hub v0.132.0: the System page (versions + OS updates with the ring/switch/approve buttons, R-852), the Hosts Proxmox/kernel column, the operator-approved Docker engine release (2 healthy ring-0 nights), the crash-guard events (R-851); evidence audits/os-docker-crash-2026-10-04
gates / gates (push) Successful in 30s

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-04 16:16:02 +02:00
parent bee277ffad
commit 175ecfcdd2
45 changed files with 2198 additions and 12 deletions
+24
View File
@@ -2,7 +2,9 @@ package web
import (
"encoding/json"
"fmt"
"net/http"
"net/url"
"strconv"
"strings"
)
@@ -12,13 +14,27 @@ import (
// POST /os/ring/<host_id> ring=0|1
// POST /os/enabled/<host_id> on=1|0
// POST /os/approve-now approve the current ring-0 set at once (an operator event)
// POST /os/approve-docker approve the Docker engine set ring 0 ran 2 healthy nights (`11` §5.8)
// (a form field return=/system makes any POST answer with a redirect to the System page)
// GET /os/fleet one line per box (JSON)
func (s *Server) handleOSAdmin(w http.ResponseWriter, r *http.Request, path string) {
if s.osUpdates == nil {
http.Error(w, "os updates not configured", http.StatusServiceUnavailable)
return
}
// A button on the System page posts return=/system: answer with a redirect and a flash, never JSON.
fromPage := r.Method == http.MethodPost && r.FormValue("return") == "/system"
reply := func(v any, err error) {
if fromPage {
q := "flash=done"
if err != nil {
q = "err=" + url.QueryEscape(err.Error())
} else if m, ok := v.(map[string]string); ok && m["release_id"] != "" {
q = "flash=" + url.QueryEscape("approved "+m["release_id"])
}
http.Redirect(w, r, "/system?"+q, http.StatusSeeOther)
return
}
if err != nil {
http.Error(w, err.Error(), http.StatusBadRequest)
return
@@ -46,6 +62,14 @@ func (s *Server) handleOSAdmin(w http.ResponseWriter, r *http.Request, path stri
case r.Method == http.MethodPost && path == "/os/approve-now":
id, err := s.osUpdates.ApproveNow()
reply(map[string]string{"release_id": id}, err)
case r.Method == http.MethodPost && path == "/os/approve-docker":
view, ok := s.osUpdates.(OSSystemView)
if !ok {
reply(nil, fmt.Errorf("docker approval not available"))
return
}
id, err := view.ApproveDocker()
reply(map[string]string{"release_id": id}, err)
default:
http.Error(w, "not found", http.StatusNotFound)
}