The web control plane adds a local, single-organization interface without changing the existing assessment engine. Phase 3 can execute the unchanged cli.py in an isolated subprocess and ingest its real report artifacts. Mock mode remains available only for interface demonstrations and tests.
- Server-side Argon2id authentication with opaque HttpOnly sessions and CSRF protection.
- Administrator, Security Analyst, and Read-only Reviewer roles.
- Authorized engagement creation with target, surface, provider, and policy data.
- Enforced assessment windows and one-active-run coordination.
- Durable SQLite records with interrupted-run recovery on backend restart.
- Real or mocked assessment lifecycle with live operational status.
- One-time API credential prompt for real runs; the credential is never persisted.
- Real JSON, HTML, and PDF artifact links after successful CLI completion.
- No API credentials stored in SQLite, browser storage, YAML, logs, or API responses.
From the web directory:
cp .env.example .env
nano .env
docker compose up --buildSet a long, unique LLMRED_WEB_BOOTSTRAP_ADMIN_PASSWORD before starting. Set LLMRED_WEB_MOCK_RUNNER=false for real assessments. Then open http://127.0.0.1:8090 through an SSH tunnel when the server is remote.
The backend is reachable only inside the Docker network. Only nginx publishes 127.0.0.1:8090; port 8080 remains available for the existing lab API.
Backend:
cd web/backend
python3 -m venv .venv
source .venv/bin/activate
pip install -r requirements.txt
cp .env.example .env
uvicorn app.main:app --host 127.0.0.1 --port 8000 --workers 1Frontend, in another terminal:
cd web/frontend
npm ci
npm run devcd web/backend
python -m pytest -q
cd ../frontend
npm run buildThe runner invokes the existing root cli.py with asyncio.create_subprocess_exec, a fixed argument array, shell=False, a validated working directory, and an allowlisted child environment. It validates generated configuration against pentest.config.AppConfig. No engine source modification or monkey-patching is used.