Files
sencho/docs/docs.json
T
Anso 2a4955f56d feat: add dedicated Security page and policy-pack foundation (#1362)
* feat: add dedicated Security page and policy-pack foundation

Bring vulnerability scanning, scan history, suppressions, Compose risks,
secrets, policy packs, and scanner setup into one node-scoped Security
command center instead of scattering them across Resources and Settings.

- New top-level Security view with Overview, Images, Compose risks,
  Secrets, Policies, Suppressions, History, and Scanner setup tabs
  (status masthead + signal rail; controlled tabs with deep-link support).
- Backend: GET /security/overview rollup and GET /security/policy-packs
  static catalog (auth-only, Community). DatabaseService gains an uncapped
  scan-status count and a node-eligible block-policy count, and
  getImageScanSummaries now projects secret and misconfig counts.
- Reuse existing surfaces: the scan-history sheet, the control-governed
  suppression and acknowledgement panels, and the scan-detail sheet (now
  with an initial-tab prop so it opens on the matching finding type).
- Extract a shared SeverityBadge (from Resources) and a TrivyManager
  (from Settings) so both surfaces render identical controls.
- Resources "Scan history" now links into the Security page History tab.
- Docs for the new Security surface and tests for the new endpoints,
  helpers, nav wiring, and tabs.

* refactor: consolidate scanner and policy management onto the Security page

Remove the Settings "Vulnerability Scanning" section now that the Security
page covers the same ground, with every option preserved:

- Scanner install / update / uninstall / auto-update live on the Scanner setup
  tab (TrivyManager).
- Scan policies, the honor-suppressions toggle, and the replica
  managed-by-control / demote controls move into a new ScanPolicyManager on the
  Policies tab (paid; Community sees only the policy-pack catalog).
- CVE suppressions and acknowledgements remain on the Suppressions tab.

Wiring removed: the registry section and the now-empty Security settings group,
the SectionId, the SettingsSectionContent case and the isPaid prop it was the
sole consumer of, and SecuritySection itself. The dashboard configuration-status
"Vulnerability scanning" row now navigates to the Security page Policies tab.

Docs that pointed at "Settings -> Security -> Vulnerability Scanning" are swept
to the relevant Security page tabs.

* fix: harden Security page scanner refresh, policy-load errors, and secret-only badges

Address independent-review findings on the Security page:

- Scanner setup now refreshes Trivy state when the active node changes, so the
  displayed scanner status matches the node TrivyManager's actions target (both
  follow x-node-id). Previously, switching nodes on the tab left stale state.
- ScanPolicyManager surfaces an explicit error state on a failed policy fetch
  instead of falling through to a false "No scan policies configured".
- The shared SeverityBadge and the Images findings column no longer label a scan
  "clean" when it has secrets or misconfigurations but no CVE severity
  (highest_severity is derived from vulnerabilities only); they show a "Findings"
  state and the secret/misconfig counts instead.
- The Overview enforcement note points to the Policies tab, not the removed
  Settings section.
- The History tab auto-opens the scan-history sheet only on a deep-link (mount
  with the History tab active), not on every manual tab selection.

Adds tests for the badge secret/misconfig state and the policy-load error state.
2026-06-12 10:41:39 -04:00

