Rewrite 7 crate READMEs to reflect current architecture: correct model types (DQN/PPO/TFT/Mamba2), AtomicKillSwitch, real EnsembleConfig source from ml, actual data crate purpose, web-dashboard project details, ml_training_service ports. Fix 5 api_gateway/TLI docs: strip swarm agent framing, update service endpoints to api_gateway:50050, remove deleted dashboard references and hardcoded paths. Add missing web-gateway/README.md documenting 24 REST endpoints, WebSocket support, JWT auth, and 3-tier rate limiting. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
59 lines
2.4 KiB
Markdown
59 lines
2.4 KiB
Markdown
# web-gateway
|
|
|
|
REST and WebSocket gateway for the Foxhunt web dashboard. Built with Axum 0.7.9, it proxies HTTP requests to backend gRPC services and bridges gRPC streams to WebSocket clients.
|
|
|
|
## Configuration
|
|
|
|
All settings are read from environment variables.
|
|
|
|
| Variable | Default | Description |
|
|
|---|---|---|
|
|
| `GATEWAY_LISTEN_ADDR` | `0.0.0.0:3000` | HTTP listen address |
|
|
| `JWT_SECRET` | _(required, min 32 chars)_ | HMAC key for JWT validation |
|
|
| `CORS_ORIGINS` | `http://localhost:5173` | Comma-separated allowed origins |
|
|
| `TRADING_SERVICE_URL` | `https://localhost:50051` | Trading gRPC upstream |
|
|
| `BACKTESTING_SERVICE_URL` | `https://localhost:50052` | Backtesting gRPC upstream |
|
|
| `ML_TRAINING_SERVICE_URL` | `https://localhost:50053` | ML training gRPC upstream |
|
|
|
|
## Routes
|
|
|
|
All API routes are under `/api`. Authentication is required unless noted.
|
|
|
|
| Tier | Rate Limit | Endpoints |
|
|
|---|---|---|
|
|
| Public | 10 req/min | `POST /api/auth/login` |
|
|
| Trading | 200 req/min | `/api/trading/*`, `/api/risk/*`, `/api/ml/*`, `/api/performance/*`, `/api/config/*` |
|
|
| Compute | 30 req/min | `/api/training/*`, `/api/backtest/*`, `/api/tune/*` |
|
|
| WebSocket | 50 msg/min | `GET /api/ws` (JWT via `token` query param) |
|
|
| Health | none | `GET /health`, `GET /ready` |
|
|
|
|
## Security
|
|
|
|
- JWT authentication middleware (32-character minimum secret enforced at startup)
|
|
- Per-IP rate limiting across three tiers
|
|
- 1 MB request body size limit
|
|
- CORS with explicit methods (`GET`, `POST`, `PUT`, `DELETE`) and headers (`Authorization`, `Content-Type`)
|
|
- Response headers: HSTS, `x-frame-options: DENY`, `x-content-type-options: nosniff`, `referrer-policy: strict-origin-when-cross-origin`
|
|
- WebSocket topic whitelist (8 valid topics), per-connection rate limit, max 20 subscriptions
|
|
- `X-Request-Id` propagation (generated if absent, echoed on response)
|
|
|
|
## Modules
|
|
|
|
| Module | Purpose |
|
|
|---|---|
|
|
| `auth` | JWT validation and login handler |
|
|
| `config` | `GatewayConfig` loaded from environment |
|
|
| `error` | Unified error types and HTTP error responses |
|
|
| `grpc` | Tonic clients and gRPC stream bridges |
|
|
| `rate_limit` | Per-IP token-bucket rate limiter (3 tiers) |
|
|
| `routes` | Axum router construction and all HTTP handlers |
|
|
| `state` | `AppState` (gRPC channels, WS broadcast, config) |
|
|
| `ws` | WebSocket upgrade, topic subscriptions, keepalive |
|
|
|
|
## Running
|
|
|
|
```sh
|
|
export JWT_SECRET="your-secret-at-least-32-characters-long"
|
|
cargo run -p web-gateway
|
|
```
|