Implements Spec 087: Legacy Runs Removal (rigorous). ### What changed - Canonicalized run history: **`operation_runs` is the only run system** for inventory sync, Entra group sync, backup schedule execution/retention/purge. - Removed legacy UI surfaces (Filament Resources / relation managers) for legacy run models. - Legacy run URLs now return **404** (no redirects), with RBAC semantics preserved (404 vs 403 as specified). - Canonicalized affected `operation_runs.type` values (dotted → underscore) via migration. - Drift + inventory references now point to canonical operation runs; includes backfills and then drops legacy FK columns. - Drops legacy run tables after cutover. - Added regression guards to prevent reintroducing legacy run tokens or “backfilling” canonical runs from legacy tables. ### Migrations - `2026_02_12_000001..000006_*` canonicalize types, add/backfill operation_run_id references, drop legacy columns, and drop legacy run tables. ### Tests Focused pack for this spec passed: - `tests/Feature/Guards/NoLegacyRunsTest.php` - `tests/Feature/Guards/NoLegacyRunBackfillTest.php` - `tests/Feature/Operations/LegacyRunRoutesNotFoundTest.php` - `tests/Feature/Monitoring/MonitoringOperationsTest.php` - `tests/Feature/Jobs/RunInventorySyncJobTest.php` ### Notes / impact - Destructive cleanup is handled via migrations (drops legacy tables) after code cutover; deploy should run migrations in the same release. Co-authored-by: Ahmed Darrazi <ahmed.darrazi@live.de> Reviewed-on: #106
159 lines
5.3 KiB
PHP
159 lines
5.3 KiB
PHP
<?php
|
|
|
|
declare(strict_types=1);
|
|
|
|
namespace App\Filament\Widgets\Dashboard;
|
|
|
|
use App\Filament\Pages\DriftLanding;
|
|
use App\Filament\Resources\FindingResource;
|
|
use App\Models\Finding;
|
|
use App\Models\OperationRun;
|
|
use App\Models\Tenant;
|
|
use App\Support\OperationRunLinks;
|
|
use App\Support\OpsUx\ActiveRuns;
|
|
use Filament\Facades\Filament;
|
|
use Filament\Widgets\Widget;
|
|
|
|
class NeedsAttention extends Widget
|
|
{
|
|
protected static bool $isLazy = false;
|
|
|
|
protected string $view = 'filament.widgets.dashboard.needs-attention';
|
|
|
|
/**
|
|
* @return array<string, mixed>
|
|
*/
|
|
protected function getViewData(): array
|
|
{
|
|
$tenant = Filament::getTenant();
|
|
|
|
if (! $tenant instanceof Tenant) {
|
|
return [
|
|
'pollingInterval' => null,
|
|
'items' => [],
|
|
'healthyChecks' => [],
|
|
];
|
|
}
|
|
|
|
$tenantId = (int) $tenant->getKey();
|
|
|
|
$items = [];
|
|
|
|
$highSeverityCount = (int) Finding::query()
|
|
->where('tenant_id', $tenantId)
|
|
->where('finding_type', Finding::FINDING_TYPE_DRIFT)
|
|
->where('status', Finding::STATUS_NEW)
|
|
->where('severity', Finding::SEVERITY_HIGH)
|
|
->count();
|
|
|
|
if ($highSeverityCount > 0) {
|
|
$items[] = [
|
|
'title' => 'High severity drift findings',
|
|
'body' => "{$highSeverityCount} finding(s) need review.",
|
|
'url' => FindingResource::getUrl('index', tenant: $tenant),
|
|
'badge' => 'Drift',
|
|
'badgeColor' => 'danger',
|
|
];
|
|
}
|
|
|
|
$latestDriftSuccess = OperationRun::query()
|
|
->where('tenant_id', $tenantId)
|
|
->where('type', 'drift_generate_findings')
|
|
->where('status', 'completed')
|
|
->where('outcome', 'succeeded')
|
|
->whereNotNull('completed_at')
|
|
->latest('completed_at')
|
|
->first();
|
|
|
|
if (! $latestDriftSuccess) {
|
|
$items[] = [
|
|
'title' => 'No drift scan yet',
|
|
'body' => 'Generate drift after you have at least two successful inventory runs.',
|
|
'url' => DriftLanding::getUrl(tenant: $tenant),
|
|
'badge' => 'Drift',
|
|
'badgeColor' => 'warning',
|
|
];
|
|
} else {
|
|
$isStale = $latestDriftSuccess->completed_at?->lt(now()->subDays(7)) ?? true;
|
|
|
|
if ($isStale) {
|
|
$items[] = [
|
|
'title' => 'Drift stale',
|
|
'body' => 'Last drift scan is older than 7 days.',
|
|
'url' => DriftLanding::getUrl(tenant: $tenant),
|
|
'badge' => 'Drift',
|
|
'badgeColor' => 'warning',
|
|
];
|
|
}
|
|
}
|
|
|
|
$latestDriftFailure = OperationRun::query()
|
|
->where('tenant_id', $tenantId)
|
|
->where('type', 'drift_generate_findings')
|
|
->where('status', 'completed')
|
|
->where('outcome', 'failed')
|
|
->latest('id')
|
|
->first();
|
|
|
|
if ($latestDriftFailure instanceof OperationRun) {
|
|
$items[] = [
|
|
'title' => 'Drift generation failed',
|
|
'body' => 'Investigate the latest failed run.',
|
|
'url' => OperationRunLinks::view($latestDriftFailure, $tenant),
|
|
'badge' => 'Operations',
|
|
'badgeColor' => 'danger',
|
|
];
|
|
}
|
|
|
|
$activeRuns = (int) OperationRun::query()
|
|
->where('tenant_id', $tenantId)
|
|
->active()
|
|
->count();
|
|
|
|
if ($activeRuns > 0) {
|
|
$items[] = [
|
|
'title' => 'Operations in progress',
|
|
'body' => "{$activeRuns} run(s) are active.",
|
|
'url' => OperationRunLinks::index($tenant),
|
|
'badge' => 'Operations',
|
|
'badgeColor' => 'warning',
|
|
];
|
|
}
|
|
|
|
$items = array_slice($items, 0, 5);
|
|
|
|
$healthyChecks = [];
|
|
|
|
if ($items === []) {
|
|
$healthyChecks = [
|
|
[
|
|
'title' => 'Drift findings look healthy',
|
|
'body' => 'No high severity drift findings are open.',
|
|
'url' => FindingResource::getUrl('index', tenant: $tenant),
|
|
'linkLabel' => 'View findings',
|
|
],
|
|
[
|
|
'title' => 'Drift scans are up to date',
|
|
'body' => $latestDriftSuccess?->completed_at
|
|
? 'Last drift scan: '.$latestDriftSuccess->completed_at->diffForHumans(['short' => true]).'.'
|
|
: 'Drift scan history is available in Drift.',
|
|
'url' => DriftLanding::getUrl(tenant: $tenant),
|
|
'linkLabel' => 'Open Drift',
|
|
],
|
|
[
|
|
'title' => 'No active operations',
|
|
'body' => 'Nothing is currently running for this tenant.',
|
|
'url' => OperationRunLinks::index($tenant),
|
|
'linkLabel' => 'View operations',
|
|
],
|
|
];
|
|
}
|
|
|
|
return [
|
|
'pollingInterval' => ActiveRuns::existForTenant($tenant) ? '10s' : null,
|
|
'items' => $items,
|
|
'healthyChecks' => $healthyChecks,
|
|
];
|
|
}
|
|
}
|