Add a "Scan this node" action on the Security overview that scans, in one pass,
any combination of three types: image vulnerabilities, image secrets, and
compose misconfigurations. Progress streams live into the deploy-feedback modal.
- TrivyService.scanNode runs the selected scanners across the node's images and,
for misconfig, every stack's compose file, behind a per-node lock and tolerant
of per-item failures. The existing scanAllNodeImages becomes a thin vuln-only
wrapper over the shared image loop, so scheduled scans are unchanged.
- POST /api/security/scan-node (admin, scanner-gated) streams sanitized progress
to the deploy terminal and returns a combined summary. Secret scans stream
counts only, never matched values.
- Frontend adds a "scan" action verb and a ScanNodeLauncher wired into the
overview; the scan stays bound to the node it started on even if the active
node changes mid-run.