Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
57 changes: 57 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,57 @@
name: CI

on:
push:
branches: [master, "cursor/**"]
pull_request:
branches: [master]

jobs:
check:
runs-on: ubuntu-latest
services:
mysql:
image: mysql:8.0
env:
MYSQL_ROOT_PASSWORD: root
MYSQL_DATABASE: asprom
MYSQL_USER: asprom
MYSQL_PASSWORD: asprom
ports:
- 3306:3306
options: >-
--health-cmd="mysqladmin ping -h localhost"
--health-interval=10s
--health-timeout=5s
--health-retries=5
env:
ASPROM_TEST_DB_HOST: 127.0.0.1
ASPROM_TEST_DB_PORT: 3306
ASPROM_TEST_DB_USER: asprom
ASPROM_TEST_DB_PASSWORD: asprom
ASPROM_TEST_DB_NAME: asprom
steps:
- uses: actions/checkout@v4

- uses: actions/setup-python@v5
with:
python-version: "3.11"

- name: Install system dependencies
run: |
sudo apt-get update
sudo apt-get install -y default-libmysqlclient-dev build-essential pkg-config

- name: Install Python dependencies
run: |
pip install -r requirements.txt
pip install pytest pytest-cov "testcontainers[mysql]" ruff mypy

- name: Run check script
env:
ASPROM_COV_FAIL_UNDER: "70"
ASPROM_RUN_MYPY: "1"
run: ./scripts/check.sh

- name: Docker build smoke test
run: docker build .
4 changes: 4 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
@@ -1,3 +1,7 @@
.env
*.swp
*.bak
__pycache__/
*.pyc
.coverage
.pytest_cache/
69 changes: 69 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -43,3 +43,72 @@ Access metrics about open ports and baseline deviations at:
### Nagios Integration
Use `aspromNagiosCheck.py` as a standard Nagios plugin to receive active alerts. The plugin will return CRITICAL status when unauthorized services are detected.

## Development

[![CI](https://github.com/daimoniac/asprom/actions/workflows/ci.yml/badge.svg)](https://github.com/daimoniac/asprom/actions/workflows/ci.yml)

Run the full project check before every commit:

```bash
ASPROM_COV_FAIL_UNDER=70 ./scripts/check.sh
```

Optional git pre-commit hook:

```bash
ln -sf ../../scripts/check.sh .git/hooks/pre-commit
```

Install Python dependencies (use a venv on Debian/Ubuntu — system Python is externally managed):

```bash
# one-time system packages (Debian/Ubuntu)
sudo apt install -y python3-venv default-libmysqlclient-dev pkg-config build-essential nmap

# create venv and install deps
./scripts/setup-venv.sh
source venv/bin/activate
```

Or manually:

```bash
python3 -m venv venv
source venv/bin/activate # not: venv/bin/activate
pip install -r requirements.txt pytest pytest-cov "testcontainers[mysql]" ruff mypy sqlalchemy
```

### Database migrations

- **Fresh Docker installs:** schema applied via `db/ddl.sql` on first MySQL container start.
- **Existing installs:** run `alembic stamp 001` then `alembic upgrade head`.
- **Future schema changes:** add Alembic revisions only.

Set `ASPROM_RUN_MIGRATIONS=1` in the asprom container to run `alembic upgrade head` on startup.

### Integration tests

Tests use `ASPROM_TEST_DB_*` environment variables (set automatically in CI via GitHub Actions MySQL service). Locally, a MySQL instance on `127.0.0.1` with database `asprom_test` is used by default.

### Local dev against production Kubernetes DB

Run the legacy Bottle GUI locally while port-forwarding the production MySQL service from Kubernetes:

```bash
./scripts/setup-venv.sh
source venv/bin/activate
./scripts/dev-prod.sh
```

The script discovers the MySQL service name via `kubectl` (default context `internal1`, namespace `asprom`), port-forwards it to `127.0.0.1:3307`, and starts `aspromGUI.py` on [http://127.0.0.1:8080](http://127.0.0.1:8080).

Override discovery if needed:

```bash
KUBE_CONTEXT=internal1 KUBE_NAMESPACE=asprom MYSQL_SERVICE=mysql ./scripts/dev-prod.sh
```

Set `ASPROM_DB_PASSWORD` if the script cannot read credentials from a Kubernetes secret.

