Summary This PR introduces Unified Operations Runs + Monitoring Hub (053). Goal: Standardize how long-running operations are tracked and monitored using the existing tenant-scoped run record (BulkOperationRun) as the canonical “operation run”, and surface it in a single Monitoring → Operations hub (view-only, tenant-scoped, role-aware). Phase 1 adoption scope (per spec): • Drift generation (drift.generate) • Backup Set “Add Policies” (backup_set.add_policies) Note: This PR does not convert every run type yet (e.g. GroupSyncRuns / InventorySyncRuns remain separate for now). This is intentionally incremental. ⸻ What changed Monitoring / Operations hub • Moved/organized run monitoring under Monitoring → Operations • Added: • status buckets (queued / running / succeeded / partially succeeded / failed) • filters (run type, status bucket, time range) • run detail “Related” links (e.g. Drift findings, Backup Set context) • All hub pages are DB-only and view-only (no rerun/cancel/delete actions) Canonical run semantics • Added canonical helpers on BulkOperationRun: • runType() (resource.action) • statusBucket() derived from status + counts (testable semantics) Drift integration (Phase 1) • Drift generation start behavior now: • creates/reuses a BulkOperationRun with drift context payload (scope_key + baseline/current run ids) • dispatches generation job • emits DB notifications including “View run” link • On generation failure: stores sanitized failure entries + sends failure notification Permissions / tenant isolation • Monitoring run list/view is tenant-scoped and returns 403 for cross-tenant access • Readonly can view runs but cannot start drift generation ⸻ Tests Added/updated Pest coverage: • BulkOperationRunStatusBucketTest.php • DriftGenerationDispatchTest.php • GenerateDriftFindingsJobNotificationTest.php • RunAuthorizationTenantIsolationTest.php Validation run locally: • ./vendor/bin/pint --dirty • targeted tests from feature quickstart / drift monitoring tests ⸻ Manual QA 1. Go to Monitoring → Operations • verify filters (run type / status / time range) • verify run detail shows counts + sanitized failures + “Related” links 2. Open Drift Landing • with >=2 successful inventory runs for scope: should queue drift generation + show notification with “View run” • as readonly: should not start generation 3. Run detail • drift.generate runs show “Drift findings” related link • failure entries are sanitized (no secrets/tokens/raw payload dumps) ⸻ Notes / Ops • Queue workers must be restarted after deploy so they load the new code: • php artisan queue:restart (or Sail equivalent) • This PR standardizes monitoring for Phase 1 producers only; follow-ups will migrate additional run types into the unified pattern. ⸻ Spec / Docs • SpecKit artifacts added under specs/053-unify-runs-monitoring/ • Checklists are complete: • requirements checklist PASS • writing checklist PASS Co-authored-by: Ahmed Darrazi <ahmeddarrazi@adsmac.local> Reviewed-on: #60
262 lines
8.5 KiB
PHP
262 lines
8.5 KiB
PHP
<?php
|
|
|
|
namespace App\Filament\Pages;
|
|
|
|
use App\Filament\Resources\BulkOperationRunResource;
|
|
use App\Filament\Resources\FindingResource;
|
|
use App\Filament\Resources\InventorySyncRunResource;
|
|
use App\Jobs\GenerateDriftFindingsJob;
|
|
use App\Models\BulkOperationRun;
|
|
use App\Models\Finding;
|
|
use App\Models\InventorySyncRun;
|
|
use App\Models\Tenant;
|
|
use App\Models\User;
|
|
use App\Notifications\RunStatusChangedNotification;
|
|
use App\Services\BulkOperationService;
|
|
use App\Services\Drift\DriftRunSelector;
|
|
use App\Support\RunIdempotency;
|
|
use BackedEnum;
|
|
