Commit Graph
474 Commits
Author SHA1 Message Date
github-actions[bot] 0b9534668e chore: update manifest image to 1.0.296 [skip ci] 2026-04-16 07:10:56 +00:00
junvandCopilot 11fa2ad673 routermon: replace ISP column with Target Service badge in WAN table
- Remove ISP column (always empty with local MMDB — no ISP data)
- Add Target Service column with color-coded badges (SSH/RDP/VNC/SMB=red,
  HTTP/HTTPS=blue, MySQL/PostgreSQL/Redis/MongoDB=purple, SMTP/POP3/IMAP=green,
  DNS=yellow, FTP=orange)
- Restore inline service label in Dst Port cell (e.g. '22 SSH')
- Expand port mapping: 21 ports covered (FTP, Telnet, SMTP, DNS, POP3,
  IMAP, SMB, MSSQL, MySQL, RDP, PostgreSQL, VNC, Redis, HTTP-alt,
  HTTPS-alt, Elasticsearch, MongoDB)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-04-16 17:06:55 +10:00
github-actions[bot] f8a341f932 chore: update manifest image to 1.0.294 [skip ci] 2026-04-16 06:49:42 +00:00
junvandCopilot 3955e95b9e geo: replace ip-api.com with local DB-IP City Lite MMDB
- Rewrite nginxmon/geo.py to use maxminddb + DB-IP City Lite MMDB
  (https://cdn.jsdelivr.net/npm/dbip-city-lite/dbip-city-lite.mmdb.gz)
  instead of ip-api.com HTTP API — eliminates all network timeouts and
  rate-limit issues; lookups are now sub-millisecond in-process
- Keep _lookup_batch() signature unchanged so routermon receiver
  requires no changes
- MMDB downloaded on first use (lazy) and refreshed monthly via
  APScheduler; reader cached module-level (thread-safe for reads)
- Add management command: manage.py download_geo_db
- Update k8s init container to download MMDB on first deploy if absent
- Add maxminddb==3.1.1 dependency

CC BY 4.0 — DB-IP (https://db-ip.com)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-04-16 16:44:02 +10:00
github-actions[bot] c66295cb87 chore: update manifest image to 1.0.293 [skip ci] 2026-04-16 06:39:42 +00:00
junvandCopilot 60dd5aeffb routermon: break chunk loop early when circuit breaker fires
Stop sending further API requests mid-batch once the backoff is
triggered, saving remaining missing IPs as empty placeholders
immediately instead of waiting for them to timeout one-by-one.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-04-16 16:35:00 +10:00
github-actions[bot] 52c39ebdb1 chore: update manifest image to 1.0.292 [skip ci] 2026-04-16 06:30:02 +00:00
junvandCopilot dde1c6640c routermon: add circuit breaker for ip-api.com geo lookups
After _GEO_MISS_THRESHOLD (2) consecutive large all-empty API responses,
assume ip-api.com is unreachable and enter a 5-minute backoff.
During backoff all missing IPs are immediately saved as empty IPGeoCache
placeholders so they are not re-queued. Resets automatically when the
backoff expires and any result is returned.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-04-16 16:24:33 +10:00
github-actions[bot] f8ee2fe2a7 chore: update manifest image to 1.0.291 [skip ci] 2026-04-16 06:17:09 +00:00
junvandCopilot cfca2c2ed7 routermon: add WAN geo map + fix batch geo enrichment
- Add WanGeoStatsView (api/wan/geo/) returning country choropleth +
  bubble data for WAN source IPs using IPGeoCache lat/lon
- Add wanGeoMap (420px) in dashboard between ports chart and live table:
  red colour scale by country, rose bubbles sized by attempt count,
  top-5 country legend
- Rewrite _geo_worker_loop to drain up to 200 queue items per cycle,
  bulk DB cache check, batch API calls (100 IPs per request) instead
  of 1 request per IP — fixes ip-api.com timeout pile-up under scan
  volumes
- Add _geo_skip in-memory set: IPs that return no geo data get an
  empty IPGeoCache placeholder saved to DB so they are never retried;
  skip set also prevents re-queuing known-empty IPs during flush
- Remove _fetch_geo / _enrich_dns_geo / _enrich_wan_geo helpers
  (logic consolidated into the new batch worker)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-04-16 16:13:30 +10:00
github-actions[bot] dcbd1fe679 chore: update manifest image to 1.0.290 [skip ci] 2026-04-16 05:38:09 +00:00
junvandCopilot 430ca18b41 routermon: add WAN incoming traffic monitoring
- Add WanEvent model (src_ip, protocol, dst_port, src_port, geo fields)
  with migration 0003_wanevent

