabled: toggle.checked }); });
});
renderDestinationForm(currentDestination.type);
scheduleContainer.querySelectorAll('.schedule-select').forEach(function(sel) {
sel.addEventListener('change', function() { updateSchedule(sel.dataset.appid, { schedule: sel.value }); });
});
scheduleContainer.querySelectorAll('.retention-input').forEach(function(inp) {
inp.addEventListener('change', function() { updateSchedule(inp.dataset.appid, { retention: { keep: parseInt(inp.value) || 7 } }); });
});
scheduleContainer.querySelectorAll('.schedule-run-now').forEach(function(btn) {
btn.addEventListener('click', function() { runBackupNow(btn.dataset.appid); });
});
scheduleContainer.querySelectorAll('.schedule-delete').forEach(function(btn) {
btn.addEventListener('click', function() { deleteSchedule(btn.dataset.appid); });
});
document.getElementById('add-schedule-btn')?.addEventListener('click', addNewSchedule);
} catch (e) {
scheduleContainer.innerHTML = '<div class="panel-empty" style="color: var(--bad-fg);">Failed to load schedule: ' + escapeHtml(e.message) + '</div>';
scheduleContainer.innerHTML = '<div class="panel-empty" style="color: var(--bad-fg);">Failed to load: ' + escapeHtml(e.message) + '</div>';
}
}
// Render the provider-specific form fields and load saved credentials (masked)
async function renderDestinationForm(type) {
var formEl = document.getElementById('backup-dest-form');
if (!formEl) return;
if (type === 'local') {
formEl.innerHTML = '<div style="font-size: 0.8rem; color: var(--muted); padding: 8px;">Backups are stored on the host filesystem. No additional configuration required.</div>';
async function updateSchedule(appId, updates) {
try {
var res = await secureFetch('/api/v1/backups/schedule', {
method: 'POST',
headers: { 'Content-Type': 'application/json' },
body: JSON.stringify({ appId, ...updates })
});
var data = await res.json();
if (data.success) {
showNotification('Schedule updated for ' + appId, 'success');
} else {
showNotification('Update failed: ' + (data.error || 'Unknown'), 'error');
loadSchedulesTab(); // Refresh on failure
}
} catch (e) {
showNotification('Error: ' + e.message, 'error');
}
}
async function runBackupNow(appId) {
try {
var res = await secureFetch('/api/v1/backups/backup/' + encodeURIComponent(appId), {
method: 'POST',
headers: { 'Content-Type': 'application/json' }
});
var data = await res.json();
if (data.success) {
showNotification('Backup started for ' + appId + '!', 'success');
} else {
showNotification('Backup failed: ' + (data.error || 'Unknown'), 'error');
}
} catch (e) {
showNotification('Error: ' + e.message, 'error');
}
}
async function deleteSchedule(appId) {
if (!confirm('Remove backup schedule for ' + appId + '?')) return;
try {
var res = await secureFetch('/api/v1/backups/schedule/' + encodeURIComponent(appId), { method: 'DELETE' });
var data = await res.json();
if (data.success) {
showNotification('Schedule removed for ' + appId, 'success');
loadSchedulesTab();
} else {
showNotification('Delete failed: ' + (data.error || 'Unknown'), 'error');
}
} catch (e) {
showNotification('Error: ' + e.message, 'error');
}
}
async function addNewSchedule() {
var appId = document.getElementById('new-schedule-appid')?.value?.trim();
var interval = document.getElementById('new-schedule-interval')?.value || 'daily';
var retention = parseInt(document.getElementById('new-schedule-retention')?.value) || 7;
if (!appId) {
showNotification('Please enter an App ID', 'warning');
return;
}
var html = '';
if (type === 'dropbox') {
html += '<label style="font-size: 0.8rem; color: var(--muted);">Access Token:</label>';
html += '<input type="password" id="dest-dropbox-token" placeholder="sl.B..." style="width: 100%; margin-bottom: 8px;" />';
html += '<label style="font-size: 0.8rem; color: var(--muted);">Folder path:</label>';
html += '<input type="text" id="dest-dropbox-path" placeholder="/dashcaddy-backups" value="' + escapeHtml(currentDestination.path || '/dashcaddy-backups') + '" style="width: 100%; margin-bottom: 8px;" />';
html += '<div style="font-size: 0.7rem; color: var(--muted); margin-bottom: 8px;">Generate a token at <a href="https://www.dropbox.com/developers/apps" target="_blank" style="color: var(--accent);">Dropbox App Console</a> with files.content.write + files.content.read scopes.</div>';
} else if (type === 'webdav') {
html += '<label style="font-size: 0.8rem; color: var(--muted);">Server URL:</label>';
html += '<input type="text" id="dest-webdav-url" placeholder="https://cloud.example.com/remote.php/dav/files/username" style="width: 100%; margin-bottom: 8px;" />';
html += '<div style="display: grid; grid-template-columns: 1fr 1fr; gap: 8px; margin-bottom: 8px;">';
html += ' <div><label style="font-size: 0.8rem; color: var(--muted);">Username:</label>';
html += ' <input type="text" id="dest-webdav-username" style="width: 100%;" /></div>';
html += ' <div><label style="font-size: 0.8rem; color: var(--muted);">Password / App password:</label>';
html += ' <input type="password" id="dest-webdav-password" style="width: 100%;" /></div>';
html += '</div>';
html += '<label style="font-size: 0.8rem; color: var(--muted);">Folder path:</label>';
html += '<input type="text" id="dest-webdav-path" placeholder="/dashcaddy-backups" value="' + escapeHtml(currentDestination.path || '/dashcaddy-backups') + '" style="width: 100%; margin-bottom: 8px;" />';
} else if (type === 'sftp') {
html += '<div style="display: grid; grid-template-columns: 2fr 1fr; gap: 8px; margin-bottom: 8px;">';
html += ' <div><label style="font-size: 0.8rem; color: var(--muted);">Host:</label>';
html += ' <input type="text" id="dest-sftp-host" placeholder="backup.example.com" style="width: 100%;" /></div>';
html += ' <div><label style="font-size: 0.8rem; color: var(--muted);">Port:</label>';
html += ' <input type="number" id="dest-sftp-port" value="22" style="width: 100%;" /></div>';
html += '</div>';
html += '<label style="font-size: 0.8rem; color: var(--muted);">Username:</label>';
html += '<input type="text" id="dest-sftp-username" style="width: 100%; margin-bottom: 8px;" />';
html += '<label style="font-size: 0.8rem; color: var(--muted);">Auth method:</label>';
html += '<select id="dest-sftp-authtype" style="width: 100%; margin-bottom: 8px;">';
html += ' <option value="password">Password</option>';
html += ' <option value="key">Private key</option>';
html += '</select>';
html += '<div id="dest-sftp-password-row"><label style="font-size: 0.8rem; color: var(--muted);">Password:</label>';
html += ' <input type="password" id="dest-sftp-password" style="width: 100%; margin-bottom: 8px;" /></div>';
html += '<div id="dest-sftp-key-row" style="display: none;"><label style="font-size: 0.8rem; color: var(--muted);">Private key (PEM):</label>';
html += ' <textarea id="dest-sftp-privatekey" rows="4" style="width: 100%; font-family: monospace; font-size: 0.75rem; margin-bottom: 8px;" placeholder="-----BEGIN OPENSSH PRIVATE KEY-----"></textarea></div>';
html += '<label style="font-size: 0.8rem; color: var(--muted);">Remote path:</label>';
html += '<input type="text" id="dest-sftp-path" placeholder="/home/user/dashcaddy-backups" value="' + escapeHtml(currentDestination.path || '/home/user/dashcaddy-backups') + '" style="width: 100%; margin-bottom: 8px;" />';
}
html += '<div style="display: flex; gap: 8px; margin-top: 8px; flex-wrap: wrap;">';
html += ' <button id="dest-save-creds" style="padding: 6px 12px; font-size: 0.8rem; border-radius: 6px; cursor: pointer;">💾 Save Credentials</button>';
html += ' <button id="dest-test-conn" style="padding: 6px 12px; font-size: 0.8rem; background: color-mix(in srgb, var(--accent) 20%, transparent); border: 1px solid var(--accent); color: var(--accent); border-radius: 6px; cursor: pointer;">🔌 Test Connection</button>';
html += ' <button id="dest-clear-creds" style="padding: 6px 12px; font-size: 0.8rem; border-radius: 6px; cursor: pointer; color: var(--bad-fg);">🗑️ Clear</button>';
html += '</div>';
formEl.innerHTML = html;
// SFTP auth type toggle
if (type === 'sftp') {
var authSel = document.getElementById('dest-sftp-authtype');
var pwRow = document.getElementById('dest-sftp-password-row');
var keyRow = document.getElementById('dest-sftp-key-row');
authSel?.addEventListener('change', function() {
if (authSel.value === 'key') { pwRow.style.display = 'none'; keyRow.style.display = ''; }
else { pwRow.style.display = ''; keyRow.style.display = 'none'; }
});
}
document.getElementById('dest-save-creds')?.addEventListener('click', function() { saveCredentials(type); });
document.getElementById('dest-test-conn')?.addEventListener('click', function() { testDestination(type); });
document.getElementById('dest-clear-creds')?.addEventListener('click', function() { clearCredentials(type); });
// Pull existing (masked) credentials
await loadCredentials(type);
}
function destResult(msg, ok) {
var el = document.getElementById('backup-dest-result');
if (!el) return;
el.innerHTML = msg;
el.style.display = 'block';
el.style.background = ok ? 'color-mix(in srgb, var(--ok-fg) 15%, transparent)' : 'color-mix(in srgb, var(--bad-fg) 15%, transparent)';
el.style.border = ok ? '1px solid var(--ok-fg)' : '1px solid var(--bad-fg)';
}
async function loadCredentials(provider) {
try {
var res = await fetch('/api/v1/backups/credentials/' + provider);
var data = await res.json();
if (!data.success || !data.credentials) return;
var c = data.credentials;
if (provider === 'dropbox') {
var t = document.getElementById('dest-dropbox-token'); if (t && c.token) t.value = c.token;
} else if (provider === 'webdav') {
var u = document.getElementById('dest-webdav-url'); if (u && c.url) u.value = c.url;
var n = document.getElementById('dest-webdav-username'); if (n && c.username) n.value = c.username;
