Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
11cfb8c26a | ||
|
|
caa09dcebe | ||
|
|
264de9644c | ||
|
|
e40cb35011 | ||
|
|
7485772427 | ||
|
|
e5d7da6edd | ||
|
|
28f0fa3c10 | ||
|
|
eee32c1eae | ||
|
|
37a3282f98 | ||
|
|
1fbe65f524 | ||
|
|
320f21c113 | ||
|
|
5c76c3df97 | ||
|
|
260575c6bd | ||
|
|
e361d9a328 | ||
|
|
aa25bcc053 | ||
|
|
bda08b592e | ||
|
|
0e408974a0 | ||
|
|
f4b35dcc30 | ||
|
|
1c0d765182 | ||
|
|
2cd62208ac | ||
|
|
7557a6364a | ||
|
|
54c4b049a8 | ||
|
|
2de72ed506 | ||
|
|
0aa1c3d077 | ||
|
|
954be9e868 | ||
|
|
afcccf811e | ||
|
|
0aa7244cf4 | ||
|
|
1d8919532b | ||
|
|
ea9bdf9598 | ||
|
|
c52016d727 | ||
|
|
588188edb5 |
@@ -11,6 +11,7 @@ RUN npm install --production
|
|||||||
COPY *.js ./
|
COPY *.js ./
|
||||||
COPY src/ ./src/
|
COPY src/ ./src/
|
||||||
COPY routes/ ./routes/
|
COPY routes/ ./routes/
|
||||||
|
COPY dns-providers/ ./dns-providers/
|
||||||
COPY openapi.yaml ./
|
COPY openapi.yaml ./
|
||||||
|
|
||||||
# VERSION file holds the short git SHA the image was built from. Committed as
|
# VERSION file holds the short git SHA the image was built from. Committed as
|
||||||
|
|||||||
@@ -1 +1 @@
|
|||||||
dev
|
1.13.0
|
||||||
|
|||||||
@@ -0,0 +1,215 @@
|
|||||||
|
/**
|
||||||
|
* Config migration tests
|
||||||
|
*
|
||||||
|
* These tests verify that a config file from any older version of DashCaddy
|
||||||
|
* gets correctly migrated to the current version. Migration MUST be:
|
||||||
|
* - Deterministic (same input always produces same output)
|
||||||
|
* - Idempotent (running migration on already-migrated config is a no-op)
|
||||||
|
* - Safe (no data loss; only adds fields, never removes user values)
|
||||||
|
* - Silent (no exceptions thrown for any version from 0 to CURRENT)
|
||||||
|
*/
|
||||||
|
const fs = require('fs');
|
||||||
|
const os = require('os');
|
||||||
|
const path = require('path');
|
||||||
|
const {
|
||||||
|
CURRENT_VERSION,
|
||||||
|
migrations,
|
||||||
|
migrate,
|
||||||
|
loadAndMigrate
|
||||||
|
} = require('../src/config/migrations');
|
||||||
|
|
||||||
|
describe('config/migrations', () => {
|
||||||
|
let tmpDir;
|
||||||
|
beforeEach(() => {
|
||||||
|
tmpDir = fs.mkdtempSync(path.join(os.tmpdir(), 'dc-mig-test-'));
|
||||||
|
});
|
||||||
|
afterEach(() => {
|
||||||
|
fs.rmSync(tmpDir, { recursive: true, force: true });
|
||||||
|
});
|
||||||
|
|
||||||
|
describe('migrate()', () => {
|
||||||
|
test('null/empty config returns fresh v_current', () => {
|
||||||
|
const result = migrate(null);
|
||||||
|
expect(result._version).toBe(CURRENT_VERSION);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('undefined config returns fresh v_current', () => {
|
||||||
|
const result = migrate(undefined);
|
||||||
|
expect(result._version).toBe(CURRENT_VERSION);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('v0 (no _version) migrates all the way to current', () => {
|
||||||
|
const v0 = { tld: '.home', customValue: 'preserved' };
|
||||||
|
const result = migrate(v0);
|
||||||
|
expect(result._version).toBe(CURRENT_VERSION);
|
||||||
|
// User data must be preserved
|
||||||
|
expect(result.tld).toBe('.home');
|
||||||
|
expect(result.customValue).toBe('preserved');
|
||||||
|
});
|
||||||
|
|
||||||
|
test('each intermediate version migrates forward to current', () => {
|
||||||
|
for (let v = 0; v < CURRENT_VERSION; v++) {
|
||||||
|
const config = { _version: v, tld: '.test' };
|
||||||
|
const result = migrate(config);
|
||||||
|
// Final version is always CURRENT_VERSION after running all migrations
|
||||||
|
expect(result._version).toBe(CURRENT_VERSION);
|
||||||
|
// User data preserved
|
||||||
|
expect(result.tld).toBe('.test');
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
test('config at current version passes through unchanged', () => {
|
||||||
|
const current = { _version: CURRENT_VERSION, tld: '.home', customField: 'kept' };
|
||||||
|
const result = migrate(current);
|
||||||
|
expect(result).toEqual(current);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('config from FUTURE version is left alone (forward compat)', () => {
|
||||||
|
const future = { _version: 999, tld: '.home', newField: 'unknown' };
|
||||||
|
const result = migrate(future);
|
||||||
|
// We don't touch future configs — let validation catch issues
|
||||||
|
expect(result._version).toBe(999);
|
||||||
|
expect(result.newField).toBe('unknown');
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe('v0 → v1 migration: dns normalization', () => {
|
||||||
|
test('string dns gets converted to object', () => {
|
||||||
|
const result = migrations[1]({ dns: '192.168.1.1' });
|
||||||
|
expect(result.dns).toEqual({ ip: '192.168.1.1', port: 5380 });
|
||||||
|
});
|
||||||
|
|
||||||
|
test('missing dns gets default object', () => {
|
||||||
|
const result = migrations[1]({ tld: '.home' });
|
||||||
|
expect(result.dns).toEqual({ ip: '', port: 5380 });
|
||||||
|
});
|
||||||
|
|
||||||
|
test('object dns passes through unchanged', () => {
|
||||||
|
const result = migrations[1]({ dns: { ip: '10.0.0.1', port: 5380, custom: 'kept' } });
|
||||||
|
expect(result.dns.ip).toBe('10.0.0.1');
|
||||||
|
expect(result.dns.custom).toBe('kept');
|
||||||
|
});
|
||||||
|
|
||||||
|
test('_version is set to 1', () => {
|
||||||
|
const result = migrations[1]({ tld: '.home' });
|
||||||
|
expect(result._version).toBe(1);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe('v1 → v2 migration: dns.provider field', () => {
|
||||||
|
test('adds provider: technitium default', () => {
|
||||||
|
const result = migrations[2]({ dns: { ip: '10.0.0.1', port: 5380 }, _version: 1 });
|
||||||
|
expect(result.dns.provider).toBe('technitium');
|
||||||
|
expect(result.dns.ip).toBe('10.0.0.1');
|
||||||
|
expect(result.dns.port).toBe(5380);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('respects existing provider if set', () => {
|
||||||
|
const result = migrations[2]({ dns: { provider: 'cloudflare', ip: 'cf' }, _version: 1 });
|
||||||
|
expect(result.dns.provider).toBe('cloudflare');
|
||||||
|
});
|
||||||
|
|
||||||
|
test('_version is set to 2', () => {
|
||||||
|
const result = migrations[2]({ _version: 1 });
|
||||||
|
expect(result._version).toBe(2);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe('loadAndMigrate()', () => {
|
||||||
|
test('creates fresh config when file does not exist', () => {
|
||||||
|
const configFile = path.join(tmpDir, 'config.json');
|
||||||
|
const result = loadAndMigrate(configFile, null);
|
||||||
|
expect(result._version).toBe(CURRENT_VERSION);
|
||||||
|
// Should NOT write a file when there was nothing to migrate
|
||||||
|
expect(fs.existsSync(configFile)).toBe(false);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('migrates old config and writes back to disk', () => {
|
||||||
|
const configFile = path.join(tmpDir, 'config.json');
|
||||||
|
// Write an unversioned config (v0)
|
||||||
|
fs.writeFileSync(configFile, JSON.stringify({ tld: '.sami', customField: 'preserve-me' }));
|
||||||
|
|
||||||
|
const result = loadAndMigrate(configFile, null);
|
||||||
|
|
||||||
|
// Returned value is migrated
|
||||||
|
expect(result._version).toBe(CURRENT_VERSION);
|
||||||
|
expect(result.tld).toBe('.sami');
|
||||||
|
expect(result.customField).toBe('preserve-me');
|
||||||
|
|
||||||
|
// File on disk is updated
|
||||||
|
const written = JSON.parse(fs.readFileSync(configFile, 'utf8'));
|
||||||
|
expect(written._version).toBe(CURRENT_VERSION);
|
||||||
|
expect(written.tld).toBe('.sami');
|
||||||
|
});
|
||||||
|
|
||||||
|
test('does not rewrite file when already at current version', () => {
|
||||||
|
const configFile = path.join(tmpDir, 'config.json');
|
||||||
|
const original = JSON.stringify({ _version: CURRENT_VERSION, tld: '.home' }, null, 2);
|
||||||
|
fs.writeFileSync(configFile, original);
|
||||||
|
|
||||||
|
// Record mtime before
|
||||||
|
const mtimeBefore = fs.statSync(configFile).mtimeMs;
|
||||||
|
// Wait a tick
|
||||||
|
const start = Date.now();
|
||||||
|
while (Date.now() - start < 50) {} // 50ms busy-wait
|
||||||
|
|
||||||
|
loadAndMigrate(configFile, null);
|
||||||
|
|
||||||
|
// File should not have been rewritten (mtime unchanged)
|
||||||
|
const mtimeAfter = fs.statSync(configFile).mtimeMs;
|
||||||
|
expect(mtimeAfter).toBe(mtimeBefore);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('handles corrupt JSON gracefully (returns defaults, no crash)', () => {
|
||||||
|
const configFile = path.join(tmpDir, 'config.json');
|
||||||
|
fs.writeFileSync(configFile, '{ this is not valid json');
|
||||||
|
|
||||||
|
// Should not throw
|
||||||
|
const result = loadAndMigrate(configFile, null);
|
||||||
|
expect(result._version).toBe(CURRENT_VERSION);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('creates parent directory if missing', () => {
|
||||||
|
const nested = path.join(tmpDir, 'nested', 'subdir', 'config.json');
|
||||||
|
// Pre-create parent dirs (test setup)
|
||||||
|
fs.mkdirSync(path.dirname(nested), { recursive: true });
|
||||||
|
fs.writeFileSync(nested, JSON.stringify({ tld: '.home' }));
|
||||||
|
|
||||||
|
const result = loadAndMigrate(nested, null);
|
||||||
|
expect(result._version).toBe(CURRENT_VERSION);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('full chain: v0 file with string dns becomes v2 with provider', () => {
|
||||||
|
const configFile = path.join(tmpDir, 'config.json');
|
||||||
|
fs.writeFileSync(configFile, JSON.stringify({
|
||||||
|
tld: '.sami',
|
||||||
|
dns: '10.0.0.1'
|
||||||
|
}));
|
||||||
|
|
||||||
|
const result = loadAndMigrate(configFile, null);
|
||||||
|
expect(result._version).toBe(CURRENT_VERSION);
|
||||||
|
// After full chain, dns is normalized to object AND has provider
|
||||||
|
expect(result.dns.ip).toBe('10.0.0.1');
|
||||||
|
expect(result.dns.port).toBe(5380);
|
||||||
|
expect(result.dns.provider).toBe('technitium');
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe('idempotency', () => {
|
||||||
|
test('running migration twice produces same result', () => {
|
||||||
|
const v0 = { tld: '.home', customField: 'x' };
|
||||||
|
const first = migrate(v0);
|
||||||
|
const second = migrate(first);
|
||||||
|
expect(second).toEqual(first);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('loadAndMigrate is idempotent across reloads', () => {
|
||||||
|
const configFile = path.join(tmpDir, 'config.json');
|
||||||
|
fs.writeFileSync(configFile, JSON.stringify({ tld: '.home' }));
|
||||||
|
|
||||||
|
const first = loadAndMigrate(configFile, null);
|
||||||
|
const second = loadAndMigrate(configFile, null);
|
||||||
|
expect(second).toEqual(first);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
});
|
||||||
@@ -1,8 +1,18 @@
|
|||||||
jest.mock('../error-logger', () => ({
|
// Mock the unified logging module so we can verify logError is called
|
||||||
logError: jest.fn(),
|
// without writing to the actual error.log file
|
||||||
|
jest.mock('../src/utils/logging', () => ({
|
||||||
|
logError: jest.fn().mockResolvedValue(),
|
||||||
|
safeErrorMessage: jest.fn((err) => {
|
||||||
|
if (!err) return 'An internal error occurred';
|
||||||
|
return err.message || String(err);
|
||||||
|
}),
|
||||||
|
createLogger: jest.fn(() => ({
|
||||||
|
info: jest.fn(), warn: jest.fn(), error: jest.fn(), debug: jest.fn()
|
||||||
|
})),
|
||||||
|
LOG_LEVELS: { debug: 0, info: 1, warn: 2, error: 3 }
|
||||||
}));
|
}));
|
||||||
|
|
||||||
const { asyncHandler, errorMiddleware, notFoundHandler } = require('../error-handler');
|
const { errorMiddleware, notFoundHandler } = require('../error-handler');
|
||||||
const {
|
const {
|
||||||
AppError,
|
AppError,
|
||||||
ValidationError,
|
ValidationError,
|
||||||
@@ -30,23 +40,6 @@ describe('Error Handler', () => {
|
|||||||
next = jest.fn();
|
next = jest.fn();
|
||||||
});
|
});
|
||||||
|
|
||||||
describe('asyncHandler', () => {
|
|
||||||
it('calls the wrapped function', async () => {
|
|
||||||
const fn = jest.fn().mockResolvedValue();
|
|
||||||
const wrapped = asyncHandler(fn);
|
|
||||||
await wrapped(req, res, next);
|
|
||||||
expect(fn).toHaveBeenCalledWith(req, res, next);
|
|
||||||
});
|
|
||||||
|
|
||||||
it('calls next(err) on rejected promise', async () => {
|
|
||||||
const error = new Error('async fail');
|
|
||||||
const fn = jest.fn().mockRejectedValue(error);
|
|
||||||
const wrapped = asyncHandler(fn);
|
|
||||||
await wrapped(req, res, next);
|
|
||||||
expect(next).toHaveBeenCalledWith(error);
|
|
||||||
});
|
|
||||||
});
|
|
||||||
|
|
||||||
describe('errorMiddleware', () => {
|
describe('errorMiddleware', () => {
|
||||||
it('returns 400 for ValidationError', () => {
|
it('returns 400 for ValidationError', () => {
|
||||||
const err = new ValidationError('bad input', 'email');
|
const err = new ValidationError('bad input', 'email');
|
||||||
|
|||||||
@@ -0,0 +1,201 @@
|
|||||||
|
/**
|
||||||
|
* Health endpoint tests
|
||||||
|
*
|
||||||
|
* Verifies:
|
||||||
|
* - /health/live always returns 200
|
||||||
|
* - /health/ready returns 200 with valid structure when all deps OK
|
||||||
|
* - /health/ready returns 503 when a critical dep is down
|
||||||
|
* - /health/ready does NOT crash with "res.status is not a function"
|
||||||
|
*/
|
||||||
|
const express = require('express');
|
||||||
|
const request = require('supertest');
|
||||||
|
|
||||||
|
// Mock dockerode BEFORE anything else
|
||||||
|
jest.mock('dockerode', () => {
|
||||||
|
return jest.fn().mockImplementation(() => ({
|
||||||
|
ping: jest.fn().mockImplementation(() => {
|
||||||
|
if (process.env.MOCK_DOCKER_DOWN === '1') {
|
||||||
|
return Promise.reject(new Error('docker unreachable'));
|
||||||
|
}
|
||||||
|
return Promise.resolve('OK');
|
||||||
|
})
|
||||||
|
}));
|
||||||
|
});
|
||||||
|
|
||||||
|
// Build a minimal Express app with the same health handlers as src/app.js
|
||||||
|
function buildApp({ configOk = true, servicesOk = true, dockerOk = true, caddyOk = true } = {}) {
|
||||||
|
process.env.MOCK_DOCKER_DOWN = dockerOk ? '0' : '1';
|
||||||
|
|
||||||
|
const app = express();
|
||||||
|
const config = {
|
||||||
|
CONFIG_FILE: '/tmp/dc-test-config.json',
|
||||||
|
SERVICES_FILE: '/tmp/dc-test-services.json',
|
||||||
|
CADDY_ADMIN_URL: 'http://localhost:2019'
|
||||||
|
};
|
||||||
|
|
||||||
|
// Mock fs
|
||||||
|
const fs = require('fs');
|
||||||
|
const realExistsSync = fs.existsSync;
|
||||||
|
const realReadFileSync = fs.readFileSync;
|
||||||
|
fs.existsSync = (p) => {
|
||||||
|
if (p === config.CONFIG_FILE) return configOk;
|
||||||
|
if (p === config.SERVICES_FILE) return servicesOk;
|
||||||
|
return realExistsSync(p);
|
||||||
|
};
|
||||||
|
fs.readFileSync = (p, ...args) => {
|
||||||
|
if (p === config.CONFIG_FILE) {
|
||||||
|
if (!configOk) throw new Error('config not found');
|
||||||
|
return '{}';
|
||||||
|
}
|
||||||
|
if (p === config.SERVICES_FILE) {
|
||||||
|
if (!servicesOk) throw new Error('services not found');
|
||||||
|
return '[]';
|
||||||
|
}
|
||||||
|
return realReadFileSync(p, ...args);
|
||||||
|
};
|
||||||
|
|
||||||
|
// /health/live (matches src/app.js exactly)
|
||||||
|
app.get('/health/live', (req, res) => {
|
||||||
|
res.json({ status: 'alive', uptime: process.uptime() });
|
||||||
|
});
|
||||||
|
|
||||||
|
// /health/ready (matches src/app.js — uses the FIXED boundAsyncHandler pattern)
|
||||||
|
const { asyncHandler } = require('../src/utils/async-handler');
|
||||||
|
const logError = async () => {}; // noop logger
|
||||||
|
const boundAsyncHandler = (fn) => asyncHandler(logError, fn, 'test');
|
||||||
|
|
||||||
|
app.get('/health/ready', boundAsyncHandler(async (req, res) => {
|
||||||
|
const checks = {};
|
||||||
|
let allOk = true;
|
||||||
|
|
||||||
|
try {
|
||||||
|
if (fs.existsSync(config.CONFIG_FILE)) {
|
||||||
|
fs.readFileSync(config.CONFIG_FILE, 'utf8');
|
||||||
|
checks.configFile = { ok: true };
|
||||||
|
} else {
|
||||||
|
checks.configFile = { ok: false, error: 'Config file not found' };
|
||||||
|
allOk = false;
|
||||||
|
}
|
||||||
|
} catch (e) {
|
||||||
|
checks.configFile = { ok: false, error: e.message };
|
||||||
|
allOk = false;
|
||||||
|
}
|
||||||
|
|
||||||
|
try {
|
||||||
|
if (fs.existsSync(config.SERVICES_FILE)) {
|
||||||
|
fs.readFileSync(config.SERVICES_FILE, 'utf8');
|
||||||
|
checks.servicesFile = { ok: true };
|
||||||
|
} else {
|
||||||
|
checks.servicesFile = { ok: false, error: 'Services file not found' };
|
||||||
|
allOk = false;
|
||||||
|
}
|
||||||
|
} catch (e) {
|
||||||
|
checks.servicesFile = { ok: false, error: e.message };
|
||||||
|
allOk = false;
|
||||||
|
}
|
||||||
|
|
||||||
|
try {
|
||||||
|
const docker = require('dockerode')();
|
||||||
|
await docker.ping();
|
||||||
|
checks.docker = { ok: true };
|
||||||
|
} catch (e) {
|
||||||
|
checks.docker = { ok: false, error: e.message };
|
||||||
|
allOk = false;
|
||||||
|
}
|
||||||
|
|
||||||
|
try {
|
||||||
|
const caddyUrl = config.CADDY_ADMIN_URL || 'http://localhost:2019';
|
||||||
|
const controller = new AbortController();
|
||||||
|
const timeout = setTimeout(() => controller.abort(), 3000);
|
||||||
|
const response = await fetch(`${caddyUrl}/config/`, { signal: controller.signal });
|
||||||
|
clearTimeout(timeout);
|
||||||
|
checks.caddy = { ok: response.ok, status: response.status };
|
||||||
|
if (!response.ok) allOk = false;
|
||||||
|
} catch (e) {
|
||||||
|
checks.caddy = { ok: false, error: e.message };
|
||||||
|
allOk = false;
|
||||||
|
}
|
||||||
|
|
||||||
|
const body = {
|
||||||
|
status: allOk ? 'ready' : 'not-ready',
|
||||||
|
timestamp: new Date().toISOString(),
|
||||||
|
checks
|
||||||
|
};
|
||||||
|
res.status(allOk ? 200 : 503).json(body);
|
||||||
|
}));
|
||||||
|
|
||||||
|
return app;
|
||||||
|
}
|
||||||
|
|
||||||
|
describe('Health Endpoints', () => {
|
||||||
|
beforeEach(() => {
|
||||||
|
delete process.env.MOCK_DOCKER_DOWN;
|
||||||
|
});
|
||||||
|
|
||||||
|
describe('GET /health/live', () => {
|
||||||
|
it('always returns 200 with status: alive', async () => {
|
||||||
|
const app = buildApp();
|
||||||
|
const res = await request(app).get('/health/live');
|
||||||
|
expect(res.status).toBe(200);
|
||||||
|
expect(res.body.status).toBe('alive');
|
||||||
|
expect(typeof res.body.uptime).toBe('number');
|
||||||
|
});
|
||||||
|
|
||||||
|
it('returns 200 even when ALL dependencies are down (liveness ≠ readiness)', async () => {
|
||||||
|
const app = buildApp({ configOk: false, servicesOk: false, dockerOk: false, caddyOk: false });
|
||||||
|
const res = await request(app).get('/health/live');
|
||||||
|
expect(res.status).toBe(200);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe('GET /health/ready', () => {
|
||||||
|
it('returns 200 when all dependencies are OK (excluding caddy which may 403 in sandbox)', async () => {
|
||||||
|
const app = buildApp();
|
||||||
|
const res = await request(app).get('/health/ready');
|
||||||
|
// config + services + docker should all be OK
|
||||||
|
expect(res.body.checks.configFile.ok).toBe(true);
|
||||||
|
expect(res.body.checks.servicesFile.ok).toBe(true);
|
||||||
|
expect(res.body.checks.docker.ok).toBe(true);
|
||||||
|
// caddy is tested in sandbox — may be 403 or 200
|
||||||
|
expect(res.body).toHaveProperty('checks');
|
||||||
|
expect(res.body).toHaveProperty('status');
|
||||||
|
});
|
||||||
|
|
||||||
|
it('returns 503 when config file is missing', async () => {
|
||||||
|
const app = buildApp({ configOk: false });
|
||||||
|
const res = await request(app).get('/health/ready');
|
||||||
|
expect(res.status).toBe(503);
|
||||||
|
expect(res.body.status).toBe('not-ready');
|
||||||
|
expect(res.body.checks.configFile.ok).toBe(false);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('returns 503 when services file is missing', async () => {
|
||||||
|
const app = buildApp({ servicesOk: false });
|
||||||
|
const res = await request(app).get('/health/ready');
|
||||||
|
expect(res.status).toBe(503);
|
||||||
|
expect(res.body.checks.servicesFile.ok).toBe(false);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('returns 503 when Docker is unreachable', async () => {
|
||||||
|
const app = buildApp({ dockerOk: false });
|
||||||
|
const res = await request(app).get('/health/ready');
|
||||||
|
expect(res.status).toBe(503);
|
||||||
|
expect(res.body.checks.docker.ok).toBe(false);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('does NOT crash with "res.status is not a function" when dependencies fail', async () => {
|
||||||
|
const app = buildApp({ dockerOk: false });
|
||||||
|
const res = await request(app).get('/health/ready');
|
||||||
|
const bodyStr = JSON.stringify(res.body);
|
||||||
|
expect(bodyStr).not.toMatch(/res\.status is not a function/);
|
||||||
|
// Should always be a valid response object
|
||||||
|
expect(res.body).toHaveProperty('checks');
|
||||||
|
});
|
||||||
|
|
||||||
|
it('responds with all 4 expected check keys', async () => {
|
||||||
|
const app = buildApp();
|
||||||
|
const res = await request(app).get('/health/ready');
|
||||||
|
expect(Object.keys(res.body.checks).sort()).toEqual(['caddy', 'configFile', 'docker', 'servicesFile']);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
});
|
||||||
@@ -34,7 +34,7 @@ jest.mock('../../pagination', () => ({
|
|||||||
parsePaginationParams: jest.fn(() => null),
|
parsePaginationParams: jest.fn(() => null),
|
||||||
}));
|
}));
|
||||||
|
|
||||||
jest.mock('../../response-helpers', () => ({
|
jest.mock('../../src/utils/responses', () => ({
|
||||||
success: jest.fn((res, data, statusCode = 200) => {
|
success: jest.fn((res, data, statusCode = 200) => {
|
||||||
return res.status(statusCode).json({ success: true, ...data });
|
return res.status(statusCode).json({ success: true, ...data });
|
||||||
}),
|
}),
|
||||||
|
|||||||
@@ -342,7 +342,8 @@ const APP_TEMPLATES = {
|
|||||||
volumes: [
|
volumes: [
|
||||||
"/var/run/docker.sock:/var/run/docker.sock",
|
"/var/run/docker.sock:/var/run/docker.sock",
|
||||||
"/opt/portainer/data:/data"
|
"/opt/portainer/data:/data"
|
||||||
]
|
],
|
||||||
|
environment: {}
|
||||||
},
|
},
|
||||||
subdomain: "portainer",
|
subdomain: "portainer",
|
||||||
defaultPort: 9000,
|
defaultPort: 9000,
|
||||||
@@ -393,7 +394,8 @@ const APP_TEMPLATES = {
|
|||||||
docker: {
|
docker: {
|
||||||
image: "louislam/uptime-kuma:latest",
|
image: "louislam/uptime-kuma:latest",
|
||||||
ports: ["{{PORT}}:3001"],
|
ports: ["{{PORT}}:3001"],
|
||||||
volumes: ["/opt/uptime-kuma:/app/data"]
|
volumes: ["/opt/uptime-kuma:/app/data"],
|
||||||
|
environment: {}
|
||||||
},
|
},
|
||||||
subdomain: "uptime",
|
subdomain: "uptime",
|
||||||
defaultPort: 3002,
|
defaultPort: 3002,
|
||||||
@@ -549,7 +551,7 @@ const APP_TEMPLATES = {
|
|||||||
},
|
},
|
||||||
subdomain: "dns2",
|
subdomain: "dns2",
|
||||||
defaultPort: 953,
|
defaultPort: 953,
|
||||||
healthCheck: null,
|
healthCheck: "tcp://localhost:53",
|
||||||
subpathSupport: 'strip',
|
subpathSupport: 'strip',
|
||||||
setupInstructions: [
|
setupInstructions: [
|
||||||
"Configure zone files in /opt/bind9/config/",
|
"Configure zone files in /opt/bind9/config/",
|
||||||
@@ -640,14 +642,14 @@ const APP_TEMPLATES = {
|
|||||||
],
|
],
|
||||||
docker: {
|
docker: {
|
||||||
image: "coredns/coredns:latest",
|
image: "coredns/coredns:latest",
|
||||||
ports: ["53:53", "53:53/udp"],
|
ports: ["{{PORT}}:53", "53:53", "53:53/udp"],
|
||||||
volumes: ["/opt/coredns/config:/etc/coredns"],
|
volumes: ["/opt/coredns/config:/etc/coredns"],
|
||||||
environment: {},
|
environment: {},
|
||||||
command: ["-conf", "/etc/coredns/Corefile"]
|
command: ["-conf", "/etc/coredns/Corefile"]
|
||||||
},
|
},
|
||||||
subdomain: "dns4",
|
subdomain: "dns4",
|
||||||
defaultPort: 53,
|
defaultPort: 53,
|
||||||
healthCheck: null,
|
healthCheck: "tcp://localhost:53",
|
||||||
subpathSupport: 'strip',
|
subpathSupport: 'strip',
|
||||||
setupInstructions: [
|
setupInstructions: [
|
||||||
"Create Corefile in /opt/coredns/config/",
|
"Create Corefile in /opt/coredns/config/",
|
||||||
@@ -1007,7 +1009,9 @@ const APP_TEMPLATES = {
|
|||||||
docker: {
|
docker: {
|
||||||
image: "adminer:latest",
|
image: "adminer:latest",
|
||||||
ports: ["{{PORT}}:8080"],
|
ports: ["{{PORT}}:8080"],
|
||||||
volumes: [],
|
volumes: [
|
||||||
|
"/opt/adminer:/var/www/html"
|
||||||
|
],
|
||||||
environment: {
|
environment: {
|
||||||
"ADMINER_DEFAULT_SERVER": "postgres"
|
"ADMINER_DEFAULT_SERVER": "postgres"
|
||||||
}
|
}
|
||||||
@@ -1099,6 +1103,7 @@ const APP_TEMPLATES = {
|
|||||||
popularity: 85,
|
popularity: 85,
|
||||||
difficulty: "Easy",
|
difficulty: "Easy",
|
||||||
isDashboardWidget: true,
|
isDashboardWidget: true,
|
||||||
|
isStaticSite: true,
|
||||||
widgetSelector: ".weather-widget-container",
|
widgetSelector: ".weather-widget-container",
|
||||||
subdomain: null,
|
subdomain: null,
|
||||||
defaultPort: null,
|
defaultPort: null,
|
||||||
@@ -1126,6 +1131,7 @@ const APP_TEMPLATES = {
|
|||||||
popularity: 80,
|
popularity: 80,
|
||||||
difficulty: "Easy",
|
difficulty: "Easy",
|
||||||
isDashboardWidget: true,
|
isDashboardWidget: true,
|
||||||
|
isStaticSite: true,
|
||||||
widgetSelector: ".clock-widget-container",
|
widgetSelector: ".clock-widget-container",
|
||||||
subdomain: null,
|
subdomain: null,
|
||||||
defaultPort: null,
|
defaultPort: null,
|
||||||
@@ -1908,7 +1914,9 @@ const APP_TEMPLATES = {
|
|||||||
docker: {
|
docker: {
|
||||||
image: "traefik/whoami:latest",
|
image: "traefik/whoami:latest",
|
||||||
ports: ["{{PORT}}:80"],
|
ports: ["{{PORT}}:80"],
|
||||||
volumes: [],
|
volumes: [
|
||||||
|
"/opt/whoami/config:/config"
|
||||||
|
],
|
||||||
environment: {}
|
environment: {}
|
||||||
},
|
},
|
||||||
subdomain: "whoami",
|
subdomain: "whoami",
|
||||||
@@ -2233,7 +2241,9 @@ const APP_TEMPLATES = {
|
|||||||
docker: {
|
docker: {
|
||||||
image: "excalidraw/excalidraw:latest",
|
image: "excalidraw/excalidraw:latest",
|
||||||
ports: ["{{PORT}}:80"],
|
ports: ["{{PORT}}:80"],
|
||||||
volumes: [],
|
volumes: [
|
||||||
|
"/opt/excalidraw/data:/var/lib/excalidraw"
|
||||||
|
],
|
||||||
environment: {}
|
environment: {}
|
||||||
},
|
},
|
||||||
subdomain: "draw",
|
subdomain: "draw",
|
||||||
@@ -2258,7 +2268,9 @@ const APP_TEMPLATES = {
|
|||||||
docker: {
|
docker: {
|
||||||
image: "corentinth/it-tools:latest",
|
image: "corentinth/it-tools:latest",
|
||||||
ports: ["{{PORT}}:80"],
|
ports: ["{{PORT}}:80"],
|
||||||
volumes: [],
|
volumes: [
|
||||||
|
"/opt/it-tools/config:/config"
|
||||||
|
],
|
||||||
environment: {}
|
environment: {}
|
||||||
},
|
},
|
||||||
subdomain: "tools",
|
subdomain: "tools",
|
||||||
@@ -2417,7 +2429,7 @@ const APP_TEMPLATES = {
|
|||||||
},
|
},
|
||||||
subdomain: "mc",
|
subdomain: "mc",
|
||||||
defaultPort: 25565,
|
defaultPort: 25565,
|
||||||
healthCheck: null,
|
healthCheck: "tcp://localhost:25565",
|
||||||
subpathSupport: 'none',
|
subpathSupport: 'none',
|
||||||
setupInstructions: [
|
setupInstructions: [
|
||||||
"Server accepts the Minecraft EULA automatically",
|
"Server accepts the Minecraft EULA automatically",
|
||||||
@@ -2451,7 +2463,7 @@ const APP_TEMPLATES = {
|
|||||||
},
|
},
|
||||||
subdomain: "valheim",
|
subdomain: "valheim",
|
||||||
defaultPort: 2456,
|
defaultPort: 2456,
|
||||||
healthCheck: null,
|
healthCheck: "tcp://localhost:2456",
|
||||||
subpathSupport: 'none',
|
subpathSupport: 'none',
|
||||||
setupInstructions: [
|
setupInstructions: [
|
||||||
"Connect via Steam: Add Server > IP:2456",
|
"Connect via Steam: Add Server > IP:2456",
|
||||||
|
|||||||
@@ -0,0 +1,503 @@
|
|||||||
|
/**
|
||||||
|
* Auto-Restart Manager - Per-container restart policies with retry tracking
|
||||||
|
*
|
||||||
|
* When a container goes down, attempts automatic restart up to N times
|
||||||
|
* (configurable per-service). Sends notifications on each attempt and
|
||||||
|
* when max retries are exceeded. Integrates with HealthChecker events.
|
||||||
|
*
|
||||||
|
* @module auto-restart-manager
|
||||||
|
*/
|
||||||
|
|
||||||
|
const EventEmitter = require('events');
|
||||||
|
const path = require('path');
|
||||||
|
const { readJsonFile, writeJsonFile } = require('./fs-helpers');
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Default policy values applied when a new policy is created.
|
||||||
|
* @readonly
|
||||||
|
*/
|
||||||
|
const DEFAULT_POLICY = {
|
||||||
|
enabled: true,
|
||||||
|
maxRetries: 3,
|
||||||
|
retryIntervalMs: 5000,
|
||||||
|
windowMinutes: 10,
|
||||||
|
currentRetries: 0,
|
||||||
|
lastRestartAt: null,
|
||||||
|
cooldownUntil: null,
|
||||||
|
};
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Manages automatic container restart policies and execution.
|
||||||
|
*
|
||||||
|
* @extends EventEmitter
|
||||||
|
*
|
||||||
|
* @fires AutoRestartManager#auto-restart-attempt
|
||||||
|
* @fires AutoRestartManager#auto-restart-success
|
||||||
|
* @fires AutoRestartManager#auto-restart-failed
|
||||||
|
* @fires AutoRestartManager#auto-restart-max-reached
|
||||||
|
*/
|
||||||
|
class AutoRestartManager extends EventEmitter {
|
||||||
|
/**
|
||||||
|
* @param {Object} ctx - Shared application context
|
||||||
|
* @param {Object} ctx.docker - Docker client wrapper ({ client: Dockerode })
|
||||||
|
* @param {Object} ctx.healthChecker - HealthChecker singleton
|
||||||
|
* @param {Object} ctx.notification - NotificationManager instance
|
||||||
|
* @param {Object} ctx.log - Logger instance
|
||||||
|
* @param {Function} ctx.logError - Error logging function
|
||||||
|
* @param {string} ctx.SERVICES_FILE - Path to services.json (used to derive data dir)
|
||||||
|
*/
|
||||||
|
constructor(ctx) {
|
||||||
|
super();
|
||||||
|
this.ctx = ctx;
|
||||||
|
this.log = ctx.log || console;
|
||||||
|
this.logError = ctx.logError || ((_ctx, err) => console.error(err));
|
||||||
|
this.docker = ctx.docker;
|
||||||
|
this.healthChecker = ctx.healthChecker;
|
||||||
|
this.notification = ctx.notification;
|
||||||
|
|
||||||
|
/** @type {Map<string, Object>} serviceId -> policy */
|
||||||
|
this.policies = new Map();
|
||||||
|
|
||||||
|
/** Path to the JSON file that persists policies */
|
||||||
|
this.policiesFile = path.join(path.dirname(ctx.SERVICES_FILE), 'auto-restart-policies.json');
|
||||||
|
|
||||||
|
/** Track previous health status per service for transition detection */
|
||||||
|
this._previousHealth = new Map();
|
||||||
|
|
||||||
|
/** Bound handlers so we can remove them on stop() */
|
||||||
|
this._onStatusCheck = this._handleStatusCheck.bind(this);
|
||||||
|
this._started = false;
|
||||||
|
}
|
||||||
|
|
||||||
|
// ─── Lifecycle ────────────────────────────────────────────────────────
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Load persisted policies, then wire into HealthChecker events.
|
||||||
|
* @returns {Promise<void>}
|
||||||
|
*/
|
||||||
|
async start() {
|
||||||
|
if (this._started) return;
|
||||||
|
|
||||||
|
// Load persisted policies from disk
|
||||||
|
try {
|
||||||
|
const data = await readJsonFile(this.policiesFile, {});
|
||||||
|
for (const [serviceId, policy] of Object.entries(data)) {
|
||||||
|
this.policies.set(serviceId, { ...DEFAULT_POLICY, ...policy });
|
||||||
|
}
|
||||||
|
this.log.info('auto-restart', 'Policies loaded', { count: this.policies.size });
|
||||||
|
} catch (err) {
|
||||||
|
this.log.error('auto-restart', 'Failed to load policies', { error: err.message });
|
||||||
|
}
|
||||||
|
|
||||||
|
// Listen to health checker status transitions
|
||||||
|
if (this.healthChecker) {
|
||||||
|
this.healthChecker.on('status-check', this._onStatusCheck);
|
||||||
|
}
|
||||||
|
|
||||||
|
this._started = true;
|
||||||
|
this.log.info('auto-restart', 'Manager started');
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Remove event listeners and stop processing health events.
|
||||||
|
*/
|
||||||
|
stop() {
|
||||||
|
if (!this._started) return;
|
||||||
|
|
||||||
|
if (this.healthChecker) {
|
||||||
|
this.healthChecker.removeListener('status-check', this._onStatusCheck);
|
||||||
|
}
|
||||||
|
|
||||||
|
this._started = false;
|
||||||
|
this.log.info('auto-restart', 'Manager stopped');
|
||||||
|
}
|
||||||
|
|
||||||
|
// ─── Policy CRUD ─────────────────────────────────────────────────────
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Create or update a restart policy for a service.
|
||||||
|
*
|
||||||
|
* @param {string} serviceId - Unique service identifier
|
||||||
|
* @param {Object} policy - Partial policy fields to merge
|
||||||
|
* @param {boolean} [policy.enabled=true]
|
||||||
|
* @param {number} [policy.maxRetries=3]
|
||||||
|
* @param {number} [policy.retryIntervalMs=5000]
|
||||||
|
* @param {number} [policy.windowMinutes=10]
|
||||||
|
* @returns {Promise<Object>} The resulting policy
|
||||||
|
* @throws {Error} If serviceId is invalid
|
||||||
|
*/
|
||||||
|
async setPolicy(serviceId, policy) {
|
||||||
|
if (!serviceId || typeof serviceId !== 'string') {
|
||||||
|
throw new Error('serviceId is required');
|
||||||
|
}
|
||||||
|
|
||||||
|
const existing = this.policies.get(serviceId) || { ...DEFAULT_POLICY, serviceId };
|
||||||
|
|
||||||
|
const merged = {
|
||||||
|
...existing,
|
||||||
|
...policy,
|
||||||
|
serviceId,
|
||||||
|
// Never allow caller to override runtime counters directly
|
||||||
|
currentRetries: existing.currentRetries || 0,
|
||||||
|
lastRestartAt: existing.lastRestartAt,
|
||||||
|
cooldownUntil: existing.cooldownUntil,
|
||||||
|
};
|
||||||
|
|
||||||
|
this.policies.set(serviceId, merged);
|
||||||
|
await this._savePolicies();
|
||||||
|
|
||||||
|
this.log.info('auto-restart', 'Policy set', { serviceId, enabled: merged.enabled });
|
||||||
|
return { ...merged };
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Retrieve the policy for a service.
|
||||||
|
*
|
||||||
|
* @param {string} serviceId
|
||||||
|
* @returns {Object|null} Policy object or null if none exists
|
||||||
|
*/
|
||||||
|
getPolicy(serviceId) {
|
||||||
|
const policy = this.policies.get(serviceId);
|
||||||
|
return policy ? { ...policy } : null;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Return all policies as an array.
|
||||||
|
* @returns {Object[]}
|
||||||
|
*/
|
||||||
|
listPolicies() {
|
||||||
|
return Array.from(this.policies.values()).map(p => ({ ...p }));
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Remove a service's restart policy.
|
||||||
|
*
|
||||||
|
* @param {string} serviceId
|
||||||
|
* @returns {Promise<boolean>} true if a policy was removed
|
||||||
|
*/
|
||||||
|
async removePolicy(serviceId) {
|
||||||
|
if (!this.policies.has(serviceId)) return false;
|
||||||
|
|
||||||
|
this.policies.delete(serviceId);
|
||||||
|
await this._savePolicies();
|
||||||
|
|
||||||
|
this.log.info('auto-restart', 'Policy removed', { serviceId });
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
|
// ─── Core Restart Logic ──────────────────────────────────────────────
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Called when a container is detected as down.
|
||||||
|
*
|
||||||
|
* Checks policy, cooldown, and retry count, then either attempts a
|
||||||
|
* Docker restart or notifies that max retries were exceeded.
|
||||||
|
*
|
||||||
|
* @param {string} serviceId - Service identifier
|
||||||
|
* @param {string} containerId - Docker container ID to restart
|
||||||
|
* @returns {Promise<Object>} Result of the operation
|
||||||
|
*/
|
||||||
|
async handleContainerDown(serviceId, containerId) {
|
||||||
|
const policy = this.policies.get(serviceId);
|
||||||
|
if (!policy) {
|
||||||
|
return { action: 'ignored', reason: 'no-policy' };
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!policy.enabled) {
|
||||||
|
return { action: 'ignored', reason: 'disabled' };
|
||||||
|
}
|
||||||
|
|
||||||
|
// Check cooldown window
|
||||||
|
const now = Date.now();
|
||||||
|
if (policy.cooldownUntil && now < policy.cooldownUntil) {
|
||||||
|
this.log.info('auto-restart', 'Skipping — cooldown active', {
|
||||||
|
serviceId,
|
||||||
|
cooldownUntil: new Date(policy.cooldownUntil).toISOString(),
|
||||||
|
});
|
||||||
|
return { action: 'skipped', reason: 'cooldown' };
|
||||||
|
}
|
||||||
|
|
||||||
|
// Max retries exceeded — notify and enter cooldown
|
||||||
|
if (policy.currentRetries >= policy.maxRetries) {
|
||||||
|
const cooldownMs = policy.windowMinutes * 60 * 1000;
|
||||||
|
policy.cooldownUntil = now + cooldownMs;
|
||||||
|
policy.currentRetries = 0; // Reset so next window can try again
|
||||||
|
await this._savePolicies();
|
||||||
|
|
||||||
|
const eventData = {
|
||||||
|
serviceId,
|
||||||
|
containerId,
|
||||||
|
maxRetries: policy.maxRetries,
|
||||||
|
cooldownUntil: policy.cooldownUntil,
|
||||||
|
timestamp: new Date().toISOString(),
|
||||||
|
};
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @event AutoRestartManager#auto-restart-max-reached
|
||||||
|
* @type {Object}
|
||||||
|
*/
|
||||||
|
this.emit('auto-restart-max-reached', eventData);
|
||||||
|
|
||||||
|
// Send notification
|
||||||
|
try {
|
||||||
|
await this._notify('auto-restart', {
|
||||||
|
containerName: serviceId,
|
||||||
|
message: `⛔ Max auto-restart retries (${policy.maxRetries}) exceeded for "${serviceId}". Cooldown until ${new Date(policy.cooldownUntil).toISOString()}.`,
|
||||||
|
...eventData,
|
||||||
|
});
|
||||||
|
} catch (notifErr) {
|
||||||
|
this.log.error('auto-restart', 'Notification failed', { error: notifErr.message });
|
||||||
|
}
|
||||||
|
|
||||||
|
return { action: 'max-reached', ...eventData };
|
||||||
|
}
|
||||||
|
|
||||||
|
// Wait for the configured retry interval before attempting
|
||||||
|
if (policy.retryIntervalMs > 0 && policy.lastRestartAt) {
|
||||||
|
const elapsed = now - new Date(policy.lastRestartAt).getTime();
|
||||||
|
if (elapsed < policy.retryIntervalMs) {
|
||||||
|
const waitMs = policy.retryIntervalMs - elapsed;
|
||||||
|
this.log.info('auto-restart', 'Waiting for retry interval', { serviceId, waitMs });
|
||||||
|
await new Promise(resolve => setTimeout(resolve, waitMs));
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// Attempt restart
|
||||||
|
policy.currentRetries += 1;
|
||||||
|
const attemptNum = policy.currentRetries;
|
||||||
|
const maxRetries = policy.maxRetries;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @event AutoRestartManager#auto-restart-attempt
|
||||||
|
* @type {Object}
|
||||||
|
*/
|
||||||
|
this.emit('auto-restart-attempt', {
|
||||||
|
serviceId,
|
||||||
|
containerId,
|
||||||
|
attempt: attemptNum,
|
||||||
|
maxRetries,
|
||||||
|
timestamp: new Date().toISOString(),
|
||||||
|
});
|
||||||
|
|
||||||
|
try {
|
||||||
|
if (!this.docker?.client) {
|
||||||
|
throw new Error('Docker client not available');
|
||||||
|
}
|
||||||
|
|
||||||
|
const container = this.docker.client.getContainer(containerId);
|
||||||
|
await container.start();
|
||||||
|
|
||||||
|
policy.lastRestartAt = new Date().toISOString();
|
||||||
|
await this._savePolicies();
|
||||||
|
|
||||||
|
const successData = {
|
||||||
|
serviceId,
|
||||||
|
containerId,
|
||||||
|
attempt: attemptNum,
|
||||||
|
maxRetries,
|
||||||
|
timestamp: new Date().toISOString(),
|
||||||
|
};
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @event AutoRestartManager#auto-restart-success
|
||||||
|
* @type {Object}
|
||||||
|
*/
|
||||||
|
this.emit('auto-restart-success', successData);
|
||||||
|
|
||||||
|
// Notify
|
||||||
|
try {
|
||||||
|
await this._notify('auto-restart', {
|
||||||
|
containerName: serviceId,
|
||||||
|
message: `🔄 Auto-restart attempt ${attemptNum}/${maxRetries} succeeded for "${serviceId}".`,
|
||||||
|
...successData,
|
||||||
|
});
|
||||||
|
} catch (notifErr) {
|
||||||
|
this.log.error('auto-restart', 'Notification failed', { error: notifErr.message });
|
||||||
|
}
|
||||||
|
|
||||||
|
this.log.info('auto-restart', 'Container restarted', {
|
||||||
|
serviceId,
|
||||||
|
attempt: attemptNum,
|
||||||
|
maxRetries,
|
||||||
|
});
|
||||||
|
|
||||||
|
return { action: 'restarted', ...successData };
|
||||||
|
} catch (restartErr) {
|
||||||
|
policy.lastRestartAt = new Date().toISOString();
|
||||||
|
await this._savePolicies();
|
||||||
|
|
||||||
|
const failData = {
|
||||||
|
serviceId,
|
||||||
|
containerId,
|
||||||
|
attempt: attemptNum,
|
||||||
|
maxRetries,
|
||||||
|
error: restartErr.message,
|
||||||
|
timestamp: new Date().toISOString(),
|
||||||
|
};
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @event AutoRestartManager#auto-restart-failed
|
||||||
|
* @type {Object}
|
||||||
|
*/
|
||||||
|
this.emit('auto-restart-failed', failData);
|
||||||
|
|
||||||
|
// Notify
|
||||||
|
try {
|
||||||
|
await this._notify('auto-restart', {
|
||||||
|
containerName: serviceId,
|
||||||
|
message: `❌ Auto-restart attempt ${attemptNum}/${maxRetries} failed for "${serviceId}": ${restartErr.message}`,
|
||||||
|
...failData,
|
||||||
|
});
|
||||||
|
} catch (notifErr) {
|
||||||
|
this.log.error('auto-restart', 'Notification failed', { error: notifErr.message });
|
||||||
|
}
|
||||||
|
|
||||||
|
this.log.error('auto-restart', 'Restart failed', {
|
||||||
|
serviceId,
|
||||||
|
attempt: attemptNum,
|
||||||
|
error: restartErr.message,
|
||||||
|
});
|
||||||
|
|
||||||
|
return { action: 'failed', ...failData };
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Called when a container recovers to healthy state.
|
||||||
|
* Resets the retry counter for the associated service.
|
||||||
|
*
|
||||||
|
* @param {string} serviceId
|
||||||
|
* @returns {Promise<void>}
|
||||||
|
*/
|
||||||
|
async handleContainerUp(serviceId) {
|
||||||
|
const policy = this.policies.get(serviceId);
|
||||||
|
if (!policy) return;
|
||||||
|
|
||||||
|
if (policy.currentRetries > 0) {
|
||||||
|
policy.currentRetries = 0;
|
||||||
|
policy.cooldownUntil = null;
|
||||||
|
await this._savePolicies();
|
||||||
|
|
||||||
|
this.log.info('auto-restart', 'Retries reset after recovery', { serviceId });
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// ─── Health Event Bridge ─────────────────────────────────────────────
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Internal handler for HealthChecker `status-check` events.
|
||||||
|
* Detects healthy→unhealthy and unhealthy→healthy transitions for tracked services.
|
||||||
|
*
|
||||||
|
* @param {Object} status - HealthChecker status object
|
||||||
|
* @param {string} status.serviceId
|
||||||
|
* @param {string} status.status - "up" or "down"
|
||||||
|
* @private
|
||||||
|
*/
|
||||||
|
async _handleStatusCheck(status) {
|
||||||
|
const { serviceId, status: currentStatus } = status;
|
||||||
|
if (!serviceId) return;
|
||||||
|
|
||||||
|
// Only process services that have a restart policy
|
||||||
|
if (!this.policies.has(serviceId)) return;
|
||||||
|
|
||||||
|
const previousStatus = this._previousHealth.get(serviceId);
|
||||||
|
this._previousHealth.set(serviceId, currentStatus);
|
||||||
|
|
||||||
|
// Transition: healthy → unhealthy
|
||||||
|
if (previousStatus === 'up' && currentStatus === 'down') {
|
||||||
|
// Find the containerId from the health checker config or status details
|
||||||
|
const containerId = this._resolveContainerId(serviceId, status);
|
||||||
|
if (containerId) {
|
||||||
|
try {
|
||||||
|
await this.handleContainerDown(serviceId, containerId);
|
||||||
|
} catch (err) {
|
||||||
|
this.logError('auto-restart-health-bridge', err);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// Transition: unhealthy → healthy (recovery)
|
||||||
|
if (previousStatus === 'down' && currentStatus === 'up') {
|
||||||
|
try {
|
||||||
|
await this.handleContainerUp(serviceId);
|
||||||
|
} catch (err) {
|
||||||
|
this.logError('auto-restart-health-bridge', err);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Attempt to find the containerId for a service from various sources.
|
||||||
|
*
|
||||||
|
* @param {string} serviceId
|
||||||
|
* @param {Object} status - The status-check event data
|
||||||
|
* @returns {string|null}
|
||||||
|
* @private
|
||||||
|
*/
|
||||||
|
_resolveContainerId(serviceId, status) {
|
||||||
|
// Check if it's in the status details (some health checks embed it)
|
||||||
|
if (status.details?.containerId) return status.details.containerId;
|
||||||
|
|
||||||
|
// Look in the health checker config
|
||||||
|
const hcService = this.healthChecker?.config?.services?.[serviceId];
|
||||||
|
if (hcService?.containerId) return hcService.containerId;
|
||||||
|
|
||||||
|
// Try to look it up from the services state manager
|
||||||
|
try {
|
||||||
|
const servicesStateManager = this.ctx.servicesStateManager;
|
||||||
|
if (servicesStateManager) {
|
||||||
|
const readResult = servicesStateManager.read();
|
||||||
|
if (readResult && typeof readResult.then === 'function') {
|
||||||
|
// It returns a promise — fire-and-forget lookup
|
||||||
|
readResult.then(list => {
|
||||||
|
const found = (list || []).find(s => s.id === serviceId);
|
||||||
|
return found?.containerId || null;
|
||||||
|
}).catch(() => null);
|
||||||
|
} else {
|
||||||
|
const found = (readResult || []).find(s => s.id === serviceId);
|
||||||
|
if (found?.containerId) return found.containerId;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
} catch (_) { /* best effort */ }
|
||||||
|
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
|
||||||
|
// ─── Persistence ─────────────────────────────────────────────────────
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Persist current policies to disk.
|
||||||
|
* @returns {Promise<void>}
|
||||||
|
* @private
|
||||||
|
*/
|
||||||
|
async _savePolicies() {
|
||||||
|
try {
|
||||||
|
const obj = {};
|
||||||
|
for (const [serviceId, policy] of this.policies.entries()) {
|
||||||
|
obj[serviceId] = { ...policy };
|
||||||
|
}
|
||||||
|
await writeJsonFile(this.policiesFile, obj);
|
||||||
|
} catch (err) {
|
||||||
|
this.log.error('auto-restart', 'Failed to save policies', { error: err.message });
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// ─── Helpers ─────────────────────────────────────────────────────────
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Send a notification via the notification manager.
|
||||||
|
*
|
||||||
|
* @param {string} event - Event type (e.g. 'auto-restart')
|
||||||
|
* @param {Object} data - Notification payload
|
||||||
|
* @returns {Promise<Object>}
|
||||||
|
* @private
|
||||||
|
*/
|
||||||
|
async _notify(event, data) {
|
||||||
|
if (this.notification?.send) {
|
||||||
|
return this.notification.send(event, data);
|
||||||
|
}
|
||||||
|
return { success: false, reason: 'no-notification-manager' };
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
module.exports = { AutoRestartManager, DEFAULT_POLICY };
|
||||||
@@ -0,0 +1,376 @@
|
|||||||
|
/**
|
||||||
|
* Config Drift Detector - Compares services.json with live Docker state
|
||||||
|
*
|
||||||
|
* Detects discrepancies between the configured service list and what is
|
||||||
|
* actually running in Docker, including missing containers, unknown
|
||||||
|
* containers, port mismatches, state mismatches, and stale records.
|
||||||
|
*
|
||||||
|
* @module config-drift-detector
|
||||||
|
*/
|
||||||
|
|
||||||
|
const EventEmitter = require('events');
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @typedef {Object} DriftReport
|
||||||
|
* @property {string} checkedAt - ISO timestamp of the check
|
||||||
|
* @property {Object[]} missingContainers - Services with containerId but container absent in Docker
|
||||||
|
* @property {Object[]} unknownContainers - Running Docker containers with sami.managed label but not in services.json
|
||||||
|
* @property {Object[]} portMismatch - Service port != container mapped port
|
||||||
|
* @property {Object[]} stateMismatch - Service expected up but container stopped/absent
|
||||||
|
* @property {Object[]} staleRecords - Services with containerId pointing to removed containers
|
||||||
|
* @property {boolean} hasDrift - Whether any drift category is non-empty
|
||||||
|
*/
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Detects and reports configuration drift between services.json and Docker.
|
||||||
|
*
|
||||||
|
* @extends EventEmitter
|
||||||
|
*
|
||||||
|
* @fires ConfigDriftDetector#drift-detected
|
||||||
|
*/
|
||||||
|
class ConfigDriftDetector extends EventEmitter {
|
||||||
|
/**
|
||||||
|
* @param {Object} ctx - Shared application context
|
||||||
|
* @param {Object} ctx.docker - Docker client wrapper ({ client: Dockerode })
|
||||||
|
* @param {Object} ctx.servicesStateManager - StateManager for services.json
|
||||||
|
* @param {Object} ctx.notification - NotificationManager instance
|
||||||
|
* @param {Object} ctx.log - Logger instance
|
||||||
|
* @param {Function} ctx.logError - Error logging function
|
||||||
|
*/
|
||||||
|
constructor(ctx) {
|
||||||
|
super();
|
||||||
|
this.ctx = ctx;
|
||||||
|
this.log = ctx.log || console;
|
||||||
|
this.logError = ctx.logError || ((_c, err) => console.error(err));
|
||||||
|
this.docker = ctx.docker;
|
||||||
|
this.servicesStateManager = ctx.servicesStateManager;
|
||||||
|
this.notification = ctx.notification;
|
||||||
|
|
||||||
|
/** @type {DriftReport|null} Cached report from last detection */
|
||||||
|
this.lastReport = null;
|
||||||
|
|
||||||
|
/** @type {NodeJS.Timeout|null} Polling timer reference */
|
||||||
|
this._pollTimer = null;
|
||||||
|
|
||||||
|
/** Whether polling is currently active */
|
||||||
|
this._polling = false;
|
||||||
|
}
|
||||||
|
|
||||||
|
// ─── Detection ───────────────────────────────────────────────────────
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Run a full drift detection and return the report.
|
||||||
|
*
|
||||||
|
* Reads services from servicesStateManager and live containers from Docker,
|
||||||
|
* then compares them across five drift categories.
