Files
monlet/web/README.md
Stanislav Rossovskii d6f9335398
Some checks failed
ci / openapi (push) Failing after 7s
ci / agent (push) Failing after 5s
ci / server (push) Failing after 6s
ci / stack-smoke (push) Has been skipped
ci / web (push) Failing after 5s
Add cron schedules and sync docs
2026-06-23 19:18:01 +04:00

2.5 KiB

Monlet Web

Dashboard for Monlet. Monitoring pages are read-only; agent admission and blacklist controls can mutate server state.

Stack

  • Next.js 16 (App Router)
  • React 19
  • TypeScript
  • Tailwind CSS v4
  • Typed API client generated from api/openapi.yaml

Commands

cd web
npm_config_cache=../.cache/npm npm install
npm_config_cache=../.cache/npm npm run dev

Build / lint / typecheck / smoke:

npm_config_cache=../.cache/npm npm run build
npm_config_cache=../.cache/npm npm run lint
npm_config_cache=../.cache/npm npm run typecheck
npm_config_cache=../.cache/npm npm run smoke

Do not install Node packages globally. Project dependencies live in web/node_modules; npm cache lives under repository .cache/npm.

Environment

Var Default Purpose
MONLET_API_BASE_URL http://127.0.0.1:8000 Server base URL (server-side fetch)
MONLET_API_TOKEN (none) Bearer token sent to server
MONLET_WEB_TIME_ZONE UTC IANA timezone used to render timestamps
MONLET_WEB_AUTH_USERNAME (none) Optional local web login username
MONLET_WEB_AUTH_PASSWORD (none) Optional local web login password
MONLET_WEB_SESSION_SECRET (none) Secret used to sign the web session cookie; required with local web login; at least 32 bytes
MONLET_WEB_SESSION_TTL_SEC 604800 Local web session lifetime
MONLET_WEB_TRUST_PROXY_AUTH false Trust X-Forwarded-User from an upstream auth proxy
NEXT_PUBLIC_MONLET_POLL_MS 10000 Browser polling interval in ms; build-time for production Next.js bundles

The API token never reaches the browser — all server calls happen in Server Components / route handlers. Agent admission actions are blocked unless local web login is configured or trusted proxy auth is enabled.

Production deployments should rate-limit /login at the reverse proxy. The app applies constant-time credential checks and a small fixed delay on failed login attempts, but it is not a full auth gateway.

The timezone switcher stores the selected mode in browser cookies, so each operator keeps their own default/browser/UTC preference.

Pages

  • / — redirects to /agents
  • /agents — agent list
  • /agents/blacklist — blocked agent keys
  • /agents/[id] — agent detail
  • /checks — current check states
  • /incidents — incident list
  • /events — events query
  • /outbox — notification outbox

API client

Types are generated from ../api/openapi.yaml into src/lib/api-types.ts via npm run gen:api.