admin: internal-only superadmin console (users, payments, DB stats)
New independent `admin` service (admin.main:app) on the same image, reusing app.db/app.models read-only. Never runs migrations or the scheduler; issues SELECTs only. - Password-gated (ADMIN_CONSOLE_PASSWORD) with a 12h signed cookie; closed by default when the password is empty. - Bound to 127.0.0.1:8091 (SSH-tunnel access); off the intranet/NPM network. - Pages: overview stats, user list + search, per-user history/payment detail, DB usage (information_schema size + row estimates). - Compose: base `admin` service (+prod DB-host override, test mount); Dockerfile bakes admin/ into runtime + test stages. - Tests: tests/test_admin_console.py (auth, queries, page wiring) — 12 passing. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
parent
8946dee2e0
commit
411094d7b8
20 changed files with 1143 additions and 1 deletions
|
|
@ -50,6 +50,17 @@ class Settings(BaseSettings):
|
|||
# created. Phase A leaves this open so the operator can self-onboard.
|
||||
CASSANDRA_SIGNUP_ENABLED: bool = True
|
||||
|
||||
# Superadmin console (independent container, internal-only — bound to
|
||||
# 127.0.0.1 on the VPS, reached via SSH tunnel). Read-only operator
|
||||
# dashboard: user list, per-user history/payment status, DB usage stats.
|
||||
# A single shared password gates it; empty ADMIN_CONSOLE_PASSWORD makes
|
||||
# every login attempt fail (the console is closed rather than open by
|
||||
# default, so a fresh deploy can't accidentally expose it).
|
||||
ADMIN_CONSOLE_PASSWORD: str = ""
|
||||
# Signing secret for the console's session cookie. Falls back to
|
||||
# CASSANDRA_SESSION_SECRET / CASSANDRA_TOKEN like the main app's cookie.
|
||||
ADMIN_CONSOLE_SESSION_SECRET: str = ""
|
||||
|
||||
# SMTP for email OTP verification. If SMTP_SERVER is empty, OTP codes
|
||||
# are written to stdout instead of sent — convenient for local dev.
|
||||
SMTP_SERVER: str = ""
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue