8 Commits

Author SHA1 Message Date
mkellermann97
2617b8372b release: v0.9.9 — FinOps, Sustainability, DR Drills, PWA + comprehensive Security Audit
Big release. New top-level features:
- Cost Dashboard / Chargeback — per-VM/tenant rollup, price book, recommendations, PDF + CSV export
- Power & Carbon Tracking — Redfish/IPMI/RAPL aggregation, kWh + CO₂e dashboard, PDF + CSV
- Network Topology Visualization — interactive nodes/bridges/bonds/VLANs/VMs map
- Snapshot Schedules — per-VM or per-tag cron with retention (count + age), 60s tick scheduler
- Config Drift Detection — 6h fingerprint scanner with sorted-CSV normalisation (no false positives on tags/content/nodes)
- SIEM Forwarder — Syslog (UDP/TCP, RFC 5424), Splunk HEC, Elasticsearch, Loki, generic webhook; per-target TLS verify, retry queue
- Cloud-Init Template Library — curated upstream cloud images + custom URL/upload, hardened deploy path
- PWA + Web Push — installable app, offline shell cache, VAPID push (no third-party gateway)
- Insights tab — capacity ETA, fragmentation, idle/oversized VMs, power outliers + PDF export
- Audit Search v2 — faceted full-text + CSV export, fail-closed HMAC chain incl. cluster + severity
- DR Drill Wizard — read-only 11-check structured dry-run for Site Recovery plans, JSON + PDF report

10 new blueprints registered; 4 background workers (drift scanner, SIEM forwarder, snapshot scheduler, push handler) — all idempotent + restart-safe.

Comprehensive security audit (3 rounds):
- C-1: command injection in template library — shlex.quote() + URL/regex whitelist
- H-1: CSRF skip on JSON POSTs — Origin/Referer enforced on every state-changing /api/*
- H-2: 21 transitive CVEs — cryptography 47, requests 2.33.1, pyOpenSSL 26.1, PyJWT 2.12.1, pyasn1 0.6.3, pillow 12.2.0; pip-audit clean
- M-1: VAPID private key encrypted at rest (AES-GCM, transparent migration)
- M-2: audit HMAC includes cluster + severity, fail-closed (legacy 5-field fallback for pre-0.9.9 entries)
- M-3: 17 str(e) leaks replaced with logging.exception() + generic message
- M-4: SIEM TLS verify per-target, default true (removed hardcoded verify=False)
- M-5: opaque session revocation token, constant-time compare
- M-10: V2P password scrubbed on phase=completed/failed
- M-11: webhook URL credential redactor before logging
- M-12: push endpoint host whitelist (RFC1918/loopback/metadata refused)
- B-1: api/push.py used flask.session instead of request.session (every push endpoint 401'd) — replaced with _current_user() helper

Air-gap mode hardening:
- /-route now injects localStorage flag prelude server-side when air_gap_mode=true so the very first page load on a fresh browser doesn't hit cdn.jsdelivr while waiting for /auth/check
- html2canvas onerror handlers (4 spots) refuse CDN fallback when air-gap is on
- html2canvas shipped locally (static/js/html2canvas.min.js)

Bumps:
- pegaprox/constants.py + web/src/constants.js → Beta 0.9.9, build 2026.05.03
- version.json → 0.9.9, update_files now 200 entries
- README.md extended with new feature sections; "What's New" block dropped in favour of GitHub releases as source of truth
- i18n: every new feature shipped in DE/EN/FR/ES/PT/KO/IT
2026-05-03 23:39:39 +02:00
MrMasterbay
cd44e39f57 feat: Predictive Load Balancing, CPU EVC, PDF templates, portal & status page improvements
- Predictive Load Balancing with trend analysis (DRS-like), configurable score weights (CPU/RAM/IO)
- CPU EVC compatibility mode: pre-migration CPU vendor/model checks, cluster baseline enforcement
- CPU compatibility matrix API for migration safety visualization
- Professional PDF export template (jsPDF + autoTable) replacing browser print dialogs
- Client Portal: dashboard overview, VM search/filter, XSS fixes, custom confirm modals,
  VNC loading state, skeleton loaders, light theme toggle, OIDC/LDAP login support
- Status Page: incident timeline, uptime tracking (90-day bar), maintenance banner,
  component-level status, embeddable SVG status badge
- User Management: folder system for organizing users, pagination (15/page),
  admin portal_only protection (prevents lockout)
- Sponsor: netwolk GmbH as first Platinum Sponsor
- Fix: cross-cluster migrate bridge mapping format (#274) — was using = instead of :
- Fix: OIDC callback now includes portal_only + redirect_after for portal SSO flow
2026-04-09 08:16:38 +02:00
Lukas Alstrup
b949338ead fix: sanitize markdown description output with DOMPurify to prevent XSS 2026-04-06 20:39:55 +02:00
Lukas Alstrup
7b747597e4 feat: markdown description, tag selector, DNS validation, compact view tags, resource filters 2026-04-06 20:19:41 +02:00
mkellermann97
1213c8abda feat: XCP-ng Tech Preview integration, ACME auto-renewal, misc fixes
- XCP-ng/XAPI pool manager with full VM lifecycle (create, clone, migrate, snapshots)
- VM power actions, disk/network/CD-ROM management via XAPI XML-RPC
- VNC console, maintenance mode, node details, ISO upload
- RBAC with xapi.* permissions (16 new permissions)
- XCP-ng cluster type in frontend with Tech Preview badge
- ACME/Let's Encrypt auto-renewal support
- Datastore uploads, offline operation fixes
- SSH WebSocket auth hardening
- Example nginx reverse proxy config
2026-03-08 12:33:00 +01:00
mkellermann97
50940e943f fix: offline operation + datastore uploads (#118, #119), bump v0.9.0.4
- replace Tailwind CDN JIT with static CLI build (65KB)
- non-blocking Google Fonts with system font fallback
- conditional preconnect hints (navigator.onLine check)
- RGB CSS variable channels for Tailwind opacity modifiers
- fix MAX_CONTENT_LENGTH race condition on file uploads
- file.stream.seek(0) before forwarding to PVE
- container template (.tar.gz/.tar.xz/.tar.zst) upload support
- update --download-static (Google Fonts woff2, skip tailwind overwrite)
- bump version to v0.9.0.4
2026-03-05 21:15:37 +01:00
Nico Schmidt
4e52844e20 0.6.6 Release 2026-02-15 16:41:00 +01:00
Nico Schmidt
153d7cc0f5 PegaProx Appears 2026-01-25 14:01:36 +01:00