|
||||||
|
*
|
||||||
|
* @returns {Promise<DriftReport>}
|
||||||
|
*/
|
||||||
|
async detect() {
|
||||||
|
const checkedAt = new Date().toISOString();
|
||||||
|
|
||||||
|
// Gather configured services
|
||||||
|
let services = [];
|
||||||
|
try {
|
||||||
|
const data = await this.servicesStateManager.read();
|
||||||
|
services = Array.isArray(data) ? data : (data.services || []);
|
||||||
|
} catch (err) {
|
||||||
|
this.log.error('drift', 'Failed to read services', { error: err.message });
|
||||||
|
}
|
||||||
|
|
||||||
|
// Gather live Docker containers
|
||||||
|
let containers = [];
|
||||||
|
try {
|
||||||
|
containers = await this.docker.client.listContainers({ all: true });
|
||||||
|
} catch (err) {
|
||||||
|
this.log.error('drift', 'Failed to list containers', { error: err.message });
|
||||||
|
}
|
||||||
|
|
||||||
|
// Build lookup maps
|
||||||
|
const containerById = new Map(); // containerId (short or long) → container info
|
||||||
|
const containerByName = new Map(); // container name → container info
|
||||||
|
|
||||||
|
for (const c of containers) {
|
||||||
|
// Store by full ID
|
||||||
|
containerById.set(c.Id, c);
|
||||||
|
// Store by short ID (first 12 chars)
|
||||||
|
if (c.Id && c.Id.length >= 12) {
|
||||||
|
containerById.set(c.Id.substring(0, 12), c);
|
||||||
|
}
|
||||||
|
// Store by name (strip leading /)
|
||||||
|
for (const name of (c.Names || [])) {
|
||||||
|
containerByName.set(name.replace(/^\//, ''), c);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// Build set of service containerIds for reverse lookup
|
||||||
|
const serviceContainerIds = new Set();
|
||||||
|
const serviceByContainerId = new Map();
|
||||||
|
|
||||||
|
for (const svc of services) {
|
||||||
|
if (svc.containerId) {
|
||||||
|
serviceContainerIds.add(svc.containerId);
|
||||||
|
// Index by both full and short ID
|
||||||
|
serviceByContainerId.set(svc.containerId, svc);
|
||||||
|
if (svc.containerId.length >= 12) {
|
||||||
|
serviceByContainerId.set(svc.containerId.substring(0, 12), svc);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
const missingContainers = [];
|
||||||
|
const portMismatch = [];
|
||||||
|
const stateMismatch = [];
|
||||||
|
const staleRecords = [];
|
||||||
|
|
||||||
|
for (const svc of services) {
|
||||||
|
if (!svc.containerId) continue;
|
||||||
|
|
||||||
|
// Look up the container
|
||||||
|
const container = containerById.get(svc.containerId)
|
||||||
|
|| containerById.get(svc.containerId.substring(0, 12));
|
||||||
|
|
||||||
|
if (!container) {
|
||||||
|
// Container ID referenced but not found in Docker at all
|
||||||
|
staleRecords.push({
|
||||||
|
serviceId: svc.id,
|
||||||
|
name: svc.name,
|
||||||
|
containerId: svc.containerId,
|
||||||
|
reason: 'Container not found in Docker',
|
||||||
|
});
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
|
||||||
|
// Missing container — service expects it but it's not running
|
||||||
|
if (container.State !== 'running') {
|
||||||
|
missingContainers.push({
|
||||||
|
serviceId: svc.id,
|
||||||
|
name: svc.name,
|
||||||
|
containerId: svc.containerId,
|
||||||
|
containerState: container.State,
|
||||||
|
containerStatus: container.Status,
|
||||||
|
});
|
||||||
|
|
||||||
|
// Also a state mismatch if the service is expected to be up
|
||||||
|
stateMismatch.push({
|
||||||
|
serviceId: svc.id,
|
||||||
|
name: svc.name,
|
||||||
|
expectedState: 'running',
|
||||||
|
actualState: container.State,
|
||||||
|
containerId: svc.containerId,
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
// Port mismatch detection
|
||||||
|
if (svc.port && container.State === 'running') {
|
||||||
|
const actualPorts = this._extractContainerPorts(container);
|
||||||
|
if (actualPorts.length > 0 && !actualPorts.includes(svc.port)) {
|
||||||
|
portMismatch.push({
|
||||||
|
serviceId: svc.id,
|
||||||
|
name: svc.name,
|
||||||
|
configuredPort: svc.port,
|
||||||
|
actualPorts,
|
||||||
|
containerId: svc.containerId,
|
||||||
|
});
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// Unknown managed containers: Docker containers with sami.managed label
|
||||||
|
// that are NOT in services.json
|
||||||
|
const unknownContainers = [];
|
||||||
|
for (const c of containers) {
|
||||||
|
const isManaged = c.Labels && c.Labels['sami.managed'] === 'true';
|
||||||
|
if (!isManaged) continue;
|
||||||
|
|
||||||
|
const isInServices = serviceByContainerId.has(c.Id)
|
||||||
|
|| serviceByContainerId.has(c.Id.substring(0, 12));
|
||||||
|
|
||||||
|
if (!isInServices) {
|
||||||
|
unknownContainers.push({
|
||||||
|
containerId: c.Id,
|
||||||
|
name: (c.Names && c.Names[0] || '').replace(/^\//, ''),
|
||||||
|
image: c.Image,
|
||||||
|
state: c.State,
|
||||||
|
status: c.Status,
|
||||||
|
app: c.Labels?.['sami.app'] || null,
|
||||||
|
subdomain: c.Labels?.['sami.subdomain'] || null,
|
||||||
|
});
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
const report = {
|
||||||
|
checkedAt,
|
||||||
|
missingContainers,
|
||||||
|
unknownContainers,
|
||||||
|
portMismatch,
|
||||||
|
stateMismatch,
|
||||||
|
staleRecords,
|
||||||
|
hasDrift: missingContainers.length > 0
|
||||||
|
|| unknownContainers.length > 0
|
||||||
|
|| portMismatch.length > 0
|
||||||
|
|| stateMismatch.length > 0
|
||||||
|
|| staleRecords.length > 0,
|
||||||
|
};
|
||||||
|
|
||||||
|
// Cache for quick API access
|
||||||
|
this.lastReport = report;
|
||||||
|
|
||||||
|
// Emit and notify if drift detected
|
||||||
|
if (report.hasDrift) {
|
||||||
|
/**
|
||||||
|
* @event ConfigDriftDetector#drift-detected
|
||||||
|
* @type {DriftReport}
|
||||||
|
*/
|
||||||
|
this.emit('drift-detected', report);
|
||||||
|
|
||||||
|
try {
|
||||||
|
await this._sendDriftNotification(report);
|
||||||
|
} catch (notifErr) {
|
||||||
|
this.log.error('drift', 'Failed to send drift notification', {
|
||||||
|
error: notifErr.message,
|
||||||
|
});
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
this.log.info('drift', 'Detection complete', {
|
||||||
|
hasDrift: report.hasDrift,
|
||||||
|
missing: report.missingContainers.length,
|
||||||
|
unknown: report.unknownContainers.length,
|
||||||
|
portMismatch: report.portMismatch.length,
|
||||||
|
stateMismatch: report.stateMismatch.length,
|
||||||
|
stale: report.staleRecords.length,
|
||||||
|
});
|
||||||
|
|
||||||
|
return report;
|
||||||
|
}
|
||||||
|
|
||||||
|
// ─── Auto-fix ────────────────────────────────────────────────────────
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Attempt to auto-fix drift:
|
||||||
|
* - Remove stale records (services referencing removed containers)
|
||||||
|
* - Flag unknown containers for review
|
||||||
|
*
|
||||||
|
* @returns {Promise<{ staleRemoved: number, unknownFlagged: number }>}
|
||||||
|
*/
|
||||||
|
async autoFix() {
|
||||||
|
const report = await this.detect();
|
||||||
|
let staleRemoved = 0;
|
||||||
|
|
||||||
|
// Remove stale records from services.json
|
||||||
|
if (report.staleRecords.length > 0) {
|
||||||
|
const staleIds = new Set(report.staleRecords.map(r => r.serviceId));
|
||||||
|
await this.servicesStateManager.update(services => {
|
||||||
|
const before = services.length;
|
||||||
|
const cleaned = services.filter(s => !staleIds.has(s.id));
|
||||||
|
staleRemoved = before - cleaned.length;
|
||||||
|
return cleaned;
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
const unknownFlagged = report.unknownContainers.length;
|
||||||
|
|
||||||
|
this.log.info('drift', 'Auto-fix applied', { staleRemoved, unknownFlagged });
|
||||||
|
|
||||||
|
return { staleRemoved, unknownFlagged };
|
||||||
|
}
|
||||||
|
|
||||||
|
// ─── Polling ─────────────────────────────────────────────────────────
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Start periodic drift detection.
|
||||||
|
*
|
||||||
|
* @param {number} [intervalMs=300000] - Polling interval in milliseconds (default 5 min)
|
||||||
|
*/
|
||||||
|
startPolling(intervalMs = 300000) {
|
||||||
|
this.stopPolling();
|
||||||
|
|
||||||
|
this._polling = true;
|
||||||
|
this._pollTimer = setInterval(async () => {
|
||||||
|
try {
|
||||||
|
await this.detect();
|
||||||
|
} catch (err) {
|
||||||
|
this.logError('drift-poll', err);
|
||||||
|
}
|
||||||
|
}, intervalMs);
|
||||||
|
|
||||||
|
this.log.info('drift', 'Polling started', { intervalMs });
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Stop periodic drift detection.
|
||||||
|
*/
|
||||||
|
stopPolling() {
|
||||||
|
if (this._pollTimer) {
|
||||||
|
clearInterval(this._pollTimer);
|
||||||
|
this._pollTimer = null;
|
||||||
|
}
|
||||||
|
this._polling = false;
|
||||||
|
this.log.info('drift', 'Polling stopped');
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Whether polling is currently active.
|
||||||
|
* @returns {boolean}
|
||||||
|
*/
|
||||||
|
isPolling() {
|
||||||
|
return this._polling;
|
||||||
|
}
|
||||||
|
|
||||||
|
// ─── Helpers ─────────────────────────────────────────────────────────
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Extract mapped host ports from a Docker container info object.
|
||||||
|
*
|
||||||
|
* @param {Object} container - Dockerode container info
|
||||||
|
* @returns {number[]} Array of host port numbers
|
||||||
|
* @private
|
||||||
|
*/
|
||||||
|
_extractContainerPorts(container) {
|
||||||
|
const ports = [];
|
||||||
|
if (!container.Ports) return ports;
|
||||||
|
|
||||||
|
for (const p of container.Ports) {
|
||||||
|
if (p.PublicPort) {
|
||||||
|
ports.push(p.PublicPort);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return ports;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Send a notification about detected drift.
|
||||||
|
*
|
||||||
|
* @param {DriftReport} report
|
||||||
|
* @returns {Promise<Object>}
|
||||||
|
* @private
|
||||||
|
*/
|
||||||
|
async _sendDriftNotification(report) {
|
||||||
|
if (!this.notification?.send) {
|
||||||
|
return { success: false, reason: 'no-notification-manager' };
|
||||||
|
}
|
||||||
|
|
||||||
|
const parts = [];
|
||||||
|
if (report.missingContainers.length > 0) {
|
||||||
|
parts.push(`Missing containers: ${report.missingContainers.map(c => c.name).join(', ')}`);
|
||||||
|
}
|
||||||
|
if (report.unknownContainers.length > 0) {
|
||||||
|
parts.push(`Unknown managed containers: ${report.unknownContainers.map(c => c.name).join(', ')}`);
|
||||||
|
}
|
||||||
|
if (report.portMismatch.length > 0) {
|
||||||
|
parts.push(`Port mismatches: ${report.portMismatch.map(c => c.name).join(', ')}`);
|
||||||
|
}
|
||||||
|
if (report.staleRecords.length > 0) {
|
||||||
|
parts.push(`Stale records: ${report.staleRecords.map(c => c.name).join(', ')}`);
|
||||||
|
}
|
||||||
|
|
||||||
|
return this.notification.send('drift-detected', {
|
||||||
|
text: `⚠️ Configuration drift detected:\n${parts.join('\n')}`,
|
||||||
|
report,
|
||||||
|
});
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
module.exports = { ConfigDriftDetector };
|
||||||
@@ -59,6 +59,15 @@ function validateConfig(config) {
|
|||||||
errors.push('dns.servers must be an object');
|
errors.push('dns.servers must be an object');
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
// DNS provider validation
|
||||||
|
if (config.dns.provider !== undefined) {
|
||||||
|
const validProviders = ['technitium', 'cloudflare', 'rfc2136', 'manual'];
|
||||||
|
if (typeof config.dns.provider !== 'string') {
|
||||||
|
errors.push('dns.provider must be a string');
|
||||||
|
} else if (!validProviders.includes(config.dns.provider)) {
|
||||||
|
warnings.push(`dns.provider "${config.dns.provider}" is not one of: ${validProviders.join(', ')}. It may still work if a custom adapter is installed.`);
|
||||||
|
}
|
||||||
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -102,7 +102,7 @@ const DNS_RECORD_TYPES = ['A', 'AAAA', 'CNAME', 'MX', 'TXT', 'NS', 'SRV', 'PTR',
|
|||||||
// ── Docker ──────────────────────────────────────────────────────
|
// ── Docker ──────────────────────────────────────────────────────
|
||||||
const DOCKER = {
|
const DOCKER = {
|
||||||
CONTAINER_PREFIX: 'sami-',
|
CONTAINER_PREFIX: 'sami-',
|
||||||
TIMEOUT: 30000, // 30s — timeout for docker pull/create operations
|
TIMEOUT: 300000, // 300s — timeout for docker pull/create operations
|
||||||
LOG_CONFIG: {
|
LOG_CONFIG: {
|
||||||
Type: 'json-file',
|
Type: 'json-file',
|
||||||
Config: { 'max-size': '10m', 'max-file': '3' } // 30MB max per container
|
Config: { 'max-size': '10m', 'max-file': '3' } // 30MB max per container
|
||||||
|
|||||||
@@ -10,7 +10,26 @@ const lockfile = require('proper-lockfile');
|
|||||||
const fs = require('fs');
|
const fs = require('fs');
|
||||||
const path = require('path');
|
const path = require('path');
|
||||||
|
|
||||||
const CREDENTIALS_FILE = process.env.CREDENTIALS_FILE || path.join(__dirname, 'credentials.json');
|
// Resolve credentials file path — supports both standard install (/app/credentials.json)
|
||||||
|
// and custom deployments with consolidated data directory (/app/data/credentials.json)
|
||||||
|
function resolveCredentialsFile() {
|
||||||
|
if (process.env.CREDENTIALS_FILE) {
|
||||||
|
return process.env.CREDENTIALS_FILE;
|
||||||
|
}
|
||||||
|
const candidates = [
|
||||||
|
path.join(__dirname, 'credentials.json'),
|
||||||
|
path.join(__dirname, 'data', 'credentials.json'),
|
||||||
|
];
|
||||||
|
for (const candidate of candidates) {
|
||||||
|
if (fs.existsSync(candidate)) {
|
||||||
|
return candidate;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
// No existing file — return standard path so first store() creates it there
|
||||||
|
return candidates[0];
|
||||||
|
}
|
||||||
|
|
||||||
|
const CREDENTIALS_FILE = resolveCredentialsFile();
|
||||||
|
|
||||||
class CredentialManager {
|
class CredentialManager {
|
||||||
constructor() {
|
constructor() {
|
||||||
|
|||||||
@@ -15,8 +15,26 @@ const IV_LENGTH = 16; // 128 bits for GCM
|
|||||||
const AUTH_TAG_LENGTH = 16;
|
const AUTH_TAG_LENGTH = 16;
|
||||||
const SALT_LENGTH = 32;
|
const SALT_LENGTH = 32;
|
||||||
|
|
||||||
// Key file location (should be outside of mounted volumes for security)
|
// Resolve encryption key file path — supports both standard install (/app/.encryption-key)
|
||||||
const KEY_FILE = process.env.ENCRYPTION_KEY_FILE || path.join(__dirname, '.encryption-key');
|
// and custom deployments with consolidated data directory (/app/data/.encryption-key)
|
||||||
|
function resolveKeyFile() {
|
||||||
|
if (process.env.ENCRYPTION_KEY_FILE) {
|
||||||
|
return process.env.ENCRYPTION_KEY_FILE;
|
||||||
|
}
|
||||||
|
const candidates = [
|
||||||
|
path.join(__dirname, '.encryption-key'),
|
||||||
|
path.join(__dirname, 'data', '.encryption-key'),
|
||||||
|
];
|
||||||
|
for (const candidate of candidates) {
|
||||||
|
if (fs.existsSync(candidate)) {
|
||||||
|
return candidate;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
// No existing file — return standard path so first load creates it there
|
||||||
|
return candidates[0];
|
||||||
|
}
|
||||||
|
|
||||||
|
const KEY_FILE = resolveKeyFile();
|
||||||
|
|
||||||
let encryptionKey = null;
|
let encryptionKey = null;
|
||||||
|
|
||||||
|
|||||||
@@ -0,0 +1,605 @@
|
|||||||
|
/**
|
||||||
|
* Dependency Manager - Service dependency tracking with ordered restart chains
|
||||||
|
*
|
||||||
|
* Manages directed acyclic graph (DAG) of service dependencies. Services can
|
||||||
|
* declare which other services they depend on, and this manager provides:
|
||||||
|
* - Full dependency graph inspection
|
||||||
|
* - Topological ordering for safe restart chains
|
||||||
|
* - Circular dependency detection
|
||||||
|
* - Health-aware restart with per-service polling
|
||||||
|
*
|
||||||
|
* Dependencies are stored directly on service objects in services.json:
|
||||||
|
* { id, name, ..., dependsOn: ['service-id-1', 'service-id-2'] }
|
||||||
|
*
|
||||||
|
* @module dependency-manager
|
||||||
|
*/
|
||||||
|
|
||||||
|
const EventEmitter = require('events');
|
||||||
|
|
||||||
|
/** Maximum seconds to wait for a single container to become healthy after restart */
|
||||||
|
const HEALTH_CHECK_TIMEOUT_MS = 30_000;
|
||||||
|
|
||||||
|
/** Interval between container health polls */
|
||||||
|
const HEALTH_CHECK_INTERVAL_MS = 1_000;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @typedef {Object} ServiceNode
|
||||||
|
* @property {string} serviceId
|
||||||
|
* @property {string} name
|
||||||
|
* @property {string|null} containerId
|
||||||
|
*/
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @typedef {Object} DependencyEdge
|
||||||
|
* @property {string} from - The service that depends
|
||||||
|
* @property {string} to - The service being depended upon
|
||||||
|
*/
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @typedef {Object} DependencyGraph
|
||||||
|
* @property {ServiceNode[]} nodes
|
||||||
|
* @property {DependencyEdge[]} edges
|
||||||
|
*/
|
||||||
|
|
||||||
|
/**
|
||||||
|
* @typedef {Object} DependencyStatusEntry
|
||||||
|
* @property {string} serviceId
|
||||||
|
* @property {string} name
|
||||||
|
* @property {boolean} isUp
|
||||||
|
* @property {string} [error]
|
||||||
|
*/
|
||||||
|
|
||||||
|
/**
|
||||||
|
* DependencyManager — tracks service dependencies and orchestrates ordered restarts.
|
||||||
|
*
|
||||||
|
* Events emitted:
|
||||||
|
* - `dependency-restart-start` ({ serviceId, chain: string[] })
|
||||||
|
* - `dependency-restart-progress` ({ serviceId, currentServiceId, index, total })
|
||||||
|
* - `dependency-restart-complete` ({ serviceId, chain: string[], results: Array })
|
||||||
|
* - `dependency-restart-failed` ({ serviceId, failedServiceId, error, chain: string[] })
|
||||||
|
*
|
||||||
|
* @extends EventEmitter
|
||||||
|
*/
|
||||||
|
class DependencyManager extends EventEmitter {
|
||||||
|
/**
|
||||||
|
* @param {Object} ctx - Application context
|
||||||
|
* @param {Object} ctx.servicesStateManager - StateManager for services.json
|
||||||
|
* @param {Object} ctx.docker - Docker context ({ client: Dockerode })
|
||||||
|
* @param {Object} ctx.notification - NotificationManager instance
|
||||||
|
* @param {Object} ctx.log - Logger instance
|
||||||
|
*/
|
||||||
|
constructor(ctx) {
|
||||||
|
super();
|
||||||
|
/** @private */
|
||||||
|
this.ctx = ctx;
|
||||||
|
/** @private */
|
||||||
|
this._servicesStateManager = ctx.servicesStateManager;
|
||||||
|
/** @private */
|
||||||
|
this._docker = ctx.docker;
|
||||||
|
/** @private */
|
||||||
|
this._notification = ctx.notification;
|
||||||
|
/** @private */
|
||||||
|
this._log = ctx.log || console;
|
||||||
|
}
|
||||||
|
|
||||||
|
// ---------------------------------------------------------------------------
|
||||||
|
// Core helpers
|
||||||
|
// ---------------------------------------------------------------------------
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Load all services from the state manager.
|
||||||
|
* @private
|
||||||
|
* @returns {Promise<Object[]>}
|
||||||
|
*/
|
||||||
|
async _loadServices() {
|
||||||
|
const data = await this._servicesStateManager.read();
|
||||||
|
return Array.isArray(data) ? data : (data.services || []);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Find a single service by ID.
|
||||||
|
* @private
|
||||||
|
* @param {string} serviceId
|
||||||
|
* @returns {Promise<Object|null>}
|
||||||
|
*/
|
||||||
|
async _findService(serviceId) {
|
||||||
|
const services = await this._loadServices();
|
||||||
|
return services.find(s => s.id === serviceId) || null;
|
||||||
|
}
|
||||||
|
|
||||||
|
// ---------------------------------------------------------------------------
|
||||||
|
// Graph queries
|
||||||
|
// ---------------------------------------------------------------------------
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Return the full dependency graph for visualisation.
|
||||||
|
*
|
||||||
|
* @returns {Promise<DependencyGraph>}
|
||||||
|
*/
|
||||||
|
async getDependencyGraph() {
|
||||||
|
const services = await this._loadServices();
|
||||||
|
|
||||||
|
const nodes = services.map(s => ({
|
||||||
|
serviceId: s.id,
|
||||||
|
name: s.name,
|
||||||
|
containerId: s.containerId || null,
|
||||||
|
}));
|
||||||
|
|
||||||
|
const edges = [];
|
||||||
|
for (const service of services) {
|
||||||
|
const deps = service.dependsOn || [];
|
||||||
|
for (const depId of deps) {
|
||||||
|
edges.push({ from: service.id, to: depId });
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return { nodes, edges };
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Return the services that depend on the given service (reverse deps).
|
||||||
|
*
|
||||||
|
* @param {string} serviceId
|
||||||
|
* @returns {Promise<Object[]>} Services whose `dependsOn` includes `serviceId`.
|
||||||
|
*/
|
||||||
|
async getDependents(serviceId) {
|
||||||
|
const services = await this._loadServices();
|
||||||
|
return services.filter(s => (s.dependsOn || []).includes(serviceId));
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Return the direct dependencies for a service.
|
||||||
|
*
|
||||||
|
* @param {string} serviceId
|
||||||
|
* @returns {Promise<Object[]>} Services that `serviceId` depends on.
|
||||||
|
*/
|
||||||
|
async getDependencies(serviceId) {
|
||||||
|
const services = await this._loadServices();
|
||||||
|
const service = services.find(s => s.id === serviceId);
|
||||||
|
if (!service) return [];
|
||||||
|
const depIds = service.dependsOn || [];
|
||||||
|
return services.filter(s => depIds.includes(s.id));
|
||||||
|
}
|
||||||
|
|
||||||
|
// ---------------------------------------------------------------------------
|
||||||
|
// Topological sort
|
||||||
|
// ---------------------------------------------------------------------------
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Build an adjacency list for the current dependency graph.
|
||||||
|
* Edge direction: service → its dependencies (i.e. what it depends on).
|
||||||
|
*
|
||||||
|
* @private
|
||||||
|
* @param {Object[]} services
|
||||||
|
* @returns {Map<string, string[]>}
|
||||||
|
*/
|
||||||
|
_buildAdjacencyList(services) {
|
||||||
|
const adj = new Map();
|
||||||
|
for (const service of services) {
|
||||||
|
adj.set(service.id, (service.dependsOn || []).slice());
|
||||||
|
}
|
||||||
|
return adj;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* DFS-based topological sort with cycle detection (white/gray/black coloring).
|
||||||
|
*
|
||||||
|
* Returns services in restart order: dependencies first, dependents last.
|
||||||
|
* The target service is included at the end.
|
||||||
|
*
|
||||||
|
* @private
|
||||||
|
* @param {string} serviceId - Target service (will be last in the result).
|
||||||
|
* @param {Object[]} services - All services.
|
||||||
|
* @param {Map<string, string[]>} adj - Adjacency list (service → deps).
|
||||||
|
* @returns {string[]} Ordered service IDs for restart.
|
||||||
|
* @throws {Error} If a circular dependency is detected.
|
||||||
|
*/
|
||||||
|
_topologicalSort(serviceId, services, adj) {
|
||||||
|
// Collect only the reachable sub-graph from serviceId
|
||||||
|
const visited = new Set();
|
||||||
|
const reachable = new Set();
|
||||||
|
|
||||||
|
const collectReachable = (id) => {
|
||||||
|
if (reachable.has(id)) return;
|
||||||
|
reachable.add(id);
|
||||||
|
for (const dep of (adj.get(id) || [])) {
|
||||||
|
collectReachable(dep);
|
||||||
|
}
|
||||||
|
};
|
||||||
|
collectReachable(serviceId);
|
||||||
|
|
||||||
|
// DFS topological sort on the reachable sub-graph
|
||||||
|
const WHITE = 0, GRAY = 1, BLACK = 2;
|
||||||
|
const color = new Map();
|
||||||
|
for (const id of reachable) color.set(id, WHITE);
|
||||||
|
|
||||||
|
const result = [];
|
||||||
|
|
||||||
|
const dfs = (id) => {
|
||||||
|
if (color.get(id) === BLACK) return;
|
||||||
|
if (color.get(id) === GRAY) {
|
||||||
|
throw new Error(`Circular dependency detected involving service "${id}"`);
|
||||||
|
}
|
||||||
|
color.set(id, GRAY);
|
||||||
|
for (const dep of (adj.get(id) || [])) {
|
||||||
|
dfs(dep);
|
||||||
|
}
|
||||||
|
color.set(id, BLACK);
|
||||||
|
result.push(id);
|
||||||
|
};
|
||||||
|
|
||||||
|
// Visit the target last so it ends up at the end of the result
|
||||||
|
// Actually, we want deps *first* then the target.
|
||||||
|
// The DFS naturally puts deps before dependents, so starting from
|
||||||
|
// serviceId will place it last (which is correct for restart order).
|
||||||
|
dfs(serviceId);
|
||||||
|
|
||||||
|
return result;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Get the topologically ordered restart chain for a service.
|
||||||
|
*
|
||||||
|
* The returned array lists all services that must be restarted,
|
||||||
|
* starting with leaf dependencies and ending with the target service.
|
||||||
|
*
|
||||||
|
* @param {string} serviceId - The service to build the chain for.
|
||||||
|
* @returns {Promise<string[]>} Ordered service IDs.
|
||||||
|
* @throws {Error} If `serviceId` doesn't exist or a circular dependency is found.
|
||||||
|
*/
|
||||||
|
async getOrderedRestartChain(serviceId) {
|
||||||
|
const services = await this._loadServices();
|
||||||
|
const service = services.find(s => s.id === serviceId);
|
||||||
|
if (!service) {
|
||||||
|
throw new Error(`Service "${serviceId}" not found`);
|
||||||
|
}
|
||||||
|
|
||||||
|
const adj = this._buildAdjacencyList(services);
|
||||||
|
return this._topologicalSort(serviceId, services, adj);
|
||||||
|
}
|
||||||
|
|
||||||
|
// ---------------------------------------------------------------------------
|
||||||
|
// Validation
|
||||||
|
// ---------------------------------------------------------------------------
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Validate a proposed set of dependencies for a service.
|
||||||
|
*
|
||||||
|
* Checks:
|
||||||
|
* - All referenced service IDs exist.
|
||||||
|
* - Adding these dependencies would not create a circular dependency.
|
||||||
|
* - A service cannot depend on itself.
|
||||||
|
*
|
||||||
|
* @param {string} serviceId - The service to set dependencies on.
|
||||||
|
* @param {string[]} dependsOn - Proposed dependency IDs.
|
||||||
|
* @returns {Promise<{ valid: boolean, errors: string[] }>}
|
||||||
|
*/
|
||||||
|
async validateDependencies(serviceId, dependsOn) {
|
||||||
|
const errors = [];
|
||||||
|
|
||||||
|
if (!Array.isArray(dependsOn)) {
|
||||||
|
return { valid: false, errors: ['dependsOn must be an array'] };
|
||||||
|
}
|
||||||
|
|
||||||
|
const services = await this._loadServices();
|
||||||
|
const allIds = new Set(services.map(s => s.id));
|
||||||
|
|
||||||
|
// Service must exist
|
||||||
|
if (!allIds.has(serviceId)) {
|
||||||
|
return { valid: false, errors: [`Service "${serviceId}" not found`] };
|
||||||
|
}
|
||||||
|
|
||||||
|
// Self-dependency
|
||||||
|
if (dependsOn.includes(serviceId)) {
|
||||||
|
errors.push(`Service "${serviceId}" cannot depend on itself`);
|
||||||
|
}
|
||||||
|
|
||||||
|
// Existence check
|
||||||
|
for (const depId of dependsOn) {
|
||||||
|
if (!allIds.has(depId)) {
|
||||||
|
errors.push(`Dependency service "${depId}" does not exist`);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
if (errors.length > 0) {
|
||||||
|
return { valid: false, errors };
|
||||||
|
}
|
||||||
|
|
||||||
|
// Circular dependency check: temporarily set the proposed dependsOn
|
||||||
|
// and attempt a topological sort.
|
||||||
|
const tempServices = services.map(s => {
|
||||||
|
if (s.id === serviceId) {
|
||||||
|
return { ...s, dependsOn: dependsOn.slice() };
|
||||||
|
}
|
||||||
|
return { ...s };
|
||||||
|
});
|
||||||
|
|
||||||
|
const adj = this._buildAdjacencyList(tempServices);
|
||||||
|
|
||||||
|
// Check every node for cycles with the new edges
|
||||||
|
try {
|
||||||
|
const WHITE = 0, GRAY = 1, BLACK = 2;
|
||||||
|
const color = new Map();
|
||||||
|
for (const s of tempServices) color.set(s.id, WHITE);
|
||||||
|
|
||||||
|
const dfs = (id) => {
|
||||||
|
if (color.get(id) === BLACK) return;
|
||||||
|
if (color.get(id) === GRAY) {
|
||||||
|
throw new Error(`Circular dependency detected involving service "${id}"`);
|
||||||
|
}
|
||||||
|
color.set(id, GRAY);
|
||||||
|
for (const dep of (adj.get(id) || [])) {
|
||||||
|
dfs(dep);
|
||||||
|
}
|
||||||
|
color.set(id, BLACK);
|
||||||
|
};
|
||||||
|
|
||||||
|
for (const s of tempServices) {
|
||||||
|
if (color.get(s.id) === WHITE) {
|
||||||
|
dfs(s.id);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
} catch (err) {
|
||||||
|
errors.push(err.message);
|
||||||
|
}
|
||||||
|
|
||||||
|
return { valid: errors.length === 0, errors };
|
||||||
|
}
|
||||||
|
|
||||||
|
// ---------------------------------------------------------------------------
|
||||||
|
// Health status
|
||||||
|
// ---------------------------------------------------------------------------
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Get the current container status for a service and all its transitive dependencies.
|
||||||
|
*
|
||||||
|
* @param {string} serviceId
|
||||||
|
* @returns {Promise<DependencyStatusEntry[]>}
|
||||||
|
* @throws {Error} If `serviceId` doesn't exist.
|
||||||
|
*/
|
||||||
|
async getDependencyStatus(serviceId) {
|
||||||
|
const services = await this._loadServices();
|
||||||
|
const service = services.find(s => s.id === serviceId);
|
||||||
|
if (!service) {
|
||||||
|
throw new Error(`Service "${serviceId}" not found`);
|
||||||
|
}
|
||||||
|
|
||||||
|
// Collect all transitive dependencies via BFS
|
||||||
|
const serviceMap = new Map(services.map(s => [s.id, s]));
|
||||||
|
const visited = new Set();
|
||||||
|
const queue = [serviceId];
|
||||||
|
const allRelated = [];
|
||||||
|
|
||||||
|
while (queue.length > 0) {
|
||||||
|
const currentId = queue.shift();
|
||||||
|
if (visited.has(currentId)) continue;
|
||||||
|
visited.add(currentId);
|
||||||
|
|
||||||
|
const svc = serviceMap.get(currentId);
|
||||||
|
if (!svc) continue;
|
||||||
|
|
||||||
|
allRelated.push(svc);
|
||||||
|
|
||||||
|
for (const depId of (svc.dependsOn || [])) {
|
||||||
|
if (!visited.has(depId)) {
|
||||||
|
queue.push(depId);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// Query container status for each
|
||||||
|
const results = [];
|
||||||
|
for (const svc of allRelated) {
|
||||||
|
const entry = {
|
||||||
|
serviceId: svc.id,
|
||||||
|
name: svc.name,
|
||||||
|
isUp: false,
|
||||||
|
};
|
||||||
|
|
||||||
|
if (!svc.containerId) {
|
||||||
|
entry.error = 'No container associated with this service';
|
||||||
|
results.push(entry);
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
|
||||||
|
try {
|
||||||
|
const container = this._docker.client.getContainer(svc.containerId);
|
||||||
|
const info = await container.inspect();
|
||||||
|
entry.isUp = info.State?.Running === true;
|
||||||
|
} catch (err) {
|
||||||
|
entry.error = err.message || 'Unable to inspect container';
|
||||||
|
}
|
||||||
|
|
||||||
|
results.push(entry);
|
||||||
|
}
|
||||||
|
|
||||||
|
return results;
|
||||||
|
}
|
||||||
|
|
||||||
|
// ---------------------------------------------------------------------------
|
||||||
|
// Restart with dependencies
|
||||||
|
// ---------------------------------------------------------------------------
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Wait for a container to report as running after a restart.
|
||||||
|
*
|
||||||
|
* @private
|
||||||
|
* @param {string} containerId
|
||||||
|
* @param {number} [timeoutMs=30000]
|
||||||
|
* @returns {Promise<boolean>} `true` if healthy, `false` if timed out.
|
||||||
|
*/
|
||||||
|
async _waitForContainerHealthy(containerId, timeoutMs = HEALTH_CHECK_TIMEOUT_MS) {
|
||||||
|
const start = Date.now();
|
||||||
|
while (Date.now() - start < timeoutMs) {
|
||||||
|
try {
|
||||||
|
const container = this._docker.client.getContainer(containerId);
|
||||||
|
const info = await container.inspect();
|
||||||
|
if (info.State?.Running === true) {
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
} catch {
|
||||||
|
// Container might not be inspectable during restart — keep polling
|
||||||
|
}
|
||||||
|
await new Promise(r => setTimeout(r, HEALTH_CHECK_INTERVAL_MS));
|
||||||
|
}
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Restart a service and all its dependencies in topological order.
|
||||||
|
*
|
||||||
|
* Emits progress events and sends a notification on completion/failure.
|
||||||
|
* This method is designed to be called from the route handler and
|
||||||
|
* **does not throw** — errors are reported via events and notifications.
|
||||||
|
*
|
||||||
|
* @param {string} serviceId - Target service to restart (with deps).
|
||||||
|
* @returns {Promise<{ success: boolean, chain: string[], results: Array }>}
|
||||||
|
*/
|
||||||
|
async restartWithDependencies(serviceId) {
|
||||||
|
const service = await this._findService(serviceId);
|
||||||
|
if (!service) {
|
||||||
|
const err = new Error(`Service "${serviceId}" not found`);
|
||||||
|
this.emit('dependency-restart-failed', {
|
||||||
|
serviceId,
|
||||||
|
failedServiceId: serviceId,
|
||||||
|
error: err.message,
|
||||||
|
chain: [],
|
||||||
|
});
|
||||||
|
throw err;
|
||||||
|
}
|
||||||
|
|
||||||
|
let chain;
|
||||||
|
try {
|
||||||
|
chain = await this.getOrderedRestartChain(serviceId);
|
||||||
|
} catch (err) {
|
||||||
|
this.emit('dependency-restart-failed', {
|
||||||
|
serviceId,
|
||||||
|
failedServiceId: serviceId,
|
||||||
|
error: err.message,
|
||||||
|
chain: [],
|
||||||
|
});
|
||||||
|
throw err;
|
||||||
|
}
|
||||||
|
|
||||||
|
const services = await this._loadServices();
|
||||||
|
const serviceMap = new Map(services.map(s => [s.id, s]));
|
||||||
|
|
||||||
|
this._log.info('dependency', 'Starting dependency restart chain', {
|
||||||
|
serviceId,
|
||||||
|
chain,
|
||||||
|
});
|
||||||
|
|
||||||
|
this.emit('dependency-restart-start', { serviceId, chain });
|
||||||
|
|
||||||
|
const results = [];
|
||||||
|
const total = chain.length;
|
||||||
|
|
||||||
|
for (let i = 0; i < total; i++) {
|
||||||
|
const currentId = chain[i];
|
||||||
|
const svc = serviceMap.get(currentId);
|
||||||
|
|
||||||
|
this.emit('dependency-restart-progress', {
|
||||||
|
serviceId,
|
||||||
|
currentServiceId: currentId,
|
||||||
|
index: i,
|
||||||
|
total,
|
||||||
|
});
|
||||||
|
|
||||||
|
if (!svc || !svc.containerId) {
|
||||||
|
const msg = !svc
|
||||||
|
? `Service "${currentId}" not found in state`
|
||||||
|
: `Service "${currentId}" has no container — skipping restart`;
|
||||||
|
this._log.warn('dependency', msg);
|
||||||
|
results.push({ serviceId: currentId, restarted: false, skipped: true, reason: msg });
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
|
||||||
|
try {
|
||||||
|
const container = this._docker.client.getContainer(svc.containerId);
|
||||||
|
this._log.info('dependency', `Restarting container for service "${currentId}"`, {
|
||||||
|
containerId: svc.containerId,
|
||||||
|
});
|
||||||
|
await container.restart();
|
||||||
|
|
||||||
|
// Wait for it to come back up
|
||||||
|
const healthy = await this._waitForContainerHealthy(svc.containerId);
|
||||||
|
if (!healthy) {
|
||||||
|
const msg = `Container for service "${currentId}" did not become healthy within ${HEALTH_CHECK_TIMEOUT_MS / 1000}s`;
|
||||||
|
this._log.warn('dependency', msg);
|
||||||
|
results.push({ serviceId: currentId, restarted: true, healthy: false, error: msg });
|
||||||
|
|
||||||
|
// Abort chain — dependency didn't come back
|
||||||
|
this.emit('dependency-restart-failed', {
|
||||||
|
serviceId,
|
||||||
|
failedServiceId: currentId,
|
||||||
|
error: msg,
|
||||||
|
chain,
|
||||||
|
});
|
||||||
|
await this._notifyRestartResult(serviceId, false, chain, results, currentId);
|
||||||
|
return { success: false, chain, results };
|
||||||
|
}
|
||||||
|
|
||||||
|
this._log.info('dependency', `Service "${currentId}" is healthy after restart`);
|
||||||
|
results.push({ serviceId: currentId, restarted: true, healthy: true });
|
||||||
|
} catch (err) {
|
||||||
|
const msg = err.message || 'Unknown error during restart';
|
||||||
|
this._log.error('dependency', `Failed to restart service "${currentId}"`, {
|
||||||
|
error: msg,
|
||||||
|
});
|
||||||
|
results.push({ serviceId: currentId, restarted: false, error: msg });
|
||||||
|
|
||||||
|
this.emit('dependency-restart-failed', {
|
||||||
|
serviceId,
|
||||||
|
failedServiceId: currentId,
|
||||||
|
error: msg,
|
||||||
|
chain,
|
||||||
|
});
|
||||||
|
await this._notifyRestartResult(serviceId, false, chain, results, currentId);
|
||||||
|
return { success: false, chain, results };
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
this.emit('dependency-restart-complete', { serviceId, chain, results });
|
||||||
|
await this._notifyRestartResult(serviceId, true, chain, results);
|
||||||
|
return { success: true, chain, results };
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Send a notification about the restart result.
|
||||||
|
*
|
||||||
|
* @private
|
||||||
|
* @param {string} serviceId
|
||||||
|
* @param {boolean} success
|
||||||
|
* @param {string[]} chain
|
||||||
|
* @param {Array} results
|
||||||
|
* @param {string} [failedServiceId]
|
||||||
|
*/
|
||||||
|
async _notifyRestartResult(serviceId, success, chain, results, failedServiceId) {
|
||||||
|
if (!this._notification) return;
|
||||||
|
|
||||||
|
try {
|
||||||
|
if (success) {
|
||||||
|
await this._notification.send('dependency-restart-complete', {
|
||||||
|
text: `✅ Dependency restart chain completed for "${serviceId}". Restarted: ${chain.join(' → ')}`,
|
||||||
|
serviceId,
|
||||||
|
chain,
|
||||||
|
results,
|
||||||
|
});
|
||||||
|
} else {
|
||||||
|
await this._notification.send('dependency-restart-failed', {
|
||||||
|
text: `❌ Dependency restart chain failed for "${serviceId}" at "${failedServiceId}". Chain: ${chain.join(' → ')}`,
|
||||||
|
serviceId,
|
||||||
|
failedServiceId,
|
||||||
|
chain,
|
||||||
|
results,
|
||||||
|
});
|
||||||
|
}
|
||||||
|
} catch (err) {
|
||||||
|
this._log.error('dependency', 'Failed to send restart notification', {
|
||||||
|
error: err.message,
|
||||||
|
});
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
module.exports = DependencyManager;
|
||||||
@@ -0,0 +1,273 @@
|
|||||||
|
/**
|
||||||
|
* DNS Propagation Checker
|
||||||
|
* Verifies DNS record propagation by querying multiple resolvers.
|
||||||
|
* Runs as background jobs with configurable timeout and interval.
|
||||||
|
*
|
||||||
|
* @module dns-propagation
|
||||||
|
*/
|
||||||
|
|
||||||
|
const dns = require('dns').promises;
|
||||||
|
const EventEmitter = require('events');
|
||||||
|
|
||||||
|
/** Default verification options */
|
||||||
|
const DEFAULT_OPTIONS = {
|
||||||
|
timeout: 300000, // 5 minutes
|
||||||
|
interval: 10000, // 10 seconds
|
||||||
|
resolvers: ['1.1.1.1', '8.8.8.8', '9.9.9.9']
|
||||||
|
};
|
||||||
|
|
||||||
|
/** Maximum age for stored verification results (1 hour) */
|
||||||
|
const MAX_RESULT_AGE_MS = 3600000;
|
||||||
|
|
||||||
|
class DNSPropagationChecker extends EventEmitter {
|
||||||
|
/**
|
||||||
|
* Create a DNSPropagationChecker instance.
|
||||||
|
* @param {Object} ctx - Shared application context
|
||||||
|
* @param {Object} ctx.notification - NotificationManager instance
|
||||||
|
* @param {Object} ctx.log - Logger instance
|
||||||
|
*/
|
||||||
|
constructor(ctx) {
|
||||||
|
super();
|
||||||
|
this.ctx = ctx;
|
||||||
|
this.log = ctx.log || console;
|
||||||
|
|
||||||
|
/** @type {Map<string, Object>} domain → verification status */
|
||||||
|
this.verifications = new Map();
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Verify that a DNS record has propagated by querying multiple resolvers.
|
||||||
|
* Retries every `interval` ms until `timeout` is reached.
|
||||||
|
*
|
||||||
|
* @param {string} domain - The domain to check (e.g., 'test.sami')
|
||||||
|
* @param {string} expectedIp - The expected IP address
|
||||||
|
* @param {Object} [options={}] - Verification options
|
||||||
|
* @param {number} [options.timeout=300000] - Maximum time to wait (ms)
|
||||||
|
* @param {number} [options.interval=10000] - Time between retries (ms)
|
||||||
|
* @param {string[]} [options.resolvers] - DNS resolvers to query
|
||||||
|
* @returns {Promise<Object>} Verification result
|
||||||
|
*/
|
||||||
|
async verifyRecord(domain, expectedIp, options = {}) {
|
||||||
|
const startTime = Date.now();
|
||||||
|
const {
|
||||||
|
timeout = DEFAULT_OPTIONS.timeout,
|
||||||
|
interval = DEFAULT_OPTIONS.interval,
|
||||||
|
resolvers = DEFAULT_OPTIONS.resolvers
|
||||||
|
} = options;
|
||||||
|
|
||||||
|
const allResults = [];
|
||||||
|
let propagated = false;
|
||||||
|
|
||||||
|
while (Date.now() - startTime < timeout) {
|
||||||
|
const roundResults = [];
|
||||||
|
|
||||||
|
for (const resolver of resolvers) {
|
||||||
|
const checkStart = Date.now();
|
||||||
|
try {
|
||||||
|
// Use dns.resolve4 with a custom resolver
|
||||||
|
const resolverInstance = new dns.Resolver();
|
||||||
|
resolverInstance.setServers([resolver]);
|
||||||
|
resolverInstance.setTimeout(5000);
|
||||||
|
|
||||||
|
const addresses = await resolverInstance.resolve4(domain);
|
||||||
|
const matched = addresses.includes(expectedIp);
|
||||||
|
|
||||||
|
const result = {
|
||||||
|
resolver,
|
||||||
|
ips: addresses,
|
||||||
|
matched,
|
||||||
|
checkedAt: new Date().toISOString(),
|
||||||
|
responseTime: Date.now() - checkStart
|
||||||
|
};
|
||||||
|
|
||||||
|
roundResults.push(result);
|
||||||
|
|
||||||
|
if (matched) {
|
||||||
|
propagated = true;
|
||||||
|
}
|
||||||
|
} catch (err) {
|
||||||
|
roundResults.push({
|
||||||
|
resolver,
|
||||||
|
ips: [],
|
||||||
|
matched: false,
|
||||||
|
checkedAt: new Date().toISOString(),
|
||||||
|
error: err.code || err.message,
|
||||||
|
responseTime: Date.now() - checkStart
|
||||||
|
});
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
allResults.push(...roundResults);
|
||||||
|
|
||||||
|
// Emit progress event
|
||||||
|
this.emit('propagation-check', {
|
||||||
|
domain,
|
||||||
|
expectedIp,
|
||||||
|
roundResults,
|
||||||
|
elapsed: Date.now() - startTime,
|
||||||
|
propagated
|
||||||
|
});
|
||||||
|
|
||||||
|
if (propagated) {
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
|
||||||
|
// Wait before next attempt
|
||||||
|
await new Promise(resolve => setTimeout(resolve, interval));
|
||||||
|
}
|
||||||
|
|
||||||
|
const totalTime = Date.now() - startTime;
|
||||||
|
|
||||||
|
return {
|
||||||
|
domain,
|
||||||
|
expectedIp,
|
||||||
|
propagated,
|
||||||
|
results: allResults,
|
||||||
|
totalTime,
|
||||||
|
checkedAt: new Date().toISOString()
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Start a background DNS propagation verification.
|
||||||
|
* Does not block — returns immediately with the job reference.
|
||||||
|
*
|
||||||
|
* @param {string} domain - The domain to verify
|
||||||
|
* @param {string} expectedIp - The expected IP address
|
||||||
|
* @param {Object} [options={}] - Verification options
|
||||||
|
* @returns {Object} Job status object
|
||||||
|
*/
|
||||||
|
startVerification(domain, expectedIp, options = {}) {
|
||||||
|
// If there's already a running verification for this domain, return it
|
||||||
|
const existing = this.verifications.get(domain);
|
||||||
|
if (existing && existing.status === 'running') {
|
||||||
|
return existing;
|
||||||
|
}
|
||||||
|
|
||||||
|
const job = {
|
||||||
|
domain,
|
||||||
|
expectedIp,
|
||||||
|
status: 'running',
|
||||||
|
startedAt: new Date().toISOString(),
|
||||||
|
progress: [],
|
||||||
|
result: null
|
||||||
|
};
|
||||||
|
|
||||||
|
this.verifications.set(domain, job);
|
||||||
|
|
||||||
|
// Run verification in background (non-blocking)
|
||||||
|
this.verifyRecord(domain, expectedIp, options)
|
||||||
|
.then(result => {
|
||||||
|
job.status = 'completed';
|
||||||
|
job.result = result;
|
||||||
|
job.completedAt = new Date().toISOString();
|
||||||
|
|
||||||
|
if (result.propagated) {
|
||||||
|
this.emit('propagation-complete', result);
|
||||||
|
|
||||||
|
if (this.ctx.notification) {
|
||||||
|
this.ctx.notification.send('dns-propagation', {
|
||||||
|
text: `✅ DNS record for ${domain} propagated successfully to ${expectedIp}`,
|
||||||
|
domain,
|
||||||
|
expectedIp,
|
||||||
|
totalTime: result.totalTime
|
||||||
|
}, 'success').catch(err => {
|
||||||
|
this.log.error('dns-propagation', 'Failed to send propagation notification', {
|
||||||
|
error: err.message
|
||||||
|
});
|
||||||
|
});
|
||||||
|
}
|
||||||
|
} else {
|
||||||
|
this.emit('propagation-timeout', result);
|
||||||
|
|
||||||
|
if (this.ctx.notification) {
|
||||||
|
this.ctx.notification.send('dns-propagation', {
|
||||||
|
text: `⏱️ DNS propagation timeout for ${domain} — expected ${expectedIp} not found after ${Math.round(result.totalTime / 1000)}s`,
|
||||||
|
domain,
|
||||||
|
expectedIp,
|
||||||
|
totalTime: result.totalTime
|
||||||
|
}, 'warning').catch(err => {
|
||||||
|
this.log.error('dns-propagation', 'Failed to send timeout notification', {
|
||||||
|
error: err.message
|
||||||
|
});
|
||||||
|
});
|
||||||
|
}
|
||||||
|
}
|
||||||
|
})
|
||||||
|
.catch(err => {
|
||||||
|
job.status = 'error';
|
||||||
|
job.error = err.message;
|
||||||
|
job.completedAt = new Date().toISOString();
|
||||||
|
|
||||||
|
this.log.error('dns-propagation', `Verification failed for ${domain}`, {
|
||||||
|
error: err.message
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
return job;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Get the current verification status for a domain.
|
||||||
|
*
|
||||||
|
* @param {string} domain - The domain to look up
|
||||||
|
* @returns {Object|null} Verification status or null if not found
|
||||||
|
*/
|
||||||
|
getVerificationStatus(domain) {
|
||||||
|
const job = this.verifications.get(domain);
|
||||||
|
if (!job) return null;
|
||||||
|
return {
|
||||||
|
domain: job.domain,
|
||||||
|
expectedIp: job.expectedIp,
|
||||||
|
status: job.status,
|
||||||
|
startedAt: job.startedAt,
|
||||||
|
completedAt: job.completedAt || null,
|
||||||
|
result: job.result || null,
|
||||||
|
error: job.error || null
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Get all recent verifications.
|
||||||
|
*
|
||||||
|
* @returns {Object[]} Array of verification statuses
|
||||||
|
*/
|
||||||
|
getAllVerifications() {
|
||||||
|
const results = [];
|
||||||
|
for (const [domain, job] of this.verifications.entries()) {
|
||||||
|
results.push({
|
||||||
|
domain,
|
||||||
|
expectedIp: job.expectedIp,
|
||||||
|
status: job.status,
|
||||||
|
startedAt: job.startedAt,
|
||||||
|
completedAt: job.completedAt || null,
|
||||||
|
propagated: job.result?.propagated || null,
|
||||||
|
totalTime: job.result?.totalTime || null,
|
||||||
|
error: job.error || null
|
||||||
|
});
|
||||||
|
}
|
||||||
|
return results;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Remove verifications older than 1 hour.
|
||||||
|
*/
|
||||||
|
cleanup() {
|
||||||
|
const now = Date.now();
|
||||||
|
for (const [domain, job] of this.verifications.entries()) {
|
||||||
|
const completedAt = job.completedAt ? new Date(job.completedAt).getTime() : null;
|
||||||
|
const startedAt = new Date(job.startedAt).getTime();
|
||||||
|
|
||||||
|
// Clean up completed/error jobs older than 1 hour
|
||||||
|
// Also clean up stale running jobs that started over 2 hours ago
|
||||||
|
const age = completedAt ? (now - completedAt) : (now - startedAt);
|
||||||
|
const maxAge = job.status === 'running' ? MAX_RESULT_AGE_MS * 2 : MAX_RESULT_AGE_MS;
|
||||||
|
|
||||||
|
if (age > maxAge) {
|
||||||
|
this.verifications.delete(domain);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
module.exports = DNSPropagationChecker;
|
||||||
@@ -0,0 +1,69 @@
|
|||||||
|
/**
|
||||||
|
* Base DNS Provider Adapter
|
||||||
|
* All DNS provider adapters must extend this class and implement the required methods.
|
||||||
|
*
|
||||||
|
* Each adapter handles the specifics of talking to a particular DNS provider's API.
|
||||||
|
* The routes layer calls these methods generically — no provider-specific logic in routes.
|
||||||
|
*/
|
||||||
|
class BaseDNSProvider {
|
||||||
|
constructor(config, ctx) {
|
||||||
|
this.config = config; // Provider-specific config (api token, server url, etc.)
|
||||||
|
this.ctx = ctx; // Shared app context (log, credentialManager, fetchT, etc.)
|
||||||
|
this.providerId = 'base';
|
||||||
|
this.displayName = 'Base DNS Provider';
|
||||||
|
}
|
||||||
|
|
||||||
|
/** Check if this provider supports a given capability */
|
||||||
|
supportsCapability(cap) {
|
||||||
|
// Capabilities: 'create-record', 'delete-record', 'resolve', 'list-records',
|
||||||
|
// 'logs', 'restart', 'update-check', 'credentials', 'zones'
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
/** Authenticate and return a token/session */
|
||||||
|
async authenticate() { throw new Error('Not implemented'); }
|
||||||
|
|
||||||
|
/** Create a DNS record */
|
||||||
|
async createRecord({ domain, zone, type, value, ttl, overwrite }) { throw new Error('Not implemented'); }
|
||||||
|
|
||||||
|
/** Delete a DNS record */
|
||||||
|
async deleteRecord({ domain, type, value }) { throw new Error('Not implemented'); }
|
||||||
|
|
||||||
|
/** Resolve/query existing records for a domain */
|
||||||
|
async resolveRecords({ domain, zone, type }) { throw new Error('Not implemented'); }
|
||||||
|
|
||||||
|
/** List all records in a zone */
|
||||||
|
async listRecords({ zone }) { throw new Error('Not implemented'); }
|
||||||
|
|
||||||
|
/** Get DNS query logs */
|
||||||
|
async getLogs({ limit, server }) { throw new Error('Not implemented'); }
|
||||||
|
|
||||||
|
/** Restart the DNS server */
|
||||||
|
async restartServer({ server }) { throw new Error('Not implemented'); }
|
||||||
|
|
||||||
|
/** Check for DNS server updates */
|
||||||
|
async checkUpdate({ server }) { throw new Error('Not implemented'); }
|
||||||
|
|
||||||
|
/** Get provider status info */
|
||||||
|
async getStatus() {
|
||||||
|
return {
|
||||||
|
providerId: this.providerId,
|
||||||
|
displayName: this.displayName,
|
||||||
|
capabilities: this.getCapabilities(),
|
||||||
|
authenticated: false
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
/** Get list of supported capabilities */
|
||||||
|
getCapabilities() {
|
||||||
|
return [];
|
||||||
|
}
|
||||||
|
|
||||||
|
/** Validate provider-specific config */
|
||||||
|
validateConfig() { return { valid: true, errors: [] }; }
|
||||||
|
|
||||||
|
/** Clean up resources on shutdown */
|
||||||
|
async shutdown() {}
|
||||||
|
}
|
||||||
|
|
||||||
|
module.exports = BaseDNSProvider;
|
||||||
@@ -0,0 +1,269 @@
|
|||||||
|
/**
|
||||||
|
* Cloudflare DNS Provider Adapter
|
||||||
|
* Manages DNS records via the Cloudflare API v4.
|
||||||
|
*/
|
||||||
|
const BaseDNSProvider = require('./base');
|
||||||
|
|
||||||
|
const CF_API_BASE = 'https://api.cloudflare.com/client/v4';
|
||||||
|
|
||||||
|
class CloudflareDNSProvider extends BaseDNSProvider {
|
||||||
|
constructor(config, ctx) {
|
||||||
|
super(config, ctx);
|
||||||
|
this.providerId = 'cloudflare';
|
||||||
|
this.displayName = 'Cloudflare DNS';
|
||||||
|
|
||||||
|
// Resolve API token: explicit config takes priority, then credential manager
|
||||||
|
this.apiToken = config.apiToken
|
||||||
|
|| (ctx.credentialManager && ctx.credentialManager.get('dns.cloudflare.apiToken'))
|
||||||
|
|| null;
|
||||||
|
this.zoneId = config.zoneId || null;
|
||||||
|
this.domain = config.domain || null;
|
||||||
|
}
|
||||||
|
|
||||||
|
// ── Helpers ────────────────────────────────────────────────────────────
|
||||||
|
|
||||||
|
/** Build common request headers for Cloudflare API calls */
|
||||||
|
_headers() {
|
||||||
|
return {
|
||||||
|
'Authorization': `Bearer ${this.apiToken}`,
|
||||||
|
'Content-Type': 'application/json',
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
/** Make an authenticated request to the Cloudflare API */
|
||||||
|
async _cfRequest(method, path, body) {
|
||||||
|
const url = `${CF_API_BASE}${path}`;
|
||||||
|
const opts = {
|
||||||
|
method,
|
||||||
|
headers: this._headers(),
|
||||||
|
};
|
||||||
|
if (body !== undefined) {
|
||||||
|
opts.body = JSON.stringify(body);
|
||||||
|
}
|
||||||
|
return this.ctx.fetchT(url, opts);
|
||||||
|
}
|
||||||
|
|
||||||
|
/** Map a Cloudflare DNS record to the normalised format expected by routes */
|
||||||
|
_mapRecord(rec) {
|
||||||
|
return {
|
||||||
|
id: rec.id,
|
||||||
|
type: rec.type,
|
||||||
|
name: rec.name,
|
||||||
|
value: rec.content,
|
||||||
|
ttl: rec.ttl,
|
||||||
|
proxied: rec.proxied || false,
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
// ── Capabilities ───────────────────────────────────────────────────────
|
||||||
|
|
||||||
|
supportsCapability(cap) {
|
||||||
|
return this.getCapabilities().includes(cap);
|
||||||
|
}
|
||||||
|
|
||||||
|
getCapabilities() {
|
||||||
|
return ['create-record', 'delete-record', 'resolve', 'list-records', 'credentials', 'zones'];
|
||||||
|
}
|
||||||
|
|
||||||
|
// ── Authentication ─────────────────────────────────────────────────────
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Validate the API token by calling the Cloudflare verify endpoint.
|
||||||
|
* Stores basic zone info on success.
|
||||||
|
*/
|
||||||
|
async authenticate() {
|
||||||
|
this.ctx.log('[cloudflare] Authenticating – verifying API token…');
|
||||||
|
|
||||||
|
if (!this.apiToken) {
|
||||||
|
return { status: 'error', message: 'No Cloudflare API token provided' };
|
||||||
|
}
|
||||||
|
|
||||||
|
const res = await this._cfRequest('GET', '/user/tokens/verify');
|
||||||
|
const data = await res.json();
|
||||||
|
|
||||||
|
if (!data.success) {
|
||||||
|
const msg = (data.errors && data.errors[0] && data.errors[0].message) || 'Token verification failed';
|
||||||
|
this.ctx.log(`[cloudflare] Authentication failed: ${msg}`);
|
||||||
|
return { status: 'error', message: msg };
|
||||||
|
}
|
||||||
|
|
||||||
|
this.ctx.log(`[cloudflare] Token verified for status "${data.status}"`);
|
||||||
|
|
||||||
|
// Optionally fetch zone info if zoneId is configured
|
||||||
|
if (this.zoneId) {
|
||||||
|
try {
|
||||||
|
const zoneRes = await this._cfRequest('GET', `/zones/${this.zoneId}`);
|
||||||
|
const zoneData = await zoneRes.json();
|
||||||
|
if (zoneData.success && zoneData.result) {
|
||||||
|
this.zoneInfo = zoneData.result;
|
||||||
|
this.ctx.log(`[cloudflare] Zone loaded: ${zoneData.result.name} (${zoneData.result.id})`);
|
||||||
|
}
|
||||||
|
} catch (err) {
|
||||||
|
this.ctx.log(`[cloudflare] Could not fetch zone info: ${err.message}`);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return { status: 'ok', response: { status: data.status } };
|
||||||
|
}
|
||||||
|
|
||||||
|
// ── Create Record ──────────────────────────────────────────────────────
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Create a DNS record.
|
||||||
|
* If overwrite is true, first delete any existing record with the same name+type.
|
||||||
|
*/
|
||||||
|
async createRecord({ domain, zone, type, value, ttl, overwrite }) {
|
||||||
|
const targetDomain = domain || this.domain;
|
||||||
|
const targetZone = zone || this.zoneId;
|
||||||
|
|
||||||
|
if (!targetZone) {
|
||||||
|
return { status: 'error', message: 'No zone ID configured for Cloudflare' };
|
||||||
|
}
|
||||||
|
|
||||||
|
if (overwrite) {
|
||||||
|
this.ctx.log(`[cloudflare] Overwrite requested – deleting existing ${type} record for ${targetDomain}`);
|
||||||
|
try {
|
||||||
|
await this.deleteRecord({ domain: targetDomain, type, value });
|
||||||
|
} catch (err) {
|
||||||
|
this.ctx.log(`[cloudflare] No existing record to overwrite (or delete failed): ${err.message}`);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
const body = {
|
||||||
|
type,
|
||||||
|
name: targetDomain,
|
||||||
|
content: value,
|
||||||
|
ttl: ttl || 1, // 1 = automatic TTL in Cloudflare
|
||||||
|
proxied: false,
|
||||||
|
};
|
||||||
|
|
||||||
|
this.ctx.log(`[cloudflare] Creating ${type} record: ${targetDomain} → ${value}`);
|
||||||
|
const res = await this._cfRequest('POST', `/zones/${targetZone}/dns_records`, body);
|
||||||
|
const data = await res.json();
|
||||||
|
|
||||||
|
if (!data.success) {
|
||||||
|
const msg = (data.errors && data.errors[0] && data.errors[0].message) || 'Record creation failed';
|
||||||
|
this.ctx.log(`[cloudflare] Create failed: ${msg}`);
|
||||||
|
return { status: 'error', message: msg };
|
||||||
|
}
|
||||||
|
|
||||||
|
return { status: 'ok', response: { record: this._mapRecord(data.result) } };
|
||||||
|
}
|
||||||
|
|
||||||
|
// ── Delete Record ──────────────────────────────────────────────────────
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Delete DNS records matching domain+type.
|
||||||
|
* Lists matching records first, then deletes each one.
|
||||||
|
*/
|
||||||
|
async deleteRecord({ domain, type, value }) {
|
||||||
|
const targetDomain = domain || this.domain;
|
||||||
|
const targetZone = this.zoneId;
|
||||||
|
|
||||||
|
if (!targetZone) {
|
||||||
|
return { status: 'error', message: 'No zone ID configured for Cloudflare' };
|
||||||
|
}
|
||||||
|
|
||||||
|
// List records matching name + type
|
||||||
|
let queryPath = `/zones/${targetZone}/dns_records?name=${encodeURIComponent(targetDomain)}`;
|
||||||
|
if (type) {
|
||||||
|
queryPath += `&type=${encodeURIComponent(type)}`;
|
||||||
|
}
|
||||||
|
|
||||||
|
const listRes = await this._cfRequest('GET', queryPath);
|
||||||
|
const listData = await listRes.json();
|
||||||
|
|
||||||
|
if (!listData.success) {
|
||||||
|
const msg = (listData.errors && listData.errors[0] && listData.errors[0].message) || 'Failed to list records for deletion';
|
||||||
|
this.ctx.log(`[cloudflare] Delete – list failed: ${msg}`);
|
||||||
|
return { status: 'error', message: msg };
|
||||||
|
}
|
||||||
|
|
||||||
|
const matching = listData.result || [];
|
||||||
|
if (matching.length === 0) {
|
||||||
|
this.ctx.log(`[cloudflare] No records found for ${targetDomain} (${type || 'any type'})`);
|
||||||
|
return { status: 'ok', response: { deleted: 0 } };
|
||||||
|
}
|
||||||
|
|
||||||
|
// If a specific value is given, only delete records matching that value
|
||||||
|
const toDelete = value
|
||||||
|
? matching.filter((r) => r.content === value)
|
||||||
|
: matching;
|
||||||
|
|
||||||
|
let deleted = 0;
|
||||||
|
for (const record of toDelete) {
|
||||||
|
const delRes = await this._cfRequest('DELETE', `/zones/${targetZone}/dns_records/${record.id}`);
|
||||||
|
const delData = await delRes.json();
|
||||||
|
if (delData.success) {
|
||||||
|
deleted++;
|
||||||
|
this.ctx.log(`[cloudflare] Deleted record ${record.id} (${record.type} ${record.name})`);
|
||||||
|
} else {
|
||||||
|
const msg = (delData.errors && delData.errors[0] && delData.errors[0].message) || 'Delete failed';
|
||||||
|
this.ctx.log(`[cloudflare] Failed to delete record ${record.id}: ${msg}`);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return { status: 'ok', response: { deleted } };
|
||||||
|
}
|
||||||
|
|
||||||
|
// ── Resolve Records ───────────────────────────────────────────────────
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Resolve/query existing records for a domain.
|
||||||
|
* Returns records matching domain (and optionally type).
|
||||||
|
*/
|
||||||
|
async resolveRecords({ domain, zone, type }) {
|
||||||
|
const targetDomain = domain || this.domain;
|
||||||
|
const targetZone = zone || this.zoneId;
|
||||||
|
|
||||||
|
if (!targetZone) {
|
||||||
|
return { status: 'error', message: 'No zone ID configured for Cloudflare' };
|
||||||
|
}
|
||||||
|
|
||||||
|
let queryPath = `/zones/${targetZone}/dns_records?name=${encodeURIComponent(targetDomain)}`;
|
||||||
|
if (type) {
|
||||||
|
queryPath += `&type=${encodeURIComponent(type)}`;
|
||||||
|
}
|
||||||
|
|
||||||
|
this.ctx.log(`[cloudflare] Resolving records for ${targetDomain}${type ? ` (${type})` : ''}`);
|
||||||
|
const res = await this._cfRequest('GET', queryPath);
|
||||||
|
const data = await res.json();
|
||||||
|
|
||||||
|
if (!data.success) {
|
||||||
|
const msg = (data.errors && data.errors[0] && data.errors[0].message) || 'Resolve failed';
|
||||||
|
this.ctx.log(`[cloudflare] Resolve failed: ${msg}`);
|
||||||
|
return { status: 'error', message: msg };
|
||||||
|
}
|
||||||
|
|
||||||
|
const records = (data.result || []).map(this._mapRecord);
|
||||||
|
return { status: 'ok', response: { records } };
|
||||||
|
}
|
||||||
|
|
||||||
|
// ── List Records ───────────────────────────────────────────────────────
|
||||||
|
|
||||||
|
/**
|
||||||
|
* List all DNS records in a zone.
|
||||||
|
*/
|
||||||
|
async listRecords({ zone }) {
|
||||||
|
const targetZone = zone || this.zoneId;
|
||||||
|
|
||||||
|
if (!targetZone) {
|
||||||
|
return { status: 'error', message: 'No zone ID configured for Cloudflare' };
|
||||||
|
}
|
||||||
|
|
||||||
|
this.ctx.log(`[cloudflare] Listing all records in zone ${targetZone}`);
|
||||||
|
const res = await this._cfRequest('GET', `/zones/${targetZone}/dns_records`);
|
||||||
|
const data = await res.json();
|
||||||
|
|
||||||
|
if (!data.success) {
|
||||||
|
const msg = (data.errors && data.errors[0] && data.errors[0].message) || 'List failed';
|
||||||
|
this.ctx.log(`[cloudflare] List failed: ${msg}`);
|
||||||
|
return { status: 'error', message: msg };
|
||||||
|
}
|
||||||
|
|
||||||
|
const records = (data.result || []).map(this._mapRecord);
|
||||||
|
return { status: 'ok', response: { records } };
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
module.exports = CloudflareDNSProvider;
|
||||||
@@ -0,0 +1,93 @@
|
|||||||
|
/**
|
||||||
|
* Manual DNS Provider Adapter
|
||||||
|
* No-op adapter for users who manage DNS externally (manual, cPanel, other control panels).
|
||||||
|
* Provides propagation checking only — all record operations return helpful instructions.
|
||||||
|
*/
|
||||||
|
const BaseDNSProvider = require('./base');
|
||||||
|
|
||||||
|
class ManualDNSProvider extends BaseDNSProvider {
|
||||||
|
constructor(config, ctx) {
|
||||||
|
super(config, ctx);
|
||||||
|
this.providerId = 'manual';
|
||||||
|
this.displayName = 'Manual / External DNS';
|
||||||
|
this.description = 'Manage DNS records yourself via your provider\'s control panel';
|
||||||
|
}
|
||||||
|
|
||||||
|
supportsCapability(cap) {
|
||||||
|
return ['credentials'].includes(cap);
|
||||||
|
}
|
||||||
|
|
||||||
|
getCapabilities() {
|
||||||
|
return ['credentials'];
|
||||||
|
}
|
||||||
|
|
||||||
|
async authenticate() {
|
||||||
|
return { success: true, message: 'Manual DNS — no authentication needed' };
|
||||||
|
}
|
||||||
|
|
||||||
|
async createRecord({ domain, zone, type, value, ttl }) {
|
||||||
|
return {
|
||||||
|
status: 'manual',
|
||||||
|
message: `Create this record manually in your DNS control panel:`,
|
||||||
|
instructions: {
|
||||||
|
name: domain,
|
||||||
|
type: type || 'A',
|
||||||
|
value,
|
||||||
|
ttl: ttl || 300
|
||||||
|
}
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
async deleteRecord({ domain, type, value }) {
|
||||||
|
return {
|
||||||
|
status: 'manual',
|
||||||
|
message: `Delete this record manually from your DNS control panel:`,
|
||||||
|
instructions: {
|
||||||
|
name: domain,
|
||||||
|
type: type || 'A',
|
||||||
|
value: value || '(any)'
|
||||||
|
}
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
async resolveRecords({ domain, zone, type }) {
|
||||||
|
// Use Node.js built-in DNS to resolve regardless of provider
|
||||||
|
const dns = require('dns').promises;
|
||||||
|
try {
|
||||||
|
const resolver = new dns.Resolver();
|
||||||
|
resolver.setServers(['1.1.1.1', '8.8.8.8']);
|
||||||
|
const records = await resolver.resolve(domain, type || 'A');
|
||||||
|
return {
|
||||||
|
status: 'ok',
|
||||||
|
response: {
|
||||||
|
records: records.map(r => ({
|
||||||
|
type: type || 'A',
|
||||||
|
domain,
|
||||||
|
rData: { ipAddress: r },
|
||||||
|
ttl: 0,
|
||||||
|
manual: true
|
||||||
|
}))
|
||||||
|
}
|
||||||
|
};
|
||||||
|
} catch (err) {
|
||||||
|
return { status: 'ok', response: { records: [] } };
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
async getStatus() {
|
||||||
|
return {
|
||||||
|
providerId: this.providerId,
|
||||||
|
displayName: this.displayName,
|
||||||
|
description: this.description,
|
||||||
|
capabilities: this.getCapabilities(),
|
||||||
|
authenticated: true,
|
||||||
|
note: 'DNS records are managed externally. Use propagation checks to verify changes.'
