Commit Graph
31 Commits
Author SHA1 Message Date
cedricandClaude Opus 5.5 42f6137391 Safer defaults, read-only role, security headers and syslog TCP limits
- ALLOW_PURGE is now false by default; the UI shows a banner when there is
  no authentication.
- Read-only role: AUTH_VIEWER_USER/AUTH_VIEWER_PASS in local mode, or
  OIDC_ADMIN_GROUP in OIDC mode; changes get 403 and the admin settings
  are greyed out.
- Content-Security-Policy (inline scripts allowed by hash) and other
  security headers; cross-site changes are refused.
- Syslog TCP: at most SYSLOG_TCP_MAX_CONNS connections, closed after
  SYSLOG_TCP_IDLE of silence; HTTP idle timeout.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-03 16:30:40 +02:00
cedricandClaude Opus 5.5 3c25b1e4e2 Default tags: keep warning and error, move ok to the Log levels preset
Existing tags.json files are unchanged; only new installs and "Restore
default tags" get the shorter list.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-03 16:07:30 +02:00
cedricandClaude Opus 5.5 688a7dc2e6 Load color tag presets from an editable presets.json file
The presets move from app.js to presets.json, built into the binary and
served by /api/presets. PRESETS_FILE (default /data/presets.json) replaces
the list when present; it is read again each time Settings opens and the
built-in list is used if it is invalid. docs/presets.md (EN/FR) explains
each preset and the file format.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-03 16:05:47 +02:00
cedricandClaude Opus 5.5 4225a2c870 More color tag presets: system, applications and general
The preset menu is grouped (HTTP/HTTPS, System, Applications, General) and
gains SSH/logins, sudo, kernel, systemd, firewall/fail2ban, Docker,
databases, log levels and IPv4 addresses.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-03 16:01:02 +02:00
cedricandClaude Opus 5.5 236c936a9d Built-in Ubuntu Mono and Inconsolata Condensed fonts
Inconsolata Condensed (Inconsolata pinned at width 75, 0.4em per
character) is now the narrowest option. Ubuntu Mono moves from Bunny
Fonts to the built-in fonts, so it works offline too.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-03 15:44:02 +02:00
cedricandClaude Opus 5.5 9ea1371696 Compact density and built-in Iosevka font for denser log display
Settings > Interface > Log display gets a Density switch (Normal/Compact)
that tightens row padding and line height, and the font list gets Iosevka,
a narrow SIL OFL monospace font served from web/fonts (Latin subset,
13 KB per weight) so it works offline, unlike the Bunny Fonts ones.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-03 15:39:33 +02:00
cedricandClaude Opus 5.5 c664f1eaaf Two-digit code per color tag, shown as badges on matching log lines
Each tag gets a stable code (01-99) assigned by the server and stored in
tags.json; existing tags get one when the file is loaded. A fixed-width
Filters column shows the codes of the active tags found in each message
(room for 3, then 2 + "+N", all listed in the tooltip).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-03 15:35:20 +02:00
cedricandClaude Opus 5.5 be58284916 Ready-made color tag presets for HTTP/HTTPS access logs
A '+ Preset…' menu in Settings > Filters adds groups of tags for status
codes, methods, probes, bots and TLS/proxy errors (nginx, Apache, Traefik,
Caddy, HAProxy). A regex group named hl colors only that part of a match,
and tags get an optional label shown in place of the pattern.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-03 15:16:44 +02:00
cedricandClaude Opus 5.5 7aebb1120f Login page for AUTH_MODE=local instead of the Basic Auth popup
The local mode now shows a login page in the colors of the UI (light/dark theme, FR/EN)
with a signed session cookie and the log out button, like the OIDC mode. LOGIN_LOGO shows
a PNG mounted in the container on that page. SESSION_TTL applies to both modes
(OIDC_SESSION_TTL still works). HTTP Basic credentials are still accepted for scripts.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-03 11:11:11 +02:00
cedricandClaude Opus 5.5 f30c353b46 OpenID Connect login (AUTH_MODE=oidc)
AUTH_MODE=local keeps the HTTP Basic authentication (unchanged default);
AUTH_MODE=oidc logs in through an OpenID Connect provider with the
authorization code flow and PKCE, standard library only: discovery,
ID token signature (RS/PS/ES) and claims checks, signed session cookie
whose key is kept in DATA_DIR. The UI gets a log out button and reloads
into the login when the session ends.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-03 10:39:54 +02:00
cedricandClaude Opus 5.5 30018e09e2 Host system logs source (systemd journal or /var/log)
New source, off by default and switched in Settings > Sources, that
collects the system logs of the machine hosting the stack:
- reads the systemd journal files directly (pure Go reader, no
  journalctl in the image), from /var/log/journal and /run/log/journal
  mounted read-only under /host;
- falls back to following the text files of /var/log (syslog,
  messages, *.log) on hosts without journald;
- positions saved in /data/hostlogs-state.json, HOST_LOGS_BACKFILL
  read when the source is turned on;
- source_type "host", selectable in the Source filter;
- compose mounts and group_add (HOST_LOGS_GID, adm by default), docs.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-03 10:05:38 +02:00
claude BotandClaude Opus 5.5 cb2c2c5200 README: remove the duplicated color tags paragraph
The "Color tags" bullet repeated under "Host names" (and its French
counterpart) duplicated Settings > Filters; it is removed from both files.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-02 13:54:03 +02:00
cedricandClaude Opus 5.5 fd1c0a2698 README in French
README.fr.md is a full French translation of README.md (same sections,
code blocks and commands unchanged, same image and links). Each README
starts with a link to the other language.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-02 11:29:21 +02:00
cedricandClaude Opus 5.5 556d5ee767 Rename the architecture diagram to docs/architecture.*
docs/logstream-schema-logique.{png,excalidraw} become
docs/architecture.{png,excalidraw}; the README image and source link
follow.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-02 09:32:56 +02:00
cedricandClaude Opus 5.5 eb51eb15b4 Architecture diagram: version 2 from the project
Replaces the diagram with the corrected version 2 (title without commit
hash, Query with the from/to zoom bounds, Histogram box linked to the API
and VictoriaLogs, arrow labels on a white background), and adds a
Timeline bullet to the README legend.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-02 09:18:17 +02:00
cedricandClaude Opus 5.5 459d5cb79b Architecture diagram: current main, timeline histogram
- Title without the commit hash (the hand-drawn font turned "32593b9" into
  "3259369"); the subtitle dates the diagram instead.
- New Histogram (histogram.go) box: API -> histogram -> VictoriaLogs (stats).
- Query mentions the from/to range (zoom); the web UI mentions the
  timeline, columns and live view.
- Multi-segment arrows drawn straight, routed between the containers.
- PNG regenerated from the .excalidraw source (Excalidraw 0.18 renderer).
- README: histogram.go in the Search flow.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-02 09:17:52 +02:00
cedricandClaude Opus 5.5 b3b7041ee9 README: architecture diagram
Adds the logical diagram of the project (PNG and its editable Excalidraw
source in docs/) and an Architecture section after the introduction,
with a short description of the data flows.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-02 09:09:08 +02:00
cedricandClaude Opus 5.5 a12fac16c8 Log list: resizable columns with a sticky header
The list gets a thin sticky header (received, message time, severity,
host, app, message). Dragging the edge of a header resizes the column,
a double-click returns it to the automatic width; widths are clamped per
column and remembered per browser (logstream.cols.*), and Settings >
Interface has a "Reset column widths" button.