var p = document.getElementById('dest-webdav-password'); if (p && c.password) p.value = c.password;
} else if (provider === 'sftp') {
var h = document.getElementById('dest-sftp-host'); if (h && c.host) h.value = c.host;
var po = document.getElementById('dest-sftp-port'); if (po && c.port) po.value = c.port;
var un = document.getElementById('dest-sftp-username'); if (un && c.username) un.value = c.username;
var pw = document.getElementById('dest-sftp-password'); if (pw && c.password) pw.value = c.password;
var pk = document.getElementById('dest-sftp-privatekey'); if (pk && c.privateKey) pk.value = c.privateKey;
if (c.privateKey) {
var sel = document.getElementById('dest-sftp-authtype');
if (sel) { sel.value = 'key'; sel.dispatchEvent(new Event('change')); }
}
}
} catch (e) { /* no creds yet — silent */ }
}
function collectCredentials(provider) {
if (provider === 'dropbox') {
return { token: document.getElementById('dest-dropbox-token')?.value };
}
if (provider === 'webdav') {
return {
url: document.getElementById('dest-webdav-url')?.value,
username: document.getElementById('dest-webdav-username')?.value,
password: document.getElementById('dest-webdav-password')?.value
};
}
if (provider === 'sftp') {
var auth = document.getElementById('dest-sftp-authtype')?.value;
var creds = {
host: document.getElementById('dest-sftp-host')?.value,
port: parseInt(document.getElementById('dest-sftp-port')?.value) || 22,
username: document.getElementById('dest-sftp-username')?.value
};
if (auth === 'key') creds.privateKey = document.getElementById('dest-sftp-privatekey')?.value;
else creds.password = document.getElementById('dest-sftp-password')?.value;
return creds;
}
return {};
}
async function saveCredentials(provider) {
try {
var creds = collectCredentials(provider);
var res = await secureFetch('/api/v1/backups/credentials/' + provider, {
var res = await secureFetch('/api/v1/backups/schedule', {
method: 'POST',
headers: { 'Content-Type': 'application/json' },
body: JSON.stringify(creds)
});
var data = await res.json();
destResult(data.success ? '✅ Credentials saved' : '⚠️ ' + escapeHtml(data.error || 'Failed'), data.success);
} catch (e) {
destResult('❌ ' + escapeHtml(e.message), false);
}
}
async function clearCredentials(provider) {
if (!confirm('Delete saved ' + provider + ' credentials?')) return;
try {
var res = await secureFetch('/api/v1/backups/credentials/' + provider, { method: 'DELETE' });
var data = await res.json();
if (data.success) {
destResult('✅ Credentials cleared', true);
renderDestinationForm(provider);
} else {
destResult('⚠️ ' + escapeHtml(data.error || 'Failed'), false);
}
} catch (e) { destResult('❌ ' + escapeHtml(e.message), false); }
}
function buildDestination(type) {
var dest = { type: type };
if (type === 'local') return dest;
if (type === 'dropbox') dest.path = document.getElementById('dest-dropbox-path')?.value || '/dashcaddy-backups';
else if (type === 'webdav') dest.path = document.getElementById('dest-webdav-path')?.value || '/dashcaddy-backups';
else if (type === 'sftp') dest.path = document.getElementById('dest-sftp-path')?.value || '/dashcaddy-backups';
return dest;
}
async function testDestination(type) {
destResult('<span class="brand-spinner"></span> Testing connection...', true);
try {
var dest = buildDestination(type);
var res = await secureFetch('/api/v1/backups/test-destination', {
method: 'POST',
headers: { 'Content-Type': 'application/json' },
body: JSON.stringify(dest)
body: JSON.stringify({ appId, schedule: interval, retention: { keep: retention }, enabled: true })
});
var data = await res.json();
if (data.success) {
var ms = data.elapsedMs ? ' (' + data.elapsedMs + 'ms)' : '';
destResult('✅ Connection OK' + ms + ' — write/read/delete probe succeeded', true);
showNotification('Schedule created for ' + appId, 'success');
loadSchedulesTab();
// Clear inputs
var appIdInput = document.getElementById('new-schedule-appid');
if (appIdInput) appIdInput.value = '';
} else {
destResult(' ' + escapeHtml(data.error || 'Connection failed'), false);
}
} catch (e) { destResult('❌ ' + escapeHtml(e.message), false); }
}
async function saveSchedule() {
var schedule = document.getElementById('backup-schedule-select')?.value;
var retention = parseInt(document.getElementById('backup-retention-select')?.value) || 5;
var encrypt = document.getElementById('backup-encrypt-toggle')?.checked ?? true;
var destType = document.getElementById('backup-dest-type')?.value || 'local';
var resultEl = document.getElementById('backup-schedule-result');
try {
var res = await secureFetch('/api/v1/backups/config', {
method: 'POST',
headers: { 'Content-Type': 'application/json' },
body: JSON.stringify({
backups: {
auto: {
enabled: schedule !== 'disabled',
schedule: schedule === 'disabled' ? 'daily' : schedule,
include: ['all'],
encrypt: encrypt,
verify: true,
retention: { keep: retention },
destinations: [buildDestination(destType)]
}
}
})
});
var data = await res.json();
if (resultEl) {
resultEl.innerHTML = data.success ? '✅ Schedule saved' : '⚠️ ' + escapeHtml(data.error);
resultEl.style.display = 'block';
resultEl.style.background = data.success ? 'color-mix(in srgb, var(--ok-fg) 15%, transparent)' : 'color-mix(in srgb, var(--bad-fg) 15%, transparent)';
resultEl.style.border = data.success ? '1px solid var(--ok-fg)' : '1px solid var(--bad-fg)';
setTimeout(function() { if (resultEl) resultEl.style.display = 'none'; }, 3000);
showNotification('Failed: ' + (data.error || 'Unknown'), 'error');
}
} catch (e) {
if (resultEl) {
resultEl.innerHTML = '❌ ' + escapeHtml(e.message);
resultEl.style.display = 'block';
resultEl.style.background = 'color-mix(in srgb, var(--bad-fg) 15%, transparent)';
resultEl.style.border = '1px solid var(--bad-fg)';
}
showNotification('Error: ' + e.message, 'error');
}
}
async function runBackupNow() {
var btn = document.getElementById('backup-run-now');
var resultEl = document.getElementById('backup-schedule-result');
var destType = document.getElementById('backup-dest-type')?.value || 'local';
if (btn) { btn.disabled = true; btn.innerHTML = '<span class="brand-spinner"></span> Running...'; }
// === Backups on Disk Tab ===
async function loadDiskBackups() {
if (!diskContainer) return;
diskContainer.innerHTML = '<div class="panel-empty"><span class="brand-spinner"></span> Loading...</div>';
try {
var res = await secureFetch('/api/v1/backups/execute', {
method: 'POST',
headers: { 'Content-Type': 'application/json' },
body: JSON.stringify({ include: ['all'], destinations: [buildDestination(destType)] })
});
var res = await fetch('/api/v1/backups/files');
var data = await res.json();
if (resultEl) {
if (data.success) {
var sizeMB = data.backup?.size ? (data.backup.size / 1024 / 1024).toFixed(2) : '?';
resultEl.innerHTML = '✅ Backup complete (' + sizeMB + ' MB)';
resultEl.style.background = 'color-mix(in srgb, var(--ok-fg) 15%, transparent)';
resultEl.style.border = '1px solid var(--ok-fg)';
} else {
resultEl.innerHTML = '⚠️ ' + escapeHtml(data.error);
resultEl.style.background = 'color-mix(in srgb, var(--bad-fg) 15%, transparent)';
resultEl.style.border = '1px solid var(--bad-fg)';
if (!data.success) throw new Error(data.error || 'Failed to load');
var files = data.files || [];
if (files.length === 0) {
diskContainer.innerHTML = '<div class="panel-empty">' +
'<span class="empty-icon">💾</span>' +
'<div>No backup files on disk</div>' +
'<div style="font-size: 0.8rem; color: var(--muted); margin-top: 4px;">Run a backup to create backup files</div>' +
'</div>';
return;
}
// Group by appId
var byApp = {};
for (var i = 0; i < files.length; i++) {
var f = files[i];
var appId = f.appId || 'unknown';
if (!byApp[appId]) byApp[appId] = [];
byApp[appId].push(f);
}
var html = '<div style="font-size: 0.75rem; color: var(--muted); margin-bottom: 12px;">' + files.length + ' backup file(s) across ' + Object.keys(byApp).length + ' app(s)</div>';
html += '<div style="display: flex; flex-direction: column; gap: 12px;">';
var appIds = Object.keys(byApp).sort();
for (var a = 0; a < appIds.length; a++) {
var appId = appIds[a];
var appFiles = byApp[appId];
html += '<div style="background: var(--card-base); border-radius: 8px; border: 1px solid var(--border); overflow: hidden;">' +
'<div style="padding: 8px 12px; background: color-mix(in srgb, var(--accent) 8%, transparent); border-bottom: 1px solid var(--border); font-weight: 600; font-size: 0.85rem;">' +
escapeHtml(appId) + ' <span style="font-weight: normal; color: var(--muted); font-size: 0.75rem;">(' + appFiles.length + ' backup(s))</span>' +
'</div>';
for (var j = 0; j < appFiles.length; j++) {
var f = appFiles[j];
var dateStr = new Date(f.timestamp).toLocaleString();
html += '<div style="padding: 10px 12px; border-bottom: 1px solid var(--border);">' +
'<div style="display: flex; justify-content: space-between; align-items: center; margin-bottom: 4px;">' +
' <div style="font-weight: 500; font-size: 0.85rem;">' + escapeHtml(f.name) + '</div>' +
' <div style="font-size: 0.75rem; color: var(--muted);">' + f.sizeFormatted + '</div>' +
'</div>' +
'<div style="font-size: 0.75rem; color: var(--muted); margin-bottom: 8px;">' + dateStr + '</div>' +
'<div style="display: flex; gap: 6px;">' +
' <button class="disk-compare-btn" data-appid="' + escapeHtml(appId) + '" data-filename="' + escapeHtml(f.name) + '" style="padding: 3px 8px; font-size: 0.75rem; background: transparent; border: 1px solid var(--accent); color: var(--accent); border-radius: 5px; cursor: pointer;">Compare</button>' +
' <button class="disk-restore-btn" data-appid="' + escapeHtml(appId) + '" data-filename="' + escapeHtml(f.name) + '" style="padding: 3px 8px; font-size: 0.75rem; background: linear-gradient(135deg, var(--ok-fg), #27ae60); border: none; color: white; border-radius: 5px; cursor: pointer; font-weight: 500;">Restore</button>' +
