Skip to content

Latest commit

 

History

History
64 lines (46 loc) · 2.21 KB

File metadata and controls

64 lines (46 loc) · 2.21 KB

LLMRed Web Control Plane

The web control plane adds a local, single-organization interface without changing the existing assessment engine. Phase 3 can execute the unchanged cli.py in an isolated subprocess and ingest its real report artifacts. Mock mode remains available only for interface demonstrations and tests.

Current capabilities

  • Server-side Argon2id authentication with opaque HttpOnly sessions and CSRF protection.
  • Administrator, Security Analyst, and Read-only Reviewer roles.
  • Authorized engagement creation with target, surface, provider, and policy data.
  • Enforced assessment windows and one-active-run coordination.
  • Durable SQLite records with interrupted-run recovery on backend restart.
  • Real or mocked assessment lifecycle with live operational status.
  • One-time API credential prompt for real runs; the credential is never persisted.
  • Real JSON, HTML, and PDF artifact links after successful CLI completion.
  • No API credentials stored in SQLite, browser storage, YAML, logs, or API responses.

Docker quick start

From the web directory:

cp .env.example .env
nano .env
docker compose up --build

Set a long, unique LLMRED_WEB_BOOTSTRAP_ADMIN_PASSWORD before starting. Set LLMRED_WEB_MOCK_RUNNER=false for real assessments. Then open http://127.0.0.1:8090 through an SSH tunnel when the server is remote.

The backend is reachable only inside the Docker network. Only nginx publishes 127.0.0.1:8090; port 8080 remains available for the existing lab API.

Local development

Backend:

cd web/backend
python3 -m venv .venv
source .venv/bin/activate
pip install -r requirements.txt
cp .env.example .env
uvicorn app.main:app --host 127.0.0.1 --port 8000 --workers 1

Frontend, in another terminal:

cd web/frontend
npm ci
npm run dev

Test

cd web/backend
python -m pytest -q

cd ../frontend
npm run build

Engine integration boundary

The runner invokes the existing root cli.py with asyncio.create_subprocess_exec, a fixed argument array, shell=False, a validated working directory, and an allowlisted child environment. It validates generated configuration against pentest.config.AppConfig. No engine source modification or monkey-patching is used.