Harden auth scopes, SQL/WebCRT gates, and per-install JWT secrets.

Add capability RBAC, Alembic bootstrap, optional worker schedulers, and close public docs by default so lab installs stay usable without shared signing keys.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
oliver 2026-08-02 16:24:34 +08:00
parent cb8e0d23c5
commit 633a9d55bd
38 changed files with 1808 additions and 452 deletions

View file

@ -37,9 +37,21 @@ NETX_UME_ALARM_WS_ENABLED=true
NETX_UME_NOTIFICATION_ESTABLISH_PATH=/restconf/operations/zte-notifications:establish-subscription
NETX_UME_NOTIFICATION_DELETE_PATH=/restconf/operations/zte-notifications:delete-subscription
NETX_UME_NOTIFICATION_TOPIC=ALARM
# Auth (optional — lab defaults: admin/admin123 + data/auth/mcp_token)
# TLS verify for UME (default true). Set false only for lab self-signed certs.
# NETX_UME_VERIFY_TLS=true
# Auth (lab defaults: admin/admin123 + data/auth/mcp_token)
# NETX_AUTH_ENABLED=true
# NETX_AUTH_SECRET=change-me-in-production
# Leave NETX_AUTH_SECRET empty to auto-create data/auth/jwt_secret on first boot.
# NETX_AUTH_SECRET=
# NETX_AUTH_SECRET_FILE=data/auth/jwt_secret
# NETX_BOOTSTRAP_ADMIN_USERNAME=admin
# NETX_BOOTSTRAP_ADMIN_PASSWORD=admin123
# NETX_API_TOKEN= # MCP: leave empty to auto-read data/auth/mcp_token
# API docs (/docs, /redoc, /openapi.json); default false. Lab: set true.
# NETX_DOCS_ENABLED=true
# NETX_ALLOW_INSECURE_DEFAULTS=false
# NETX_SKIP_LEGACY_STARTUP_DDL=true
# NETX_SQL_READONLY_DATABASE_URL=postgresql+psycopg://netx_ro:xxx@127.0.0.1:5432/netx
# NETX_RUN_INLINE_SCHEDULERS=true
# NETX_AUDIT_ASYNC=true
# NETX_AUDIT_SAMPLE_N=1