'</div>' +
'</div>';
}
resultEl.style.display = 'block';
html += '</div>';
}
loadBackupHistory();
} catch (e) {
if (resultEl) {
resultEl.innerHTML = '❌ ' + escapeHtml(e.message);
resultEl.style.display = 'block';
resultEl.style.background = 'color-mix(in srgb, var(--bad-fg) 15%, transparent)';
resultEl.style.border = '1px solid var(--bad-fg)';
}
}
if (btn) { btn.disabled = false; btn.innerHTML = '▶️ Run Backup Now'; }
}
html += '</div>';
diskContainer.innerHTML = html;
// Wire up buttons
diskContainer.querySelectorAll('.disk-compare-btn').forEach(function(btn) {
btn.addEventListener('click', function() { compareBackupFile(btn.dataset.appid, btn.dataset.filename); });
});
diskContainer.querySelectorAll('.disk-restore-btn').forEach(function(btn) {
btn.addEventListener('click', function() { restoreBackupFile(btn.dataset.appid, btn.dataset.filename); });
});
} catch (e) {
diskContainer.innerHTML = '<div class="panel-empty" style="color: var(--bad-fg);">Failed: ' + escapeHtml(e.message) + '</div>';
}
}
// === Backup History Tab ===
async function loadBackupHistory() {
if (!historyContainer) return;
@@ -794,6 +731,191 @@
};
// Lazy-load tabs
document.querySelector('[data-panel="backup-automated"]')?.addEventListener('click', loadBackupSchedule);
document.querySelector('[data-panel="backup-schedules-tab"]')?.addEventListener('click', loadSchedulesTab);
document.querySelector('[data-panel="backup-disk-tab"]')?.addEventListener('click', loadDiskBackups);
document.querySelector('[data-panel="backup-pointintime-tab"]')?.addEventListener('click', loadPointInTimeTab);
document.querySelector('[data-panel="backup-history-tab"]')?.addEventListener('click', loadBackupHistory);
// ===== Point-in-Time Restore Tab =====
async function loadPointInTimeTab() {
if (!pointintimeContainer) return;
// Check premium
try {
var licenseRes = await fetch('/api/v1/license/status');
var licenseData = await licenseRes.json();
if (licenseData.tier !== 'premium') {
pointintimeContainer.innerHTML = '<div class="panel-empty" style="padding: 24px; text-align: center;">' +
'<div style="font-size: 2rem; margin-bottom: 12px;">⭐</div>' +
'<div style="font-weight: 600; margin-bottom: 8px;">Premium Feature</div>' +
'<div style="font-size: 0.85rem; color: var(--muted);">Point-in-time restore requires DashCaddy Premium with auto-backup enabled.</div>' +
'<button onclick="showNotification(\'Upgrade to Premium for point-in-time restore!\', \'info\'); scrollToSection(\'license\');" style="margin-top: 16px; padding: 8px 20px; background: linear-gradient(135deg, #f39c12, #e67e22); border: none; color: white; border-radius: 8px; cursor: pointer; font-weight: 600;">Upgrade to Premium</button>' +
'</div>';
return;
}
} catch (e) { /* ignore */ }
pointintimeContainer.innerHTML = '<div class="panel-empty"><span class="brand-spinner"></span> Loading...</div>';
try {
// Fetch services for dropdown
var servicesRes = await fetch('/api/v1/services');
var servicesData = await servicesRes.json();
var services = servicesData.services || [];
if (services.length === 0) {
pointintimeContainer.innerHTML = '<div class="panel-empty"><span class="empty-icon">📦</span> No apps deployed yet</div>';
return;
}
var html = '<div style="padding: 8px 0 12px;">' +
'<div style="display: flex; gap: 8px; align-items: center; margin-bottom: 12px;">' +
' <label style="font-size: 0.85rem; color: var(--muted); white-space: nowrap;">App:</label>' +
' <select id="pit-app-select" style="flex: 1; padding: 8px; border-radius: 6px; border: 1px solid var(--border); background: var(--base); max-width: 240px;">';
for (var i = 0; i < services.length; i++) {
html += '<option value="' + escapeHtml(services[i].id || services[i].name || '') + '">' +
escapeHtml(services[i].name || services[i].id || '') + '</option>';
}
html += '</select>' +
' <button id="pit-load-btn" style="padding: 8px 16px; background: var(--accent); border: none; color: white; border-radius: 6px; cursor: pointer; font-weight: 500;">Load Backups</button>' +
'</div>' +
'<div id="pit-backups-list" style="max-height: 320px; overflow-y: auto;"></div>' +
'</div>';
pointintimeContainer.innerHTML = html;
document.getElementById('pit-load-btn')?.addEventListener('click', function() {
var appId = document.getElementById('pit-app-select')?.value;
if (appId) loadPointInTimeBackups(appId);
});
} catch (e) {
pointintimeContainer.innerHTML = '<div class="panel-empty" style="color: var(--bad-fg);">Failed: ' + escapeHtml(e.message) + '</div>';
}
}
async function loadPointInTimeBackups(appId) {
var listEl = document.getElementById('pit-backups-list');
if (!listEl) return;
listEl.innerHTML = '<div style="padding: 20px; text-align: center;"><span class="brand-spinner"></span> Loading backups...</div>';
try {
var res = await fetch('/api/v1/backups/files/' + encodeURIComponent(appId));
var data = await res.json();
if (!data.success || !data.files || data.files.length === 0) {
listEl.innerHTML = '<div class="panel-empty"><span class="empty-icon">💾</span> No backup files for ' + escapeHtml(appId) + '</div>';
return;
}
var html = '<div style="font-size: 0.75rem; color: var(--muted); margin-bottom: 8px;">' + data.files.length + ' backup(s)</div>' +
'<div style="display: flex; flex-direction: column; gap: 6px;">';
for (var i = 0; i < data.files.length; i++) {
var f = data.files[i];
var dateStr = new Date(f.timestamp).toLocaleString();
html += '<div style="padding: 10px 12px; background: var(--card-base); border-radius: 8px; border: 1px solid var(--border);">' +
'<div style="display: flex; justify-content: space-between; align-items: center; margin-bottom: 4px;">' +
' <div style="font-weight: 500; font-size: 0.85rem;">' + escapeHtml(f.name) + '</div>' +
' <div style="font-size: 0.75rem; color: var(--muted);">' + f.sizeFormatted + '</div>' +
'</div>' +
'<div style="font-size: 0.75rem; color: var(--muted); margin-bottom: 8px;">' + dateStr + '</div>' +
'<div style="display: flex; gap: 6px;">' +
' <button class="pit-compare-btn" data-appid="' + escapeHtml(appId) + '" data-filename="' + escapeHtml(f.name) + '" style="padding: 4px 10px; font-size: 0.75rem; background: transparent; border: 1px solid var(--accent); color: var(--accent); border-radius: 5px; cursor: pointer;">Compare</button>' +
' <button class="pit-restore-btn" data-appid="' + escapeHtml(appId) + '" data-filename="' + escapeHtml(f.name) + '" style="padding: 4px 10px; font-size: 0.75rem; background: linear-gradient(135deg, var(--ok-fg), #27ae60); border: none; color: white; border-radius: 5px; cursor: pointer; font-weight: 500;">Restore</button>' +
'</div>' +
'</div>';
}
html += '</div>';
listEl.innerHTML = html;
// Wire up buttons
listEl.querySelectorAll('.pit-compare-btn').forEach(function(btn) {
btn.addEventListener('click', function() { compareBackupFile(btn.dataset.appid, btn.dataset.filename); });
});
listEl.querySelectorAll('.pit-restore-btn').forEach(function(btn) {
btn.addEventListener('click', function() { restoreBackupFile(btn.dataset.appid, btn.dataset.filename); });
});
} catch (e) {
listEl.innerHTML = '<div class="panel-empty" style="color: var(--bad-fg);">Failed: ' + escapeHtml(e.message) + '</div>';
}
}
async function compareBackupFile(appId, filename) {
try {
var res = await secureFetch('/api/v1/backups/compare/' + encodeURIComponent(filename), {
method: 'POST',
headers: { 'Content-Type': 'application/json' },
body: JSON.stringify({})
});
var data = await res.json();
if (!data.success) {
showNotification('Compare failed: ' + (data.error || 'Unknown'), 'error');
return;
}
var diff = data.diff;
var html = '<div style="position: fixed; top: 0; left: 0; right: 0; bottom: 0; background: rgba(0,0,0,0.5); z-index: 10000; display: flex; align-items: center; justify-content: center;" id="compare-overlay">' +
'<div style="background: var(--base); border-radius: 12px; max-width: 600px; width: 90%; max-height: 80vh; overflow: auto; padding: 20px; border: 1px solid var(--border);">' +
'<h4 style="margin: 0 0 16px;">📊 Compare: ' + escapeHtml(filename) + '</h4>' +
'<div style="font-size: 0.8rem; color: var(--muted); margin-bottom: 16px;">Size: ' + (diff.sizeFormatted || '?') + ' | Created: ' + new Date(diff.timestamp).toLocaleString() + '</div>';
if (diff.services) {
var svcChanged = diff.services.hasChanges ? '🔴' : '🟢';
html += '<div style="margin-bottom: 12px; padding: 10px; background: var(--card-base); border-radius: 6px; border: 1px solid var(--border);">' +
'<div style="font-weight: 600; font-size: 0.85rem; margin-bottom: 4px;">' + svcChanged + ' Services (backup vs current)</div>' +
'<div style="font-size: 0.8rem; color: var(--muted);">Backup: ' + diff.services.backupCount + ' services | Current: ' + diff.services.currentCount + ' services</div>';
if (diff.services.hasChanges) {
html += '<div style="margin-top: 6px; font-size: 0.8rem; color: #f39c12;">Services differ — restoring will replace current configuration</div>';
}
html += '</div>';
}
if (diff.config) {
var cfgChanged = diff.config.hasChanges ? '🔴' : '🟢';
html += '<div style="margin-bottom: 12px; padding: 10px; background: var(--card-base); border-radius: 6px; border: 1px solid var(--border);">' +
'<div style="font-weight: 600; font-size: 0.85rem; margin-bottom: 4px;">' + cfgChanged + ' Configuration</div>';
if (diff.config.hasChanges) {
html += '<div style="font-size: 0.8rem; color: #f39c12;">Configuration differs — restoring will replace current settings</div>';
} else {
html += '<div style="font-size: 0.8rem; color: var(--ok-fg);">No changes</div>';
}
html += '</div>';
}
html += '<button id="compare-close-btn" style="padding: 8px 20px; background: var(--accent); border: none; color: white; border-radius: 6px; cursor: pointer; font-weight: 500;">Close</button>' +
'</div></div>';
document.body.insertAdjacentHTML('beforeend', html);