The columns are defined once on a #table wrapper from --col-* variables;
the header and every row use subgrid, so all rows line up (host and app
widths no longer vary from row to row). The wrapper clips with
overflow: clip so that the header can stick under the top bar. Phones
keep the two-line layout without header.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-01 22:07:05 +02:00
cedricandClaude Opus 5.5 ebf6340ff0 Timeline: scales, graduations, tooltip, colors, live updates and zoom
The histogram above the list becomes a configurable timeline:

- Scale linear / sqrt (default) / log, height S/M/L, bars or area.
- Colors: stacked by severity (error+, warning, the rest), intensity
  against the median of the window (calm, burst >3x, anomaly >10x), or
  none; colors are CSS variables with light and dark values.
- Vertical graduations on round local times (hh:mm:ss, hh:mm, dd/mm).
- Tooltip: interval bounds, total and detail per severity.
- Division automatic (~100 intervals) or fixed (1 s to 1 day), capped at
  300 intervals by the server; intervals aligned on the local time zone.
- Refresh off / 5 s / 15 s / 30 s / 1 min / at each new interval. In
  live mode the last interval is incremented from the SSE stream and the
  timeline reloads at each new interval; paused while the tab is hidden.
- Click a bar to zoom on its interval, drag to zoom on a selection: the
  list, export and counters follow through new from/to parameters.

The timeline now runs on the server clock (bounds and "now" come from
/api/histogram): the axis was drawn from the browser clock and refreshed
every 30 s only, so a clock difference with the server or a hidden tab
left it behind the logs.

