Rewrite the README as highlights with screenshots; move the detail into docs/ #43

Merged
niklas merged 4 commits from operator-key-and-docs into main 2026-10-09 13:34:16 +00:00
Owner
No description provided.
niklas added 2 commits 2026-10-09 12:59:57 +00:00
The README was 1,240 lines of reference material and still described a
SQLite quick start. It is now a short tour (highlights, screenshots of the
web UI, an accurate quick start against Postgres), and each topic has its
own page under docs/ with an index: deployment, configuration, Alertmanager,
incidents, notifications, escalation, dead man's switches, single sign-on,
web UI, API and development. SERVICE-ACCOUNTS.md is rewritten from a
proposal into a reference, and TEAM-LOOKUP.md is gone with the endpoint it
described. The "Upgrading to ..." sections for an unreleased product are
dropped.

Claude-Session: https://claude.ai/code/session_016mBLURvJoMuUEr9cB2RpUN
Let an operator authenticate with a seeded key, and reset the schema
CI / chart (pull_request) Successful in 2s
CI / security (pull_request) Failing after 19s
CI / test (pull_request) Successful in 5m34s
9029d48584
- TERDUT_OPERATOR_KEY creates or re-keys the instance-scoped service account
  "terdut-operator" at every start, so terdut-operator needs no bootstrap
  handshake. An instance-scoped account now acts as owner of every team's
  configuration, but is not a member of any team.
- POST /api/teams takes an external_id (instance service accounts only) and
  is idempotent on it, so automation finds its own team again after a crash
  instead of adopting by display name. GET /api/teams?name= is removed.
- Integration and dead man's switch names are unique per team (409). The
  escalation PUT accepts usernames and resolves them itself.
- The 18 migrations are squashed into 001_schema.sql, with no Default team.
  TERDUT_DEADMAN_* and the env seeding of switches are removed: teams carry
  their own. Existing development databases must be recreated.

Security and robustness:
- GET /api/users no longer returns other people's email or ntfy topic to
  non-admins.
- The access log records the route pattern, so integration keys and ack
  tokens in the path are not written to the log. Server errors are logged.
- Rate limits take the client address TERDUT_TRUSTED_PROXIES hops from the
  right of X-Forwarded-For instead of trusting the first, forgeable entry.
- /api/bootstrap runs in a transaction under an advisory lock, so two
  concurrent calls cannot both create an administrator.
- API key last_used_at is written at most every five minutes.

Cleanup: remove GET /api/incidents/{id}/alerts, unused exports, SQLite
remnants in comments and config.

Claude-Session: https://claude.ai/code/session_016mBLURvJoMuUEr9cB2RpUN
niklas added 1 commit 2026-10-09 13:17:05 +00:00
Build and scan with Go 1.26.9
CI / chart (pull_request) Successful in 3s
CI / security (pull_request) Failing after 4m29s
CI / test (pull_request) Successful in 8m47s
eb63e5e138
govulncheck in the security job reports ten standard-library
vulnerabilities (net/http, mime/multipart, crypto/tls), all fixed in
1.26.9. The workflows pinned golang:1.26.6-bookworm.

Claude-Session: https://claude.ai/code/session_016mBLURvJoMuUEr9cB2RpUN
niklas added 1 commit 2026-10-09 13:27:49 +00:00
Satisfy gosec on the proxy count and the request log
CI / chart (pull_request) Successful in 3s
CI / security (pull_request) Successful in 25s
CI / test (pull_request) Successful in 5m42s
01922291f6
G115: the trusted-proxy count is stored as an int64 instead of narrowing
it to int32. G706: the request logger and serverError quote the request
method and route; the logger's remaining taint comes from the wrapped
response writer, so it carries a justified nosec like the other quoted log
lines.

Claude-Session: https://claude.ai/code/session_016mBLURvJoMuUEr9cB2RpUN
niklas merged commit 30b3f0ff75 into main 2026-10-09 13:34:16 +00:00
Sign in to join this conversation.