Caching (reduce MCMS API load with multiple operators): - web/cache.js: in-memory TTL cache with single-flight, keyed by MCMS host. Concurrent identical bulk reads collapse into ONE upstream fetch; everyone on the same MCMS shares the snapshot. - Wired into the bulk reads only (ONU/OLT config+state lists, controllers, firmware). Per-ONU read-modify-write and the FEC pre-flight stay live. - Writes (delete / per-ONU + bulk upgrade / flood change / firmware upload) invalidate the affected datasets for that host, so changes show on the next load instead of waiting out the TTL. - PFW_CACHE_TTL_SECONDS (default 60, 0 disables). Authenticated _cacheStats / _cacheClear endpoints for ops. Deploy (Debian 13 LXC, clone-to-run) in web/deploy/: - pon-fleet-web.service (runs as unprivileged ponfw, hardened, repo read-only, no disk writes), pon-fleet-web.env.example, update.sh (git pull + npm install --omit=dev + restart; uses install not ci since package-lock.json is gitignored). - README: full LXC setup, Nginx Proxy Manager proxy-host + access-list notes. Streams already send X-Accel-Buffering: no so NPM/nginx don't buffer the NDJSON progress. Verified: node --check; cache unit-tested (single-flight, TTL hit/expiry, fresh, invalidate, key isolation, disable — 9/9); server boots and reports the cache TTL; _cacheStats gated to logged-in sessions. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
35 lines
968 B
Desktop File
35 lines
968 B
Desktop File
[Unit]
|
|
Description=PON Fleet web server (MCMS tools, multi-user)
|
|
Documentation=https://git.vanvikinternet.no/Svorka/ponfw
|
|
After=network-online.target
|
|
Wants=network-online.target
|
|
|
|
[Service]
|
|
Type=simple
|
|
User=ponfw
|
|
Group=ponfw
|
|
# The repo is cloned to /opt/ponfw; the server lives in its web/ subdir.
|
|
WorkingDirectory=/opt/ponfw/web
|
|
ExecStart=/usr/bin/env node server.js
|
|
# Defaults; override anything in /etc/pon-fleet-web.env (optional).
|
|
Environment=NODE_ENV=production
|
|
EnvironmentFile=-/etc/pon-fleet-web.env
|
|
Restart=on-failure
|
|
RestartSec=3
|
|
|
|
# --- Hardening (the app reads its repo, writes nothing to disk) ---
|
|
NoNewPrivileges=true
|
|
PrivateTmp=true
|
|
ProtectSystem=strict
|
|
ProtectHome=true
|
|
ProtectKernelTunables=true
|
|
ProtectKernelModules=true
|
|
ProtectControlGroups=true
|
|
RestrictSUIDSGID=true
|
|
RestrictNamespaces=true
|
|
LockPersonality=true
|
|
# V8 needs writable+executable memory for its JIT, so do NOT deny W^X.
|
|
MemoryDenyWriteExecute=false
|
|
|
|
[Install]
|
|
WantedBy=multi-user.target
|