Enterprise-Backup-, Recovery-, Verification-, Security- und Monitoring-Plattform fuer Proxmox VE, Windows, Linux und Dateisysteme. Der Leitsatz, der fast jede Entscheidung erklaert: Ein Backup gilt erst als vertrauenswuerdig, wenn Integritaet geprueft und Wiederherstellbarkeit nachgewiesen wurde. Deshalb steigt ein Wiederherstellungspunkt erst nach einem tatsaechlich durchgefuehrten Restore-Test auf "recoverable", und Unbekanntes geht in keine Bewertung als "gut" ein. Umfang (Phasen 0-23): - Repository Engine: inhaltsadressierte Bloecke, atomares Commit-Protokoll, Katalogaufbau allein aus den Manifesten — ohne Datenbank - Backup Engine: inhaltsabhaengiges Chunking, Deduplizierung trotz Verschluesselung, zstd, AES-256-GCM, Streaming mit Gegendruck - Agenten fuer Windows und Linux mit Auftragsabholung (Pull-Modell) - Proxmox-Provider mit beiden Zugriffswegen auf die Sicherungsarchive - Scheduler, Recovery Engine mit Pruefpunkt, Verification, Unveraenderlichkeit - Weboberflaeche, Kennzahlen, Meldungen, Berichte, Security Center, Ransomware-Heuristik (meldet, handelt nie) - Disaster Recovery, Haertung, Leistungsmessung, Chaos Testing - Eingefrorene Vertraege fuer API, Migrationen, Backup-Format und Repository - Auslieferungspaket fuer linux/amd64, linux/arm64 und windows/amd64 Nicht enthalten und als solches gekennzeichnet: Kapazitaetsprognose, Backup Copy, Changed Block Tracking bei Proxmox, erweiterte Attribute und ACLs. Gebaut, aber nie auf echter Hardware gefahren: der Windows-Dienst, die systemd-Einheit und der verpflichtende Proxmox-Meilenstein — ob eine wiederhergestellte VM startet, ist ungeprueft. Einzelheiten in CHANGELOG.md und docs/release-candidate.md. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