use Filament\Pages\Page;
|
|
use UnitEnum;
|
|
|
|
class DriftLanding extends Page
|
|
{
|
|
protected static string|BackedEnum|null $navigationIcon = 'heroicon-o-arrows-right-left';
|
|
|
|
protected static string|UnitEnum|null $navigationGroup = 'Drift';
|
|
|
|
protected static ?string $navigationLabel = 'Drift';
|
|
|
|
protected string $view = 'filament.pages.drift-landing';
|
|
|
|
public ?string $state = null;
|
|
|
|
public ?string $message = null;
|
|
|
|
public ?string $scopeKey = null;
|
|
|
|
public ?int $baselineRunId = null;
|
|
|
|
public ?int $currentRunId = null;
|
|
|
|
public ?string $baselineFinishedAt = null;
|
|
|
|
public ?string $currentFinishedAt = null;
|
|
|
|
public ?int $bulkOperationRunId = null;
|
|
|
|
/** @var array<string, int>|null */
|
|
public ?array $statusCounts = null;
|
|
|
|
public static function canAccess(): bool
|
|
{
|
|
return FindingResource::canAccess();
|
|
}
|
|
|
|
public function mount(): void
|
|
{
|
|
$tenant = Tenant::current();
|
|
|
|
$user = auth()->user();
|
|
if (! $user instanceof User) {
|
|
abort(403, 'Not allowed');
|
|
}
|
|
|
|
$latestSuccessful = InventorySyncRun::query()
|
|
->where('tenant_id', $tenant->getKey())
|
|
->where('status', InventorySyncRun::STATUS_SUCCESS)
|
|
->whereNotNull('finished_at')
|
|
->orderByDesc('finished_at')
|
|
->first();
|
|
|
|
if (! $latestSuccessful instanceof InventorySyncRun) {
|
|
$this->state = 'blocked';
|
|
$this->message = 'No successful inventory runs found yet.';
|
|
|
|
return;
|
|
}
|
|
|
|
$scopeKey = (string) $latestSuccessful->selection_hash;
|
|
$this->scopeKey = $scopeKey;
|
|
|
|
$selector = app(DriftRunSelector::class);
|
|
$comparison = $selector->selectBaselineAndCurrent($tenant, $scopeKey);
|
|
|
|
if ($comparison === null) {
|
|
$this->state = 'blocked';
|
|
$this->message = 'Need at least 2 successful runs for this scope to calculate drift.';
|
|
|
|
return;
|
|
}
|
|
|
|
$baseline = $comparison['baseline'];
|
|
$current = $comparison['current'];
|
|
|
|
$this->baselineRunId = (int) $baseline->getKey();
|
|
$this->currentRunId = (int) $current->getKey();
|
|
|
|
$this->baselineFinishedAt = $baseline->finished_at?->toDateTimeString();
|
|
$this->currentFinishedAt = $current->finished_at?->toDateTimeString();
|
|
|
|
$idempotencyKey = RunIdempotency::buildKey(
|
|
tenantId: (int) $tenant->getKey(),
|
|
operationType: 'drift.generate',
|
|
targetId: $scopeKey,
|
|
context: [
|
|
'scope_key' => $scopeKey,
|
|
'baseline_run_id' => (int) $baseline->getKey(),
|
|
'current_run_id' => (int) $current->getKey(),
|
|
],
|
|
);
|
|
|
|
$exists = Finding::query()
|
|
->where('tenant_id', $tenant->getKey())
|
|
->where('finding_type', Finding::FINDING_TYPE_DRIFT)
|
|
->where('scope_key', $scopeKey)
|
|
->where('baseline_run_id', $baseline->getKey())
|
|
->where('current_run_id', $current->getKey())
|
|
->exists();
|
|
|
|
if ($exists) {
|
|
$this->state = 'ready';
|
|
$newCount = (int) Finding::query()
|
|
->where('tenant_id', $tenant->getKey())
|
|
->where('finding_type', Finding::FINDING_TYPE_DRIFT)
|
|
->where('scope_key', $scopeKey)
|
|
->where('baseline_run_id', $baseline->getKey())
|
|
->where('current_run_id', $current->getKey())
|
|
->where('status', Finding::STATUS_NEW)
|
|
->count();
|
|
|
|
$this->statusCounts = [Finding::STATUS_NEW => $newCount];
|
|
|
|
return;
|
|
}
|
|
|
|
$latestRun = BulkOperationRun::query()
|
|
->where('tenant_id', $tenant->getKey())
|
|
->where('idempotency_key', $idempotencyKey)
|
|
->latest('id')
|
|
->first();
|
|
|
|
$activeRun = RunIdempotency::findActiveBulkOperationRun((int) $tenant->getKey(), $idempotencyKey);
|
|
