Extends monitoring to the two bare-metal boxes Proxmox can't see.
Uses a dedicated ed25519 key with a forced authorized_keys command
(see docs/ssh-collector-key-setup.md) so a leaked key can only ever
run the fixed read-only stats script, never arbitrary commands.
CPU is approximated from 1-min load average / core count (a true
utilization % would need two /proc/stat samples).
Closes#8.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Cookie was silently never set because NODE_ENV=production forced
secure=true while the app is served over plain HTTP on the LAN (TLS
terminates at a reverse proxy later, not here). Add explicit
COOKIE_SECURE env var, default false.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Vertical slice for Phase 1 (v1-dashboard milestone): Proxmox collector,
SQLite storage, local auth, and a dashboard UI showing host/container
status cards. Config-driven collector registry so future data sources
(SSH-based hosts, Zabbix, network discovery) plug in without rewiring.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>