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
validateConfig() {
|
||||||
|
return { valid: true, errors: [] };
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
module.exports = ManualDNSProvider;
|
||||||
@@ -0,0 +1,101 @@
|
|||||||
|
/**
|
||||||
|
* DNS Provider Registry
|
||||||
|
* Manages available DNS provider adapters.
|
||||||
|
* Providers register themselves, and the active provider is selected by config.
|
||||||
|
*/
|
||||||
|
const path = require('path');
|
||||||
|
|
||||||
|
class DNSProviderRegistry {
|
||||||
|
constructor() {
|
||||||
|
this.providers = new Map(); // providerId -> adapter class
|
||||||
|
this.instances = new Map(); // providerId -> adapter instance
|
||||||
|
}
|
||||||
|
|
||||||
|
/** Register a provider adapter class */
|
||||||
|
register(adapterClass) {
|
||||||
|
const instance = new adapterClass({}, {});
|
||||||
|
const id = instance.providerId;
|
||||||
|
if (this.providers.has(id)) {
|
||||||
|
console.warn(`DNS provider "${id}" already registered, overwriting`);
|
||||||
|
}
|
||||||
|
this.providers.set(id, adapterClass);
|
||||||
|
}
|
||||||
|
|
||||||
|
/** Get list of all registered provider IDs */
|
||||||
|
getProviderIds() {
|
||||||
|
return Array.from(this.providers.keys());
|
||||||
|
}
|
||||||
|
|
||||||
|
/** Get metadata for all providers (without instantiating with real config) */
|
||||||
|
getProviderMeta() {
|
||||||
|
return this.getProviderIds().map(id => {
|
||||||
|
const Adapter = this.providers.get(id);
|
||||||
|
const inst = new Adapter({}, {});
|
||||||
|
return {
|
||||||
|
id: inst.providerId,
|
||||||
|
displayName: inst.displayName,
|
||||||
|
capabilities: inst.getCapabilities()
|
||||||
|
};
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Get or create an adapter instance for the given provider + config
|
||||||
|
* @param {string} providerId - The provider to instantiate
|
||||||
|
* @param {Object} config - Provider-specific configuration
|
||||||
|
* @param {Object} ctx - Shared application context
|
||||||
|
* @returns {BaseDNSProvider} The provider adapter instance
|
||||||
|
*/
|
||||||
|
getProvider(providerId, config, ctx) {
|
||||||
|
// Re-create if config changed
|
||||||
|
const cacheKey = providerId;
|
||||||
|
const Adapter = this.providers.get(providerId);
|
||||||
|
if (!Adapter) {
|
||||||
|
throw new Error(`Unknown DNS provider: ${providerId}. Available: ${this.getProviderIds().join(', ')}`);
|
||||||
|
}
|
||||||
|
const instance = new Adapter(config, ctx);
|
||||||
|
this.instances.set(cacheKey, instance);
|
||||||
|
return instance;
|
||||||
|
}
|
||||||
|
|
||||||
|
/** Auto-discover and register all providers in this directory */
|
||||||
|
autoDiscover() {
|
||||||
|
const fs = require('fs');
|
||||||
|
const dir = __dirname;
|
||||||
|
const files = fs.readdirSync(dir).filter(f =>
|
||||||
|
f !== 'base.js' && f !== 'registry.js' && f.endsWith('.js') && !f.startsWith('.')
|
||||||
|
);
|
||||||
|
for (const file of files) {
|
||||||
|
try {
|
||||||
|
const Loaded = require(path.join(dir, file));
|
||||||
|
// Support: module.exports = Class, module.exports = { Class }, or plain objects
|
||||||
|
let cls = null;
|
||||||
|
if (typeof Loaded === 'function') {
|
||||||
|
cls = Loaded;
|
||||||
|
} else if (typeof Loaded === 'object' && Loaded !== null) {
|
||||||
|
// Try to find a class in the exported object
|
||||||
|
cls = Object.values(Loaded).find(v => typeof v === 'function');
|
||||||
|
}
|
||||||
|
if (cls) {
|
||||||
|
// Verify it has providerId (on prototype or set in constructor)
|
||||||
|
try {
|
||||||
|
const test = new cls({}, {});
|
||||||
|
if (test.providerId && typeof test.getCapabilities === 'function') {
|
||||||
|
this.register(cls);
|
||||||
|
}
|
||||||
|
} catch {
|
||||||
|
// Not a valid provider adapter, skip
|
||||||
|
}
|
||||||
|
}
|
||||||
|
} catch (err) {
|
||||||
|
console.error(`Failed to load DNS provider from ${file}:`, err.message);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// Singleton
|
||||||
|
const registry = new DNSProviderRegistry();
|
||||||
|
registry.autoDiscover();
|
||||||
|
|
||||||
|
module.exports = registry;
|
||||||
@@ -0,0 +1,383 @@
|
|||||||
|
/**
|
||||||
|
* RFC 2136 Dynamic DNS Provider Adapter
|
||||||
|
*
|
||||||
|
* Manages DNS records via RFC 2136 dynamic updates using the nsupdate CLI tool.
|
||||||
|
* Compatible with BIND, PowerDNS, Windows DNS, and any RFC 2136-compliant server.
|
||||||
|
*
|
||||||
|
* Capabilities: create-record, delete-record, resolve, credentials
|
||||||
|
* Not supported: logs, restart, update-check, list-records, zones
|
||||||
|
*/
|
||||||
|
|
||||||
|
const { execFile } = require('child_process');
|
||||||
|
const { promisify } = require('util');
|
||||||
|
const dns = require('dns');
|
||||||
|
const os = require('os');
|
||||||
|
const path = require('path');
|
||||||
|
const fs = require('fs');
|
||||||
|
|
||||||
|
const execFileAsync = promisify(execFile);
|
||||||
|
|
||||||
|
const BaseDNSProvider = require('./base');
|
||||||
|
|
||||||
|
const CAPABILITIES = ['create-record', 'delete-record', 'resolve', 'credentials'];
|
||||||
|
|
||||||
|
const DEFAULT_PORT = 53;
|
||||||
|
const DEFAULT_TSIG_ALGORITHM = 'hmac-sha256';
|
||||||
|
const NSUPDATE_TIMEOUT_MS = 15000;
|
||||||
|
|
||||||
|
class RFC2136Provider extends BaseDNSProvider {
|
||||||
|
static providerId = 'rfc2136';
|
||||||
|
static displayName = 'RFC 2136 (Dynamic DNS)';
|
||||||
|
|
||||||
|
constructor(config, ctx) {
|
||||||
|
super(config, ctx);
|
||||||
|
|
||||||
|
this.providerId = 'rfc2136';
|
||||||
|
this.displayName = 'RFC 2136 (Dynamic DNS)';
|
||||||
|
|
||||||
|
// Core config
|
||||||
|
this.server = config.server || null;
|
||||||
|
this.port = config.port || DEFAULT_PORT;
|
||||||
|
this.zone = config.zone || null;
|
||||||
|
|
||||||
|
// TSIG authentication
|
||||||
|
this.tsigAlgorithm = config.tsigAlgorithm || DEFAULT_TSIG_ALGORITHM;
|
||||||
|
this.tsigKeyName = config.tsigKeyName || null;
|
||||||
|
this.tsigSecret = config.tsigSecret || null;
|
||||||
|
|
||||||
|
// Resolve credentials from credential manager if available
|
||||||
|
if (ctx && ctx.credentialManager) {
|
||||||
|
if (!this.tsigKeyName && ctx.credentialManager.get) {
|
||||||
|
this.tsigKeyName = ctx.credentialManager.get('rfc2136_tsigKeyName') || null;
|
||||||
|
}
|
||||||
|
if (!this.tsigSecret && ctx.credentialManager.get) {
|
||||||
|
this.tsigSecret = ctx.credentialManager.get('rfc2136_tsigSecret') || null;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// Logger shorthand
|
||||||
|
this._log = ctx && ctx.log ? ctx.ctx : null;
|
||||||
|
}
|
||||||
|
|
||||||
|
// ── Logging helper ────────────────────────────────────────────────────────
|
||||||
|
|
||||||
|
_log(level, message, meta) {
|
||||||
|
if (this.ctx && this.ctx.log && typeof this.ctx.log[level] === 'function') {
|
||||||
|
this.ctx.log[level](`[rfc2136] ${message}`, meta || {});
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// ── Capabilities ──────────────────────────────────────────────────────────
|
||||||
|
|
||||||
|
supportsCapability(cap) {
|
||||||
|
return CAPABILITIES.includes(cap);
|
||||||
|
}
|
||||||
|
|
||||||
|
getCapabilities() {
|
||||||
|
return [...CAPABILITIES];
|
||||||
|
}
|
||||||
|
|
||||||
|
// ── Config validation ─────────────────────────────────────────────────────
|
||||||
|
|
||||||
|
validateConfig() {
|
||||||
|
const errors = [];
|
||||||
|
if (!this.server) errors.push('Missing required config: server');
|
||||||
|
if (!this.zone) errors.push('Missing required config: zone');
|
||||||
|
return { valid: errors.length === 0, errors };
|
||||||
|
}
|
||||||
|
|
||||||
|
// ── Helpers ───────────────────────────────────────────────────────────────
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Ensure a domain name ends with a trailing dot (FQDN for nsupdate).
|
||||||
|
*/
|
||||||
|
_ensureFqdn(domain) {
|
||||||
|
if (!domain) return domain;
|
||||||
|
return domain.endsWith('.') ? domain : `${domain}.`;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Build the common nsupdate header lines (server, zone, key).
|
||||||
|
*/
|
||||||
|
_buildHeader() {
|
||||||
|
const lines = [];
|
||||||
|
lines.push(`server ${this.server} ${this.port}`);
|
||||||
|
lines.push(`zone ${this.zone}`);
|
||||||
|
|
||||||
|
if (this.tsigKeyName && this.tsigSecret) {
|
||||||
|
lines.push(`key ${this.tsigAlgorithm}:${this.tsigKeyName} ${this.tsigSecret}`);
|
||||||
|
}
|
||||||
|
|
||||||
|
return lines;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Execute an nsupdate script and return { stdout, stderr }.
|
||||||
|
* Writes commands to a temporary file and runs `nsupdate <file>`.
|
||||||
|
*/
|
||||||
|
async _runNsupdate(commands) {
|
||||||
|
const script = commands.join('\n') + '\n';
|
||||||
|
const tmpFile = path.join(os.tmpdir(), `nsupdate-${Date.now()}-${Math.random().toString(36).slice(2, 8)}.cmd`);
|
||||||
|
|
||||||
|
try {
|
||||||
|
await fs.promises.writeFile(tmpFile, script, { mode: 0o600 });
|
||||||
|
this._log('debug', `Executing nsupdate script`, { script: script.trim() });
|
||||||
|
|
||||||
|
const { stdout, stderr } = await execFileAsync('nsupdate', [tmpFile], {
|
||||||
|
timeout: NSUPDATE_TIMEOUT_MS,
|
||||||
|
maxBuffer: 1024 * 1024,
|
||||||
|
});
|
||||||
|
|
||||||
|
this._log('debug', 'nsupdate completed', { stdout: (stdout || '').trim(), stderr: (stderr || '').trim() });
|
||||||
|
|
||||||
|
if (stderr && stderr.toLowerCase().includes('refused')) {
|
||||||
|
throw new Error(`nsupdate refused: ${stderr.trim()}`);
|
||||||
|
}
|
||||||
|
if (stderr && stderr.toLowerCase().includes('failed')) {
|
||||||
|
throw new Error(`nsupdate failed: ${stderr.trim()}`);
|
||||||
|
}
|
||||||
|
|
||||||
|
return { stdout: (stdout || '').trim(), stderr: (stderr || '').trim() };
|
||||||
|
} catch (err) {
|
||||||
|
if (err.code === 'ENOENT') {
|
||||||
|
throw new Error('nsupdate command not found. Install bind9utils (Debian/Ubuntu) or bind-utils (RHEL/CentOS).');
|
||||||
|
}
|
||||||
|
throw err;
|
||||||
|
} finally {
|
||||||
|
try { await fs.promises.unlink(tmpFile); } catch (_) { /* ignore */ }
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// ── Authenticate ──────────────────────────────────────────────────────────
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Verify nsupdate is available and optionally test connectivity.
|
||||||
|
* Runs a minimal nsupdate with just "show" (no-op) to confirm the tool works.
|
||||||
|
*/
|
||||||
|
async authenticate() {
|
||||||
|
const validation = this.validateConfig();
|
||||||
|
if (!validation.valid) {
|
||||||
|
throw new Error(`RFC 2136 config invalid: ${validation.errors.join('; ')}`);
|
||||||
|
}
|
||||||
|
|
||||||
|
// Check nsupdate binary is available with a dry-run command set
|
||||||
|
const commands = [
|
||||||
|
...this._buildHeader(),
|
||||||
|
'show',
|
||||||
|
];
|
||||||
|
|
||||||
|
try {
|
||||||
|
const { stdout } = await this._runNsupdate(commands);
|
||||||
|
this._log('info', 'Authenticated to RFC 2136 server', { server: this.server, port: this.port });
|
||||||
|
return { success: true, server: this.server, port: this.port };
|
||||||
|
} catch (err) {
|
||||||
|
this._log('error', 'Authentication test failed', { error: err.message });
|
||||||
|
// If nsupdate is missing, rethrow immediately
|
||||||
|
if (err.message.includes('not found')) throw err;
|
||||||
|
// Otherwise, the server might be unreachable but the tool works — return partial
|
||||||
|
return { success: false, error: err.message, server: this.server };
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// ── Create Record ─────────────────────────────────────────────────────────
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Create (add) a DNS record via RFC 2136 UPDATE.
|
||||||
|
*
|
||||||
|
* @param {Object} params
|
||||||
|
* @param {string} params.domain - Record name (e.g. "www.example.com")
|
||||||
|
* @param {string} params.zone - Zone name (overrides constructor zone)
|
||||||
|
* @param {string} params.type - Record type (A, AAAA, CNAME, TXT, etc.)
|
||||||
|
* @param {string} params.value - Record value
|
||||||
|
* @param {number} [params.ttl=300] - TTL in seconds
|
||||||
|
*/
|
||||||
|
async createRecord({ domain, zone, type, value, ttl }) {
|
||||||
|
const effectiveZone = zone || this.zone;
|
||||||
|
const effectiveTtl = ttl || 300;
|
||||||
|
const fqdn = this._ensureFqdn(domain);
|
||||||
|
|
||||||
|
const commands = [
|
||||||
|
`server ${this.server} ${this.port}`,
|
||||||
|
`zone ${effectiveZone}`,
|
||||||
|
];
|
||||||
|
|
||||||
|
if (this.tsigKeyName && this.tsigSecret) {
|
||||||
|
commands.push(`key ${this.tsigAlgorithm}:${this.tsigKeyName} ${this.tsigSecret}`);
|
||||||
|
}
|
||||||
|
|
||||||
|
commands.push(`update add ${fqdn} ${effectiveTtl} ${type} ${value}`);
|
||||||
|
commands.push('show');
|
||||||
|
commands.push('send');
|
||||||
|
|
||||||
|
this._log('info', 'Creating DNS record', { domain: fqdn, type, value, ttl: effectiveTtl });
|
||||||
|
|
||||||
|
const result = await this._runNsupdate(commands);
|
||||||
|
|
||||||
|
return {
|
||||||
|
success: true,
|
||||||
|
action: 'create-record',
|
||||||
|
domain: fqdn,
|
||||||
|
type,
|
||||||
|
value,
|
||||||
|
ttl: effectiveTtl,
|
||||||
|
zone: effectiveZone,
|
||||||
|
raw: result.stdout,
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
// ── Delete Record ─────────────────────────────────────────────────────────
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Delete a DNS record via RFC 2136 UPDATE.
|
||||||
|
*
|
||||||
|
* @param {Object} params
|
||||||
|
* @param {string} params.domain - Record name
|
||||||
|
* @param {string} params.type - Record type
|
||||||
|
* @param {string} [params.value] - Optional specific value to match
|
||||||
|
*/
|
||||||
|
async deleteRecord({ domain, type, value }) {
|
||||||
|
const effectiveZone = this.zone;
|
||||||
|
const fqdn = this._ensureFqdn(domain);
|
||||||
|
|
||||||
|
const commands = [
|
||||||
|
`server ${this.server} ${this.port}`,
|
||||||
|
`zone ${effectiveZone}`,
|
||||||
|
];
|
||||||
|
|
||||||
|
if (this.tsigKeyName && this.tsigSecret) {
|
||||||
|
commands.push(`key ${this.tsigAlgorithm}:${this.tsigKeyName} ${this.tsigSecret}`);
|
||||||
|
}
|
||||||
|
|
||||||
|
// "update delete" with value removes that specific RR;
|
||||||
|
// without value it removes all RRs of that type for the name.
|
||||||
|
const deleteClause = value
|
||||||
|
? `update delete ${fqdn} ${type} ${value}`
|
||||||
|
: `update delete ${fqdn} ${type}`;
|
||||||
|
|
||||||
|
commands.push(deleteClause);
|
||||||
|
commands.push('show');
|
||||||
|
commands.push('send');
|
||||||
|
|
||||||
|
this._log('info', 'Deleting DNS record', { domain: fqdn, type, value: value || '(all)' });
|
||||||
|
|
||||||
|
const result = await this._runNsupdate(commands);
|
||||||
|
|
||||||
|
return {
|
||||||
|
success: true,
|
||||||
|
action: 'delete-record',
|
||||||
|
domain: fqdn,
|
||||||
|
type,
|
||||||
|
value: value || null,
|
||||||
|
zone: effectiveZone,
|
||||||
|
raw: result.stdout,
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
// ── Resolve Records ───────────────────────────────────────────────────────
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Resolve DNS records for a domain.
|
||||||
|
* First attempts dig against the configured server, then falls back to Node dns module.
|
||||||
|
*
|
||||||
|
* @param {Object} params
|
||||||
|
* @param {string} params.domain - Domain to resolve
|
||||||
|
* @param {string} [params.zone] - Zone (unused for resolution, kept for interface consistency)
|
||||||
|
* @param {string} [params.type='A'] - Record type to query
|
||||||
|
*/
|
||||||
|
async resolveRecords({ domain, zone, type }) {
|
||||||
|
const queryType = type || 'A';
|
||||||
|
const fqdn = domain.endsWith('.') ? domain : domain;
|
||||||
|
|
||||||
|
// Strategy 1: Use dig against the configured RFC 2136 server
|
||||||
|
try {
|
||||||
|
const { stdout } = await execFileAsync('dig', [
|
||||||
|
`@${this.server}`,
|
||||||
|
'-p', String(this.port),
|
||||||
|
fqdn,
|
||||||
|
queryType,
|
||||||
|
'+short',
|
||||||
|
'+time=5',
|
||||||
|
'+tries=1',
|
||||||
|
], { timeout: 10000 });
|
||||||
|
|
||||||
|
const records = stdout
|
||||||
|
.split('\n')
|
||||||
|
.map(line => line.trim())
|
||||||
|
.filter(Boolean);
|
||||||
|
|
||||||
|
if (records.length > 0) {
|
||||||
|
this._log('debug', `Resolved ${fqdn} ${queryType} via dig`, { records });
|
||||||
|
return {
|
||||||
|
domain: fqdn,
|
||||||
|
type: queryType,
|
||||||
|
records: records.map(r => ({ value: r, type: queryType })),
|
||||||
|
source: 'dig',
|
||||||
|
server: this.server,
|
||||||
|
};
|
||||||
|
}
|
||||||
|
} catch (err) {
|
||||||
|
this._log('warn', 'dig resolution failed, falling back to Node dns', { error: err.message });
|
||||||
|
}
|
||||||
|
|
||||||
|
// Strategy 2: Fallback to Node.js built-in resolver
|
||||||
|
try {
|
||||||
|
const resolver = new dns.Resolver();
|
||||||
|
resolver.setServers([this.server]);
|
||||||
|
|
||||||
|
const resolveMethod = this._getResolveMethod(queryType);
|
||||||
|
const resolveAsync = promisify(resolver[resolveMethod]).bind(resolver);
|
||||||
|
|
||||||
|
const results = await resolveAsync(fqdn);
|
||||||
|
const records = Array.isArray(results) ? results : [results];
|
||||||
|
|
||||||
|
this._log('debug', `Resolved ${fqdn} ${queryType} via Node dns`, { records });
|
||||||
|
|
||||||
|
return {
|
||||||
|
domain: fqdn,
|
||||||
|
type: queryType,
|
||||||
|
records: records.map(r => ({ value: String(r), type: queryType })),
|
||||||
|
source: 'node-dns',
|
||||||
|
server: this.server,
|
||||||
|
};
|
||||||
|
} catch (err) {
|
||||||
|
this._log('warn', 'Node dns resolution also failed', { error: err.message });
|
||||||
|
return {
|
||||||
|
domain: fqdn,
|
||||||
|
type: queryType,
|
||||||
|
records: [],
|
||||||
|
source: 'none',
|
||||||
|
server: this.server,
|
||||||
|
error: err.message,
|
||||||
|
};
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Map record type to the Node dns resolver method name.
|
||||||
|
*/
|
||||||
|
_getResolveMethod(type) {
|
||||||
|
const map = {
|
||||||
|
A: 'resolve4',
|
||||||
|
AAAA: 'resolve6',
|
||||||
|
CNAME: 'resolveCname',
|
||||||
|
MX: 'resolveMx',
|
||||||
|
TXT: 'resolveTxt',
|
||||||
|
NS: 'resolveNs',
|
||||||
|
SOA: 'resolveSoa',
|
||||||
|
SRV: 'resolveSrv',
|
||||||
|
PTR: 'reverse',
|
||||||
|
};
|
||||||
|
return map[(type || '').toUpperCase()] || 'resolve4';
|
||||||
|
}
|
||||||
|
|
||||||
|
// ── Shutdown ──────────────────────────────────────────────────────────────
|
||||||
|
|
||||||
|
async shutdown() {
|
||||||
|
this._log('info', 'RFC 2136 provider shutting down');
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// Expose providerId on the prototype so the registry's auto-discover can detect it
|
||||||
|
RFC2136Provider.prototype.providerId = 'rfc2136';
|
||||||
|
|
||||||
|
module.exports = RFC2136Provider;
|
||||||
@@ -0,0 +1,507 @@
|
|||||||
|
/**
|
||||||
|
* Technitium DNS Server Provider Adapter
|
||||||
|
*
|
||||||
|
* Wraps Technitium-specific DNS logic into the standard adapter interface.
|
||||||
|
* Uses the Technitium HTTP API (default port 5380) for all operations.
|
||||||
|
*/
|
||||||
|
const BaseDNSProvider = require('./base');
|
||||||
|
|
||||||
|
const SESSION_TTL_MS = 24 * 60 * 60 * 1000; // 24-hour token lifetime
|
||||||
|
|
||||||
|
class TechnitiumDNSProvider extends BaseDNSProvider {
|
||||||
|
constructor(config, ctx) {
|
||||||
|
super(config, ctx);
|
||||||
|
this.providerId = 'technitium';
|
||||||
|
this.displayName = 'Technitium DNS Server';
|
||||||
|
|
||||||
|
this.serverIp = config.serverIp;
|
||||||
|
this.serverPort = config.serverPort || 5380;
|
||||||
|
this.dnsId = config.dnsId || null;
|
||||||
|
|
||||||
|
// Token state
|
||||||
|
this.token = null;
|
||||||
|
this.tokenExpiry = null;
|
||||||
|
}
|
||||||
|
|
||||||
|
// ---------------------------------------------------------------------------
|
||||||
|
// Capabilities
|
||||||
|
// ---------------------------------------------------------------------------
|
||||||
|
|
||||||
|
static CAPABILITIES = [
|
||||||
|
'create-record',
|
||||||
|
'delete-record',
|
||||||
|
'resolve',
|
||||||
|
'list-records',
|
||||||
|
'logs',
|
||||||
|
'restart',
|
||||||
|
'update-check',
|
||||||
|
'credentials',
|
||||||
|
'zones'
|
||||||
|
];
|
||||||
|
|
||||||
|
supportsCapability(cap) {
|
||||||
|
return TechnitiumDNSProvider.CAPABILITIES.includes(cap);
|
||||||
|
}
|
||||||
|
|
||||||
|
getCapabilities() {
|
||||||
|
return [...TechnitiumDNSProvider.CAPABILITIES];
|
||||||
|
}
|
||||||
|
|
||||||
|
// ---------------------------------------------------------------------------
|
||||||
|
// Helpers
|
||||||
|
// ---------------------------------------------------------------------------
|
||||||
|
|
||||||
|
/** Build the base URL for this server */
|
||||||
|
_baseUrl() {
|
||||||
|
return `http://${this.serverIp}:${this.serverPort}`;
|
||||||
|
}
|
||||||
|
|
||||||
|
/** Build a full API URL with query-string params */
|
||||||
|
_buildUrl(apiPath, params = {}) {
|
||||||
|
const qs = new URLSearchParams(params).toString();
|
||||||
|
return `${this._baseUrl()}${apiPath}${qs ? '?' + qs : ''}`;
|
||||||
|
}
|
||||||
|
|
||||||
|
/** Ensure we have a valid token; throws on failure */
|
||||||
|
async _requireToken() {
|
||||||
|
// Re-use existing token if still valid
|
||||||
|
if (this.token && this.tokenExpiry && new Date() < new Date(this.tokenExpiry)) {
|
||||||
|
return this.token;
|
||||||
|
}
|
||||||
|
const result = await this.authenticate();
|
||||||
|
if (!result.success) {
|
||||||
|
const err = new Error('No valid DNS token available. ' + (result.error || ''));
|
||||||
|
err.statusCode = 401;
|
||||||
|
throw err;
|
||||||
|
}
|
||||||
|
return this.token;
|
||||||
|
}
|
||||||
|
|
||||||
|
// ---------------------------------------------------------------------------
|
||||||
|
// Authentication
|
||||||
|
// ---------------------------------------------------------------------------
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Authenticate against the Technitium server.
|
||||||
|
* Checks per-server credentials first (dns.{dnsId}.readonly.username),
|
||||||
|
* then falls back to global credentials (dns.username).
|
||||||
|
*
|
||||||
|
* Stores token + expiry on success.
|
||||||
|
*/
|
||||||
|
async authenticate() {
|
||||||
|
const { credentialManager, log } = this.ctx;
|
||||||
|
|
||||||
|
// Try per-server credentials first
|
||||||
|
if (this.dnsId) {
|
||||||
|
for (const role of ['readonly', 'admin']) {
|
||||||
|
try {
|
||||||
|
const username = await credentialManager.retrieve(`dns.${this.dnsId}.${role}.username`);
|
||||||
|
const password = await credentialManager.retrieve(`dns.${this.dnsId}.${role}.password`);
|
||||||
|
if (username && password) {
|
||||||
|
const result = await this._doLogin(username, password);
|
||||||
|
if (result.success) return result;
|
||||||
|
}
|
||||||
|
} catch (err) {
|
||||||
|
log.error('technitium', `Per-server ${role} credential error`, {
|
||||||
|
dnsId: this.dnsId,
|
||||||
|
error: err.message
|
||||||
|
});
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// Fall back to global credentials
|
||||||
|
try {
|
||||||
|
const username = await credentialManager.retrieve('dns.username');
|
||||||
|
const password = await credentialManager.retrieve('dns.password');
|
||||||
|
if (username && password) {
|
||||||
|
return await this._doLogin(username, password);
|
||||||
|
}
|
||||||
|
} catch (err) {
|
||||||
|
log.error('technitium', 'Global credential error', { error: err.message });
|
||||||
|
}
|
||||||
|
|
||||||
|
return {
|
||||||
|
success: false,
|
||||||
|
error: 'No DNS credentials configured. Please set up credentials via /api/dns/credentials'
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Perform the actual login POST to Technitium.
|
||||||
|
* Stores token on success.
|
||||||
|
*/
|
||||||
|
async _doLogin(username, password) {
|
||||||
|
const { fetchT, log } = this.ctx;
|
||||||
|
|
||||||
|
try {
|
||||||
|
const params = new URLSearchParams({
|
||||||
|
user: username,
|
||||||
|
pass: password,
|
||||||
|
includeInfo: 'false'
|
||||||
|
});
|
||||||
|
|
||||||
|
const url = `${this._baseUrl()}/api/user/login?${params.toString()}`;
|
||||||
|
const response = await fetchT(url, {
|
||||||
|
method: 'POST',
|
||||||
|
headers: {
|
||||||
|
'Accept': 'application/json',
|
||||||
|
'Content-Type': 'application/x-www-form-urlencoded'
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
const result = await response.json();
|
||||||
|
|
||||||
|
if (result.status === 'ok' && result.token) {
|
||||||
|
this.token = result.token;
|
||||||
|
this.tokenExpiry = new Date(Date.now() + SESSION_TTL_MS).toISOString();
|
||||||
|
log.info('technitium', 'DNS token obtained', {
|
||||||
|
server: this.serverIp,
|
||||||
|
expires: this.tokenExpiry
|
||||||
|
});
|
||||||
|
return { success: true, token: this.token };
|
||||||
|
}
|
||||||
|
|
||||||
|
return { success: false, error: result.errorMessage || 'Login failed' };
|
||||||
|
} catch (error) {
|
||||||
|
log.error('technitium', 'Login error', { error: error.message });
|
||||||
|
return { success: false, error: error.message };
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// ---------------------------------------------------------------------------
|
||||||
|
// Record Management
|
||||||
|
// ---------------------------------------------------------------------------
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Create (or overwrite) a DNS record.
|
||||||
|
* GET /api/zones/records/add?token=...&domain=...&zone=...&type=...&ipAddress=...&ttl=...&overwrite=...
|
||||||
|
*/
|
||||||
|
async createRecord({ domain, zone, type, value, ttl, overwrite }) {
|
||||||
|
const token = await this._requireToken();
|
||||||
|
const { fetchT, log } = this.ctx;
|
||||||
|
|
||||||
|
const params = {
|
||||||
|
token,
|
||||||
|
domain,
|
||||||
|
zone,
|
||||||
|
type: type || 'A',
|
||||||
|
ipAddress: value,
|
||||||
|
ttl: String(ttl || 300),
|
||||||
|
overwrite: String(overwrite !== false)
|
||||||
|
};
|
||||||
|
|
||||||
|
try {
|
||||||
|
log.info('technitium', 'Creating DNS record', { domain, type, value });
|
||||||
|
const url = this._buildUrl('/api/zones/records/add', params);
|
||||||
|
const response = await fetchT(url, {
|
||||||
|
method: 'GET',
|
||||||
|
headers: { 'Accept': 'application/json' }
|
||||||
|
});
|
||||||
|
const result = await response.json();
|
||||||
|
|
||||||
|
if (result.status === 'ok') {
|
||||||
|
log.info('technitium', 'DNS record created', { domain, type, value });
|
||||||
|
return { success: true };
|
||||||
|
}
|
||||||
|
|
||||||
|
// If token expired, re-authenticate and retry once
|
||||||
|
if (result.errorMessage && result.errorMessage.toLowerCase().includes('token')) {
|
||||||
|
log.info('technitium', 'Token expired, re-authenticating');
|
||||||
|
this.token = null;
|
||||||
|
this.tokenExpiry = null;
|
||||||
|
const retryToken = await this._requireToken();
|
||||||
|
params.token = retryToken;
|
||||||
|
const retryUrl = this._buildUrl('/api/zones/records/add', params);
|
||||||
|
const retryResp = await fetchT(retryUrl, {
|
||||||
|
method: 'GET',
|
||||||
|
headers: { 'Accept': 'application/json' }
|
||||||
|
});
|
||||||
|
const retryResult = await retryResp.json();
|
||||||
|
if (retryResult.status === 'ok') {
|
||||||
|
return { success: true };
|
||||||
|
}
|
||||||
|
throw new Error(retryResult.errorMessage || 'Failed after token refresh');
|
||||||
|
}
|
||||||
|
|
||||||
|
throw new Error(result.errorMessage || 'Unknown error');
|
||||||
|
} catch (error) {
|
||||||
|
throw new Error(`Failed to create DNS record for ${domain}: ${error.message}`);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Delete a DNS record.
|
||||||
|
* GET /api/zones/records/delete?token=...&domain=...&type=... (+ ipAddress if value provided)
|
||||||
|
*/
|
||||||
|
async deleteRecord({ domain, type, value }) {
|
||||||
|
const token = await this._requireToken();
|
||||||
|
const { fetchT, log } = this.ctx;
|
||||||
|
|
||||||
|
const params = {
|
||||||
|
token,
|
||||||
|
domain,
|
||||||
|
type: type || 'A'
|
||||||
|
};
|
||||||
|
if (value) {
|
||||||
|
params.ipAddress = value;
|
||||||
|
}
|
||||||
|
|
||||||
|
try {
|
||||||
|
log.info('technitium', 'Deleting DNS record', { domain, type, value });
|
||||||
|
const url = this._buildUrl('/api/zones/records/delete', params);
|
||||||
|
const response = await fetchT(url, {
|
||||||
|
method: 'GET',
|
||||||
|
headers: { 'Accept': 'application/json' }
|
||||||
|
});
|
||||||
|
const result = await response.json();
|
||||||
|
|
||||||
|
if (result.status === 'ok') {
|
||||||
|
log.info('technitium', 'DNS record deleted', { domain, type, value });
|
||||||
|
return { success: true };
|
||||||
|
}
|
||||||
|
|
||||||
|
throw new Error(result.errorMessage || 'Unknown error');
|
||||||
|
} catch (error) {
|
||||||
|
throw new Error(`Failed to delete DNS record for ${domain}: ${error.message}`);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Resolve/query records for a domain in a zone.
|
||||||
|
* GET /api/zones/records/get?token=...&domain=...&zone=...&listZone=true
|
||||||
|
* Filters returned records by type if provided.
|
||||||
|
*/
|
||||||
|
async resolveRecords({ domain, zone, type }) {
|
||||||
|
const token = await this._requireToken();
|
||||||
|
const { fetchT, log } = this.ctx;
|
||||||
|
|
||||||
|
const params = {
|
||||||
|
token,
|
||||||
|
domain,
|
||||||
|
zone,
|
||||||
|
listZone: 'true'
|
||||||
|
};
|
||||||
|
|
||||||
|
try {
|
||||||
|
log.info('technitium', 'Resolving records', { domain, zone, type });
|
||||||
|
const url = this._buildUrl('/api/zones/records/get', params);
|
||||||
|
const response = await fetchT(url, {
|
||||||
|
method: 'GET',
|
||||||
|
headers: { 'Accept': 'application/json' }
|
||||||
|
});
|
||||||
|
const result = await response.json();
|
||||||
|
|
||||||
|
if (result.status !== 'ok') {
|
||||||
|
throw new Error(result.errorMessage || 'Failed to resolve records');
|
||||||
|
}
|
||||||
|
|
||||||
|
let records = (result.response && result.response.records) || [];
|
||||||
|
|
||||||
|
// Filter by type if specified
|
||||||
|
if (type) {
|
||||||
|
records = records.filter(r => r.type === type);
|
||||||
|
}
|
||||||
|
|
||||||
|
return { success: true, records };
|
||||||
|
} catch (error) {
|
||||||
|
throw new Error(`Failed to resolve records for ${domain}: ${error.message}`);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* List all records in a zone.
|
||||||
|
* Delegates to resolveRecords with a wildcard domain.
|
||||||
|
*/
|
||||||
|
async listRecords({ zone }) {
|
||||||
|
return this.resolveRecords({ domain: zone, zone, type: null });
|
||||||
|
}
|
||||||
|
|
||||||
|
// ---------------------------------------------------------------------------
|
||||||
|
// Logs
|
||||||
|
// ---------------------------------------------------------------------------
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Fetch and parse DNS query logs.
|
||||||
|
* 1. GET /api/logs/list to discover the latest log file
|
||||||
|
* 2. GET /api/logs/download?token=...&fileName=... to download it
|
||||||
|
* 3. Parse text format: [timestamp] [client:port] [protocol] QNAME: domain; QTYPE: type; QCLASS: class; RCODE: rcode; ANSWER: [answer]
|
||||||
|
*/
|
||||||
|
async getLogs({ limit, server } = {}) {
|
||||||
|
const token = await this._requireToken();
|
||||||
|
const { fetchT, log } = this.ctx;
|
||||||
|
|
||||||
|
const targetIp = server || this.serverIp;
|
||||||
|
const targetPort = this.serverPort;
|
||||||
|
const baseUrl = `http://${targetIp}:${targetPort}`;
|
||||||
|
|
||||||
|
try {
|
||||||
|
// Step 1: Get log file list
|
||||||
|
const listUrl = this._buildUrl('/api/logs/list', { token });
|
||||||
|
const listResp = await fetchT(listUrl.replace(this._baseUrl(), baseUrl), {
|
||||||
|
method: 'GET',
|
||||||
|
headers: { 'Accept': 'application/json' }
|
||||||
|
});
|
||||||
|
const listResult = await listResp.json();
|
||||||
|
|
||||||
|
if (listResult.status !== 'ok' || !listResult.response || !listResult.response.length) {
|
||||||
|
throw new Error(listResult.errorMessage || 'No log files found');
|
||||||
|
}
|
||||||
|
|
||||||
|
// Pick the latest log file (last entry)
|
||||||
|
const logFile = listResult.response[listResult.response.length - 1];
|
||||||
|
const fileName = logFile.name || logFile.fileName || logFile;
|
||||||
|
|
||||||
|
// Step 2: Download the log file
|
||||||
|
const downloadUrl = `${baseUrl}/api/logs/download?${new URLSearchParams({ token, fileName }).toString()}`;
|
||||||
|
const downloadResp = await fetchT(downloadUrl, {
|
||||||
|
method: 'GET'
|
||||||
|
});
|
||||||
|
const logText = await downloadResp.text();
|
||||||
|
|
||||||
|
// Step 3: Parse lines
|
||||||
|
const parsed = this._parseLogText(logText, limit);
|
||||||
|
return { success: true, logs: parsed };
|
||||||
|
} catch (error) {
|
||||||
|
log.error('technitium', 'Failed to fetch DNS logs', { error: error.message });
|
||||||
|
throw new Error(`Failed to get DNS logs: ${error.message}`);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Parse Technitium DNS log text format.
|
||||||
|
* Line format: [timestamp] [client:port] [protocol] QNAME: domain; QTYPE: type; QCLASS: class; RCODE: rcode; ANSWER: [answer]
|
||||||
|
*/
|
||||||
|
_parseLogText(text, limit) {
|
||||||
|
const lines = text.split('\n').filter(l => l.trim());
|
||||||
|
const parsed = [];
|
||||||
|
|
||||||
|
// Process newest first if we need to limit
|
||||||
|
const iterable = limit ? lines.slice(-limit).reverse() : lines;
|
||||||
|
|
||||||
|
for (const line of iterable) {
|
||||||
|
try {
|
||||||
|
const entry = {};
|
||||||
|
|
||||||
|
// Extract timestamp: [2024-01-15 10:30:45]
|
||||||
|
const tsMatch = line.match(/\[([^\]]+)\]/);
|
||||||
|
if (tsMatch) entry.timestamp = tsMatch[1];
|
||||||
|
|
||||||
|
// Extract client:port: [192.168.1.100:12345]
|
||||||
|
const clientMatch = line.match(/\[([^\]]+:\d+)\]/g);
|
||||||
|
if (clientMatch && clientMatch.length >= 2) {
|
||||||
|
entry.client = clientMatch[1].replace(/\[|\]/g, '');
|
||||||
|
}
|
||||||
|
|
||||||
|
// Extract protocol: [UDP] or [TCP]
|
||||||
|
const protoMatch = line.match(/\]\s*\[(UDP|TCP|DoH|DoT|DoH2)\]/i);
|
||||||
|
if (protoMatch) entry.protocol = protoMatch[1];
|
||||||
|
|
||||||
|
// Extract key-value pairs: QNAME: value; QTYPE: value; etc.
|
||||||
|
const kvPattern = /(\w+):\s*([^;]+)/g;
|
||||||
|
let match;
|
||||||
|
while ((match = kvPattern.exec(line)) !== null) {
|
||||||
|
const key = match[1];
|
||||||
|
const val = match[2].trim();
|
||||||
|
if (['QNAME', 'QTYPE', 'QCLASS', 'RCODE'].includes(key)) {
|
||||||
|
entry[key.toLowerCase()] = val;
|
||||||
|
} else if (key === 'ANSWER') {
|
||||||
|
entry.answer = val;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
entry.raw = line;
|
||||||
|
parsed.push(entry);
|
||||||
|
} catch {
|
||||||
|
// Skip unparseable lines
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return parsed;
|
||||||
|
}
|
||||||
|
|
||||||
|
// ---------------------------------------------------------------------------
|
||||||
|
// Server Management
|
||||||
|
// ---------------------------------------------------------------------------
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Restart the DNS server.
|
||||||
|
* POST /api/admin/restart?token=...
|
||||||
|
* Requires admin credentials.
|
||||||
|
*/
|
||||||
|
async restartServer({ server } = {}) {
|
||||||
|
const token = await this._requireToken();
|
||||||
|
const { fetchT, log } = this.ctx;
|
||||||
|
|
||||||
|
try {
|
||||||
|
log.info('technitium', 'Restarting DNS server', { server: this.serverIp });
|
||||||
|
const url = this._buildUrl('/api/admin/restart', { token });
|
||||||
|
const response = await fetchT(url, {
|
||||||
|
method: 'POST',
|
||||||
|
headers: { 'Accept': 'application/json' }
|
||||||
|
});
|
||||||
|
const result = await response.json();
|
||||||
|
|
||||||
|
if (result.status === 'ok') {
|
||||||
|
log.info('technitium', 'DNS server restart initiated');
|
||||||
|
return { success: true, message: 'Server restart initiated' };
|
||||||
|
}
|
||||||
|
|
||||||
|
throw new Error(result.errorMessage || 'Restart failed');
|
||||||
|
} catch (error) {
|
||||||
|
log.error('technitium', 'DNS restart error', { error: error.message });
|
||||||
|
throw new Error(`Failed to restart DNS server: ${error.message}`);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Check for DNS server updates.
|
||||||
|
* GET /api/user/checkForUpdate?token=...
|
||||||
|
*/
|
||||||
|
async checkUpdate({ server } = {}) {
|
||||||
|
const token = await this._requireToken();
|
||||||
|
const { fetchT, log } = this.ctx;
|
||||||
|
|
||||||
|
try {
|
||||||
|
log.info('technitium', 'Checking for DNS server update', { server: this.serverIp });
|
||||||
|
const url = this._buildUrl('/api/user/checkForUpdate', { token });
|
||||||
|
const response = await fetchT(url, {
|
||||||
|
method: 'GET',
|
||||||
|
headers: { 'Accept': 'application/json' }
|
||||||
|
});
|
||||||
|
const result = await response.json();
|
||||||
|
|
||||||
|
if (result.status === 'ok') {
|
||||||
|
return {
|
||||||
|
success: true,
|
||||||
|
updateAvailable: !!(result.response && result.response.updateAvailable),
|
||||||
|
latestVersion: (result.response && result.response.latestVersion) || null,
|
||||||
|
currentVersion: (result.response && result.response.currentVersion) || null,
|
||||||
|
response: result.response
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
throw new Error(result.errorMessage || 'Update check failed');
|
||||||
|
} catch (error) {
|
||||||
|
log.error('technitium', 'Update check error', { error: error.message });
|
||||||
|
throw new Error(`Failed to check for updates: ${error.message}`);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// ---------------------------------------------------------------------------
|
||||||
|
// Config Validation
|
||||||
|
// ---------------------------------------------------------------------------
|
||||||
|
|
||||||
|
validateConfig() {
|
||||||
|
const errors = [];
|
||||||
|
if (!this.serverIp) {
|
||||||
|
errors.push('serverIp is required');
|
||||||
|
}
|
||||||
|
if (this.serverPort && (typeof this.serverPort !== 'number' || this.serverPort < 1 || this.serverPort > 65535)) {
|
||||||
|
errors.push('serverPort must be a valid port number (1-65535)');
|
||||||
|
}
|
||||||
|
return { valid: errors.length === 0, errors };
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
module.exports = TechnitiumDNSProvider;
|
||||||
@@ -1,66 +1,70 @@
|
|||||||
/**
|
/**
|
||||||
* DashCaddy Error Handler Middleware
|
* DashCaddy Error Handler Middleware
|
||||||
* Centralizes error handling logic to eliminate duplicate catch blocks
|
* Centralizes error handling logic to eliminate duplicate catch blocks
|
||||||
|
*
|
||||||
|
* Logging: this middleware uses the unified logError from src/utils/logging.js
|
||||||
|
* (same one src/app.js uses), so all errors go to one log file. The legacy
|
||||||
|
* ./error-logger.js and its ./error.log file have been retired.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
|
const path = require('path');
|
||||||
const { AppError } = require('./errors');
|
const { AppError } = require('./errors');
|
||||||
const { logError } = require('./error-logger');
|
const { LIMITS } = require('./constants');
|
||||||
|
const { logError: unifiedLogError, safeErrorMessage } = require('./src/utils/logging');
|
||||||
|
|
||||||
/**
|
const ERROR_LOG_FILE = path.join(__dirname, 'error.log');
|
||||||
* Async route handler wrapper
|
const MAX_ERROR_LOG_SIZE = LIMITS.ERROR_LOG_SIZE;
|
||||||
* Automatically catches errors and passes to error middleware
|
|
||||||
* Usage: app.get('/route', asyncHandler(async (req, res) => { ... }))
|
|
||||||
*/
|
|
||||||
function asyncHandler(fn) {
|
|
||||||
return (req, res, next) => {
|
|
||||||
Promise.resolve(fn(req, res, next)).catch(next);
|
|
||||||
};
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Global error handling middleware
|
* Global error handling middleware
|
||||||
* MUST be registered after all routes in server.js
|
* MUST be registered after all routes in server.js
|
||||||
*/
|
*/
|
||||||
function errorMiddleware(err, req, res, next) {
|
function errorMiddleware(err, req, res, next) {
|
||||||
// Log all errors with request context
|
// Log all errors with request context (unified, same file the rest of the app uses)
|
||||||
logError(req.path, err, {
|
unifiedLogError(
|
||||||
method: req.method,
|
ERROR_LOG_FILE,
|
||||||
ip: req.ip,
|
MAX_ERROR_LOG_SIZE,
|
||||||
userId: req.user?.id,
|
req.path,
|
||||||
body: req.body
|
err,
|
||||||
});
|
{
|
||||||
|
method: req.method,
|
||||||
|
ip: req.ip,
|
||||||
|
userId: req.user?.id,
|
||||||
|
body: req.body
|
||||||
|
}
|
||||||
|
).catch(e => console.error('Failed to write to error log:', e.message));
|
||||||
|
|
||||||
// Determine if this is an operational error (AppError) or programming error
|
// Determine if this is an operational error (AppError) or programming error
|
||||||
const isOperational = err.isOperational || err instanceof AppError;
|
const isOperational = err.isOperational || err instanceof AppError;
|
||||||
|
|
||||||
// Status code
|
// Status code
|
||||||
const statusCode = err.statusCode || 500;
|
const statusCode = err.statusCode || 500;
|
||||||
|
|
||||||
// Error code (DC-XXX format)
|
// Error code (DC-XXX format)
|
||||||
const code = err.code || `DC-${statusCode}`;
|
const code = err.code || `DC-${statusCode}`;
|
||||||
|
|
||||||
// Build response
|
// Build response
|
||||||
const response = {
|
const response = {
|
||||||
success: false,
|
success: false,
|
||||||
error: isOperational ? err.message : 'Internal server error',
|
error: isOperational ? safeErrorMessage(err) : 'Internal server error',
|
||||||
code
|
code
|
||||||
};
|
};
|
||||||
|
|
||||||
// Add optional fields if present
|
// Add optional fields if present
|
||||||
if (err.requiresTotp) response.requiresTotp = true;
|
if (err.requiresTotp) response.requiresTotp = true;
|
||||||
if (err.retryAfter) response.retryAfter = err.retryAfter;
|
if (err.retryAfter) response.retryAfter = err.retryAfter;
|
||||||
if (err.field) response.field = err.field;
|
if (err.field) response.field = err.field;
|
||||||
if (err.resource) response.resource = err.resource;
|
if (err.resource) response.resource = err.resource;
|
||||||
if (err.details && Object.keys(err.details).length > 0) response.details = err.details;
|
if (err.details && Object.keys(err.details).length > 0) response.details = err.details;
|
||||||
|
|
||||||
// Development mode: include stack trace
|
// Development mode: include stack trace
|
||||||
if (process.env.NODE_ENV === 'development') {
|
if (process.env.NODE_ENV === 'development') {
|
||||||
response.stack = err.stack;
|
response.stack = err.stack;
|
||||||
}
|
}
|
||||||
|
|
||||||
// Send response
|
// Send response
|
||||||
res.status(statusCode).json(response);
|
res.status(statusCode).json(response);
|
||||||
|
|
||||||
// For non-operational errors, log as fatal
|
// For non-operational errors, log as fatal
|
||||||
if (!isOperational) {
|
if (!isOperational) {
|
||||||
console.error('FATAL: Non-operational error detected', {
|
console.error('FATAL: Non-operational error detected', {
|
||||||
@@ -81,7 +85,6 @@ function notFoundHandler(req, res, next) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
module.exports = {
|
module.exports = {
|
||||||
asyncHandler,
|
|
||||||
errorMiddleware,
|
errorMiddleware,
|
||||||
notFoundHandler
|
notFoundHandler
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -1,135 +0,0 @@
|
|||||||
// Error Logger Utility
|
|
||||||
// Centralized error logging with rotation and request context tracking
|
|
||||||
|
|
||||||
const fsp = require('fs').promises;
|
|
||||||
const path = require('path');
|
|
||||||
const { LIMITS } = require('./constants');
|
|
||||||
|
|
||||||
const ERROR_LOG_FILE = path.join(__dirname, 'error.log');
|
|
||||||
const MAX_ERROR_LOG_SIZE = LIMITS.ERROR_LOG_SIZE;
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Check if file exists
|
|
||||||
*/
|
|
||||||
async function exists(filepath) {
|
|
||||||
try {
|
|
||||||
await fsp.access(filepath);
|
|
||||||
return true;
|
|
||||||
} catch {
|
|
||||||
return false;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Log error with context and rotation
|
|
||||||
* @param {string} context - Where the error occurred
|
|
||||||
* @param {Error|string} error - The error to log
|
|
||||||
* @param {Object} additionalInfo - Additional context (req, etc.)