**Warning:** this connects to production data. Scans and baseline changes affect live systems.

4 changes: 0 additions & 4 deletions __init__.py

This file was deleted.

149 changes: 149 additions & 0 deletions alembic.ini
Original file line number Diff line number Diff line change
@@ -0,0 +1,149 @@
# A generic, single database configuration.

[alembic]
# path to migration scripts.
# this is typically a path given in POSIX (e.g. forward slashes)
# format, relative to the token %(here)s which refers to the location of this
# ini file
script_location = %(here)s/alembic

# template used to generate migration file names; The default value is %%(rev)s_%%(slug)s
# Uncomment the line below if you want the files to be prepended with date and time
# see https://alembic.sqlalchemy.org/en/latest/tutorial.html#editing-the-ini-file
# for all available tokens
# file_template = %%(year)d_%%(month).2d_%%(day).2d_%%(hour).2d%%(minute).2d-%%(rev)s_%%(slug)s
# Or organize into date-based subdirectories (requires recursive_version_locations = true)
# file_template = %%(year)d/%%(month).2d/%%(day).2d_%%(hour).2d%%(minute).2d_%%(second).2d_%%(rev)s_%%(slug)s

# sys.path path, will be prepended to sys.path if present.
# defaults to the current working directory. for multiple paths, the path separator
# is defined by "path_separator" below.
prepend_sys_path = .


# timezone to use when rendering the date within the migration file
# as well as the filename.
# If specified, requires the tzdata library which can be installed by adding
# `alembic[tz]` to the pip requirements.
# string value is passed to ZoneInfo()
# leave blank for localtime
# timezone =

# max length of characters to apply to the "slug" field
# truncate_slug_length = 40

# set to 'true' to run the environment during
# the 'revision' command, regardless of autogenerate
# revision_environment = false

# set to 'true' to allow .pyc and .pyo files without
# a source .py file to be detected as revisions in the
# versions/ directory
# sourceless = false

# version location specification; This defaults
# to <script_location>/versions. When using multiple version
# directories, initial revisions must be specified with --version-path.
# The path separator used here should be the separator specified by "path_separator"
# below.
# version_locations = %(here)s/bar:%(here)s/bat:%(here)s/alembic/versions

# path_separator; This indicates what character is used to split lists of file
# paths, including version_locations and prepend_sys_path within configparser
# files such as alembic.ini.
# The default rendered in new alembic.ini files is "os", which uses os.pathsep
# to provide os-dependent path splitting.
#
# Note that in order to support legacy alembic.ini files, this default does NOT
# take place if path_separator is not present in alembic.ini. If this
# option is omitted entirely, fallback logic is as follows:
#
# 1. Parsing of the version_locations option falls back to using the legacy
# "version_path_separator" key, which if absent then falls back to the legacy
# behavior of splitting on spaces and/or commas.
# 2. Parsing of the prepend_sys_path option falls back to the legacy
# behavior of splitting on spaces, commas, or colons.
#
# Valid values for path_separator are:
#
# path_separator = :
# path_separator = ;
# path_separator = space
# path_separator = newline
#
# Use os.pathsep. Default configuration used for new projects.
path_separator = os

# set to 'true' to search source files recursively
# in each "version_locations" directory
# new in Alembic version 1.10
# recursive_version_locations = false

# the output encoding used when revision files
# are written from script.py.mako
# output_encoding = utf-8

# database URL. This is consumed by the user-maintained env.py script only.
# other means of configuring database URLs may be customized within the env.py
# file.
sqlalchemy.url = driver://user:pass@localhost/dbname


[post_write_hooks]
# post_write_hooks defines scripts or Python functions that are run
# on newly generated revision scripts. See the documentation for further
# detail and examples

# format using "black" - use the console_scripts runner, against the "black" entrypoint
# hooks = black
# black.type = console_scripts
# black.entrypoint = black
# black.options = -l 79 REVISION_SCRIPT_FILENAME

# lint with attempts to fix using "ruff" - use the module runner, against the "ruff" module
# hooks = ruff
# ruff.type = module
# ruff.module = ruff
# ruff.options = check --fix REVISION_SCRIPT_FILENAME