document.getElementById('compare-close-btn')?.addEventListener('click', function() {
document.getElementById('compare-overlay')?.remove();
});
document.getElementById('compare-overlay')?.addEventListener('click', function(e) {
if (e.target === this) this.remove();
});
} catch (e) {
showNotification('Compare error: ' + e.message, 'error');
}
}
async function restoreBackupFile(appId, filename) {
if (!confirm('Restore ' + filename + ' for ' + appId + '?\n\nThis will replace current configuration, credentials, and data. Containers will be restarted.')) return;
try {
var res = await secureFetch('/api/v1/apps/' + encodeURIComponent(appId) + '/revert/' + encodeURIComponent(filename), {
method: 'POST',
headers: { 'Content-Type': 'application/json' },
body: JSON.stringify({ restartContainers: true })
});
var data = await res.json();
if (data.success) {
showNotification(appId + ' restored to ' + filename, 'success');
setTimeout(function() { location.reload(); }, 1500);
} else {
showNotification('Restore failed: ' + (data.error || 'Unknown'), 'error');
}
} catch (e) {
showNotification('Restore error: ' + e.message, 'error');
}
}
})();
+455
View File
@@ -0,0 +1,455 @@
// ========== BUNDLED WORKFLOWS ==========
(function() {
const WORKFLOW_DEFINITIONS = {
'auto-restart-on-crash': {
name: 'Auto-Restart on Crash',
icon: '🔄',
description: 'Automatically restart a container when it goes down',
trigger: 'container-down',
actions: 'restart + notify'
},
'backup-before-update': {
name: 'Backup Before Update',
icon: '💾',
description: 'Create a backup before any app update',
trigger: 'pre-update',
actions: 'backup + notify'
},
'health-check-on-interval': {
name: 'Periodic Health Check',
icon: '🏥',
description: 'Run health checks every 15 minutes and alert if degraded',
trigger: 'scheduled (15m)',
actions: 'health-check + alert'
},
'disk-space-alert': {
name: 'Disk Space Alert',
icon: '⚠️',
description: 'Alert when disk usage exceeds 80%',
trigger: 'resource-alert',
actions: 'notify'
},
'weekly-container-report': {
name: 'Weekly Container Report',
icon: '📊',
description: 'Send a weekly summary of container status and resource usage',
trigger: 'scheduled (weekly)',
actions: 'collect metrics + report'
}
};
let isPremium = false;
// === CHECK PREMIUM ===
async function checkPremium() {
try {
const resp = await fetch('/api/v1/license/feature/workflows');
const data = await resp.json();
isPremium = data.available;
} catch {
isPremium = false;
}
return isPremium;
}
// === RENDER WORKFLOW CARD ===
function renderWorkflowCard(workflow) {
const def = WORKFLOW_DEFINITIONS[workflow.id] || {
name: workflow.name || workflow.id,
icon: '⚡',
description: workflow.description || '',
trigger: workflow.trigger || 'unknown',
actions: workflow.actions ? workflow.actions.map(a => a.type).join(' + ') : ''
};
const locked = !isPremium;
const cardClass = locked ? 'workflow-card locked' : 'workflow-card';
return `<div class="${cardClass}" data-workflow="${workflow.id}">
<div class="workflow-header">
<span class="workflow-name">${def.icon} ${escapeHtml(def.name)}</span>
<label class="toggle-switch">
<input type="checkbox" class="workflow-toggle" data-workflow="${workflow.id}" ${workflow.enabled ? 'checked' : ''} ${locked ? 'disabled' : ''} />
<span class="slider"></span>
</label>
</div>
<p class="workflow-desc">${escapeHtml(def.description)}</p>
<div class="workflow-meta">
<span class="workflow-trigger"> Trigger: ${escapeHtml(def.trigger)}</span>
<span class="workflow-actions"> Actions: ${escapeHtml(def.actions)}</span>
</div>
${locked ? `<div class="workflow-locked-overlay">
<span class="lock-icon">🔒</span>
<span class="lock-text">Upgrade to Enable</span>
</div>` : ''}
<button class="btn-run-now" data-workflow="${workflow.id}" ${locked ? 'disabled' : ''}>
Run Now
</button>
</div>`;
}
// === LOAD WORKFLOWS TAB ===
async function loadWorkflowsTab() {
const container = document.getElementById('workflow-list-container');
if (!container) return;
container.innerHTML = '<div class="panel-empty"><span class="brand-spinner"></span> Loading workflows...</div>';
try {
const resp = await fetch('/api/v1/workflows');
const data = await resp.json();
if (data.success && data.workflows) {
if (data.workflows.length === 0) {
container.innerHTML = '<div class="panel-empty"><span class="empty-icon">⚡</span>No workflows configured</div>';
return;
}
let html = '';
for (const workflow of data.workflows) {
html += renderWorkflowCard(workflow);
}
// Add non-premium banner
if (!isPremium) {
html += `<div class="accent-info-box" style="margin-top: 16px; text-align: center;">
<span>🔒 Upgrade to unlock automated workflows</span>
<button onclick="showNotification('Upgrade to Premium to enable workflows!', 'info'); scrollToSection('license');" style="margin-left: 12px; padding: 6px 16px; background: linear-gradient(135deg, #f39c12, #e67e22); border: none; color: white; border-radius: 6px; cursor: pointer; font-weight: 600;">Upgrade to Premium</button>
</div>`;
}
container.innerHTML = `<div class="workflow-list">${html}</div>`;
wireWorkflowEvents();
} else {
container.innerHTML = '<div class="panel-empty"><span class="empty-icon">⚠️</span>Failed to load workflows</div>';
}
} catch (error) {
container.innerHTML = '<div class="panel-empty"><span class="empty-icon">⚠️</span>Error loading workflows: ' + escapeHtml(error.message) + '</div>';
}
}
// === LOAD HISTORY TAB ===
async function loadHistoryTab() {
const container = document.getElementById('workflow-history-body');
if (!container) return;
container.innerHTML = '<tr><td colspan="5" style="text-align: center; padding: 20px;"><span class="brand-spinner"></span> Loading history...</td></tr>';
try {
const resp = await fetch('/api/v1/workflows/history?limit=100');
const data = await resp.json();
if (data.success && data.history && data.history.length > 0) {
let html = '';
for (const entry of data.history) {
const time = new Date(entry.timestamp).toLocaleString();
const duration = entry.duration ? entry.duration + 'ms' : '-';
const resultClass = entry.success ? 'result-success' : 'result-failure';
const resultText = entry.success ? '✓ Success' : '✗ Failed';
html += `<tr>
<td>${escapeHtml(time)}</td>
<td>${escapeHtml(entry.workflowName || entry.workflowId)}</td>
<td>${escapeHtml(entry.trigger || 'manual')}</td>
<td class="${resultClass}">${resultText}</td>
<td>${escapeHtml(duration)}</td>
</tr>`;
}
container.innerHTML = html;
} else {
container.innerHTML = '<tr><td colspan="5" style="text-align: center; padding: 20px; color: var(--muted);">No workflow history yet</td></tr>';
}
} catch (error) {
container.innerHTML = '<tr><td colspan="5" style="text-align: center; padding: 20px; color: var(--bad-fg);">Error loading history</td></tr>';
}
}
// === WIRE WORKFLOW EVENTS ===
function wireWorkflowEvents() {
// Toggle switches
document.querySelectorAll('.workflow-toggle').forEach(toggle => {
toggle.addEventListener('change', async function() {
const workflowId = this.dataset.workflow;
const enabled = this.checked;
const endpoint = enabled ? 'enable' : 'disable';
try {
const resp = await fetch(`/api/v1/workflows/${workflowId}/${endpoint}`, { method: 'POST' });
const data = await resp.json();
if (!data.success) {
showNotification(`Failed to ${endpoint} workflow`, 'error', 3000);
this.checked = !enabled; // revert
}
} catch (error) {
showNotification(`Error: ${error.message}`, 'error', 3000);
this.checked = !enabled; // revert
}
});
});
// Run Now buttons
document.querySelectorAll('.btn-run-now').forEach(btn => {
btn.addEventListener('click', async function() {
const workflowId = this.dataset.workflow;
const originalText = this.innerHTML;
this.innerHTML = '<span class="brand-spinner"></span>';
this.disabled = true;
try {
const resp = await fetch(`/api/v1/workflows/${workflowId}/run`, {
method: 'POST',
headers: { 'Content-Type': 'application/json' },
body: JSON.stringify({ trigger: 'manual' })
});
const data = await resp.json();
if (data.success) {
showNotification(`Workflow "${WORKFLOW_DEFINITIONS[workflowId]?.name || workflowId}" executed successfully`, 'success', 3000);
} else {
showNotification(`Workflow failed: ${data.error || 'Unknown error'}`, 'error', 4000);
}
} catch (error) {
showNotification(`Error: ${error.message}`, 'error', 3000);
} finally {
this.innerHTML = originalText;
this.disabled = false;
}
});
});
}
// === TAB SWITCHING ===
function setupTabSwitching() {
document.querySelectorAll('.workflows-tab-btn').forEach(btn => {
btn.addEventListener('click', function() {
const panelId = this.dataset.panel;
// Update tab buttons
document.querySelectorAll('.workflows-tab-btn').forEach(b => b.classList.remove('active'));
this.classList.add('active');
// Update panels
document.querySelectorAll('.workflow-panel').forEach(p => p.classList.remove('active'));
document.getElementById(panelId)?.classList.add('active');
// Load data for the active panel
if (panelId === 'workflows-list-panel') {
loadWorkflowsTab();
} else if (panelId === 'workflows-history-panel') {
loadHistoryTab();
}
});
});
}
// === INJECT MODAL HTML ===
injectModal('bundled-workflows-modal', `<div id="bundled-workflows-modal" class="weather-modal">
<div class="weather-modal-content" style="min-width: 600px; max-width: 750px;">
<h3> Bundled Workflows</h3>
<p class="modal-subtitle">
Automated workflows to keep your system running smoothly
</p>
<!-- Tab bar -->
<div class="panel-tabs">
<button class="workflows-tab-btn panel-tab active" data-panel="workflows-list-panel">Workflows</button>
<button class="workflows-tab-btn panel-tab" data-panel="workflows-history-panel">History</button>
</div>
<!-- Tab: Workflows -->
<div id="workflows-list-panel" class="workflow-panel panel-section active">
<div id="workflow-list-container">
<div class="panel-empty">
<span class="brand-spinner"></span> Loading workflows...
