mirror of
https://github.com/Studio-Saelix/sencho.git
synced 2026-07-26 20:00:08 +00:00
2a4955f56d
* feat: add dedicated Security page and policy-pack foundation Bring vulnerability scanning, scan history, suppressions, Compose risks, secrets, policy packs, and scanner setup into one node-scoped Security command center instead of scattering them across Resources and Settings. - New top-level Security view with Overview, Images, Compose risks, Secrets, Policies, Suppressions, History, and Scanner setup tabs (status masthead + signal rail; controlled tabs with deep-link support). - Backend: GET /security/overview rollup and GET /security/policy-packs static catalog (auth-only, Community). DatabaseService gains an uncapped scan-status count and a node-eligible block-policy count, and getImageScanSummaries now projects secret and misconfig counts. - Reuse existing surfaces: the scan-history sheet, the control-governed suppression and acknowledgement panels, and the scan-detail sheet (now with an initial-tab prop so it opens on the matching finding type). - Extract a shared SeverityBadge (from Resources) and a TrivyManager (from Settings) so both surfaces render identical controls. - Resources "Scan history" now links into the Security page History tab. - Docs for the new Security surface and tests for the new endpoints, helpers, nav wiring, and tabs. * refactor: consolidate scanner and policy management onto the Security page Remove the Settings "Vulnerability Scanning" section now that the Security page covers the same ground, with every option preserved: - Scanner install / update / uninstall / auto-update live on the Scanner setup tab (TrivyManager). - Scan policies, the honor-suppressions toggle, and the replica managed-by-control / demote controls move into a new ScanPolicyManager on the Policies tab (paid; Community sees only the policy-pack catalog). - CVE suppressions and acknowledgements remain on the Suppressions tab. Wiring removed: the registry section and the now-empty Security settings group, the SectionId, the SettingsSectionContent case and the isPaid prop it was the sole consumer of, and SecuritySection itself. The dashboard configuration-status "Vulnerability scanning" row now navigates to the Security page Policies tab. Docs that pointed at "Settings -> Security -> Vulnerability Scanning" are swept to the relevant Security page tabs. * fix: harden Security page scanner refresh, policy-load errors, and secret-only badges Address independent-review findings on the Security page: - Scanner setup now refreshes Trivy state when the active node changes, so the displayed scanner status matches the node TrivyManager's actions target (both follow x-node-id). Previously, switching nodes on the tab left stale state. - ScanPolicyManager surfaces an explicit error state on a failed policy fetch instead of falling through to a false "No scan policies configured". - The shared SeverityBadge and the Images findings column no longer label a scan "clean" when it has secrets or misconfigurations but no CVE severity (highest_severity is derived from vulnerabilities only); they show a "Findings" state and the secret/misconfig counts instead. - The Overview enforcement note points to the Policies tab, not the removed Settings section. - The History tab auto-opens the scan-history sheet only on a deep-link (mount with the History tab active), not on every manual tab selection. Adds tests for the badge secret/misconfig state and the policy-load error state.
340 lines
10 KiB
JSON
340 lines
10 KiB
JSON
{
|
|
"$schema": "https://mintlify.com/docs.json",
|
|
"theme": "mint",
|
|
"name": "Sencho",
|
|
"colors": {
|
|
"primary": "#00BEC7",
|
|
"light": "#007982",
|
|
"dark": "#00BEC7"
|
|
},
|
|
"logo": {
|
|
"light": "/images/logo/logo-light.png",
|
|
"dark": "/images/logo/logo-dark.png",
|