# Alternatively, use the exec runner to execute a binary found on your PATH
# hooks = ruff
# ruff.type = exec
# ruff.executable = ruff
# ruff.options = check --fix REVISION_SCRIPT_FILENAME

# Logging configuration. This is also consumed by the user-maintained
# env.py script only.
[loggers]
keys = root,sqlalchemy,alembic

[handlers]
keys = console

[formatters]
keys = generic

[logger_root]
level = WARNING
handlers = console
qualname =

[logger_sqlalchemy]
level = WARNING
handlers =
qualname = sqlalchemy.engine

[logger_alembic]
level = INFO
handlers =
qualname = alembic

[handler_console]
class = StreamHandler
args = (sys.stderr,)
level = NOTSET
formatter = generic

[formatter_generic]
format = %(levelname)-5.5s [%(name)s] %(message)s
datefmt = %H:%M:%S
1 change: 1 addition & 0 deletions alembic/README
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
Generic single-database configuration.
58 changes: 58 additions & 0 deletions alembic/env.py
Original file line number Diff line number Diff line change
@@ -0,0 +1,58 @@
import os
from logging.config import fileConfig

from sqlalchemy import engine_from_config, pool

from alembic import context

config = context.config

if config.config_file_name is not None:
fileConfig(config.config_file_name)

target_metadata = None


def _database_url() -> str:
if url := os.environ.get("ASPROM_DB_URL"):
return url
host = os.environ.get("ASPROM_TEST_DB_HOST", os.environ.get("MYSQL_HOST", "127.0.0.1"))
port = os.environ.get("ASPROM_TEST_DB_PORT", os.environ.get("MYSQL_PORT", "3306"))
user = os.environ.get("ASPROM_TEST_DB_USER", os.environ.get("MYSQL_USER", "asprom"))
password = os.environ.get("ASPROM_TEST_DB_PASSWORD", os.environ.get("MYSQL_PASSWORD", "asprom"))
database = os.environ.get("ASPROM_TEST_DB_NAME", os.environ.get("MYSQL_DATABASE", "asprom"))
return f"mysql+mysqldb://{user}:{password}@{host}:{port}/{database}"


def run_migrations_offline() -> None:
context.configure(
url=_database_url(),
target_metadata=target_metadata,
literal_binds=True,
dialect_opts={"paramstyle": "named"},
)

with context.begin_transaction():
context.run_migrations()


def run_migrations_online() -> None:
configuration = config.get_section(config.config_ini_section, {})
configuration["sqlalchemy.url"] = _database_url()
connectable = engine_from_config(
configuration,
prefix="sqlalchemy.",
poolclass=pool.NullPool,
)

with connectable.connect() as connection:
context.configure(connection=connection, target_metadata=target_metadata)

with context.begin_transaction():
context.run_migrations()


if context.is_offline_mode():
run_migrations_offline()
else:
run_migrations_online()
28 changes: 28 additions & 0 deletions alembic/script.py.mako
Original file line number Diff line number Diff line change
@@ -0,0 +1,28 @@
"""${message}

Revision ID: ${up_revision}
Revises: ${down_revision | comma,n}
Create Date: ${create_date}

"""
from typing import Sequence, Union

from alembic import op
import sqlalchemy as sa
${imports if imports else ""}

# revision identifiers, used by Alembic.
revision: str = ${repr(up_revision)}
down_revision: Union[str, Sequence[str], None] = ${repr(down_revision)}
branch_labels: Union[str, Sequence[str], None] = ${repr(branch_labels)}
depends_on: Union[str, Sequence[str], None] = ${repr(depends_on)}


def upgrade() -> None:
"""Upgrade schema."""
${upgrades if upgrades else "pass"}


def downgrade() -> None:
"""Downgrade schema."""
${downgrades if downgrades else "pass"}
14 changes: 14 additions & 0 deletions alembic/versions/001_baseline.py
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
"""Baseline schema — existing installs should stamp at this revision."""

revision = "001"
down_revision = None
branch_labels = None
depends_on = None


def upgrade() -> None:
pass


def downgrade() -> None:
pass
Loading
Loading