</div>
</div>
</div>
<!-- Tab: History -->
<div id="workflows-history-panel" class="workflow-panel panel-section">
<div class="workflow-history">
<table>
<thead>
<tr>
<th>Time</th>
<th>Workflow</th>
<th>Trigger</th>
<th>Result</th>
<th>Duration</th>
</tr>
</thead>
<tbody id="workflow-history-body">
<!-- populated from API -->
</tbody>
</table>
</div>
</div>
<!-- Close Button -->
<div class="weather-modal-buttons modal-footer-bar">
<button id="workflows-cancel">Close</button>
</div>
</div>
</div>`);
const modal = document.getElementById('bundled-workflows-modal');
const openBtn = document.getElementById('bundled-workflows-btn');
const cancelBtn = document.getElementById('workflows-cancel');
// === STYLES ===
const style = document.createElement('style');
style.textContent = `
.workflow-list {
display: flex;
flex-direction: column;
gap: 12px;
}
.workflow-card {
position: relative;
padding: 16px;
background: var(--card-base);
border: 1px solid var(--border);
border-radius: 10px;
transition: all 0.2s ease;
}
.workflow-card:hover {
border-color: var(--accent);
box-shadow: 0 2px 8px rgba(0,0,0,0.1);
}
.workflow-card.locked {
opacity: 0.7;
}
.workflow-header {
display: flex;
justify-content: space-between;
align-items: center;
margin-bottom: 8px;
}
.workflow-name {
font-weight: 600;
font-size: 0.95rem;
}
.workflow-desc {
font-size: 0.82rem;
color: var(--muted);
margin: 0 0 10px 0;
line-height: 1.4;
}
.workflow-meta {
display: flex;
flex-wrap: wrap;
gap: 8px;
font-size: 0.75rem;
color: var(--muted);
margin-bottom: 12px;
}
.workflow-meta span {
padding: 2px 8px;
background: var(--base);
border-radius: 4px;
}
.workflow-locked-overlay {
position: absolute;
top: 0;
left: 0;
right: 0;
bottom: 0;
background: rgba(0,0,0,0.5);
border-radius: 10px;
display: flex;
flex-direction: column;
align-items: center;
justify-content: center;
gap: 8px;
}
.lock-icon {
font-size: 1.5rem;
}
.lock-text {
font-size: 0.8rem;
font-weight: 600;
color: #f39c12;
}
.workflow-history {
max-height: 400px;
overflow-y: auto;
}
.workflow-history table {
width: 100%;
border-collapse: collapse;
font-size: 0.82rem;
}
.workflow-history th {
text-align: left;
padding: 8px 10px;
background: var(--base);
border-bottom: 1px solid var(--border);
font-weight: 600;
position: sticky;
top: 0;
}
.workflow-history td {
padding: 8px 10px;
border-bottom: 1px solid var(--border);
}
.result-success {
color: var(--ok-fg);
font-weight: 500;
}
.result-failure {
color: var(--bad-fg);
font-weight: 500;
}
.workflow-panel {
display: none;
}
.workflow-panel.active {
display: block;
}
.accent-info-box {
padding: 12px 16px;
background: color-mix(in srgb, var(--accent) 10%, transparent);
border: 1px solid var(--accent);
border-radius: 8px;
margin-bottom: 12px;
}
`;
document.head.appendChild(style);
// === MODAL EVENTS ===
openBtn?.addEventListener('click', async function() {
modal.classList.add('show');
await checkPremium();
loadWorkflowsTab();
});
setupTabSwitching();
// Close on cancel
cancelBtn?.addEventListener('click', function() {
modal.classList.remove('show');
});
// Wire modal escape key / click outside
wireModal(modal, cancelBtn);
})();
+31 -9
View File
@@ -41,8 +41,11 @@
dismissedUpdates = new Set();
}
// Track global update state for cross-component access
let knownUpdates = [];
// Fetch update data and show badges
async function refreshCardUpdates() {
async function refreshCardUpdates(notifyNew) {
try {
const res = await fetch('/api/v1/updates/available');
const data = await res.json();
@@ -51,9 +54,21 @@
// Clear all update badges first
document.querySelectorAll('.update-available-badge').forEach(el => el.classList.remove('visible'));
if (!data.updates?.length) return;
const updates = data.updates || [];
knownUpdates = updates; // store globally
for (const upd of data.updates) {
// Notify if new updates appeared (periodic check with notification)
if (notifyNew && updates.length > 0) {
const prev = window._lastKnownUpdateCount || 0;
if (prev > 0 && updates.length > prev) {
showNotification(`${updates.length} container update(s) available — click Update Management to review.`, 'info');
}
window._lastKnownUpdateCount = updates.length;
}
if (!updates.length) return;
for (const upd of updates) {
// Try to match by container name to service id
const apps = window.APPS || [];
for (const app of apps) {
@@ -61,17 +76,24 @@
// Skip dismissed updates
if (dismissedUpdates.has(app.id)) break;
const badge = document.getElementById('update-badge-' + app.id);
const updateBtn = document.getElementById('update-btn-' + app.id);
if (badge) {
badge.classList.add('visible');
badge.title = `Image digest changed. Click to dismiss if already up to date.\n${upd.imageName || ''}`;
badge.title = `Update available — click to open Update Management.`;
badge.style.cursor = 'pointer';
badge.onclick = (e) => {
e.stopPropagation();
badge.classList.remove('visible');
dismissedUpdates.add(app.id);
safeSessionSet('dismissed-updates', JSON.stringify([...dismissedUpdates]));
// Open Update Management modal focused on this app
if (window.openUpdateModal) window.openUpdateModal(app.id);
};
}
// Highlight update button if update is available
if (updateBtn) {
updateBtn.style.background = '#f97316';
updateBtn.style.borderColor = '#f97316';
updateBtn.style.boxShadow = '0 0 6px #f9731688';
updateBtn.title = `Update available — click to open Update Management.`;
}
break;
}
}
@@ -90,10 +112,10 @@
refreshCardUpdates();
}, 5000);
// Periodic refresh every 60 seconds
// Periodic refresh every 60 seconds — notify on new updates detected
setInterval(() => {
refreshCardHealth();
refreshCardUpdates();
refreshCardUpdates(true); // true = notify if new updates found
}, 60000);
}
+15
View File
@@ -95,6 +95,8 @@
const card = el('div', 'card');
card.setAttribute('data-app', s.id);
card.setAttribute('data-status', 'off'); // Initial status
if (s.containerId) card.setAttribute('data-container-id', s.containerId);
if (s.category) card.setAttribute('data-category', s.category);
if (s.recipeId) card.setAttribute('data-recipe-id', s.recipeId);
const dot = el('span', 'dot bad at-bl'); dot.id = 'dot-' + s.id + '-grid'; card.appendChild(dot);
@@ -156,6 +158,16 @@
nameSpan.appendChild(tsBadge);
}
// Add Category badge if service has one (colored pill with icon)
if (s.category) {
const cats = (typeof DC !== 'undefined' && DC.CATEGORIES) || window.DC_CATEGORIES || {};
const catInfo = cats[s.category] || {};
const catBadge = el('span', 'cat-badge', `${catInfo.icon || ''} ${s.category}`.trim());
catBadge.title = `Category: ${s.category}`;
catBadge.style.cssText = `margin-left: 6px; font-size: 0.65rem; padding: 1px 6px; border-radius: 999px; background: color-mix(in srgb, ${catInfo.color || '#7f8c8d'} 25%, transparent); color: ${catInfo.color || '#7f8c8d'}; border: 1px solid color-mix(in srgb, ${catInfo.color || '#7f8c8d'} 50%, transparent); white-space: nowrap; font-weight: 500;`;
nameSpan.appendChild(catBadge);
}
row.appendChild(el('span', 'spacer'));
const pill = el('span', 'badge off', 'OFF'); pill.id = 'badge-' + s.id; row.appendChild(pill);
@@ -282,6 +294,9 @@
// Group recipe cards visually after grid is built
if (window.groupRecipeCards) requestAnimationFrame(() => window.groupRecipeCards());
// Refresh the service filter so the category dropdown reflects new services
if (window.refreshServiceFilter) window.refreshServiceFilter();
}
function setBadge(id, up, responseTime = null) {
+51
View File
@@ -59,11 +59,13 @@
}
_dashboardInitialized = true;
await window.loadServices();
await loadTemplateCategories();
window.buildGrid();
animateTopCards();
window.refreshAll();
setInterval(window.refreshAll, DC.POLL.DASHBOARD);
if (typeof window.refreshCredsButtons === 'function') window.refreshCredsButtons();
if (typeof window.refreshMonitoringWidgets === 'function') window.refreshMonitoringWidgets();
// Update auth card (may have already been updated by the auto-load IIFE but ensure it's correct)
if (typeof window._updateAuthCard === 'function') {
try {
@@ -200,6 +202,55 @@
window.loadCustomServices = loadCustomServices;
registerServiceWorker();
// ===== TEMPLATE CATEGORIES =====
// Cached template categories from /api/v1/templates for use across the UI
// (service create/edit, filter dropdown, category badges, etc.)
async function loadTemplateCategories() {
try {
const r = await fetch('/api/v1/templates', { cache: 'no-store' });
if (!r.ok) return;
const data = await r.json();
if (data && data.categories) {
window.DC_CATEGORIES = data.categories;
// Also expose via globals.js constant for convenience
if (typeof DC !== 'undefined') DC.CATEGORIES = data.categories;
// Populate any category <select> that's already in the DOM
populateCategorySelects();
}
} catch (e) {
console.warn('[init] Failed to load template categories:', e);
}
}
function populateCategorySelects() {
const cats = window.DC_CATEGORIES || (typeof DC !== 'undefined' && DC.CATEGORIES);
if (!cats) return;
document.querySelectorAll('select[data-role="service-category"]').forEach(select => {
const current = select.dataset.current || '';
// Clear options but keep the first (placeholder)
const placeholder = select.querySelector('option[value=""]');
select.innerHTML = '';
if (placeholder) select.appendChild(placeholder);
else {
const ph = document.createElement('option');
ph.value = '';
ph.textContent = '— Select category —';
select.appendChild(ph);
}
Object.entries(cats).forEach(([name, info]) => {
const opt = document.createElement('option');
opt.value = name;
opt.textContent = `${info.icon || ''} ${name}`.trim();
if (name === current) opt.selected = true;
select.appendChild(opt);
});
});
}
// Allow other modules to re-run population after they (re)inject selects
window.populateCategorySelects = populateCategorySelects;
window.loadTemplateCategories = loadTemplateCategories;
// TOTP-gated initialization
(async () => {
try {
+12
View File
@@ -262,6 +262,7 @@
const proxyIp = document.getElementById('external-proxy-ip').value.trim() || SITE.dnsIp || 'localhost';
const preserveHost = document.getElementById('external-preserve-host').checked;
const followRedirects = document.getElementById('external-follow-redirects').checked;
const category = document.getElementById('external-service-category')?.value || '';
if (!name || !externalUrl) {
showNotification('Please fill in Name and External URL', 'warning');
@@ -341,6 +342,8 @@
isExternal: true,
isCustom: true
};
// Only attach category if user actually picked one
if (category) newService.category = category;
window.APPS.push(newService);
results.dashboard = true;
@@ -457,6 +460,13 @@
const healthCheck = document.getElementById('health-check-input')?.value || '';
const timeout = document.getElementById('timeout-input')?.value || 30;
// Category is optional — pulled from either local or external select by the
// openAddServiceModal reset. If user doesn't choose one, it stays undefined
// and we don't send it (so the backend keeps the existing behavior).
const categoryEl = document.getElementById('service-category-input')
|| document.getElementById('external-service-category');
const category = categoryEl?.value || '';
const dnsToken = window.getToken(getPrimaryDnsId(), 'admin');
if (!name || !port || !ip) {
@@ -525,6 +535,8 @@
logo: logo || `/assets/${subdomain}.png`,
tailscaleOnly: tailscaleOnly || false
};
// Only include category if user actually picked one
if (category) serviceConfig.category = category;
await window.addServiceToConfig(serviceConfig);
results.dashboard = true;
+16 -2
View File
@@ -19,6 +19,16 @@
document.getElementById('edit-tailscale-only').checked = service.tailscaleOnly || false;
document.getElementById('edit-logo-url').value = service.logo || '';
// Populate the category select for this service, then set the current value.
