Add remote instance management with mTLS agent and phone-home registration
Enables the CCP to manage CML instances on remote servers via a lightweight HTTP agent. Key components: - ExecutionDriver abstraction (local-driver.ts / remote-driver.ts) routes operations to local Docker or remote agent transparently - Remote agent package (agent/) with mTLS authentication, Docker Compose operations, file management, backup/upgrade delegation - Certificate service using openssl CLI for CA management and cert issuance - Phone-home registration: remote agents register via invite code, CCP admin approves, agent receives mTLS cert bundle automatically - config.sh integration with configure_control_panel() section - ccp-agent Docker Compose service (profile-gated) - Frontend: AgentRegistrationsPage, InviteCodesPage, Remote Agents sidebar menu - Security hardened: cert bundle wiped after delivery, shell injection prevention via execFile, command allowlist with metachar rejection, rate-limited public endpoints, auto-populated fingerprint pinning Also wires ENABLE_SOCIAL/PEOPLE/ANALYTICS through env.ts, seed.ts, and docker-compose env passthrough (from previous session). Bunker Admin
This commit is contained in:
20
.env.example
20
.env.example
@@ -403,6 +403,26 @@ SMS_MAX_RETRIES=3
|
||||
SMS_RESPONSE_SYNC_INTERVAL_MS=120000
|
||||
SMS_DEVICE_MONITOR_INTERVAL_MS=300000
|
||||
|
||||
# --- Social, People & Analytics ---
|
||||
# ENABLE_SOCIAL is the initial default; once saved in admin Settings, the DB value is authoritative
|
||||
ENABLE_SOCIAL=false
|
||||
# ENABLE_PEOPLE is the initial default; once saved in admin Settings, the DB value is authoritative
|
||||
ENABLE_PEOPLE=false
|
||||
# ENABLE_ANALYTICS is the initial default; once saved in admin Settings, the DB value is authoritative
|
||||
ENABLE_ANALYTICS=false
|
||||
|
||||
# --- Control Panel Agent ---
|
||||
# Set to true to enable the CCP remote management agent
|
||||
ENABLE_CCP_AGENT=false
|
||||
# URL of the Changemaker Control Panel
|
||||
CCP_URL=
|
||||
# One-time invite code for registration
|
||||
CCP_INVITE_CODE=
|
||||
# How the CCP can reach this agent (must be externally accessible)
|
||||
CCP_AGENT_URL=
|
||||
# Agent port (default 7443)
|
||||
CCP_AGENT_PORT=7443
|
||||
|
||||
# --- Monitoring (only used with --profile monitoring) ---
|
||||
PROMETHEUS_PORT=9090
|
||||
GRAFANA_PORT=3005
|
||||
|
||||
Reference in New Issue
Block a user