340 lines
10 KiB
JSON

{
"$schema": "https://mintlify.com/docs.json",
"theme": "mint",
"name": "Sencho",
"colors": {
"primary": "#00BEC7",
"light": "#007982",
"dark": "#00BEC7"
},
"logo": {
"light": "/images/logo/logo-light.png",
"dark": "/images/logo/logo-dark.png",
"href": "https://sencho.io"
},
"favicon": "/images/logo/favicon.ico",
"appearance": {
"default": "dark"
},
"fonts": {
"family": "Geist"
},
"background": {
"decoration": "gradient",
"color": {
"dark": "#090909"
}
},
"navbar": {
"links": [
{
"type": "github",
"href": "https://github.com/studio-saelix/sencho"
}
],
"primary": {
"type": "button",
"label": "Get Started",
"href": "https://sencho.io/#pricing"
}
},
"footer": {
"socials": {
"github": "https://github.com/studio-saelix/sencho"
},
"links": [
{
"header": "Product",
"items": [
{ "label": "Website", "href": "https://sencho.io" },
{ "label": "Pricing", "href": "https://sencho.io/#pricing" },
{ "label": "Changelog", "href": "https://github.com/studio-saelix/sencho/releases" }
]
},
{
"header": "Community",
"items": [
{ "label": "GitHub", "href": "https://github.com/studio-saelix/sencho" },
{ "label": "Contributing", "href": "https://github.com/studio-saelix/sencho/blob/main/CONTRIBUTING.md" }
]
},
{
"header": "Legal",
"items": [
{ "label": "Terms of Service", "href": "https://sencho.io/terms" },
{ "label": "Privacy Policy", "href": "https://sencho.io/privacy" }
]
}
]
},
"api": {
"auth": {
"method": "bearer",
"name": "Authorization"
},
"playground": {
"display": "simple"
}
},
"navigation": {
"tabs": [
{
"tab": "Documentation",
"groups": [
{
"group": "Getting Started",
"pages": [
"getting-started/introduction",
"getting-started/quickstart",
"getting-started/configuration",
"getting-started/sso-quickstart"
]
},
{
"group": "Features",
"pages": [
"features/overview",
"features/appearance",
{
"group": "Stacks",
"expanded": true,
"pages": [
"features/stack-management",
"features/editor",
"features/stack-file-explorer",
"features/stack-activity",
"features/stack-dossier",
"features/stack-drift",
"features/compose-doctor",
"features/compose-networking",
"features/stack-labels",
"features/sidebar"
]
},
{
"group": "Deployment",
"expanded": true,
"pages": [
"features/deploy-progress",
"features/atomic-deployments",
"features/health-gated-updates",
"features/deploy-enforcement",
"features/git-sources",
"features/app-store",
"features/blueprint-model"
]
},
"features/resources",
{
"group": "Observability",
"expanded": true,
"pages": [
"features/dashboard",
"features/global-search",
"features/global-observability",
"features/alerts-notifications",
"features/audit-log"
]
},
{
"group": "Fleet",
"expanded": true,
"pages": [
"features/multi-node",
"features/pilot-agent",
"features/sencho-mesh",
"features/fleet-view",
"features/fleet-dossier",
"features/fleet-federation",
"features/fleet-actions",
"features/fleet-sync",
"features/fleet-secrets",
"features/fleet-backups",
"features/remote-updates",
"features/node-compatibility",
"features/host-console"
]
},
{
"group": "Automation",
"expanded": true,
"pages": [
"features/scheduled-operations",
"features/auto-update-policies",
"features/auto-heal-policies",
"features/webhooks"
]
},
{
"group": "Security & Identity",
"expanded": true,
"pages": [
"features/two-factor-authentication",
"features/rbac",
"features/sso",
"features/api-tokens",
"features/security",
"features/vulnerability-scanning",
"features/cve-suppressions",
"features/private-registries"
]
}
]
},
{
"group": "Operations",
"pages": [
"operations/self-hosting",
"operations/upgrade",
"operations/backup",
"operations/recovery",
"operations/emergency-cli",
"operations/troubleshooting",
"operations/verifying-images",
"operations/trivy-setup",
"operations/two-factor-admin"
]
},
{
"group": "Reference",
"pages": [
"reference/settings",
"features/licensing",
"reference/security",
"reference/contact"
]
}
]
},
{
"tab": "API Reference",
"openapi": "openapi.yaml",
"pages": [
"api-reference/overview",
"api-reference/security",
{
"group": "Health & Meta",
"pages": [
"GET /api/health",
"GET /api/meta",
"POST /api/system/update"
]
},
{
"group": "Stacks",
"pages": [
"GET /api/stacks",
"POST /api/stacks",
"GET /api/stacks/{stackName}",
"PUT /api/stacks/{stackName}",
"DELETE /api/stacks/{stackName}",
"GET /api/stacks/{stackName}/envs",
"GET /api/stacks/{stackName}/env",
"PUT /api/stacks/{stackName}/env",
"GET /api/stacks/{stackName}/containers",
"GET /api/stacks/{stackName}/services",
"POST /api/stacks/{stackName}/deploy",
"POST /api/stacks/{stackName}/down",
"POST /api/stacks/{stackName}/start",
"POST /api/stacks/{stackName}/stop",
"POST /api/stacks/{stackName}/restart",
"POST /api/stacks/{stackName}/update",
"POST /api/stacks/{stackName}/rollback",
"GET /api/stacks/{stackName}/backup"
]
},
{
"group": "Containers",
"pages": [
"GET /api/containers",
"GET /api/containers/{id}/logs",
"POST /api/containers/{id}/start",
"POST /api/containers/{id}/stop",
"POST /api/containers/{id}/restart"
]
},
{
"group": "API Tokens",
"pages": [
"POST /api/api-tokens",
"GET /api/api-tokens",
"DELETE /api/api-tokens/{id}"
]
},
{
"group": "Webhooks",
"pages": [
"GET /api/webhooks",
"POST /api/webhooks",
"PUT /api/webhooks/{id}",
"DELETE /api/webhooks/{id}",
"GET /api/webhooks/{id}/history",
"POST /api/webhooks/{id}/trigger"
]
},
{
"group": "Nodes",
"pages": [
"GET /api/nodes",
"POST /api/nodes",
"GET /api/nodes/{id}",
"PUT /api/nodes/{id}",
"DELETE /api/nodes/{id}",
"POST /api/nodes/{id}/test",
"GET /api/nodes/{id}/meta"
]
},
{
"group": "Fleet",
"pages": [
"GET /api/fleet/overview",
"GET /api/fleet/node/{nodeId}/stacks",
"GET /api/fleet/node/{nodeId}/stacks/{stackName}/containers",
"GET /api/fleet/update-status",
"POST /api/fleet/nodes/{nodeId}/update",
"POST /api/fleet/update-all",
"POST /api/fleet/snapshots",
"GET /api/fleet/snapshots",
"GET /api/fleet/snapshots/{id}",
"POST /api/fleet/snapshots/{id}/restore",
"DELETE /api/fleet/snapshots/{id}"
]
},
{
"group": "Scheduled Tasks",
"pages": [
"GET /api/scheduled-tasks",
"POST /api/scheduled-tasks",
"GET /api/scheduled-tasks/{id}",
"PUT /api/scheduled-tasks/{id}",
"DELETE /api/scheduled-tasks/{id}",
"PATCH /api/scheduled-tasks/{id}/toggle",
"POST /api/scheduled-tasks/{id}/run",
"GET /api/scheduled-tasks/{id}/runs",
"GET /api/scheduled-tasks/{id}/runs/export"
]
},
{
"group": "Registries",
"pages": [
"GET /api/registries",
"POST /api/registries",
"PUT /api/registries/{id}",
"DELETE /api/registries/{id}",
"POST /api/registries/{id}/test"
]
},
{
"group": "Image Updates",
"pages": [
"GET /api/image-updates",
"POST /api/image-updates/refresh",
"GET /api/image-updates/status"
]
}
]
}
]
}
}