// populateCategorySelects() uses data-current so we set it first, then call.
const categorySelect = document.getElementById('edit-service-category');
if (categorySelect) {
categorySelect.dataset.current = service.category || '';
if (typeof window.populateCategorySelects === 'function') {
window.populateCategorySelects();
}
}
modal.classList.add('show');
}
@@ -36,6 +46,7 @@
const newIp = document.getElementById('edit-ip').value.trim() || 'localhost';
const tailscaleOnly = document.getElementById('edit-tailscale-only').checked;
const newLogo = document.getElementById('edit-logo-url').value.trim();
const newCategory = document.getElementById('edit-service-category')?.value || '';
if (!newSubdomain) {
showNotification('Subdomain is required', 'warning');
@@ -51,6 +62,7 @@
if (newIp !== currentEditService.ip) changes.push('ip');
if (tailscaleOnly !== (currentEditService.tailscaleOnly || false)) changes.push('tailscale');
if (newLogo && newLogo !== currentEditService.logo) changes.push('logo');
if (newCategory !== (currentEditService.category || '')) changes.push('category');
if (changes.length === 0) {
closeServiceEditModal();
@@ -72,7 +84,8 @@
port: newPort || currentEditService.port,
ip: newIp,
tailscaleOnly,
logo: newLogo || undefined
logo: newLogo || undefined,
category: newCategory
})
});
@@ -91,7 +104,8 @@
port: newPort || window.APPS[appIndex].port,
ip: newIp,
tailscaleOnly,
logo: newLogo || window.APPS[appIndex].logo
logo: newLogo || window.APPS[appIndex].logo,
category: newCategory || undefined
};
}
+6 -3
View File
@@ -14,15 +14,15 @@
const result = await response.json();
if (result.status === 'success') {
if (result.success) {
const select = document.getElementById('existing-ca-select');
select.innerHTML = '';
if (result.data.cas.length === 0) {
if (result.cas.length === 0) {
select.innerHTML = '<option value="">No CAs found in Caddyfile</option>';
} else {
select.innerHTML = '<option value="">Select existing CA...</option>';
result.data.cas.forEach(ca => {
result.cas.forEach(ca => {
const option = document.createElement('option');
if (typeof ca === 'object') {
option.value = ca.id;
@@ -187,6 +187,9 @@
name: serviceConfig.name,
logo: serviceConfig.logo || `/assets/${serviceConfig.subdomain}.png`
};
// Forward optional metadata fields if provided
if (serviceConfig.category) newService.category = serviceConfig.category;
if (serviceConfig.containerId) newService.containerId = serviceConfig.containerId;
try {
const response = await secureFetch('/api/v1/services', {
+27
View File
@@ -82,6 +82,16 @@
Enter a URL or upload an image file (PNG, JPG, SVG)
</div>
</div>
<!-- Category -->
<div>
<label for="edit-service-category" class="form-label-accent-sm">
Category
</label>
<select id="edit-service-category" data-role="service-category" class="form-input-md">
<option value=""> No category </option>
</select>
</div>
</div>
<div class="weather-modal-buttons" style="margin-top: 24px;">
@@ -239,6 +249,15 @@
Reload Caddy after adding
</label>
<!-- Category -->
<div>
<label for="service-category-input" style="font-size: 0.8rem; color: var(--muted); margin-bottom: 4px; display: block;">Category</label>
<select id="service-category-input" data-role="service-category" style="width: 100%;">
<option value=""> No category </option>
</select>
<div style="font-size: 0.7rem; color: var(--muted); margin-top: 3px;">Group services on the dashboard by purpose (Media, Productivity, etc.)</div>
</div>
<hr style="border: none; border-top: 1px solid var(--border); margin: 4px 0;" />
<div class="grid-2col">
@@ -326,6 +345,14 @@
Follow Redirects
</label>
<!-- Category (external) -->
<div>
<label for="external-service-category" style="font-size: 0.8rem; color: var(--muted); margin-bottom: 4px; display: block;">Category</label>
<select id="external-service-category" data-role="service-category" style="width: 100%;">
<option value=""> No category </option>
</select>
</div>
</div>
</details>
</div>
+30
View File
@@ -95,6 +95,36 @@
'Prometheus metrics'
],
recommended: false
},
{
id: 'cloudflare',
name: 'Cloudflare DNS',
description: 'Managed DNS with API access — no self-hosting needed',
icon: '🔶',
difficulty: 'Easy',
features: [
'Fully managed, no server needed',
'API for automated record management',
'Global anycast network',
'Free tier available'
],
recommended: false,
providerId: 'cloudflare'
},
{
id: 'external',
name: 'External / Manual DNS',
description: 'Use your own DNS provider (cPanel, Route53, etc.)',
icon: '🔗',
difficulty: 'Easy',
features: [
'Works with any DNS provider',
'DashCaddy shows you what records to create',
'Propagation checking still works',
'No API credentials needed'
],
recommended: false,
providerId: 'manual'
}
];
}
+304
View File
@@ -0,0 +1,304 @@
// ========== MONITORING WIDGETS ==========
// Embeds a compact system-resource + health summary panel directly on the
// main dashboard. Replaces the need for a separate monitoring-dashboard.html
// page — quick at-a-glance stats where you already are.
(function () {
// ----- Style injection (scoped to .dc-monitor so it doesn't leak) -----
const styleEl = document.createElement('style');
styleEl.textContent = `
.dc-monitor {
display: grid;
grid-template-columns: repeat(auto-fit, minmax(220px, 1fr));
gap: 12px;
margin-bottom: 16px;
padding: 12px 16px;
background: var(--card-base);
border: 1px solid var(--border);
border-radius: var(--radius);
}
.dc-monitor-card {
padding: 10px 12px;
background: var(--card-bg, rgba(255,255,255,0.04));
border-radius: 8px;
border: 1px solid var(--border);
}
.dc-monitor-label {
font-size: 0.7rem;
color: var(--muted);
text-transform: uppercase;
letter-spacing: 0.5px;
margin-bottom: 4px;
}
.dc-monitor-value {
font-size: 1.4rem;
font-weight: 600;
color: var(--fg);
}
.dc-monitor-sub {
font-size: 0.7rem;
color: var(--muted);
margin-top: 4px;
}
.dc-monitor-bar {
margin-top: 6px;
width: 100%;
height: 4px;
background: color-mix(in srgb, var(--muted) 20%, transparent);
border-radius: 2px;
overflow: hidden;
}
.dc-monitor-bar-fill {
height: 100%;
width: 0%;
background: var(--ok-fg, #27ae60);
transition: width 0.3s ease, background 0.3s ease;
}
.dc-monitor-bar-fill.warn { background: #f39c12; }
.dc-monitor-bar-fill.bad { background: #e74c3c; }
.dc-monitor-header {
display: flex;
align-items: center;
justify-content: space-between;
margin-bottom: 8px;
}
.dc-monitor-title {
font-size: 0.85rem;
font-weight: 500;
color: var(--muted);
display: flex;
align-items: center;
gap: 6px;
}
.dc-monitor-pill {
display: inline-flex;
align-items: center;
gap: 4px;
padding: 2px 8px;
border-radius: 999px;
font-size: 0.7rem;
font-weight: 500;
}
.dc-monitor-pill.ok { background: color-mix(in srgb, #27ae60 20%, transparent); color: #27ae60; }
.dc-monitor-pill.warn { background: color-mix(in srgb, #f39c12 20%, transparent); color: #f39c12; }
.dc-monitor-pill.bad { background: color-mix(in srgb, #e74c3c 20%, transparent); color: #e74c3c; }
.dc-monitor-refresh {
font-size: 0.7rem;
color: var(--muted);
opacity: 0.7;
}
`;
document.head.appendChild(styleEl);
// ----- Container element (inserted above service-filter-bar) -----
const filterBar = document.getElementById('service-filter-bar');
if (!filterBar) return;
const panel = document.createElement('div');
panel.className = 'dc-monitor';
panel.id = 'dc-monitor-panel';
panel.innerHTML = `
<div class="dc-monitor-header" style="grid-column: 1 / -1;">
<div class="dc-monitor-title">📊 System Overview</div>
<span class="dc-monitor-refresh" id="dc-monitor-refresh-stamp"></span>
</div>
<div class="dc-monitor-card">
<div class="dc-monitor-label">Services</div>
<div class="dc-monitor-value" id="dc-monitor-services"></div>
<div class="dc-monitor-sub" id="dc-monitor-services-sub">loading</div>
</div>
<div class="dc-monitor-card">
<div class="dc-monitor-label">Containers Up</div>
<div class="dc-monitor-value" id="dc-monitor-containers"></div>
<div class="dc-monitor-sub" id="dc-monitor-containers-sub">loading</div>
</div>
<div class="dc-monitor-card">
<div class="dc-monitor-label">Avg CPU</div>
<div class="dc-monitor-value" id="dc-monitor-cpu"></div>
<div class="dc-monitor-bar"><div class="dc-monitor-bar-fill" id="dc-monitor-cpu-bar"></div></div>
</div>
<div class="dc-monitor-card">
<div class="dc-monitor-label">Avg Memory</div>
<div class="dc-monitor-value" id="dc-monitor-mem"></div>
<div class="dc-monitor-bar"><div class="dc-monitor-bar-fill" id="dc-monitor-mem-bar"></div></div>
</div>
<div class="dc-monitor-card">
<div class="dc-monitor-label">Health</div>
<div class="dc-monitor-value" id="dc-monitor-health"></div>
<div class="dc-monitor-sub" id="dc-monitor-health-sub"></div>
</div>
`;
// Insert ABOVE the filter bar
filterBar.parentNode.insertBefore(panel, filterBar);
// ----- Helpers -----
function setBar(id, pct) {
const el = document.getElementById(id);
if (!el) return;
const p = Math.max(0, Math.min(100, Number(pct) || 0));
el.style.width = p + '%';
el.classList.remove('warn', 'bad');
if (p >= 85) el.classList.add('bad');
else if (p >= 65) el.classList.add('warn');
}
function fmtPct(v) {
if (v == null || isNaN(v)) return '—';
return (Math.round(v * 10) / 10) + '%';
}
function fmtBytes(b) {
if (b == null || isNaN(b)) return '—';
const units = ['B', 'KB', 'MB', 'GB', 'TB'];
let i = 0;
while (b >= 1024 && i < units.length - 1) { b /= 1024; i++; }
return b.toFixed(1) + ' ' + units[i];
}
function setServicesCard() {
const total = (window.APPS || []).length;
let up = 0;
document.querySelectorAll('#cards .card').forEach(c => {
if (c.dataset.status === 'on') up++;
});
const el = document.getElementById('dc-monitor-services');
const sub = document.getElementById('dc-monitor-services-sub');
if (el) el.textContent = `${up} / ${total}`;
if (sub) sub.textContent = total === 0 ? 'no services yet' : `${up} online · ${total - up} offline`;
