Files
Ansible/scripts/addons/webgui/docs/ARCHITECTURE.md
T
2026-09-22 19:23:17 +02:00

18 lines
2.7 KiB
Markdown

# Architecture - 2.1.0rc9
Core3.3.0rc8 owns current inventory, normalized requests/revisions, native execution, credential handling, safe progress, per-target outcomes and declared final report validation. Its API remains1.0. WebGUI owns authentication/authorization, reviewed workflows, UI and its own retained history.
Browser -> HTTP/queue (aim-web) -> fixed private executor socket -> executor account -> aimctl under same UID -> native Ansible. No new daemon, privilege or Core import.
The reviewed plan now includes a validated result_contract. Public response parsing has separate large-result limits and strict JSON parsing; secret transport stays unchanged. Core's final result event is progress only. The final response is projected against the reviewed schema/scope/targets/mode and is the sole report-persistence input.
During execution Capture.submit projects metadata into a bounded queue. A writer thread batches durable journal rows and a latest-observation checkpoint into SQLite transactions. HTTP reads/replay query committed rows and never connect to the process console. Browser latency cannot fill the Core credential pipe or control capture. Capture loss/limits are recorded distinctly from execution outcomes.
Schema5 adds job_progress_events,job_progress_state,job_operation_results and job_operation_reports; all reference jobs with ON DELETE CASCADE. Core_result keeps its small authoritative status/targets and a compact report availability summary. Analytics need not decode report bodies. Report reads lazily select one slot. Histories still use only retained WebGUI jobs, with owner/admin authorization before queries and aggregation.
Core reports are independent of progress. Schema-aware views render typed structured facts and a generic safe JSON alternative. Unknown supported schemas have no dynamic code/$ref/network loading. Report availability, retention and execution verdict remain separate. No global reporting operation ships with Core; generic global support is fixture-qualified only.
Journal/report storage uses the existing private web DB, rollback journaling and synchronous FULL. It is not an immutable or tamper-proof audit store. Bounded metadata queues plus250ms transaction busy limits separate capture pressure from task execution; persistent DB failure remains a service failure and cannot be hidden as success. Job-linked deletion is not backup/physical erasure.
The existing read-only Explorer/Activity/Insights remain public Core reads or authorized SQL reads. They do not modify current inventory, contact hosts or include terminal history. Host report references explicitly label date/mode; successful Ansible outcomes are not live health/compliance.