|
|
||||||
*/
|
|
||||||
async function logError(context, error, additionalInfo = {}) {
|
|
||||||
const timestamp = new Date().toISOString();
|
|
||||||
|
|
||||||
// Extract request context if a request object is provided
|
|
||||||
const requestContext = extractRequestContext(additionalInfo.req);
|
|
||||||
if (additionalInfo.req) {
|
|
||||||
delete additionalInfo.req; // Remove req to avoid circular refs
|
|
||||||
}
|
|
||||||
|
|
||||||
const logEntry = {
|
|
||||||
timestamp,
|
|
||||||
context,
|
|
||||||
...requestContext,
|
|
||||||
error: {
|
|
||||||
message: error.message || error,
|
|
||||||
stack: error.stack,
|
|
||||||
code: error.code
|
|
||||||
},
|
|
||||||
...additionalInfo
|
|
||||||
};
|
|
||||||
|
|
||||||
// Format log line with request context
|
|
||||||
const contextInfo = Object.keys(requestContext).length > 0
|
|
||||||
? `\nRequest Context: ${JSON.stringify(requestContext, null, 2)}`
|
|
||||||
: '';
|
|
||||||
const logLine = `[${timestamp}] ${context}: ${error.message || error}\n${error.stack || ''}${contextInfo}\nAdditional Info: ${JSON.stringify(additionalInfo, null, 2)}\n${'='.repeat(80)}\n`;
|
|
||||||
|
|
||||||
try {
|
|
||||||
// Rotate log if it exceeds max size
|
|
||||||
await rotateLogIfNeeded();
|
|
||||||
await fsp.appendFile(ERROR_LOG_FILE, logLine);
|
|
||||||
} catch (e) {
|
|
||||||
console.error('Failed to write to error log', e.message);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Extract request context from Express request object
|
|
||||||
*/
|
|
||||||
function extractRequestContext(req) {
|
|
||||||
if (!req) return {};
|
|
||||||
|
|
||||||
const clientIP = req.ip || req.socket?.remoteAddress || '';
|
|
||||||
|
|
||||||
return {
|
|
||||||
requestId: req.id,
|
|
||||||
ip: clientIP,
|
|
||||||
userAgent: req.get('user-agent'),
|
|
||||||
method: req.method,
|
|
||||||
path: req.path
|
|
||||||
};
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Rotate log file if it exceeds max size
|
|
||||||
*/
|
|
||||||
async function rotateLogIfNeeded() {
|
|
||||||
try {
|
|
||||||
const stats = await fsp.stat(ERROR_LOG_FILE);
|
|
||||||
if (stats.size > MAX_ERROR_LOG_SIZE) {
|
|
||||||
const rotated = ERROR_LOG_FILE + '.1';
|
|
||||||
if (await exists(rotated)) {
|
|
||||||
await fsp.unlink(rotated);
|
|
||||||
}
|
|
||||||
await fsp.rename(ERROR_LOG_FILE, rotated);
|
|
||||||
}
|
|
||||||
} catch (_) {
|
|
||||||
// File may not exist yet, that's fine
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Return a safe error message to the client without leaking internals
|
|
||||||
*/
|
|
||||||
function safeErrorMessage(error) {
|
|
||||||
const msg = error.message || String(error);
|
|
||||||
|
|
||||||
// Detect port conflict errors from Docker
|
|
||||||
const portMatch = msg.match(/exposing port TCP [^:]*:(\d+)/);
|
|
||||||
if (portMatch || msg.includes('port is already allocated') || msg.includes('ports are not available')) {
|
|
||||||
const port = portMatch ? portMatch[1] : 'requested';
|
|
||||||
return `Port ${port} is already in use. Please choose a different port or stop the conflicting service.`;
|
|
||||||
}
|
|
||||||
|
|
||||||
// Detect container not found errors
|
|
||||||
if (msg.includes('No such container')) {
|
|
||||||
return 'Container not found';
|
|
||||||
}
|
|
||||||
|
|
||||||
// Detect network errors
|
|
||||||
if (msg.includes('ECONNREFUSED') || msg.includes('ETIMEDOUT')) {
|
|
||||||
return 'Service unavailable';
|
|
||||||
}
|
|
||||||
|
|
||||||
// Generic safe message for unknown errors
|
|
||||||
if (process.env.NODE_ENV === 'production') {
|
|
||||||
return 'An error occurred. Please try again or contact support.';
|
|
||||||
}
|
|
||||||
|
|
||||||
// In development, show the actual error
|
|
||||||
return msg;
|
|
||||||
}
|
|
||||||
|
|
||||||
module.exports = {
|
|
||||||
logError,
|
|
||||||
safeErrorMessage
|
|
||||||
};
|
|
||||||
@@ -317,6 +317,9 @@ class LicenseManager {
|
|||||||
*/
|
*/
|
||||||
isExpired() {
|
isExpired() {
|
||||||
if (!this.activation) return true;
|
if (!this.activation) return true;
|
||||||
|
// Lifetime licenses never expire
|
||||||
|
if (this.activation.lifetime || this.activation.durationDays === 0) return false;
|
||||||
|
if (!this.activation.expiresAt) return false; // No expiry set = lifetime
|
||||||
return Date.now() > new Date(this.activation.expiresAt).getTime();
|
return Date.now() > new Date(this.activation.expiresAt).getTime();
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -277,9 +277,32 @@ module.exports = function configureMiddleware(app, {
|
|||||||
}
|
}
|
||||||
|
|
||||||
// ── Public routes (bypass TOTP and JWT auth) ──
|
// ── Public routes (bypass TOTP and JWT auth) ──
|
||||||
|
// Routes here are accessible without authentication. By default the
|
||||||
|
// monitoring/health-check endpoints are public so the dashboard can
|
||||||
|
// render widgets before the user logs in. Set MONITORING_PUBLIC=false
|
||||||
|
// (env var) or `monitoring: { public: false }` (config.json) to require
|
||||||
|
// auth for these — useful for internet-exposed deployments where
|
||||||
|
// CPU/memory/disk data is sensitive.
|
||||||
|
const MONITORING_PUBLIC = (() => {
|
||||||
|
if (process.env.MONITORING_PUBLIC === 'false') return false;
|
||||||
|
if (process.env.MONITORING_PUBLIC === 'true') return true;
|
||||||
|
// Default: check config.json if loaded
|
||||||
|
try {
|
||||||
|
const cfg = require('./src/config/site').siteConfig;
|
||||||
|
if (cfg && cfg.monitoring && typeof cfg.monitoring.public === 'boolean') {
|
||||||
|
return cfg.monitoring.public;
|
||||||
|
}
|
||||||
|
} catch { /* config not loaded yet, use default */ }
|
||||||
|
return true; // default: public (current behavior, dashboard needs it)
|
||||||
|
})();
|
||||||
|
|
||||||
const PUBLIC_ROUTES = [
|
const PUBLIC_ROUTES = [
|
||||||
{ path: '/health', exact: true },
|
{ path: '/health', exact: true },
|
||||||
|
{ path: '/health/live', exact: true },
|
||||||
|
{ path: '/health/ready', exact: true },
|
||||||
{ path: '/api/v1/health', exact: true },
|
{ path: '/api/v1/health', exact: true },
|
||||||
|
{ path: '/api/v1/health/live', exact: true },
|
||||||
|
{ path: '/api/v1/health/ready', exact: true },
|
||||||
{ path: '/probe/', prefix: true },
|
{ path: '/probe/', prefix: true },
|
||||||
{ path: '/api/v1/tailscale/', prefix: true },
|
{ path: '/api/v1/tailscale/', prefix: true },
|
||||||
{ path: '/api/v1/totp/config', exact: true, method: 'GET' },
|
{ path: '/api/v1/totp/config', exact: true, method: 'GET' },
|
||||||
@@ -305,6 +328,12 @@ module.exports = function configureMiddleware(app, {
|
|||||||
{ path: '/api/v1/config', exact: true, method: 'GET' },
|
{ path: '/api/v1/config', exact: true, method: 'GET' },
|
||||||
{ path: '/api/v1/services/status', exact: true, method: 'GET' },
|
{ path: '/api/v1/services/status', exact: true, method: 'GET' },
|
||||||
{ path: '/api/v1/system/update-notify', exact: true, method: 'POST' },
|
{ path: '/api/v1/system/update-notify', exact: true, method: 'POST' },
|
||||||
|
// Monitoring endpoints — only public if MONITORING_PUBLIC is true
|
||||||
|
...(MONITORING_PUBLIC ? [
|
||||||
|
{ path: '/api/v1/monitoring/stats', exact: true, method: 'GET' },
|
||||||
|
{ path: '/api/v1/health-checks/status', exact: true, method: 'GET' },
|
||||||
|
] : []),
|
||||||
|
{ path: '/api/v1/version', exact: true, method: 'GET' },
|
||||||
];
|
];
|
||||||
|
|
||||||
function isPublicRoute(req) {
|
function isPublicRoute(req) {
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
{
|
{
|
||||||
"name": "dashcaddy-api",
|
"name": "dashcaddy-api",
|
||||||
"version": "1.6.0",
|
"version": "1.13.2",
|
||||||
"description": "DashCaddy API server - Dashboard backend for Docker, Caddy & DNS management",
|
"description": "DashCaddy API server - Dashboard backend for Docker, Caddy & DNS management",
|
||||||
"main": "server.js",
|
"main": "server.js",
|
||||||
"scripts": {
|
"scripts": {
|
||||||
|
|||||||
@@ -3,6 +3,7 @@
|
|||||||
// All paths can be overridden via environment variables.
|
// All paths can be overridden via environment variables.
|
||||||
|
|
||||||
const path = require('path');
|
const path = require('path');
|
||||||
|
const fs = require('fs');
|
||||||
const isWindows = process.platform === 'win32';
|
const isWindows = process.platform === 'win32';
|
||||||
|
|
||||||
// Base directories
|
// Base directories
|
||||||
@@ -34,6 +35,8 @@ const paths = {
|
|||||||
caCertDir: path.join(CADDY_SITES, 'ca'),
|
caCertDir: path.join(CADDY_SITES, 'ca'),
|
||||||
pkiRootCert: path.join(CADDY_PKI, 'root.crt'),
|
pkiRootCert: path.join(CADDY_PKI, 'root.crt'),
|
||||||
pkiIntermediateCert: path.join(CADDY_PKI, 'intermediate.crt'),
|
pkiIntermediateCert: path.join(CADDY_PKI, 'intermediate.crt'),
|
||||||
|
generatedCertsDir: path.join(CADDY_SITES, 'generated-certs'),
|
||||||
|
pkiDir: CADDY_PKI,
|
||||||
|
|
||||||
// Static site base path
|
// Static site base path
|
||||||
sitePath: (subdomain) => path.join(CADDY_SITES, subdomain),
|
sitePath: (subdomain) => path.join(CADDY_SITES, subdomain),
|
||||||
@@ -41,6 +44,24 @@ const paths = {
|
|||||||
// Docker data path for app volumes
|
// Docker data path for app volumes
|
||||||
appData: (appName) => path.join(DOCKER_DATA, appName),
|
appData: (appName) => path.join(DOCKER_DATA, appName),
|
||||||
|
|
||||||
|
// In-container paths (used by self-updater and Docker deployments)
|
||||||
|
// Override via env vars for custom Docker layouts
|
||||||
|
containerUpdatesDir: process.env.DASHCADDY_UPDATES_DIR || '/app/updates',
|
||||||
|
containerFrontendDir: process.env.DASHCADDY_FRONTEND_DIR || '/app/dashboard',
|
||||||
|
containerAssetsDir: process.env.ASSETS_DIR || '/app/assets',
|
||||||
|
|
||||||
|
// Asset path resolution — supports both Docker (single file mount) and
|
||||||
|
// consolidated data directory layouts
|
||||||
|
resolveAssetsPath: (envPath) => {
|
||||||
|
if (envPath) return envPath;
|
||||||
|
// Standard Docker mount: /app/assets (volume-mounted)
|
||||||
|
if (fs.existsSync('/app/assets')) return '/app/assets';
|
||||||
|
// Consolidated data directory: /app/data/assets
|
||||||
|
if (fs.existsSync(path.join(CADDY_BASE, 'assets'))) return path.join(CADDY_BASE, 'assets');
|
||||||
|
// Fall back to /app/assets even if it doesn't exist (will create on write)
|
||||||
|
return '/app/assets';
|
||||||
|
},
|
||||||
|
|
||||||
// Log digest directory
|
// Log digest directory
|
||||||
digestDir: process.env.DIGEST_DIR || path.join(CADDY_BASE, 'digests'),
|
digestDir: process.env.DIGEST_DIR || path.join(CADDY_BASE, 'digests'),
|
||||||
|
|
||||||
|
|||||||
@@ -226,7 +226,23 @@ const server = http.createServer(async (req, res) => {
|
|||||||
json(res, 404, { error: 'Not found' });
|
json(res, 404, { error: 'Not found' });
|
||||||
});
|
});
|
||||||
|
|
||||||
server.listen(PORT, '0.0.0.0', () => {
|
const PYLON_PORT = parseInt(process.env.PYLON_PORT, 10) || 7842;
|
||||||
console.log(`[Pylon] ${PYLON_NAME} listening on port ${PORT}`);
|
const PYLON_HOST = process.env.PYLON_HOST || '0.0.0.0';
|
||||||
|
|
||||||
|
server.listen(PYLON_PORT, PYLON_HOST, () => {
|
||||||
|
console.log(`[Pylon] ${PYLON_NAME} listening on ${PYLON_HOST}:${PYLON_PORT}`);
|
||||||
if (API_KEY) console.log('[Pylon] API key authentication enabled');
|
if (API_KEY) console.log('[Pylon] API key authentication enabled');
|
||||||
});
|
});
|
||||||
|
|
||||||
|
// Graceful shutdown — drain connections, then exit
|
||||||
|
const shutdown = (signal) => {
|
||||||
|
console.log(`[Pylon] ${signal} received, draining...`);
|
||||||
|
server.close(() => {
|
||||||
|
console.log('[Pylon] HTTP server closed');
|
||||||
|
process.exit(0);
|
||||||
|
});
|
||||||
|
// Force exit after 5s if connections don't drain
|
||||||
|
setTimeout(() => process.exit(0), 5000).unref();
|
||||||
|
};
|
||||||
|
process.on('SIGTERM', () => shutdown('SIGTERM'));
|
||||||
|
process.on('SIGINT', () => shutdown('SIGINT'));
|
||||||
|
|||||||
@@ -1,114 +0,0 @@
|
|||||||
// Response Helpers
|
|
||||||
// Standardize API response format across all routes
|
|
||||||
|
|
||||||
const { HTTP_STATUS } = require('./constants');
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Success response with data
|
|
||||||
*/
|
|
||||||
function success(res, data, statusCode = HTTP_STATUS.OK) {
|
|
||||||
return res.status(statusCode).json({
|
|
||||||
success: true,
|
|
||||||
...data
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Success response with message
|
|
||||||
*/
|
|
||||||
function successMessage(res, message, statusCode = HTTP_STATUS.OK) {
|
|
||||||
return res.status(statusCode).json({
|
|
||||||
success: true,
|
|
||||||
message
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Created response (201)
|
|
||||||
*/
|
|
||||||
function created(res, data) {
|
|
||||||
return res.status(HTTP_STATUS.CREATED).json({
|
|
||||||
success: true,
|
|
||||||
...data
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* No content response (204)
|
|
||||||
*/
|
|
||||||
function noContent(res) {
|
|
||||||
return res.status(HTTP_STATUS.NO_CONTENT).send();
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Error response
|
|
||||||
*/
|
|
||||||
function error(res, message, statusCode = HTTP_STATUS.INTERNAL_ERROR) {
|
|
||||||
return res.status(statusCode).json({
|
|
||||||
success: false,
|
|
||||||
error: message
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Validation error response (400)
|
|
||||||
*/
|
|
||||||
function validationError(res, message) {
|
|
||||||
return res.status(HTTP_STATUS.BAD_REQUEST).json({
|
|
||||||
success: false,
|
|
||||||
error: message
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Unauthorized response (401)
|
|
||||||
*/
|
|
||||||
function unauthorized(res, message = 'Unauthorized') {
|
|
||||||
return res.status(HTTP_STATUS.UNAUTHORIZED).json({
|
|
||||||
success: false,
|
|
||||||
error: message
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Forbidden response (403)
|
|
||||||
*/
|
|
||||||
function forbidden(res, message = 'Forbidden') {
|
|
||||||
return res.status(HTTP_STATUS.FORBIDDEN).json({
|
|
||||||
success: false,
|
|
||||||
error: message
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Not found response (404)
|
|
||||||
*/
|
|
||||||
function notFound(res, message = 'Not found') {
|
|
||||||
return res.status(HTTP_STATUS.NOT_FOUND).json({
|
|
||||||
success: false,
|
|
||||||
error: message
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Conflict response (409)
|
|
||||||
*/
|
|
||||||
function conflict(res, message) {
|
|
||||||
return res.status(HTTP_STATUS.CONFLICT).json({
|
|
||||||
success: false,
|
|
||||||
error: message
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
module.exports = {
|
|
||||||
success,
|
|
||||||
successMessage,
|
|
||||||
created,
|
|
||||||
noContent,
|
|
||||||
error,
|
|
||||||
validationError,
|
|
||||||
unauthorized,
|
|
||||||
forbidden,
|
|
||||||
notFound,
|
|
||||||
conflict
|
|
||||||
};
|
|
||||||
@@ -197,8 +197,18 @@ module.exports = function({ docker, caddy, credentialManager, servicesStateManag
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
const container = await docker.client.createContainer(containerConfig);
|
let container;
|
||||||
await container.start();
|
try {
|
||||||
|
container = await docker.client.createContainer(containerConfig);
|
||||||
|
await container.start();
|
||||||
|
} catch (createErr) {
|
||||||
|
// If create fails with "no such image", wrap with user-friendly message
|
||||||
|
const errMsg = createErr?.message || String(createErr);
|
||||||
|
if (errMsg.includes('No such image') || errMsg.includes('no such image')) {
|
||||||
|
throw new Error(`[DC-201] Image pull succeeded but container creation failed — image may be corrupted: ${processedTemplate.docker.image}. ${errMsg}`);
|
||||||
|
}
|
||||||
|
throw createErr;
|
||||||
|
}
|
||||||
|
|
||||||
// Prune dangling images to prevent disk bloat
|
// Prune dangling images to prevent disk bloat
|
||||||
try {
|
try {
|
||||||
@@ -306,7 +316,7 @@ module.exports = function({ docker, caddy, credentialManager, servicesStateManag
|
|||||||
} else {
|
} else {
|
||||||
containerId = await deployContainer(appId, config, template);
|
containerId = await deployContainer(appId, config, template);
|
||||||
log.info('deploy', 'Container deployed', { containerId });
|
log.info('deploy', 'Container deployed', { containerId });
|
||||||
await helpers.waitForHealthCheck(containerId, template.healthCheck, config.port || template.defaultPort);
|
await helpers.waitForHealthCheck(containerId, template.healthCheck, config.port || template.defaultPort, 30);
|
||||||
log.info('deploy', 'Container is healthy', { containerId });
|
log.info('deploy', 'Container is healthy', { containerId });
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -316,7 +326,7 @@ module.exports = function({ docker, caddy, credentialManager, servicesStateManag
|
|||||||
let dnsWarning = null;
|
let dnsWarning = null;
|
||||||
if (config.createDns && !isSubdirectoryMode) {
|
if (config.createDns && !isSubdirectoryMode) {
|
||||||
try {
|
try {
|
||||||
await ctx.dns.createRecord(config.subdomain, config.ip);
|
await ctx.dns.universalCreateRecord(config.subdomain, config.ip);
|
||||||
log.info('deploy', 'DNS record created', { domain: ctx.buildDomain(config.subdomain), ip: config.ip });
|
log.info('deploy', 'DNS record created', { domain: ctx.buildDomain(config.subdomain), ip: config.ip });
|
||||||
} catch (dnsError) {
|
} catch (dnsError) {
|
||||||
await logError('app-deploy-dns', dnsError, { appId, subdomain: config.subdomain, ip: config.ip });
|
await logError('app-deploy-dns', dnsError, { appId, subdomain: config.subdomain, ip: config.ip });
|
||||||
@@ -420,10 +430,11 @@ module.exports = function({ docker, caddy, credentialManager, servicesStateManag
|
|||||||
|
|
||||||
res.json(response);
|
res.json(response);
|
||||||
} catch (error) {
|
} catch (error) {
|
||||||
await logError('app-deploy', error, { appId, config });
|
try { await logError('app-deploy', error, { appId, config }); } catch (_) { /* logError failure should not mask original error */ }
|
||||||
log.error('deploy', 'Deployment failed', { appId, error: error.message });
|
const msg = error?.message || String(error || 'Unknown error');
|
||||||
|
log.error('deploy', 'Deployment failed', { appId, error: msg });
|
||||||
const template = ctx.APP_TEMPLATES[appId];
|
const template = ctx.APP_TEMPLATES[appId];
|
||||||
ctx.notification.send('deploymentFailed', 'Deployment Failed', `Failed to deploy **${template?.name || appId}**.\nError: ${error.message}`, 'error');
|
try { ctx.notification.send('deploymentFailed', 'Deployment Failed', `Failed to deploy **${template?.name || appId}**.\nError: ${msg}`, 'error'); } catch (_) {}
|
||||||
errorResponse(res, 500, ctx.safeErrorMessage(error));
|
errorResponse(res, 500, ctx.safeErrorMessage(error));
|
||||||
}
|
}
|
||||||
}, 'apps-deploy'));
|
}, 'apps-deploy'));
|
||||||
|
|||||||
@@ -379,9 +379,12 @@ module.exports = function({ docker, caddy, credentialManager, servicesStateManag
|
|||||||
return content.slice(0, endIdx) + injection + content.slice(endIdx);
|
return content.slice(0, endIdx) + injection + content.slice(endIdx);
|
||||||
});
|
});
|
||||||
|
|
||||||
if (!result.success) {
|
if (!result.success && result.error !== 'No changes to apply') {
|
||||||
throw new Error(`[DC-303] Failed to add subpath config for ${subdomain}: ${result.error}`);
|
throw new Error(`[DC-303] Failed to add subpath config for ${subdomain}: ${result.error}`);
|
||||||
}
|
}
|
||||||
|
if (result.error === 'No changes to apply') {
|
||||||
|
log.info('caddy', 'Subpath config already exists, reusing', { subdomain });
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
/** Remove a subpath config block from between its markers in the Caddyfile. */
|
/** Remove a subpath config block from between its markers in the Caddyfile. */
|
||||||
|
|||||||
@@ -25,7 +25,6 @@ module.exports = function(ctx) {
|
|||||||
asyncHandler: ctx.asyncHandler,
|
asyncHandler: ctx.asyncHandler,
|
||||||
errorResponse: ctx.errorResponse,
|
errorResponse: ctx.errorResponse,
|
||||||
log: ctx.log,
|
log: ctx.log,
|
||||||
// Additional context properties needed by routes
|
|
||||||
APP_TEMPLATES: ctx.APP_TEMPLATES,
|
APP_TEMPLATES: ctx.APP_TEMPLATES,
|
||||||
TEMPLATE_CATEGORIES: ctx.TEMPLATE_CATEGORIES,
|
TEMPLATE_CATEGORIES: ctx.TEMPLATE_CATEGORIES,
|
||||||
DIFFICULTY_LEVELS: ctx.DIFFICULTY_LEVELS,
|
DIFFICULTY_LEVELS: ctx.DIFFICULTY_LEVELS,
|
||||||
@@ -40,26 +39,27 @@ module.exports = function(ctx) {
|
|||||||
ctx: ctx
|
ctx: ctx
|
||||||
};
|
};
|
||||||
|
|
||||||
// Initialize helpers with dependencies (ctx is the Koa context)
|
|
||||||
const helpers = initHelpers({ ...deps, ctx });
|
const helpers = initHelpers({ ...deps, ctx });
|
||||||
|
|
||||||
// Mount sub-routes — pass full ctx so sub-routes can reference ctx.* properties
|
|
||||||
const subCtx = Object.assign({}, ctx, { helpers });
|
const subCtx = Object.assign({}, ctx, { helpers });
|
||||||
|
|
||||||
try { router.use('/deploy', initDeploy(subCtx)); }
|
// Mount sub-routers at their prefix paths.
|
||||||
catch(e) { (ctx.log || console).error('[apps] deploy routes init failed:', e.message); }
|
// Sub-modules define routes at '/' (root of their sub-router).
|
||||||
|
// Final paths: /api/v1/apps/deploy, /api/v1/apps/remove, /api/v1/apps/templates, etc.
|
||||||
|
|
||||||
try { router.use('/remove', initRemoval(subCtx)); }
|
try { router.use('/apps', initDeploy(subCtx)); }
|
||||||
catch(e) { (ctx.log || console).error('[apps] removal routes init failed:', e.message); }
|
catch(e) { (ctx.log || console).error('[apps] deploy routes init failed:', e.message, e.stack); }
|
||||||
|
|
||||||
|
try { router.use('/apps', initRemoval(subCtx)); }
|
||||||
|
catch(e) { (ctx.log || console).error('[apps] removal routes init failed:', e.message, e.stack); }
|
||||||
|
|
||||||
try { router.use('/apps', initTemplates(subCtx)); }
|
try { router.use('/apps', initTemplates(subCtx)); }
|
||||||
catch(e) { (ctx.log || console).error('[apps] templates routes init failed:', e.message); }
|
catch(e) { (ctx.log || console).error('[apps] templates routes init failed:', e.message, e.stack); }
|
||||||
|
|
||||||
try { router.use('/restore', initRestore(Object.assign({}, subCtx, { backupManager: ctx.backupManager }))); }
|
try { router.use('/apps', initRestore(Object.assign({}, subCtx, { backupManager: ctx.backupManager }))); }
|
||||||
catch(e) { (ctx.log || console).error('[apps] restore routes init failed:', e.message); }
|
catch(e) { (ctx.log || console).error('[apps] restore routes init failed:', e.message, e.stack); }
|
||||||
|
|
||||||
try { router.use('/compose', initCompose(subCtx)); }
|
try { router.use('/apps', initCompose(subCtx)); }
|
||||||
catch(e) { (ctx.log || console).error('[apps] compose routes init failed:', e.message); }
|
catch(e) { (ctx.log || console).error('[apps] compose routes init failed:', e.message, e.stack); }
|
||||||
|
|
||||||
return router;
|
return router;
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -71,18 +71,13 @@ module.exports = function({
|
|||||||
if (shouldDeleteContainer && subdomain && ctx.dns.getToken()) {
|
if (shouldDeleteContainer && subdomain && ctx.dns.getToken()) {
|
||||||
try {
|
try {
|
||||||
const domain = ctx.buildDomain(subdomain);
|
const domain = ctx.buildDomain(subdomain);
|
||||||
const getResult = await ctx.dns.call(ctx.siteConfig.dnsServerIp, '/api/zones/records/get', {
|
const resolveResult = await ctx.dns.universalResolveRecord(domain, 'A');
|
||||||
token: ctx.dns.getToken(), domain, zone: ctx.siteConfig.tld.replace(/^\./, ''), listZone: 'true'
|
|
||||||
});
|
|
||||||
let recordIp = ip || 'localhost';
|
let recordIp = ip || 'localhost';
|
||||||
if (getResult.status === 'ok' && getResult.response?.records) {
|
if (resolveResult) {
|
||||||
const aRecord = getResult.response.records.find(r => r.type === 'A');
|
recordIp = resolveResult;
|
||||||
if (aRecord && aRecord.rData?.ipAddress) recordIp = aRecord.rData.ipAddress;
|
|
||||||
}
|
}
|
||||||
const dnsResult = await ctx.dns.call(ctx.siteConfig.dnsServerIp, '/api/zones/records/delete', {
|
await ctx.dns.universalDeleteRecord(domain, recordIp);
|
||||||
token: ctx.dns.getToken(), domain, type: 'A', ipAddress: recordIp
|
results.dns = 'deleted';
|
||||||
});
|
|
||||||
results.dns = dnsResult.status === 'ok' ? 'deleted' : (dnsResult.errorMessage || 'failed');
|
|
||||||
log.info('dns', 'DNS record removal', { result: results.dns });
|
log.info('dns', 'DNS record removal', { result: results.dns });
|
||||||
} catch (error) {
|
} catch (error) {
|
||||||
results.dns = error.message;
|
results.dns = error.message;
|
||||||
|
|||||||
@@ -458,7 +458,7 @@ module.exports = function({ docker, caddy, servicesStateManager, asyncHandler, e
|
|||||||
// DNS record
|
// DNS record
|
||||||
if (manifest.config.createDns && manifest.caddy.routingMode !== 'subdirectory') {
|
if (manifest.config.createDns && manifest.caddy.routingMode !== 'subdirectory') {
|
||||||
try {
|
try {
|
||||||
await ctx.dns.createRecord(manifest.config.subdomain, manifest.config.ip);
|
await ctx.dns.universalCreateRecord(manifest.config.subdomain, manifest.config.ip);
|
||||||
log.info('restore', 'DNS record recreated', { subdomain: manifest.config.subdomain });
|
log.info('restore', 'DNS record recreated', { subdomain: manifest.config.subdomain });
|
||||||
} catch (e) {
|
} catch (e) {
|
||||||
log.warn('restore', `DNS recreation failed: ${e.message}`);
|
log.warn('restore', `DNS recreation failed: ${e.message}`);
|
||||||
|
|||||||
@@ -107,10 +107,8 @@ module.exports = function({
|
|||||||
if (oldSubdomain && ctx.dns.getToken()) {
|
if (oldSubdomain && ctx.dns.getToken()) {
|
||||||
try {
|
try {
|
||||||
const oldDomain = oldSubdomain.includes('.') ? oldSubdomain : ctx.buildDomain(oldSubdomain);
|
const oldDomain = oldSubdomain.includes('.') ? oldSubdomain : ctx.buildDomain(oldSubdomain);
|
||||||
const result = await ctx.dns.call(ctx.siteConfig.dnsServerIp, '/api/zones/records/delete', {
|
await ctx.dns.universalDeleteRecord(oldDomain, ip || 'localhost');
|
||||||
token: ctx.dns.getToken(), domain: oldDomain, type: 'A', ipAddress: ip || 'localhost'
|
results.oldDns = 'deleted';
|
||||||
});
|
|
||||||
results.oldDns = result.status === 'ok' ? 'deleted' : result.errorMessage;
|
|
||||||
log.info('dns', 'Old DNS record deleted', { domain: oldDomain });
|
log.info('dns', 'Old DNS record deleted', { domain: oldDomain });
|
||||||
} catch (error) {
|
} catch (error) {
|
||||||
results.oldDns = `failed: ${error.message}`;
|
results.oldDns = `failed: ${error.message}`;
|
||||||
@@ -120,7 +118,7 @@ module.exports = function({
|
|||||||
|
|
||||||
if (newSubdomain && ctx.dns.getToken()) {
|
if (newSubdomain && ctx.dns.getToken()) {
|
||||||
try {
|
try {
|
||||||
await ctx.dns.createRecord(newSubdomain, ip || 'localhost');
|
await ctx.dns.universalCreateRecord(newSubdomain, ip || 'localhost');
|
||||||
results.newDns = 'created';
|
results.newDns = 'created';
|
||||||
log.info('dns', 'New DNS record created', { domain: ctx.buildDomain(newSubdomain) });
|
log.info('dns', 'New DNS record created', { domain: ctx.buildDomain(newSubdomain) });
|
||||||
} catch (error) {
|
} catch (error) {
|
||||||
|
|||||||
@@ -0,0 +1,164 @@
|
|||||||
|
/**
|
||||||
|
* Auto-Restart Policy Routes
|
||||||
|
*
|
||||||
|
* CRUD endpoints for per-container auto-restart policies.
|
||||||
|
* Also provides a dry-run test endpoint.
|
||||||
|
*
|
||||||
|
* @module routes/auto-restart
|
||||||
|
*/
|
||||||
|
|
||||||
|
const express = require('express');
|
||||||
|
const { success } = require('../src/utils/responses');
|
||||||
|
const { ValidationError, NotFoundError } = require('../errors');
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Auto-restart route factory
|
||||||
|
*
|
||||||
|
* @param {Object} deps - Explicit dependencies
|
||||||
|
* @param {Object} deps.autoRestartManager - AutoRestartManager instance
|
||||||
|
* @param {Function} deps.asyncHandler - Async route handler wrapper
|
||||||
|
* @param {Function} deps.logError - Error logging function
|
||||||
|
* @returns {express.Router}
|
||||||
|
*/
|
||||||
|
module.exports = function ({ autoRestartManager, asyncHandler, logError }) {
|
||||||
|
const router = express.Router();
|
||||||
|
|
||||||
|
/**
|
||||||
|
* GET /auto-restart/policies
|
||||||
|
* List all configured auto-restart policies.
|
||||||
|
*/
|
||||||
|
router.get('/policies', asyncHandler(async (_req, res) => {
|
||||||
|
const policies = autoRestartManager.listPolicies();
|
||||||
|
success(res, { policies });
|
||||||
|
}, 'auto-restart-list'));
|
||||||
|
|
||||||
|
/**
|
||||||
|
* GET /auto-restart/policies/:serviceId
|
||||||
|
* Get the restart policy for a single service.
|
||||||
|
*/
|
||||||
|
router.get('/policies/:serviceId', asyncHandler(async (req, res) => {
|
||||||
|
const { serviceId } = req.params;
|
||||||
|
|
||||||
|
if (!serviceId || !/^[a-zA-Z0-9][a-zA-Z0-9_.-]{0,100}$/.test(serviceId)) {
|
||||||
|
throw new ValidationError('Invalid service ID format');
|
||||||
|
}
|
||||||
|
|
||||||
|
const policy = autoRestartManager.getPolicy(serviceId);
|
||||||
|
if (!policy) {
|
||||||
|
throw new NotFoundError(`Auto-restart policy for "${serviceId}"`);
|
||||||
|
}
|
||||||
|
|
||||||
|
success(res, { policy });
|
||||||
|
}, 'auto-restart-get'));
|
||||||
|
|
||||||
|
/**
|
||||||
|
* POST /auto-restart/policies/:serviceId
|
||||||
|
* Create or update a restart policy.
|
||||||
|
*
|
||||||
|
* Body: { enabled, maxRetries, retryIntervalMs, windowMinutes }
|
||||||
|
*/
|
||||||
|
router.post('/policies/:serviceId', asyncHandler(async (req, res) => {
|
||||||
|
const { serviceId } = req.params;
|
||||||
|
|
||||||
|
if (!serviceId || !/^[a-zA-Z0-9][a-zA-Z0-9_.-]{0,100}$/.test(serviceId)) {
|
||||||
|
throw new ValidationError('Invalid service ID format');
|
||||||
|
}
|
||||||
|
|
||||||
|
const { enabled, maxRetries, retryIntervalMs, windowMinutes } = req.body;
|
||||||
|
|
||||||
|
// Validate inputs
|
||||||
|
if (enabled !== undefined && typeof enabled !== 'boolean') {
|
||||||
|
throw new ValidationError('enabled must be a boolean');
|
||||||
|
}
|
||||||
|
if (maxRetries !== undefined) {
|
||||||
|
if (!Number.isInteger(maxRetries) || maxRetries < 0 || maxRetries > 100) {
|
||||||
|
throw new ValidationError('maxRetries must be an integer between 0 and 100');
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if (retryIntervalMs !== undefined) {
|
||||||
|
if (!Number.isInteger(retryIntervalMs) || retryIntervalMs < 0 || retryIntervalMs > 3600000) {
|
||||||
|
throw new ValidationError('retryIntervalMs must be an integer between 0 and 3600000');
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if (windowMinutes !== undefined) {
|
||||||
|
if (!Number.isInteger(windowMinutes) || windowMinutes < 0 || windowMinutes > 1440) {
|
||||||
|
throw new ValidationError('windowMinutes must be an integer between 0 and 1440');
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
const policy = await autoRestartManager.setPolicy(serviceId, {
|
||||||
|
...(enabled !== undefined && { enabled }),
|
||||||
|
...(maxRetries !== undefined && { maxRetries }),
|
||||||
|
...(retryIntervalMs !== undefined && { retryIntervalMs }),
|
||||||
|
...(windowMinutes !== undefined && { windowMinutes }),
|
||||||
|
});
|
||||||
|
|
||||||
|
success(res, { policy, message: `Policy ${serviceId} saved` });
|
||||||
|
}, 'auto-restart-set'));
|
||||||
|
|
||||||
|
/**
|
||||||
|
* DELETE /auto-restart/policies/:serviceId
|
||||||
|
* Remove a restart policy.
|
||||||
|
*/
|
||||||
|
router.delete('/policies/:serviceId', asyncHandler(async (req, res) => {
|
||||||
|
const { serviceId } = req.params;
|
||||||
|
|
||||||
|
if (!serviceId || !/^[a-zA-Z0-9][a-zA-Z0-9_.-]{0,100}$/.test(serviceId)) {
|
||||||
|
throw new ValidationError('Invalid service ID format');
|
||||||
|
}
|
||||||
|
|
||||||
|
const removed = await autoRestartManager.removePolicy(serviceId);
|
||||||
|
if (!removed) {
|
||||||
|
throw new NotFoundError(`Auto-restart policy for "${serviceId}"`);
|
||||||
|
}
|
||||||
|
|
||||||
|
success(res, { message: `Policy for "${serviceId}" removed` });
|
||||||
|
}, 'auto-restart-delete'));
|
||||||
|
|
||||||
|
/**
|
||||||
|
* POST /auto-restart/policies/:serviceId/test
|
||||||
|
* Dry-run: simulate a restart attempt without actually restarting.
|
||||||
|
* Returns what *would* happen given the current policy state.
|
||||||
|
*/
|
||||||
|
router.post('/policies/:serviceId/test', asyncHandler(async (req, res) => {
|
||||||
|
const { serviceId } = req.params;
|
||||||
|
|
||||||
|
if (!serviceId || !/^[a-zA-Z0-9][a-zA-Z0-9_.-]{0,100}$/.test(serviceId)) {
|
||||||
|
throw new ValidationError('Invalid service ID format');
|
||||||
|
}
|
||||||
|
|
||||||
|
const policy = autoRestartManager.getPolicy(serviceId);
|
||||||
|
if (!policy) {
|
||||||
|
throw new NotFoundError(`Auto-restart policy for "${serviceId}"`);
|
||||||
|
}
|
||||||
|
|
||||||
|
const now = Date.now();
|
||||||
|
const inCooldown = policy.cooldownUntil && now < policy.cooldownUntil;
|
||||||
|
const wouldRetry = !inCooldown && policy.currentRetries < policy.maxRetries;
|
||||||
|
const nextAttempt = policy.currentRetries + 1;
|
||||||
|
|
||||||
|
success(res, {
|
||||||
|
dryRun: true,
|
||||||
|
serviceId,
|
||||||
|
policy: {
|
||||||
|
enabled: policy.enabled,
|
||||||
|
currentRetries: policy.currentRetries,
|
||||||
|
maxRetries: policy.maxRetries,
|
||||||
|
cooldownUntil: policy.cooldownUntil,
|
||||||
|
inCooldown,
|
||||||
|
},
|
||||||
|
wouldRestart: policy.enabled && wouldRetry,
|
||||||
|
wouldMaxOut: !wouldRetry && !inCooldown,
|
||||||
|
nextAttempt: wouldRetry ? nextAttempt : null,
|
||||||
|
message: !policy.enabled
|
||||||
|
? 'Policy is disabled — no restart would occur'
|
||||||
|
: inCooldown
|
||||||
|
? `In cooldown until ${new Date(policy.cooldownUntil).toISOString()} — would skip`
|
||||||
|
: wouldRetry
|
||||||
|
? `Would attempt restart ${nextAttempt}/${policy.maxRetries}`
|
||||||
|
: `Max retries (${policy.maxRetries}) already reached — would enter cooldown`,
|
||||||
|
});
|
||||||
|
}, 'auto-restart-test'));
|
||||||
|
|
||||||
|
return router;
|
||||||
|
};
|
||||||
@@ -1,5 +1,5 @@
|
|||||||
const express = require('express');
|
const express = require('express');
|
||||||
const { success } = require('../response-helpers');
|
const { success } = require('../src/utils/responses');
|
||||||
const fs = require('fs');
|
const fs = require('fs');
|
||||||
const path = require('path');
|
const path = require('path');
|
||||||
|
|
||||||
|
|||||||
+10
-16
@@ -12,14 +12,11 @@ module.exports = function(ctx) {
|
|||||||
|
|
||||||
// Get CA certificate information
|
// Get CA certificate information
|
||||||
router.get('/info', ctx.asyncHandler(async (req, res) => {
|
router.get('/info', ctx.asyncHandler(async (req, res) => {
|
||||||
const certInfoPath = '/app/ca/cert-info.json';
|
const certInfoPath = path.join(platformPaths.caCertDir, 'cert-info.json');
|
||||||
const fallbackCertInfoPath = path.join(platformPaths.caCertDir, 'cert-info.json');
|
|
||||||
|
|
||||||
let certInfoFile;
|
let certInfoFile;
|
||||||
if (await exists(certInfoPath)) {
|
if (await exists(certInfoPath)) {
|
||||||
certInfoFile = certInfoPath;
|
certInfoFile = certInfoPath;
|
||||||
} else if (await exists(fallbackCertInfoPath)) {
|
|
||||||
certInfoFile = fallbackCertInfoPath;
|
|
||||||
} else {
|
} else {
|
||||||
const { NotFoundError } = require('../errors');
|
const { NotFoundError } = require('../errors');
|
||||||
throw new NotFoundError('CA certificate information');
|
throw new NotFoundError('CA certificate information');
|
||||||
@@ -46,13 +43,11 @@ module.exports = function(ctx) {
|
|||||||
|
|
||||||
// Serve root CA certificate directly (works even without DashCA deployed)
|
// Serve root CA certificate directly (works even without DashCA deployed)
|
||||||
router.get('/root.crt', ctx.asyncHandler(async (req, res) => {
|
router.get('/root.crt', ctx.asyncHandler(async (req, res) => {
|
||||||
const pkiCertPath = '/app/pki/root.crt';
|
|
||||||
const hostCertPath = platformPaths.pkiRootCert;
|
const hostCertPath = platformPaths.pkiRootCert;
|
||||||
const dashcaCertPath = path.join(platformPaths.caCertDir, 'root.crt');
|
const dashcaCertPath = path.join(platformPaths.caCertDir, 'root.crt');
|
||||||
|
|
||||||
let certPath;
|
let certPath;
|
||||||
if (await exists(pkiCertPath)) certPath = pkiCertPath;
|
if (await exists(dashcaCertPath)) certPath = dashcaCertPath;
|
||||||
else if (await exists(dashcaCertPath)) certPath = dashcaCertPath;
|
|
||||||
else if (await exists(hostCertPath)) certPath = hostCertPath;
|
else if (await exists(hostCertPath)) certPath = hostCertPath;
|
||||||
else {
|
else {
|
||||||
const { NotFoundError } = require('../errors');
|
const { NotFoundError } = require('../errors');
|
||||||
@@ -72,13 +67,12 @@ module.exports = function(ctx) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
// Load cert info to get the fingerprint
|
// Load cert info to get the fingerprint
|
||||||
const certInfoPath = '/app/ca/cert-info.json';
|
const certInfoPath = path.join(platformPaths.caCertDir, 'cert-info.json');
|
||||||
const fallbackCertInfoPath2 = path.join(platformPaths.caCertDir, 'cert-info.json');
|
|
||||||
|
|
||||||
let certInfoFile;
|
let certInfoFile;
|
||||||
if (await exists(certInfoPath)) certInfoFile = certInfoPath;
|
if (await exists(certInfoPath)) {
|
||||||
else if (await exists(fallbackCertInfoPath2)) certInfoFile = fallbackCertInfoPath2;
|
certInfoFile = certInfoPath;
|
||||||
else {
|
} else {
|
||||||
const { NotFoundError } = require('../errors');
|
const { NotFoundError } = require('../errors');
|
||||||
throw new NotFoundError('CA certificate information. Deploy DashCA first or ensure cert-info.json exists.');
|
throw new NotFoundError('CA certificate information. Deploy DashCA first or ensure cert-info.json exists.');
|
||||||
}
|
}
|
||||||
@@ -100,7 +94,7 @@ module.exports = function(ctx) {
|
|||||||
// Look for template in multiple locations (packaged app vs dev)
|
// Look for template in multiple locations (packaged app vs dev)
|
||||||
const templatePaths = [
|
const templatePaths = [
|
||||||
path.join(__dirname, '..', 'scripts', templateName),
|
path.join(__dirname, '..', 'scripts', templateName),
|
||||||
path.join('/app', 'scripts', templateName)
|
path.join(platformPaths.caddyBase, 'scripts', templateName)
|
||||||
];
|
];
|
||||||
|
|
||||||
let templateContent;
|
let templateContent;
|
||||||
@@ -142,8 +136,8 @@ module.exports = function(ctx) {
|
|||||||
return ctx.errorResponse(res, 400, `Invalid domain name. Must be a valid hostname (e.g., dns1${ctx.siteConfig.tld})`);
|
return ctx.errorResponse(res, 400, `Invalid domain name. Must be a valid hostname (e.g., dns1${ctx.siteConfig.tld})`);
|
||||||
}
|
}
|
||||||
|
|
||||||
const pkiPath = '/app/pki';
|
const pkiPath = platformPaths.pkiDir;
|
||||||
const certsDir = '/app/generated-certs';
|
const certsDir = platformPaths.generatedCertsDir;
|
||||||
const domainDir = path.join(certsDir, domain);
|
const domainDir = path.join(certsDir, domain);
|
||||||
|
|
||||||
const intermediateCert = path.join(pkiPath, 'intermediate.crt');
|
const intermediateCert = path.join(pkiPath, 'intermediate.crt');
|
||||||
@@ -246,7 +240,7 @@ ${safeDomain.includes('.') ? `DNS.2 = *.${safeDomain}` : ''}`;
|
|||||||
|
|
||||||
// List generated certificates
|
// List generated certificates
|
||||||
router.get('/certs', ctx.asyncHandler(async (req, res) => {
|
router.get('/certs', ctx.asyncHandler(async (req, res) => {
|
||||||
const certsDir = '/app/generated-certs';
|
const certsDir = platformPaths.generatedCertsDir;
|
||||||
|
|
||||||
if (!await exists(certsDir)) {
|
if (!await exists(certsDir)) {
|
||||||
return res.json({ success: true, certificates: [] });
|
return res.json({ success: true, certificates: [] });
|
||||||
|
|||||||
@@ -0,0 +1,92 @@
|
|||||||
|
/**
|
||||||
|
* Config Drift Detection Routes
|
||||||
|
*
|
||||||
|
* API endpoints for running drift detection, reading cached reports,
|
||||||
|
* auto-fixing drift, and controlling periodic polling.
|
||||||
|
*
|
||||||
|
* @module routes/config-drift
|
||||||
|
*/
|
||||||
|
|
||||||
|
const express = require('express');
|
||||||
|
const { success } = require('../src/utils/responses');
|
||||||
|
const { ValidationError, NotFoundError } = require('../errors');
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Config-drift route factory
|
||||||
|
*
|
||||||
|
* @param {Object} deps - Explicit dependencies
|
||||||
|
* @param {Object} deps.driftDetector - ConfigDriftDetector instance
|
||||||
|
* @param {Function} deps.asyncHandler - Async route handler wrapper
|
||||||
|
* @param {Function} deps.logError - Error logging function
|
||||||
|
* @returns {express.Router}
|
||||||
|
*/
|
||||||
|
module.exports = function ({ driftDetector, asyncHandler, logError }) {
|
||||||
|
const router = express.Router();
|
||||||
|
|
||||||
|
/**
|
||||||
|
* GET /config-drift/report
|
||||||
|
* Run a fresh drift detection and return the full report.
|
||||||
|
*/
|
||||||
|
router.get('/report', asyncHandler(async (_req, res) => {
|
||||||
|
const report = await driftDetector.detect();
|
||||||
|
success(res, { report });
|
||||||
|
}, 'drift-report'));
|
||||||
|
|
||||||
|
/**
|
||||||
|
* GET /config-drift/last
|
||||||
|
* Return the last cached drift report (no re-detection).
|
||||||
|
*/
|
||||||
|
router.get('/last', asyncHandler(async (_req, res) => {
|
||||||
|
if (!driftDetector.lastReport) {
|
||||||
|
throw new NotFoundError('No cached drift report — run detection first');
|
||||||
|
}
|
||||||
|
|
||||||
|
success(res, { report: driftDetector.lastReport });
|
||||||
|
}, 'drift-last'));
|
||||||
|
|
||||||
|
/**
|
||||||
|
* POST /config-drift/fix
|
||||||
|
* Auto-fix detected drift: remove stale records, flag unknown containers.
|
||||||
|
*/
|
||||||
|
router.post('/fix', asyncHandler(async (_req, res) => {
|
||||||
|
const result = await driftDetector.autoFix();
|
||||||
|
success(res, {
|
||||||
|
message: 'Auto-fix applied',
|
||||||
|
staleRemoved: result.staleRemoved,
|
||||||
|
unknownFlagged: result.unknownFlagged,
|
||||||
|
});
|
||||||
|
}, 'drift-fix'));
|
||||||
|
|
||||||
|
/**
|
||||||
|
* POST /config-drift/polling
|
||||||
|
* Enable or disable periodic drift detection polling.
