Repository navigation
feat(demo): read-only demo mode and :demo image - #124
Merged
Merged
Conversation
A binary linked with DEMO_MODE=true refuses every mutating request with 403 DEMO_MODE, closes the ping, MCP and OAuth surfaces, and only accepts a remote Docker endpoint (DOCKER_HOST=tcp://) so a demo instance can never reach a local socket or a cluster. A driver token (MAINTENANT_DEMO_TOKEN) lets the seeding job write through the guard. The SPA reads the edition payload, shows a persistent banner and turns the 403 into a toast instead of an error. CI builds the same Dockerfile a second time on push to main and publishes it as the `:demo` tag, without touching the outputs release.yml signs.
Demo mode now leaves the outbound heartbeat routes unregistered and never starts the send loop, so a demo instance cannot reach out to arbitrary URLs, even with the demo token. The Heartbeats page hides the Outgoing tab. The :demo image is now built on each published, non-prerelease release instead of on every push to main.
Add the Outbound Heartbeats section the Heartbeats page links to, list its endpoints in the API reference, and state that the daemon must expose Docker API 1.40 or later (Docker 19.03+).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds a read-only demo mode so Maintenant can run as a public demo
(demo.maintenant.dev) against the fake Docker daemon from maintenant-demo.
A binary built with
DEMO_MODE=true:403 DEMO_MODE, except for requestscarrying
MAINTENANT_DEMO_TOKEN, which the demo driver uses to seed data;instance never calls URLs that come from outside;
DOCKER_HOST=tcp://), never alocal socket or a Kubernetes cluster.
The SPA shows a persistent demo banner, turns 403 responses into toasts and
hides the Outgoing heartbeats tab.
CI builds the same Dockerfile with
DEMO_MODE=trueon every published,non-prerelease release and publishes it as
ghcr.io/kolapsis/maintenant:demo.The signed release image and its attestations are unchanged.