Add dashboard integrity/watchdog console

Surface integrity and watchdog state in the read-only dashboard via a new
/api/integrity endpoint and integrity_report(): watchdog/heartbeat
verdict, FIM baseline and package-DB anchor freshness, pacman keyring and
SigLevel posture, and Sentinel's own self-integrity footprint. The
endpoint summarizes existing anchors and heartbeats only — it runs no live
FIM or package verification from the request path, keeping the dashboard
read-only.

Add the enodia.integrity.v1 schema (schemas.py + docs/SCHEMAS.md) with a
contract test, a new "Integrity" dashboard tab and summary metric, and
web tests for the report shape, schema contract, endpoint, and console
wiring. Docs updated; completes the v1.0 "dashboard to local console"
roadmap item.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
Luna 2026-06-18 17:39:53 -07:00
parent e0e5cd62d9
commit 11d91a40b4
12 changed files with 337 additions and 29 deletions

View file

@ -90,6 +90,25 @@ Required fields:
| `heartbeat_age` | number or null | Seconds since heartbeat, if present. |
| `heartbeat_stale` | boolean | Whether heartbeat exceeds configured max age. |
## `enodia.integrity.v1`
Integrity/watchdog object returned by `/api/integrity`. This is a read-only
summary of existing state; the dashboard endpoint does not run live FIM or
package verification work.
Required fields:
| Field | Type | Meaning |
|---|---|---|
| `schema` | string | `enodia.integrity.v1`. |
| `generated_at` | number | Unix timestamp when the report was built. |
| `status` | string | Overall state: `ok`, `review`, or `critical`. |
| `checks` | object | Compact per-check status map. |
| `watchdog` | object | Daemon running state, heartbeat age, stale flag, max age, and verdict message. |
| `anchors` | object | FIM baseline, package DB anchor, pacman keyring, and SigLevel summary. |
| `sentinel_footprint` | object | Configured Sentinel self-integrity paths and present/missing counts. |
| `read_only` | boolean | Always true for this dashboard API. |
## `enodia.response.plan.v1`
Dry-run response plan from `respond plan <incident-id>`.