Tau.Acuvim/portal/src/Tau.Acuvim.Portal/Services/ConfigOverviewService.cs
Diseri Pearson e17921a122 Add portal: customer-facing white-labeled monitoring stack
New top-level portal/ project, peer to console/ and firmware/. Delivers a
.NET 10 + React 18 + TimescaleDB + Grafana stack, one container set per
customer behind Traefik. Built in 12 phases per FrontEndPrompt spec; no
changes to existing console or firmware.

Backend (src/Tau.Acuvim.Portal/):
- .NET 10 minimal API, Serilog, ASP.NET Identity (cookie auth, lockout).
- Single AppDbContext with identity / app / monitoring schemas.
- MigrateAsync + TimescaleBootstrapper (idempotent hypertable creation)
  + IdentityBootstrapper (seeded admin + branding) on startup.
- Pure CostCalculator + DB-backed RateService for tariffs (effective-dated,
  TOU periods, VAT, fixed charges, per-municipality timezone).
- BrandingService with logo upload to mounted volume.
- Time-series ingest + bucketed query services (time_bucket aggregates,
  ON CONFLICT for idempotent re-delivery).
- ConfigOverviewService with redaction-by-construction (passwords never in
  payload).
- DataProtection keys persisted to /data/keys volume for cookie survival
  across container restarts.

Frontend (frontend/):
- React 18 + TypeScript + Vite + Ant Design 5 + TanStack Query.
- BrandingProvider + ThemedRoot for live re-themed white-labelling.
- RequireAuth / RequireRole guards.
- Pages: Login, Dashboard, Dashboards (embedded Grafana), Sites (admin),
  Settings tabs (Branding / Rates / Users / Grafana / App config).

Infra:
- Dev (docker-compose.yml) and prod (docker-compose.prod.yml) compose
  files. Three services per customer; Traefik subdomain + same-origin
  /grafana path-prefix routing wired with labels.
- Grafana 11 with provisioned timescaledb datasource (uid pinned) and
  starter power-overview.json dashboard with device template variable.
- Compose project name documented as lowercase (Compose v2 requirement).

Tests (tests/Tau.Acuvim.Portal.Tests/):
- xUnit, 40 tests. Covers CostCalculator (period match, TZ, overlap,
  VAT, fixed), ConnectionStringResolver (all 4 precedence branches incl.
  Production refusal), TariffValidator, DayOfWeekFlag.
- All passing locally against .NET 10.

Docs:
- README.md (onboarding + 11 spec sections), OPERATIONS.md (per-customer
  provisioning, secret rotation, backup, troubleshooting), TESTING.md
  (manual integration scenarios, frontend test scaffolding recipe).

Production safety guards:
- Refuses to start if Authentication:DefaultAdminPassword is unchanged
  default in Production.
- Refuses to start if Database:AutoProvisionLocalTimescaleDb=true in
  Production.
- Prod Grafana ships with anonymous off and auth mode unset (three
  options documented in README Security) so iframe refuses to load
  until a deliberate prod auth choice is made.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-18 09:30:30 +02:00

83 lines
2.9 KiB
C#

using Microsoft.Extensions.Options;
using Npgsql;
using Tau.Acuvim.Portal.Configuration;
using Tau.Acuvim.Portal.DTOs;
namespace Tau.Acuvim.Portal.Services;
// Captures the DB connection-resolution source at startup so the App-config view
// can show how the running container resolved its DB without re-parsing config.
public sealed class DatabaseResolutionInfo
{
public DatabaseResolutionInfo(string source) => Source = source;
public string Source { get; }
public DateTime StartedAtUtc { get; } = DateTime.UtcNow;
}
public sealed class ConfigOverviewService(
IOptions<ApplicationOptions> appOptions,
IOptions<DatabaseOptions> dbOptions,
IOptions<GrafanaOptions> grafanaOptions,
IOptions<MonitoringOptions> monitoringOptions,
IOptions<AuthenticationOptions> authOptions,
IHostEnvironment env,
DatabaseResolutionInfo dbResolution)
{
public ConfigOverviewDto Build()
{
var (host, port, database) = ParseConnection(dbOptions.Value.ConnectionString);
var application = new AppInfoDto(
appOptions.Value.Name,
env.EnvironmentName,
appOptions.Value.PublicUrl);
var database_ = new DatabaseInfoDto(
dbOptions.Value.Provider,
host, port, database,
dbOptions.Value.MigrateOnStartup,
dbOptions.Value.AutoProvisionLocalTimescaleDb,
dbResolution.Source);
var grafana = new GrafanaInfoDto(
grafanaOptions.Value.BaseUrl,
grafanaOptions.Value.InternalUrl,
grafanaOptions.Value.EmbedPathPrefix,
grafanaOptions.Value.EmbedMode,
grafanaOptions.Value.DefaultDashboardUid,
grafanaOptions.Value.AuthMode,
grafanaOptions.Value.Dashboards.Count);
var monitoring = new MonitoringInfoDto(
monitoringOptions.Value.ChunkTimeInterval,
monitoringOptions.Value.EnableHourlyAggregates);
var auth = new AuthInfoDto(
authOptions.Value.CookieName,
authOptions.Value.RequireConfirmedEmail,
authOptions.Value.DefaultAdminEmail);
var assembly = typeof(ConfigOverviewService).Assembly.GetName();
var build = new BuildInfoDto(
assembly.Version?.ToString() ?? "0.0.0",
Environment.Version.ToString(),
dbResolution.StartedAtUtc);
return new ConfigOverviewDto(application, database_, grafana, monitoring, auth, build);
}
private static (string Host, int Port, string Database) ParseConnection(string connectionString)
{
if (string.IsNullOrWhiteSpace(connectionString)) return ("(unset)", 0, "(unset)");
try
{
var b = new NpgsqlConnectionStringBuilder(connectionString);
return (b.Host ?? "(unset)", b.Port, b.Database ?? "(unset)");
}
catch
{
return ("(unparseable)", 0, "(unparseable)");
}
}
}