- OUI: mac-oui-lookup package resolves vendor from the MAC prefix
(computed on read, no storage needed). Already correctly identifies
the LXC host prefix as "Proxmox Server Solutions GmbH" and several
"unknown" devices as "Amazon Technologies Inc." -- likely the Echo
Dots / Ring gear.
- mDNS: discover-devices.sh now runs avahi-resolve per discovered IP
(parallel, bounded 2s timeout per host so one non-mDNS device can't
stall the run), stored in a new devices.mdns_hostname column.
- Manual labels: new device_labels table keyed by MAC (survives DHCP
IP changes), PUT/DELETE /api/devices/:mac/label, inline-editable
Name cell in the dashboard. Deliberately separate from vendor/mDNS
info -- those are shown as an italic *hint* for unlabeled devices,
not treated as "known" until the admin actually confirms one.
- Fixed the Name column's sort comparator to match what's rendered
(name, else vendor/mDNS hint) instead of just the raw name field --
caught while reasoning through what the existing sort test would
actually need to assert once hints appear in the column.
Part of #15 (OUI/mDNS/manual labels done; on-demand deep-check next).
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Local auth stays the primary/always-available login (don't want to
lock out the saved admin password) — OIDC is additive, shown as a
second button when OIDC_ENABLED=true. Uses openid-client v6 with PKCE.
Authentik-side provider was set up via an authentik blueprint (its own
declarative automation, see docs/oidc-setup.md) rather than touching
any existing admin credentials.
Closes#12.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Extends monitoring to the two bare-metal boxes Proxmox can't see.
Uses a dedicated ed25519 key with a forced authorized_keys command
(see docs/ssh-collector-key-setup.md) so a leaked key can only ever
run the fixed read-only stats script, never arbitrary commands.
CPU is approximated from 1-min load average / core count (a true
utilization % would need two /proc/stat samples).
Closes#8.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Vertical slice for Phase 1 (v1-dashboard milestone): Proxmox collector,
SQLite storage, local auth, and a dashboard UI showing host/container
status cards. Config-driven collector registry so future data sources
(SSH-based hosts, Zabbix, network discovery) plug in without rewiring.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>