2.5 KiB
Monlet Web
Dashboard for Monlet. Monitoring pages are read-only; agent admission and blacklist controls can mutate server state.
Stack
- Next.js 16 (App Router)
- React 19
- TypeScript
- Tailwind CSS v4
- Typed API client generated from
api/openapi.yaml
Commands
cd web
npm_config_cache=../.cache/npm npm install
npm_config_cache=../.cache/npm npm run dev
Build / lint / typecheck / smoke:
npm_config_cache=../.cache/npm npm run build
npm_config_cache=../.cache/npm npm run lint
npm_config_cache=../.cache/npm npm run typecheck
npm_config_cache=../.cache/npm npm run smoke
Do not install Node packages globally. Project dependencies live in web/node_modules; npm cache lives under repository .cache/npm.
Environment
| Var | Default | Purpose |
|---|---|---|
MONLET_API_BASE_URL |
http://127.0.0.1:8000 |
Server base URL (server-side fetch) |
MONLET_API_TOKEN |
(none) | Bearer token sent to server |
MONLET_WEB_TIME_ZONE |
UTC |
IANA timezone used to render timestamps |
MONLET_WEB_AUTH_USERNAME |
(none) | Optional local web login username |
MONLET_WEB_AUTH_PASSWORD |
(none) | Optional local web login password |
MONLET_WEB_SESSION_SECRET |
(none) | Secret used to sign the web session cookie; required with local web login; at least 32 bytes |
MONLET_WEB_SESSION_TTL_SEC |
604800 |
Local web session lifetime |
MONLET_WEB_TRUST_PROXY_AUTH |
false |
Trust X-Forwarded-User from an upstream auth proxy |
NEXT_PUBLIC_MONLET_POLL_MS |
10000 |
Browser polling interval in ms; build-time for production Next.js bundles |
The API token never reaches the browser — all server calls happen in Server Components / route handlers. Agent admission actions are blocked unless local web login is configured or trusted proxy auth is enabled.
Production deployments should rate-limit /login at the reverse proxy. The app applies constant-time credential checks and a small fixed delay on failed login attempts, but it is not a full auth gateway.
The timezone switcher stores the selected mode in browser cookies, so each operator keeps their own default/browser/UTC preference.
Pages
/— redirects to/agents/agents— agent list/agents/blacklist— blocked agent keys/agents/[id]— agent detail/checks— current check states/incidents— incident list/events— events query/outbox— notification outbox
API client
Types are generated from ../api/openapi.yaml into src/lib/api-types.ts via npm run gen:api.