125 lines
5.4 KiB
Plaintext
125 lines
5.4 KiB
Plaintext
# Eingefrorener API-Vertrag (Phase 22)
|
|
#
|
|
# Eine Zeile je Endpunkt: <METHODE> <pfad> <berechtigung>
|
|
#
|
|
# "/api/v1" ist ausgeliefert. Diese Datei zu aendern ist erlaubt — aber es ist
|
|
# eine bewusste Handlung, und genau darum geht es. Drei Faelle:
|
|
#
|
|
# Neuer Endpunkt -> eintragen. Er nimmt niemandem etwas weg.
|
|
# Geaenderte Berechtigung -> pruefen. Eine gelockerte Pruefung ist die
|
|
# gefaehrlichste Aenderung ueberhaupt: Der Endpunkt
|
|
# funktioniert weiter, nur duerfen ihn ploetzlich
|
|
# mehr Leute aufrufen.
|
|
# Entfallener Endpunkt -> gehoert nicht hierher. Bestehende Aufrufer brechen;
|
|
# das ist ein Fall fuer /api/v2.
|
|
#
|
|
# "-" bedeutet: ohne Anmeldung erreichbar. Das sind genau die Endpunkte, die es
|
|
# sein muessen — Anmeldung selbst und die Aufnahme eines Agenten, der noch kein
|
|
# Betriebstoken besitzt.
|
|
# "agent-token" bedeutet: Betriebstoken eines Agenten statt Benutzersitzung.
|
|
# "sitzung" bedeutet: angemeldet, aber ohne besondere Berechtigung — die
|
|
# Endpunkte, die jeder ueber sich selbst aufruft.
|
|
|
|
DELETE /api/v1/backups/{id} backups.delete
|
|
DELETE /api/v1/backups/{id}/legal-hold immutability.manage
|
|
DELETE /api/v1/jobs/{id} jobs.write
|
|
DELETE /api/v1/notification-channels/{id} settings.write
|
|
DELETE /api/v1/proxmox/clusters/{id} providers.write
|
|
DELETE /api/v1/retention-policies/{id} retention.write
|
|
DELETE /api/v1/roles/{id} roles.write
|
|
DELETE /api/v1/users/{id} users.write
|
|
GET /api/v1/agents agents.read
|
|
GET /api/v1/agents/{id} agents.read
|
|
GET /api/v1/agents/{id}/health agents.read
|
|
GET /api/v1/alerts alerts.read
|
|
GET /api/v1/alerts/summary alerts.read
|
|
GET /api/v1/alerts/{id} alerts.read
|
|
GET /api/v1/audit-events audit.read
|
|
GET /api/v1/backups backups.read
|
|
GET /api/v1/backups/{id}/assurance backups.read
|
|
GET /api/v1/backups/{id}/protection backups.read
|
|
GET /api/v1/backups/{id}/ransomware-assessment backups.read
|
|
GET /api/v1/dashboard backups.read
|
|
GET /api/v1/health -
|
|
GET /api/v1/jobs jobs.read
|
|
GET /api/v1/jobs/{id} jobs.read
|
|
GET /api/v1/jobs/{id}/runs jobs.read
|
|
GET /api/v1/me sitzung
|
|
GET /api/v1/metrics monitoring.read
|
|
GET /api/v1/metrics/{metric} monitoring.read
|
|
GET /api/v1/notification-channels settings.read
|
|
GET /api/v1/permissions roles.read
|
|
GET /api/v1/proxmox/clusters providers.read
|
|
GET /api/v1/proxmox/clusters/{id} providers.read
|
|
GET /api/v1/proxmox/clusters/{id}/hosts providers.read
|
|
GET /api/v1/proxmox/clusters/{id}/vms providers.read
|
|
GET /api/v1/proxmox/vms/{id} providers.read
|
|
GET /api/v1/reports reports.read
|
|
GET /api/v1/repositories repositories.read
|
|
GET /api/v1/repositories/{id} repositories.read
|
|
GET /api/v1/restores restores.read
|
|
GET /api/v1/restores/{id} restores.read
|
|
GET /api/v1/retention-policies repositories.read
|
|
GET /api/v1/roles roles.read
|
|
GET /api/v1/roles/{id} roles.read
|
|
GET /api/v1/security security.read
|
|
GET /api/v1/security/findings security.read
|
|
GET /api/v1/users users.read
|
|
GET /api/v1/users/{id} users.read
|
|
GET /api/v1/verification verification.read
|
|
GET /api/v1/verification/{id} verification.read
|
|
GET /api/v1/verification/{id}/results verification.read
|
|
GET /api/v1/virtual-machines providers.read
|
|
GET /health/live -
|
|
GET /health/ready -
|
|
PATCH /api/v1/repositories/{id} repositories.write
|
|
PATCH /api/v1/retention-policies/{id} retention.write
|
|
PATCH /api/v1/roles/{id} roles.write
|
|
PATCH /api/v1/users/{id} users.write
|
|
POST /api/v1/agents/enrollment-tokens agents.enroll
|
|
POST /api/v1/agents/heartbeat agent-token
|
|
POST /api/v1/agents/register -
|
|
POST /api/v1/agents/tasks/claim agent-token
|
|
POST /api/v1/agents/tasks/{id}/progress agent-token
|
|
POST /api/v1/agents/tasks/{id}/result agent-token
|
|
POST /api/v1/agents/{id}/revoke agents.write
|
|
POST /api/v1/agents/{id}/rotate-credentials agents.write
|
|
POST /api/v1/alerts/{id}/acknowledge alerts.write
|
|
POST /api/v1/alerts/{id}/resolve alerts.write
|
|
POST /api/v1/auth/login -
|
|
POST /api/v1/auth/logout sitzung
|
|
POST /api/v1/auth/mfa/verify -
|
|
POST /api/v1/auth/refresh -
|
|
POST /api/v1/backup-runs/{id}/cancel jobs.run
|
|
POST /api/v1/backups/{id}/legal-hold immutability.manage
|
|
POST /api/v1/backups/{id}/retention/extend immutability.manage
|
|
POST /api/v1/jobs jobs.write
|
|
POST /api/v1/jobs/{id}/pause jobs.run
|
|
POST /api/v1/jobs/{id}/resume jobs.run
|
|
POST /api/v1/jobs/{id}/run jobs.run
|
|
POST /api/v1/me/mfa/confirm sitzung
|
|
POST /api/v1/me/mfa/enroll sitzung
|
|
POST /api/v1/notification-channels settings.write
|
|
POST /api/v1/proxmox/clusters providers.write
|
|
POST /api/v1/proxmox/clusters/{id}/discover providers.write
|
|
POST /api/v1/proxmox/clusters/{id}/test providers.write
|
|
POST /api/v1/reports/generate reports.read
|
|
POST /api/v1/repositories repositories.write
|
|
POST /api/v1/repositories/{id}/enforcement/measure repositories.write
|
|
POST /api/v1/repositories/{id}/health-check repositories.read
|
|
POST /api/v1/repositories/{id}/integrity-scan repositories.write
|
|
POST /api/v1/repositories/{id}/rebuild-catalog repositories.write
|
|
POST /api/v1/repositories/{id}/retention/apply retention.write
|
|
POST /api/v1/repositories/{id}/retention/preview repositories.read
|
|
POST /api/v1/repositories/{id}/test repositories.read
|
|
POST /api/v1/restores restores.execute
|
|
POST /api/v1/restores/validate restores.read
|
|
POST /api/v1/restores/{id}/cancel restores.execute
|
|
POST /api/v1/restores/{id}/resume restores.execute
|
|
POST /api/v1/retention-policies retention.write
|
|
POST /api/v1/roles roles.write
|
|
POST /api/v1/users users.write
|
|
POST /api/v1/users/{id}/mfa/disable users.write
|
|
POST /api/v1/verification verification.write
|
|
POST /api/v1/verification/{id}/cancel verification.write
|