}
function applyHealthSummary(data) {
const el = document.getElementById('dc-monitor-health');
const sub = document.getElementById('dc-monitor-health-sub');
if (!el) return;
if (!data || data.summary == null) {
el.textContent = '—';
if (sub) sub.textContent = 'no data';
return;
}
const s = data.summary;
const healthy = s.healthy ?? s.up ?? 0;
const unhealthy = s.unhealthy ?? s.down ?? 0;
const total = s.total ?? (healthy + unhealthy);
el.textContent = `${healthy}/${total}`;
if (sub) {
if (unhealthy === 0) {
sub.innerHTML = '<span class="dc-monitor-pill ok">● all healthy</span>';
} else if (unhealthy <= 2) {
sub.innerHTML = `<span class="dc-monitor-pill warn">● ${unhealthy} degraded</span>`;
} else {
sub.innerHTML = `<span class="dc-monitor-pill bad">● ${unhealthy} down</span>`;
}
}
}
// ----- Data fetches -----
async function fetchStats() {
try {
const r = await fetch('/api/v1/monitoring/stats', { cache: 'no-store' });
if (!r.ok) return null;
const data = await r.json();
return (data && data.stats) ? data.stats : null;
} catch (_) {
return null;
}
}
async function fetchHealth() {
try {
const r = await fetch('/api/v1/health-checks/status', { cache: 'no-store' });
if (!r.ok) return null;
return await r.json();
} catch (_) {
return null;
}
}
function applyStats(stats) {
const containers = document.getElementById('dc-monitor-containers');
const containersSub = document.getElementById('dc-monitor-containers-sub');
const cpuEl = document.getElementById('dc-monitor-cpu');
const memEl = document.getElementById('dc-monitor-mem');
if (!stats) {
if (containers) containers.textContent = '—';
if (cpuEl) cpuEl.textContent = '—';
if (memEl) memEl.textContent = '—';
return;
}
const entries = Object.values(stats);
if (entries.length === 0) {
if (containers) containers.textContent = '0';
if (containersSub) containersSub.textContent = 'no containers reporting';
if (cpuEl) cpuEl.textContent = '0%';
if (memEl) memEl.textContent = '0%';
setBar('dc-monitor-cpu-bar', 0);
setBar('dc-monitor-mem-bar', 0);
return;
}
let cpuSum = 0, memSum = 0, memBytes = 0, cpuCount = 0, memCount = 0;
entries.forEach(s => {
// CPU may be percentage (0-100) or fraction (0-1) — handle both
if (s.cpu != null) {
const cpu = Number(s.cpu);
if (!isNaN(cpu)) {
cpuSum += cpu > 1 ? cpu : cpu * 100;
cpuCount++;
}
}
if (s.memory != null) {
const mem = Number(s.memory);
if (!isNaN(mem)) {
memSum += mem;
memBytes += Number(s.memoryUsage || 0);
memCount++;
}
}
});
const avgCpu = cpuCount ? cpuSum / cpuCount : 0;
const avgMem = memCount ? memSum / memCount : 0;
if (containers) containers.textContent = String(entries.length);
if (containersSub) {
const memTxt = memBytes ? ` · ${fmtBytes(memBytes)} RAM` : '';
containersSub.textContent = `running${memTxt}`;
}
if (cpuEl) cpuEl.textContent = fmtPct(avgCpu);
if (memEl) memEl.textContent = fmtPct(avgMem);
setBar('dc-monitor-cpu-bar', avgCpu);
setBar('dc-monitor-mem-bar', avgMem);
}
// ----- Public refresh function -----
let inFlight = false;
async function refresh() {
if (inFlight) return;
inFlight = true;
try {
setServicesCard();
const [stats, health] = await Promise.all([fetchStats(), fetchHealth()]);
applyStats(stats);
applyHealthSummary(health);
const stamp = document.getElementById('dc-monitor-refresh-stamp');
if (stamp) {
const now = new Date();
stamp.textContent = `updated ${now.toLocaleTimeString()}`;
}
} finally {
inFlight = false;
}
}
// Expose for init.js to call once and re-call after each refreshAll cycle
window.refreshMonitoringWidgets = refresh;
// Auto-refresh on the STATS interval (separate from full DASHBOARD refresh)
setInterval(refresh, (typeof DC !== 'undefined' && DC.POLL && DC.POLL.STATS) || 5000);
// Refresh once on first script load (init.js also calls this; double-call is harmless)
setTimeout(refresh, 200);
})();
+59 -1
View File
@@ -168,6 +168,9 @@
<label class="checkbox-label-sm">
<input type="checkbox" id="event-deploy-failed" checked /> Deployment Failed
</label>
<label class="checkbox-label-sm" style="grid-column: 1 / -1;">
<input type="checkbox" id="event-resource-alert" checked /> Resource Alerts
</label>
</div>
<!-- History -->
@@ -175,9 +178,11 @@
<div id="notification-history" style="max-height: 150px; overflow-y: auto; padding: 8px; background: var(--card-base); border-radius: 8px; border: 1px solid var(--border); font-size: 0.8rem;">
<div style="color: var(--muted); text-align: center; padding: 20px;">No notifications yet</div>
</div>
<div id="last-notification-sent" style="font-size: 0.75rem; color: var(--muted); text-align: center; margin-top: 6px;"></div>
<!-- Buttons -->
<div class="weather-modal-buttons modal-footer-bar">
<button id="notifications-send-test" class="btn-secondary" style="margin-right: auto;">Send Test</button>
<button id="notifications-cancel">Cancel</button>
<button id="notifications-save" class="btn-accent">Save Settings</button>
</div>
@@ -254,6 +259,7 @@
document.getElementById('event-container-up').checked = config.events?.containerUp !== false;
document.getElementById('event-deploy-success').checked = config.events?.deploymentSuccess !== false;
document.getElementById('event-deploy-failed').checked = config.events?.deploymentFailed !== false;
document.getElementById('event-resource-alert').checked = config.events?.resourceAlert !== false;
}
} catch (error) {
errorHandler.logError('[Notifications] Load Config', error, { function: 'loadConfig' });
@@ -329,7 +335,8 @@
containerDown: document.getElementById('event-container-down').checked,
containerUp: document.getElementById('event-container-up').checked,
deploymentSuccess: document.getElementById('event-deploy-success').checked,
deploymentFailed: document.getElementById('event-deploy-failed').checked
deploymentFailed: document.getElementById('event-deploy-failed').checked,
resourceAlert: document.getElementById('event-resource-alert').checked
},
healthCheck: {
enabled: document.getElementById('health-check-enabled').checked,
@@ -404,5 +411,56 @@
});
saveBtn?.addEventListener('click', saveNotificationConfig);
// Send Test button - sends test notification to all enabled providers
document.getElementById('notifications-send-test')?.addEventListener('click', async () => {
const btn = document.getElementById('notifications-send-test');
const originalText = btn.textContent;
btn.textContent = 'Sending...';
btn.disabled = true;
try {
const response = await secureFetch('/api/v1/notifications/send', {
method: 'POST',
headers: { 'Content-Type': 'application/json' },
body: JSON.stringify({
event: 'test',
data: { message: 'This is a test notification from DashCaddy.' },
type: 'info'
})
});
const data = await response.json();
if (data.success) {
showNotification('Test notification sent!', 'success', 3000);
// Update last sent timestamp
loadNotificationStatus();
} else {
showNotification(`Test failed: ${data.results?.map(r => `${r.provider}: ${r.error || 'ok'}`).join(', ')}`, 'error', 5000);
}
} catch (error) {
showNotification(`Error: ${error.message}`, 'error', 3000);
} finally {
btn.textContent = originalText;
btn.disabled = false;
}
});
// Load notification status (last sent timestamp)
async function loadNotificationStatus() {
try {
const response = await fetch('/api/v1/notifications/status');
const data = await response.json();
if (data.success && data.lastSent) {
const lastSentEl = document.getElementById('last-notification-sent');
if (lastSentEl) {
lastSentEl.textContent = `Last sent: ${new Date(data.lastSent).toLocaleString()}`;
}
}
} catch (error) {
// Silently fail - status is not critical
}
}
wireModal(modal, cancelBtn);
})();
+172 -57
View File
@@ -236,70 +236,185 @@
async function loadAlerts() {
if (!alertsContainer) return;
alertsContainer.innerHTML = '<div class="panel-empty"><span class="brand-spinner"></span> Loading alerts...</div>';
const data = cachedMonitoringData;
if (!data || Object.keys(data).length === 0) {
alertsContainer.innerHTML = '<div class="panel-empty"><span class="empty-icon">🔔</span>No containers found. Open the Live Stats tab first.</div>';
return;
}
let html = '<div style="display: flex; flex-direction: column; gap: 12px;">';
for (const [id, info] of Object.entries(data)) {
const alertCfg = info.alertConfig || {};
html += `<div style="padding: 12px; background: var(--card-base); border-radius: 8px; border: 1px solid var(--border);">
<div style="display: flex; align-items: center; gap: 8px; margin-bottom: 10px;">
<span style="font-weight: 600; flex: 1;">${info.name || id}</span>
<label style="display: flex; align-items: center; gap: 6px; font-size: 0.8rem; cursor: pointer;">
<input type="checkbox" class="alert-enabled" data-container="${id}" ${alertCfg.enabled ? 'checked' : ''} /> Enabled
</label>
</div>
<div style="display: grid; grid-template-columns: 1fr 1fr 1fr; gap: 8px;">
<div>
<label style="font-size: 0.75rem; color: var(--muted);">CPU Threshold %</label>
<input type="number" class="alert-cpu" data-container="${id}" value="${alertCfg.cpuThreshold || 80}" min="1" max="100" style="width: 100%; font-size: 0.85rem;" />
</div>
<div>
<label style="font-size: 0.75rem; color: var(--muted);">Memory Threshold %</label>
<input type="number" class="alert-mem" data-container="${id}" value="${alertCfg.memoryThreshold || 85}" min="1" max="100" style="width: 100%; font-size: 0.85rem;" />
</div>
<div>
<label style="font-size: 0.75rem; color: var(--muted);">Cooldown (min)</label>
<input type="number" class="alert-cooldown" data-container="${id}" value="${alertCfg.cooldownMinutes || 15}" min="1" max="1440" style="width: 100%; font-size: 0.85rem;" />
</div>
</div>
<div style="display: flex; gap: 8px; margin-top: 8px; align-items: center;">
<label style="display: flex; align-items: center; gap: 6px; font-size: 0.8rem; cursor: pointer;">
