- C1: Replace innerHTML template literals with DOM textContent in sites_map.ts - C2: Derive user_id from current_scope instead of client params in policy consent - C3: Fix broken halt() in GDPR data export (orphaned _ = ... halt()) - C4: Add owner/admin authorization check to MembersController update/delete - C5: Require HMAC signature on agent release webhook (was optional) - C6: Fix Repo.all_by/2 (not a real Ecto function) → Repo.all with query - C7: Move auth exemption to before_send callback in BruteForceProtection - C8: Block </style>/<script injection in status page custom_css validation - C9: Create secrets.example.yaml with placeholders; secrets.yaml already gitignored - C10: Load Stripe key from STRIPE_SECRET_KEY env var instead of hardcoded value - C13: Remove credentials from PubSub backup broadcast; channel resolves them C11 (no force_ssl): by design — Cloudflared terminates TLS C12 (device quota race): false positive — FOR UPDATE serializes correctly
245 lines
8.7 KiB
Elixir
245 lines
8.7 KiB
Elixir
import Config
|
|
|
|
# Console backend configuration
|
|
config :logger, :console,
|
|
format: "[$level] $message\n",
|
|
metadata: []
|
|
|
|
# File backend configuration (writes to log/dev.log)
|
|
# Backend is registered in application.ex via LoggerBackends.add/1
|
|
config :logger, :file_log,
|
|
path: "log/dev.log",
|
|
level: :info,
|
|
format: "[$level] $message\n",
|
|
metadata: []
|
|
|
|
# Logger configuration
|
|
config :logger,
|
|
level: :info
|
|
|
|
# Configure file system watcher to ignore directories that don't need watching
|
|
# This prevents "too many open files" errors in development
|
|
config :phoenix, :code_reloader,
|
|
ignore: [
|
|
~r"deps/",
|
|
~r"_build/",
|
|
~r"node_modules/",
|
|
~r"assets/node_modules/",
|
|
~r"\.git/",
|
|
~r"priv/static/",
|
|
~r"priv/mibs/",
|
|
~r"e2e/",
|
|
~r"test/",
|
|
~r"cover/",
|
|
~r"doc/"
|
|
]
