feat(ssf): 实现安全事件一键连接与凭据托管
新增数据库驱动的 SecurityEventConnectionManager,复用 RFC 7662 机器 Client,自动完成 Discovery、Push Bearer 生成、Stream 创建、Verification、首次启用、零停机轮换和安全退役。 增加文件与 Kubernetes SecretStore、最小权限 RBAC、动态 Receiver/撤销水位/内省降级,以及系统设置管理页面。已通过全量 Go 测试、go vet、关键包竞态测试、27 个 Web 测试、类型检查、生产构建、Compose 和 Kubernetes dry-run。
This commit is contained in:
@@ -957,6 +957,34 @@ export interface ClientCustomizationSettingsUpdateRequest {
|
||||
iconPath?: string;
|
||||
}
|
||||
|
||||
export interface SecurityEventConnection {
|
||||
connectionId: string;
|
||||
transmitterIssuer: string;
|
||||
receiverEndpoint: string;
|
||||
audience?: string;
|
||||
streamId?: string;
|
||||
lifecycleStatus: 'connecting' | 'verifying' | 'bootstrap' | 'enabled' | 'degraded' | 'rotating' | 'disconnect_pending' | 'retiring' | 'error' | string;
|
||||
healthMode: 'disabled' | 'bootstrap' | 'push_healthy' | 'introspection_fallback' | string;
|
||||
managementClientId: string;
|
||||
lastVerificationAt?: string;
|
||||
lastErrorCategory?: string;
|
||||
version: number;
|
||||
}
|
||||
|
||||
export interface SecurityEventConnectionPrerequisites {
|
||||
oidcConfigured: boolean;
|
||||
introspectionClientConfigured: boolean;
|
||||
publicBaseUrlConfigured: boolean;
|
||||
managementClientId: string;
|
||||
}
|
||||
|
||||
export interface SecurityEventConnectionResponse {
|
||||
connected: boolean;
|
||||
lifecycleStatus?: 'disconnected' | string;
|
||||
connection?: SecurityEventConnection;
|
||||
prerequisites?: SecurityEventConnectionPrerequisites;
|
||||
}
|
||||
|
||||
export interface GatewayTask {
|
||||
id: string;
|
||||
kind: string;
|
||||
|
||||
Reference in New Issue
Block a user