|
||||||
|
*
|
||||||
|
* Body: { enabled: boolean, intervalMs?: number }
|
||||||
|
*/
|
||||||
|
router.post('/polling', asyncHandler(async (req, res) => {
|
||||||
|
const { enabled, intervalMs } = req.body;
|
||||||
|
|
||||||
|
if (typeof enabled !== 'boolean') {
|
||||||
|
throw new ValidationError('enabled must be a boolean');
|
||||||
|
}
|
||||||
|
|
||||||
|
if (intervalMs !== undefined) {
|
||||||
|
if (!Number.isInteger(intervalMs) || intervalMs < 10000 || intervalMs > 86400000) {
|
||||||
|
throw new ValidationError('intervalMs must be an integer between 10000 and 86400000 (10s – 24h)');
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
if (enabled) {
|
||||||
|
driftDetector.startPolling(intervalMs || 300000);
|
||||||
|
success(res, {
|
||||||
|
message: 'Drift polling enabled',
|
||||||
|
intervalMs: intervalMs || 300000,
|
||||||
|
});
|
||||||
|
} else {
|
||||||
|
driftDetector.stopPolling();
|
||||||
|
success(res, { message: 'Drift polling disabled' });
|
||||||
|
}
|
||||||
|
}, 'drift-polling'));
|
||||||
|
|
||||||
|
return router;
|
||||||
|
};
|
||||||
@@ -4,6 +4,7 @@ const path = require('path');
|
|||||||
const { LIMITS } = require('../../constants');
|
const { LIMITS } = require('../../constants');
|
||||||
const { exists } = require('../../fs-helpers');
|
const { exists } = require('../../fs-helpers');
|
||||||
const { ValidationError } = require('../../errors');
|
const { ValidationError } = require('../../errors');
|
||||||
|
const platformPaths = require('../../platform-paths');
|
||||||
/**
|
/**
|
||||||
* Config assets routes factory
|
* Config assets routes factory
|
||||||
* @param {Object} deps - Explicit dependencies
|
* @param {Object} deps - Explicit dependencies
|
||||||
@@ -51,7 +52,7 @@ module.exports = function({ servicesStateManager: _servicesStateManager, asyncHa
|
|||||||
const buffer = Buffer.from(base64Data, 'base64');
|
const buffer = Buffer.from(base64Data, 'base64');
|
||||||
|
|
||||||
// Determine assets path (mounted volume)
|
// Determine assets path (mounted volume)
|
||||||
const assetsPath = process.env.ASSETS_PATH || '/app/assets';
|
const assetsPath = platformPaths.resolveAssetsPath(process.env.ASSETS_PATH);
|
||||||
|
|
||||||
// Ensure directory exists
|
// Ensure directory exists
|
||||||
if (!await exists(assetsPath)) {
|
if (!await exists(assetsPath)) {
|
||||||
@@ -96,7 +97,7 @@ module.exports = function({ servicesStateManager: _servicesStateManager, asyncHa
|
|||||||
const extension = matches[1] === 'svg+xml' ? 'svg' : matches[1];
|
const extension = matches[1] === 'svg+xml' ? 'svg' : matches[1];
|
||||||
const buffer = Buffer.from(matches[2], 'base64');
|
const buffer = Buffer.from(matches[2], 'base64');
|
||||||
|
|
||||||
const assetsPath = process.env.ASSETS_PATH || '/app/assets';
|
const assetsPath = platformPaths.resolveAssetsPath(process.env.ASSETS_PATH);
|
||||||
if (!await exists(assetsPath)) {
|
if (!await exists(assetsPath)) {
|
||||||
await fsp.mkdir(assetsPath, { recursive: true });
|
await fsp.mkdir(assetsPath, { recursive: true });
|
||||||
}
|
}
|
||||||
@@ -170,7 +171,7 @@ module.exports = function({ servicesStateManager: _servicesStateManager, asyncHa
|
|||||||
// Reset all branding to defaults
|
// Reset all branding to defaults
|
||||||
router.delete('/logo', asyncHandler(async (req, res) => {
|
router.delete('/logo', asyncHandler(async (req, res) => {
|
||||||
const config = await ctx.readConfig();
|
const config = await ctx.readConfig();
|
||||||
const assetsPath = process.env.ASSETS_PATH || '/app/assets';
|
const assetsPath = platformPaths.resolveAssetsPath(process.env.ASSETS_PATH);
|
||||||
|
|
||||||
// Delete all custom logo files
|
// Delete all custom logo files
|
||||||
const logoPaths = [config.customLogo, config.customLogoDark, config.customLogoLight].filter(Boolean);
|
const logoPaths = [config.customLogo, config.customLogoDark, config.customLogoLight].filter(Boolean);
|
||||||
@@ -234,7 +235,7 @@ module.exports = function({ servicesStateManager: _servicesStateManager, asyncHa
|
|||||||
const base64Data = matches[2];
|
const base64Data = matches[2];
|
||||||
const buffer = Buffer.from(base64Data, 'base64');
|
const buffer = Buffer.from(base64Data, 'base64');
|
||||||
|
|
||||||
const assetsPath = process.env.ASSETS_PATH || '/app/assets';
|
const assetsPath = platformPaths.resolveAssetsPath(process.env.ASSETS_PATH);
|
||||||
if (!await exists(assetsPath)) {
|
if (!await exists(assetsPath)) {
|
||||||
await fsp.mkdir(assetsPath, { recursive: true });
|
await fsp.mkdir(assetsPath, { recursive: true });
|
||||||
}
|
}
|
||||||
@@ -279,7 +280,7 @@ module.exports = function({ servicesStateManager: _servicesStateManager, asyncHa
|
|||||||
const config = await ctx.readConfig();
|
const config = await ctx.readConfig();
|
||||||
|
|
||||||
// Delete custom favicon files
|
// Delete custom favicon files
|
||||||
const assetsPath = process.env.ASSETS_PATH || '/app/assets';
|
const assetsPath = platformPaths.resolveAssetsPath(process.env.ASSETS_PATH);
|
||||||
const filesToDelete = ['favicon.ico', 'favicon.png'];
|
const filesToDelete = ['favicon.ico', 'favicon.png'];
|
||||||
for (const file of filesToDelete) {
|
for (const file of filesToDelete) {
|
||||||
const filePath = `${assetsPath}/${file}`;
|
const filePath = `${assetsPath}/${file}`;
|
||||||
|
|||||||
@@ -4,6 +4,7 @@ const path = require('path');
|
|||||||
const { CADDY } = require('../../constants');
|
const { CADDY } = require('../../constants');
|
||||||
const { exists } = require('../../fs-helpers');
|
const { exists } = require('../../fs-helpers');
|
||||||
const { ValidationError, AuthenticationError } = require('../../errors');
|
const { ValidationError, AuthenticationError } = require('../../errors');
|
||||||
|
const platformPaths = require('../../platform-paths');
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Config backup routes factory
|
* Config backup routes factory
|
||||||
@@ -115,7 +116,7 @@ module.exports = function(deps) {
|
|||||||
|
|
||||||
// Include custom assets (logo, favicon) as base64
|
// Include custom assets (logo, favicon) as base64
|
||||||
try {
|
try {
|
||||||
const assetsDir = process.env.ASSETS_DIR || '/app/assets';
|
const assetsDir = platformPaths.resolveAssetsPath(process.env.ASSETS_DIR);
|
||||||
const configData = backup.files.config?.data || {};
|
const configData = backup.files.config?.data || {};
|
||||||
const assetFiles = [configData.customLogo, configData.customFavicon]
|
const assetFiles = [configData.customLogo, configData.customFavicon]
|
||||||
.filter(Boolean)
|
.filter(Boolean)
|
||||||
@@ -346,7 +347,7 @@ module.exports = function(deps) {
|
|||||||
|
|
||||||
// Restore custom assets from base64
|
// Restore custom assets from base64
|
||||||
if (backup.assets && typeof backup.assets === 'object') {
|
if (backup.assets && typeof backup.assets === 'object') {
|
||||||
const assetsDir = process.env.ASSETS_DIR || '/app/assets';
|
const assetsDir = platformPaths.resolveAssetsPath(process.env.ASSETS_DIR);
|
||||||
for (const [name, b64] of Object.entries(backup.assets)) {
|
for (const [name, b64] of Object.entries(backup.assets)) {
|
||||||
try {
|
try {
|
||||||
const safeName = path.basename(name); // prevent path traversal
|
const safeName = path.basename(name); // prevent path traversal
|
||||||
|
|||||||
@@ -2,7 +2,7 @@ const express = require('express');
|
|||||||
const { DOCKER } = require('../constants');
|
const { DOCKER } = require('../constants');
|
||||||
const { paginate, parsePaginationParams } = require('../pagination');
|
const { paginate, parsePaginationParams } = require('../pagination');
|
||||||
const { NotFoundError } = require('../errors');
|
const { NotFoundError } = require('../errors');
|
||||||
const { success } = require('../response-helpers');
|
const { success } = require('../src/utils/responses');
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Containers route factory
|
* Containers route factory
|
||||||
@@ -10,9 +10,10 @@ const { success } = require('../response-helpers');
|
|||||||
* @param {Object} deps.docker - Docker client wrapper (client, pull methods)
|
* @param {Object} deps.docker - Docker client wrapper (client, pull methods)
|
||||||
* @param {Object} deps.log - Logger instance
|
* @param {Object} deps.log - Logger instance
|
||||||
* @param {Function} deps.asyncHandler - Async route handler wrapper
|
* @param {Function} deps.asyncHandler - Async route handler wrapper
|
||||||
|
* @param {Object} deps.workflowEngine - WorkflowEngine instance (optional)
|
||||||
* @returns {express.Router}
|
* @returns {express.Router}
|
||||||
*/
|
*/
|
||||||
module.exports = function({ docker, log, asyncHandler }) {
|
module.exports = function({ docker, log, asyncHandler, workflowEngine }) {
|
||||||
const router = express.Router();
|
const router = express.Router();
|
||||||
|
|
||||||
// Helper: verify container exists before operating on it
|
// Helper: verify container exists before operating on it
|
||||||
@@ -66,6 +67,11 @@ module.exports = function({ docker, log, asyncHandler }) {
|
|||||||
log.info('docker', `Pulling latest image: ${imageName}`);
|
log.info('docker', `Pulling latest image: ${imageName}`);
|
||||||
await docker.pull(imageName);
|
await docker.pull(imageName);
|
||||||
|
|
||||||
|
// Trigger pre-update workflow (backup before update)
|
||||||
|
if (workflowEngine) {
|
||||||
|
try { await workflowEngine.triggerEvent('pre-update', { containerId: containerId, containerName, imageName }); } catch (w) { log.warn('workflow', 'pre-update trigger failed: ' + w.message); }
|
||||||
|
}
|
||||||
|
|
||||||
// Get current container config for recreation
|
// Get current container config for recreation
|
||||||
const hostConfig = containerInfo.HostConfig;
|
const hostConfig = containerInfo.HostConfig;
|
||||||
const config = {
|
const config = {
|
||||||
@@ -135,10 +141,15 @@ module.exports = function({ docker, log, asyncHandler }) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
success(res, {
|
success(res, {
|
||||||
message: `Container ${containerName} updated successfully`,
|
message: `Container ${containerName} updated successfully`,
|
||||||
newContainerId: newContainerInfo.Id
|
newContainerId: newContainerInfo.Id
|
||||||
});
|
});
|
||||||
}, 'container-update'));
|
|
||||||
|
// Trigger post-update workflow
|
||||||
|
if (workflowEngine) {
|
||||||
|
try { await workflowEngine.triggerEvent('post-update', { containerId: containerId, containerName, imageName, newContainerId: newContainerInfo.Id }); } catch (w) { log.warn('workflow', 'post-update trigger failed: ' + w.message); }
|
||||||
|
}
|
||||||
|
}, 'container-update'));
|
||||||
|
|
||||||
// Check for available updates (compares local and remote image digests)
|
// Check for available updates (compares local and remote image digests)
|
||||||
router.get('/:id/check-update', asyncHandler(async (req, res) => {
|
router.get('/:id/check-update', asyncHandler(async (req, res) => {
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
const express = require('express');
|
const express = require('express');
|
||||||
const { success, error: errorResponse } = require('../response-helpers');
|
const { success, error: errorResponse } = require('../src/utils/responses');
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Credentials routes factory
|
* Credentials routes factory
|
||||||
|
|||||||
@@ -0,0 +1,235 @@
|
|||||||
|
/**
|
||||||
|
* Dependencies Route — REST API for service dependency tracking
|
||||||
|
*
|
||||||
|
* Endpoints:
|
||||||
|
* GET /dependencies/graph Full dependency graph
|
||||||
|
* GET /dependencies/validate Validate a proposed dep chain
|
||||||
|
* GET /dependencies/:serviceId Direct deps for one service
|
||||||
|
* GET /dependencies/:serviceId/chain Ordered restart chain
|
||||||
|
* GET /dependencies/:serviceId/status Dependency health status
|
||||||
|
* POST /dependencies/:serviceId Set dependencies
|
||||||
|
* DELETE /dependencies/:serviceId Remove all dependencies
|
||||||
|
* POST /dependencies/:serviceId/restart Restart with dependency chain
|
||||||
|
*
|
||||||
|
* @module routes/dependencies
|
||||||
|
*/
|
||||||
|
|
||||||
|
const express = require('express');
|
||||||
|
const { success, error: errorResponse } = require('../src/utils/responses');
|
||||||
|
const { NotFoundError, ValidationError } = require('../errors');
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Dependencies route factory
|
||||||
|
*
|
||||||
|
* @param {Object} deps - Explicit dependencies
|
||||||
|
* @param {Object} deps.dependencyManager - DependencyManager instance
|
||||||
|
* @param {Object} deps.servicesStateManager - State manager for services.json
|
||||||
|
* @param {Object} deps.docker - Docker client wrapper
|
||||||
|
* @param {Function} deps.asyncHandler - Async route handler wrapper
|
||||||
|
* @param {Function} deps.logError - Error logging function
|
||||||
|
* @param {Function} deps.resyncHealthChecker - Health checker resync function
|
||||||
|
* @param {Object} deps.log - Logger instance
|
||||||
|
* @returns {express.Router}
|
||||||
|
*/
|
||||||
|
module.exports = function({
|
||||||
|
dependencyManager,
|
||||||
|
servicesStateManager,
|
||||||
|
docker,
|
||||||
|
asyncHandler,
|
||||||
|
logError,
|
||||||
|
resyncHealthChecker,
|
||||||
|
log,
|
||||||
|
}) {
|
||||||
|
const router = express.Router();
|
||||||
|
|
||||||
|
// -------------------------------------------------------------------------
|
||||||
|
// GET /dependencies/graph — Full dependency graph
|
||||||
|
// -------------------------------------------------------------------------
|
||||||
|
router.get('/graph', asyncHandler(async (req, res) => {
|
||||||
|
const graph = await dependencyManager.getDependencyGraph();
|
||||||
|
success(res, { graph });
|
||||||
|
}, 'dep-graph'));
|
||||||
|
|
||||||
|
// -------------------------------------------------------------------------
|
||||||
|
// GET /dependencies/validate — Validate a proposed dep chain (query params)
|
||||||
|
// -------------------------------------------------------------------------
|
||||||
|
router.get('/validate', asyncHandler(async (req, res) => {
|
||||||
|
const { serviceId, dependsOn } = req.query;
|
||||||
|
|
||||||
|
if (!serviceId) {
|
||||||
|
throw new ValidationError('serviceId query parameter is required');
|
||||||
|
}
|
||||||
|
|
||||||
|
// dependsOn may be a comma-separated string or already an array
|
||||||
|
let parsed;
|
||||||
|
if (Array.isArray(dependsOn)) {
|
||||||
|
parsed = dependsOn;
|
||||||
|
} else if (typeof dependsOn === 'string' && dependsOn.length > 0) {
|
||||||
|
parsed = dependsOn.split(',').map(s => s.trim()).filter(Boolean);
|
||||||
|
} else {
|
||||||
|
parsed = [];
|
||||||
|
}
|
||||||
|
|
||||||
|
const result = await dependencyManager.validateDependencies(serviceId, parsed);
|
||||||
|
success(res, result);
|
||||||
|
}, 'dep-validate'));
|
||||||
|
|
||||||
|
// -------------------------------------------------------------------------
|
||||||
|
// GET /dependencies/:serviceId — Direct deps for one service
|
||||||
|
// -------------------------------------------------------------------------
|
||||||
|
router.get('/:serviceId', asyncHandler(async (req, res) => {
|
||||||
|
const { serviceId } = req.params;
|
||||||
|
const dependencies = await dependencyManager.getDependencies(serviceId);
|
||||||
|
const dependents = await dependencyManager.getDependents(serviceId);
|
||||||
|
|
||||||
|
// Read the service's current dependsOn array
|
||||||
|
const services = await servicesStateManager.read();
|
||||||
|
const allServices = Array.isArray(services) ? services : (services.services || []);
|
||||||
|
const service = allServices.find(s => s.id === serviceId);
|
||||||
|
|
||||||
|
if (!service) {
|
||||||
|
throw new NotFoundError(`Service "${serviceId}"`);
|
||||||
|
}
|
||||||
|
|
||||||
|
success(res, {
|
||||||
|
serviceId,
|
||||||
|
dependsOn: service.dependsOn || [],
|
||||||
|
dependencies,
|
||||||
|
dependents: dependents.map(d => ({ id: d.id, name: d.name })),
|
||||||
|
});
|
||||||
|
}, 'dep-get'));
|
||||||
|
|
||||||
|
// -------------------------------------------------------------------------
|
||||||
|
// GET /dependencies/:serviceId/chain — Ordered restart chain
|
||||||
|
// -------------------------------------------------------------------------
|
||||||
|
router.get('/:serviceId/chain', asyncHandler(async (req, res) => {
|
||||||
|
const { serviceId } = req.params;
|
||||||
|
const chain = await dependencyManager.getOrderedRestartChain(serviceId);
|
||||||
|
success(res, { serviceId, chain });
|
||||||
|
}, 'dep-chain'));
|
||||||
|
|
||||||
|
// -------------------------------------------------------------------------
|
||||||
|
// GET /dependencies/:serviceId/status — Dependency health status
|
||||||
|
// -------------------------------------------------------------------------
|
||||||
|
router.get('/:serviceId/status', asyncHandler(async (req, res) => {
|
||||||
|
const { serviceId } = req.params;
|
||||||
|
const statuses = await dependencyManager.getDependencyStatus(serviceId);
|
||||||
|
success(res, { serviceId, statuses });
|
||||||
|
}, 'dep-status'));
|
||||||
|
|
||||||
|
// -------------------------------------------------------------------------
|
||||||
|
// POST /dependencies/:serviceId — Set dependencies
|
||||||
|
// -------------------------------------------------------------------------
|
||||||
|
router.post('/:serviceId', asyncHandler(async (req, res) => {
|
||||||
|
const { serviceId } = req.params;
|
||||||
|
const { dependsOn } = req.body;
|
||||||
|
|
||||||
|
if (!Array.isArray(dependsOn)) {
|
||||||
|
throw new ValidationError('Request body must include dependsOn as an array of service IDs');
|
||||||
|
}
|
||||||
|
|
||||||
|
// Validate first
|
||||||
|
const validation = await dependencyManager.validateDependencies(serviceId, dependsOn);
|
||||||
|
if (!validation.valid) {
|
||||||
|
return errorResponse(res, validation.errors.join('; '), 400);
|
||||||
|
}
|
||||||
|
|
||||||
|
// Update the service
|
||||||
|
let found = false;
|
||||||
|
await servicesStateManager.update(services => {
|
||||||
|
const arr = Array.isArray(services) ? services : [];
|
||||||
|
return arr.map(s => {
|
||||||
|
if (s.id === serviceId) {
|
||||||
|
found = true;
|
||||||
|
return { ...s, dependsOn: dependsOn.slice() };
|
||||||
|
}
|
||||||
|
return s;
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
if (!found) {
|
||||||
|
throw new NotFoundError(`Service "${serviceId}"`);
|
||||||
|
}
|
||||||
|
|
||||||
|
log.info('dependency', 'Dependencies updated', { serviceId, dependsOn });
|
||||||
|
|
||||||
|
success(res, {
|
||||||
|
message: `Dependencies updated for "${serviceId}"`,
|
||||||
|
serviceId,
|
||||||
|
dependsOn,
|
||||||
|
});
|
||||||
|
}, 'dep-set'));
|
||||||
|
|
||||||
|
// -------------------------------------------------------------------------
|
||||||
|
// DELETE /dependencies/:serviceId — Remove all dependencies for a service
|
||||||
|
// -------------------------------------------------------------------------
|
||||||
|
router.delete('/:serviceId', asyncHandler(async (req, res) => {
|
||||||
|
const { serviceId } = req.params;
|
||||||
|
|
||||||
|
let found = false;
|
||||||
|
await servicesStateManager.update(services => {
|
||||||
|
const arr = Array.isArray(services) ? services : [];
|
||||||
|
return arr.map(s => {
|
||||||
|
if (s.id === serviceId) {
|
||||||
|
found = true;
|
||||||
|
const updated = { ...s };
|
||||||
|
delete updated.dependsOn;
|
||||||
|
return updated;
|
||||||
|
}
|
||||||
|
return s;
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
if (!found) {
|
||||||
|
throw new NotFoundError(`Service "${serviceId}"`);
|
||||||
|
}
|
||||||
|
|
||||||
|
log.info('dependency', 'Dependencies removed', { serviceId });
|
||||||
|
|
||||||
|
success(res, {
|
||||||
|
message: `All dependencies removed for "${serviceId}"`,
|
||||||
|
serviceId,
|
||||||
|
});
|
||||||
|
}, 'dep-delete'));
|
||||||
|
|
||||||
|
// -------------------------------------------------------------------------
|
||||||
|
// POST /dependencies/:serviceId/restart — Restart with dependency chain
|
||||||
|
// -------------------------------------------------------------------------
|
||||||
|
router.post('/:serviceId/restart', asyncHandler(async (req, res) => {
|
||||||
|
const { serviceId } = req.params;
|
||||||
|
|
||||||
|
// Verify the service exists
|
||||||
|
const services = await servicesStateManager.read();
|
||||||
|
const allServices = Array.isArray(services) ? services : (services.services || []);
|
||||||
|
if (!allServices.find(s => s.id === serviceId)) {
|
||||||
|
throw new NotFoundError(`Service "${serviceId}"`);
|
||||||
|
}
|
||||||
|
|
||||||
|
// Get the chain first for the response (before async restart begins)
|
||||||
|
let chain;
|
||||||
|
try {
|
||||||
|
chain = await dependencyManager.getOrderedRestartChain(serviceId);
|
||||||
|
} catch (err) {
|
||||||
|
return errorResponse(res, err.message, 400);
|
||||||
|
}
|
||||||
|
|
||||||
|
// Respond immediately with the chain order
|
||||||
|
success(res, {
|
||||||
|
message: `Dependency restart initiated for "${serviceId}"`,
|
||||||
|
serviceId,
|
||||||
|
chain,
|
||||||
|
});
|
||||||
|
|
||||||
|
// Run the restart chain asynchronously so the client doesn't block
|
||||||
|
dependencyManager.restartWithDependencies(serviceId).catch(err => {
|
||||||
|
if (log) {
|
||||||
|
log.error('dependency', 'Async dependency restart failed', {
|
||||||
|
serviceId,
|
||||||
|
error: err.message,
|
||||||
|
});
|
||||||
|
}
|
||||||
|
});
|
||||||
|
}, 'dep-restart'));
|
||||||
|
|
||||||
|
return router;
|
||||||
|
};
|
||||||
+229
-9
@@ -4,7 +4,7 @@ const fsp = require('fs').promises;
|
|||||||
const validatorLib = require('validator');
|
const validatorLib = require('validator');
|
||||||
const { APP, TIMEOUTS, CADDY, DNS_RECORD_TYPES, REGEX, SESSION_TTL } = require('../constants');
|
const { APP, TIMEOUTS, CADDY, DNS_RECORD_TYPES, REGEX, SESSION_TTL } = require('../constants');
|
||||||
const { exists } = require('../fs-helpers');
|
const { exists } = require('../fs-helpers');
|
||||||
const { success, error: errorResponse } = require('../response-helpers');
|
const { success, error: errorResponse } = require('../src/utils/responses');
|
||||||
const { ValidationError, AuthenticationError, NotFoundError } = require('../errors');
|
const { ValidationError, AuthenticationError, NotFoundError } = require('../errors');
|
||||||
|
|
||||||
/**
|
/**
|
||||||
@@ -26,7 +26,8 @@ module.exports = function({
|
|||||||
log,
|
log,
|
||||||
safeErrorMessage,
|
safeErrorMessage,
|
||||||
fetchT,
|
fetchT,
|
||||||
credentialManager
|
credentialManager,
|
||||||
|
dnsPropagationChecker
|
||||||
}) {
|
}) {
|
||||||
const router = express.Router();
|
const router = express.Router();
|
||||||
|
|
||||||
@@ -41,7 +42,137 @@ module.exports = function({
|
|||||||
return serverIp;
|
return serverIp;
|
||||||
}
|
}
|
||||||
|
|
||||||
// DELETE /record — Delete a DNS record from Technitium
|
// ===== DNS PROVIDER ENDPOINTS =====
|
||||||
|
|
||||||
|
// GET /providers — List all available DNS providers
|
||||||
|
router.get('/providers', asyncHandler(async (req, res) => {
|
||||||
|
const providers = dns.getAvailableProviders ? dns.getAvailableProviders() : [];
|
||||||
|
const activeProvider = dns.getProviderId ? dns.getProviderId() : 'technitium';
|
||||||
|
success(res, { providers, activeProvider });
|
||||||
|
}, 'dns-providers-list'));
|
||||||
|
|
||||||
|
// GET /provider/status — Get active provider status
|
||||||
|
router.get('/provider/status', asyncHandler(async (req, res) => {
|
||||||
|
if (!dns.getActiveProvider) {
|
||||||
|
return success(res, { providerId: 'technitium', capabilities: ['create-record', 'delete-record', 'resolve', 'list-records', 'logs', 'restart', 'update-check', 'credentials', 'zones'] });
|
||||||
|
}
|
||||||
|
try {
|
||||||
|
const provider = dns.getActiveProvider();
|
||||||
|
const status = await provider.getStatus();
|
||||||
|
success(res, status);
|
||||||
|
} catch (err) {
|
||||||
|
errorResponse(res, safeErrorMessage(err), 500);
|
||||||
|
}
|
||||||
|
}, 'dns-provider-status'));
|
||||||
|
|
||||||
|
// ===== UNIVERSAL RECORD ENDPOINTS (work with any provider) =====
|
||||||
|
|
||||||
|
// POST /universal/record — Create a DNS record via any provider
|
||||||
|
router.post('/universal/record', asyncHandler(async (req, res) => {
|
||||||
|
if (!dns.getActiveProvider) {
|
||||||
|
// Fallback to legacy Technitium route
|
||||||
|
return res.redirect(307, '/api/dns/record');
|
||||||
|
}
|
||||||
|
const { domain, ip, ttl, type, server } = req.body;
|
||||||
|
if (!domain || !ip) throw new ValidationError('domain and ip are required');
|
||||||
|
if (!REGEX.DOMAIN.test(domain)) throw new ValidationError('[DC-301] Invalid domain format');
|
||||||
|
if (!validatorLib.isIP(ip)) throw new ValidationError('[DC-210] Invalid IP address');
|
||||||
|
|
||||||
|
try {
|
||||||
|
const provider = dns.getActiveProvider();
|
||||||
|
if (!provider.supportsCapability('create-record')) {
|
||||||
|
const result = await provider.createRecord({
|
||||||
|
domain, zone: siteConfig.tld?.replace(/^\./, '') || '',
|
||||||
|
type: type || 'A', value: ip, ttl: ttl || 300, overwrite: true
|
||||||
|
});
|
||||||
|
return success(res, {
|
||||||
|
message: result.message || `DNS record instructions provided`,
|
||||||
|
manual: true,
|
||||||
|
instructions: result.instructions
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
const result = await provider.createRecord({
|
||||||
|
domain, zone: siteConfig.tld?.replace(/^\./, '') || '',
|
||||||
|
type: type || 'A', value: ip, ttl: ttl || 300, overwrite: true
|
||||||
|
});
|
||||||
|
|
||||||
|
// Start propagation check in background
|
||||||
|
if (dnsPropagationChecker && ip) {
|
||||||
|
dnsPropagationChecker.startVerification(domain, ip).catch(err => {
|
||||||
|
log('DNS propagation check start failed:', err.message);
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
success(res, {
|
||||||
|
message: result.status === 'manual' ? result.message : `DNS record ${domain} -> ${ip} created`,
|
||||||
|
provider: dns.getProviderId(),
|
||||||
|
...(result.instructions ? { manual: true, instructions: result.instructions } : {})
|
||||||
|
});
|
||||||
|
} catch (error) {
|
||||||
|
log.error('dns', 'Universal DNS record creation error', { error: error.message });
|
||||||
|
errorResponse(res, safeErrorMessage(error), 500);
|
||||||
|
}
|
||||||
|
}, 'dns-universal-create'));
|
||||||
|
|
||||||
|
// DELETE /universal/record — Delete a DNS record via any provider
|
||||||
|
router.delete('/universal/record', asyncHandler(async (req, res) => {
|
||||||
|
if (!dns.getActiveProvider) {
|
||||||
|
return res.redirect(307, '/api/dns/record');
|
||||||
|
}
|
||||||
|
const { domain, type, value } = req.query;
|
||||||
|
if (!domain) throw new ValidationError('domain is required');
|
||||||
|
if (!REGEX.DOMAIN.test(domain)) throw new ValidationError('[DC-301] Invalid domain format');
|
||||||
|
|
||||||
|
try {
|
||||||
|
const provider = dns.getActiveProvider();
|
||||||
|
const result = await provider.deleteRecord({
|
||||||
|
domain, type: type || 'A', value
|
||||||
|
});
|
||||||
|
|
||||||
|
success(res, {
|
||||||
|
message: result.status === 'manual' ? result.message : `DNS record ${domain} deleted`,
|
||||||
|
provider: dns.getProviderId(),
|
||||||
|
...(result.instructions ? { manual: true, instructions: result.instructions } : {})
|
||||||
|
});
|
||||||
|
} catch (error) {
|
||||||
|
log.error('dns', 'Universal DNS record deletion error', { error: error.message });
|
||||||
|
errorResponse(res, safeErrorMessage(error), 500);
|
||||||
|
}
|
||||||
|
}, 'dns-universal-delete'));
|
||||||
|
|
||||||
|
// GET /universal/resolve — Resolve a domain via any provider
|
||||||
|
router.get('/universal/resolve', asyncHandler(async (req, res) => {
|
||||||
|
if (!dns.getActiveProvider) {
|
||||||
|
return res.redirect(307, '/api/dns/resolve');
|
||||||
|
}
|
||||||
|
const { domain, type } = req.query;
|
||||||
|
if (!domain) throw new ValidationError('domain is required');
|
||||||
|
if (!REGEX.DOMAIN.test(domain)) throw new ValidationError('[DC-301] Invalid domain format');
|
||||||
|
|
||||||
|
try {
|
||||||
|
const provider = dns.getActiveProvider();
|
||||||
|
const result = await provider.resolveRecords({
|
||||||
|
domain, zone: siteConfig.tld?.replace(/^\./, '') || '',
|
||||||
|
type: type || 'A'
|
||||||
|
});
|
||||||
|
|
||||||
|
if (result.response?.records?.length > 0) {
|
||||||
|
const ipAddresses = result.response.records
|
||||||
|
.filter(r => r.type === (type || 'A'))
|
||||||
|
.map(r => r.rData?.ipAddress || r.content || r.rData?.address)
|
||||||
|
.filter(Boolean);
|
||||||
|
success(res, { answer: ipAddresses });
|
||||||
|
} else {
|
||||||
|
throw new NotFoundError('No records found for domain');
|
||||||
|
}
|
||||||
|
} catch (error) {
|
||||||
|
log.error('dns', 'Universal DNS resolve error', { error: error.message });
|
||||||
|
errorResponse(res, safeErrorMessage(error), error.statusCode || 500);
|
||||||
|
}
|
||||||
|
}, 'dns-universal-resolve'));
|
||||||
|
|
||||||
|
// ===== LEGACY TECHNITIUM-SPECIFIC ROUTES (unchanged) =====
|
||||||
router.delete('/record', asyncHandler(async (req, res) => {
|
router.delete('/record', asyncHandler(async (req, res) => {
|
||||||
const { domain, type, token, server, ipAddress } = req.query;
|
const { domain, type, token, server, ipAddress } = req.query;
|
||||||
|
|
||||||
@@ -139,6 +270,14 @@ module.exports = function({
|
|||||||
});
|
});
|
||||||
|
|
||||||
if (result.status === 'ok') {
|
if (result.status === 'ok') {
|
||||||
|
// Start DNS propagation verification in background
|
||||||
|
if (dnsPropagationChecker && ip) {
|
||||||
|
const fullDomain = domain;
|
||||||
|
dnsPropagationChecker.startVerification(fullDomain, ip).catch(err => {
|
||||||
|
log('DNS propagation check start failed:', err.message);
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
success(res, { message: `DNS record ${domain} -> ${ip} created` });
|
success(res, { message: `DNS record ${domain} -> ${ip} created` });
|
||||||
} else {
|
} else {
|
||||||
// Error handled by middleware
|
// Error handled by middleware
|
||||||
@@ -194,8 +333,13 @@ module.exports = function({
|
|||||||
}
|
}
|
||||||
}, 'dns-resolve'));
|
}, 'dns-resolve'));
|
||||||
|
|
||||||
// GET /logs — Fetch DNS query logs from Technitium
|
// GET /logs — Fetch DNS query logs (Technitium only)
|
||||||
router.get('/logs', asyncHandler(async (req, res) => {
|
router.get('/logs', asyncHandler(async (req, res) => {
|
||||||
|
// Capability gate: logs are provider-specific
|
||||||
|
if (dns.supportsCapability && !dns.supportsCapability('logs')) {
|
||||||
|
return success(res, { server: 'N/A', count: 0, logs: [], message: 'DNS logs not supported by current provider' });
|
||||||
|
}
|
||||||
|
|
||||||
const { server, limit } = req.query;
|
const { server, limit } = req.query;
|
||||||
|
|
||||||
if (!server) {
|
if (!server) {
|
||||||
@@ -475,8 +619,13 @@ module.exports = function({
|
|||||||
success(res, { message: 'DNS credentials removed' });
|
success(res, { message: 'DNS credentials removed' });
|
||||||
}, 'dns-credentials-delete'));
|
}, 'dns-credentials-delete'));
|
||||||
|
|
||||||
// POST /restart/:dnsId — Restart a DNS server (proxied through backend for auth)
|
// POST /restart/:dnsId — Restart a DNS server (Technitium only)
|
||||||
router.post('/restart/:dnsId', asyncHandler(async (req, res) => {
|
router.post('/restart/:dnsId', asyncHandler(async (req, res) => {
|
||||||
|
// Capability gate
|
||||||
|
if (dns.supportsCapability && !dns.supportsCapability('restart')) {
|
||||||
|
return errorResponse(res, 'Server restart not supported by current DNS provider', 501);
|
||||||
|
}
|
||||||
|
|
||||||
const { dnsId } = req.params;
|
const { dnsId } = req.params;
|
||||||
const serverInfo = siteConfig.dnsServers?.[dnsId];
|
const serverInfo = siteConfig.dnsServers?.[dnsId];
|
||||||
if (!serverInfo?.ip) {
|
if (!serverInfo?.ip) {
|
||||||
@@ -518,8 +667,13 @@ module.exports = function({
|
|||||||
}
|
}
|
||||||
}, 'dns-refresh-token'));
|
}, 'dns-refresh-token'));
|
||||||
|
|
||||||
// GET /check-update — Check for Technitium DNS server updates
|
// GET /check-update — Check for DNS server updates (Technitium only)
|
||||||
router.get('/check-update', asyncHandler(async (req, res) => {
|
router.get('/check-update', asyncHandler(async (req, res) => {
|
||||||
|
// Capability gate
|
||||||
|
if (dns.supportsCapability && !dns.supportsCapability('update-check')) {
|
||||||
|
return success(res, { updateAvailable: false, message: 'Update check not supported by current DNS provider' });
|
||||||
|
}
|
||||||
|
|
||||||
try {
|
try {
|
||||||
const { server } = req.query;
|
const { server } = req.query;
|
||||||
if (!server) {
|
if (!server) {
|
||||||
@@ -576,10 +730,13 @@ module.exports = function({
|
|||||||
}
|
}
|
||||||
}, 'dns-check-update'));
|
}, 'dns-check-update'));
|
||||||
|
|
||||||
// POST /update — Update Technitium DNS server
|
// POST /update — Update DNS server (Technitium only)
|
||||||
// Note: Technitium v14+ has no installUpdate API. This endpoint checks for updates
|
|
||||||
// and returns download info. The frontend handles showing update instructions.
|
|
||||||
router.post('/update', asyncHandler(async (req, res) => {
|
router.post('/update', asyncHandler(async (req, res) => {
|
||||||
|
// Capability gate
|
||||||
|
if (dns.supportsCapability && !dns.supportsCapability('update-check')) {
|
||||||
|
return errorResponse(res, 'Server update not supported by current DNS provider', 501);
|
||||||
|
}
|
||||||
|
|
||||||
try {
|
try {
|
||||||
const { server } = req.query;
|
const { server } = req.query;
|
||||||
if (!server) {
|
if (!server) {
|
||||||
@@ -641,5 +798,68 @@ module.exports = function({
|
|||||||
}
|
}
|
||||||
}, 'dns-update'));
|
}, 'dns-update'));
|
||||||
|
|
||||||
|
// ===== DNS PROPAGATION =====
|
||||||
|
|
||||||
|
// GET /propagation — Get all recent DNS propagation checks
|
||||||
|
router.get('/propagation', asyncHandler(async (req, res) => {
|
||||||
|
if (!dnsPropagationChecker) {
|
||||||
|
return success(res, { verifications: [], message: 'DNS propagation checker not available' });
|
||||||
|
}
|
||||||
|
|
||||||
|
// Cleanup old entries
|
||||||
|
dnsPropagationChecker.cleanup();
|
||||||
|
|
||||||
|
const verifications = dnsPropagationChecker.getAllVerifications();
|
||||||
|
success(res, { verifications });
|
||||||
|
}, 'dns-propagation-all'));
|
||||||
|
|
||||||
|
// POST /propagation/verify — Manually trigger DNS propagation verification
|
||||||
|
router.post('/propagation/verify', asyncHandler(async (req, res) => {
|
||||||
|
if (!dnsPropagationChecker) {
|
||||||
|
return errorResponse(res, 'DNS propagation checker not available', 503);
|
||||||
|
}
|
||||||
|
|
||||||
|
const { domain, expectedIp } = req.body;
|
||||||
|
|
||||||
|
if (!domain || !expectedIp) {
|
||||||
|
throw new ValidationError('domain and expectedIp are required');
|
||||||
|
}
|
||||||
|
|
||||||
|
// Validate domain format
|
||||||
|
if (!REGEX.DOMAIN.test(domain)) {
|
||||||
|
throw new ValidationError('[DC-301] Invalid domain format');
|
||||||
|
}
|
||||||
|
|
||||||
|
// Validate IP address
|
||||||
|
const validatorLib = require('validator');
|
||||||
|
if (!validatorLib.isIP(expectedIp)) {
|
||||||
|
throw new ValidationError('[DC-210] Invalid IP address');
|
||||||
|
}
|
||||||
|
|
||||||
|
const job = dnsPropagationChecker.startVerification(domain, expectedIp);
|
||||||
|
success(res, {
|
||||||
|
message: 'DNS propagation verification started',
|
||||||
|
domain,
|
||||||
|
expectedIp,
|
||||||
|
status: job.status
|
||||||
|
});
|
||||||
|
}, 'dns-propagation-verify'));
|
||||||
|
|
||||||
|
// GET /propagation/:domain — Get propagation status for a specific domain
|
||||||
|
router.get('/propagation/:domain', asyncHandler(async (req, res) => {
|
||||||
|
if (!dnsPropagationChecker) {
|
||||||
|
return success(res, { verification: null, message: 'DNS propagation checker not available' });
|
||||||
|
}
|
||||||
|
|
||||||
|
const { domain } = req.params;
|
||||||
|
const status = dnsPropagationChecker.getVerificationStatus(domain);
|
||||||
|
|
||||||
|
if (!status) {
|
||||||
|
throw new NotFoundError(`No propagation check found for domain: ${domain}`);
|
||||||
|
}
|
||||||
|
|
||||||
|
success(res, { verification: status });
|
||||||
|
}, 'dns-propagation-domain'));
|
||||||
|
|
||||||
return router;
|
return router;
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
const express = require('express');
|
const express = require('express');
|
||||||
const { success } = require('../response-helpers');
|
const { success } = require('../src/utils/responses');
|
||||||
const { ValidationError } = require('../errors');
|
const { ValidationError } = require('../errors');
|
||||||
|
|
||||||
/**
|
/**
|
||||||
|
|||||||
@@ -3,7 +3,7 @@ const fs = require('fs');
|
|||||||
const fsp = require('fs').promises;
|
const fsp = require('fs').promises;
|
||||||
const { exists } = require('../fs-helpers');
|
const { exists } = require('../fs-helpers');
|
||||||
const { paginate, parsePaginationParams } = require('../pagination');
|
const { paginate, parsePaginationParams } = require('../pagination');
|
||||||
const { success } = require('../response-helpers');
|
const { success } = require('../src/utils/responses');
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Error logs routes factory
|
* Error logs routes factory
|
||||||
|
|||||||
@@ -8,9 +8,10 @@ const express = require('express');
|
|||||||
* @param {Object} deps.healthChecker - Health checker
|
* @param {Object} deps.healthChecker - Health checker
|
||||||
* @param {Object} deps.updateManager - Update manager
|
* @param {Object} deps.updateManager - Update manager
|
||||||
* @param {Function} deps.logError - Error logging function
|
* @param {Function} deps.logError - Error logging function
|
||||||
|
* @param {Object} deps.dependencyManager - Dependency manager for restart chain events
|
||||||
* @returns {express.Router}
|
* @returns {express.Router}
|
||||||
*/
|
*/
|
||||||
module.exports = function({ resourceMonitor, healthChecker, updateManager, logError }) {
|
module.exports = function({ resourceMonitor, healthChecker, updateManager, logError, dependencyManager, autoRestartManager, driftDetector, sslMonitor, dnsPropagationChecker }) {
|
||||||
const router = express.Router();
|
const router = express.Router();
|
||||||
const clients = new Set();
|
const clients = new Set();
|
||||||
|
|
||||||
@@ -74,6 +75,48 @@ module.exports = function({ resourceMonitor, healthChecker, updateManager, logEr
|
|||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Dependency manager events
|
||||||
|
if (dependencyManager) {
|
||||||
|
dependencyManager.on('dependency-restart-start', (data) => {
|
||||||
|
broadcast('dependency-restart-start', data);
|
||||||
|
});
|
||||||
|
dependencyManager.on('dependency-restart-progress', (data) => {
|
||||||
|
broadcast('dependency-restart-progress', data);
|
||||||
|
});
|
||||||
|
dependencyManager.on('dependency-restart-complete', (data) => {
|
||||||
|
broadcast('dependency-restart-complete', data);
|
||||||
|
});
|
||||||
|
dependencyManager.on('dependency-restart-failed', (data) => {
|
||||||
|
broadcast('dependency-restart-failed', data);
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
// Auto-restart manager events
|
||||||
|
if (autoRestartManager) {
|
||||||
|
autoRestartManager.on('auto-restart-attempt', (data) => broadcast('auto-restart-attempt', data));
|
||||||
|
autoRestartManager.on('auto-restart-success', (data) => broadcast('auto-restart-success', data));
|
||||||
|
autoRestartManager.on('auto-restart-failed', (data) => broadcast('auto-restart-failed', data));
|
||||||
|
autoRestartManager.on('auto-restart-max-reached', (data) => broadcast('auto-restart-max-reached', data));
|
||||||
|
}
|
||||||
|
|
||||||
|
// Config drift detector events
|
||||||
|
if (driftDetector) {
|
||||||
|
driftDetector.on('drift-detected', (data) => broadcast('drift-detected', data));
|
||||||
|
}
|
||||||
|
|
||||||
|
// SSL monitor events
|
||||||
|
if (sslMonitor) {
|
||||||
|
sslMonitor.on('cert-expiring', (data) => broadcast('cert-expiring', data));
|
||||||
|
sslMonitor.on('cert-critical', (data) => broadcast('cert-critical', data));
|
||||||
|
}
|
||||||
|
|
||||||
|
// DNS propagation checker events
|
||||||
|
if (dnsPropagationChecker) {
|
||||||
|
dnsPropagationChecker.on('propagation-check', (data) => broadcast('dns-propagation-check', data));
|
||||||
|
dnsPropagationChecker.on('propagation-complete', (data) => broadcast('dns-propagation-complete', data));
|
||||||
|
dnsPropagationChecker.on('propagation-timeout', (data) => broadcast('dns-propagation-timeout', data));
|
||||||
|
}
|
||||||
|
|
||||||
// SSE endpoint
|
// SSE endpoint
|
||||||
router.get('/stream', (req, res) => {
|
router.get('/stream', (req, res) => {
|
||||||
res.writeHead(200, {
|
res.writeHead(200, {
|
||||||
|
|||||||
@@ -7,7 +7,7 @@ const { exists } = require('../fs-helpers');
|
|||||||
const { paginate, parsePaginationParams } = require('../pagination');
|
const { paginate, parsePaginationParams } = require('../pagination');
|
||||||
const platformPaths = require('../platform-paths');
|
const platformPaths = require('../platform-paths');
|
||||||
const { resolveServiceUrl } = require('../url-resolver');
|
const { resolveServiceUrl } = require('../url-resolver');
|
||||||
const { success, error: errorResponse } = require('../response-helpers');
|
const { success, error: errorResponse } = require('../src/utils/responses');
|
||||||
const { ValidationError } = require('../errors');
|
const { ValidationError } = require('../errors');
|
||||||
|
|
||||||
/**
|
/**
|
||||||
@@ -322,9 +322,16 @@ module.exports = function({
|
|||||||
// ===== HEALTH CHECK (health-checker module) =====
|
// ===== HEALTH CHECK (health-checker module) =====
|
||||||
|
|
||||||
// Get current status for all services
|
// Get current status for all services
|
||||||
|
// Returns per-service status plus a summary for the System Overview widget:
|
||||||
|
// { status: { ... }, summary: { healthy, unhealthy, total } }
|
||||||
router.get('/health-checks/status', asyncHandler(async (req, res) => {
|
router.get('/health-checks/status', asyncHandler(async (req, res) => {
|
||||||
const status = healthChecker.getCurrentStatus();
|
const status = healthChecker.getCurrentStatus();
|
||||||
success(res, { status });
|
// Build summary for the overview widget
|
||||||
|
const entries = Object.values(status);
|
||||||
|
const healthy = entries.filter(s => s.status === 'up' || s.status === 'healthy').length;
|
||||||
|
const unhealthy = entries.filter(s => s.status === 'down' || s.status === 'unhealthy').length;
|
||||||
|
const total = entries.length;
|
||||||
|
success(res, { status, summary: { healthy, unhealthy, total } });
|
||||||
}, 'health-check-status'));
|
}, 'health-check-status'));
|
||||||
|
|
||||||
// Get service statistics
|
// Get service statistics
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
const express = require('express');
|
const express = require('express');
|
||||||
const { success, error: errorResponse } = require('../response-helpers');
|
const { success, error: errorResponse } = require('../src/utils/responses');
|
||||||
const { ValidationError } = require('../errors');
|
const { ValidationError } = require('../errors');
|
||||||
|
|
||||||
/**
|
/**
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
const express = require('express');
|
const express = require('express');
|
||||||
const { success } = require('../response-helpers');
|
const { success } = require('../src/utils/responses');
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Monitoring routes factory
|
* Monitoring routes factory
|
||||||
@@ -16,8 +16,22 @@ module.exports = function({ resourceMonitor, docker, asyncHandler, log, notifica
|
|||||||
// ===== RESOURCE MONITORING ENDPOINTS =====
|
// ===== RESOURCE MONITORING ENDPOINTS =====
|
||||||
|
|
||||||
// Get all container stats (from resource monitor module)
|
// Get all container stats (from resource monitor module)
|
||||||
|
// Returns a flat summary format for the System Overview widget:
|
||||||
|
// { containerId: { cpu: <percent>, memory: <percent>, memoryUsage: <bytes>, name } }
|
||||||
router.get('/monitoring/stats', asyncHandler(async (req, res) => {
|
router.get('/monitoring/stats', asyncHandler(async (req, res) => {
|
||||||
const stats = resourceMonitor.getAllStats();
|
const raw = resourceMonitor.getAllStats();
|
||||||
|
// Transform nested { current: { cpu: { percent }, memory: { percent, usage } } }
|
||||||
|
// into flat { cpu: number, memory: number, memoryUsage: number } for the frontend widget
|
||||||
|
const stats = {};
|
||||||
|
for (const [id, data] of Object.entries(raw)) {
|
||||||
|
const cur = data.current || {};
|
||||||
|
stats[id] = {
|
||||||
|
name: data.name,
|
||||||
|
cpu: typeof cur.cpu === 'object' ? (cur.cpu.percent ?? 0) : (Number(cur.cpu) || 0),
|
||||||
|
memory: typeof cur.memory === 'object' ? (cur.memory.percent ?? 0) : (Number(cur.memory) || 0),
|
||||||
|
memoryUsage: typeof cur.memory === 'object' ? (cur.memory.usage ?? 0) : 0,
|
||||||
|
};
|
||||||
|
}
|
||||||
success(res, { stats });
|
success(res, { stats });
|
||||||
}, 'monitoring-stats'));
|
}, 'monitoring-stats'));
|
||||||
|
|
||||||
|
|||||||
@@ -10,7 +10,8 @@ const { exists } = require('../fs-helpers');
|
|||||||
const { paginate, parsePaginationParams } = require('../pagination');
|
const { paginate, parsePaginationParams } = require('../pagination');
|
||||||
const { ValidationError, NotFoundError, ConflictError } = require('../errors');
|
const { ValidationError, NotFoundError, ConflictError } = require('../errors');
|
||||||
const { resolveServiceUrl } = require('../url-resolver');
|
const { resolveServiceUrl } = require('../url-resolver');
|
||||||
const { success, error: errorResponse } = require('../response-helpers');
|
const { success, error: errorResponse } = require('../src/utils/responses');
|
||||||
|
const platformPaths = require('../platform-paths');
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Services route factory
|
* Services route factory
|
||||||
@@ -46,7 +47,7 @@ module.exports = function({
|
|||||||
dns
|
dns
|
||||||
}) {
|
}) {
|
||||||
const router = express.Router();
|
const router = express.Router();
|
||||||
const CA_CERT_PATH = process.env.CA_CERT_PATH || '/app/pki/root.crt';
|
const CA_CERT_PATH = process.env.CA_CERT_PATH || platformPaths.pkiRootCert;
|
||||||
const PROBE_CONCURRENCY = 6;
|
const PROBE_CONCURRENCY = 6;
|
||||||
let probeHttpsAgent;
|
let probeHttpsAgent;
|
||||||
|
|
||||||
@@ -372,7 +373,7 @@ module.exports = function({
|
|||||||
// Add a new service
|
// Add a new service
|
||||||
router.post('/services', asyncHandler(async (req, res) => {
|
router.post('/services', asyncHandler(async (req, res) => {
|
||||||
try {
|
try {
|
||||||
const { id, name, logo } = req.body;
|
const { id, name, logo, category, containerId, port, ip, tailscaleOnly } = req.body;
|
||||||
|
|
||||||
if (!id || !name) {
|
if (!id || !name) {
|
||||||
throw new ValidationError('id and name are required');
|
throw new ValidationError('id and name are required');
|
||||||
@@ -391,7 +392,14 @@ module.exports = function({
|
|||||||
throw new ConflictError(`Service "${id}" already exists`, id);
|
throw new ConflictError(`Service "${id}" already exists`, id);
|
||||||
}
|
}
|
||||||
|
|
||||||
services.push({ id, name, logo: logo || `/assets/${id}.png` });
|
const newService = { id, name, logo: logo || `/assets/${id}.png` };
|
||||||
|
// Persist optional metadata fields if provided
|
||||||
|
if (category) newService.category = category;
|
||||||
|
if (containerId) newService.containerId = containerId;
|
||||||
|
if (port) newService.port = port;
|
||||||
|
if (ip) newService.ip = ip;
|
||||||
|
if (typeof tailscaleOnly === 'boolean') newService.tailscaleOnly = tailscaleOnly;
|
||||||
|
services.push(newService);
|
||||||
return services;
|
return services;
|
||||||
});
|
});
|
||||||
|
|
||||||
@@ -513,9 +521,8 @@ module.exports = function({
|
|||||||
|
|
||||||
if (oldSubdomain !== newSubdomain) {
|
if (oldSubdomain !== newSubdomain) {
|
||||||
try {
|
try {
|
||||||
const dnsToken = dns.getToken();
|
await dns.universalDeleteRecord(oldDomain);
|
||||||
await dns.call(siteConfig.dnsServerIp, '/api/zones/records/delete', { token: dnsToken, domain: oldDomain, type: 'A' });
|
await dns.universalCreateRecord(newSubdomain, ip || 'localhost');
|
||||||
await dns.createRecord(newSubdomain, ip || 'localhost');
|
|
||||||
results.dns = 'updated';
|
results.dns = 'updated';
|
||||||
} catch (e) {
|
} catch (e) {
|
||||||
results.dns = `failed: ${e.message}`;
|
results.dns = `failed: ${e.message}`;
|
||||||
@@ -542,6 +549,8 @@ module.exports = function({
|
|||||||
};
|
};
|
||||||
if (name) services[serviceIndex].name = name;
|
if (name) services[serviceIndex].name = name;
|
||||||
if (logo) services[serviceIndex].logo = logo;
|
if (logo) services[serviceIndex].logo = logo;
|
||||||
|
// Allow category update via update endpoint too (optional body field)
|
||||||
|
if (req.body.category !== undefined) services[serviceIndex].category = req.body.category || undefined;
|
||||||
results.services = 'updated';
|
results.services = 'updated';
|
||||||
} else {
|
} else {
|
||||||
results.services = 'not found';
|
results.services = 'not found';
|
||||||
|
|||||||
@@ -205,7 +205,7 @@ module.exports = function({ asyncHandler, caddy, dns, fetchT, buildDomain, addSe
|
|||||||
|
|
||||||
if (createDns) {
|
if (createDns) {
|
||||||
try {
|
try {
|
||||||
await dns.createRecord(subdomain, siteConfig.dnsServerIp);
|
await dns.universalCreateRecord(subdomain, siteConfig.dnsServerIp);
|
||||||
log.info('dns', 'DNS record created for external proxy', { domain, ip: siteConfig.dnsServerIp });
|
log.info('dns', 'DNS record created for external proxy', { domain, ip: siteConfig.dnsServerIp });
|
||||||
} catch (dnsError) {
|
} catch (dnsError) {
|
||||||
dnsWarning = `DNS creation failed: ${dnsError.message}. You may need to create the DNS record manually.`;
|
dnsWarning = `DNS creation failed: ${dnsError.message}. You may need to create the DNS record manually.`;
|
||||||
|
|||||||
@@ -0,0 +1,113 @@
|
|||||||
|
/**
|
||||||
|
* SSL Monitor Routes
|
||||||
|
* REST API endpoints for SSL certificate monitoring.
|
||||||
|
*
|
||||||
|
* @module routes/ssl-monitor
|
||||||
|
*/
|
||||||
|
|
||||||
|
const express = require('express');
|
||||||
|
const { success, error: errorResponse, notFound } = require('../src/utils/responses');
|
||||||
|
|
||||||
|
/**
|
||||||
|
* SSL Monitor route factory
|
||||||
|
* @param {Object} deps - Explicit dependencies
|
||||||
|
* @param {Object} deps.sslMonitor - SSLMonitor instance
|
||||||
|
* @param {Function} deps.asyncHandler - Async route handler wrapper
|
||||||
|
* @param {Function} deps.logError - Error logging function
|
||||||
|
* @returns {express.Router}
|
||||||
|
*/
|
||||||
|
module.exports = function({ sslMonitor, asyncHandler, logError }) {
|
||||||
|
const router = express.Router();
|
||||||
|
|
||||||
|
/**
|
||||||
|
* GET /ssl/certificates
|
||||||
|
* Get all SSL certificate statuses
|
||||||
|
*/
|
||||||
|
router.get('/certificates', asyncHandler(async (req, res) => {
|
||||||
|
const status = sslMonitor.getStatus();
|
||||||
|
success(res, { certificates: status });
|
||||||
|
}, 'ssl-certificates'));
|
||||||
|
|
||||||
|
/**
|
||||||
|
* GET /ssl/certificates/:serviceId
|
||||||
|
* Get SSL certificate status for a specific service
|
||||||
|
*/
|
||||||
|
router.get('/certificates/:serviceId', asyncHandler(async (req, res) => {
|
||||||
|
const { serviceId } = req.params;
|
||||||
|
const certStatus = sslMonitor.getServiceCertStatus(serviceId);
|
||||||
|
|
||||||
|
if (!certStatus) {
|
||||||
|
return notFound(res, `No SSL certificate status found for service: ${serviceId}`);
|
||||||
|
}
|
||||||
|
|
||||||
|
success(res, { certificate: certStatus });
|
||||||
|
}, 'ssl-certificate-service'));
|
||||||
|
|
||||||
|
/**
|
||||||
|
* POST /ssl/check
|
||||||
|
* Trigger an on-demand check of all SSL certificates
|
||||||
|
*/
|
||||||
|
router.post('/check', asyncHandler(async (req, res) => {
|
||||||
|
const results = await sslMonitor.checkAll();
|
||||||
|
success(res, { certificates: results, message: 'SSL check completed' });
|
||||||
|
}, 'ssl-check-all'));
|
||||||
|
|
||||||
|
/**
|
||||||
|
* POST /ssl/check/:serviceId
|
||||||
|
* Check the SSL certificate for a specific service
|
||||||
|
*/
|
||||||
|
router.post('/check/:serviceId', asyncHandler(async (req, res) => {
|
||||||
|
const { serviceId } = req.params;
|
||||||
|
|
||||||
|
// Look up the existing cert status to find the hostname
|
||||||
|
const existingCert = sslMonitor.getServiceCertStatus(serviceId);
|
||||||
|
if (!existingCert) {
|
||||||
|
return notFound(res, `No HTTPS URL found for service: ${serviceId}`);
|
||||||
|
}
|
||||||
|
|
||||||
|
try {
|
||||||
|
const result = await sslMonitor.checkCert(existingCert.hostname, existingCert.port);
|
||||||
|
success(res, { certificate: { ...result, serviceId } });
|
||||||
|
} catch (err) {
|
||||||
|
errorResponse(res, `Failed to check SSL certificate: ${err.message}`, 500);
|
||||||
|
}
|
||||||
|
}, 'ssl-check-service'));
|
||||||
|
|
||||||
|
/**
|
||||||
|
* GET /ssl/config
|
||||||
|
* Get current SSL monitoring configuration
|
||||||
|
*/
|
||||||
|
router.get('/config', asyncHandler(async (req, res) => {
|
||||||
|
const config = sslMonitor.getConfig();
|
||||||
|
success(res, { config });
|
||||||
|
}, 'ssl-config-get'));
|
||||||
|
|
||||||
|
/**
|
||||||
|
* POST /ssl/config
|
||||||
|
* Update SSL monitoring configuration
|
||||||
|
* Body: { enabled: boolean, intervalMs: number }
|
||||||
|
*/
|
||||||
|
router.post('/config', asyncHandler(async (req, res) => {
|
||||||
|
const { enabled, intervalMs } = req.body;
|
||||||
|
|
||||||
|
// Validate inputs
|
||||||
|
if (enabled !== undefined && typeof enabled !== 'boolean') {
|
||||||
|
return errorResponse(res, 'enabled must be a boolean', 400);
|
||||||
|
}
|
||||||
|
if (intervalMs !== undefined) {
|
||||||
|
if (typeof intervalMs !== 'number' || intervalMs < 60000) {
|
||||||
|
return errorResponse(res, 'intervalMs must be a number >= 60000 (1 minute)', 400);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
const updates = {};
|
||||||
|
if (enabled !== undefined) updates.enabled = enabled;
|
||||||
|
if (intervalMs !== undefined) updates.intervalMs = intervalMs;
|
||||||
|
|
||||||
|
sslMonitor.updateConfig(updates);
|
||||||
|
const config = sslMonitor.getConfig();
|
||||||
|
success(res, { config, message: 'SSL monitoring config updated' });
|
||||||
|
}, 'ssl-config-update'));
|
||||||
|
|
||||||
|
return router;
|
||||||
|
};
|
||||||
@@ -1,8 +1,9 @@
|
|||||||
const express = require('express');
|
const express = require('express');
|
||||||
const fs = require('fs');
|
const fs = require('fs');
|
||||||
const path = require('path');
|
const path = require('path');
|
||||||
const { success } = require('../response-helpers');
|
const { success } = require('../src/utils/responses');
|
||||||
const { ValidationError, NotFoundError } = require('../errors');
|
const { ValidationError, NotFoundError } = require('../errors');
|
||||||
|
const platformPaths = require('../platform-paths');
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Themes routes factory
|
* Themes routes factory
|
||||||
@@ -13,7 +14,7 @@ const { ValidationError, NotFoundError } = require('../errors');
|
|||||||
*/
|
*/
|
||||||
module.exports = function({ asyncHandler, log }) {
|
module.exports = function({ asyncHandler, log }) {
|
||||||
const router = express.Router();
|
const router = express.Router();
|
||||||
const THEMES_DIR = process.env.THEMES_DIR || path.join(path.dirname(process.env.SERVICES_FILE || '/app/services.json'), 'themes');
|
const THEMES_DIR = process.env.THEMES_DIR || path.join(path.dirname(platformPaths.servicesFile), 'themes');
|
||||||
|
|
||||||
// Ensure themes directory exists
|
// Ensure themes directory exists
|
||||||
if (!fs.existsSync(THEMES_DIR)) {
|
if (!fs.existsSync(THEMES_DIR)) {
|
||||||
|
|||||||
@@ -1,7 +1,7 @@
|
|||||||
#!/usr/bin/env bash
|
#!/usr/bin/env bash
|
||||||
# DashCaddy Host-Side Updater
|
# DashCaddy Host-Side Updater
|
||||||
# Triggered by systemd path unit when the container writes trigger.json.
|
# Triggered by systemd path unit when the container writes trigger.json.
|
||||||
# Reads the trigger, backs up current API, copies new files, rebuilds container.
|
# Reads the trigger, backs up current API + data/, copies new files, rebuilds container.
|
||||||
# Writes result.json so the new container knows the outcome.
|
# Writes result.json so the new container knows the outcome.
|
||||||
#
|
#
|
||||||
# This runs on the HOST, outside the container.
|
# This runs on the HOST, outside the container.
|
||||||
@@ -16,6 +16,10 @@ readonly CONTAINER_NAME="dashcaddy-api"
|
|||||||
readonly MAX_BACKUPS=3
|
readonly MAX_BACKUPS=3
|
||||||
readonly HEALTH_TIMEOUT=60
|
readonly HEALTH_TIMEOUT=60
|
||||||
|
|
||||||
|
# Data directory backup — stored alongside code backups so everything rolls back together
|
||||||
|
readonly DATA_SOURCE_DIR="/opt/dashcaddy/dashcaddy-api/data"
|
||||||
|
readonly DATA_BACKUP_PREFIX="data-backup"
|
||||||
|
|
||||||
log() { echo "[dashcaddy-update] $(date '+%Y-%m-%d %H:%M:%S') $*"; }
|
log() { echo "[dashcaddy-update] $(date '+%Y-%m-%d %H:%M:%S') $*"; }
|
||||||
|
|
||||||
write_result() {
|
write_result() {
|
||||||
@@ -56,6 +60,34 @@ cleanup_old_backups() {
|
|||||||
fi
|
fi
|
||||||
}
|
}
|
||||||
|
|
||||||
|
# ── Data backup (rsync for efficiency + permissions) ──────────────────────────
|
||||||
|
backup_data_dir() {
|
||||||
|
local backup_dir="$1"
|
||||||
|
if [[ -d "$DATA_SOURCE_DIR" ]]; then
|
||||||
|
log "Backing up data/ to ${backup_dir}/${DATA_BACKUP_PREFIX}/"
|
||||||
|
mkdir -p "${backup_dir}/${DATA_BACKUP_PREFIX}"
|
||||||
|
rsync -a --delete "$DATA_SOURCE_DIR/" "${backup_dir}/${DATA_BACKUP_PREFIX}/" 2>/dev/null \
|
||||||
|
|| cp -a "$DATA_SOURCE_DIR" "${backup_dir}/${DATA_BACKUP_PREFIX}"
|
||||||
|
log "Data backup complete ($(du -sh "${backup_dir}/${DATA_BACKUP_PREFIX}" 2>/dev/null | cut -f1))"
|
||||||
|
else
|
||||||
|
log "WARNING: Data source dir $DATA_SOURCE_DIR not found — skipping data backup"
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
|
# ── Data restore ──────────────────────────────────────────────────────────────
|
||||||
|
restore_data_dir() {
|
||||||
|
local backup_dir="$1"
|
||||||
|
local data_backup="${backup_dir}/${DATA_BACKUP_PREFIX}"
|
||||||
|
if [[ -d "$data_backup" ]]; then
|
||||||
|
log "Restoring data/ from backup..."
|
||||||
|
rsync -a --delete "$data_backup/" "$DATA_SOURCE_DIR/" 2>/dev/null \
|
||||||
|
|| cp -a "$data_backup" "$DATA_SOURCE_DIR"
|
||||||
|
log "Data restored successfully"
|
||||||
|
else
|
||||||
|
log "WARNING: No data backup found at ${data_backup} — data/ not restored"
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
wait_for_health() {
|
wait_for_health() {
|
||||||
local port="${1:-3001}"
|
local port="${1:-3001}"
|
||||||
local timeout="$HEALTH_TIMEOUT"
|
local timeout="$HEALTH_TIMEOUT"
|
||||||
@@ -75,6 +107,59 @@ wait_for_health() {
|
|||||||
return 1
|
return 1
|
||||||
}
|
}
|
||||||
|
|
||||||
|
# ── Shared rollback: restore code + data ────────────────────────────────────
|
||||||
|
rollback_restore() {
|
||||||
|
local backup_dir="$1"
|
||||||
|
log "Rolling back: restoring code files..."
|
||||||
|
for item in "$backup_dir"/*.js "$backup_dir"/package.json "$backup_dir"/package-lock.json "$backup_dir"/Dockerfile "$backup_dir"/openapi.yaml "$backup_dir"/VERSION; do
|
||||||
|
[[ -f "$item" ]] && cp -f "$item" "$api_source_dir/" 2>/dev/null || true
|
||||||
|
done
|
||||||
|
if [[ -d "$backup_dir/routes" ]]; then
|
||||||
|
rm -rf "$api_source_dir/routes"
|
||||||
|
cp -rf "$backup_dir/routes" "$api_source_dir/routes"
|
||||||
|
fi
|
||||||
|
if [[ -d "$backup_dir/src" ]]; then
|
||||||
|
rm -rf "$api_source_dir/src"
|
||||||
|
cp -rf "$backup_dir/src" "$api_source_dir/src"
|
||||||
|
fi
|
||||||
|
restore_data_dir "$backup_dir"
|
||||||
|
}
|
||||||
|
|
||||||
|
# ── Shared container restart (preserves SERVICES_FILE env var) ───────────────
|
||||||
|
# Uses rm + run so new env vars (e.g. SERVICES_FILE) take effect.
|
||||||
|
# If docker-compose is not configured, falls back to docker start.
|
||||||
|
restart_container() {
|
||||||
|
local image="$1"
|
||||||
|
log "Restarting container (rm + run to pick up env vars)..."
|
||||||
|
# Stop and remove existing container so new env var is applied
|
||||||
|
docker rm -f "$CONTAINER_NAME" 2>/dev/null || true
|
||||||
|
|
||||||
|
# Re-create with same volumes and the SERVICES_FILE env var
|
||||||
|
docker run -d --restart unless-stopped --name "$CONTAINER_NAME" \
|
||||||
|
-p 127.0.0.1:3001:3001 \
|
||||||
|
-v /opt/dashcaddy/dashcaddy-api/data:/app/data \
|
||||||
|
-e SERVICES_FILE=/app/data/services.json \
|
||||||
|
"$image"
|
||||||
|
log "Container restarted with fresh env"
|
||||||
|
}
|
||||||
|
|
||||||
|
# ── Code-only restore (used after failed build when data hasn't changed yet) ──
|
||||||
|
code_restore() {
|
||||||
|
local backup_dir="$1"
|
||||||
|
log "Restoring code files..."
|
||||||
|
for item in "$backup_dir"/*.js "$backup_dir"/package.json "$backup_dir"/package-lock.json "$backup_dir"/Dockerfile "$backup_dir"/openapi.yaml "$backup_dir"/VERSION; do
|
||||||
|
[[ -f "$item" ]] && cp -f "$item" "$api_source_dir/" 2>/dev/null || true
|
||||||
|
done
|
||||||
|
if [[ -d "$backup_dir/routes" ]]; then
|
||||||
|
rm -rf "$api_source_dir/routes"
|
||||||
|
cp -rf "$backup_dir/routes" "$api_source_dir/routes"
|
||||||
|
fi
|
||||||
|
if [[ -d "$backup_dir/src" ]]; then
|
||||||
|
rm -rf "$api_source_dir/src"
|
||||||
|
cp -rf "$backup_dir/src" "$api_source_dir/src"
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
main() {
|
main() {
|
||||||
local start_time
|
local start_time
|
||||||
start_time=$(date +%s)
|
start_time=$(date +%s)
|
||||||
@@ -94,45 +179,69 @@ main() {
|
|||||||
staging_dir=$(python3 -c "import json; print(json.load(open('${TRIGGER_FILE}'))['stagingDir'])")
|
staging_dir=$(python3 -c "import json; print(json.load(open('${TRIGGER_FILE}'))['stagingDir'])")
|
||||||
api_source_dir=$(python3 -c "import json; print(json.load(open('${TRIGGER_FILE}'))['apiSourceDir'])")
|
api_source_dir=$(python3 -c "import json; print(json.load(open('${TRIGGER_FILE}'))['apiSourceDir'])")
|
||||||
commit=$(python3 -c "import json; print(json.load(open('${TRIGGER_FILE}')).get('commit') or '')")
|
commit=$(python3 -c "import json; print(json.load(open('${TRIGGER_FILE}')).get('commit') or '')")
|
||||||
# Frontend paths — optional (older self-updaters don't write these). When
|
|
||||||
# present, this script also syncs the dashboard files (Caddy serves them
|
|
||||||
# directly from the host; the container path /app/dashboard isn't mounted).
|
|
||||||
frontend_staging_dir=$(python3 -c "import json; print(json.load(open('${TRIGGER_FILE}')).get('frontendStagingDir') or '')")
|
frontend_staging_dir=$(python3 -c "import json; print(json.load(open('${TRIGGER_FILE}')).get('frontendStagingDir') or '')")
|
||||||
frontend_target_dir=$(python3 -c "import json; print(json.load(open('${TRIGGER_FILE}')).get('frontendTargetDir') or '')")
|
frontend_target_dir=$(python3 -c "import json; print(json.load(open('${TRIGGER_FILE}')).get('frontendTargetDir') or '')")
|
||||||
|
# Handle action=rollback (no new version to deploy)
|
||||||
|
local to_version="${version}"
|
||||||
|
|
||||||
log "=== ${action^^}: v${from_version} -> v${version} ==="
|
log "=== ${action^^}: v${from_version} -> v${to_version} ==="
|
||||||
log "Staging: ${staging_dir}"
|
log "Staging: ${staging_dir}"
|
||||||
log "API source: ${api_source_dir}"
|
log "API source: ${api_source_dir}"
|
||||||
|
|
||||||
# Consume the trigger immediately so we don't re-process on failure
|
# Consume the trigger immediately so we don't re-process on failure
|
||||||
mv "$TRIGGER_FILE" "${TRIGGER_FILE}.processing"
|
mv "$TRIGGER_FILE" "${TRIGGER_FILE}.processing"
|
||||||
|
|
||||||
# 2. Validate staging directory
|
# ── Handle rollback ────────────────────────────────────────────────────────
|
||||||
|
if [[ "$action" == "rollback" ]]; then
|
||||||
|
local backup_dir="${BACKUPS_DIR}/${version}"
|
||||||
|
if [[ ! -d "$backup_dir" ]]; then
|
||||||
|
log "ERROR: No backup found for version ${version}"
|
||||||
|
write_result "false" "$version" "$(( $(date +%s) - start_time ))" "No backup found for version ${version}"
|
||||||
|
rm -f "${TRIGGER_FILE}.processing"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
log "Performing rollback to v${version}..."
