feat(distribution): production install/update/backup scripts + public-repo sync (#106)

Builds the customer-facing distribution: a curated distribution/ directory
containing only what an end customer needs (production docker-compose.yml
with no build: sections, install.sh/update.sh/uninstall.sh/healthcheck.sh/
backup.sh/restore.sh, a customer-facing CHANGELOG.md, and README/LICENSE/
NOTICE/THIRD_PARTY_LICENSES) — pushed as the initial content of the new
public alleyviper/argus repo.

install.sh: detects OS, validates Docker/Compose, fetches all deployment
files, generates a secure DB password, creates the required Docker
network, pulls images, starts the stack, waits for health, and rotates
the default admin/admin credentials via the auth API — printing the
generated password once at the end.

update.sh/healthcheck.sh/backup.sh/restore.sh/uninstall.sh formalize what
was previously ad-hoc README snippets into real, safe-by-default scripts
(uninstall.sh keeps data unless --remove-data is explicitly passed and
confirmed; restore.sh requires typed confirmation and documents that it
targets a fresh install, not a live merge).

Added a sync-distribution job to release.yml: after a successful release,
mirrors distribution/ into the public repo and creates a matching
(customer-facing, commit-log-free) release marker there. Needs a one-time
setup step — a fine-grained PAT scoped to alleyviper/argus added as the
ARGUS_PUBLIC_REPO_TOKEN secret — the job cleanly no-ops until that's added.

Not yet done: GHCR package visibility (argus-secure-api/-ui/-nginx) is
still private, which blocks a genuine end-to-end curl-install test from a
clean, unauthenticated environment — deferred at the user's request until
they flip it manually (GitHub does not expose this via API).
This commit is contained in:
alleyviper
2026-07-19 18:06:02 +01:00
committed by GitHub
commit 44f662afc0
14 changed files with 1213 additions and 0 deletions
+17
View File
@@ -0,0 +1,17 @@
ARGUS Secure — Proprietary Software License
Copyright (c) 2025-2026 AI4SEC / lmelo. All rights reserved.
** PLACEHOLDER — NOT A FINAL LICENSE **
This repository contains proprietary, commercial software. A complete commercial license
agreement has not yet been finalized and this file is a placeholder pending legal review.
Until a final license is adopted, no rights are granted to use, copy, modify, merge, publish,
distribute, sublicense, or sell copies of this software, in whole or in part, except as
separately agreed in writing with the copyright holder.
This software incorporates third-party open-source components under their own licenses;
see THIRD_PARTY_LICENSES and NOTICE for details. Nothing in this placeholder alters the terms
of those third-party components.
TODO before release: replace this file with final commercial/enterprise license text.