feat: move trivy auto-update, node labels, fleet topology, and single-scan SBOM to Community (#1336)

Rebalance several capabilities from the paid tier to the free Community tier:

- Managed Trivy auto-update toggle is admin-only, no longer tier-gated.
- Node labels (assign, view, manage) are available on every tier; cordon and
  FleetSync anchor reset stay paid.
- Fleet topology layout modes (Hub, Grouped, Free) are available on Community.
- Single-scan SBOM export (SPDX and CycloneDX) is admin-only on Community;
  SARIF export stays paid via a dedicated canExportSarif capability split out
  from the former shared SBOM flag.

Backend route guards and frontend affordances are updated together, with tier
and admin-role tests covering the Community-allowed and still-paid paths.
This commit is contained in:
Anso
2026-06-08 08:58:14 -04:00
committed by GitHub
parent 710647a44f
commit 54119be0c2
18 changed files with 214 additions and 74 deletions
+2 -1
View File
@@ -1534,7 +1534,8 @@ export default function ResourcesView() {
scanId={inspectScanId}
onClose={() => setInspectScanId(null)}
onRescan={isAdmin ? (imageRef) => { setInspectScanId(null); handleScanImage(imageRef, { force: true }); } : undefined}
canGenerateSbom={isPaid && isAdmin}
canGenerateSbom={isAdmin}
canExportSarif={isPaid && isAdmin}
canCompare
canManageSuppressions={isAdmin}
/>