diff --git a/.env.example b/.env.example index 62d3878..748a589 100644 --- a/.env.example +++ b/.env.example @@ -30,9 +30,9 @@ DB_NAME=argus ANIS_ENABLED=false # ANIS_URL=https://anis.example.com:8090 +# License key from ANIS dashboard -> Licenses -> Create License. +# Leave blank to use the community (free) tier. ANIS_LICENSE_KEY= -# Must match the ANIS instance's own ANIS_ADMIN_KEY. Generate: openssl rand -hex 32 -ANIS_ADMIN_KEY= ANIS_SHARE_ATTACKERS=false # =========================================== diff --git a/docker-compose.yml b/docker-compose.yml index a70abd6..9163a43 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -123,7 +123,6 @@ services: ANIS_ENABLED: ${ANIS_ENABLED:-false} ANIS_URL: ${ANIS_URL:-} ANIS_LICENSE_KEY: ${ANIS_LICENSE_KEY:-} - ANIS_ADMIN_KEY: ${ANIS_ADMIN_KEY:-} ANIS_SHARE_ATTACKERS: ${ANIS_SHARE_ATTACKERS:-false} DNS_SECURITY_LISTEN_ADDR: ":53" ports: @@ -196,6 +195,7 @@ services: max-file: "5" environment: TZ: ${TZ:-UTC} + UI_PORT: ${UI_PORT:-81} ulimits: nofile: soft: 65535 diff --git a/install.sh b/install.sh index 5235a8e..2226214 100755 --- a/install.sh +++ b/install.sh @@ -97,32 +97,13 @@ if [ "$READY" != "true" ]; then fi ok "ARGUS is up" -# ── 8. Rotate the default admin credentials ─────────────────────────────────── -ADMIN_USER="admin" -ADMIN_PASSWORD="Ax9!$(openssl rand -base64 24 | tr -dc 'A-Za-z0-9' | head -c 20)" -API_BASE="http://127.0.0.1:${API_HOST_PORT}/api/v1" - -LOGIN_RESP="$(curl -fsS -X POST "${API_BASE}/auth/login" \ - -H 'Content-Type: application/json' \ - -d '{"username":"admin","password":"admin"}' 2>/dev/null || true)" -TOKEN="$(printf '%s' "${LOGIN_RESP}" | grep -oP '"token"\s*:\s*"\K[^"]+' || true)" - -CREDS_ROTATED=false -if [ -n "$TOKEN" ]; then - CHANGE_RESP="$(curl -fsS -o /dev/null -w '%{http_code}' -X POST "${API_BASE}/auth/change-credentials" \ - -H 'Content-Type: application/json' \ - -H "Authorization: Bearer ${TOKEN}" \ - -d "{\"current_password\":\"admin\",\"new_username\":\"${ADMIN_USER}\",\"new_password\":\"${ADMIN_PASSWORD}\",\"new_password_confirm\":\"${ADMIN_PASSWORD}\"}" 2>/dev/null || echo "000")" - if [ "$CHANGE_RESP" = "200" ]; then - CREDS_ROTATED=true - ok "Rotated the default admin password" - fi -fi -if [ "$CREDS_ROTATED" != "true" ]; then - warn "Could not auto-rotate admin credentials (already changed on a prior run?). Log in with your existing credentials, or admin/admin on a genuinely fresh install." -fi - -# ── 9. Summary ───────────────────────────────────────────────────────────────── +# ── 8. Summary ───────────────────────────────────────────────────────────────── +# Credentials are no longer auto-rotated here — a fresh install always lands +# on admin/admin, and ARGUS itself forces a mandatory First-Run Setup Wizard +# on that first login (credential change, regional settings, guided feature +# configuration, installation validation) before the dashboard is reachable. +# Pre-rotating here just made that flow inconsistent across install paths and +# risked silently leaving defaults active if the rotation call failed. UI_PORT="$(grep -oP '^UI_PORT=\K.*' .env 2>/dev/null || true)" UI_PORT="${UI_PORT:-81}" @@ -130,13 +111,8 @@ echo bold "ARGUS is installed and running." echo info "Admin Panel: https://localhost:${UI_PORT} (accept the self-signed certificate)" -if [ "$CREDS_ROTATED" = "true" ]; then - info "Username: ${ADMIN_USER}" - info "Password: ${ADMIN_PASSWORD}" - warn "Save this password now — it is not stored anywhere and cannot be recovered." -else - info "Log in with your existing admin credentials." -fi +info "Default Login: admin / admin" +warn "You will be required to set a real username/password and complete the First-Run Setup Wizard on first login." echo info "Configuration: ${INSTALL_DIR}/.env and ${INSTALL_DIR}/docker-compose.yml" info "Upgrade: cd ${INSTALL_DIR} && docker compose pull && docker compose up -d"