[CORE] Initial project scaffold - NIS2 Agile Compliance Platform

Complete MVP implementation including:
- PHP 8.4 backend with Front Controller pattern (80+ API endpoints)
- Multi-tenant architecture with organization_id isolation
- JWT authentication (HS256, 2h access + 7d refresh tokens)
- 14 controllers: Auth, Organization, Assessment, Dashboard, Risk,
  Incident, Policy, SupplyChain, Training, Asset, Audit, Admin
- AI Service integration (Anthropic Claude API) for gap analysis,
  risk suggestions, policy generation, incident classification
- NIS2 gap analysis questionnaire (~80 questions, 10 categories)
- MySQL schema (20 tables) with NIS2 Art. 21 compliance controls
- NIS2 Art. 23 incident reporting workflow (24h/72h/30d)
- Frontend: login, register, dashboard, assessment wizard, org setup
- Docker configuration (PHP-FPM + Nginx + MySQL)

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
2026-02-17 17:50:18 +01:00
co-authored by Claude Opus 4.6
commit ae78a2f7f4
36 changed files with 10483 additions and 0 deletions
+18
View File
@@ -0,0 +1,18 @@
FROM php:8.4-fpm-alpine
# Extensions
RUN docker-php-ext-install pdo pdo_mysql
# Curl extension
RUN apk add --no-cache curl-dev && docker-php-ext-install curl
# Config
COPY docker/php.ini /usr/local/etc/php/conf.d/custom.ini
WORKDIR /var/www/nis2-agile
COPY . .
RUN chown -R www-data:www-data /var/www/nis2-agile
EXPOSE 9000
+77
View File
@@ -0,0 +1,77 @@
version: '3.8'
services:
# ── PHP-FPM Application ──────────────────────────────────────────────────
app:
build:
context: ..
dockerfile: docker/Dockerfile
container_name: nis2-app
restart: unless-stopped
volumes:
- ../application:/var/www/nis2-agile/application
- ../public:/var/www/nis2-agile/public
environment:
- APP_ENV=${APP_ENV:-production}
- APP_DEBUG=${APP_DEBUG:-false}
- DB_HOST=db
- DB_PORT=3306
- DB_DATABASE=${DB_DATABASE:-nis2_agile_db}
- DB_USERNAME=${DB_USERNAME:-nis2_user}
- DB_PASSWORD=${DB_PASSWORD}
- JWT_SECRET=${JWT_SECRET}
- ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY}
networks:
- nis2-network
depends_on:
db:
condition: service_healthy
# ── Nginx Web Server ─────────────────────────────────────────────────────
web:
image: nginx:1.25-alpine
container_name: nis2-web
restart: unless-stopped
ports:
- "${WEB_PORT:-8080}:8080"
volumes:
- ./nginx.conf:/etc/nginx/conf.d/default.conf:ro
- ../public:/var/www/nis2-agile/public:ro
networks:
- nis2-network
depends_on:
- app
# ── MySQL Database ───────────────────────────────────────────────────────
db:
image: mysql:8.0
container_name: nis2-db
restart: unless-stopped
environment:
MYSQL_ROOT_PASSWORD: ${DB_ROOT_PASSWORD}
MYSQL_DATABASE: ${DB_DATABASE:-nis2_agile_db}
MYSQL_USER: ${DB_USERNAME:-nis2_user}
MYSQL_PASSWORD: ${DB_PASSWORD}
ports:
- "${DB_PORT:-3306}:3306"
volumes:
- nis2-db-data:/var/lib/mysql
- ../docs/sql/001_initial_schema.sql:/docker-entrypoint-initdb.d/001_initial_schema.sql:ro
healthcheck:
test: ["CMD", "mysqladmin", "ping", "-h", "localhost", "-u", "root", "-p${DB_ROOT_PASSWORD}"]
interval: 10s
timeout: 5s
retries: 5
start_period: 30s
networks:
- nis2-network
# ── Volumes ──────────────────────────────────────────────────────────────
volumes:
nis2-db-data:
driver: local
# ── Networks ─────────────────────────────────────────────────────────────
networks:
nis2-network:
driver: bridge
+62
View File
@@ -0,0 +1,62 @@
server {
listen 8080;
server_name _;
root /var/www/nis2-agile/public;
index index.php index.html;
charset utf-8;
# ── Security Headers ───────────────────────────────────────────────────
add_header X-Frame-Options "SAMEORIGIN" always;
add_header X-Content-Type-Options "nosniff" always;
add_header X-XSS-Protection "1; mode=block" always;
add_header Referrer-Policy "strict-origin-when-cross-origin" always;
# ── Logging ────────────────────────────────────────────────────────────
access_log /var/log/nginx/nis2-access.log;
error_log /var/log/nginx/nis2-error.log;
# ── Max Upload Size ────────────────────────────────────────────────────
client_max_body_size 20M;
# ── Main Location ──────────────────────────────────────────────────────
location / {
try_files $uri $uri/ /index.php?$query_string;
}
# ── PHP-FPM Processing ─────────────────────────────────────────────────
location ~ \.php$ {
fastcgi_pass app:9000;
fastcgi_index index.php;
fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
include fastcgi_params;
fastcgi_param HTTP_PROXY "";
fastcgi_buffer_size 128k;
fastcgi_buffers 4 256k;
fastcgi_busy_buffers_size 256k;
fastcgi_read_timeout 300;
}
# ── Static Assets Caching ──────────────────────────────────────────────
location ~* \.(css|js|png|jpg|jpeg|gif|ico|svg|woff|woff2|ttf|eot)$ {
expires 30d;
add_header Cache-Control "public, immutable";
access_log off;
}
# ── Deny Hidden Files ──────────────────────────────────────────────────
location ~ /\. {
deny all;
access_log off;
log_not_found off;
}
# ── Deny access to sensitive files ─────────────────────────────────────
location ~* \.(env|sql|md|json|lock|yml|yaml)$ {
deny all;
access_log off;
log_not_found off;
}
}