|
|
|
|
# Initialize plugs at runtime for faster development compilation
|
|
config :phoenix, :plug_init_mode, :runtime
|
|
|
|
# Set a higher stacktrace during development. Avoid configuring such
|
|
# in production as building large stacktraces may be expensive.
|
|
config :phoenix, :stacktrace_depth, 20
|
|
|
|
config :phoenix_live_view,
|
|
# Include debug annotations and locations in rendered markup.
|
|
# Changing this configuration will require mix clean and a full recompile.
|
|
debug_heex_annotations: true,
|
|
debug_attributes: true,
|
|
# Enable helpful, but potentially expensive runtime checks
|
|
enable_expensive_runtime_checks: true
|
|
|
|
# Disable swoosh api client as it is only required for production adapters.
|
|
config :swoosh, :api_client, false
|
|
|
|
# Configure Oban for background jobs
|
|
config :towerops, Oban,
|
|
repo: Towerops.Repo,
|
|
queues: [
|
|
default: 10,
|
|
discovery: 10,
|
|
# SNMP polling jobs - one per device
|
|
pollers: 50,
|
|
# Device monitoring jobs - health checks
|
|
monitors: 50,
|
|
# Alert notifications (PagerDuty, email, etc.)
|
|
notifications: 10,
|
|
maintenance: 5,
|
|
weather: 2,
|
|
# RF coverage prediction (CPU + GDAL/HTTP-range I/O heavy, slow)
|
|
coverage: 2
|
|
],
|
|
plugins: [
|
|
# Cron jobs for periodic maintenance tasks
|
|
{Oban.Plugins.Cron,
|
|
crontab: [
|
|
# Run neighbor cleanup every hour
|
|
{"0 * * * *", Towerops.Snmp.NeighborCleanupWorker},
|
|
# Check for stale agents every minute
|
|
{"* * * * *", Towerops.Workers.StaleAgentWorker},
|
|
# Cloud latency probes every 8 hours (00:00, 08:00, 16:00)
|
|
{"0 */8 * * *", Towerops.Workers.CloudLatencyProbeWorker},
|
|
# Evaluate latency-based agent reassignment 30 min after each probe batch
|
|
{"30 0,8,16 * * *", Towerops.Workers.AgentLatencyEvaluator},
|
|
# Health check for missing jobs every 10 minutes
|
|
{"*/10 * * * *", Towerops.Workers.JobHealthCheckWorker},
|
|
# Fetch latest firmware versions daily at 2 AM
|
|
{"0 2 * * *", Towerops.Workers.FirmwareVersionFetcherWorker},
|
|
# MikroTik configuration backups daily at 7 AM UTC
|
|
{"0 7 * * *", Towerops.Workers.MikrotikBackupWorker},
|
|
# Mark stale backup requests as timeout every 10 minutes
|
|
{"*/10 * * * *", Towerops.Workers.BackupTimeoutWorker},
|
|
# Send backup summary email daily at 8 AM
|
|
{"0 8 * * *", Towerops.Workers.BackupSummaryWorker},
|
|
# Delete expired IP bans every hour
|
|
{"0 * * * *", Towerops.Workers.ExpiredBanCleanupWorker},
|
|
# Delete stale violation records daily at 2 AM
|
|
{"0 2 * * *", Towerops.Workers.StaleViolationCleanupWorker},
|
|
# Sync Preseem data every 10 minutes
|
|
{"*/10 * * * *", Towerops.Workers.PreseemSyncWorker},
|
|
# Compute Preseem baselines and fleet profiles nightly at 2:30 AM
|
|
{"30 2 * * *", Towerops.Workers.PreseemBaselineWorker},
|
|
# Sync Gaiia data every 15 minutes
|
|
{"*/15 * * * *", Towerops.Workers.GaiiaSyncWorker},
|
|
# Device health insights nightly at 3:30 AM
|
|
{"30 3 * * *", Towerops.Workers.DeviceHealthInsightWorker},
|
|
# System insights (agent offline detection) every 5 minutes
|
|
{"*/5 * * * *", Towerops.Workers.SystemInsightWorker},
|
|
# Gaiia reconciliation insights nightly at 4:30 AM
|
|
{"30 4 * * *", Towerops.Workers.GaiiaInsightWorker},
|
|
# Backhaul capacity utilization insights every 15 minutes
|
|
{"*/15 * * * *", Towerops.Workers.CapacityInsightWorker},
|
|
# Sync device usage to Stripe daily at 3 AM UTC
|
|
{"0 3 * * *", Towerops.Workers.BillingSyncWorker}
|
|
]},
|
|
# Automatically delete completed jobs after 60 seconds
|
|
{Oban.Plugins.Pruner, max_age: 60},
|
|
# Rescue orphaned jobs (when node crashes)
|
|
{Oban.Plugins.Reindexer, schedule: "0 2 * * *"},
|
|
# Rescue jobs stuck in executing state (mark as cancelled after 10 minutes)
|
|
{Oban.Plugins.Lifeline, rescue_after: to_timeout(minute: 10)}
|
|
]
|
|
|
|
# Configure your database
|
|
# Configure your database
|
|
# In CI, DATABASE_URL is set and will be used automatically by Ecto.
|
|
# Locally, fall back to individual connection parameters.
|
|
if database_url = System.get_env("DATABASE_URL") do
|
|
config :towerops, Towerops.Repo,
|
|
url: database_url,
|
|
stacktrace: true,
|
|
show_sensitive_data_on_connection_error: true,
|
|
pool_size: 10
|
|
else
|
|
config :towerops, Towerops.Repo,
|
|
username: "postgres",
|
|
password: "postgres",
|
|
hostname: "localhost",
|
|
database: "towerops_dev",
|
|
stacktrace: true,
|
|
show_sensitive_data_on_connection_error: true,
|
|
pool_size: 10
|
|
end
|
|
|
|
# Configure Cloak encryption for development
|
|
# Use a fixed key for development (DO NOT use in production!)
|
|
config :towerops, Towerops.Vault,
|
|
ciphers: [
|
|
default: {
|
|
Cloak.Ciphers.AES.GCM,
|
|
# Development-only key - replace with env var in production
|
|
tag: "AES.GCM.V1", key: Base.decode64!("nQWmgQYhoCNXA3PAxwriKxLyPHAOWH9VgpLkBOXrowM=")
|
|
}
|
|
]
