backup: pre-hardening baseline

This commit is contained in:
backup 2026-09-02 11:20:31 -05:00
commit 9e4c612dcb
57 changed files with 10393 additions and 0 deletions

View file

@ -0,0 +1,131 @@
package models
import "time"
type Router struct {
Name string `json:"name"`
Provider string `json:"provider"`
Rule string `json:"rule"`
EntryPoints []string `json:"entry_points"`
Service string `json:"service"`
Middlewares []string `json:"middlewares"`
Priority int `json:"priority"`
TLS *RouterTLSConfig `json:"tls,omitempty"`
Status string `json:"status"`
Using []string `json:"using,omitempty"`
}
type RouterTLSConfig struct {
Options string `json:"options,omitempty"`
CertResolver string `json:"cert_resolver,omitempty"`
Domains []Domain `json:"domains,omitempty"`
}
type Domain struct {
Main string `json:"main"`
SANs []string `json:"sans,omitempty"`
}
type Service struct {
Name string `json:"name"`
Provider string `json:"provider"`
Type string `json:"type"`
LoadBalancer *LoadBalancer `json:"load_balancer,omitempty"`
ServerStatus map[string]string `json:"server_status,omitempty"`
Status string `json:"status"`
}
type LoadBalancer struct {
Servers []Server `json:"servers,omitempty"`
Strategy string `json:"strategy,omitempty"`
PassHostHeader *bool `json:"pass_host_header,omitempty"`
HealthCheck *HealthCheck `json:"health_check,omitempty"`
}
type Server struct {
URL string `json:"url"`
Weight *int `json:"weight,omitempty"`
PreservePath bool `json:"preserve_path,omitempty"`
}
type HealthCheck struct {
Scheme string `json:"scheme,omitempty"`
Path string `json:"path,omitempty"`
Method string `json:"method,omitempty"`
Status int `json:"status,omitempty"`
Port int `json:"port,omitempty"`
Interval string `json:"interval,omitempty"`
Timeout string `json:"timeout,omitempty"`
Hostname string `json:"hostname,omitempty"`
FollowRedirects *bool `json:"follow_redirects,omitempty"`
Headers map[string]string `json:"headers,omitempty"`
}
type Middleware struct {
Name string `json:"name"`
Provider string `json:"provider"`
Type string `json:"type"`
Spec map[string]interface{} `json:"spec,omitempty"`
Status string `json:"status"`
}
type Certificate struct {
Name string `json:"name"`
CommonName string `json:"common_name"`
SANs []string `json:"sans"`
IssuerOrg string `json:"issuer_org"`
IssuerCN string `json:"issuer_cn"`
NotBefore time.Time `json:"not_before"`
NotAfter time.Time `json:"not_after"`
Status string `json:"status"`
Provider string `json:"provider"`
}
type EntryPoint struct {
Name string `json:"name"`
Address string `json:"address"`
HTTP *EntryPointHTTP `json:"http,omitempty"`
ForwardedHeaders *ForwardedHeaders `json:"forwarded_headers,omitempty"`
}
type EntryPointHTTP struct {
TLS *EntryPointTLS `json:"tls,omitempty"`
Middlewares []string `json:"middlewares,omitempty"`
RedirectToHTTPS bool `json:"redirect_to_https,omitempty"`
}
type EntryPointTLS struct {
CertResolver string `json:"cert_resolver,omitempty"`
Domains []Domain `json:"domains,omitempty"`
Options string `json:"options,omitempty"`
}
type ForwardedHeaders struct {
InsecureSkipVerify bool `json:"insecure_skip_verify,omitempty"`
TrustedIPs []string `json:"trusted_ips,omitempty"`
}
type Overview struct {
HTTP struct {
Routers Section `json:"routers"`
Services Section `json:"services"`
Middlewares Section `json:"middlewares"`
} `json:"http"`
TCP struct {
Routers Section `json:"routers"`
Services Section `json:"services"`
Middlewares Section `json:"middlewares"`
} `json:"tcp"`
UDP struct {
Routers Section `json:"routers"`
Services Section `json:"services"`
} `json:"udp"`
Certificates *Section `json:"certificates,omitempty"`
Providers []string `json:"providers,omitempty"`
}
type Section struct {
Total int `json:"total"`
Warnings int `json:"warnings"`
Errors int `json:"errors"`
}

View file

@ -0,0 +1,56 @@
package models
import (
"database/sql"
"time"
)
type User struct {
ID string `json:"id"`
Username string `json:"username"`
Email string `json:"email"`
PasswordHash string `json:"-"`
Role string `json:"role"`
CreatedAt time.Time `json:"created_at"`
UpdatedAt time.Time `json:"updated_at"`
LastLogin sql.NullTime `json:"last_login,omitempty"`
}
type Session struct {
ID string `json:"id"`
UserID string `json:"user_id"`
CSRFToken string `json:"-"`
CreatedAt time.Time `json:"created_at"`
ExpiresAt time.Time `json:"expires_at"`
}
type AuthResponse struct {
User *User `json:"user"`
Token string `json:"-"` // Not sent in JSON, only in cookie
}
type LoginRequest struct {
Username string `json:"username" binding:"required"`
Password string `json:"password" binding:"required"`
}
type UserRole string
const (
RoleAdmin UserRole = "admin"
RoleOperator UserRole = "operator"
RoleViewer UserRole = "viewer"
)
func (r UserRole) Can(permission string) bool {
switch r {
case RoleAdmin:
return true
case RoleOperator:
return permission != "users:write" && permission != "settings:write"
case RoleViewer:
return permission == "config:read" || permission == "traefik:read"
default:
return false
}
}