<input type="checkbox" class="alert-autorestart" data-container="${id}" ${alertCfg.autoRestart ? 'checked' : ''} /> Auto-restart on breach
</label>
<span style="flex: 1;"></span>
<button class="alert-save-btn" data-container="${id}" style="padding: 4px 12px; font-size: 0.8rem; background: color-mix(in srgb, var(--accent) 20%, transparent); border: 1px solid var(--accent); color: var(--accent); border-radius: 4px; cursor: pointer;">Save</button>
</div>
</div>`;
}
html += '</div>';
alertsContainer.innerHTML = html;
// Wire up save buttons
alertsContainer.querySelectorAll('.alert-save-btn').forEach(btn => {
btn.addEventListener('click', async () => {
const cId = btn.dataset.container;
const enabled = alertsContainer.querySelector(`.alert-enabled[data-container="${cId}"]`)?.checked || false;
const cpuThreshold = parseInt(alertsContainer.querySelector(`.alert-cpu[data-container="${cId}"]`)?.value) || 80;
const memoryThreshold = parseInt(alertsContainer.querySelector(`.alert-mem[data-container="${cId}"]`)?.value) || 85;
const cooldownMinutes = parseInt(alertsContainer.querySelector(`.alert-cooldown[data-container="${cId}"]`)?.value) || 15;
const autoRestart = alertsContainer.querySelector(`.alert-autorestart[data-container="${cId}"]`)?.checked || false;
try {
const res = await secureFetch(`/api/v1/monitoring/alerts/${cId}`, {
method: 'POST',
headers: { 'Content-Type': 'application/json' },
body: JSON.stringify({ enabled, cpuThreshold, memoryThreshold, cooldownMinutes, autoRestart })
});
const data = await res.json();
btn.textContent = data.success ? '✅ Saved' : '⚠️ Failed';
setTimeout(() => { btn.textContent = 'Save'; }, 2000);
} catch (e) {
btn.textContent = '❌ Error';
setTimeout(() => { btn.textContent = 'Save'; }, 2000);
}
// Check premium status for config section visibility
let isPremium = false;
try {
const resp = await fetch('/api/v1/license/feature/resource-alerts');
const ld = await resp.json();
isPremium = ld.available;
} catch (_) { isPremium = false; }
// Fetch alert history
let alertHistory = [];
try {
const hr = await fetch('/api/v1/monitoring/alerts?limit=50');
const hd = await hr.json();
if (hd.success) alertHistory = hd.history || [];
} catch (_) {}
// Fetch all alert configs
let allConfigs = {};
try {
const cr = await fetch('/api/v1/monitoring/alerts/config');
const cd = await cr.json();
if (cd.success) allConfigs = cd.configs || {};
} catch (_) {}
const containers = Object.entries(data);
const containerRows = containers.map(([id, info]) => {
const cfg = allConfigs[id] || { cpuThreshold: 80, memoryThreshold: 90, diskIOThreshold: 50, autoRestart: false, enabled: false };
return `
<tr data-container="${id}">
<td style="font-weight: 600; padding: 8px;">${info.name || id}</td>
<td style="padding: 4px 8px;"><input type="number" class="alert-cpu" value="${cfg.cpuThreshold ?? 80}" min="0" max="100" style="width: 60px; font-size: 0.8rem; padding: 2px 4px;" ${isPremium ? '' : 'disabled'} /></td>
<td style="padding: 4px 8px;"><input type="number" class="alert-mem" value="${cfg.memoryThreshold ?? 90}" min="0" max="100" style="width: 60px; font-size: 0.8rem; padding: 2px 4px;" ${isPremium ? '' : 'disabled'} /></td>
<td style="padding: 4px 8px;"><input type="number" class="alert-disk" value="${cfg.diskIOThreshold ?? 50}" min="0" max="1000" style="width: 70px; font-size: 0.8rem; padding: 2px 4px;" ${isPremium ? '' : 'disabled'} /></td>
<td style="padding: 4px 8px;"><input type="checkbox" class="alert-autorestart" ${cfg.autoRestart ? 'checked' : ''} ${isPremium ? '' : 'disabled'} /></td>
<td style="padding: 4px 8px;">
<button class="alert-test-btn btn-xs" data-container="${id}" data-name="${info.name || id}" style="padding: 2px 8px; font-size: 0.75rem; background: var(--card-base); border: 1px solid var(--border); border-radius: 4px; cursor: pointer;">Test</button>
</td>
</tr>
`;
}).join('');
const historyRows = alertHistory.map(entry => {
const time = new Date(entry.timestamp).toLocaleString();
const notifiedMark = entry.notified ? '✓' : '—';
return `
<tr>
<td style="padding: 6px 8px; font-size: 0.8rem; color: var(--muted);">${time}</td>
<td style="padding: 6px 8px; font-weight: 500;">${entry.containerName || entry.containerId}</td>
<td style="padding: 6px 8px; text-transform: capitalize;">${entry.metric || entry.type}</td>
<td style="padding: 6px 8px;">${typeof entry.value === 'number' ? entry.value.toFixed(1) : entry.value}${entry.metric === 'disk' ? ' MB/s' : '%'}</td>
<td style="padding: 6px 8px; text-align: center;">${notifiedMark}</td>
<td style="padding: 6px 8px; font-size: 0.75rem; color: ${entry.autoRestartTriggered ? '#f39c12' : 'var(--muted)'};">${entry.autoRestartTriggered ? '↻' : ''}</td>
</tr>
`;
}).join('');
const configSection = isPremium ? `
<div style="margin-bottom: 20px;">
<div style="display: flex; align-items: center; justify-content: space-between; margin-bottom: 10px;">
<h4 style="margin: 0; font-size: 0.9rem;"> Alert Configuration</h4>
<a href="#" id="go-to-notifications" style="font-size: 0.8rem; color: var(--accent); text-decoration: none;">Configure notifications </a>
</div>
<div style="overflow-x: auto;">
<table style="width: 100%; border-collapse: collapse; font-size: 0.85rem;">
<thead>
<tr style="border-bottom: 1px solid var(--border);">
<th style="text-align: left; padding: 6px 8px; color: var(--muted);">Container</th>
<th style="text-align: left; padding: 6px 8px; color: var(--muted);">CPU %</th>
<th style="text-align: left; padding: 6px 8px; color: var(--muted);">Mem %</th>
<th style="text-align: left; padding: 6px 8px; color: var(--muted);">Disk I/O MB/s</th>
<th style="text-align: center; padding: 6px 8px; color: var(--muted);">Auto-Restart</th>
<th style="padding: 6px 8px;"></th>
</tr>
</thead>
<tbody>${containerRows}</tbody>
</table>
</div>
<div style="margin-top: 12px; display: flex; justify-content: flex-end;">
<button id="save-all-alerts" style="padding: 6px 16px; font-size: 0.85rem; background: var(--accent); color: var(--base); border: none; border-radius: 4px; cursor: pointer; font-weight: 600;">Save All</button>
</div>
</div>
` : `
<div style="margin-bottom: 20px; padding: 12px; background: rgba(241,196,15,0.1); border: 1px solid rgba(241,196,15,0.3); border-radius: 8px; text-align: center;">
<span style="color: #f1c40f; font-weight: 600; font-size: 0.85rem;"> Premium Feature</span>
<p style="margin: 6px 0 0; font-size: 0.75rem; color: var(--muted);">Upgrade to configure resource alert thresholds per container.</p>
<button id="upgrade-for-alerts" style="margin-top: 8px; padding: 4px 12px; font-size: 0.75rem; background: #f1c40f; color: #000; border: none; border-radius: 4px; cursor: pointer; font-weight: 600;">Upgrade Now</button>
</div>
`;
alertsContainer.innerHTML = `
${configSection}
<div>
<h4 style="margin: 0 0 10px; font-size: 0.9rem;">📋 Recent Alerts</h4>
${historyRows ? `
<div style="overflow-x: auto;">
<table style="width: 100%; border-collapse: collapse; font-size: 0.8rem;">
<thead>
<tr style="border-bottom: 1px solid var(--border);">
<th style="text-align: left; padding: 6px 8px; color: var(--muted);">Time</th>
<th style="text-align: left; padding: 6px 8px; color: var(--muted);">Container</th>
<th style="text-align: left; padding: 6px 8px; color: var(--muted);">Metric</th>
<th style="text-align: left; padding: 6px 8px; color: var(--muted);">Value</th>
<th style="text-align: center; padding: 6px 8px; color: var(--muted);">?</th>
<th style="padding: 6px 8px;"></th>
</tr>
</thead>
<tbody>${historyRows}</tbody>
</table>
</div>
` : '<div style="color: var(--muted); text-align: center; padding: 20px;">No alerts recorded yet.</div>'}
</div>
`;
// Wire up save-all button
document.getElementById('save-all-alerts')?.addEventListener('click', async () => {
const configs = {};
document.querySelectorAll('#stats-alerts-container tr[data-container]').forEach(row => {
const cId = row.dataset.container;
configs[cId] = {
cpuThreshold: parseInt(row.querySelector('.alert-cpu')?.value) || 80,
memoryThreshold: parseInt(row.querySelector('.alert-mem')?.value) || 90,
diskIOThreshold: parseInt(row.querySelector('.alert-disk')?.value) || 50,
autoRestart: !!row.querySelector('.alert-autorestart')?.checked,
enabled: true
};
});
try {
const res = await secureFetch('/api/v1/monitoring/alerts/config', {
method: 'POST',
headers: { 'Content-Type': 'application/json' },
body: JSON.stringify({ configs })
});
const d = await res.json();
const btn = document.getElementById('save-all-alerts');
btn.textContent = d.success ? '✅ Saved' : '❌ Failed';
setTimeout(() => { btn.textContent = 'Save All'; }, 2000);
} catch (e) {
const btn = document.getElementById('save-all-alerts');
btn.textContent = '❌ Error';
setTimeout(() => { btn.textContent = 'Save All'; }, 2000);
}
});
// Wire up notification settings link
document.getElementById('go-to-notifications')?.addEventListener('click', (e) => {
e.preventDefault();
modal.classList.remove('show');
stopAutoRefresh();
document.getElementById('manage-notifications')?.click();
});
// Wire up test buttons
document.querySelectorAll('.alert-test-btn').forEach(btn => {
btn.addEventListener('click', async () => {
const orig = btn.textContent;
btn.textContent = '...';
try {
await secureFetch(`/api/v1/monitoring/alerts/${btn.dataset.container}/test`, { method: 'POST' });
btn.textContent = '✅';
showNotification('Test alert sent for ' + btn.dataset.name, 'success', 3000);
} catch (e) {
btn.textContent = '❌';
}
setTimeout(() => { btn.textContent = orig; }, 2000);
});
});
// Wire up upgrade button
document.getElementById('upgrade-for-alerts')?.addEventListener('click', () => {
modal.classList.remove('show');
stopAutoRefresh();
if (typeof openLicenseModal === 'function') openLicenseModal();
});
}

Some files were not shown because too many files have changed in this diff Show More