feat: open security basics, manual fleet ops, and basic fleet management to Community (#930)

Realign tier guards to the user-stated philosophy: Community covers
deploy/monitor at scale plus security basics, Skipper adds automation
and advanced fleet management, Admiral keeps enterprise control.

Community now includes:
- Trivy install / uninstall / update from the Settings Hub (admin role)
- CVE suppressions CRUD (admin role; replicates fleet-wide)
- Manual image scan with vuln, secret, and misconfig results
- Stack-config scan, scan comparison
- Manual fleet snapshots: create, list, view, restore, delete
- Per-node Sencho self-update (Check Updates + per-node Update)
- Fleet Overview search, sort, filters, node-card expand, auto-refresh

Stays paid:
- Scan policies with block_on_deploy enforcement (Skipper+)
- SBOM (SPDX, CycloneDX), SARIF export (Skipper+)
- Bulk Update All across the fleet (Skipper+)
- Scheduled snapshot create (now Skipper, was Admiral)
- Trivy auto-update toggle, fleet-wide policy push (Admiral)

The Settings -> Security tab is unhidden by setting the registry tier to
null. The SecuritySection no longer early-returns a PaidGate; the policy
list, Add Policy button, and policy dialogs are wrapped in {isPaid && }.
The Fleet view drops isPaid gates on the Snapshots tab, Check Updates
button, per-node update handlers, OverviewToolbar grid controls, the
NodeCard expand affordance, and the auto-refresh notice. The
NodeUpdatesSheet receives a canBulkUpdate prop and gates the Update All
button on it. useFleetUpdateStatus and useFleetPolling drop their isPaid
guards so polling runs for Community; useFleetOverview drops the isPaid
wrap on the filter and sort path.

Backend route guards are flipped per the matrix above. The scheduler
tick and requireScheduledTaskTier add 'snapshot' to the Skipper+ branch.
Backend test assertions are inverted for the now-Community endpoints
and a positive Skipper-snapshot-task test is added.

Documentation across features/, api-reference/, and operations/ is
updated to reflect the new tier mapping.
This commit is contained in:
Anso
2026-05-05 12:54:26 -04:00
committed by GitHub
parent f1a592372b
commit ecf4dd5d52
28 changed files with 234 additions and 280 deletions
@@ -39,7 +39,6 @@ function renderPaletteOption(option: { label: string; color?: string }) {
}
interface OverviewToolbarProps {
isPaid: boolean;
viewMode: ViewMode;
onViewModeChange: (mode: ViewMode) => void;
searchQuery: string;
@@ -53,7 +52,6 @@ interface OverviewToolbarProps {
}
export function OverviewToolbar({
isPaid,
viewMode,
onViewModeChange,
searchQuery,
@@ -65,7 +63,7 @@ export function OverviewToolbar({
onLabelFiltersChange,
onClearFilters,
}: OverviewToolbarProps) {
const showPaidControls = isPaid && viewMode === 'grid';
const showGridControls = viewMode === 'grid';
const activeFilterCount =
(prefs.filterStatus !== 'all' ? 1 : 0) +
(prefs.filterType !== 'all' ? 1 : 0) +
@@ -79,7 +77,7 @@ export function OverviewToolbar({
return (
<div className="flex flex-wrap items-center gap-2 mb-4">
{showPaidControls && (
{showGridControls && (
<>
<div className="relative flex-1 min-w-[200px] max-w-sm">
<Search className="absolute left-3 top-1/2 -translate-y-1/2 w-4 h-4 text-muted-foreground pointer-events-none" />