if ($activeRun instanceof BulkOperationRun) {
|
|
$this->state = 'generating';
|
|
$this->bulkOperationRunId = (int) $activeRun->getKey();
|
|
|
|
return;
|
|
}
|
|
|
|
if ($latestRun instanceof BulkOperationRun && $latestRun->status === 'completed') {
|
|
$this->state = 'ready';
|
|
$this->bulkOperationRunId = (int) $latestRun->getKey();
|
|
|
|
$newCount = (int) Finding::query()
|
|
->where('tenant_id', $tenant->getKey())
|
|
->where('finding_type', Finding::FINDING_TYPE_DRIFT)
|
|
->where('scope_key', $scopeKey)
|
|
->where('baseline_run_id', $baseline->getKey())
|
|
->where('current_run_id', $current->getKey())
|
|
->where('status', Finding::STATUS_NEW)
|
|
->count();
|
|
|
|
$this->statusCounts = [Finding::STATUS_NEW => $newCount];
|
|
|
|
if ($newCount === 0) {
|
|
$this->message = 'No drift findings for this comparison. If you changed settings after the current run, run Inventory Sync again to capture a newer snapshot.';
|
|
}
|
|
|
|
return;
|
|
}
|
|
|
|
if ($latestRun instanceof BulkOperationRun && in_array($latestRun->status, ['failed', 'aborted'], true)) {
|
|
$this->state = 'error';
|
|
$this->message = 'Drift generation failed for this comparison. See the run for details.';
|
|
$this->bulkOperationRunId = (int) $latestRun->getKey();
|
|
|
|
return;
|
|
}
|
|
|
|
if (! $user->canSyncTenant($tenant)) {
|
|
$this->state = 'blocked';
|
|
$this->message = 'You can view existing drift findings and run history, but you do not have permission to generate drift.';
|
|
|
|
return;
|
|
}
|
|
|
|
$bulkOperationService = app(BulkOperationService::class);
|
|
$run = $bulkOperationService->createRun(
|
|
tenant: $tenant,
|
|
user: $user,
|
|
resource: 'drift',
|
|
action: 'generate',
|
|
itemIds: [
|
|
'scope_key' => $scopeKey,
|
|
'baseline_run_id' => (int) $baseline->getKey(),
|
|
'current_run_id' => (int) $current->getKey(),
|
|
],
|
|
totalItems: 1,
|
|
);
|
|
|
|
$run->update(['idempotency_key' => $idempotencyKey]);
|
|
|
|
$this->state = 'generating';
|
|
$this->bulkOperationRunId = (int) $run->getKey();
|
|
|
|
GenerateDriftFindingsJob::dispatch(
|
|
tenantId: (int) $tenant->getKey(),
|
|
userId: (int) $user->getKey(),
|
|
baselineRunId: (int) $baseline->getKey(),
|
|
currentRunId: (int) $current->getKey(),
|
|
scopeKey: $scopeKey,
|
|
bulkOperationRunId: (int) $run->getKey(),
|
|
);
|
|
|
|
$user->notify(new RunStatusChangedNotification([
|
|
'tenant_id' => (int) $tenant->getKey(),
|
|
'run_type' => 'bulk_operation',
|
|
'run_id' => (int) $run->getKey(),
|
|
'status' => 'queued',
|
|
'counts' => [
|
|
'total' => (int) $run->total_items,
|
|
'processed' => (int) $run->processed_items,
|
|
'succeeded' => (int) $run->succeeded,
|
|
'failed' => (int) $run->failed,
|
|
'skipped' => (int) $run->skipped,
|
|
],
|
|
]));
|
|
}
|
|
|
|
public function getFindingsUrl(): string
|
|
{
|
|
return FindingResource::getUrl('index', tenant: Tenant::current());
|
|
}
|
|
|
|
public function getBaselineRunUrl(): ?string
|
|
{
|
|
if (! is_int($this->baselineRunId)) {
|
|
return null;
|
|
}
|
|
|
|
return InventorySyncRunResource::getUrl('view', ['record' => $this->baselineRunId], tenant: Tenant::current());
|
|
}
|
|
|
|
public function getCurrentRunUrl(): ?string
|
|
{
|
|
if (! is_int($this->currentRunId)) {
|
|
return null;
|
|
}
|
|
|
|
return InventorySyncRunResource::getUrl('view', ['record' => $this->currentRunId], tenant: Tenant::current());
|
|
}
|
|
|
|
public function getBulkRunUrl(): ?string
|
|
{
|
|
if (! is_int($this->bulkOperationRunId)) {
|
|
return null;
|
|
}
|
|
|
|
return BulkOperationRunResource::getUrl('view', ['record' => $this->bulkOperationRunId], tenant: Tenant::current());
|
|
}
|
|
}
|