|
|
|
|
# For development, we disable any cache and enable
|
|
# debugging and code reloading.
|
|
#
|
|
# The watchers configuration can be used to run external
|
|
# watchers to your application. For example, we can use it
|
|
# to bundle .js and .css sources.
|
|
config :towerops, ToweropsWeb.Endpoint,
|
|
# Binding to loopback ipv4 address prevents access from other machines.
|
|
# Change to `ip: {0, 0, 0, 0}` to allow access from other machines.
|
|
http: [ip: {127, 0, 0, 1}],
|
|
check_origin: false,
|
|
code_reloader: true,
|
|
debug_errors: true,
|
|
secret_key_base: "ZA80pnF0GDr5/cb3jn/mtGjJPjg+0J68+MkglRQMlZNbxWYLPOAMCcYo2/rajclz",
|
|
watchers: [
|
|
esbuild: {Esbuild, :install_and_run, [:towerops, ~w(--sourcemap=inline --watch)]},
|
|
tailwind: {Tailwind, :install_and_run, [:towerops, ~w(--watch)]}
|
|
]
|
|
|
|
# ## SSL Support
|
|
#
|
|
# In order to use HTTPS in development, a self-signed
|
|
# certificate can be generated by running the following
|
|
# Mix task:
|
|
#
|
|
# mix phx.gen.cert
|
|
#
|
|
# Run `mix help phx.gen.cert` for more information.
|
|
#
|
|
# The `http:` config above can be replaced with:
|
|
#
|
|
# https: [
|
|
# port: 4001,
|
|
# cipher_suite: :strong,
|
|
# keyfile: "priv/cert/selfsigned_key.pem",
|
|
# certfile: "priv/cert/selfsigned.pem"
|
|
# ],
|
|
#
|
|
# If desired, both `http:` and `https:` keys can be
|
|
# configured to run both http and https servers on
|
|
# different ports.
|
|
|
|
# Reload browser tabs when matching files change.
|
|
config :towerops, ToweropsWeb.Endpoint,
|
|
live_reload: [
|
|
web_console_logger: true,
|
|
patterns: [
|
|
# Static assets, except user uploads
|
|
~r"priv/static/(?!uploads/).*\.(js|css|png|jpeg|jpg|gif|svg)$",
|
|
# Gettext translations
|
|
~r"priv/gettext/.*\.po$",
|
|
# Router, Controllers, LiveViews and LiveComponents
|
|
~r"lib/towerops_web/router\.ex$",
|
|
~r"lib/towerops_web/(controllers|live|components)/.*\.(ex|heex)$"
|
|
]
|
|
]
|
|
|
|
# Webhook secret for CI-triggered agent updates
|
|
config :towerops, :agent_webhook_secret, "dev-webhook-secret"
|
|
|
|
# Set environment identifier for runtime checks
|
|
config :towerops, :env, :dev
|
|
|
|
# Configure SNMP MIB directories for development
|
|
# Point to local priv/mibs subdirectories where MIB files are stored
|
|
# Note: The root mibs/ directory only contains symlinks to LibreNMS repo
|
|
# SNMP MIB directories for development
|
|
# MibTranslator automatically expands these to include subdirectories
|
|
config :towerops, :mib_dirs, [
|
|
Path.join([File.cwd!(), "priv", "mibs"]),
|
|
"/usr/share/snmp/mibs"
|
|
]
|
|
|
|
# Disable rate limiting in development
|
|
config :towerops, :rate_limiting_enabled, false
|
|
|
|
# Redis is not configured in development - application will use stub Agent
|
|
# If you need Redis for local development, set REDIS_HOST env var
|
|
|
|
# Configure SNMP polling interval for development (60 seconds)
|
|
config :towerops, :snmp_min_poll_interval, 60
|
|
|
|
# Enable dev routes for dashboard and mailbox
|
|
config :towerops, dev_routes: true
|
|
|
|
# Stripe configuration for development
|
|
config :towerops,
|
|
stripe_secret_key: System.get_env("STRIPE_SECRET_KEY", "sk_test_use_your_own_key"),
|
|
stripe_webhook_secret: "whsec_dev_fake_secret",
|
|
stripe_price_id: "price_1T81XBS77kvnTfgyPlw1jF8N",
|
|
stripe_meter_id: "mtr_test_61UHPU067veEZ7bhl41S77kvnTfgyODY"
|