- Extend parser to handle kernel:/iptables WAN_IN: syslog lines
  - Generalise _RE_SYSLOG to accept 'kernel' process name (no pid)
  - Parse KEY=value tokens from iptables log (robust vs monolithic regex)
  - Reject private source IPs silently

- Receiver: bulk-create WanEvent rows in _flush(); replace per-flush
  geo threads with a single bounded geo-enrichment worker (_geo_queue,
  max 500) to safely handle high-volume port scans

- Tasks: batch-delete WanEvent rows (<=3 day retention cap); batch-delete
  DnsQuery rows to avoid long SQLite locks

- Views: WanLivePartialView (filterable HTMX table), WanChartDataView
  (timeline JSON); dashboard context adds wan_total_24h,
  top_attacked_ports_json, top_wan_sources

- Templates:
  - _live_wan.html: live event table with color-coded protocol,
    clickable IP/port filters, well-known port labels
  - dashboard.html: WAN section with 24h counter, timeline chart,
    top attacked ports bar chart, top source IPs table, live event stream
  - settings.html: Step 5 guide for /jffs/scripts/firewall-start with
    rate-limited iptables LOG rules (INPUT + FORWARD chains, 60/min limit)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-04-16 15:34:39 +10:00
github-actions[bot] 8d4a3d7843 chore: update manifest image to 1.0.289 [skip ci] 2026-04-16 05:02:04 +00:00
junvandCopilot 611305b0ab fix(routermon): fix receiver startup, logging config, and JS template escaping
- Remove SO_REUSEADDR from UDP socket so only one gunicorn worker binds
  port 5514 (second worker intentionally gets EADDRINUSE and skips)
- Add print() fallback for bind confirmation/errors so startup is visible
  even when Django logging config is not fully set up
- Fix duplicate LOGGING dict in settings.py: second assignment was
  overriding the first and removing the root logger handler, silently
  swallowing all routermon/core startup logs
- Add sys.stderr fallback in core/apps.py ready() for startup exceptions
- Fix JS SyntaxError: {{ top_domains_json }} needs |safe filter since
  Django auto-escapes quotes to &quot; inside script tags

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-04-16 14:58:39 +10:00
junv 3d481385b0 Update 2026-04-16 14:26:28 +10:00
github-actions[bot] 1574fb53f1 chore: update manifest image to 1.0.288 [skip ci] 2026-04-16 04:22:21 +00:00
junv 1fb54880d6 fix build 2026-04-16 14:18:46 +10:00
junv 7e0db3cdfb fix ci 2026-04-16 14:15:15 +10:00
junv 3409fc8045 fix build 2026-04-16 14:12:21 +10:00
junv 5b1df2ee5e Add router monitor 2026-04-16 14:01:43 +10:00
github-actions[bot] b3b6f77c84 chore: update manifest image to 1.0.283 [skip ci] 2026-04-14 04:58:25 +00:00
junv 864166ecbd ci: fix Python setup — use setup-uv python-version instead of separate install step 2026-04-14 14:54:48 +10:00
github-actions[bot] a07b0b181e chore: update manifest image to 1.0.280 [skip ci] 2026-04-14 04:47:49 +00:00
junvandGitHub af73cdf267 Merge pull request #77 from wahyd4/dependabot/uv/pillow-12.2.0
Bump pillow from 12.1.1 to 12.2.0
2026-04-14 14:44:04 +10:00
junvandGitHub 4cd667b067 Merge pull request #78 from wahyd4/dependabot/uv/pytest-9.0.3
Bump pytest from 8.3.4 to 9.0.3
2026-04-14 14:43:52 +10:00
junvandGitHub d85402e98a Merge pull request #57 from wahyd4/dependabot/npm_and_yarn/minimatch-9.0.9
Bump minimatch from 9.0.5 to 9.0.9
2026-04-14 14:43:38 +10:00
junv 04aad674e4 Test 2026-04-14 14:42:54 +10:00
junvandGitHub a8351dab76 Merge pull request #80 from wahyd4/remove-knowledge-graph
K8s template
2026-04-14 14:35:22 +10:00
junv 6a82b59863 ci: skip workflow when only k8s/ files change to prevent commit loop 2026-04-14 14:33:39 +10:00
junv a04aa1b828 chore: add manifest template and update deploy step to commit rendered manifest 2026-04-14 14:32:30 +10:00
junvandGitHub ba7daaa879 Merge pull request #79 from wahyd4/remove-knowledge-graph
Remove knowledge graph feature
2026-04-14 12:05:46 +10:00
junv 049d417cc8 Remove knowledge graph feature
The knowledge graph feature (links graph) was not functioning correctly
and was slowing down the application. This commit removes it entirely:

