- 13 commands with full gRPC implementations: service, train, tune, model, trade, broker, agent, data, risk, config, cluster, auth, backtest - Streaming support: train logs --follow, broker executions --follow - --json output on every command via OutputFormat/HumanReadable - Fix web-gateway monitoring URL default (50057 → 50051, API Gateway) - Rewire 7 remaining build.rs to consolidated proto/ root (web-gateway, backtesting_service, training_uploader, 3 test crates, e2e) - Fix web-gateway ml_training.proto new fields (mode, max_epochs, resume) - 75 fxt tests + 139 web-gateway tests, 0 clippy warnings, workspace clean Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
web-gateway
REST and WebSocket gateway for the Foxhunt web dashboard. Axum 0.7.9 proxying HTTP to backend gRPC services.
Key Types
AppState— shared state (gRPC channels, WS broadcast, config)GatewayConfig— configuration loaded from environment variables
Modules
auth— JWT validation and login handlerroutes— Axum router and HTTP handlersgrpc— Tonic clients and gRPC stream bridgesws— WebSocket upgrade, topic subscriptions, keepaliverate_limit— per-IP token-bucket rate limiter (3 tiers)error— unified error types and HTTP error responses
Rate Limits
| Tier | Limit | Endpoints |
|---|---|---|
| Public | 10 req/min | POST /api/auth/login |
| Trading | 200 req/min | /api/trading/*, /api/risk/*, /api/ml/* |
| Compute | 30 req/min | /api/training/*, /api/backtest/*, /api/tune/* |
Security
- JWT (32-char min secret), CORS, 1MB body limit, HSTS
- WebSocket topic whitelist (8 topics), per-connection rate limit, max 20 subs
X-Request-Idpropagation