towerops/config/dev.exs
Graham McIntire c7df6a8569
Add CI-triggered mass agent update webhook
POST /api/v1/webhooks/agent-release triggers all connected agents
to self-update via their existing WebSocket channels. Authenticated
with a shared secret (AGENT_WEBHOOK_SECRET env var).

- Add ReleaseChecker.invalidate_cache/0 for fresh GitHub fetch
- Add Agents.list_updatable_agents/0 (enabled + seen < 10min)
- Add Agents.broadcast_mass_update/0 orchestration function
- Add WebhookAuth plug with timing-safe secret comparison
- Add AgentReleaseWebhookController with :webhook pipeline
- Configure AGENT_WEBHOOK_SECRET in dev/test/runtime configs
2026-02-10 13:40:32 -06:00

192 lines
6.3 KiB
Elixir

import Config
# Disable Honeybadger in development
config :honeybadger,
environment_name: :dev,
exclude_envs: [:dev],
# Don't use custom filter in dev since Honeybadger is excluded
filter: Honeybadger.Filter.Default
# Console backend configuration
config :logger, :console,
format: "[$level] $message\n",
metadata: []
# File backend configuration (writes to log/dev.log)
# Backend is registered in application.ex via LoggerBackends.add/1
config :logger, :file_log,
path: "log/dev.log",
level: :info,
format: "[$level] $message\n",
metadata: []
# Logger configuration
config :logger,
level: :info
# Initialize plugs at runtime for faster development compilation
config :phoenix, :plug_init_mode, :runtime
# Set a higher stacktrace during development. Avoid configuring such
# in production as building large stacktraces may be expensive.
config :phoenix, :stacktrace_depth, 20
config :phoenix_live_view,
# Include debug annotations and locations in rendered markup.
# Changing this configuration will require mix clean and a full recompile.
debug_heex_annotations: true,
debug_attributes: true,
# Enable helpful, but potentially expensive runtime checks
enable_expensive_runtime_checks: true
# Disable swoosh api client as it is only required for production adapters.
config :swoosh, :api_client, false
# Configure Oban for background jobs
config :towerops, Oban,
repo: Towerops.Repo,
queues: [
default: 10,
discovery: 10,
# SNMP polling jobs - one per device
pollers: 50,
# Device monitoring jobs - health checks
monitors: 50,
maintenance: 5
],
plugins: [
# Cron jobs for periodic maintenance tasks
{Oban.Plugins.Cron,
crontab: [
# Run neighbor cleanup every hour
{"0 * * * *", Towerops.Snmp.NeighborCleanupWorker},
# Check for stale agents every minute
{"* * * * *", Towerops.Workers.StaleAgentWorker},
# Evaluate latency-based agent reassignment every 5 minutes
{"*/5 * * * *", Towerops.Workers.AgentLatencyEvaluator},
# Health check for missing jobs every 10 minutes
{"*/10 * * * *", Towerops.Workers.JobHealthCheckWorker},
# Fetch latest firmware versions daily at 2 AM
{"0 2 * * *", Towerops.Workers.FirmwareVersionFetcherWorker},
# MikroTik configuration backups daily at 7 AM UTC
{"0 7 * * *", Towerops.Workers.MikrotikBackupWorker},
# Mark stale backup requests as timeout every 10 minutes
{"*/10 * * * *", Towerops.Workers.BackupTimeoutWorker},
# Send backup summary email daily at 8 AM
{"0 8 * * *", Towerops.Workers.BackupSummaryWorker}
]},
# Automatically delete completed jobs after 60 seconds
{Oban.Plugins.Pruner, max_age: 60},
# Rescue orphaned jobs (when node crashes)
{Oban.Plugins.Reindexer, schedule: "0 2 * * *"},
# Rescue jobs stuck in executing state (mark as cancelled after 10 minutes)
{Oban.Plugins.Lifeline, rescue_after: to_timeout(minute: 10)}
]
# Configure your database
config :towerops, Towerops.Repo,
username: "postgres",
password: "postgres",
hostname: "localhost",
database: "towerops_dev",
stacktrace: true,
show_sensitive_data_on_connection_error: true,
pool_size: 10
# Configure Cloak encryption for development
# Use a fixed key for development (DO NOT use in production!)
config :towerops, Towerops.Vault,
ciphers: [
default: {
Cloak.Ciphers.AES.GCM,
# Development-only key - replace with env var in production
tag: "AES.GCM.V1", key: Base.decode64!("nQWmgQYhoCNXA3PAxwriKxLyPHAOWH9VgpLkBOXrowM=")
}
]
# For development, we disable any cache and enable
# debugging and code reloading.
#
# The watchers configuration can be used to run external
# watchers to your application. For example, we can use it
# to bundle .js and .css sources.
config :towerops, ToweropsWeb.Endpoint,
# Binding to loopback ipv4 address prevents access from other machines.
# Change to `ip: {0, 0, 0, 0}` to allow access from other machines.
http: [ip: {127, 0, 0, 1}],
check_origin: false,
code_reloader: true,
debug_errors: true,
secret_key_base: "ZA80pnF0GDr5/cb3jn/mtGjJPjg+0J68+MkglRQMlZNbxWYLPOAMCcYo2/rajclz",
watchers: [
esbuild: {Esbuild, :install_and_run, [:towerops, ~w(--sourcemap=inline --watch)]},
tailwind: {Tailwind, :install_and_run, [:towerops, ~w(--watch)]}
]
# ## SSL Support
#
# In order to use HTTPS in development, a self-signed
# certificate can be generated by running the following
# Mix task:
#
# mix phx.gen.cert
#
# Run `mix help phx.gen.cert` for more information.
#
# The `http:` config above can be replaced with:
#
# https: [
# port: 4001,
# cipher_suite: :strong,
# keyfile: "priv/cert/selfsigned_key.pem",
# certfile: "priv/cert/selfsigned.pem"
# ],
#
# If desired, both `http:` and `https:` keys can be
# configured to run both http and https servers on
# different ports.
# Reload browser tabs when matching files change.
config :towerops, ToweropsWeb.Endpoint,
live_reload: [
web_console_logger: true,
patterns: [
# Static assets, except user uploads
~r"priv/static/(?!uploads/).*\.(js|css|png|jpeg|jpg|gif|svg)$",
# Gettext translations
~r"priv/gettext/.*\.po$",
# Router, Controllers, LiveViews and LiveComponents
~r"lib/towerops_web/router\.ex$",
~r"lib/towerops_web/(controllers|live|components)/.*\.(ex|heex)$"
]
]
# Webhook secret for CI-triggered agent updates
config :towerops, :agent_webhook_secret, "dev-webhook-secret"
# Set environment identifier for runtime checks
config :towerops, :env, :dev
# Configure SNMP MIB directories for development
# Point to local priv/mibs subdirectories where MIB files are stored
# Note: The root mibs/ directory only contains symlinks to LibreNMS repo
# SNMP MIB directories for development
# MibTranslator automatically expands these to include subdirectories
config :towerops, :mib_dirs, [
Path.join([File.cwd!(), "priv", "mibs"]),
"/usr/share/snmp/mibs"
]
# Disable rate limiting in development
config :towerops, :rate_limiting_enabled, false
# Configure Redis/Valkey for development
config :towerops, :redis,
host: "localhost",
port: 6379
# Configure SNMP polling interval for development (60 seconds)
config :towerops, :snmp_min_poll_interval, 60
# Enable dev routes for dashboard and mailbox
config :towerops, dev_routes: true