{% extends "base.html" %} {% block title %}Settings{% endblock %} {% block heading %}Settings{% endblock %} {% block content %}

Caches

{% include "_cache_badges.html" %}

Security lookups are cached in the application database: NVD CVSS data per CVE (table nvd_cache), Canonical security data per CVE (cve_metadata_cache) and Amazon Linux updateinfo per repository (amazon_updateinfo_cache). An entry younger than its TTL is used without a request; an older one is refreshed on its next lookup and only used as a fallback when the source cannot be reached. Changing a TTL never deletes entries. Failed lookups are never cached.

{% for key, label in cache_ttl_labels.items() %}
{% if cache_ttl_errors.get(key) %}
{{ cache_ttl_errors[key] }}
{% endif %}
{% endfor %}
Hours (24h) or days (30d), between 1 hour and 365 days. Defaults: NVD 30d, Canonical 24h (1h while a release is under investigation), Amazon updateinfo 24h.{% if not cache_ttl_saved %} The defaults are in use.{% endif %}

Clear Security Cache empties all three caches (NVD, Canonical and Amazon updateinfo) and the in-memory lookup state.

Patch & Download Settings

{% if template_error %}
{{ template_error }}
{% endif %}
Must contain ${server_name} and resolve to an absolute path (~ is expanded). Default: {{ default_staging_template }}. Changes apply to future patch executions only.
Saved Template
{{ saved_template }}
Resolved for {{ preview_name }}
{% if preview %}{{ preview }}{% else %}{{ preview_error }}{% endif %}
Remote Staging
{{ remote_example }} (fixed: /tmp/${server_name} on the server)
{% if server_names|length > 1 %}
{% endif %}

NVD API Key

Optional key for faster CVSS lookups (50 instead of 5 NVD requests per 30 s). A key saved here is stored encrypted and is used instead of the NVD_API_KEY environment variable. Only its last 4 characters are ever shown.

Saved key
{% if nvd_key.error %}{{ nvd_key.error }}{% elif nvd_key.saved %}{{ nvd_key.masked }}{% else %}none{% endif %}
NVD_API_KEY env var
{% if nvd_key.env_set %}set{% if nvd_key.saved %} (overridden by the saved key){% endif %}{% else %}not set{% endif %}
Status
{% include "_nvd_key_badge.html" %}
{# Never pre-filled: the key is never sent back to the browser. #} {% if nvd_key_error %}
{{ nvd_key_error }}
{% endif %}
{% if nvd_key.testable %}{% endif %} {% if nvd_key.saved %}{% endif %}

Logging

{% if log_dir_error %}
{{ log_dir_error }}
{% endif %}
Absolute path (~ is expanded); it is created if needed and must be writable. Default: {{ default_log_dir }}.
Current log file
{% if active_log_file %}{{ active_log_file }}{% else %}{{ log_file }} (file logging is not active in this process){% endif %}
Rotation
{{ log_backups }} × {{ log_max_mb }} MB (oldest file is removed)

Application

Version
{{ version }}
Database
{{ db_path }}
SSH user
Per server (default ubuntu)
SSH login
Per server: PEM key (default) or username + password via sshpass; passwords are stored per server, encrypted
Encryption key
{{ secret_key_path }} (mode 0600, never in the database; without it stored secrets must be entered again)

Security Data

Canonical security data is queried online per CVE during analysis. Each fetched CVE is also cached in the application database (see Caches for the TTLs); an expired copy is used (and marked with its age) only when ubuntu.com cannot be reached.

Cache
table cve_metadata_cache in {{ metadata_status.cache_db }}
Cache TTL
{{ "%g"|format(metadata_status.cache_ttl_hours) }} hours ({{ "%g"|format(metadata_status.investigating_ttl_hours) }} hour{{ "" if metadata_status.investigating_ttl_hours == 1 else "s" }} while a release is under investigation) — change
Requests
{{ "%g"|format(metadata_status.timeout_seconds) }} s timeout, {{ "%g"|format(metadata_status.pace_seconds) }} s apart, up to {{ metadata_status.attempts }} attempts with backoff; lookups pause for the rest of the run after {{ metadata_status.breaker_threshold }} consecutive failures
Proxy
HTTPS_PROXY / NO_PROXY from the environment

APT Resolution

APT candidates and the .deb plan are resolved on this workstation against private package lists per Ubuntu release and architecture (release, -updates and -security pockets). Servers are only read (dpkg-query); the system APT configuration is never used or changed.

Private APT state
{{ apt_state_dir }}
Refresh when older than
{{ "%g"|format(apt_max_age_hours) }} hours{% if not apt_max_age_hours %} (every analysis run){% endif %}

Reset Database

Permanently removes servers, reports, analyses, and settings.

{% endblock %}