The WebUI is a static single-page application (SPA) running entirely in the browser. It communicates with local EdgeStream services via a secure reverse proxy.
Browser
|
| HTTPS
v
nginx (Gateway)
|---- /api ------> EdgeStream API (FastAPI)
|---- /graphql --> GraphQL WebSocket service
|---- /influx ---> InfluxDB UI (proxied)
- Static build, no server-side rendering
- Reverse-proxy enforced security
- Offline-first appliance deployment
- Minimal runtime dependencies
- HTTPS requests to
/api - Apollo Client manages caching and state
- WebSocket connections to
/graphql - Used for live metrics and event flow updates
- Credentials validated by API
- JWT stored client-side
- No external dependencies
- OAuth2 / OIDC redirect flow
- Token validated by API
- UI adapts based on auth mode
- Strict Content-Security-Policy
- Explicit WebSocket upgrades
- Same-origin API enforcement
- TLS terminated at gateway
- Installed via Debian package
- Static assets served from
/opt/edgestream-webui/html - nginx handles routing, headers, and TLS