|
"href": "https://sencho.io"
|
|
},
|
|
"favicon": "/images/logo/favicon.ico",
|
|
"appearance": {
|
|
"default": "dark"
|
|
},
|
|
"fonts": {
|
|
"family": "Geist"
|
|
},
|
|
"background": {
|
|
"decoration": "gradient",
|
|
"color": {
|
|
"dark": "#090909"
|
|
}
|
|
},
|
|
"navbar": {
|
|
"links": [
|
|
{
|
|
"type": "github",
|
|
"href": "https://github.com/studio-saelix/sencho"
|
|
}
|
|
],
|
|
"primary": {
|
|
"type": "button",
|
|
"label": "Get Started",
|
|
"href": "https://sencho.io/#pricing"
|
|
}
|
|
},
|
|
"footer": {
|
|
"socials": {
|
|
"github": "https://github.com/studio-saelix/sencho"
|
|
},
|
|
"links": [
|
|
{
|
|
"header": "Product",
|
|
"items": [
|
|
{ "label": "Website", "href": "https://sencho.io" },
|
|
{ "label": "Pricing", "href": "https://sencho.io/#pricing" },
|
|
{ "label": "Changelog", "href": "https://github.com/studio-saelix/sencho/releases" }
|
|
]
|
|
},
|
|
{
|
|
"header": "Community",
|
|
"items": [
|
|
{ "label": "GitHub", "href": "https://github.com/studio-saelix/sencho" },
|
|
{ "label": "Contributing", "href": "https://github.com/studio-saelix/sencho/blob/main/CONTRIBUTING.md" }
|
|
]
|
|
},
|
|
{
|
|
"header": "Legal",
|
|
"items": [
|
|
{ "label": "Terms of Service", "href": "https://sencho.io/terms" },
|
|
{ "label": "Privacy Policy", "href": "https://sencho.io/privacy" }
|
|
]
|
|
}
|
|
]
|
|
},
|
|
"api": {
|
|
"auth": {
|
|
"method": "bearer",
|
|
"name": "Authorization"
|
|
},
|
|
"playground": {
|
|
"display": "simple"
|
|
}
|
|
},
|
|
"navigation": {
|
|
"tabs": [
|
|
{
|
|
"tab": "Documentation",
|
|
"groups": [
|
|
{
|
|
"group": "Getting Started",
|
|
"pages": [
|
|
"getting-started/introduction",
|
|
"getting-started/quickstart",
|
|
"getting-started/configuration",
|
|
"getting-started/sso-quickstart"
|
|
]
|
|
},
|
|
{
|
|
"group": "Features",
|
|
"pages": [
|
|
"features/overview",
|
|
"features/appearance",
|
|
{
|
|
"group": "Stacks",
|
|
"expanded": true,
|
|
"pages": [
|
|
"features/stack-management",
|
|
"features/editor",
|
|
"features/stack-file-explorer",
|
|
"features/stack-activity",
|
|
"features/stack-dossier",
|
|
"features/stack-drift",
|
|
"features/compose-doctor",
|
|
"features/compose-networking",
|
|
"features/stack-labels",
|
|
"features/sidebar"
|
|
]
|
|
},
|
|
{
|
|
"group": "Deployment",
|
|
"expanded": true,
|
|
"pages": [
|
|
"features/deploy-progress",
|
|
"features/atomic-deployments",
|
|
"features/health-gated-updates",
|
|
"features/deploy-enforcement",
|
|
"features/git-sources",
|
|
"features/app-store",
|
|
"features/blueprint-model"
|
|
]
|
|
},
|
|
"features/resources",
|
|
{
|
|
"group": "Observability",
|
|
"expanded": true,
|
|
"pages": [
|
|
"features/dashboard",
|
|
"features/global-search",
|
|
"features/global-observability",
|
|
"features/alerts-notifications",
|
|
"features/audit-log"
|
|
]
|
|
},
|
|
{
|
|
"group": "Fleet",
|
|
"expanded": true,
|
|
"pages": [
|
|
"features/multi-node",
|
|
"features/pilot-agent",
|
|
"features/sencho-mesh",
|
|
"features/fleet-view",
|
|
"features/fleet-dossier",
|
|
"features/fleet-federation",
|
|
"features/fleet-actions",
|
|
"features/fleet-sync",
|
|
"features/fleet-secrets",
|
|
"features/fleet-backups",
|
|
"features/remote-updates",
|
|
"features/node-compatibility",
|
|
"features/host-console"
|
|
]
|
|
},
|
|
{
|
|
"group": "Automation",
|
|
"expanded": true,
|
|
"pages": [
|
|
"features/scheduled-operations",
|
|
"features/auto-update-policies",
|
|
"features/auto-heal-policies",
|
|
"features/webhooks"
|
|
]
|
|
},
|
|
{
|
|
"group": "Security & Identity",
|
|
"expanded": true,
|
|
"pages": [
|
|
"features/two-factor-authentication",
|
|
"features/rbac",
|
|
"features/sso",
|
|
"features/api-tokens",
|
|
"features/security",
|
|
"features/vulnerability-scanning",
|
|
"features/cve-suppressions",
|
|
"features/private-registries"
|