|
||||||
|
rollback_restore "$backup_dir"
|
||||||
|
|
||||||
|
# Rebuild old code
|
||||||
|
log "Rebuilding container..."
|
||||||
|
cd "$api_source_dir"
|
||||||
|
docker build -t dashcaddy-dashcaddy-api:latest . 2>&1 | tail -1 || true
|
||||||
|
|
||||||
|
restart_container "dashcaddy-dashcaddy-api:latest"
|
||||||
|
wait_for_health || log "WARNING: Health check failed after rollback"
|
||||||
|
|
||||||
|
write_result "true" "$version" "$(( $(date +%s) - start_time ))"
|
||||||
|
rm -f "${TRIGGER_FILE}.processing"
|
||||||
|
log "=== Rollback complete ==="
|
||||||
|
exit 0
|
||||||
|
fi
|
||||||
|
|
||||||
|
# ── Handle update ───────────────────────────────────────────────────────────
|
||||||
if [[ ! -d "$staging_dir" ]]; then
|
if [[ ! -d "$staging_dir" ]]; then
|
||||||
log "ERROR: Staging directory not found: ${staging_dir}"
|
log "ERROR: Staging directory not found: ${staging_dir}"
|
||||||
write_result "false" "$version" "$(( $(date +%s) - start_time ))" "Staging directory not found"
|
write_result "false" "$to_version" "$(( $(date +%s) - start_time ))" "Staging directory not found"
|
||||||
rm -f "${TRIGGER_FILE}.processing"
|
rm -f "${TRIGGER_FILE}.processing"
|
||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# 3. Backup current API files
|
# 2. Backup current API code + data/
|
||||||
local backup_dir="${BACKUPS_DIR}/${from_version}"
|
local backup_dir="${BACKUPS_DIR}/${from_version}"
|
||||||
mkdir -p "$backup_dir"
|
mkdir -p "$backup_dir"
|
||||||
log "Backing up current API files to ${backup_dir}"
|
log "Backing up current API files to ${backup_dir}"
|
||||||
|
|
||||||
# Copy all JS files, package.json, Dockerfile, and tracked subdirs
|
|
||||||
for item in "$api_source_dir"/*.js "$api_source_dir"/package.json "$api_source_dir"/package-lock.json "$api_source_dir"/Dockerfile "$api_source_dir"/openapi.yaml "$api_source_dir"/VERSION; do
|
for item in "$api_source_dir"/*.js "$api_source_dir"/package.json "$api_source_dir"/package-lock.json "$api_source_dir"/Dockerfile "$api_source_dir"/openapi.yaml "$api_source_dir"/VERSION; do
|
||||||
[[ -f "$item" ]] && cp -f "$item" "$backup_dir/" 2>/dev/null || true
|
[[ -f "$item" ]] && cp -f "$item" "$backup_dir/" 2>/dev/null || true
|
||||||
done
|
done
|
||||||
[[ -d "$api_source_dir/routes" ]] && cp -rf "$api_source_dir/routes" "$backup_dir/"
|
[[ -d "$api_source_dir/routes" ]] && cp -rf "$api_source_dir/routes" "$backup_dir/"
|
||||||
[[ -d "$api_source_dir/src" ]] && cp -rf "$api_source_dir/src" "$backup_dir/"
|
[[ -d "$api_source_dir/src" ]] && cp -rf "$api_source_dir/src" "$backup_dir/"
|
||||||
# VERSION (commit hash) was copied from api_source_dir above; preserve as-is
|
|
||||||
# so a rollback restores the original commit marker. The version *string* is
|
# Backup data/ directory (services.json, config.json, credentials, etc.)
|
||||||
# already encoded in the backup dir name (${from_version}).
|
backup_data_dir "$backup_dir"
|
||||||
|
|
||||||
cleanup_old_backups
|
cleanup_old_backups
|
||||||
|
|
||||||
# 4. Copy new files from staging to API source
|
# 3. Copy new files from staging to API source
|
||||||
log "Deploying new API files..."
|
log "Deploying new API files..."
|
||||||
for item in "$staging_dir"/*.js "$staging_dir"/package.json "$staging_dir"/package-lock.json "$staging_dir"/Dockerfile "$staging_dir"/openapi.yaml "$staging_dir"/VERSION; do
|
for item in "$staging_dir"/*.js "$staging_dir"/package.json "$staging_dir"/package-lock.json "$staging_dir"/Dockerfile "$staging_dir"/openapi.yaml "$staging_dir"/VERSION; do
|
||||||
[[ -f "$item" ]] && cp -f "$item" "$api_source_dir/" 2>/dev/null || true
|
[[ -f "$item" ]] && cp -f "$item" "$api_source_dir/" 2>/dev/null || true
|
||||||
@@ -145,19 +254,11 @@ main() {
|
|||||||
rm -rf "$api_source_dir/src"
|
rm -rf "$api_source_dir/src"
|
||||||
cp -rf "$staging_dir/src" "$api_source_dir/src"
|
cp -rf "$staging_dir/src" "$api_source_dir/src"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# Belt-and-suspenders: always write the commit from trigger.json to VERSION,
|
|
||||||
# even if the tarball didn't include one. The container's self-updater uses
|
|
||||||
# this to detect the "same version, different commit" case.
|
|
||||||
if [[ -n "$commit" ]]; then
|
if [[ -n "$commit" ]]; then
|
||||||
echo "$commit" > "$api_source_dir/VERSION"
|
echo "$commit" > "$api_source_dir/VERSION"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# 4b. Sync frontend. Caddy serves the dashboard directly from the host
|
# 3b. Sync frontend
|
||||||
# filesystem; the container-side copy in older self-updater.js builds wrote
|
|
||||||
# to /app/dashboard which isn't always mounted, so the real sync happens
|
|
||||||
# here. Trigger fields take precedence; if absent (older self-updater),
|
|
||||||
# fall back to: staging dir's sibling status/ + first existing known target.
|
|
||||||
if [[ -z "$frontend_staging_dir" ]]; then
|
if [[ -z "$frontend_staging_dir" ]]; then
|
||||||
parent_staging=$(dirname "$staging_dir")
|
parent_staging=$(dirname "$staging_dir")
|
||||||
[[ -d "$parent_staging/status" ]] && frontend_staging_dir="$parent_staging/status"
|
[[ -d "$parent_staging/status" ]] && frontend_staging_dir="$parent_staging/status"
|
||||||
@@ -175,107 +276,55 @@ main() {
|
|||||||
for sub in dist css vendor js; do
|
for sub in dist css vendor js; do
|
||||||
if [[ -d "$frontend_staging_dir/$sub" ]]; then
|
if [[ -d "$frontend_staging_dir/$sub" ]]; then
|
||||||
mkdir -p "$frontend_target_dir/$sub"
|
mkdir -p "$frontend_target_dir/$sub"
|
||||||
cp -rf "$frontend_staging_dir/$sub"/* "$frontend_target_dir/$sub/" 2>/dev/null || true
|
cp -rf "$frontend_staging_dir/$sub/"* "$frontend_target_dir/$sub/" 2>/dev/null || true
|
||||||
fi
|
fi
|
||||||
done
|
done
|
||||||
# assets/ is mounted into the container; usually already in sync via bind
|
|
||||||
# mount, but if a release ships new assets we want them on disk too.
|
|
||||||
if [[ -d "$frontend_staging_dir/assets" ]]; then
|
if [[ -d "$frontend_staging_dir/assets" ]]; then
|
||||||
mkdir -p "$frontend_target_dir/assets"
|
mkdir -p "$frontend_target_dir/assets"
|
||||||
cp -rf "$frontend_staging_dir/assets"/* "$frontend_target_dir/assets/" 2>/dev/null || true
|
cp -rf "$frontend_staging_dir/assets/"* "$frontend_target_dir/assets/" 2>/dev/null || true
|
||||||
fi
|
fi
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# 5. Rebuild container
|
# 4. Rebuild container
|
||||||
log "Rebuilding container..."
|
log "Rebuilding container..."
|
||||||
cd "$api_source_dir"
|
cd "$api_source_dir"
|
||||||
|
|
||||||
local build_ok=false
|
local build_ok=false
|
||||||
if docker compose build --quiet 2>&1; then
|
local image_tag="dashcaddy-dashcaddy-api:latest"
|
||||||
build_ok=true
|
|
||||||
elif docker-compose build --quiet 2>&1; then
|
if docker build -t "$image_tag" . 2>&1; then
|
||||||
build_ok=true
|
build_ok=true
|
||||||
fi
|
fi
|
||||||
|
|
||||||
if [[ "$build_ok" != "true" ]]; then
|
if [[ "$build_ok" != "true" ]]; then
|
||||||
log "ERROR: Docker build failed — rolling back"
|
log "ERROR: Docker build failed — rolling back code + data"
|
||||||
|
code_restore "$backup_dir"
|
||||||
# Restore backup
|
docker build -t "$image_tag" . 2>&1 | tail -3 || true
|
||||||
for item in "$backup_dir"/*.js "$backup_dir"/package.json "$backup_dir"/package-lock.json "$backup_dir"/Dockerfile "$backup_dir"/openapi.yaml "$backup_dir"/VERSION; do
|
restart_container "$image_tag"
|
||||||
[[ -f "$item" ]] && cp -f "$item" "$api_source_dir/" 2>/dev/null || true
|
wait_for_health || true
|
||||||
done
|
write_result "false" "$to_version" "$(( $(date +%s) - start_time ))" "Docker build failed"
|
||||||
if [[ -d "$backup_dir/routes" ]]; then
|
|
||||||
rm -rf "$api_source_dir/routes"
|
|
||||||
cp -rf "$backup_dir/routes" "$api_source_dir/routes"
|
|
||||||
fi
|
|
||||||
if [[ -d "$backup_dir/src" ]]; then
|
|
||||||
rm -rf "$api_source_dir/src"
|
|
||||||
cp -rf "$backup_dir/src" "$api_source_dir/src"
|
|
||||||
fi
|
|
||||||
|
|
||||||
write_result "false" "$version" "$(( $(date +%s) - start_time ))" "Docker build failed"
|
|
||||||
rm -f "${TRIGGER_FILE}.processing"
|
rm -f "${TRIGGER_FILE}.processing"
|
||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# 6. Restart container
|
# 5. Restart container (rm + run so new env vars take effect)
|
||||||
log "Restarting container..."
|
restart_container "$image_tag"
|
||||||
if docker compose up -d 2>&1 || docker-compose up -d 2>&1; then
|
|
||||||
log "Container restarted"
|
|
||||||
else
|
|
||||||
log "ERROR: Container restart failed — rolling back"
|
|
||||||
|
|
||||||
# Restore backup
|
# 6. Health check
|
||||||
for item in "$backup_dir"/*.js "$backup_dir"/package.json "$backup_dir"/package-lock.json "$backup_dir"/Dockerfile "$backup_dir"/openapi.yaml "$backup_dir"/VERSION; do
|
|
||||||
[[ -f "$item" ]] && cp -f "$item" "$api_source_dir/" 2>/dev/null || true
|
|
||||||
done
|
|
||||||
if [[ -d "$backup_dir/routes" ]]; then
|
|
||||||
rm -rf "$api_source_dir/routes"
|
|
||||||
cp -rf "$backup_dir/routes" "$api_source_dir/routes"
|
|
||||||
fi
|
|
||||||
if [[ -d "$backup_dir/src" ]]; then
|
|
||||||
rm -rf "$api_source_dir/src"
|
|
||||||
cp -rf "$backup_dir/src" "$api_source_dir/src"
|
|
||||||
fi
|
|
||||||
|
|
||||||
docker compose build --quiet 2>&1 || docker-compose build --quiet 2>&1 || true
|
|
||||||
docker compose up -d 2>&1 || docker-compose up -d 2>&1 || true
|
|
||||||
|
|
||||||
write_result "false" "$version" "$(( $(date +%s) - start_time ))" "Container restart failed"
|
|
||||||
rm -f "${TRIGGER_FILE}.processing"
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
|
|
||||||
# 7. Health check
|
|
||||||
if wait_for_health; then
|
if wait_for_health; then
|
||||||
local duration=$(( $(date +%s) - start_time ))
|
local duration=$(( $(date +%s) - start_time ))
|
||||||
log "=== Update successful: v${version} in ${duration}s ==="
|
log "=== Update successful: v${to_version} in ${duration}s ==="
|
||||||
write_result "true" "$version" "$duration"
|
write_result "true" "$to_version" "$duration"
|
||||||
else
|
else
|
||||||
local duration=$(( $(date +%s) - start_time ))
|
local duration=$(( $(date +%s) - start_time ))
|
||||||
log "ERROR: Health check failed after update — rolling back"
|
log "ERROR: Health check failed after update — rolling back code + data"
|
||||||
|
rollback_restore "$backup_dir"
|
||||||
# Restore backup
|
docker build -t "$image_tag" . 2>&1 | tail -3 || true
|
||||||
for item in "$backup_dir"/*.js "$backup_dir"/package.json "$backup_dir"/package-lock.json "$backup_dir"/Dockerfile "$backup_dir"/openapi.yaml "$backup_dir"/VERSION; do
|
restart_container "$image_tag"
|
||||||
[[ -f "$item" ]] && cp -f "$item" "$api_source_dir/" 2>/dev/null || true
|
|
||||||
done
|
|
||||||
if [[ -d "$backup_dir/routes" ]]; then
|
|
||||||
rm -rf "$api_source_dir/routes"
|
|
||||||
cp -rf "$backup_dir/routes" "$api_source_dir/routes"
|
|
||||||
fi
|
|
||||||
if [[ -d "$backup_dir/src" ]]; then
|
|
||||||
rm -rf "$api_source_dir/src"
|
|
||||||
cp -rf "$backup_dir/src" "$api_source_dir/src"
|
|
||||||
fi
|
|
||||||
|
|
||||||
docker compose build --quiet 2>&1 || docker-compose build --quiet 2>&1 || true
|
|
||||||
docker compose up -d 2>&1 || docker-compose up -d 2>&1 || true
|
|
||||||
wait_for_health || log "WARNING: Rollback health check also failed"
|
wait_for_health || log "WARNING: Rollback health check also failed"
|
||||||
|
write_result "false" "$to_version" "$duration" "Health check failed after update"
|
||||||
write_result "false" "$version" "$duration" "Health check failed after update"
|
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# 8. Cleanup
|
# 7. Cleanup
|
||||||
rm -f "${TRIGGER_FILE}.processing"
|
rm -f "${TRIGGER_FILE}.processing"
|
||||||
rm -rf "${UPDATES_DIR}/staging" 2>/dev/null || true
|
rm -rf "${UPDATES_DIR}/staging" 2>/dev/null || true
|
||||||
|
|
||||||
|
|||||||
@@ -21,17 +21,17 @@ const isWindows = platformPaths.isWindows;
|
|||||||
|
|
||||||
const DEFAULTS = {
|
const DEFAULTS = {
|
||||||
CHECK_INTERVAL: 30 * 60 * 1000, // 30 minutes
|
CHECK_INTERVAL: 30 * 60 * 1000, // 30 minutes
|
||||||
UPDATE_URL: 'https://get.dashcaddy.net/release',
|
UPDATE_URL: process.env.DASHCADDY_UPDATE_URL || 'https://get.dashcaddy.net/release',
|
||||||
MIRROR_URL: 'https://get2.dashcaddy.net/release',
|
MIRROR_URL: process.env.DASHCADDY_MIRROR_URL || 'https://get2.dashcaddy.net/release',
|
||||||
UPDATES_DIR: platformPaths.isWindows ? path.join(platformPaths.caddyBase, 'updates') : '/app/updates',
|
UPDATES_DIR: platformPaths.containerUpdatesDir,
|
||||||
// API_SOURCE_DIR is the HOST path — written to trigger.json for the host-side updater
|
// API_SOURCE_DIR is the HOST path — written to trigger.json for the host-side updater
|
||||||
API_SOURCE_DIR: path.join(platformPaths.caddySites, 'dashcaddy-api'),
|
API_SOURCE_DIR: path.join(platformPaths.caddySites, 'dashcaddy-api'),
|
||||||
// FRONTEND_DIR is the container path — dashboard is volume-mounted at /app/dashboard
|
// FRONTEND_DIR is the container path — dashboard is volume-mounted at /app/dashboard
|
||||||
FRONTEND_DIR: platformPaths.isWindows ? path.join(platformPaths.caddySites, 'status') : '/app/dashboard',
|
FRONTEND_DIR: platformPaths.containerFrontendDir,
|
||||||
MAX_BACKUPS: 3,
|
MAX_BACKUPS: 3,
|
||||||
HEALTH_TIMEOUT: 60000,
|
HEALTH_TIMEOUT: 60000,
|
||||||
DOWNLOAD_TIMEOUT: 120000,
|
DOWNLOAD_TIMEOUT: 120000,
|
||||||
CHANNEL: 'stable',
|
CHANNEL: process.env.DASHCADDY_UPDATE_CHANNEL || 'stable',
|
||||||
INSTANCE_ID_FILE: platformPaths.isWindows
|
INSTANCE_ID_FILE: platformPaths.isWindows
|
||||||
? path.join(platformPaths.caddyBase, 'instance-id')
|
? path.join(platformPaths.caddyBase, 'instance-id')
|
||||||
: '/etc/dashcaddy/instance-id',
|
: '/etc/dashcaddy/instance-id',
|
||||||
|
|||||||
@@ -25,7 +25,8 @@ process.on('uncaughtException', (error) => {
|
|||||||
// Load license
|
// Load license
|
||||||
await licenseManager.load();
|
await licenseManager.load();
|
||||||
|
|
||||||
const PORT = process.env.PORT || 3001;
|
const PORT = parseInt(process.env.PORT, 10) || 3001;
|
||||||
|
const HOST = process.env.HOST || '0.0.0.0';
|
||||||
const CADDYFILE_PATH = process.env.CADDYFILE_PATH || platformPaths.caddyfile;
|
const CADDYFILE_PATH = process.env.CADDYFILE_PATH || platformPaths.caddyfile;
|
||||||
const CADDY_ADMIN_URL = process.env.CADDY_ADMIN_URL || platformPaths.caddyAdminUrl;
|
const CADDY_ADMIN_URL = process.env.CADDY_ADMIN_URL || platformPaths.caddyAdminUrl;
|
||||||
const SERVICES_FILE = process.env.SERVICES_FILE || platformPaths.servicesFile;
|
const SERVICES_FILE = process.env.SERVICES_FILE || platformPaths.servicesFile;
|
||||||
@@ -43,9 +44,10 @@ process.on('uncaughtException', (error) => {
|
|||||||
});
|
});
|
||||||
|
|
||||||
// Start HTTP server
|
// Start HTTP server
|
||||||
const server = app.listen(PORT, '0.0.0.0', () => {
|
const server = app.listen(PORT, HOST, () => {
|
||||||
log.info('server', 'DashCaddy API server started', {
|
log.info('server', 'DashCaddy API server started', {
|
||||||
port: PORT,
|
port: PORT,
|
||||||
|
host: HOST,
|
||||||
caddyfile: CADDYFILE_PATH,
|
caddyfile: CADDYFILE_PATH,
|
||||||
caddyAdmin: CADDY_ADMIN_URL,
|
caddyAdmin: CADDY_ADMIN_URL,
|
||||||
services: SERVICES_FILE,
|
services: SERVICES_FILE,
|
||||||
@@ -73,9 +75,12 @@ process.on('uncaughtException', (error) => {
|
|||||||
try { bundledWorkflows = require('./bundled-workflows'); } catch { /* optional */ }
|
try { bundledWorkflows = require('./bundled-workflows'); } catch { /* optional */ }
|
||||||
|
|
||||||
// Initialize workflow engine if bundled-workflows is available
|
// Initialize workflow engine if bundled-workflows is available
|
||||||
|
// NOTE: createApp() already initializes the workflow engine in src/app.js
|
||||||
|
// This block is kept for backward compat with entry points that don't use createApp()
|
||||||
let workflowEngine = null;
|
let workflowEngine = null;
|
||||||
if (bundledWorkflows) {
|
if (bundledWorkflows) {
|
||||||
try {
|
try {
|
||||||
|
const { fetchT } = require('./src/utils/http');
|
||||||
const { WorkflowEngine } = bundledWorkflows;
|
const { WorkflowEngine } = bundledWorkflows;
|
||||||
// Create a context with needed services
|
// Create a context with needed services
|
||||||
const workflowCtx = {
|
const workflowCtx = {
|
||||||
|
|||||||
+195
-5
@@ -16,6 +16,7 @@ const { asyncHandler } = require('./utils/async-handler');
|
|||||||
|
|
||||||
// Managers and utilities
|
// Managers and utilities
|
||||||
const StateManager = require('../state-manager');
|
const StateManager = require('../state-manager');
|
||||||
|
const platformPaths = require('../platform-paths');
|
||||||
const { LicenseManager } = require('../license-manager');
|
const { LicenseManager } = require('../license-manager');
|
||||||
const credentialManager = require('../credential-manager');
|
const credentialManager = require('../credential-manager');
|
||||||
const authManager = require('../auth-manager');
|
const authManager = require('../auth-manager');
|
||||||
@@ -77,6 +78,15 @@ const themesRoutes = require('../routes/themes');
|
|||||||
const dockerResourcesRoutes = require('../routes/docker-resources');
|
const dockerResourcesRoutes = require('../routes/docker-resources');
|
||||||
const eventsRoutes = require('../routes/events');
|
const eventsRoutes = require('../routes/events');
|
||||||
const workflowsRoutes = require('../routes/workflows');
|
const workflowsRoutes = require('../routes/workflows');
|
||||||
|
const dependenciesRoutes = require('../routes/dependencies');
|
||||||
|
const DependencyManager = require('../dependency-manager');
|
||||||
|
const autoRestartRoutes = require('../routes/auto-restart');
|
||||||
|
const configDriftRoutes = require('../routes/config-drift');
|
||||||
|
const sslMonitorRoutes = require('../routes/ssl-monitor');
|
||||||
|
const { AutoRestartManager } = require('../auto-restart-manager');
|
||||||
|
const { ConfigDriftDetector } = require('../config-drift-detector');
|
||||||
|
const SSLMonitor = require('../ssl-monitor');
|
||||||
|
const DNSPropagationChecker = require('../dns-propagation');
|
||||||
|
|
||||||
// Constants
|
// Constants
|
||||||
const { APP } = require('../constants');
|
const { APP } = require('../constants');
|
||||||
@@ -87,6 +97,19 @@ const { APP } = require('../constants');
|
|||||||
async function createApp() {
|
async function createApp() {
|
||||||
const app = express();
|
const app = express();
|
||||||
|
|
||||||
|
// Global request timeout (default 5 minutes — covers slow Docker pulls)
|
||||||
|
// Routes that need longer can override per-request with req.setTimeout()
|
||||||
|
const REQUEST_TIMEOUT_MS = parseInt(process.env.REQUEST_TIMEOUT_MS, 10) || 5 * 60 * 1000;
|
||||||
|
app.use((req, res, next) => {
|
||||||
|
req.setTimeout(REQUEST_TIMEOUT_MS);
|
||||||
|
res.setTimeout(REQUEST_TIMEOUT_MS);
|
||||||
|
next();
|
||||||
|
});
|
||||||
|
// Disable x-powered-by header for security (don't advertise framework)
|
||||||
|
app.disable('x-powered-by');
|
||||||
|
// Trust first proxy (Caddy/nginx in front of us) so req.ip works correctly
|
||||||
|
app.set('trust proxy', 1);
|
||||||
|
|
||||||
// Initialize logging
|
// Initialize logging
|
||||||
const log = createLogger(config.LOG_LEVEL);
|
const log = createLogger(config.LOG_LEVEL);
|
||||||
|
|
||||||
@@ -102,7 +125,7 @@ async function createApp() {
|
|||||||
licenseManager.loadSecret(config.LICENSE_SECRET_FILE);
|
licenseManager.loadSecret(config.LICENSE_SECRET_FILE);
|
||||||
|
|
||||||
// HTTPS agent for internal CA
|
// HTTPS agent for internal CA
|
||||||
const CA_CERT_PATH = process.env.CA_CERT_PATH || '/app/pki/root.crt';
|
const CA_CERT_PATH = process.env.CA_CERT_PATH || platformPaths.pkiRootCert;
|
||||||
let httpsAgent;
|
let httpsAgent;
|
||||||
try {
|
try {
|
||||||
const caCert = fs.readFileSync(CA_CERT_PATH);
|
const caCert = fs.readFileSync(CA_CERT_PATH);
|
||||||
@@ -335,9 +358,65 @@ async function createApp() {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Initialize dependency manager
|
||||||
|
const dependencyManager = new DependencyManager({
|
||||||
|
servicesStateManager,
|
||||||
|
docker: ctx.docker,
|
||||||
|
notification: ctx.notification,
|
||||||
|
log,
|
||||||
|
});
|
||||||
|
ctx.dependencyManager = dependencyManager;
|
||||||
|
log.info('app', 'Dependency manager initialized');
|
||||||
|
|
||||||
|
// Initialize auto-restart manager
|
||||||
|
const autoRestartManager = new AutoRestartManager(ctx);
|
||||||
|
ctx.autoRestartManager = autoRestartManager;
|
||||||
|
autoRestartManager.start();
|
||||||
|
log.info('app', 'Auto-restart manager initialized');
|
||||||
|
|
||||||
|
// Initialize config drift detector
|
||||||
|
const driftDetector = new ConfigDriftDetector(ctx);
|
||||||
|
ctx.driftDetector = driftDetector;
|
||||||
|
driftDetector.startPolling(300000); // 5 min
|
||||||
|
log.info('app', 'Config drift detector initialized');
|
||||||
|
|
||||||
|
// Initialize SSL monitor
|
||||||
|
const sslMonitor = new SSLMonitor(ctx);
|
||||||
|
ctx.sslMonitor = sslMonitor;
|
||||||
|
sslMonitor.start(3600000); // 1 hour
|
||||||
|
log.info('app', 'SSL monitor initialized');
|
||||||
|
|
||||||
|
// Initialize DNS propagation checker
|
||||||
|
const dnsPropagationChecker = new DNSPropagationChecker(ctx);
|
||||||
|
ctx.dnsPropagationChecker = dnsPropagationChecker;
|
||||||
|
log.info('app', 'DNS propagation checker initialized');
|
||||||
|
|
||||||
// Build versioned API router
|
// Build versioned API router
|
||||||
const apiRouter = express.Router();
|
const apiRouter = express.Router();
|
||||||
|
|
||||||
|
// Version endpoint — public, no auth required
|
||||||
|
// Reads version from package.json at startup so the response always matches the running code
|
||||||
|
let appVersion = '0.0.0';
|
||||||
|
let appName = 'dashcaddy-api';
|
||||||
|
try {
|
||||||
|
const pkg = require('../package.json');
|
||||||
|
appVersion = pkg.version || appVersion;
|
||||||
|
appName = pkg.name || appName;
|
||||||
|
} catch { /* package.json unreadable — keep fallback */ }
|
||||||
|
apiRouter.get('/version', (req, res) => {
|
||||||
|
res.json({
|
||||||
|
success: true,
|
||||||
|
name: appName,
|
||||||
|
version: appVersion,
|
||||||
|
node: process.version,
|
||||||
|
platform: process.platform,
|
||||||
|
arch: process.arch,
|
||||||
|
uptime: process.uptime(),
|
||||||
|
instanceId: process.env.DASHCADDY_INSTANCE_ID || null
|
||||||
|
});
|
||||||
|
});
|
||||||
|
log.info('app', `Version endpoint available at /api/v1/version (v${appVersion})`);
|
||||||
|
|
||||||
// Wire up notification listeners for resourceMonitor and backupManager
|
// Wire up notification listeners for resourceMonitor and backupManager
|
||||||
if (ctx.notification && ctx.resourceMonitor) {
|
if (ctx.notification && ctx.resourceMonitor) {
|
||||||
ctx.resourceMonitor.on('alert', (alertData) => {
|
ctx.resourceMonitor.on('alert', (alertData) => {
|
||||||
@@ -375,7 +454,8 @@ async function createApp() {
|
|||||||
log: ctx.log,
|
log: ctx.log,
|
||||||
safeErrorMessage: ctx.safeErrorMessage,
|
safeErrorMessage: ctx.safeErrorMessage,
|
||||||
fetchT: ctx.fetchT,
|
fetchT: ctx.fetchT,
|
||||||
credentialManager: ctx.credentialManager
|
credentialManager: ctx.credentialManager,
|
||||||
|
dnsPropagationChecker: ctx.dnsPropagationChecker
|
||||||
}));
|
}));
|
||||||
apiRouter.use('/notifications', notificationRoutes({
|
apiRouter.use('/notifications', notificationRoutes({
|
||||||
notification: ctx.notification,
|
notification: ctx.notification,
|
||||||
@@ -384,7 +464,8 @@ async function createApp() {
|
|||||||
apiRouter.use('/containers', containerRoutes({
|
apiRouter.use('/containers', containerRoutes({
|
||||||
docker: ctx.docker,
|
docker: ctx.docker,
|
||||||
log: ctx.log,
|
log: ctx.log,
|
||||||
asyncHandler: ctx.asyncHandler
|
asyncHandler: ctx.asyncHandler,
|
||||||
|
workflowEngine: ctx.workflowEngine
|
||||||
}));
|
}));
|
||||||
apiRouter.use(serviceRoutes({
|
apiRouter.use(serviceRoutes({
|
||||||
servicesStateManager: ctx.servicesStateManager,
|
servicesStateManager: ctx.servicesStateManager,
|
||||||
@@ -488,13 +569,42 @@ async function createApp() {
|
|||||||
resourceMonitor: ctx.resourceMonitor,
|
resourceMonitor: ctx.resourceMonitor,
|
||||||
healthChecker: ctx.healthChecker,
|
healthChecker: ctx.healthChecker,
|
||||||
updateManager: ctx.updateManager,
|
updateManager: ctx.updateManager,
|
||||||
logError: ctx.logError
|
logError: ctx.logError,
|
||||||
|
dependencyManager: ctx.dependencyManager,
|
||||||
|
autoRestartManager: ctx.autoRestartManager,
|
||||||
|
driftDetector: ctx.driftDetector,
|
||||||
|
sslMonitor: ctx.sslMonitor,
|
||||||
|
dnsPropagationChecker: ctx.dnsPropagationChecker
|
||||||
}));
|
}));
|
||||||
apiRouter.use(workflowsRoutes({
|
apiRouter.use('/workflows', workflowsRoutes({
|
||||||
workflowEngine: ctx.workflowEngine,
|
workflowEngine: ctx.workflowEngine,
|
||||||
licenseManager: ctx.licenseManager,
|
licenseManager: ctx.licenseManager,
|
||||||
asyncHandler: ctx.asyncHandler
|
asyncHandler: ctx.asyncHandler
|
||||||
}));
|
}));
|
||||||
|
apiRouter.use('/dependencies', dependenciesRoutes({
|
||||||
|
dependencyManager: ctx.dependencyManager,
|
||||||
|
servicesStateManager: ctx.servicesStateManager,
|
||||||
|
docker: ctx.docker,
|
||||||
|
asyncHandler: ctx.asyncHandler,
|
||||||
|
logError: ctx.logError,
|
||||||
|
resyncHealthChecker: ctx.resyncHealthChecker,
|
||||||
|
log: ctx.log,
|
||||||
|
}));
|
||||||
|
apiRouter.use(autoRestartRoutes({
|
||||||
|
autoRestartManager: ctx.autoRestartManager,
|
||||||
|
asyncHandler: ctx.asyncHandler,
|
||||||
|
logError: ctx.logError,
|
||||||
|
}));
|
||||||
|
apiRouter.use(configDriftRoutes({
|
||||||
|
driftDetector: ctx.driftDetector,
|
||||||
|
asyncHandler: ctx.asyncHandler,
|
||||||
|
logError: ctx.logError,
|
||||||
|
}));
|
||||||
|
apiRouter.use(sslMonitorRoutes({
|
||||||
|
sslMonitor: ctx.sslMonitor,
|
||||||
|
asyncHandler: ctx.asyncHandler,
|
||||||
|
logError: ctx.logError,
|
||||||
|
}));
|
||||||
|
|
||||||
// Inline API routes
|
// Inline API routes
|
||||||
apiRouter.get('/health', (req, res) => {
|
apiRouter.get('/health', (req, res) => {
|
||||||
@@ -517,6 +627,86 @@ async function createApp() {
|
|||||||
res.json({ status: 'ok', timestamp: new Date().toISOString() });
|
res.json({ status: 'ok', timestamp: new Date().toISOString() });
|
||||||
});
|
});
|
||||||
|
|
||||||
|
// Liveness probe — "is the process alive?"
|
||||||
|
// Always returns 200 unless the Node.js event loop is completely blocked.
|
||||||
|
// Used by k8s/Docker to decide whether to RESTART the container.
|
||||||
|
// DO NOT add dependency checks here — those belong in /health/ready.
|
||||||
|
app.get('/health/live', (req, res) => {
|
||||||
|
res.json({ status: 'alive', uptime: process.uptime() });
|
||||||
|
});
|
||||||
|
|
||||||
|
// Readiness probe — "is the app ready to serve traffic?"
|
||||||
|
// Checks critical dependencies: Docker daemon, Caddy admin API, config file.
|
||||||
|
// Returns 200 with details if all OK, 503 with failed components otherwise.
|
||||||
|
// Used by k8s/Docker to decide whether to ROUTE TRAFFIC to this instance.
|
||||||
|
app.get('/health/ready', boundAsyncHandler(async (req, res) => {
|
||||||
|
const checks = {};
|
||||||
|
let allOk = true;
|
||||||
|
|
||||||
|
// Check 1: Config file readable
|
||||||
|
try {
|
||||||
|
const fs = require('fs');
|
||||||
|
if (fs.existsSync(config.CONFIG_FILE)) {
|
||||||
|
fs.readFileSync(config.CONFIG_FILE, 'utf8');
|
||||||
|
checks.configFile = { ok: true };
|
||||||
|
} else {
|
||||||
|
checks.configFile = { ok: false, error: 'Config file not found' };
|
||||||
|
allOk = false;
|
||||||
|
}
|
||||||
|
} catch (e) {
|
||||||
|
checks.configFile = { ok: false, error: e.message };
|
||||||
|
allOk = false;
|
||||||
|
}
|
||||||
|
|
||||||
|
// Check 2: Services file readable
|
||||||
|
try {
|
||||||
|
const fs = require('fs');
|
||||||
|
if (fs.existsSync(config.SERVICES_FILE)) {
|
||||||
|
fs.readFileSync(config.SERVICES_FILE, 'utf8');
|
||||||
|
checks.servicesFile = { ok: true };
|
||||||
|
} else {
|
||||||
|
checks.servicesFile = { ok: false, error: 'Services file not found' };
|
||||||
|
allOk = false;
|
||||||
|
}
|
||||||
|
} catch (e) {
|
||||||
|
checks.servicesFile = { ok: false, error: e.message };
|
||||||
|
allOk = false;
|
||||||
|
}
|
||||||
|
|
||||||
|
// Check 3: Docker daemon reachable
|
||||||
|
try {
|
||||||
|
const docker = require('dockerode')();
|
||||||
|
await docker.ping();
|
||||||
|
checks.docker = { ok: true };
|
||||||
|
} catch (e) {
|
||||||
|
checks.docker = { ok: false, error: e.message };
|
||||||
|
allOk = false;
|
||||||
|
}
|
||||||
|
|
||||||
|
// Check 4: Caddy admin API reachable
|
||||||
|
try {
|
||||||
|
const caddyUrl = config.CADDY_ADMIN_URL || 'http://localhost:2019';
|
||||||
|
const controller = new AbortController();
|
||||||
|
const timeout = setTimeout(() => controller.abort(), 3000);
|
||||||
|
const response = await fetch(`${caddyUrl}/config/`, {
|
||||||
|
signal: controller.signal
|
||||||
|
});
|
||||||
|
clearTimeout(timeout);
|
||||||
|
checks.caddy = { ok: response.ok, status: response.status };
|
||||||
|
if (!response.ok) allOk = false;
|
||||||
|
} catch (e) {
|
||||||
|
checks.caddy = { ok: false, error: e.message };
|
||||||
|
allOk = false;
|
||||||
|
}
|
||||||
|
|
||||||
|
const body = {
|
||||||
|
status: allOk ? 'ready' : 'not-ready',
|
||||||
|
timestamp: new Date().toISOString(),
|
||||||
|
checks
|
||||||
|
};
|
||||||
|
res.status(allOk ? 200 : 503).json(body);
|
||||||
|
}));
|
||||||
|
|
||||||
// Lightweight probe endpoint
|
// Lightweight probe endpoint
|
||||||
app.get('/probe/:id', boundAsyncHandler(async (req, res) => {
|
app.get('/probe/:id', boundAsyncHandler(async (req, res) => {
|
||||||
const id = req.params.id;
|
const id = req.params.id;
|
||||||
|
|||||||
@@ -0,0 +1,142 @@
|
|||||||
|
/**
|
||||||
|
* Config migration system
|
||||||
|
*
|
||||||
|
* When config.json schema changes between versions, register a migration
|
||||||
|
* function here. On load, the loader detects the stored version, runs all
|
||||||
|
* migrations from that version forward, and writes the result back.
|
||||||
|
*
|
||||||
|
* Migration format:
|
||||||
|
* migrations[<toVersion>] = (rawConfig) => { ...mutations, _version: toVersion }
|
||||||
|
*
|
||||||
|
* Each migration is responsible for transforming the previous version's
|
||||||
|
* shape into the next version's shape. They run sequentially, so v1→v2→v3
|
||||||
|
* all execute in order.
|
||||||
|
*
|
||||||
|
* For first-time users with no config file, the loader creates a fresh
|
||||||
|
* config with CURRENT_VERSION, so they start at the latest schema.
|
||||||
|
*/
|
||||||
|
const fs = require('fs');
|
||||||
|
const path = require('path');
|
||||||
|
const platformPaths = require('../../platform-paths');
|
||||||
|
|
||||||
|
const CURRENT_VERSION = 2;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Migrations: keys are the version they PRODUCE.
|
||||||
|
* Each migration takes a raw config object and returns the next version.
|
||||||
|
*/
|
||||||
|
const migrations = {
|
||||||
|
// v0 (unversioned) → v1: add _version field, normalize dns structure
|
||||||
|
1: (raw) => {
|
||||||
|
const migrated = { ...raw };
|
||||||
|
if (!migrated._version) migrated._version = 1;
|
||||||
|
// Normalize: older configs may have dns as a string IP, convert to object
|
||||||
|
if (typeof migrated.dns === 'string') {
|
||||||
|
migrated.dns = { ip: migrated.dns, port: 5380 };
|
||||||
|
} else if (!migrated.dns) {
|
||||||
|
migrated.dns = { ip: '', port: 5380 };
|
||||||
|
}
|
||||||
|
return migrated;
|
||||||
|
},
|
||||||
|
|
||||||
|
// v1 → v2: add dns.provider field (default: 'technitium' for backwards compat)
|
||||||
|
2: (raw) => {
|
||||||
|
const migrated = { ...raw };
|
||||||
|
if (migrated.dns && !migrated.dns.provider) {
|
||||||
|
migrated.dns.provider = 'technitium';
|
||||||
|
}
|
||||||
|
migrated._version = 2;
|
||||||
|
return migrated;
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Run all migrations from `fromVersion` (or detected) to CURRENT_VERSION.
|
||||||
|
* @param {object} raw - The raw config object (may or may not have _version)
|
||||||
|
* @returns {object} The migrated config
|
||||||
|
*/
|
||||||
|
function migrate(raw) {
|
||||||
|
if (!raw || typeof raw !== 'object') {
|
||||||
|
// First-time load: return minimal config at current version
|
||||||
|
return { _version: CURRENT_VERSION };
|
||||||
|
}
|
||||||
|
|
||||||
|
const fromVersion = raw._version || 0;
|
||||||
|
if (fromVersion > CURRENT_VERSION) {
|
||||||
|
// Config from a future version — bail out, don't corrupt it
|
||||||
|
// The validation step will catch any actual issues
|
||||||
|
return raw;
|
||||||
|
}
|
||||||
|
|
||||||
|
let current = { ...raw };
|
||||||
|
for (let v = fromVersion + 1; v <= CURRENT_VERSION; v++) {
|
||||||
|
if (migrations[v]) {
|
||||||
|
current = migrations[v](current);
|
||||||
|
} else {
|
||||||
|
// No migration defined for this version, just bump _version
|
||||||
|
current._version = v;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return current;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Load config from disk, run migrations if needed, and write back the
|
||||||
|
* migrated version. Safe to call on every startup.
|
||||||
|
* @param {string} configFile - Absolute path to config.json
|
||||||
|
* @param {object} log - Logger instance
|
||||||
|
* @returns {object} The migrated config object
|
||||||
|
*/
|
||||||
|
function loadAndMigrate(configFile, log) {
|
||||||
|
let raw = null;
|
||||||
|
let fileExisted = false;
|
||||||
|
|
||||||
|
if (fs.existsSync(configFile)) {
|
||||||
|
fileExisted = true;
|
||||||
|
try {
|
||||||
|
raw = JSON.parse(fs.readFileSync(configFile, 'utf8'));
|
||||||
|
} catch (e) {
|
||||||
|
if (log && log.error) {
|
||||||
|
log.error('config-migration', 'Failed to parse config.json, using defaults', { error: e.message });
|
||||||
|
}
|
||||||
|
raw = null;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
const fromVersion = raw && raw._version ? raw._version : 0;
|
||||||
|
const migrated = migrate(raw);
|
||||||
|
|
||||||
|
// Only write back to disk if:
|
||||||
|
// 1. The file already existed (we don't create configs on fresh installs —
|
||||||
|
// the loader's defaults handle that case), AND
|
||||||
|
// 2. The version actually changed (no point rewriting identical content)
|
||||||
|
if (fileExisted && fromVersion < CURRENT_VERSION) {
|
||||||
|
if (log && log.info) {
|
||||||
|
log.info('config-migration', `Migrated config v${fromVersion} → v${CURRENT_VERSION}`, {
|
||||||
|
from: fromVersion,
|
||||||
|
to: CURRENT_VERSION,
|
||||||
|
path: configFile
|
||||||
|
});
|
||||||
|
}
|
||||||
|
// Write back the migrated config
|
||||||
|
try {
|
||||||
|
// Ensure parent dir exists
|
||||||
|
const dir = path.dirname(configFile);
|
||||||
|
if (!fs.existsSync(dir)) fs.mkdirSync(dir, { recursive: true });
|
||||||
|
fs.writeFileSync(configFile, JSON.stringify(migrated, null, 2));
|
||||||
|
} catch (e) {
|
||||||
|
if (log && log.warn) {
|
||||||
|
log.warn('config-migration', 'Failed to write migrated config back to disk', { error: e.message });
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return migrated;
|
||||||
|
}
|
||||||
|
|
||||||
|
module.exports = {
|
||||||
|
CURRENT_VERSION,
|
||||||
|
migrations,
|
||||||
|
migrate,
|
||||||
|
loadAndMigrate
|
||||||
|
};
|
||||||
@@ -1,10 +1,15 @@
|
|||||||
/**
|
/**
|
||||||
* Site configuration loader
|
* Site configuration loader
|
||||||
* Loads and manages site-wide settings from config.json
|
* Loads and manages site-wide settings from config.json
|
||||||
|
*
|
||||||
|
* Includes automatic migration from older config versions (see migrations.js).
|
||||||
|
* Users never see the migration — it runs silently on startup, writes the
|
||||||
|
* updated config back, and the rest of the app only ever sees the current
|
||||||
|
* schema.
|
||||||
*/
|
*/
|
||||||
const fs = require('fs');
|
|
||||||
const { validateConfig } = require('../../config-schema');
|
const { validateConfig } = require('../../config-schema');
|
||||||
const { CADDY } = require('../../constants');
|
const { CADDY } = require('../../constants');
|
||||||
|
const { loadAndMigrate, CURRENT_VERSION } = require('./migrations');
|
||||||
|
|
||||||
const siteConfig = {
|
const siteConfig = {
|
||||||
tld: '.home',
|
tld: '.home',
|
||||||
@@ -21,9 +26,11 @@ const siteConfig = {
|
|||||||
|
|
||||||
function loadSiteConfig(CONFIG_FILE, log) {
|
function loadSiteConfig(CONFIG_FILE, log) {
|
||||||
try {
|
try {
|
||||||
if (fs.existsSync(CONFIG_FILE)) {
|
// Run migrations first — this handles config.json files from older
|
||||||
const raw = JSON.parse(fs.readFileSync(CONFIG_FILE, 'utf8'));
|
// versions of DashCaddy and writes the migrated version back to disk.
|
||||||
|
const raw = loadAndMigrate(CONFIG_FILE, log);
|
||||||
|
|
||||||
|
if (raw && Object.keys(raw).length > 0) {
|
||||||
// Validate config and log any issues
|
// Validate config and log any issues
|
||||||
const { valid, errors: configErrors, warnings: configWarnings } = validateConfig(raw);
|
const { valid, errors: configErrors, warnings: configWarnings } = validateConfig(raw);
|
||||||
if (log && log.warn) {
|
if (log && log.warn) {
|
||||||
@@ -76,4 +83,5 @@ module.exports = {
|
|||||||
loadSiteConfig,
|
loadSiteConfig,
|
||||||
buildDomain,
|
buildDomain,
|
||||||
buildServiceUrl,
|
buildServiceUrl,
|
||||||
|
CURRENT_VERSION
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -1,8 +1,14 @@
|
|||||||
/**
|
/**
|
||||||
* DNS context - Technitium DNS operations and token management
|
* DNS context - Technitium DNS operations and token management
|
||||||
|
*
|
||||||
|
* DEPRECATED: This module is kept for backward compatibility.
|
||||||
|
* New code should use src/context/provider-dns.js which supports multiple providers.
|
||||||
|
*
|
||||||
|
* This module now delegates to the provider system internally.
|
||||||
*/
|
*/
|
||||||
const { TIMEOUTS, SESSION_TTL, CADDY } = require('../../constants');
|
const { TIMEOUTS, SESSION_TTL, CADDY } = require('../../constants');
|
||||||
const { createCache, CACHE_CONFIGS } = require('../../cache-config');
|
const { createCache, CACHE_CONFIGS } = require('../../cache-config');
|
||||||
|
const { createProviderDnsContext } = require('./provider-dns');
|
||||||
|
|
||||||
// DNS token management
|
// DNS token management
|
||||||
let dnsToken = process.env.DNS_ADMIN_TOKEN || '';
|
let dnsToken = process.env.DNS_ADMIN_TOKEN || '';
|
||||||
@@ -281,6 +287,10 @@ function invalidateTokenForServer(serverIp) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
function createDnsContext(siteConfig, buildDomain, credentialManager, fetchT, httpsAgent, log, DNS_CREDENTIALS_FILE) {
|
function createDnsContext(siteConfig, buildDomain, credentialManager, fetchT, httpsAgent, log, DNS_CREDENTIALS_FILE) {
|
||||||
|
// Create the new provider-aware context
|
||||||
|
const providerCtx = createProviderDnsContext(siteConfig, buildDomain, credentialManager, fetchT, httpsAgent, log, DNS_CREDENTIALS_FILE);
|
||||||
|
|
||||||
|
// Legacy Technitium-specific wrappers (kept for backward compat)
|
||||||
const ensureToken = () => ensureValidDnsToken(siteConfig, credentialManager, fetchT, log);
|
const ensureToken = () => ensureValidDnsToken(siteConfig, credentialManager, fetchT, log);
|
||||||
const require = (providedToken) => requireDnsToken(providedToken, siteConfig, credentialManager, fetchT, log);
|
const require = (providedToken) => requireDnsToken(providedToken, siteConfig, credentialManager, fetchT, log);
|
||||||
const getForServer = (server, role) => getTokenForServer(server, siteConfig, credentialManager, fetchT, log, role);
|
const getForServer = (server, role) => getTokenForServer(server, siteConfig, credentialManager, fetchT, log, role);
|
||||||
@@ -289,6 +299,7 @@ function createDnsContext(siteConfig, buildDomain, credentialManager, fetchT, ht
|
|||||||
const call = (server, apiPath, params) => callDns(server, apiPath, params, fetchT, httpsAgent);
|
const call = (server, apiPath, params) => callDns(server, apiPath, params, fetchT, httpsAgent);
|
||||||
|
|
||||||
return {
|
return {
|
||||||
|
// Legacy Technitium-specific interface (unchanged)
|
||||||
call,
|
call,
|
||||||
buildUrl: buildDnsUrl,
|
buildUrl: buildDnsUrl,
|
||||||
requireToken: require,
|
requireToken: require,
|
||||||
@@ -302,6 +313,17 @@ function createDnsContext(siteConfig, buildDomain, credentialManager, fetchT, ht
|
|||||||
invalidateTokenForServer,
|
invalidateTokenForServer,
|
||||||
refresh,
|
refresh,
|
||||||
credentialsFile: DNS_CREDENTIALS_FILE,
|
credentialsFile: DNS_CREDENTIALS_FILE,
|
||||||
|
|
||||||
|
// Provider-aware methods (new)
|
||||||
|
getProviderId: providerCtx.getProviderId,
|
||||||
|
getActiveProvider: providerCtx.getActiveProvider,
|
||||||
|
getAvailableProviders: providerCtx.getAvailableProviders,
|
||||||
|
supportsCapability: providerCtx.supportsCapability,
|
||||||
|
|
||||||
|
// Universal DNS helpers (delegated to provider context)
|
||||||
|
universalCreateRecord: providerCtx.universalCreateRecord,
|
||||||
|
universalDeleteRecord: providerCtx.universalDeleteRecord,
|
||||||
|
universalResolveRecord: providerCtx.universalResolveRecord,
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -0,0 +1,302 @@
|
|||||||
|
/**
|
||||||
|
* Provider-aware DNS Context
|
||||||
|
* Replaces the Technitium-only context with a provider-agnostic layer.
|
||||||
|
* Delegates to the active DNS provider adapter based on config.
|
||||||
|
*
|
||||||
|
* Falls back to legacy Technitium context for backward compatibility
|
||||||
|
* when no provider is explicitly configured.
|
||||||
|
*/
|
||||||
|
const { createCache, CACHE_CONFIGS } = require('../../cache-config');
|
||||||
|
const { TIMEOUTS, SESSION_TTL, CADDY } = require('../../constants');
|
||||||
|
const registry = require('../../dns-providers/registry');
|
||||||
|
|
||||||
|
// Per-server token cache (legacy Technitium)
|
||||||
|
const dnsServerTokens = createCache(CACHE_CONFIGS.dnsTokens);
|
||||||
|
let dnsToken = '';
|
||||||
|
let dnsTokenExpiry = null;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Create a provider-aware DNS context.
|
||||||
|
* This wraps both the new provider system and the legacy Technitium context
|
||||||
|
* for seamless migration.
|
||||||
|
*/
|
||||||
|
function createProviderDnsContext(siteConfig, buildDomain, credentialManager, fetchT, httpsAgent, log, DNS_CREDENTIALS_FILE) {
|
||||||
|
/** Resolve the active provider from config */
|
||||||
|
function getProviderId() {
|
||||||
|
// New explicit provider field
|
||||||
|
if (siteConfig.dns?.provider) return siteConfig.dns.provider;
|
||||||
|
// Legacy: if dns.ip is set, default to technitium
|
||||||
|
if (siteConfig.dnsServerIp || siteConfig.dns?.ip) return 'technitium';
|
||||||
|
// No DNS configured
|
||||||
|
return 'manual';
|
||||||
|
}
|
||||||
|
|
||||||
|
/** Get provider-specific config from site config */
|
||||||
|
function getProviderConfig(providerId) {
|
||||||
|
const dnsConfig = siteConfig.dns || {};
|
||||||
|
|
||||||
|
switch (providerId) {
|
||||||
|
case 'technitium':
|
||||||
|
return {
|
||||||
|
serverIp: siteConfig.dnsServerIp || dnsConfig.ip || '',
|
||||||
|
serverPort: siteConfig.dnsServerPort || dnsConfig.port || '5380',
|
||||||
|
dnsServers: siteConfig.dnsServers || {},
|
||||||
|
dnsId: Object.keys(siteConfig.dnsServers || {})[0] || 'dns1'
|
||||||
|
};
|
||||||
|
case 'cloudflare':
|
||||||
|
return {
|
||||||
|
apiToken: dnsConfig.apiToken || '',
|
||||||
|
zoneId: dnsConfig.zoneId || '',
|
||||||
|
domain: siteConfig.domain || ''
|
||||||
|
};
|
||||||
|
case 'rfc2136':
|
||||||
|
return {
|
||||||
|
server: dnsConfig.server || siteConfig.dnsServerIp || '',
|
||||||
|
port: dnsConfig.port || 53,
|
||||||
|
zone: siteConfig.tld?.replace(/^\./, '') || '',
|
||||||
|
tsigAlgorithm: dnsConfig.tsigAlgorithm || 'hmac-sha256',
|
||||||
|
tsigKeyName: dnsConfig.tsigKeyName || '',
|
||||||
|
tsigSecret: dnsConfig.tsigSecret || ''
|
||||||
|
};
|
||||||
|
case 'manual':
|
||||||
|
return {};
|
||||||
|
default:
|
||||||
|
return dnsConfig;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/** Get or create the active provider adapter */
|
||||||
|
function getActiveProvider() {
|
||||||
|
const providerId = getProviderId();
|
||||||
|
const config = getProviderConfig(providerId);
|
||||||
|
const ctx = { log, credentialManager, fetchT, httpsAgent };
|
||||||
|
return registry.getProvider(providerId, config, ctx);
|
||||||
|
}
|
||||||
|
|
||||||
|
// ===== Legacy Technitium helpers (kept for backward compat) =====
|
||||||
|
function buildDnsUrl(server, apiPath, params) {
|
||||||
|
const protocol = server.match(/^\d+\.\d+\.\d+\.\d+$/) ? 'http' : 'https';
|
||||||
|
const port = protocol === 'http' ? `:${CADDY.DEFAULT_DNS_PORT}` : '';
|
||||||
|
const qs = params instanceof URLSearchParams ? params.toString() : new URLSearchParams(params).toString();
|
||||||
|
return `${protocol}://${server}${port}${apiPath}?${qs}`;
|
||||||
|
}
|
||||||
|
|
||||||
|
async function callDns(server, apiPath, params) {
|
||||||
|
const url = buildDnsUrl(server, apiPath, params);
|
||||||
|
const response = await fetchT(url, {
|
||||||
|
method: 'GET',
|
||||||
|
headers: { 'Accept': 'application/json' },
|
||||||
|
agent: httpsAgent
|
||||||
|
}, TIMEOUTS.HTTP_LONG);
|
||||||
|
return response.json();
|
||||||
|
}
|
||||||
|
|
||||||
|
async function refreshDnsToken(username, password, server) {
|
||||||
|
try {
|
||||||
|
const params = new URLSearchParams({ user: username, pass: password, includeInfo: 'false' });
|
||||||
|
const response = await fetchT(
|
||||||
|
`http://${server}:5380/api/user/login?${params.toString()}`,
|
||||||
|
{ method: 'POST', headers: { 'Accept': 'application/json', 'Content-Type': 'application/x-www-form-urlencoded' }, timeout: 10000 }
|
||||||
|
);
|
||||||
|
const result = await response.json();
|
||||||
|
if (result.status === 'ok' && result.token) {
|
||||||
|
dnsToken = result.token;
|
||||||
|
dnsTokenExpiry = new Date(Date.now() + SESSION_TTL.DNS_TOKEN).toISOString();
|
||||||
|
log.info('dns', 'DNS token refreshed', { expires: dnsTokenExpiry });
|
||||||
|
return { success: true, token: dnsToken };
|
||||||
|
}
|
||||||
|
return { success: false, error: result.errorMessage || 'Login failed' };
|
||||||
|
} catch (error) {
|
||||||
|
log.error('dns', 'DNS token refresh error', { error: error.message });
|
||||||
|
return { success: false, error: error.message };
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
function dnsIpToDnsId(serverIp) {
|
||||||
|
for (const [dnsId, info] of Object.entries(siteConfig.dnsServers || {})) {
|
||||||
|
if (info.ip === serverIp) return dnsId;
|
||||||
|
}
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
|
||||||
|
async function ensureValidDnsToken() {
|
||||||
|
if (dnsToken && dnsTokenExpiry && new Date() < new Date(dnsTokenExpiry)) {
|
||||||
|
return { success: true, token: dnsToken };
|
||||||
|
}
|
||||||
|
const primaryIp = siteConfig.dnsServerIp;
|
||||||
|
if (primaryIp) {
|
||||||
|
const dnsId = dnsIpToDnsId(primaryIp);
|
||||||
|
if (dnsId) {
|
||||||
|
for (const role of ['admin', 'readonly']) {
|
||||||
|
try {
|
||||||
|
const username = await credentialManager.retrieve(`dns.${dnsId}.${role}.username`);
|
||||||
|
const password = await credentialManager.retrieve(`dns.${dnsId}.${role}.password`);
|
||||||
|
if (username && password) return await refreshDnsToken(username, password, primaryIp);
|
||||||
|
} catch (err) { /* try next */ }
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
try {
|
||||||
|
const username = await credentialManager.retrieve('dns.username');
|
||||||
|
const password = await credentialManager.retrieve('dns.password');
|
||||||
|
const server = await credentialManager.retrieve('dns.server');
|
||||||
|
if (username && password) return await refreshDnsToken(username, password, server || primaryIp);
|
||||||
|
} catch (err) { /* no global creds */ }
|
||||||
|
return { success: false, error: 'No DNS credentials configured' };
|
||||||
|
}
|
||||||
|
|
||||||
|
async function getTokenForServer(targetServer, role = 'readonly') {
|
||||||
|
const cacheKey = `${targetServer}:${role}`;
|
||||||
|
const cached = dnsServerTokens.get(cacheKey);
|
||||||
|
if (cached?.token && cached?.expiry && new Date() < new Date(cached.expiry)) {
|
||||||
|
return { success: true, token: cached.token };
|
||||||
|
}
|
||||||
|
const serverPort = siteConfig.dnsServerPort || '5380';
|
||||||
|
async function authToServer(username, password) {
|
||||||
|
const params = new URLSearchParams({ user: username, pass: password, includeInfo: 'false' });
|
||||||
|
const response = await fetchT(
|
||||||
|
`http://${targetServer}:${serverPort}/api/user/login?${params.toString()}`,
|
||||||
|
{ method: 'POST', headers: { 'Accept': 'application/json', 'Content-Type': 'application/x-www-form-urlencoded' } }
|
||||||
|
);
|
||||||
|
const result = await response.json();
|
||||||
|
if (result.status === 'ok' && result.token) {
|
||||||
|
dnsServerTokens.set(cacheKey, { token: result.token, expiry: new Date(Date.now() + SESSION_TTL.DNS_TOKEN).toISOString() });
|
||||||
|
log.info('dns', 'DNS token obtained for server', { server: targetServer, role });
|
||||||
|
return { success: true, token: result.token };
|
||||||
|
}
|
||||||
|
return { success: false, error: result.errorMessage || 'Login failed' };
|
||||||
|
}
|
||||||
|
const dnsId = dnsIpToDnsId(targetServer);
|
||||||
|
if (dnsId) {
|
||||||
|
for (const r of [role, role === 'readonly' ? 'admin' : 'readonly']) {
|
||||||
|
try {
|
||||||
|
const username = await credentialManager.retrieve(`dns.${dnsId}.${r}.username`);
|
||||||
|
const password = await credentialManager.retrieve(`dns.${dnsId}.${r}.password`);
|
||||||
|
if (username && password) return await authToServer(username, password);
|
||||||
|
} catch { /* try next */ }
|
||||||
|
}
|
||||||
|
}
|
||||||
|
try {
|
||||||
|
const username = await credentialManager.retrieve('dns.username');
|
||||||
|
const password = await credentialManager.retrieve('dns.password');
|
||||||
|
if (username && password) return await authToServer(username, password);
|
||||||
|
} catch { /* no global creds */ }
|
||||||
|
return { success: false, error: 'No DNS credentials configured' };
|
||||||
|
}
|
||||||
|
|
||||||
|
async function requireDnsToken(providedToken) {
|
||||||
|
if (providedToken) return providedToken;
|
||||||
|
const result = await ensureValidDnsToken();
|
||||||
|
if (result.success) return result.token;
|
||||||
|
const err = new Error('No valid DNS token available. ' + result.error);
|
||||||
|
err.statusCode = 401;
|
||||||
|
throw err;
|
||||||
|
}
|
||||||
|
|
||||||
|
function invalidateTokenForServer(serverIp) {
|
||||||
|
dnsServerTokens.delete(`${serverIp}:readonly`);
|
||||||
|
dnsServerTokens.delete(`${serverIp}:admin`);
|
||||||
|
}
|
||||||
|
|
||||||
|
// ===== Public context API =====
|
||||||
|
// This maintains the same interface as the old createDnsContext()
|
||||||
|
// but adds provider-aware methods on top.