- Delete knowledge_graph_urls.py, knowledge_graph_views.py, llm_client.py
- Delete knowledge_graph.html template
- Remove KnowledgeGraphSnapshot model and all llm_*/kg_* fields from
  SiteSettings (migration 0048)
- Remove build_knowledge_graph() and schedule_kg_build() from tasks.py
- Remove KG settings save logic and bulk delete action from views.py
- Remove knowledge_graph_urls include from links/urls.py
- Remove schedule_kg_build scheduler job from core/apps.py
- Remove KG snapshot job registry from links/apps.py
- Remove Knowledge Graph nav item from base.html
- Remove KG settings cards and llmSettingsHelper JS from settings.html
2026-04-14 12:04:44 +10:00
dependabot[bot]andGitHub d3aa50794a Bump pytest from 8.3.4 to 9.0.3
Bumps [pytest](https://github.com/pytest-dev/pytest) from 8.3.4 to 9.0.3.
- [Release notes](https://github.com/pytest-dev/pytest/releases)
- [Changelog](https://github.com/pytest-dev/pytest/blob/main/CHANGELOG.rst)
- [Commits](https://github.com/pytest-dev/pytest/compare/8.3.4...9.0.3)

---
updated-dependencies:
- dependency-name: pytest
  dependency-version: 9.0.3
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-04-14 00:22:04 +00:00
dependabot[bot]andGitHub 19ea20485d Bump pillow from 12.1.1 to 12.2.0
Bumps [pillow](https://github.com/python-pillow/Pillow) from 12.1.1 to 12.2.0.
- [Release notes](https://github.com/python-pillow/Pillow/releases)
- [Changelog](https://github.com/python-pillow/Pillow/blob/main/CHANGES.rst)
- [Commits](https://github.com/python-pillow/Pillow/compare/12.1.1...12.2.0)

---
updated-dependencies:
- dependency-name: pillow
  dependency-version: 12.2.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-04-13 23:41:28 +00:00
junv bf11b675e8 Update ui 2026-04-01 21:52:29 +11:00
junv 3e6d348554 Update ui 2026-04-01 21:52:26 +11:00
junv e89825a114 Add auto ban feature! 2026-04-01 21:33:07 +11:00
junv 0d489e658e Update mini app 2026-04-01 21:06:22 +11:00
junv 70fbb78a54 ui update 2026-04-01 20:27:01 +11:00
junv 57516a3c9c minor fix! 2026-04-01 20:20:25 +11:00
junv 5fee444db9 Update 2026-04-01 20:02:57 +11:00
junv 1d1fb2db55 Exclude ips 2026-04-01 19:56:46 +11:00
junv 99b35dc934 Update UI 2026-04-01 19:44:31 +11:00
junv 14ffb118c7 Update 2026-04-01 19:36:28 +11:00
junv 179702ac6d Fix nginx logs ingestion! 2026-04-01 19:26:47 +11:00
junv 26d3ac9607 Fix docker build 2026-04-01 18:58:00 +11:00
junv cc4e66b945 Add geo 2026-04-01 18:44:29 +11:00
junv ccee1f408e ignore db sqlite file 2026-04-01 15:57:02 +11:00
junv 0b564ec19c Update 2026-04-01 15:54:07 +11:00
junv 7eb002a437 Add nginx visualization 2026-04-01 15:51:20 +11:00