* feat(fleet): open Fleet Actions tab to Community (admin-only)
Removes the requirePaid guard from the five Fleet Actions endpoints
(fleet-stop, fleet-prune, match-preview, prune/estimate, bulk-assign)
and drops the matching isPaid parent gate on FleetActionsTab so Community
admins can run fleet-wide bulk operations. requireAdmin stays on every
endpoint; operator and viewer roles still 403 on apply.
Tests flipped from "403 PAID_REQUIRED on community" to positive
"reachable on community + admin" assertions. Docs (fleet-actions,
fleet-view, licensing, overview, stack-labels) rewritten to state the
admin-role requirement once and drop the prior Skipper framing.
* fix(fleet): apply audit findings from PR #1153 review
- stack-labels.mdx: fix the page intro that still framed fleet label
actions as "Operators on a Skipper or Admiral license". The cards are
now Community + admin, so the intro reads "Admins also get a pair of
fleet-wide actions".
- Collapse redundant role-rule statements on the two affected pages.
fleet-actions.mdx now states the admin gate once in the lead-in Note
and again only in the troubleshooting accordion (the Prerequisites
row was duplicative). stack-labels.mdx trims the "Limits and rules"
bullet to the value-add half (label authoring is open to every role)
and drops the Fleet Actions repetition.
- Strip now-no-op mockTier('paid') calls from non-tier tests across the
three fleet test files, plus the test-wide default in the
fleet-action-card-endpoints beforeEach. Those mocks were misleading
after the routes stopped consulting tier; if a future change re-adds
requirePaid the tests will fail loudly instead of silently passing.
Adds a third card to the Fleet Actions tab that fans out Docker prune
(images, volumes, networks) across every node in one submit. Local nodes
call DockerController under a bulk-prune lock; remote nodes receive one
POST /api/system/prune/system per target. Per-node + per-target results
with reclaimed bytes are surfaced inline via ResultsList.
Tier: Skipper / Admiral (requirePaid + requireAdmin), matching the rest
of Fleet Actions. The frontend card is mounted inside the existing
isPaid branch at FleetActionsTab; no new frontend gate is required.
The card uses an amber accent rail and the Eraser icon so it reads as
'cleanup' rather than 'destructive stop'. Scope toggle defaults to
Managed only (Sencho-tagged resources) with an All unused option that
escalates the destructive-confirm copy.