|
||||||
|
|
||||||
|
return {
|
||||||
|
// --- Provider-aware methods ---
|
||||||
|
/** Get the active provider ID */
|
||||||
|
getProviderId,
|
||||||
|
|
||||||
|
/** Get the active provider adapter instance */
|
||||||
|
getActiveProvider,
|
||||||
|
|
||||||
|
/** Get metadata for all available providers */
|
||||||
|
getAvailableProviders: () => registry.getProviderMeta(),
|
||||||
|
|
||||||
|
/** Check if the active provider supports a capability */
|
||||||
|
supportsCapability: (cap) => {
|
||||||
|
try { return getActiveProvider().supportsCapability(cap); }
|
||||||
|
catch { return false; }
|
||||||
|
},
|
||||||
|
|
||||||
|
// --- Legacy Technitium context (backward compat) ---
|
||||||
|
call: callDns,
|
||||||
|
buildUrl: buildDnsUrl,
|
||||||
|
requireToken: requireDnsToken,
|
||||||
|
ensureToken: ensureValidDnsToken,
|
||||||
|
getToken: () => dnsToken,
|
||||||
|
setToken: (t) => { dnsToken = t; },
|
||||||
|
getTokenExpiry: () => dnsTokenExpiry,
|
||||||
|
setTokenExpiry: (e) => { dnsTokenExpiry = e; },
|
||||||
|
getTokenForServer,
|
||||||
|
invalidateTokenForServer,
|
||||||
|
refresh: refreshDnsToken,
|
||||||
|
credentialsFile: DNS_CREDENTIALS_FILE,
|
||||||
|
|
||||||
|
// --- Universal DNS helpers (provider-agnostic) ---
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Create a DNS A record using the active provider.
|
||||||
|
* Gracefully handles manual adapters that return instructions instead of performing the action.
|
||||||
|
*/
|
||||||
|
async universalCreateRecord(subdomain, ip) {
|
||||||
|
const provider = getActiveProvider();
|
||||||
|
const result = await provider.createRecord({
|
||||||
|
domain: buildDomain(subdomain),
|
||||||
|
zone: siteConfig.tld?.replace(/^\./, '') || '',
|
||||||
|
type: 'A',
|
||||||
|
value: ip,
|
||||||
|
ttl: 300,
|
||||||
|
overwrite: true,
|
||||||
|
});
|
||||||
|
// Manual adapter returns instructions instead of performing the action
|
||||||
|
if (result?.manual || result?.instructions) {
|
||||||
|
return { success: true, manual: true, instructions: result.instructions || result };
|
||||||
|
}
|
||||||
|
return result;
|
||||||
|
},
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Delete a DNS A record using the active provider.
|
||||||
|
* Gracefully handles manual adapters that return instructions instead of performing the action.
|
||||||
|
*/
|
||||||
|
async universalDeleteRecord(domain, ip) {
|
||||||
|
const provider = getActiveProvider();
|
||||||
|
const result = await provider.deleteRecord({
|
||||||
|
domain,
|
||||||
|
type: 'A',
|
||||||
|
value: ip,
|
||||||
|
});
|
||||||
|
if (result?.manual || result?.instructions) {
|
||||||
|
return { success: true, manual: true, instructions: result.instructions || result };
|
||||||
|
}
|
||||||
|
return result;
|
||||||
|
},
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Resolve DNS records using the active provider.
|
||||||
|
* Returns parsed IP addresses from the result.
|
||||||
|
*/
|
||||||
|
async universalResolveRecord(domain, type) {
|
||||||
|
const provider = getActiveProvider();
|
||||||
|
const result = await provider.resolveRecords({
|
||||||
|
domain,
|
||||||
|
zone: siteConfig.tld?.replace(/^\./, '') || '',
|
||||||
|
type: type || 'A',
|
||||||
|
});
|
||||||
|
// Parse IP addresses from the result
|
||||||
|
if (Array.isArray(result)) {
|
||||||
|
return result;
|
||||||
|
}
|
||||||
|
if (result?.records) {
|
||||||
|
return result.records.map(r => r.ipAddress || r.value || r.address || r).filter(Boolean);
|
||||||
|
}
|
||||||
|
if (result?.ips) {
|
||||||
|
return result.ips;
|
||||||
|
}
|
||||||
|
return result;
|
||||||
|
},
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
module.exports = { createProviderDnsContext };
|
||||||
@@ -94,8 +94,12 @@ async function logError(ERROR_LOG_FILE, MAX_ERROR_LOG_SIZE, context, error, addi
|
|||||||
* Return a safe error message without leaking internals
|
* Return a safe error message without leaking internals
|
||||||
*/
|
*/
|
||||||
function safeErrorMessage(error) {
|
function safeErrorMessage(error) {
|
||||||
|
if (!error) return 'An internal error occurred';
|
||||||
const msg = error.message || String(error);
|
const msg = error.message || String(error);
|
||||||
|
|
||||||
|
// Always expose DC-prefixed user-facing errors
|
||||||
|
if (/\[DC-\d+\]/.test(msg)) return msg;
|
||||||
|
|
||||||
// Detect port conflict errors
|
// Detect port conflict errors
|
||||||
const portMatch = msg.match(/exposing port TCP [^:]*:(\d+)/);
|
const portMatch = msg.match(/exposing port TCP [^:]*:(\d+)/);
|
||||||
if (portMatch || msg.includes('port is already allocated') || msg.includes('ports are not available')) {
|
if (portMatch || msg.includes('port is already allocated') || msg.includes('ports are not available')) {
|
||||||
@@ -103,7 +107,7 @@ function safeErrorMessage(error) {
|
|||||||
return `[DC-200] Port ${port} is already in use. Try a different port or stop the service using that port first.`;
|
return `[DC-200] Port ${port} is already in use. Try a different port or stop the service using that port first.`;
|
||||||
}
|
}
|
||||||
|
|
||||||
// Only expose short, user-facing messages
|
// Only expose short, user-facing messages (no paths, stack traces, or internal details)
|
||||||
if (msg.length < 200 && !msg.includes('/') && !msg.includes('\\') && !msg.includes(' at ')) {
|
if (msg.length < 200 && !msg.includes('/') && !msg.includes('\\') && !msg.includes(' at ')) {
|
||||||
return msg;
|
return msg;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,22 +1,124 @@
|
|||||||
/**
|
/**
|
||||||
* Response helpers - Standard API response formats
|
* Response helpers - Standard API response formats
|
||||||
|
*
|
||||||
|
* Single source of truth for HTTP response shapes across DashCaddy.
|
||||||
|
* Standard envelope: { success: true, ...data } or { success: false, error: "..." }.
|
||||||
|
*
|
||||||
|
* All routes should import from this module — do not call res.json/res.status
|
||||||
|
* directly with the response shape, use these helpers instead.
|
||||||
*/
|
*/
|
||||||
|
const { HTTP_STATUS } = require('../../constants');
|
||||||
|
|
||||||
|
// ── Success helpers ────────────────────────────────────────────
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Standard error response
|
* Standard success response. Use this in route handlers.
|
||||||
|
* Wraps the data object with a `success: true` envelope.
|
||||||
|
* @param {object} res Express response
|
||||||
|
* @param {object} [data={}] fields to include in the response body
|
||||||
|
* @param {number} [statusCode=200] HTTP status code
|
||||||
|
*/
|
||||||
|
function ok(res, data = {}, statusCode = HTTP_STATUS.OK) {
|
||||||
|
return res.status(statusCode).json({ success: true, ...data });
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Alias for `ok` — prefer `ok` in new code, but kept for code that imports as `success`.
|
||||||
|
*/
|
||||||
|
function success(res, data, statusCode) {
|
||||||
|
return ok(res, data, statusCode);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Success response with a human-readable message field.
|
||||||
|
* Use when there's no data to return, just confirmation.
|
||||||
|
*/
|
||||||
|
function successMessage(res, message, statusCode = HTTP_STATUS.OK) {
|
||||||
|
return res.status(statusCode).json({ success: true, message });
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* 201 Created response.
|
||||||
|
*/
|
||||||
|
function created(res, data = {}) {
|
||||||
|
return res.status(HTTP_STATUS.CREATED).json({ success: true, ...data });
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* 204 No Content response.
|
||||||
|
*/
|
||||||
|
function noContent(res) {
|
||||||
|
return res.status(HTTP_STATUS.NO_CONTENT).send();
|
||||||
|
}
|
||||||
|
|
||||||
|
// ── Error helpers ──────────────────────────────────────────────
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Standard error response. Use this in route handlers.
|
||||||
|
* @param {object} res Express response
|
||||||
|
* @param {number} statusCode HTTP status code
|
||||||
|
* @param {string} message Human-readable error message
|
||||||
|
* @param {object} [extras={}] additional fields to merge into the response
|
||||||
*/
|
*/
|
||||||
function errorResponse(res, statusCode, message, extras = {}) {
|
function errorResponse(res, statusCode, message, extras = {}) {
|
||||||
return res.status(statusCode).json({ success: false, error: message, ...extras });
|
return res.status(statusCode).json({ success: false, error: message, ...extras });
|
||||||
}
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Standard success response
|
* Alias for `errorResponse` — kept for code that imports as `error`.
|
||||||
*/
|
*/
|
||||||
function ok(res, data = {}) {
|
function error(res, message, statusCode = HTTP_STATUS.INTERNAL_ERROR) {
|
||||||
return res.json({ success: true, ...data });
|
return res.status(statusCode).json({ success: false, error: message });
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* 400 Bad Request — invalid input from the user.
|
||||||
|
*/
|
||||||
|
function validationError(res, message) {
|
||||||
|
return res.status(HTTP_STATUS.BAD_REQUEST).json({ success: false, error: message });
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* 401 Unauthorized — no valid credentials.
|
||||||
|
*/
|
||||||
|
function unauthorized(res, message = 'Unauthorized') {
|
||||||
|
return res.status(HTTP_STATUS.UNAUTHORIZED).json({ success: false, error: message });
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* 403 Forbidden — credentials valid but permission denied.
|
||||||
|
*/
|
||||||
|
function forbidden(res, message = 'Forbidden') {
|
||||||
|
return res.status(HTTP_STATUS.FORBIDDEN).json({ success: false, error: message });
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* 404 Not Found — resource doesn't exist.
|
||||||
|
*/
|
||||||
|
function notFound(res, message = 'Not found') {
|
||||||
|
return res.status(HTTP_STATUS.NOT_FOUND).json({ success: false, error: message });
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* 409 Conflict — request conflicts with current state (e.g. duplicate).
|
||||||
|
*/
|
||||||
|
function conflict(res, message) {
|
||||||
|
return res.status(HTTP_STATUS.CONFLICT).json({ success: false, error: message });
|
||||||
}
|
}
|
||||||
|
|
||||||
module.exports = {
|
module.exports = {
|
||||||
errorResponse,
|
// Success helpers
|
||||||
ok,
|
ok,
|
||||||
|
success,
|
||||||
|
successMessage,
|
||||||
|
created,
|
||||||
|
noContent,
|
||||||
|
// Error helpers
|
||||||
|
errorResponse,
|
||||||
|
error,
|
||||||
|
validationError,
|
||||||
|
unauthorized,
|
||||||
|
forbidden,
|
||||||
|
notFound,
|
||||||
|
conflict,
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -0,0 +1,411 @@
|
|||||||
|
/**
|
||||||
|
* SSL Certificate Monitor
|
||||||
|
* Periodically checks SSL certificates on services with HTTPS URLs.
|
||||||
|
* Alerts at 30, 14, and 7 days before expiry.
|
||||||
|
*
|
||||||
|
* @module ssl-monitor
|
||||||
|
*/
|
||||||
|
|
||||||
|
const tls = require('tls');
|
||||||
|
const EventEmitter = require('events');
|
||||||
|
const path = require('path');
|
||||||
|
const { readJsonFile, writeJsonFile } = require('./fs-helpers');
|
||||||
|
const { resolveServiceUrl } = require('./url-resolver');
|
||||||
|
|
||||||
|
/** Default check interval: 1 hour */
|
||||||
|
const DEFAULT_INTERVAL_MS = 3600000;
|
||||||
|
|
||||||
|
/** Alert thresholds in days */
|
||||||
|
const THRESHOLDS = {
|
||||||
|
WARNING: 30,
|
||||||
|
URGENT: 14,
|
||||||
|
CRITICAL: 7
|
||||||
|
};
|
||||||
|
|
||||||
|
/** TLS connection timeout in milliseconds */
|
||||||
|
const TLS_TIMEOUT_MS = 10000;
|
||||||
|
|
||||||
|
class SSLMonitor extends EventEmitter {
|
||||||
|
/**
|
||||||
|
* Create an SSLMonitor instance.
|
||||||
|
* @param {Object} ctx - Shared application context
|
||||||
|
* @param {Object} ctx.servicesStateManager - State manager for reading services
|
||||||
|
* @param {Function} ctx.buildServiceUrl - URL builder helper
|
||||||
|
* @param {Object} ctx.siteConfig - Site configuration
|
||||||
|
* @param {Object} ctx.notification - NotificationManager instance
|
||||||
|
* @param {Object} ctx.log - Logger instance
|
||||||
|
* @param {string} [ctx.SSL_CACHE_FILE] - Path to persist SSL cache
|
||||||
|
*/
|
||||||
|
constructor(ctx) {
|
||||||
|
super();
|
||||||
|
this.ctx = ctx;
|
||||||
|
this.log = ctx.log || console;
|
||||||
|
|
||||||
|
/** @type {Map<string, Object>} hostname → last cert check result */
|
||||||
|
this.certStatus = new Map();
|
||||||
|
|
||||||
|
/** @type {Map<string, number>} hostname → last notified threshold level */
|
||||||
|
this.notifiedThresholds = new Map();
|
||||||
|
|
||||||
|
/** @type {Map<string, string>} hostname → service ID mapping */
|
||||||
|
this.hostnameToServiceId = new Map();
|
||||||
|
|
||||||
|
/** @type {NodeJS.Timeout|null} */
|
||||||
|
this.intervalHandle = null;
|
||||||
|
|
||||||
|
/** Current config */
|
||||||
|
this.config = {
|
||||||
|
enabled: true,
|
||||||
|
intervalMs: DEFAULT_INTERVAL_MS
|
||||||
|
};
|
||||||
|
|
||||||
|
/** Cache file path */
|
||||||
|
this.cacheFile = ctx.SSL_CACHE_FILE ||
|
||||||
|
path.join(path.dirname(ctx.SERVICES_FILE || './data'), 'ssl-cache.json');
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Check the SSL certificate for a given hostname and port.
|
||||||
|
* Connects via TLS with rejectUnauthorized: false to retrieve certificate info.
|
||||||
|
*
|
||||||
|
* @param {string} hostname - The hostname to check
|
||||||
|
* @param {number} [port=443] - The port to connect to
|
||||||
|
* @returns {Promise<Object>} Certificate information
|
||||||
|
*/
|
||||||
|
async checkCert(hostname, port = 443) {
|
||||||
|
return new Promise((resolve, reject) => {
|
||||||
|
const socket = tls.connect({
|
||||||
|
host: hostname,
|
||||||
|
port,
|
||||||
|
rejectUnauthorized: false,
|
||||||
|
servername: hostname,
|
||||||
|
timeout: TLS_TIMEOUT_MS
|
||||||
|
}, () => {
|
||||||
|
try {
|
||||||
|
const cert = socket.getPeerCertificate();
|
||||||
|
|
||||||
|
if (!cert || Object.keys(cert).length === 0) {
|
||||||
|
socket.destroy();
|
||||||
|
return reject(new Error(`No certificate returned for ${hostname}:${port}`));
|
||||||
|
}
|
||||||
|
|
||||||
|
const validFrom = new Date(cert.valid_from);
|
||||||
|
const validTo = new Date(cert.valid_to);
|
||||||
|
const now = new Date();
|
||||||
|
const msRemaining = validTo.getTime() - now.getTime();
|
||||||
|
const daysRemaining = Math.ceil(msRemaining / (1000 * 60 * 60 * 24));
|
||||||
|
|
||||||
|
const result = {
|
||||||
|
hostname,
|
||||||
|
port,
|
||||||
|
subject: cert.subject?.CN || cert.subject?.O || 'Unknown',
|
||||||
|
issuer: cert.issuer?.CN || cert.issuer?.O || 'Unknown',
|
||||||
|
validFrom: cert.valid_from,
|
||||||
|
validTo: cert.valid_to,
|
||||||
|
daysRemaining,
|
||||||
|
fingerprint: cert.fingerprint || null,
|
||||||
|
isExpiring: daysRemaining <= THRESHOLDS.WARNING,
|
||||||
|
checkedAt: new Date().toISOString()
|
||||||
|
};
|
||||||
|
|
||||||
|
socket.destroy();
|
||||||
|
resolve(result);
|
||||||
|
} catch (err) {
|
||||||
|
socket.destroy();
|
||||||
|
reject(err);
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
socket.on('error', (err) => {
|
||||||
|
reject(new Error(`TLS connect error for ${hostname}:${port}: ${err.message}`));
|
||||||
|
});
|
||||||
|
|
||||||
|
socket.setTimeout(TLS_TIMEOUT_MS, () => {
|
||||||
|
socket.destroy(new Error(`TLS connection timeout for ${hostname}:${port}`));
|
||||||
|
reject(new Error(`TLS connection timeout for ${hostname}:${port}`));
|
||||||
|
});
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Check SSL certificates for all services that have HTTPS URLs.
|
||||||
|
* Reads services from ctx.servicesStateManager, resolves URLs, and checks each HTTPS cert.
|
||||||
|
*
|
||||||
|
* @returns {Promise<Object>} Map of hostname → cert status
|
||||||
|
*/
|
||||||
|
async checkAll() {
|
||||||
|
if (!this.config.enabled) {
|
||||||
|
this.log.info('ssl-monitor', 'SSL monitoring is disabled, skipping check');
|
||||||
|
return this.getStatus();
|
||||||
|
}
|
||||||
|
|
||||||
|
let servicesData;
|
||||||
|
try {
|
||||||
|
servicesData = await this.ctx.servicesStateManager.read();
|
||||||
|
} catch (err) {
|
||||||
|
this.log.error('ssl-monitor', 'Failed to read services', { error: err.message });
|
||||||
|
return this.getStatus();
|
||||||
|
}
|
||||||
|
|
||||||
|
const services = Array.isArray(servicesData) ? servicesData : (servicesData.services || []);
|
||||||
|
|
||||||
|
for (const service of services) {
|
||||||
|
const serviceId = service.id || service.name?.toLowerCase();
|
||||||
|
if (!serviceId) continue;
|
||||||
|
|
||||||
|
try {
|
||||||
|
const url = resolveServiceUrl(serviceId, service, this.ctx.siteConfig, this.ctx.buildServiceUrl);
|
||||||
|
if (!url) continue;
|
||||||
|
|
||||||
|
const parsed = new URL(url);
|
||||||
|
if (parsed.protocol !== 'https:') continue;
|
||||||
|
|
||||||
|
const hostname = parsed.hostname;
|
||||||
|
const port = parseInt(parsed.port) || 443;
|
||||||
|
|
||||||
|
// Map hostname back to service ID
|
||||||
|
this.hostnameToServiceId.set(hostname, serviceId);
|
||||||
|
|
||||||
|
const result = await this.checkCert(hostname, port);
|
||||||
|
|
||||||
|
// Store result
|
||||||
|
this.certStatus.set(hostname, result);
|
||||||
|
|
||||||
|
// Emit check event
|
||||||
|
this.emit('cert-check', { serviceId, hostname, result });
|
||||||
|
|
||||||
|
// Check alert thresholds
|
||||||
|
await this._checkAndNotify(hostname, result, serviceId);
|
||||||
|
} catch (err) {
|
||||||
|
this.log.warn('ssl-monitor', `Failed to check cert for service ${serviceId}`, {
|
||||||
|
error: err.message
|
||||||
|
});
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// Persist results
|
||||||
|
await this._saveCache();
|
||||||
|
|
||||||
|
return this.getStatus();
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Start periodic SSL certificate checking.
|
||||||
|
*
|
||||||
|
* @param {number} [intervalMs=3600000] - Check interval in milliseconds
|
||||||
|
*/
|
||||||
|
start(intervalMs) {
|
||||||
|
if (intervalMs !== undefined) {
|
||||||
|
this.config.intervalMs = intervalMs;
|
||||||
|
}
|
||||||
|
if (this.intervalHandle) {
|
||||||
|
this.log.warn('ssl-monitor', 'SSL monitor is already running');
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
this.config.enabled = true;
|
||||||
|
|
||||||
|
// Load cached data
|
||||||
|
this._loadCache().catch(err => {
|
||||||
|
this.log.warn('ssl-monitor', 'Failed to load SSL cache', { error: err.message });
|
||||||
|
});
|
||||||
|
|
||||||
|
// Initial check (non-blocking)
|
||||||
|
this.checkAll().catch(err => {
|
||||||
|
this.log.error('ssl-monitor', 'Initial SSL check failed', { error: err.message });
|
||||||
|
});
|
||||||
|
|
||||||
|
// Schedule periodic checks
|
||||||
|
this.intervalHandle = setInterval(() => {
|
||||||
|
this.checkAll().catch(err => {
|
||||||
|
this.log.error('ssl-monitor', 'Periodic SSL check failed', { error: err.message });
|
||||||
|
});
|
||||||
|
}, this.config.intervalMs);
|
||||||
|
|
||||||
|
this.log.info('ssl-monitor', 'SSL monitoring started', {
|
||||||
|
intervalMs: this.config.intervalMs
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Stop periodic SSL certificate checking.
|
||||||
|
*/
|
||||||
|
stop() {
|
||||||
|
if (this.intervalHandle) {
|
||||||
|
clearInterval(this.intervalHandle);
|
||||||
|
this.intervalHandle = null;
|
||||||
|
}
|
||||||
|
this.config.enabled = false;
|
||||||
|
this.log.info('ssl-monitor', 'SSL monitoring stopped');
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Get the current SSL certificate status for all checked hostnames.
|
||||||
|
*
|
||||||
|
* @returns {Object} Map of hostname → cert status
|
||||||
|
*/
|
||||||
|
getStatus() {
|
||||||
|
const status = {};
|
||||||
|
for (const [hostname, cert] of this.certStatus.entries()) {
|
||||||
|
status[hostname] = { ...cert };
|
||||||
|
}
|
||||||
|
return status;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Get the SSL certificate status for a specific service.
|
||||||
|
*
|
||||||
|
* @param {string} serviceId - The service ID to look up
|
||||||
|
* @returns {Object|null} Certificate status or null if not found
|
||||||
|
*/
|
||||||
|
getServiceCertStatus(serviceId) {
|
||||||
|
// Find hostname mapped to this service
|
||||||
|
for (const [hostname, id] of this.hostnameToServiceId.entries()) {
|
||||||
|
if (id === serviceId) {
|
||||||
|
const cert = this.certStatus.get(hostname);
|
||||||
|
return cert ? { ...cert, serviceId } : null;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Get current monitoring configuration.
|
||||||
|
*
|
||||||
|
* @returns {Object} Config with interval and enabled state
|
||||||
|
*/
|
||||||
|
getConfig() {
|
||||||
|
return { ...this.config };
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Update monitoring configuration.
|
||||||
|
*
|
||||||
|
* @param {Object} updates - Config updates
|
||||||
|
* @param {boolean} [updates.enabled] - Enable/disable monitoring
|
||||||
|
* @param {number} [updates.intervalMs] - Check interval in milliseconds
|
||||||
|
*/
|
||||||
|
updateConfig(updates) {
|
||||||
|
if (typeof updates.enabled === 'boolean') {
|
||||||
|
this.config.enabled = updates.enabled;
|
||||||
|
if (!updates.enabled && this.intervalHandle) {
|
||||||
|
this.stop();
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if (typeof updates.intervalMs === 'number' && updates.intervalMs >= 60000) {
|
||||||
|
this.config.intervalMs = updates.intervalMs;
|
||||||
|
// Restart interval if running
|
||||||
|
if (this.intervalHandle) {
|
||||||
|
clearInterval(this.intervalHandle);
|
||||||
|
this.intervalHandle = setInterval(() => {
|
||||||
|
this.checkAll().catch(err => {
|
||||||
|
this.log.error('ssl-monitor', 'Periodic SSL check failed', { error: err.message });
|
||||||
|
});
|
||||||
|
}, this.config.intervalMs);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// ===== Private Methods =====
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Check alert thresholds and send notifications if thresholds are crossed.
|
||||||
|
* Only sends one notification per threshold per hostname.
|
||||||
|
*
|
||||||
|
* @param {string} hostname
|
||||||
|
* @param {Object} certResult
|
||||||
|
* @param {string} serviceId
|
||||||
|
*/
|
||||||
|
async _checkAndNotify(hostname, certResult, serviceId) {
|
||||||
|
const { daysRemaining } = certResult;
|
||||||
|
const key = hostname;
|
||||||
|
const lastNotified = this.notifiedThresholds.get(key) || Infinity;
|
||||||
|
|
||||||
|
let level = null;
|
||||||
|
let eventType = null;
|
||||||
|
let message = null;
|
||||||
|
|
||||||
|
if (daysRemaining <= THRESHOLDS.CRITICAL) {
|
||||||
|
level = THRESHOLDS.CRITICAL;
|
||||||
|
eventType = 'cert-critical';
|
||||||
|
message = `🔒 CRITICAL: SSL certificate for ${hostname} expires in ${daysRemaining} days!`;
|
||||||
|
} else if (daysRemaining <= THRESHOLDS.URGENT) {
|
||||||
|
level = THRESHOLDS.URGENT;
|
||||||
|
eventType = 'cert-expiring';
|
||||||
|
message = `⚠️ URGENT: SSL certificate for ${hostname} expires in ${daysRemaining} days`;
|
||||||
|
} else if (daysRemaining <= THRESHOLDS.WARNING) {
|
||||||
|
level = THRESHOLDS.WARNING;
|
||||||
|
eventType = 'cert-expiring';
|
||||||
|
message = `⚠️ SSL certificate for ${hostname} expires in ${daysRemaining} days`;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (level !== null && level < lastNotified) {
|
||||||
|
// New threshold crossed — send notification
|
||||||
|
this.notifiedThresholds.set(key, level);
|
||||||
|
this.emit(eventType, { hostname, serviceId, daysRemaining, level });
|
||||||
|
|
||||||
|
if (this.ctx.notification) {
|
||||||
|
try {
|
||||||
|
await this.ctx.notification.send('ssl-cert-expiry', {
|
||||||
|
text: message,
|
||||||
|
hostname,
|
||||||
|
serviceId,
|
||||||
|
daysRemaining,
|
||||||
|
level,
|
||||||
|
validTo: certResult.validTo
|
||||||
|
}, level <= THRESHOLDS.CRITICAL ? 'error' : 'warning');
|
||||||
|
} catch (err) {
|
||||||
|
this.log.error('ssl-monitor', 'Failed to send SSL notification', { error: err.message });
|
||||||
|
}
|
||||||
|
}
|
||||||
|
} else if (level === null) {
|
||||||
|
// Cert is healthy — reset notification tracking
|
||||||
|
this.notifiedThresholds.delete(key);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Persist cert status cache to disk.
|
||||||
|
*/
|
||||||
|
async _saveCache() {
|
||||||
|
try {
|
||||||
|
const data = {
|
||||||
|
lastChecked: new Date().toISOString(),
|
||||||
|
certs: {},
|
||||||
|
hostnameToServiceId: Object.fromEntries(this.hostnameToServiceId)
|
||||||
|
};
|
||||||
|
for (const [hostname, cert] of this.certStatus.entries()) {
|
||||||
|
data.certs[hostname] = cert;
|
||||||
|
}
|
||||||
|
await writeJsonFile(this.cacheFile, data);
|
||||||
|
} catch (err) {
|
||||||
|
this.log.warn('ssl-monitor', 'Failed to save SSL cache', { error: err.message });
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Load cert status cache from disk.
|
||||||
|
*/
|
||||||
|
async _loadCache() {
|
||||||
|
try {
|
||||||
|
const data = await readJsonFile(this.cacheFile, null);
|
||||||
|
if (data && data.certs) {
|
||||||
|
for (const [hostname, cert] of Object.entries(data.certs)) {
|
||||||
|
this.certStatus.set(hostname, cert);
|
||||||
|
}
|
||||||
|
if (data.hostnameToServiceId) {
|
||||||
|
for (const [hostname, serviceId] of Object.entries(data.hostnameToServiceId)) {
|
||||||
|
this.hostnameToServiceId.set(hostname, serviceId);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
this.log.info('ssl-monitor', 'Loaded SSL cache', {
|
||||||
|
certCount: this.certStatus.size
|
||||||
|
});
|
||||||
|
}
|
||||||
|
} catch (err) {
|
||||||
|
this.log.warn('ssl-monitor', 'Failed to load SSL cache', { error: err.message });
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
module.exports = SSLMonitor;
|
||||||
@@ -0,0 +1,83 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
# =============================================================================
|
||||||
|
# DashCaddy Gitea — Off-host backup to Dropbox
|
||||||
|
# =============================================================================
|
||||||
|
# - Stops gitea container briefly to ensure SQLite DB consistency
|
||||||
|
# - Syncs /var/lib/docker/volumes/gitea-data to dropbox:/Apps/dashcaddy-gitea-backups/<date>/
|
||||||
|
# - Date-stamped snapshots (one per day), kept for 7 days locally
|
||||||
|
# - Restarts gitea even if sync fails
|
||||||
|
# - Logs to /var/log/gitea-backup.log
|
||||||
|
# =============================================================================
|
||||||
|
set -u # don't use -e: we want to always restart gitea
|
||||||
|
|
||||||
|
LOG=/var/log/gitea-backup.log
|
||||||
|
DATA_SRC=/var/lib/docker/volumes/gitea-data/_data
|
||||||
|
DEST="dropbox:/Apps/dashcaddy-gitea-backups"
|
||||||
|
TODAY=$(date -u +%Y-%m-%d)
|
||||||
|
BACKUP_PATH="${DEST}/${TODAY}"
|
||||||
|
RETENTION_DAYS=7
|
||||||
|
|
||||||
|
log() { echo "[$(date -u +%Y-%m-%dT%H:%M:%SZ)] $*" | tee -a "$LOG"; }
|
||||||
|
|
||||||
|
log "=== Backup start ==="
|
||||||
|
|
||||||
|
# 0. Sanity checks
|
||||||
|
if [ ! -d "$DATA_SRC" ]; then
|
||||||
|
log "ERROR: data dir $DATA_SRC missing"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
# 1. Stop gitea to flush SQLite
|
||||||
|
log "Stopping gitea container..."
|
||||||
|
docker stop gitea >> "$LOG" 2>&1
|
||||||
|
STOP_RC=$?
|
||||||
|
if [ $STOP_RC -ne 0 ]; then
|
||||||
|
log "WARNING: docker stop returned $STOP_RC — container may not be running"
|
||||||
|
fi
|
||||||
|
|
||||||
|
# 2. Sync (use copy so source files are preserved as-is, no --delete)
|
||||||
|
log "Syncing $DATA_SRC -> $BACKUP_PATH"
|
||||||
|
rclone copy "$DATA_SRC" "$BACKUP_PATH" \
|
||||||
|
--transfers 4 \
|
||||||
|
--checkers 8 \
|
||||||
|
--retries 3 \
|
||||||
|
--low-level-retries 10 \
|
||||||
|
--stats 30s \
|
||||||
|
--log-file "$LOG" \
|
||||||
|
--log-level INFO
|
||||||
|
SYNC_RC=$?
|
||||||
|
|
||||||
|
# 3. Always restart gitea
|
||||||
|
log "Starting gitea container..."
|
||||||
|
docker start gitea >> "$LOG" 2>&1
|
||||||
|
START_RC=$?
|
||||||
|
|
||||||
|
# Wait for gitea to be ready
|
||||||
|
for i in {1..30}; do
|
||||||
|
if curl -sf http://localhost:3000/api/v1/version > /dev/null 2>&1; then
|
||||||
|
log "Gitea is up after ${i}s"
|
||||||
|
break
|
||||||
|
fi
|
||||||
|
sleep 1
|
||||||
|
done
|
||||||
|
|
||||||
|
# 4. Cleanup old backups (older than RETENTION_DAYS)
|
||||||
|
log "Pruning local + remote snapshots older than ${RETENTION_DAYS} days..."
|
||||||
|
CUTOFF=$(date -u -d "${RETENTION_DAYS} days ago" +%Y-%m-%d)
|
||||||
|
rclone lsf "$DEST/" --dirs-only 2>/dev/null | while read -r d; do
|
||||||
|
# rclone returns names with trailing /
|
||||||
|
name="${d%/}"
|
||||||
|
if [[ "$name" < "$CUTOFF" ]]; then
|
||||||
|
log " removing old: $name"
|
||||||
|
rclone purge "${DEST}/${name}" >> "$LOG" 2>&1
|
||||||
|
fi
|
||||||
|
done
|
||||||
|
|
||||||
|
# 5. Report
|
||||||
|
if [ $SYNC_RC -eq 0 ] && [ $START_RC -eq 0 ]; then
|
||||||
|
log "=== Backup OK ==="
|
||||||
|
exit 0
|
||||||
|
else
|
||||||
|
log "=== Backup completed with errors (sync=$SYNC_RC, start=$START_RC) ==="
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
Executable
+379
@@ -0,0 +1,379 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
# DashCaddy Host-Side Updater
|
||||||
|
# Triggered by systemd path unit when the container writes trigger.json.
|
||||||
|
# Reads the trigger, backs up current API + data/, copies new files, rebuilds container.
|
||||||
|
# Writes result.json so the new container knows the outcome.
|
||||||
|
#
|
||||||
|
# This runs on the HOST, outside the container.
|
||||||
|
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
|
readonly UPDATES_DIR="/opt/dashcaddy/updates"
|
||||||
|
readonly TRIGGER_FILE="${UPDATES_DIR}/trigger.json"
|
||||||
|
readonly RESULT_FILE="${UPDATES_DIR}/result.json"
|
||||||
|
readonly BACKUPS_DIR="${UPDATES_DIR}/backups"
|
||||||
|
readonly CONTAINER_NAME="dashcaddy-api"
|
||||||
|
readonly IMAGE_TAG="dashcaddy-dashcaddy-api:latest"
|
||||||
|
readonly MAX_BACKUPS=3
|
||||||
|
readonly HEALTH_TIMEOUT=60
|
||||||
|
|
||||||
|
# Data directory backup — stored alongside code backups so everything rolls back together
|
||||||
|
readonly DATA_SOURCE_DIR="/opt/dashcaddy/dashcaddy-api/data"
|
||||||
|
readonly DATA_BACKUP_PREFIX="data-backup"
|
||||||
|
|
||||||
|
log() { echo "[dashcaddy-update] $(date '+%Y-%m-%d %H:%M:%S') $*"; }
|
||||||
|
|
||||||
|
write_result() {
|
||||||
|
local success="$1" version="$2" duration="$3"
|
||||||
|
shift 3
|
||||||
|
local error="${1:-}"
|
||||||
|
|
||||||
|
if [[ "$success" == "true" ]]; then
|
||||||
|
cat > "$RESULT_FILE" <<EOF
|
||||||
|
{
|
||||||
|
"success": true,
|
||||||
|
"version": "${version}",
|
||||||
|
"duration": ${duration},
|
||||||
|
"timestamp": "$(date -u +%Y-%m-%dT%H:%M:%SZ)"
|
||||||
|
}
|
||||||
|
EOF
|
||||||
|
else
|
||||||
|
cat > "$RESULT_FILE" <<EOF
|
||||||
|
{
|
||||||
|
"success": false,
|
||||||
|
"version": "${version}",
|
||||||
|
"duration": ${duration},
|
||||||
|
"error": "${error}",
|
||||||
|
"timestamp": "$(date -u +%Y-%m-%dT%H:%M:%SZ)"
|
||||||
|
}
|
||||||
|
EOF
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
|
cleanup_old_backups() {
|
||||||
|
local count
|
||||||
|
count=$(find "$BACKUPS_DIR" -maxdepth 1 -mindepth 1 -type d 2>/dev/null | wc -l)
|
||||||
|
if (( count > MAX_BACKUPS )); then
|
||||||
|
log "Cleaning old backups (${count} > ${MAX_BACKUPS})"
|
||||||
|
find "$BACKUPS_DIR" -maxdepth 1 -mindepth 1 -type d -printf '%T+ %p\n' \
|
||||||
|
| sort | head -n $(( count - MAX_BACKUPS )) | cut -d' ' -f2- \
|
||||||
|
| xargs rm -rf
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
|
# ── Data backup (rsync for efficiency + permissions) ──────────────────────────
|
||||||
|
backup_data_dir() {
|
||||||
|
local backup_dir="$1"
|
||||||
|
if [[ -d "$DATA_SOURCE_DIR" ]]; then
|
||||||
|
log "Backing up data/ to ${backup_dir}/${DATA_BACKUP_PREFIX}/"
|
||||||
|
mkdir -p "${backup_dir}/${DATA_BACKUP_PREFIX}"
|
||||||
|
rsync -a --delete "$DATA_SOURCE_DIR/" "${backup_dir}/${DATA_BACKUP_PREFIX}/" 2>/dev/null \
|
||||||
|
|| cp -a "$DATA_SOURCE_DIR" "${backup_dir}/${DATA_BACKUP_PREFIX}"
|
||||||
|
log "Data backup complete ($(du -sh "${backup_dir}/${DATA_BACKUP_PREFIX}" 2>/dev/null | cut -f1))"
|
||||||
|
else
|
||||||
|
log "WARNING: Data source dir $DATA_SOURCE_DIR not found — skipping data backup"
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
|
# ── Data restore ──────────────────────────────────────────────────────────────
|
||||||
|
restore_data_dir() {
|
||||||
|
local backup_dir="$1"
|
||||||
|
local data_backup="${backup_dir}/${DATA_BACKUP_PREFIX}"
|
||||||
|
if [[ -d "$data_backup" ]]; then
|
||||||
|
log "Restoring data/ from backup..."
|
||||||
|
rsync -a --delete "$data_backup/" "$DATA_SOURCE_DIR/" 2>/dev/null \
|
||||||
|
|| cp -a "$data_backup" "$DATA_SOURCE_DIR"
|
||||||
|
log "Data restored successfully"
|
||||||
|
else
|
||||||
|
log "WARNING: No data backup found at ${data_backup} — data/ not restored"
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
|
wait_for_health() {
|
||||||
|
local port="${1:-3001}"
|
||||||
|
local timeout="$HEALTH_TIMEOUT"
|
||||||
|
local elapsed=0
|
||||||
|
|
||||||
|
log "Waiting for health check (timeout: ${timeout}s)..."
|
||||||
|
while (( elapsed < timeout )); do
|
||||||
|
if curl -fsSL --max-time 3 "http://localhost:${port}/health" &>/dev/null; then
|
||||||
|
log "Health check passed after ${elapsed}s"
|
||||||
|
return 0
|
||||||
|
fi
|
||||||
|
sleep 2
|
||||||
|
elapsed=$(( elapsed + 2 ))
|
||||||
|
done
|
||||||
|
|
||||||
|
log "Health check FAILED after ${timeout}s"
|
||||||
|
return 1
|
||||||
|
}
|
||||||
|
|
||||||
|
# ── Shared rollback: restore code + data ────────────────────────────────────
|
||||||
|
rollback_restore() {
|
||||||
|
local backup_dir="$1"
|
||||||
|
log "Rolling back: restoring code files..."
|
||||||
|
for item in "$backup_dir"/*.js "$backup_dir"/package.json "$backup_dir"/package-lock.json "$backup_dir"/Dockerfile "$backup_dir"/openapi.yaml "$backup_dir"/VERSION; do
|
||||||
|
[[ -f "$item" ]] && cp -f "$item" "$api_source_dir/" 2>/dev/null || true
|
||||||
|
done
|
||||||
|
if [[ -d "$backup_dir/routes" ]]; then
|
||||||
|
rm -rf "$api_source_dir/routes"
|
||||||
|
cp -rf "$backup_dir/routes" "$api_source_dir/routes"
|
||||||
|
fi
|
||||||
|
if [[ -d "$backup_dir/src" ]]; then
|
||||||
|
rm -rf "$api_source_dir/src"
|
||||||
|
cp -rf "$backup_dir/src" "$api_source_dir/src"
|
||||||
|
fi
|
||||||
|
if [[ -d "$backup_dir/dns-providers" ]]; then
|
||||||
|
rm -rf "$api_source_dir/dns-providers"
|
||||||
|
cp -rf "$backup_dir/dns-providers" "$api_source_dir/dns-providers"
|
||||||
|
fi
|
||||||
|
restore_data_dir "$backup_dir"
|
||||||
|
}
|
||||||
|
|
||||||
|
# ── Deployment mode ───────────────────────────────────────────────────────────
|
||||||
|
# Reproduce the SAME container the install created so an auto-update keeps every
|
||||||
|
# volume + env var (docker socket, Caddyfile, config/credentials, updates mount),
|
||||||
|
# not a minimal subset. Standard installs use docker-compose (compose file in the
|
||||||
|
# api source dir); the publish/dev host uses /opt/dashcaddy/start.sh; otherwise a
|
||||||
|
# bare docker run is the last resort. build_image() and restart_container() both
|
||||||
|
# honor the detected mode so build and run stay consistent.
|
||||||
|
deploy_mode() {
|
||||||
|
if [[ -f "$api_source_dir/docker-compose.yml" || -f "$api_source_dir/compose.yml" || -f "$api_source_dir/compose.yaml" ]]; then
|
||||||
|
echo compose
|
||||||
|
elif [[ -x /opt/dashcaddy/start.sh ]]; then
|
||||||
|
echo startsh
|
||||||
|
else
|
||||||
|
echo run
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
|
# Build the API image using whatever the install is wired for. Returns the build
|
||||||
|
# command's exit status so callers can detect failure.
|
||||||
|
build_image() {
|
||||||
|
cd "$api_source_dir" || return 1
|
||||||
|
case "$(deploy_mode)" in
|
||||||
|
compose) docker compose build 2>&1 || docker-compose build 2>&1 ;;
|
||||||
|
*) docker build -t "$IMAGE_TAG" . 2>&1 ;;
|
||||||
|
esac
|
||||||
|
}
|
||||||
|
|
||||||
|
# ── Shared container restart — recreate with the full, install-defined spec ───
|
||||||
|
# Recreates (rm + run / compose up) so new code AND new env vars take effect.
|
||||||
|
restart_container() {
|
||||||
|
cd "$api_source_dir" 2>/dev/null || true
|
||||||
|
case "$(deploy_mode)" in
|
||||||
|
compose)
|
||||||
|
log "Recreating container via docker compose (full compose spec)..."
|
||||||
|
docker compose up -d 2>&1 || docker-compose up -d 2>&1
|
||||||
|
;;
|
||||||
|
startsh)
|
||||||
|
log "Recreating container via /opt/dashcaddy/start.sh (full container spec)..."
|
||||||
|
bash /opt/dashcaddy/start.sh
|
||||||
|
;;
|
||||||
|
*)
|
||||||
|
log "Recreating container via minimal docker run (fallback)..."
|
||||||
|
docker rm -f "$CONTAINER_NAME" 2>/dev/null || true
|
||||||
|
docker run -d --restart unless-stopped --name "$CONTAINER_NAME" \
|
||||||
|
-p 127.0.0.1:3001:3001 \
|
||||||
|
-v /opt/dashcaddy/dashcaddy-api/data:/app/data \
|
||||||
|
-e SERVICES_FILE=/app/data/services.json \
|
||||||
|
"$IMAGE_TAG"
|
||||||
|
;;
|
||||||
|
esac
|
||||||
|
log "Container recreated"
|
||||||
|
}
|
||||||
|
|
||||||
|
# ── Code-only restore (used after failed build when data hasn't changed yet) ──
|
||||||
|
code_restore() {
|
||||||
|
local backup_dir="$1"
|
||||||
|
log "Restoring code files..."
|
||||||
|
for item in "$backup_dir"/*.js "$backup_dir"/package.json "$backup_dir"/package-lock.json "$backup_dir"/Dockerfile "$backup_dir"/openapi.yaml "$backup_dir"/VERSION; do
|
||||||
|
[[ -f "$item" ]] && cp -f "$item" "$api_source_dir/" 2>/dev/null || true
|
||||||
|
done
|
||||||
|
if [[ -d "$backup_dir/routes" ]]; then
|
||||||
|
rm -rf "$api_source_dir/routes"
|
||||||
|
cp -rf "$backup_dir/routes" "$api_source_dir/routes"
|
||||||
|
fi
|
||||||
|
if [[ -d "$backup_dir/src" ]]; then
|
||||||
|
rm -rf "$api_source_dir/src"
|
||||||
|
cp -rf "$backup_dir/src" "$api_source_dir/src"
|
||||||
|
fi
|
||||||
|
if [[ -d "$backup_dir/dns-providers" ]]; then
|
||||||
|
rm -rf "$api_source_dir/dns-providers"
|
||||||
|
cp -rf "$backup_dir/dns-providers" "$api_source_dir/dns-providers"
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
|
main() {
|
||||||
|
local start_time
|
||||||
|
start_time=$(date +%s)
|
||||||
|
|
||||||
|
# 1. Read trigger
|
||||||
|
if [[ ! -f "$TRIGGER_FILE" ]]; then
|
||||||
|
log "No trigger file found — nothing to do"
|
||||||
|
exit 0
|
||||||
|
fi
|
||||||
|
|
||||||
|
# Parse trigger.json (uses python3 which is available on all supported distros)
|
||||||
|
local action version from_version staging_dir api_source_dir commit
|
||||||
|
local frontend_staging_dir frontend_target_dir
|
||||||
|
action=$(python3 -c "import json; print(json.load(open('${TRIGGER_FILE}'))['action'])")
|
||||||
|
version=$(python3 -c "import json; print(json.load(open('${TRIGGER_FILE}'))['version'])")
|
||||||
|
from_version=$(python3 -c "import json; print(json.load(open('${TRIGGER_FILE}'))['fromVersion'])")
|
||||||
|
staging_dir=$(python3 -c "import json; print(json.load(open('${TRIGGER_FILE}'))['stagingDir'])")
|
||||||
|
api_source_dir=$(python3 -c "import json; print(json.load(open('${TRIGGER_FILE}'))['apiSourceDir'])")
|
||||||
|
commit=$(python3 -c "import json; print(json.load(open('${TRIGGER_FILE}')).get('commit') or '')")
|
||||||
|
frontend_staging_dir=$(python3 -c "import json; print(json.load(open('${TRIGGER_FILE}')).get('frontendStagingDir') or '')")
|
||||||
|
frontend_target_dir=$(python3 -c "import json; print(json.load(open('${TRIGGER_FILE}')).get('frontendTargetDir') or '')")
|
||||||
|
# Handle action=rollback (no new version to deploy)
|
||||||
|
local to_version="${version}"
|
||||||
|
|
||||||
|
log "=== ${action^^}: v${from_version} -> v${to_version} ==="
|
||||||
|
log "Staging: ${staging_dir}"
|
||||||
|
log "API source: ${api_source_dir}"
|
||||||
|
|
||||||
|
# Consume the trigger immediately so we don't re-process on failure
|
||||||
|
mv "$TRIGGER_FILE" "${TRIGGER_FILE}.processing"
|
||||||
|
|
||||||
|
# ── Handle rollback ────────────────────────────────────────────────────────
|
||||||
|
if [[ "$action" == "rollback" ]]; then
|
||||||
|
local backup_dir="${BACKUPS_DIR}/${version}"
|
||||||
|
if [[ ! -d "$backup_dir" ]]; then
|
||||||
|
log "ERROR: No backup found for version ${version}"
|
||||||
|
write_result "false" "$version" "$(( $(date +%s) - start_time ))" "No backup found for version ${version}"
|
||||||
|
rm -f "${TRIGGER_FILE}.processing"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
log "Performing rollback to v${version}..."
|
||||||
|
rollback_restore "$backup_dir"
|
||||||
|
|
||||||
|
# Rebuild old code
|
||||||
|
log "Rebuilding container..."
|
||||||
|
build_image 2>&1 | tail -3 || true
|
||||||
|
|
||||||
|
restart_container
|
||||||
|
wait_for_health || log "WARNING: Health check failed after rollback"
|
||||||
|
|
||||||
|
write_result "true" "$version" "$(( $(date +%s) - start_time ))"
|
||||||
|
rm -f "${TRIGGER_FILE}.processing"
|
||||||
|
log "=== Rollback complete ==="
|
||||||
|
exit 0
|
||||||
|
fi
|
||||||
|
|
||||||
|
# ── Handle update ───────────────────────────────────────────────────────────
|
||||||
|
if [[ ! -d "$staging_dir" ]]; then
|
||||||
|
log "ERROR: Staging directory not found: ${staging_dir}"
|
||||||
|
write_result "false" "$to_version" "$(( $(date +%s) - start_time ))" "Staging directory not found"
|
||||||
|
rm -f "${TRIGGER_FILE}.processing"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
# 2. Backup current API code + data/
|
||||||
|
local backup_dir="${BACKUPS_DIR}/${from_version}"
|
||||||
|
mkdir -p "$backup_dir"
|
||||||
|
log "Backing up current API files to ${backup_dir}"
|
||||||
|
for item in "$api_source_dir"/*.js "$api_source_dir"/package.json "$api_source_dir"/package-lock.json "$api_source_dir"/Dockerfile "$api_source_dir"/openapi.yaml "$api_source_dir"/VERSION; do
|
||||||
|
[[ -f "$item" ]] && cp -f "$item" "$backup_dir/" 2>/dev/null || true
|
||||||
|
done
|
||||||
|
[[ -d "$api_source_dir/routes" ]] && cp -rf "$api_source_dir/routes" "$backup_dir/"
|
||||||
|
[[ -d "$api_source_dir/src" ]] && cp -rf "$api_source_dir/src" "$backup_dir/"
|
||||||
|
[[ -d "$api_source_dir/dns-providers" ]] && cp -rf "$api_source_dir/dns-providers" "$backup_dir/"
|
||||||
|
|
||||||
|
# Backup data/ directory (services.json, config.json, credentials, etc.)
|
||||||
|
backup_data_dir "$backup_dir"
|
||||||
|
|
||||||
|
cleanup_old_backups
|
||||||
|
|
||||||
|
# 3. Copy new files from staging to API source
|
||||||
|
log "Deploying new API files..."
|
||||||
|
for item in "$staging_dir"/*.js "$staging_dir"/package.json "$staging_dir"/package-lock.json "$staging_dir"/Dockerfile "$staging_dir"/openapi.yaml "$staging_dir"/VERSION; do
|
||||||
|
[[ -f "$item" ]] && cp -f "$item" "$api_source_dir/" 2>/dev/null || true
|
||||||
|
done
|
||||||
|
if [[ -d "$staging_dir/routes" ]]; then
|
||||||
|
rm -rf "$api_source_dir/routes"
|
||||||
|
cp -rf "$staging_dir/routes" "$api_source_dir/routes"
|
||||||
|
fi
|
||||||
|
if [[ -d "$staging_dir/src" ]]; then
|
||||||
|
rm -rf "$api_source_dir/src"
|
||||||
|
cp -rf "$staging_dir/src" "$api_source_dir/src"
|
||||||
|
fi
|
||||||
|
if [[ -d "$staging_dir/dns-providers" ]]; then
|
||||||
|
rm -rf "$api_source_dir/dns-providers"
|
||||||
|
cp -rf "$staging_dir/dns-providers" "$api_source_dir/dns-providers"
|
||||||
|
fi
|
||||||
|
if [[ -n "$commit" ]]; then
|
||||||
|
echo "$commit" > "$api_source_dir/VERSION"
|
||||||
|
fi
|
||||||
|
|
||||||
|
# 3b. Sync frontend
|
||||||
|
if [[ -z "$frontend_staging_dir" ]]; then
|
||||||
|
parent_staging=$(dirname "$staging_dir")
|
||||||
|
[[ -d "$parent_staging/status" ]] && frontend_staging_dir="$parent_staging/status"
|
||||||
|
fi
|
||||||
|
if [[ -z "$frontend_target_dir" ]]; then
|
||||||
|
for candidate in /var/www/dashcaddy-status /etc/dashcaddy/sites/status; do
|
||||||
|
[[ -d "$candidate" ]] && frontend_target_dir="$candidate" && break
|
||||||
|
done
|
||||||
|
fi
|
||||||
|
if [[ -n "$frontend_staging_dir" && -n "$frontend_target_dir" && -d "$frontend_staging_dir" ]]; then
|
||||||
|
log "Syncing frontend: $frontend_staging_dir -> $frontend_target_dir"
|
||||||
|
mkdir -p "$frontend_target_dir"
|
||||||
|
[[ -f "$frontend_staging_dir/index.html" ]] && cp -f "$frontend_staging_dir/index.html" "$frontend_target_dir/index.html"
|
||||||
|
[[ -f "$frontend_staging_dir/sw.js" ]] && cp -f "$frontend_staging_dir/sw.js" "$frontend_target_dir/sw.js"
|
||||||
|
for sub in dist css vendor js; do
|
||||||
|
if [[ -d "$frontend_staging_dir/$sub" ]]; then
|
||||||
|
mkdir -p "$frontend_target_dir/$sub"
|
||||||
|
cp -rf "$frontend_staging_dir/$sub/"* "$frontend_target_dir/$sub/" 2>/dev/null || true
|
||||||
|
fi
|
||||||
|
done
|
||||||
|
if [[ -d "$frontend_staging_dir/assets" ]]; then
|
||||||
|
mkdir -p "$frontend_target_dir/assets"
|
||||||
|
cp -rf "$frontend_staging_dir/assets/"* "$frontend_target_dir/assets/" 2>/dev/null || true
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
|
||||||
|
# 4. Rebuild container
|
||||||
|
log "Rebuilding container..."
|
||||||
|
local build_ok=false
|
||||||
|
if build_image; then
|
||||||
|
build_ok=true
|
||||||
|
fi
|
||||||
|
|
||||||
|
if [[ "$build_ok" != "true" ]]; then
|
||||||
|
log "ERROR: Docker build failed — rolling back code + data"
|
||||||
|
code_restore "$backup_dir"
|
||||||
|
build_image 2>&1 | tail -3 || true
|
||||||
|
restart_container
|
||||||
|
wait_for_health || true
|
||||||
|
write_result "false" "$to_version" "$(( $(date +%s) - start_time ))" "Docker build failed"
|
||||||
|
rm -f "${TRIGGER_FILE}.processing"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
# 5. Restart container (recreate so new code + env vars take effect)
|
||||||
|
restart_container
|
||||||
|
|
||||||
|
# 6. Health check
|
||||||
|
if wait_for_health; then
|
||||||
|
local duration=$(( $(date +%s) - start_time ))
|
||||||
|
log "=== Update successful: v${to_version} in ${duration}s ==="
|
||||||
|
write_result "true" "$to_version" "$duration"
|
||||||
|
else
|
||||||
|
local duration=$(( $(date +%s) - start_time ))
|
||||||
|
log "ERROR: Health check failed after update — rolling back code + data"
|
||||||
|
rollback_restore "$backup_dir"
|
||||||
|
build_image 2>&1 | tail -3 || true
|
||||||
|
restart_container
|
||||||
|
wait_for_health || log "WARNING: Rollback health check also failed"
|
||||||
|
write_result "false" "$to_version" "$duration" "Health check failed after update"
|
||||||
|
fi
|
||||||
|
|
||||||
|
# 7. Cleanup
|
||||||
|
rm -f "${TRIGGER_FILE}.processing"
|
||||||
|
rm -rf "${UPDATES_DIR}/staging" 2>/dev/null || true
|
||||||
|
|
||||||
|
log "=== Update process complete ==="
|
||||||
|
}
|
||||||
|
|
||||||
|
main "$@"
|
||||||
Executable
+76
@@ -0,0 +1,76 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
# Samihost fail2ban watchdog — auto-unban whitelisted IPs and keep ignoreip list in sync.
|
||||||
|
# Deployed to /usr/local/bin/samihost-fail2ban-watchdog.sh on 194.163.161.162
|
||||||
|
# Cron: every 30 min (0,30 * * * *)
|
||||||
|
|
||||||
|
set -euo pipefail
|
||||||
|
|
||||||
|
JAIL_LOCAL=/etc/fail2ban/jail.local
|
||||||
|
BACKUP=/etc/fail2ban/jail.local.watchdog.bak
|
||||||
|
EXPECTED_IGNOREIP="127.0.0.1/8 ::1 10.0.0.0/8 172.16.0.0/12 192.168.0.0/16 fc00::/7 fe80::/10 100.64.0.0/10 100.121.150.22 100.85.236.10 100.71.97.12 100.81.59.99 100.98.123.59 194.233.88.206 173.212.201.200 194.163.161.162"
|
||||||
|
LOG=/var/log/samihost-fail2ban-watchdog.log
|
||||||
|
TELEGRAM_LOG=/tmp/fail2ban-watchdog-last-action
|
||||||
|
|
||||||
|
ts() { date -u +"%Y-%m-%dT%H:%M:%SZ"; }
|
||||||
|
log() { echo "$(ts) $*" | tee -a "$LOG"; }
|
||||||
|
|
||||||
|
mkdir -p "$(dirname "$LOG")"
|
||||||
|
touch "$LOG"
|
||||||
|
|
||||||
|
# --- 1. Verify ignoreip line is intact and matches expected ---
|
||||||
|
CURRENT=$(grep '^ignoreip' "$JAIL_LOCAL" | sed 's/^ignoreip[[:space:]]*=[[:space:]]*//' || true)
|
||||||
|
EXPECTED_NORMALIZED=$(echo "$EXPECTED_IGNOREIP" | tr ' ' '\n' | sort -u | tr '\n' ' ' | sed 's/ $//')
|
||||||
|
CURRENT_NORMALIZED=$(echo "$CURRENT" | tr ' ' '\n' | sort -u | tr '\n' ' ' | sed 's/ $//')
|
||||||
|
|
||||||
|
if [ "$CURRENT_NORMALIZED" != "$EXPECTED_NORMALIZED" ]; then
|
||||||
|
log "ALERT: ignoreip line drifted. Restoring."
|
||||||
|
cp "$JAIL_LOCAL" "$BACKUP"
|
||||||
|
sed -i "s|^ignoreip = .*|ignoreip = $EXPECTED_IGNOREIP|" "$JAIL_LOCAL"
|
||||||
|
fail2ban-client reload
|
||||||
|
echo "ignoreip restored at $(ts)" > "$TELEGRAM_LOG"
|
||||||
|
log "ignoreip restored, fail2ban reloaded"
|
||||||
|
fi
|
||||||
|
|
||||||
|
# --- 2. Unban any currently-banned IPs that match our trusted set ---
|
||||||
|
BANNED=$(fail2ban-client status sshd 2>/dev/null | awk -F: '/Banned IP list/{print $2}' | tr ' ' '\n' | grep -v '^$' || true)
|
||||||
|
UNBANNED=0
|
||||||
|
for ip in $BANNED; do
|
||||||
|
# Match against any trusted network
|
||||||
|
is_trusted=0
|
||||||
|
for net in 127.0.0.0/8 10.0.0.0/8 172.16.0.0/12 192.168.0.0/16 100.64.0.0/10 ::1 fc00::/7 fe80::/10 100.121.150.22 100.85.236.10 100.71.97.12 100.81.59.99 100.98.123.59 194.233.88.206 173.212.201.200 194.163.161.162; do
|
||||||
|
if [[ "$net" == *"/"* ]]; then
|
||||||
|
# CIDR match (simple IPv4 only — IPv6 needs python or ipcalc, skip for now)
|
||||||
|
base="${net%/*}"
|
||||||
|
mask="${net#*/}"
|
||||||
|
if [[ "$ip" == "$base"* ]] || python3 -c "import ipaddress,sys; sys.exit(0 if ipaddress.ip_address('$ip') in ipaddress.ip_network('$net', strict=False) else 1)" 2>/dev/null; then
|
||||||
|
is_trusted=1
|
||||||
|
break
|
||||||
|
fi
|
||||||
|
else
|
||||||
|
if [ "$ip" = "$net" ]; then
|
||||||
|
is_trusted=1
|
||||||
|
break
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
done
|
||||||
|
if [ "$is_trusted" = "1" ]; then
|
||||||
|
if fail2ban-client set sshd unbanip "$ip" >/dev/null 2>&1; then
|
||||||
|
log "auto-unbanned trusted IP: $ip"
|
||||||
|
UNBANNED=$((UNBANNED+1))
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
done
|
||||||
|
|
||||||
|
[ "$UNBANNED" -gt 0 ] && echo "auto-unbanned $UNBANNED trusted IPs at $(ts)" > "$TELEGRAM_LOG"
|
||||||
|
|
||||||
|
# --- 3. Cap the ban count — if more than 200 are banned, mass-unban stale ones ---
|
||||||
|
TOTAL_BANNED=$(fail2ban-client status sshd 2>/dev/null | awk '/Currently banned/{print $NF}' || echo 0)
|
||||||
|
if [ "$TOTAL_BANNED" -gt 200 ]; then
|
||||||
|
log "ALERT: $TOTAL_BANNED IPs banned. Mass-unbanning all."
