feat(backend): add §8 data model + Alembic baseline (B0.2, B0.3)

- SQLAlchemy 2 typed mapped classes for every spec §8 aggregate:
  engagement, c2_credential, host, user, group, group_permission,
  user_group, engagement_member, ttp, ttp_version, scenario,
  scenario_step, run, run_step, run_step_cleanup, detection, evidence,
  report, soc_session, audit_log.
- Shared mixins: UuidPkMixin (PG_UUID(as_uuid=True)) + TimestampsMixin.
- StrEnum types covering every spec enum (C2Type, PayloadType, UserType,
  EngagementStatus, HostStatus, TtpSource, RunStatus, RunStepStatus,
  CleanupStatus, DetectionLevel, DetectionSource, EvidenceStatus).
- Alembic baseline migration 202605210001_initial_schema: creates every
  table, enum, index, and idempotent grants for the audit_log
  write-only Postgres role (mimic_audit_writer).
- Audit log carries prev_hash / row_hash from v1 (D-009).
- ttp_version table coexists with run.snapshot_json (D-008,
  overrides H32).
This commit is contained in:
knacky
2026-05-21 20:32:45 +02:00
parent a93c959444
commit 22d37fb240
23 changed files with 1833 additions and 0 deletions

View File

@@ -0,0 +1,27 @@
"""Structured JSON logging (NF-observability)."""
from __future__ import annotations
import logging
import sys
from pythonjsonlogger.jsonlogger import JsonFormatter
def configure_logging(level: str = "INFO", *, as_json: bool = True) -> None:
"""Configure the root logger once at app start."""
handler = logging.StreamHandler(sys.stdout)
if as_json:
formatter: logging.Formatter = JsonFormatter(
"%(asctime)s %(levelname)s %(name)s %(message)s"
)
else:
formatter = logging.Formatter(
"%(asctime)s %(levelname)-8s %(name)s: %(message)s"
)
handler.setFormatter(formatter)
root = logging.getLogger()
root.handlers.clear()
root.addHandler(handler)
root.setLevel(level.upper())