feat(anis): auto-provision ANIS Community Edition on fresh installs (Phase 4)

Changed the ANIS_URL default from the docker-internal
"http://argus-anis:8090" to the public Community Edition hub
(https://anis.weboria.eu). That internal default was dead on arrival for
every real deployment path: neither docker/docker-compose.yml nor
distribution/docker-compose.yml bundles its own ANIS container (confirmed
via grep — only the dev-only docker-compose.local-sandbox.yml does, and
it already sets ANIS_URL explicitly, so it's unaffected by this change),
so a fresh install using either client-facing compose file previously got
ANIS_ENABLED=false and an empty/unreachable ANIS_URL with no working
threat intelligence out of the box.

An empty license key already grants the "community" tier server-side
(confirmed against ANIS's own RegisterInstance handler in a prior
grounding pass) — no signup or key needed, so defaulting
enabled=true/url=<public hub>/key=empty is a genuine zero-friction
default, not a placeholder pointing at something that doesn't work.
ANIS_ENABLED flipped from :-false to :-true in both compose files'
inline fallback (not just the .env.example docs) since a compose-level
explicit "false" string takes precedence over the Go binary's own
compiled default and previously masked it.

Updated distribution/.env.example and configs/env.example to match.

Live-verified against a genuinely fresh sandbox install (temporarily
unset the sandbox compose's own ANIS_URL override to actually exercise
the new default, reverted before committing — confirmed clean via `git
diff`): anis_settings bootstrapped to
enabled=true/url=https://anis.weboria.eu/license_key=''/bootstrapped=true
on first boot. Re-verified the sandbox's own explicit local override
(http://anis:8090, for its bundled ANIS container) still wins unaffected
after reverting.
This commit is contained in:
alleyviper
2026-07-25 15:20:10 +00:00
committed by root
parent 913615903b
commit 5bdfd99c4d
2 changed files with 12 additions and 8 deletions
+6 -4
View File
@@ -25,11 +25,13 @@ DB_NAME=argus
# community instance). These vars configure how THIS ARGUS instance talks to
# an already-running ANIS service — they do not start one.
#
# Set ANIS_ENABLED=true and ANIS_URL to turn on reporting WAF auto-bans to
# ANIS and pulling its community threat-intelligence feed.
# On by default against the public Community Edition hub — an empty license
# key already grants the community (free) tier, no signup required. Point
# ANIS_URL at your own self-hosted ANIS instead if you run one, or set
# ANIS_ENABLED=false to turn this off entirely.
ANIS_ENABLED=false
# ANIS_URL=https://anis.example.com:8090
ANIS_ENABLED=true
ANIS_URL=https://anis.weboria.eu
# License key from ANIS dashboard -> Licenses -> Create License.
# Leave blank to use the community (free) tier.
ANIS_LICENSE_KEY=
+6 -4
View File
@@ -118,10 +118,12 @@ services:
NGINX_HTTPS_PORT: ${NGINX_HTTPS_PORT:-}
API_HOST_PORT: ${API_HOST_PORT:-9080}
API_HOST: ${API_HOST:-}
# ANIS community intelligence — optional, off by default. Set these to
# connect this instance to an already-running ANIS hub.
ANIS_ENABLED: ${ANIS_ENABLED:-false}
ANIS_URL: ${ANIS_URL:-}
# ANIS community intelligence — on by default against the public
# Community Edition hub (empty license key = community tier, no signup
# required). Set ANIS_URL to your own self-hosted ANIS instead if you
# run one, or ANIS_ENABLED=false to turn this off entirely.
ANIS_ENABLED: ${ANIS_ENABLED:-true}
ANIS_URL: ${ANIS_URL:-https://anis.weboria.eu}
ANIS_LICENSE_KEY: ${ANIS_LICENSE_KEY:-}
ANIS_SHARE_ATTACKERS: ${ANIS_SHARE_ATTACKERS:-false}
DNS_SECURITY_LISTEN_ADDR: ":53"