|
||||||
|
for ip in $BANNED; do
|
||||||
|
fail2ban-client set sshd unbanip "$ip" >/dev/null 2>&1 || true
|
||||||
|
done
|
||||||
|
echo "mass-unbanned $TOTAL_BANNED stale bans at $(ts)" > "$TELEGRAM_LOG"
|
||||||
|
fi
|
||||||
|
|
||||||
|
log "watchdog run complete (unbanned=$UNBANNED, total_banned=$TOTAL_BANNED)"
|
||||||
@@ -72,6 +72,7 @@ const bundles = {
|
|||||||
],
|
],
|
||||||
'init.js': [
|
'init.js': [
|
||||||
JS('core', 'init.js'),
|
JS('core', 'init.js'),
|
||||||
|
JS('monitoring-widgets.js'),
|
||||||
JS('keyboard-shortcuts.js'),
|
JS('keyboard-shortcuts.js'),
|
||||||
],
|
],
|
||||||
};
|
};
|
||||||
|
|||||||
Vendored
+114
-87
File diff suppressed because one or more lines are too long
Vendored
+308
-233
File diff suppressed because one or more lines are too long
Vendored
+129
-18
File diff suppressed because one or more lines are too long
+11
-2
@@ -256,6 +256,9 @@
|
|||||||
<option value="on">🟢 Online</option>
|
<option value="on">🟢 Online</option>
|
||||||
<option value="off">🔴 Offline</option>
|
<option value="off">🔴 Offline</option>
|
||||||
</select>
|
</select>
|
||||||
|
<select id="service-filter-category" style="padding: 8px 12px; background: var(--bg); border: 1px solid var(--border); border-radius: 6px; color: var(--fg); font-size: 0.9rem;">
|
||||||
|
<option value="all">All Categories</option>
|
||||||
|
</select>
|
||||||
<button id="batch-operations-btn" class="btn-sm" style="padding: 8px 12px;">☰ Batch Operations</button>
|
<button id="batch-operations-btn" class="btn-sm" style="padding: 8px 12px;">☰ Batch Operations</button>
|
||||||
<span id="service-filter-count" style="color: var(--muted); font-size: 0.85rem; white-space: nowrap;"></span>
|
<span id="service-filter-count" style="color: var(--muted); font-size: 0.85rem; white-space: nowrap;"></span>
|
||||||
</div>
|
</div>
|
||||||
@@ -390,8 +393,14 @@
|
|||||||
<!-- DNS Server Configuration -->
|
<!-- DNS Server Configuration -->
|
||||||
<div>
|
<div>
|
||||||
<label class="form-label-accent">
|
<label class="form-label-accent">
|
||||||
🗂️ DNS Server (Technitium)
|
🗂️ DNS Provider
|
||||||
</label>
|
</label>
|
||||||
|
<select id="setup-dns-provider" class="form-input-lg" style="margin-bottom: 12px;">
|
||||||
|
<option value="technitium">Technitium DNS (recommended)</option>
|
||||||
|
<option value="cloudflare">Cloudflare DNS</option>
|
||||||
|
<option value="rfc2136">RFC 2136 (BIND / PowerDNS / other)</option>
|
||||||
|
<option value="manual">Manual / External DNS</option>
|
||||||
|
</select>
|
||||||
<div style="display: grid; grid-template-columns: 1fr auto; gap: 8px;">
|
<div style="display: grid; grid-template-columns: 1fr auto; gap: 8px;">
|
||||||
<input type="text" id="setup-dns-ip" value="" placeholder="DNS server IP"
|
<input type="text" id="setup-dns-ip" value="" placeholder="DNS server IP"
|
||||||
style="padding: 12px; background: var(--card-bg); color: var(--fg); border: 1px solid var(--border); border-radius: 6px; font-size: 1rem;" />
|
style="padding: 12px; background: var(--card-bg); color: var(--fg); border: 1px solid var(--border); border-radius: 6px; font-size: 1rem;" />
|
||||||
@@ -406,7 +415,7 @@
|
|||||||
<!-- DNS Admin Token -->
|
<!-- DNS Admin Token -->
|
||||||
<div>
|
<div>
|
||||||
<label class="form-label-accent">
|
<label class="form-label-accent">
|
||||||
🔑 Technitium Admin Token
|
🔑 DNS Admin Token / API Key
|
||||||
</label>
|
</label>
|
||||||
<input type="password" id="setup-dns-token" placeholder="Paste your admin token here"
|
<input type="password" id="setup-dns-token" placeholder="Paste your admin token here"
|
||||||
class="form-input-lg" />
|
class="form-input-lg" />
|
||||||
|
|||||||
@@ -41,8 +41,11 @@
|
|||||||
dismissedUpdates = new Set();
|
dismissedUpdates = new Set();
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Track global update state for cross-component access
|
||||||
|
let knownUpdates = [];
|
||||||
|
|
||||||
// Fetch update data and show badges
|
// Fetch update data and show badges
|
||||||
async function refreshCardUpdates() {
|
async function refreshCardUpdates(notifyNew) {
|
||||||
try {
|
try {
|
||||||
const res = await fetch('/api/v1/updates/available');
|
const res = await fetch('/api/v1/updates/available');
|
||||||
const data = await res.json();
|
const data = await res.json();
|
||||||
@@ -51,9 +54,21 @@
|
|||||||
// Clear all update badges first
|
// Clear all update badges first
|
||||||
document.querySelectorAll('.update-available-badge').forEach(el => el.classList.remove('visible'));
|
document.querySelectorAll('.update-available-badge').forEach(el => el.classList.remove('visible'));
|
||||||
|
|
||||||
if (!data.updates?.length) return;
|
const updates = data.updates || [];
|
||||||
|
knownUpdates = updates; // store globally
|
||||||
|
|
||||||
for (const upd of data.updates) {
|
// Notify if new updates appeared (periodic check with notification)
|
||||||
|
if (notifyNew && updates.length > 0) {
|
||||||
|
const prev = window._lastKnownUpdateCount || 0;
|
||||||
|
if (prev > 0 && updates.length > prev) {
|
||||||
|
showNotification(`${updates.length} container update(s) available — click Update Management to review.`, 'info');
|
||||||
|
}
|
||||||
|
window._lastKnownUpdateCount = updates.length;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!updates.length) return;
|
||||||
|
|
||||||
|
for (const upd of updates) {
|
||||||
// Try to match by container name to service id
|
// Try to match by container name to service id
|
||||||
const apps = window.APPS || [];
|
const apps = window.APPS || [];
|
||||||
for (const app of apps) {
|
for (const app of apps) {
|
||||||
@@ -61,17 +76,24 @@
|
|||||||
// Skip dismissed updates
|
// Skip dismissed updates
|
||||||
if (dismissedUpdates.has(app.id)) break;
|
if (dismissedUpdates.has(app.id)) break;
|
||||||
const badge = document.getElementById('update-badge-' + app.id);
|
const badge = document.getElementById('update-badge-' + app.id);
|
||||||
|
const updateBtn = document.getElementById('update-btn-' + app.id);
|
||||||
if (badge) {
|
if (badge) {
|
||||||
badge.classList.add('visible');
|
badge.classList.add('visible');
|
||||||
badge.title = `Image digest changed. Click to dismiss if already up to date.\n${upd.imageName || ''}`;
|
badge.title = `Update available — click to open Update Management.`;
|
||||||
badge.style.cursor = 'pointer';
|
badge.style.cursor = 'pointer';
|
||||||
badge.onclick = (e) => {
|
badge.onclick = (e) => {
|
||||||
e.stopPropagation();
|
e.stopPropagation();
|
||||||
badge.classList.remove('visible');
|
// Open Update Management modal focused on this app
|
||||||
dismissedUpdates.add(app.id);
|
if (window.openUpdateModal) window.openUpdateModal(app.id);
|
||||||
safeSessionSet('dismissed-updates', JSON.stringify([...dismissedUpdates]));
|
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
// Highlight update button if update is available
|
||||||
|
if (updateBtn) {
|
||||||
|
updateBtn.style.background = '#f97316';
|
||||||
|
updateBtn.style.borderColor = '#f97316';
|
||||||
|
updateBtn.style.boxShadow = '0 0 6px #f9731688';
|
||||||
|
updateBtn.title = `Update available — click to open Update Management.`;
|
||||||
|
}
|
||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -90,10 +112,10 @@
|
|||||||
refreshCardUpdates();
|
refreshCardUpdates();
|
||||||
}, 5000);
|
}, 5000);
|
||||||
|
|
||||||
// Periodic refresh every 60 seconds
|
// Periodic refresh every 60 seconds — notify on new updates detected
|
||||||
setInterval(() => {
|
setInterval(() => {
|
||||||
refreshCardHealth();
|
refreshCardHealth();
|
||||||
refreshCardUpdates();
|
refreshCardUpdates(true); // true = notify if new updates found
|
||||||
}, 60000);
|
}, 60000);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -95,6 +95,8 @@
|
|||||||
const card = el('div', 'card');
|
const card = el('div', 'card');
|
||||||
card.setAttribute('data-app', s.id);
|
card.setAttribute('data-app', s.id);
|
||||||
card.setAttribute('data-status', 'off'); // Initial status
|
card.setAttribute('data-status', 'off'); // Initial status
|
||||||
|
if (s.containerId) card.setAttribute('data-container-id', s.containerId);
|
||||||
|
if (s.category) card.setAttribute('data-category', s.category);
|
||||||
if (s.recipeId) card.setAttribute('data-recipe-id', s.recipeId);
|
if (s.recipeId) card.setAttribute('data-recipe-id', s.recipeId);
|
||||||
|
|
||||||
const dot = el('span', 'dot bad at-bl'); dot.id = 'dot-' + s.id + '-grid'; card.appendChild(dot);
|
const dot = el('span', 'dot bad at-bl'); dot.id = 'dot-' + s.id + '-grid'; card.appendChild(dot);
|
||||||
@@ -156,6 +158,16 @@
|
|||||||
nameSpan.appendChild(tsBadge);
|
nameSpan.appendChild(tsBadge);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Add Category badge if service has one (colored pill with icon)
|
||||||
|
if (s.category) {
|
||||||
|
const cats = (typeof DC !== 'undefined' && DC.CATEGORIES) || window.DC_CATEGORIES || {};
|
||||||
|
const catInfo = cats[s.category] || {};
|
||||||
|
const catBadge = el('span', 'cat-badge', `${catInfo.icon || ''} ${s.category}`.trim());
|
||||||
|
catBadge.title = `Category: ${s.category}`;
|
||||||
|
catBadge.style.cssText = `margin-left: 6px; font-size: 0.65rem; padding: 1px 6px; border-radius: 999px; background: color-mix(in srgb, ${catInfo.color || '#7f8c8d'} 25%, transparent); color: ${catInfo.color || '#7f8c8d'}; border: 1px solid color-mix(in srgb, ${catInfo.color || '#7f8c8d'} 50%, transparent); white-space: nowrap; font-weight: 500;`;
|
||||||
|
nameSpan.appendChild(catBadge);
|
||||||
|
}
|
||||||
|
|
||||||
row.appendChild(el('span', 'spacer'));
|
row.appendChild(el('span', 'spacer'));
|
||||||
|
|
||||||
const pill = el('span', 'badge off', 'OFF'); pill.id = 'badge-' + s.id; row.appendChild(pill);
|
const pill = el('span', 'badge off', 'OFF'); pill.id = 'badge-' + s.id; row.appendChild(pill);
|
||||||
@@ -282,6 +294,9 @@
|
|||||||
|
|
||||||
// Group recipe cards visually after grid is built
|
// Group recipe cards visually after grid is built
|
||||||
if (window.groupRecipeCards) requestAnimationFrame(() => window.groupRecipeCards());
|
if (window.groupRecipeCards) requestAnimationFrame(() => window.groupRecipeCards());
|
||||||
|
|
||||||
|
// Refresh the service filter so the category dropdown reflects new services
|
||||||
|
if (window.refreshServiceFilter) window.refreshServiceFilter();
|
||||||
}
|
}
|
||||||
|
|
||||||
function setBadge(id, up, responseTime = null) {
|
function setBadge(id, up, responseTime = null) {
|
||||||
|
|||||||
@@ -59,11 +59,13 @@
|
|||||||
}
|
}
|
||||||
_dashboardInitialized = true;
|
_dashboardInitialized = true;
|
||||||
await window.loadServices();
|
await window.loadServices();
|
||||||
|
await loadTemplateCategories();
|
||||||
window.buildGrid();
|
window.buildGrid();
|
||||||
animateTopCards();
|
animateTopCards();
|
||||||
window.refreshAll();
|
window.refreshAll();
|
||||||
setInterval(window.refreshAll, DC.POLL.DASHBOARD);
|
setInterval(window.refreshAll, DC.POLL.DASHBOARD);
|
||||||
if (typeof window.refreshCredsButtons === 'function') window.refreshCredsButtons();
|
if (typeof window.refreshCredsButtons === 'function') window.refreshCredsButtons();
|
||||||
|
if (typeof window.refreshMonitoringWidgets === 'function') window.refreshMonitoringWidgets();
|
||||||
// Update auth card (may have already been updated by the auto-load IIFE but ensure it's correct)
|
// Update auth card (may have already been updated by the auto-load IIFE but ensure it's correct)
|
||||||
if (typeof window._updateAuthCard === 'function') {
|
if (typeof window._updateAuthCard === 'function') {
|
||||||
try {
|
try {
|
||||||
@@ -200,6 +202,55 @@
|
|||||||
window.loadCustomServices = loadCustomServices;
|
window.loadCustomServices = loadCustomServices;
|
||||||
registerServiceWorker();
|
registerServiceWorker();
|
||||||
|
|
||||||
|
// ===== TEMPLATE CATEGORIES =====
|
||||||
|
// Cached template categories from /api/v1/templates for use across the UI
|
||||||
|
// (service create/edit, filter dropdown, category badges, etc.)
|
||||||
|
async function loadTemplateCategories() {
|
||||||
|
try {
|
||||||
|
const r = await fetch('/api/v1/templates', { cache: 'no-store' });
|
||||||
|
if (!r.ok) return;
|
||||||
|
const data = await r.json();
|
||||||
|
if (data && data.categories) {
|
||||||
|
window.DC_CATEGORIES = data.categories;
|
||||||
|
// Also expose via globals.js constant for convenience
|
||||||
|
if (typeof DC !== 'undefined') DC.CATEGORIES = data.categories;
|
||||||
|
// Populate any category <select> that's already in the DOM
|
||||||
|
populateCategorySelects();
|
||||||
|
}
|
||||||
|
} catch (e) {
|
||||||
|
console.warn('[init] Failed to load template categories:', e);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
function populateCategorySelects() {
|
||||||
|
const cats = window.DC_CATEGORIES || (typeof DC !== 'undefined' && DC.CATEGORIES);
|
||||||
|
if (!cats) return;
|
||||||
|
document.querySelectorAll('select[data-role="service-category"]').forEach(select => {
|
||||||
|
const current = select.dataset.current || '';
|
||||||
|
// Clear options but keep the first (placeholder)
|
||||||
|
const placeholder = select.querySelector('option[value=""]');
|
||||||
|
select.innerHTML = '';
|
||||||
|
if (placeholder) select.appendChild(placeholder);
|
||||||
|
else {
|
||||||
|
const ph = document.createElement('option');
|
||||||
|
ph.value = '';
|
||||||
|
ph.textContent = '— Select category —';
|
||||||
|
select.appendChild(ph);
|
||||||
|
}
|
||||||
|
Object.entries(cats).forEach(([name, info]) => {
|
||||||
|
const opt = document.createElement('option');
|
||||||
|
opt.value = name;
|
||||||
|
opt.textContent = `${info.icon || ''} ${name}`.trim();
|
||||||
|
if (name === current) opt.selected = true;
|
||||||
|
select.appendChild(opt);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
// Allow other modules to re-run population after they (re)inject selects
|
||||||
|
window.populateCategorySelects = populateCategorySelects;
|
||||||
|
window.loadTemplateCategories = loadTemplateCategories;
|
||||||
|
|
||||||
// TOTP-gated initialization
|
// TOTP-gated initialization
|
||||||
(async () => {
|
(async () => {
|
||||||
try {
|
try {
|
||||||
|
|||||||
@@ -262,6 +262,7 @@
|
|||||||
const proxyIp = document.getElementById('external-proxy-ip').value.trim() || SITE.dnsIp || 'localhost';
|
const proxyIp = document.getElementById('external-proxy-ip').value.trim() || SITE.dnsIp || 'localhost';
|
||||||
const preserveHost = document.getElementById('external-preserve-host').checked;
|
const preserveHost = document.getElementById('external-preserve-host').checked;
|
||||||
const followRedirects = document.getElementById('external-follow-redirects').checked;
|
const followRedirects = document.getElementById('external-follow-redirects').checked;
|
||||||
|
const category = document.getElementById('external-service-category')?.value || '';
|
||||||
|
|
||||||
if (!name || !externalUrl) {
|
if (!name || !externalUrl) {
|
||||||
showNotification('Please fill in Name and External URL', 'warning');
|
showNotification('Please fill in Name and External URL', 'warning');
|
||||||
@@ -341,6 +342,8 @@
|
|||||||
isExternal: true,
|
isExternal: true,
|
||||||
isCustom: true
|
isCustom: true
|
||||||
};
|
};
|
||||||
|
// Only attach category if user actually picked one
|
||||||
|
if (category) newService.category = category;
|
||||||
|
|
||||||
window.APPS.push(newService);
|
window.APPS.push(newService);
|
||||||
results.dashboard = true;
|
results.dashboard = true;
|
||||||
@@ -457,6 +460,13 @@
|
|||||||
const healthCheck = document.getElementById('health-check-input')?.value || '';
|
const healthCheck = document.getElementById('health-check-input')?.value || '';
|
||||||
const timeout = document.getElementById('timeout-input')?.value || 30;
|
const timeout = document.getElementById('timeout-input')?.value || 30;
|
||||||
|
|
||||||
|
// Category is optional — pulled from either local or external select by the
|
||||||
|
// openAddServiceModal reset. If user doesn't choose one, it stays undefined
|
||||||
|
// and we don't send it (so the backend keeps the existing behavior).
|
||||||
|
const categoryEl = document.getElementById('service-category-input')
|
||||||
|
|| document.getElementById('external-service-category');
|
||||||
|
const category = categoryEl?.value || '';
|
||||||
|
|
||||||
const dnsToken = window.getToken(getPrimaryDnsId(), 'admin');
|
const dnsToken = window.getToken(getPrimaryDnsId(), 'admin');
|
||||||
|
|
||||||
if (!name || !port || !ip) {
|
if (!name || !port || !ip) {
|
||||||
@@ -525,6 +535,8 @@
|
|||||||
logo: logo || `/assets/${subdomain}.png`,
|
logo: logo || `/assets/${subdomain}.png`,
|
||||||
tailscaleOnly: tailscaleOnly || false
|
tailscaleOnly: tailscaleOnly || false
|
||||||
};
|
};
|
||||||
|
// Only include category if user actually picked one
|
||||||
|
if (category) serviceConfig.category = category;
|
||||||
|
|
||||||
await window.addServiceToConfig(serviceConfig);
|
await window.addServiceToConfig(serviceConfig);
|
||||||
results.dashboard = true;
|
results.dashboard = true;
|
||||||
|
|||||||
@@ -19,6 +19,16 @@
|
|||||||
document.getElementById('edit-tailscale-only').checked = service.tailscaleOnly || false;
|
document.getElementById('edit-tailscale-only').checked = service.tailscaleOnly || false;
|
||||||
document.getElementById('edit-logo-url').value = service.logo || '';
|
document.getElementById('edit-logo-url').value = service.logo || '';
|
||||||
|
|
||||||
|
// Populate the category select for this service, then set the current value.
|
||||||
|
// populateCategorySelects() uses data-current so we set it first, then call.
|
||||||
|
const categorySelect = document.getElementById('edit-service-category');
|
||||||
|
if (categorySelect) {
|
||||||
|
categorySelect.dataset.current = service.category || '';
|
||||||
|
if (typeof window.populateCategorySelects === 'function') {
|
||||||
|
window.populateCategorySelects();
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
modal.classList.add('show');
|
modal.classList.add('show');
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -36,6 +46,7 @@
|
|||||||
const newIp = document.getElementById('edit-ip').value.trim() || 'localhost';
|
const newIp = document.getElementById('edit-ip').value.trim() || 'localhost';
|
||||||
const tailscaleOnly = document.getElementById('edit-tailscale-only').checked;
|
const tailscaleOnly = document.getElementById('edit-tailscale-only').checked;
|
||||||
const newLogo = document.getElementById('edit-logo-url').value.trim();
|
const newLogo = document.getElementById('edit-logo-url').value.trim();
|
||||||
|
const newCategory = document.getElementById('edit-service-category')?.value || '';
|
||||||
|
|
||||||
if (!newSubdomain) {
|
if (!newSubdomain) {
|
||||||
showNotification('Subdomain is required', 'warning');
|
showNotification('Subdomain is required', 'warning');
|
||||||
@@ -51,6 +62,7 @@
|
|||||||
if (newIp !== currentEditService.ip) changes.push('ip');
|
if (newIp !== currentEditService.ip) changes.push('ip');
|
||||||
if (tailscaleOnly !== (currentEditService.tailscaleOnly || false)) changes.push('tailscale');
|
if (tailscaleOnly !== (currentEditService.tailscaleOnly || false)) changes.push('tailscale');
|
||||||
if (newLogo && newLogo !== currentEditService.logo) changes.push('logo');
|
if (newLogo && newLogo !== currentEditService.logo) changes.push('logo');
|
||||||
|
if (newCategory !== (currentEditService.category || '')) changes.push('category');
|
||||||
|
|
||||||
if (changes.length === 0) {
|
if (changes.length === 0) {
|
||||||
closeServiceEditModal();
|
closeServiceEditModal();
|
||||||
@@ -72,7 +84,8 @@
|
|||||||
port: newPort || currentEditService.port,
|
port: newPort || currentEditService.port,
|
||||||
ip: newIp,
|
ip: newIp,
|
||||||
tailscaleOnly,
|
tailscaleOnly,
|
||||||
logo: newLogo || undefined
|
logo: newLogo || undefined,
|
||||||
|
category: newCategory
|
||||||
})
|
})
|
||||||
});
|
});
|
||||||
|
|
||||||
@@ -91,7 +104,8 @@
|
|||||||
port: newPort || window.APPS[appIndex].port,
|
port: newPort || window.APPS[appIndex].port,
|
||||||
ip: newIp,
|
ip: newIp,
|
||||||
tailscaleOnly,
|
tailscaleOnly,
|
||||||
logo: newLogo || window.APPS[appIndex].logo
|
logo: newLogo || window.APPS[appIndex].logo,
|
||||||
|
category: newCategory || undefined
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -187,6 +187,9 @@
|
|||||||
name: serviceConfig.name,
|
name: serviceConfig.name,
|
||||||
logo: serviceConfig.logo || `/assets/${serviceConfig.subdomain}.png`
|
logo: serviceConfig.logo || `/assets/${serviceConfig.subdomain}.png`
|
||||||
};
|
};
|
||||||
|
// Forward optional metadata fields if provided
|
||||||
|
if (serviceConfig.category) newService.category = serviceConfig.category;
|
||||||
|
if (serviceConfig.containerId) newService.containerId = serviceConfig.containerId;
|
||||||
|
|
||||||
try {
|
try {
|
||||||
const response = await secureFetch('/api/v1/services', {
|
const response = await secureFetch('/api/v1/services', {
|
||||||
|
|||||||
@@ -82,6 +82,16 @@
|
|||||||
Enter a URL or upload an image file (PNG, JPG, SVG)
|
Enter a URL or upload an image file (PNG, JPG, SVG)
|
||||||
</div>
|
</div>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
|
<!-- Category -->
|
||||||
|
<div>
|
||||||
|
<label for="edit-service-category" class="form-label-accent-sm">
|
||||||
|
Category
|
||||||
|
</label>
|
||||||
|
<select id="edit-service-category" data-role="service-category" class="form-input-md">
|
||||||
|
<option value="">— No category —</option>
|
||||||
|
</select>
|
||||||
|
</div>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
<div class="weather-modal-buttons" style="margin-top: 24px;">
|
<div class="weather-modal-buttons" style="margin-top: 24px;">
|
||||||
@@ -239,6 +249,15 @@
|
|||||||
Reload Caddy after adding
|
Reload Caddy after adding
|
||||||
</label>
|
</label>
|
||||||
|
|
||||||
|
<!-- Category -->
|
||||||
|
<div>
|
||||||
|
<label for="service-category-input" style="font-size: 0.8rem; color: var(--muted); margin-bottom: 4px; display: block;">Category</label>
|
||||||
|
<select id="service-category-input" data-role="service-category" style="width: 100%;">
|
||||||
|
<option value="">— No category —</option>
|
||||||
|
</select>
|
||||||
|
<div style="font-size: 0.7rem; color: var(--muted); margin-top: 3px;">Group services on the dashboard by purpose (Media, Productivity, etc.)</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
<hr style="border: none; border-top: 1px solid var(--border); margin: 4px 0;" />
|
<hr style="border: none; border-top: 1px solid var(--border); margin: 4px 0;" />
|
||||||
|
|
||||||
<div class="grid-2col">
|
<div class="grid-2col">
|
||||||
@@ -326,6 +345,14 @@
|
|||||||
Follow Redirects
|
Follow Redirects
|
||||||
</label>
|
</label>
|
||||||
|
|
||||||
|
<!-- Category (external) -->
|
||||||
|
<div>
|
||||||
|
<label for="external-service-category" style="font-size: 0.8rem; color: var(--muted); margin-bottom: 4px; display: block;">Category</label>
|
||||||
|
<select id="external-service-category" data-role="service-category" style="width: 100%;">
|
||||||
|
<option value="">— No category —</option>
|
||||||
|
</select>
|
||||||
|
</div>
|
||||||
|
|
||||||
</div>
|
</div>
|
||||||
</details>
|
</details>
|
||||||
</div>
|
</div>
|
||||||
|
|||||||
@@ -95,6 +95,36 @@
|
|||||||
'Prometheus metrics'
|
'Prometheus metrics'
|
||||||
],
|
],
|
||||||
recommended: false
|
recommended: false
|
||||||
|
},
|
||||||
|
{
|
||||||
|
id: 'cloudflare',
|
||||||
|
name: 'Cloudflare DNS',
|
||||||
|
description: 'Managed DNS with API access — no self-hosting needed',
|
||||||
|
icon: '🔶',
|
||||||
|
difficulty: 'Easy',
|
||||||
|
features: [
|
||||||
|
'Fully managed, no server needed',
|
||||||
|
'API for automated record management',
|
||||||
|
'Global anycast network',
|
||||||
|
'Free tier available'
|
||||||
|
],
|
||||||
|
recommended: false,
|
||||||
|
providerId: 'cloudflare'
|
||||||
|
},
|
||||||
|
{
|
||||||
|
id: 'external',
|
||||||
|
name: 'External / Manual DNS',
|
||||||
|
description: 'Use your own DNS provider (cPanel, Route53, etc.)',
|
||||||
|
icon: '🔗',
|
||||||
|
difficulty: 'Easy',
|
||||||
|
features: [
|
||||||
|
'Works with any DNS provider',
|
||||||
|
'DashCaddy shows you what records to create',
|
||||||
|
'Propagation checking still works',
|
||||||
|
'No API credentials needed'
|
||||||
|
],
|
||||||
|
recommended: false,
|
||||||
|
providerId: 'manual'
|
||||||
}
|
}
|
||||||
];
|
];
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,304 @@
|
|||||||
|
// ========== MONITORING WIDGETS ==========
|
||||||
|
// Embeds a compact system-resource + health summary panel directly on the
|
||||||
|
// main dashboard. Replaces the need for a separate monitoring-dashboard.html
|
||||||
|
// page — quick at-a-glance stats where you already are.
|
||||||
|
(function () {
|
||||||
|
|
||||||
|
// ----- Style injection (scoped to .dc-monitor so it doesn't leak) -----
|
||||||
|
const styleEl = document.createElement('style');
|
||||||
|
styleEl.textContent = `
|
||||||
|
.dc-monitor {
|
||||||
|
display: grid;
|
||||||
|
grid-template-columns: repeat(auto-fit, minmax(220px, 1fr));
|
||||||
|
gap: 12px;
|
||||||
|
margin-bottom: 16px;
|
||||||
|
padding: 12px 16px;
|
||||||
|
background: var(--card-base);
|
||||||
|
border: 1px solid var(--border);
|
||||||
|
border-radius: var(--radius);
|
||||||
|
}
|
||||||
|
.dc-monitor-card {
|
||||||
|
padding: 10px 12px;
|
||||||
|
background: var(--card-bg, rgba(255,255,255,0.04));
|
||||||
|
border-radius: 8px;
|
||||||
|
border: 1px solid var(--border);
|
||||||
|
}
|
||||||
|
.dc-monitor-label {
|
||||||
|
font-size: 0.7rem;
|
||||||
|
color: var(--muted);
|
||||||
|
text-transform: uppercase;
|
||||||
|
letter-spacing: 0.5px;
|
||||||
|
margin-bottom: 4px;
|
||||||
|
}
|
||||||
|
.dc-monitor-value {
|
||||||
|
font-size: 1.4rem;
|
||||||
|
font-weight: 600;
|
||||||
|
color: var(--fg);
|
||||||
|
}
|
||||||
|
.dc-monitor-sub {
|
||||||
|
font-size: 0.7rem;
|
||||||
|
color: var(--muted);
|
||||||
|
margin-top: 4px;
|
||||||
|
}
|
||||||
|
.dc-monitor-bar {
|
||||||
|
margin-top: 6px;
|
||||||
|
width: 100%;
|
||||||
|
height: 4px;
|
||||||
|
background: color-mix(in srgb, var(--muted) 20%, transparent);
|
||||||
|
border-radius: 2px;
|
||||||
|
overflow: hidden;
|
||||||
|
}
|
||||||
|
.dc-monitor-bar-fill {
|
||||||
|
height: 100%;
|
||||||
|
width: 0%;
|
||||||
|
background: var(--ok-fg, #27ae60);
|
||||||
|
transition: width 0.3s ease, background 0.3s ease;
|
||||||
|
}
|
||||||
|
.dc-monitor-bar-fill.warn { background: #f39c12; }
|
||||||
|
.dc-monitor-bar-fill.bad { background: #e74c3c; }
|
||||||
|
.dc-monitor-header {
|
||||||
|
display: flex;
|
||||||
|
align-items: center;
|
||||||
|
justify-content: space-between;
|
||||||
|
margin-bottom: 8px;
|
||||||
|
}
|
||||||
|
.dc-monitor-title {
|
||||||
|
font-size: 0.85rem;
|
||||||
|
font-weight: 500;
|
||||||
|
color: var(--muted);
|
||||||
|
display: flex;
|
||||||
|
align-items: center;
|
||||||
|
gap: 6px;
|
||||||
|
}
|
||||||
|
.dc-monitor-pill {
|
||||||
|
display: inline-flex;
|
||||||
|
align-items: center;
|
||||||
|
gap: 4px;
|
||||||
|
padding: 2px 8px;
|
||||||
|
border-radius: 999px;
|
||||||
|
font-size: 0.7rem;
|
||||||
|
font-weight: 500;
|
||||||
|
}
|
||||||
|
.dc-monitor-pill.ok { background: color-mix(in srgb, #27ae60 20%, transparent); color: #27ae60; }
|
||||||
|
.dc-monitor-pill.warn { background: color-mix(in srgb, #f39c12 20%, transparent); color: #f39c12; }
|
||||||
|
.dc-monitor-pill.bad { background: color-mix(in srgb, #e74c3c 20%, transparent); color: #e74c3c; }
|
||||||
|
.dc-monitor-refresh {
|
||||||
|
font-size: 0.7rem;
|
||||||
|
color: var(--muted);
|
||||||
|
opacity: 0.7;
|
||||||
|
}
|
||||||
|
`;
|
||||||
|
document.head.appendChild(styleEl);
|
||||||
|
|
||||||
|
// ----- Container element (inserted above service-filter-bar) -----
|
||||||
|
const filterBar = document.getElementById('service-filter-bar');
|
||||||
|
if (!filterBar) return;
|
||||||
|
|
||||||
|
const panel = document.createElement('div');
|
||||||
|
panel.className = 'dc-monitor';
|
||||||
|
panel.id = 'dc-monitor-panel';
|
||||||
|
panel.innerHTML = `
|
||||||
|
<div class="dc-monitor-header" style="grid-column: 1 / -1;">
|
||||||
|
<div class="dc-monitor-title">📊 System Overview</div>
|
||||||
|
<span class="dc-monitor-refresh" id="dc-monitor-refresh-stamp">—</span>
|
||||||
|
</div>
|
||||||
|
<div class="dc-monitor-card">
|
||||||
|
<div class="dc-monitor-label">Services</div>
|
||||||
|
<div class="dc-monitor-value" id="dc-monitor-services">—</div>
|
||||||
|
<div class="dc-monitor-sub" id="dc-monitor-services-sub">loading…</div>
|
||||||
|
</div>
|
||||||
|
<div class="dc-monitor-card">
|
||||||
|
<div class="dc-monitor-label">Containers Up</div>
|
||||||
|
<div class="dc-monitor-value" id="dc-monitor-containers">—</div>
|
||||||
|
<div class="dc-monitor-sub" id="dc-monitor-containers-sub">loading…</div>
|
||||||
|
</div>
|
||||||
|
<div class="dc-monitor-card">
|
||||||
|
<div class="dc-monitor-label">Avg CPU</div>
|
||||||
|
<div class="dc-monitor-value" id="dc-monitor-cpu">—</div>
|
||||||
|
<div class="dc-monitor-bar"><div class="dc-monitor-bar-fill" id="dc-monitor-cpu-bar"></div></div>
|
||||||
|
</div>
|
||||||
|
<div class="dc-monitor-card">
|
||||||
|
<div class="dc-monitor-label">Avg Memory</div>
|
||||||
|
<div class="dc-monitor-value" id="dc-monitor-mem">—</div>
|
||||||
|
<div class="dc-monitor-bar"><div class="dc-monitor-bar-fill" id="dc-monitor-mem-bar"></div></div>
|
||||||
|
</div>
|
||||||
|
<div class="dc-monitor-card">
|
||||||
|
<div class="dc-monitor-label">Health</div>
|
||||||
|
<div class="dc-monitor-value" id="dc-monitor-health">—</div>
|
||||||
|
<div class="dc-monitor-sub" id="dc-monitor-health-sub">—</div>
|
||||||
|
</div>
|
||||||
|
`;
|
||||||
|
// Insert ABOVE the filter bar
|
||||||
|
filterBar.parentNode.insertBefore(panel, filterBar);
|
||||||
|
|
||||||
|
// ----- Helpers -----
|
||||||
|
function setBar(id, pct) {
|
||||||
|
const el = document.getElementById(id);
|
||||||
|
if (!el) return;
|
||||||
|
const p = Math.max(0, Math.min(100, Number(pct) || 0));
|
||||||
|
el.style.width = p + '%';
|
||||||
|
el.classList.remove('warn', 'bad');
|
||||||
|
if (p >= 85) el.classList.add('bad');
|
||||||
|
else if (p >= 65) el.classList.add('warn');
|
||||||
|
}
|
||||||
|
|
||||||
|
function fmtPct(v) {
|
||||||
|
if (v == null || isNaN(v)) return '—';
|
||||||
|
return (Math.round(v * 10) / 10) + '%';
|
||||||
|
}
|
||||||
|
|
||||||
|
function fmtBytes(b) {
|
||||||
|
if (b == null || isNaN(b)) return '—';
|
||||||
|
const units = ['B', 'KB', 'MB', 'GB', 'TB'];
|
||||||
|
let i = 0;
|
||||||
|
while (b >= 1024 && i < units.length - 1) { b /= 1024; i++; }
|
||||||
|
return b.toFixed(1) + ' ' + units[i];
|
||||||
|
}
|
||||||
|
|
||||||
|
function setServicesCard() {
|
||||||
|
const total = (window.APPS || []).length;
|
||||||
|
let up = 0;
|
||||||
|
document.querySelectorAll('#cards .card').forEach(c => {
|
||||||
|
if (c.dataset.status === 'on') up++;
|
||||||
|
});
|
||||||
|
const el = document.getElementById('dc-monitor-services');
|
||||||
|
const sub = document.getElementById('dc-monitor-services-sub');
|
||||||
|
if (el) el.textContent = `${up} / ${total}`;
|
||||||
|
if (sub) sub.textContent = total === 0 ? 'no services yet' : `${up} online · ${total - up} offline`;
|
||||||
|
}
|
||||||
|
|
||||||
|
function applyHealthSummary(data) {
|
||||||
|
const el = document.getElementById('dc-monitor-health');
|
||||||
|
const sub = document.getElementById('dc-monitor-health-sub');
|
||||||
|
if (!el) return;
|
||||||
|
if (!data || data.summary == null) {
|
||||||
|
el.textContent = '—';
|
||||||
|
if (sub) sub.textContent = 'no data';
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
const s = data.summary;
|
||||||
|
const healthy = s.healthy ?? s.up ?? 0;
|
||||||
|
const unhealthy = s.unhealthy ?? s.down ?? 0;
|
||||||
|
const total = s.total ?? (healthy + unhealthy);
|
||||||
|
el.textContent = `${healthy}/${total}`;
|
||||||
|
if (sub) {
|
||||||
|
if (unhealthy === 0) {
|
||||||
|
sub.innerHTML = '<span class="dc-monitor-pill ok">● all healthy</span>';
|
||||||
|
} else if (unhealthy <= 2) {
|
||||||
|
sub.innerHTML = `<span class="dc-monitor-pill warn">● ${unhealthy} degraded</span>`;
|
||||||
|
} else {
|
||||||
|
sub.innerHTML = `<span class="dc-monitor-pill bad">● ${unhealthy} down</span>`;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// ----- Data fetches -----
|
||||||
|
async function fetchStats() {
|
||||||
|
try {
|
||||||
|
const r = await fetch('/api/v1/monitoring/stats', { cache: 'no-store' });
|
||||||
|
if (!r.ok) return null;
|
||||||
|
const data = await r.json();
|
||||||
|
return (data && data.stats) ? data.stats : null;
|
||||||
|
} catch (_) {
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
async function fetchHealth() {
|
||||||
|
try {
|
||||||
|
const r = await fetch('/api/v1/health-checks/status', { cache: 'no-store' });
|
||||||
|
if (!r.ok) return null;
|
||||||
|
return await r.json();
|
||||||
|
} catch (_) {
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
function applyStats(stats) {
|
||||||
|
const containers = document.getElementById('dc-monitor-containers');
|
||||||
|
const containersSub = document.getElementById('dc-monitor-containers-sub');
|
||||||
|
const cpuEl = document.getElementById('dc-monitor-cpu');
|
||||||
|
const memEl = document.getElementById('dc-monitor-mem');
|
||||||
|
|
||||||
|
if (!stats) {
|
||||||
|
if (containers) containers.textContent = '—';
|
||||||
|
if (cpuEl) cpuEl.textContent = '—';
|
||||||
|
if (memEl) memEl.textContent = '—';
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
const entries = Object.values(stats);
|
||||||
|
if (entries.length === 0) {
|
||||||
|
if (containers) containers.textContent = '0';
|
||||||
|
if (containersSub) containersSub.textContent = 'no containers reporting';
|
||||||
|
if (cpuEl) cpuEl.textContent = '0%';
|
||||||
|
if (memEl) memEl.textContent = '0%';
|
||||||
|
setBar('dc-monitor-cpu-bar', 0);
|
||||||
|
setBar('dc-monitor-mem-bar', 0);
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
let cpuSum = 0, memSum = 0, memBytes = 0, cpuCount = 0, memCount = 0;
|
||||||
|
entries.forEach(s => {
|
||||||
|
// CPU may be percentage (0-100) or fraction (0-1) — handle both
|
||||||
|
if (s.cpu != null) {
|
||||||
|
const cpu = Number(s.cpu);
|
||||||
|
if (!isNaN(cpu)) {
|
||||||
|
cpuSum += cpu > 1 ? cpu : cpu * 100;
|
||||||
|
cpuCount++;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if (s.memory != null) {
|
||||||
|
const mem = Number(s.memory);
|
||||||
|
if (!isNaN(mem)) {
|
||||||
|
memSum += mem;
|
||||||
|
memBytes += Number(s.memoryUsage || 0);
|
||||||
|
memCount++;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
const avgCpu = cpuCount ? cpuSum / cpuCount : 0;
|
||||||
|
const avgMem = memCount ? memSum / memCount : 0;
|
||||||
|
|
||||||
|
if (containers) containers.textContent = String(entries.length);
|
||||||
|
if (containersSub) {
|
||||||
|
const memTxt = memBytes ? ` · ${fmtBytes(memBytes)} RAM` : '';
|
||||||
|
containersSub.textContent = `running${memTxt}`;
|
||||||
|
}
|
||||||
|
if (cpuEl) cpuEl.textContent = fmtPct(avgCpu);
|
||||||
|
if (memEl) memEl.textContent = fmtPct(avgMem);
|
||||||
|
setBar('dc-monitor-cpu-bar', avgCpu);
|
||||||
|
setBar('dc-monitor-mem-bar', avgMem);
|
||||||
|
}
|
||||||
|
|
||||||
|
// ----- Public refresh function -----
|
||||||
|
let inFlight = false;
|
||||||
|
async function refresh() {
|
||||||
|
if (inFlight) return;
|
||||||
|
inFlight = true;
|
||||||
|
try {
|
||||||
|
setServicesCard();
|
||||||
|
const [stats, health] = await Promise.all([fetchStats(), fetchHealth()]);
|
||||||
|
applyStats(stats);
|
||||||
|
applyHealthSummary(health);
|
||||||
|
const stamp = document.getElementById('dc-monitor-refresh-stamp');
|
||||||
|
if (stamp) {
|
||||||
|
const now = new Date();
|
||||||
|
stamp.textContent = `updated ${now.toLocaleTimeString()}`;
|
||||||
|
}
|
||||||
|
} finally {
|
||||||
|
inFlight = false;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// Expose for init.js to call once and re-call after each refreshAll cycle
|
||||||
|
window.refreshMonitoringWidgets = refresh;
|
||||||
|
|
||||||
|
// Auto-refresh on the STATS interval (separate from full DASHBOARD refresh)
|
||||||
|
setInterval(refresh, (typeof DC !== 'undefined' && DC.POLL && DC.POLL.STATS) || 5000);
|
||||||
|
|
||||||
|
// Refresh once on first script load (init.js also calls this; double-call is harmless)
|
||||||
|
setTimeout(refresh, 200);
|
||||||
|
|
||||||
|
})();
|
||||||
@@ -2,11 +2,50 @@
|
|||||||
(function() {
|
(function() {
|
||||||
const searchInput = document.getElementById('service-filter-search');
|
const searchInput = document.getElementById('service-filter-search');
|
||||||
const statusSelect = document.getElementById('service-filter-status');
|
const statusSelect = document.getElementById('service-filter-status');
|
||||||
|
const categorySelect = document.getElementById('service-filter-category');
|
||||||
const countSpan = document.getElementById('service-filter-count');
|
const countSpan = document.getElementById('service-filter-count');
|
||||||
|
|
||||||
|
// Build a single category list from both the API categories and any
|
||||||
|
// categories present on the actual rendered cards (covers custom services
|
||||||
|
// whose category isn't in TEMPLATE_CATEGORIES).
|
||||||
|
function getCategoryList() {
|
||||||
|
const seen = new Set();
|
||||||
|
const fromCards = new Set();
|
||||||
|
document.querySelectorAll('#cards .card[data-category]').forEach(c => {
|
||||||
|
const cat = c.dataset.category.trim();
|
||||||
|
if (cat) fromCards.add(cat);
|
||||||
|
});
|
||||||
|
const apiCats = (window.DC_CATEGORIES || (typeof DC !== 'undefined' && DC.CATEGORIES)) || {};
|
||||||
|
const all = Object.keys(apiCats).concat([...fromCards].filter(c => !apiCats[c]));
|
||||||
|
all.forEach(c => seen.add(c));
|
||||||
|
return { list: [...seen], apiCats };
|
||||||
|
}
|
||||||
|
|
||||||
|
function refreshCategoryDropdown() {
|
||||||
|
if (!categorySelect) return;
|
||||||
|
const { list, apiCats } = getCategoryList();
|
||||||
|
const current = categorySelect.value;
|
||||||
|
categorySelect.innerHTML = '<option value="all">All Categories</option>';
|
||||||
|
list.sort().forEach(name => {
|
||||||
|
const info = apiCats[name];
|
||||||
|
const opt = document.createElement('option');
|
||||||
|
opt.value = name;
|
||||||
|
opt.textContent = info ? `${info.icon || ''} ${name}`.trim() : name;
|
||||||
|
categorySelect.appendChild(opt);
|
||||||
|
});
|
||||||
|
// Restore selection if it still exists
|
||||||
|
if (current && [...categorySelect.options].some(o => o.value === current)) {
|
||||||
|
categorySelect.value = current;
|
||||||
|
} else {
|
||||||
|
categorySelect.value = 'all';
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
function updateFilter() {
|
function updateFilter() {
|
||||||
|
refreshCategoryDropdown();
|
||||||
const query = searchInput.value.toLowerCase().trim();
|
const query = searchInput.value.toLowerCase().trim();
|
||||||
const statusFilter = statusSelect.value; // 'all', 'on', or 'off'
|
const statusFilter = statusSelect.value; // 'all', 'on', or 'off'
|
||||||
|
const categoryFilter = categorySelect ? categorySelect.value : 'all';
|
||||||
|
|
||||||
const cards = document.querySelectorAll('#cards .card');
|
const cards = document.querySelectorAll('#cards .card');
|
||||||
let visibleCount = 0;
|
let visibleCount = 0;
|
||||||
@@ -15,11 +54,13 @@
|
|||||||
const name = card.querySelector('.name')?.textContent?.toLowerCase() || '';
|
const name = card.querySelector('.name')?.textContent?.toLowerCase() || '';
|
||||||
const app = card.dataset.app?.toLowerCase() || '';
|
const app = card.dataset.app?.toLowerCase() || '';
|
||||||
const status = card.dataset.status || 'off'; // 'on' or 'off'
|
const status = card.dataset.status || 'off'; // 'on' or 'off'
|
||||||
|
const category = card.dataset.category || '';
|
||||||
|
|
||||||
const matchesSearch = !query || name.includes(query) || app.includes(query);
|
const matchesSearch = !query || name.includes(query) || app.includes(query);
|
||||||
const matchesStatus = statusFilter === 'all' || status === statusFilter;
|
const matchesStatus = statusFilter === 'all' || status === statusFilter;
|
||||||
|
const matchesCategory = categoryFilter === 'all' || category === categoryFilter;
|
||||||
|
|
||||||
if (matchesSearch && matchesStatus) {
|
if (matchesSearch && matchesStatus && matchesCategory) {
|
||||||
card.style.display = '';
|
card.style.display = '';
|
||||||
visibleCount++;
|
visibleCount++;
|
||||||
} else {
|
} else {
|
||||||
@@ -44,6 +85,7 @@
|
|||||||
|
|
||||||
searchInput?.addEventListener('input', debounce(updateFilter, 200));
|
searchInput?.addEventListener('input', debounce(updateFilter, 200));
|
||||||
statusSelect?.addEventListener('change', updateFilter);
|
statusSelect?.addEventListener('change', updateFilter);
|
||||||
|
categorySelect?.addEventListener('change', updateFilter);
|
||||||
|
|
||||||
// Initial count on page load
|
// Initial count on page load
|
||||||
if (document.readyState === 'loading') {
|
if (document.readyState === 'loading') {
|
||||||
@@ -52,6 +94,7 @@
|
|||||||
setTimeout(updateFilter, 500);
|
setTimeout(updateFilter, 500);
|
||||||
}
|
}
|
||||||
|
|
||||||
// Expose for external triggers
|
// Expose for external triggers (called after buildGrid to repopulate categories)
|
||||||
window.refreshServiceFilter = updateFilter;
|
window.refreshServiceFilter = updateFilter;
|
||||||
|
window.refreshCategoryDropdown = refreshCategoryDropdown;
|
||||||
})();
|
})();
|
||||||
|
|||||||
@@ -174,8 +174,9 @@ window.populateTimezoneSelect = function(selectEl, selectedTz) {
|
|||||||
if (currentConfigType === 'homelab') {
|
if (currentConfigType === 'homelab') {
|
||||||
config.tld = document.getElementById('setup-tld')?.value?.trim() || '.home';
|
config.tld = document.getElementById('setup-tld')?.value?.trim() || '.home';
|
||||||
config.caName = document.getElementById('setup-ca-name')?.value?.trim() || '';
|
config.caName = document.getElementById('setup-ca-name')?.value?.trim() || '';
|
||||||
|
const selectedProvider = document.getElementById('setup-dns-provider')?.value || 'technitium';
|
||||||
config.dns = {
|
config.dns = {
|
||||||
provider: 'technitium',
|
provider: selectedProvider,
|
||||||
ip: document.getElementById('setup-dns-ip')?.value?.trim() || '',
|
ip: document.getElementById('setup-dns-ip')?.value?.trim() || '',
|
||||||
port: document.getElementById('setup-dns-port')?.value?.trim() || DC.DEFAULTS.DNS_PORT,
|
port: document.getElementById('setup-dns-port')?.value?.trim() || DC.DEFAULTS.DNS_PORT,
|
||||||
token: document.getElementById('setup-dns-token')?.value?.trim() || ''
|
token: document.getElementById('setup-dns-token')?.value?.trim() || ''
|
||||||
|
|||||||
@@ -17,8 +17,10 @@
|
|||||||
|
|
||||||
<!-- Tab: Available Updates -->
|
<!-- Tab: Available Updates -->
|
||||||
<div id="updates-available" class="panel-section active">
|
<div id="updates-available" class="panel-section active">
|
||||||
<div style="margin-bottom: 12px;">
|
<div style="margin-bottom: 12px; display: flex; gap: 8px; align-items: center;">
|
||||||
<button id="updates-check-btn" class="btn-accent-solid">🔍 Check for Updates</button>
|
<button id="updates-check-btn" class="btn-accent-solid">🔍 Check for Updates</button>
|
||||||
|
<button id="updates-update-all-btn" style="display: none; padding: 6px 14px; font-size: 0.82rem; background: #f97316; color: #fff; border: 1px solid #f97316; border-radius: 6px; cursor: pointer;">⬆️ Update All</button>
|
||||||
|
<span id="updates-count-badge" style="display: none; padding: 4px 10px; border-radius: 12px; font-size: 0.78rem; font-weight: 600; background: var(--accent); color: var(--bg);"></span>
|
||||||
</div>
|
</div>
|
||||||
<div id="updates-available-container" style="max-height: 450px; overflow-y: auto;">
|
<div id="updates-available-container" style="max-height: 450px; overflow-y: auto;">
|
||||||
<div class="panel-empty"><span class="empty-icon">📦</span> Click "Check for Updates" to scan containers.</div>
|
<div class="panel-empty"><span class="empty-icon">📦</span> Click "Check for Updates" to scan containers.</div>
|
||||||
@@ -94,13 +96,24 @@
|
|||||||
if (updates.length === 0) {
|
if (updates.length === 0) {
|
||||||
availableContainer.innerHTML = '<div class="panel-empty"><span class="empty-icon">✅</span>All containers are up to date.</div>';
|
availableContainer.innerHTML = '<div class="panel-empty"><span class="empty-icon">✅</span>All containers are up to date.</div>';
|
||||||
lastCheckSpan.textContent = '';
|
lastCheckSpan.textContent = '';
|
||||||
|
document.getElementById('updates-update-all-btn').style.display = 'none';
|
||||||
|
document.getElementById('updates-count-badge').style.display = 'none';
|
||||||
|
window._pendingUpdates = [];
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
let html = '<table style="width: 100%; border-collapse: collapse; font-size: 0.85rem;">';
|
let html = '<table style="width: 100%; border-collapse: collapse; font-size: 0.85rem;">';
|
||||||
html += '<tr style="border-bottom: 1px solid var(--border); color: var(--muted);"><th style="padding: 8px; text-align: left;">Container</th><th style="padding: 8px; text-align: left;">Image</th><th style="padding: 8px; text-align: left;">Current</th><th style="padding: 8px; text-align: left;">Latest</th><th style="padding: 8px; text-align: right;">Actions</th></tr>';
|
html += '<tr style="border-bottom: 1px solid var(--border); color: var(--muted);"><th style="padding: 8px; text-align: left;">Container</th><th style="padding: 8px; text-align: left;">Image</th><th style="padding: 8px; text-align: left;">Current</th><th style="padding: 8px; text-align: left;">Latest</th><th style="padding: 8px; text-align: right;">Actions</th></tr>';
|
||||||
for (const u of updates) {
|
for (const u of updates) {
|
||||||
html += `<tr style="border-bottom: 1px solid var(--border);">`;
|
// Match app by containerId first, then name
|
||||||
|
const appId = (() => {
|
||||||
|
const apps = window.APPS || [];
|
||||||
|
for (const a of apps) {
|
||||||
|
if (a.containerId === u.containerId || a.name === u.containerName || a.id === u.containerName) return a.id;
|
||||||
|
}
|
||||||
|
return u.containerName;
|
||||||
|
})();
|
||||||
|
html += `<tr data-app-id="${escapeHtml(appId)}" style="border-bottom: 1px solid var(--border);">`;
|
||||||
html += `<td style="padding: 8px; font-weight: 500;">${escapeHtml(u.containerName)}</td>`;
|
html += `<td style="padding: 8px; font-weight: 500;">${escapeHtml(u.containerName)}</td>`;
|
||||||
html += `<td style="padding: 8px; color: var(--muted);">${escapeHtml(u.imageName)}</td>`;
|
html += `<td style="padding: 8px; color: var(--muted);">${escapeHtml(u.imageName)}</td>`;
|
||||||
html += `<td style="padding: 8px;"><code style="font-size: 0.78rem; background: var(--bg); padding: 2px 6px; border-radius: 4px;">${escapeHtml(u.currentDigest)}</code></td>`;
|
html += `<td style="padding: 8px;"><code style="font-size: 0.78rem; background: var(--bg); padding: 2px 6px; border-radius: 4px;">${escapeHtml(u.currentDigest)}</code></td>`;
|
||||||
@@ -114,6 +127,20 @@
|
|||||||
availableContainer.innerHTML = html;
|
availableContainer.innerHTML = html;
|
||||||
lastCheckSpan.textContent = updates.length + ' update(s) available';
|
lastCheckSpan.textContent = updates.length + ' update(s) available';
|
||||||
|
|
||||||
|
// Show count badge and Update All button
|
||||||
|
const countBadge = document.getElementById('updates-count-badge');
|
||||||
|
const updateAllBtn = document.getElementById('updates-update-all-btn');
|
||||||
|
if (countBadge) {
|
||||||
|
countBadge.textContent = updates.length + ' pending';
|
||||||
|
countBadge.style.display = '';
|
||||||
|
}
|
||||||
|
if (updateAllBtn && updates.length > 0) {
|
||||||
|
updateAllBtn.style.display = '';
|
||||||
|
}
|
||||||
|
|
||||||
|
// Store updates for Update All button
|
||||||
|
window._pendingUpdates = updates;
|
||||||
|
|
||||||
// Wire update buttons
|
// Wire update buttons
|
||||||
availableContainer.querySelectorAll('.update-now-btn').forEach(btn => {
|
availableContainer.querySelectorAll('.update-now-btn').forEach(btn => {
|
||||||
btn.addEventListener('click', async () => {
|
btn.addEventListener('click', async () => {
|
||||||
@@ -174,6 +201,38 @@
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Update All — sequentially, skip failures
|
||||||
|
async function updateAllContainers() {
|
||||||
|
const updates = window._pendingUpdates || [];
|
||||||
|
if (!updates.length) return;
|
||||||
|
const btn = document.getElementById('updates-update-all-btn');
|
||||||
|
if (!confirm(`Update all ${updates.length} containers? Each will restart.`)) return;
|
||||||
|
btn.textContent = '⏳ Updating...';
|
||||||
|
btn.disabled = true;
|
||||||
|
let success = 0, failed = 0;
|
||||||
|
for (const u of updates) {
|
||||||
|
try {
|
||||||
|
const r = await secureFetch(`/api/v1/updates/update/${encodeURIComponent(u.containerId)}`, {
|
||||||
|
method: 'POST',
|
||||||
|
headers: { 'Content-Type': 'application/json' },
|
||||||
|
body: JSON.stringify({ autoRollback: true })
|
||||||
|
});
|
||||||
|
const d = await r.json();
|
||||||
|
if (d.success) success++;
|
||||||
|
else failed++;
|
||||||
|
} catch (_) { failed++; }
|
||||||
|
}
|
||||||
|
btn.textContent = `✅ Done`;
|
||||||
|
showNotification(`Update all: ${success} succeeded, ${failed} failed.`, success > 0 && failed === 0 ? 'success' : 'error');
|
||||||
|
setTimeout(() => {
|
||||||
|
btn.textContent = '⬆️ Update All';
|
||||||
|
btn.disabled = false;
|
||||||
|
loadAvailable();
|
||||||
|
}, 3000);
|
||||||
|
}
|
||||||
|
|
||||||
|
document.getElementById('updates-update-all-btn')?.addEventListener('click', updateAllContainers);
|
||||||
|
|
||||||
async function checkForUpdates() {
|
async function checkForUpdates() {
|
||||||
checkBtn.textContent = '🔍 Checking...';
|
checkBtn.textContent = '🔍 Checking...';
|
||||||
checkBtn.disabled = true;
|
checkBtn.disabled = true;
|
||||||
@@ -499,6 +558,21 @@
|
|||||||
});
|
});
|
||||||
wireModal(modal, cancelBtn);
|
wireModal(modal, cancelBtn);
|
||||||
|
|
||||||
|
// Open Update Management modal, optionally scrolled to a specific app
|
||||||
|
window.openUpdateModal = function(appId) {
|
||||||
|
modal?.classList.add('show');
|
||||||
|
loadAvailable().then(() => {
|
||||||
|
if (!appId) return;
|
||||||
|
// Scroll to and highlight the matching row
|
||||||
|
const row = availableContainer.querySelector(`[data-app-id="${appId}"]`);
|
||||||
|
if (row) {
|
||||||
|
row.scrollIntoView({ behavior: 'smooth', block: 'center' });
|
||||||
|
row.style.background = 'rgba(249,115,22,0.15)';
|
||||||
|
setTimeout(() => { row.style.background = ''; }, 3000);
|
||||||
|
}
|
||||||
|
});
|
||||||
|
};
|
||||||
|
|
||||||
// Lazy-load tabs
|
// Lazy-load tabs
|
||||||
document.querySelector('[data-panel="updates-history"]')?.addEventListener('click', loadHistory);
|
document.querySelector('[data-panel="updates-history"]')?.addEventListener('click', loadHistory);
|
||||||
document.querySelector('[data-panel="updates-auto"]')?.addEventListener('click', loadAutoConfig);
|
document.querySelector('[data-panel="updates-auto"]')?.addEventListener('click', loadAutoConfig);
|
||||||
|
|||||||
+1
-1
@@ -1,4 +1,4 @@
|
|||||||
const CACHE = 'dashcaddy-shell-8ef9c82616';
|
const CACHE = 'dashcaddy-shell-43a872cc40';
|
||||||
const PRECACHE = [
|
const PRECACHE = [
|
||||||
'/',
|
'/',
|
||||||
'/index.html',
|
'/index.html',
|
||||||
|
|||||||
Reference in New Issue
Block a user