feat: marketplace modules and isolated container management

This commit is contained in:
ayde64
2026-10-07 23:18:02 +02:00
parent 564f7def1c
commit 7b121fa908
68 changed files with 2560 additions and 699 deletions

View File

@@ -26,7 +26,7 @@ Definition of Done:
- [x] PostgreSQL mit persistentem Volume
- [x] Migrationen (eigener Runner mit Advisory-Lock) + Seed (Rollen, Admin)
- [x] Login / Logout (Argon2id, serverseitige Sessions, HttpOnly-Cookies)
- [x] CSRF-Schutz, Rate Limiting, Account Lockout
- [x] CSRF-Schutz und IP-basiertes Rate Limiting
- [x] User-Modell & Rollen (ADMIN/USER, RBAC-Guards)
- [x] Audit-Log (LOGIN_SUCCESS, LOGIN_FAILED, LOGOUT)
- [x] Health-Endpoint (`/api/v1/health`)
@@ -58,7 +58,7 @@ Definition of Done: Modul-Datenmodell, Manifest, Installation, Registrierung, St
- [x] `modules`-Tabelle (Migration 002) mit Lifecycle-Status und eindeutigen Ports/Slugs
- [x] Manifest-Vertrag `module.json` (Zod: ID, Name, Version, Slug, Runtime, Entrypoint, Port 41000–41999, Healthcheck, apiVersion)
- [x] ZIP-Installer mit Manifest-Validierung, Größenlimit (10 MB) und **Zip-Slip-Schutz**
- [x] Modul-Prozess-Manager: Start/Stop (SIGTERM→SIGKILL) als Kindprozesse, minimale ENV (keine Plattform-Secrets), eigene Log-Dateien
- [x] Modul-Lifecycle: Compose-Containerstacks pro Modul, Datenbanken als separate Services und persistente Named Volumes
- [x] Healthcheck-Service mit Startup-Grace (10 Retries × 500 ms)
- [x] Lifecycle: INSTALLED → STARTING → RUNNING → STOPPING → STOPPED, ERROR, DISABLED
- [x] `GET/POST /api/v1/modules`, `POST :id/start|stop|restart`, `PATCH :id/enabled`, `GET :id/health`, `DELETE :id` (nur ADMIN)
@@ -139,4 +139,4 @@ Definition of Done: Modulübersicht, Benutzerverwaltung, Rechteverwaltung, Syste
## Nächste Schritte
- Einbindung bestehender Projekte als Module (ersetzt Phase 7; Infrastruktur steht seit Phase 3–8)
- Phase 10 – Security Hardening: Dependency/Container-Scans, HSTS, Backup/Restore, Pen-Tests
- Phase 10 – Security Hardening: Dependency/Container-Scans, HSTS, Backup/Restore, Pen-Tests