From c6cd96cbd1ce60e419a505522d74a3530e7aba47 Mon Sep 17 00:00:00 2001 From: mrhid6 Date: Tue, 25 Aug 2026 09:05:06 +0000 Subject: [PATCH] docs: correct the status page URL for self-hosted, trim to what ships MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit - The status page URL was given only as `.vantage.`, which a self-hosted install does not serve. Both deployments are now described. - The banner is documented as one notice: the editor exposes no level picker and the view renders every level identically. - `pending` added to the component states, which a monitor with no result yet renders. - Delete page documented alongside un-publish. - `TRUSTED_PROXIES` names the LAN case: with the RFC1918 default, a client on a private range reaching the server directly is itself trusted and can spoof `X-Forwarded-For` — and now `X-Forwarded-Host`. Narrow it to the proxy. - CLAUDE.md: scopes are nine resources, not eight; `status-pages` added to the REST route table; the host-resolution rules recorded under Status pages. --- docs/reference/environment-variables.md | 2 +- docs/vantage/status-pages.md | 28 ++++++++++++++++++++----- 2 files changed, 24 insertions(+), 6 deletions(-) diff --git a/docs/reference/environment-variables.md b/docs/reference/environment-variables.md index ab09677..9270c51 100644 --- a/docs/reference/environment-variables.md +++ b/docs/reference/environment-variables.md @@ -25,7 +25,7 @@ it is absent. | `VANTAGE_LICENSE` | no | | A licence supplied at startup, so an automated install does not have to paste one in | | `VANTAGE_TRIVY_DB_REF` | no | `ghcr.io/aquasecurity/trivy-db:2` | Where the vulnerability database is pulled from. Point it at a mirror for an air-gapped install | | `VANTAGE_VULNDB_DISABLED` | no | | `true` switches [vulnerability scanning](../vantage/vulnerabilities.md) off entirely. Findings already stored are still served, and still shown as stale | -| `TRUSTED_PROXIES` | no | `10.0.0.0/8,172.16.0.0/12,192.168.0.0/16` | Comma-separated CIDRs or addresses of proxies allowed to set `X-Forwarded-For`. The shipped Docker Compose and Helm chart default to the private RFC1918 ranges, which covers Nginx Proxy Manager on the Docker bridge network and Traefik on a Kubernetes pod CIDR. An operator whose proxy sits on a public address must set this themselves, or every visitor behind it shares one address for rate-limiting purposes. Unset entirely (outside those shipped defaults) trusts none, so the client address is the direct peer | +| `TRUSTED_PROXIES` | no | `10.0.0.0/8,172.16.0.0/12,192.168.0.0/16` | Comma-separated CIDRs or addresses of proxies allowed to set `X-Forwarded-For`. The shipped Docker Compose and Helm chart default to the private RFC1918 ranges, which covers Nginx Proxy Manager on the Docker bridge network and Traefik on a Kubernetes pod CIDR. An operator whose proxy sits on a public address must set this themselves, or every visitor behind it shares one address for rate-limiting purposes. Unset entirely (outside those shipped defaults) trusts none, so the client address is the direct peer. **On a LAN-only install, narrow this to your proxy's address.** The RFC1918 default trusts every private range, so a client on 192.168.0.0/16 reaching the server directly is itself a "trusted proxy" and can put whatever it likes in `X-Forwarded-For` — and, on the public status route, in `X-Forwarded-Host`. Behind a proxy on a public address, or with no proxy at all, that is not reachable; on a flat LAN it is | :::danger `KEY_ENCRYPTION_KEY` has no recovery path It encrypts SSH private keys, vault secrets, OIDC client secrets and console diff --git a/docs/vantage/status-pages.md b/docs/vantage/status-pages.md index 90f000f..3e78553 100644 --- a/docs/vantage/status-pages.md +++ b/docs/vantage/status-pages.md @@ -22,9 +22,19 @@ of lowercase letters, digits and `-`, starting and ending with a letter or digit. It becomes part of the public URL: ``` -https://.vantage./status/ +https:///status/ ``` +On **Vantage Cloud** that address is your instance's own subdomain, so the page +is at `https://.vantage.hostxtra.co.uk/status/`. + +On a **self-hosted** install it is whatever address you reach Vantage on — +`https://vantage.acme.com/status/`, or an IP and port on a LAN +install. A self-hosted install serves exactly one Vantage instance, so no +subdomain is needed to say which one you mean. The **Copy** control next to the +page address in the editor gives you the exact URL for your install, which is +the one to hand out. + **The page id cannot be changed after creation.** Once you have shared the link, changing the id would break it, so pick something you would still be happy with in a year — `platform`, `api`, a customer's own name for a @@ -38,6 +48,11 @@ so you can build out the components and copy before announcing it. Toggle **Published** when it is ready. Un-publishing later takes it back to *not found* rather than deleting anything. +**Delete page**, in the editor header, is the only way to correct a page id you +regret — the id is fixed once created. It takes the page, its sections and its +authored incidents with it; monitors and their history are untouched. If you +only want the page off the internet, un-publish it instead. + ## Sections and components A page is organised into **sections** — arbitrary groupings such as "API" or @@ -55,12 +70,15 @@ more and claiming otherwise would be a false claim of health. ## What a visitor sees -- Component name, current state (up / down / under maintenance / unknown) and - a 90-day uptime percentage. +- Component name, current state (up / down / under maintenance / pending / + unknown) and a 90-day uptime percentage. **Pending** is a monitor that has + been added but has not produced a result yet; **unknown** is one nothing is + checking any more. - A 90-day history bar per component. - Any active incidents, upcoming maintenance, and a rolling history of both. -- An optional banner across the top of the page (info / warning / critical), - for anything you want said regardless of component state. +- An optional banner across the top of the page, for anything you want said + regardless of component state. It is one notice with one appearance — there + are no severity levels to choose between. A visitor never sees a target URL, host or port, the check's expected status or keyword, latency, a certificate expiry date, failure text, or which