|
]
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"group": "Operations",
|
|
"pages": [
|
|
"operations/self-hosting",
|
|
"operations/upgrade",
|
|
"operations/backup",
|
|
"operations/recovery",
|
|
"operations/emergency-cli",
|
|
"operations/troubleshooting",
|
|
"operations/verifying-images",
|
|
"operations/trivy-setup",
|
|
"operations/two-factor-admin"
|
|
]
|
|
},
|
|
{
|
|
"group": "Reference",
|
|
"pages": [
|
|
"reference/settings",
|
|
"features/licensing",
|
|
"reference/security",
|
|
"reference/contact"
|
|
]
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"tab": "API Reference",
|
|
"openapi": "openapi.yaml",
|
|
"pages": [
|
|
"api-reference/overview",
|
|
"api-reference/security",
|
|
{
|
|
"group": "Health & Meta",
|
|
"pages": [
|
|
"GET /api/health",
|
|
"GET /api/meta",
|
|
"POST /api/system/update"
|
|
]
|
|
},
|
|
{
|
|
"group": "Stacks",
|
|
"pages": [
|
|
"GET /api/stacks",
|
|
"POST /api/stacks",
|
|
"GET /api/stacks/{stackName}",
|
|
"PUT /api/stacks/{stackName}",
|
|
"DELETE /api/stacks/{stackName}",
|
|
"GET /api/stacks/{stackName}/envs",
|
|
"GET /api/stacks/{stackName}/env",
|
|
"PUT /api/stacks/{stackName}/env",
|
|
"GET /api/stacks/{stackName}/containers",
|
|
"GET /api/stacks/{stackName}/services",
|
|
"POST /api/stacks/{stackName}/deploy",
|
|
"POST /api/stacks/{stackName}/down",
|
|
"POST /api/stacks/{stackName}/start",
|
|
"POST /api/stacks/{stackName}/stop",
|
|
"POST /api/stacks/{stackName}/restart",
|
|
"POST /api/stacks/{stackName}/update",
|
|
"POST /api/stacks/{stackName}/rollback",
|
|
"GET /api/stacks/{stackName}/backup"
|
|
]
|
|
},
|
|
{
|
|
"group": "Containers",
|
|
"pages": [
|
|
"GET /api/containers",
|
|
"GET /api/containers/{id}/logs",
|
|
"POST /api/containers/{id}/start",
|
|
"POST /api/containers/{id}/stop",
|
|
"POST /api/containers/{id}/restart"
|
|
]
|
|
},
|
|
{
|
|
"group": "API Tokens",
|
|
"pages": [
|
|
"POST /api/api-tokens",
|
|
"GET /api/api-tokens",
|
|
"DELETE /api/api-tokens/{id}"
|
|
]
|
|
},
|
|
{
|
|
"group": "Webhooks",
|
|
"pages": [
|
|
"GET /api/webhooks",
|
|
"POST /api/webhooks",
|
|
"PUT /api/webhooks/{id}",
|
|
"DELETE /api/webhooks/{id}",
|
|
"GET /api/webhooks/{id}/history",
|
|
"POST /api/webhooks/{id}/trigger"
|
|
]
|
|
},
|
|
{
|
|
"group": "Nodes",
|
|
"pages": [
|
|
"GET /api/nodes",
|
|
"POST /api/nodes",
|
|
"GET /api/nodes/{id}",
|
|
"PUT /api/nodes/{id}",
|
|
"DELETE /api/nodes/{id}",
|
|
"POST /api/nodes/{id}/test",
|
|
"GET /api/nodes/{id}/meta"
|
|
]
|
|
},
|
|
{
|
|
"group": "Fleet",
|
|
"pages": [
|
|
"GET /api/fleet/overview",
|
|
"GET /api/fleet/node/{nodeId}/stacks",
|
|
"GET /api/fleet/node/{nodeId}/stacks/{stackName}/containers",
|
|
"GET /api/fleet/update-status",
|
|
"POST /api/fleet/nodes/{nodeId}/update",
|
|
"POST /api/fleet/update-all",
|
|
"POST /api/fleet/snapshots",
|
|
"GET /api/fleet/snapshots",
|
|
"GET /api/fleet/snapshots/{id}",
|
|
"POST /api/fleet/snapshots/{id}/restore",
|
|
"DELETE /api/fleet/snapshots/{id}"
|
|
]
|
|
},
|
|
{
|
|
"group": "Scheduled Tasks",
|
|
"pages": [
|
|
"GET /api/scheduled-tasks",
|
|
"POST /api/scheduled-tasks",
|
|
"GET /api/scheduled-tasks/{id}",
|
|
"PUT /api/scheduled-tasks/{id}",
|
|
"DELETE /api/scheduled-tasks/{id}",
|
|
"PATCH /api/scheduled-tasks/{id}/toggle",
|
|
"POST /api/scheduled-tasks/{id}/run",
|
|
"GET /api/scheduled-tasks/{id}/runs",
|
|
"GET /api/scheduled-tasks/{id}/runs/export"
|
|
]
|
|
},
|
|
{
|
|
"group": "Registries",
|
|
"pages": [
|
|
"GET /api/registries",
|
|
"POST /api/registries",
|
|
"PUT /api/registries/{id}",
|
|
"DELETE /api/registries/{id}",
|
|
"POST /api/registries/{id}/test"
|
|
]
|
|
},
|
|
{
|
|
"group": "Image Updates",
|
|
"pages": [
|
|
"GET /api/image-updates",
|
|
"POST /api/image-updates/refresh",
|
|
"GET /api/image-updates/status"
|
|
]
|
|
}
|
|
]
|
|
}
|
|
]
|
|
}
|
|
}
|