/api/histogram returns interval indexes with the count per severity; the
division logic lives in histogram.go with table-driven tests.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-01 20:23:18 +02:00
cedricandClaude Opus 5.5 32593b9515 Settings > Sources: turn syslog reception on/off, choose UDP/TCP
- SyslogServer opens and closes the UDP/TCP listeners at runtime from the
  configuration saved in /data/syslog.json; a busy port no longer stops
  Logstream, the error is shown in Settings instead.
- Sources tab: syslog section with an on/off switch, UDP and TCP labels,
  the live listening state and the published port (SYSLOG_PORT, passed as
  SYSLOG_PUBLIC_PORT for display; the mapping stays in docker-compose).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-28 17:37:08 +02:00
cedricandClaude Opus 5.5 7beb791e44 Pin image versions
- docker-compose: victoria-logs v1.52.0 and docker-socket-proxy v0.5.0,
  the versions running on sandbox.
- Dockerfile: golang 1.27.1-alpine3.24 and alpine 3.24.2 (Go 1.23 and
  Alpine 3.20 no longer receive security fixes).
- README: pinned versions and how to update them.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-28 17:29:49 +02:00
cedricandClaude Opus 5.5 d751fb54ae Sources: container labels in one field, colored by compose project
- One label per container (project/service) in a single field, like
  tag pickers: followed ones in the project color, a separator, then the
  others in grey; a click switches a label. Excluded ones last, locked.
- Stopped containers hidden by default, shown dashed and still editable
  with 'Show stopped containers'; filter box; enable/disable all apply to
  the labels shown.
- Docker app names in the log list use their compose project color.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-28 17:18:27 +02:00
cedricandClaude Opus 5.5 085095c46f Collect the logs of the local Docker containers
- docker.go follows every running container through the Docker API
  (events + logs with follow), resumes after a restart from the last
  position saved in /data/docker-state.json, reads DOCKER_BACKFILL (1h)
  of history for new containers, strips terminal color codes and guesses
  the severity from the line (JSON, logfmt, [ERROR], ERROR ...).
- Logs carry source_type=docker, container, container_id, image,
  compose_project, compose_service and stream; host is the Docker host.
- Settings > Sources: one switch per container (grouped by compose
  project), enable/disable all, follow new containers automatically.
  Choices are saved per compose service in /data/docker.json.
- Source filter (syslog / docker) in the filter bar and the live view.
- docker-compose: read-only docker-socket-proxy; Logstream and the proxy
  are labelled logstream.exclude=true and never collected.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-28 16:52:05 +02:00
cedricandClaude Opus 5.5 328384032b Add CSV export of the logs matching the current filters
- GET /api/export.csv streams every stored log matching the filters
  (newest first, up to EXPORT_MAX rows, 100000 by default) straight from
  VictoriaLogs, with dates in the time zone chosen in Settings.
- Export button with two variants: CSV (comma, UTF-8) and CSV for Excel
  (semicolon + BOM, formula injection neutralized).
- Store.QueryStream streams query results without buffering them.
- Mobile: filter bar keeps two selects per row, count next to Export.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-28 16:26:40 +02:00
cedricandClaude Opus 5.5 84e71f741c Settings in tabs: localization, filters, interface, data
- Tabbed settings dialog (side navigation, 4-column tabs on mobile);
  the last opened tab is remembered.
- Interface: theme System/Light/Dark (System follows the OS preference),
  log font size (tiny, small, medium, large) and log font: system
  monospace or 12 free monospace fonts loaded from Bunny Fonts, with a
  live preview. Ligatures disabled in log rows.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-28 16:13:53 +02:00
cedricandClaude Opus 5.5 e583ab4b87 Index logs by reception time, host filter from displayed logs, pastel tags
- _time is now the reception time; the device timestamp moves to msg_time.
  Devices with a wrong clock were indexed in the past and escaped time
  ranges and the host list.
- Host/app lists also include values seen in displayed and live logs;
  clicking a host or app cell filters on it.
- Severity badges err/crit and warning use the colors of the error and
  warning tags; default tags are now pastel (old default colors migrated).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-28 15:55:12 +02:00
cedricandClaude Opus 5.5 7a706eeb82 Resolve host IPs through DNS, add purge, French date format by default
- Reverse DNS (cached PTR lookups): IP hosts are stored with their name
  in 'host' and the IP in 'host_ip'; older IP-only logs are resolved on
  display and the host filter shows 'name (IP)'. RDNS / DNS_SERVER env.
- Settings > Danger zone: delete all logs (type PURGE to confirm) through
  VictoriaLogs /delete/run_task; -delete.enable added to docker-compose.
  ALLOW_PURGE env to disable it.
- Remove the custom YYYY-MM-DD - HH:MM:SS:mmm format; default is now the
  usual French display DD/MM/YYYY HH:MM:SS.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-28 15:39:53 +02:00
cedricandClaude Opus 5.5 85701a9119 Show server reception time before the message time
- Store a 'received' field (server clock) with every message
- New first column with the reception time
- Settings: time zone (browser, UTC, ~80 zones) and reception time
  format (YYYY-MM-DD - HH:MM:SS:mmm by default, ISO 8601, 12h, epoch...)
- The chosen time zone applies to every date shown

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-28 14:55:43 +02:00
cedric 35d51defc8 ajout anglais/francais 2026-09-28 14:24:10 +02:00
cedric a1c53892f0 changement de nom 2026-09-28 12:43:56 +02:00
cedric 8200c2bc87 First commit 2026-09-28 12:19:29 +02:00