Files
foxhunt/web-gateway/README.md
jgrusewski 8b81138262 docs: rewrite outdated READMEs and add web-gateway docs
Rewrite 7 crate READMEs to reflect current architecture: correct
model types (DQN/PPO/TFT/Mamba2), AtomicKillSwitch, real
EnsembleConfig source from ml, actual data crate purpose,
web-dashboard project details, ml_training_service ports.

Fix 5 api_gateway/TLI docs: strip swarm agent framing, update
service endpoints to api_gateway:50050, remove deleted dashboard
references and hardcoded paths.

Add missing web-gateway/README.md documenting 24 REST endpoints,
WebSocket support, JWT auth, and 3-tier rate limiting.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-22 18:39:12 +01:00

59 lines
2.4 KiB
Markdown

# web-gateway
REST and WebSocket gateway for the Foxhunt web dashboard. Built with Axum 0.7.9, it proxies HTTP requests to backend gRPC services and bridges gRPC streams to WebSocket clients.
## Configuration
All settings are read from environment variables.
| Variable | Default | Description |
|---|---|---|
| `GATEWAY_LISTEN_ADDR` | `0.0.0.0:3000` | HTTP listen address |
| `JWT_SECRET` | _(required, min 32 chars)_ | HMAC key for JWT validation |
| `CORS_ORIGINS` | `http://localhost:5173` | Comma-separated allowed origins |
| `TRADING_SERVICE_URL` | `https://localhost:50051` | Trading gRPC upstream |
| `BACKTESTING_SERVICE_URL` | `https://localhost:50052` | Backtesting gRPC upstream |
| `ML_TRAINING_SERVICE_URL` | `https://localhost:50053` | ML training gRPC upstream |
## Routes
All API routes are under `/api`. Authentication is required unless noted.
| Tier | Rate Limit | Endpoints |
|---|---|---|
| Public | 10 req/min | `POST /api/auth/login` |
| Trading | 200 req/min | `/api/trading/*`, `/api/risk/*`, `/api/ml/*`, `/api/performance/*`, `/api/config/*` |
| Compute | 30 req/min | `/api/training/*`, `/api/backtest/*`, `/api/tune/*` |
| WebSocket | 50 msg/min | `GET /api/ws` (JWT via `token` query param) |
| Health | none | `GET /health`, `GET /ready` |
## Security
- JWT authentication middleware (32-character minimum secret enforced at startup)
- Per-IP rate limiting across three tiers
- 1 MB request body size limit
- CORS with explicit methods (`GET`, `POST`, `PUT`, `DELETE`) and headers (`Authorization`, `Content-Type`)
- Response headers: HSTS, `x-frame-options: DENY`, `x-content-type-options: nosniff`, `referrer-policy: strict-origin-when-cross-origin`
- WebSocket topic whitelist (8 valid topics), per-connection rate limit, max 20 subscriptions
- `X-Request-Id` propagation (generated if absent, echoed on response)
## Modules
| Module | Purpose |
|---|---|
| `auth` | JWT validation and login handler |
| `config` | `GatewayConfig` loaded from environment |
| `error` | Unified error types and HTTP error responses |
| `grpc` | Tonic clients and gRPC stream bridges |
| `rate_limit` | Per-IP token-bucket rate limiter (3 tiers) |
| `routes` | Axum router construction and all HTTP handlers |
| `state` | `AppState` (gRPC channels, WS broadcast, config) |
| `ws` | WebSocket upgrade, topic subscriptions, keepalive |
## Running
```sh
export JWT_SECRET="your-secret-at-least-32-characters-long"
cargo run -p web-gateway
```