fix(installer): align installer/onboarding with current codebase (Phase 1 audit)
A full audit of the installer and first-run experience found the mandatory
first-run wizard (is_initial_setup gate + InitialSetup.tsx) already works
correctly end-to-end — the real gap was discoverability and drift between
the installer and current app, not the wizard itself:
- nginx's static welcome page (served on the default HTTP/HTTPS ports, the
first place any new admin looks) never mentioned the admin panel lives on
a separate port, still shipped a Korean-language switcher despite Korean
being fully removed from the product, and linked to the retired
"Argus-appliance" identity. Now surfaces a live, dynamically-derived
admin panel link and drops the dead i18n/branding.
- users.language defaulted to 'ko' at the schema level (both the column
DEFAULT and the seed admin row) — a leftover from before Korean removal,
silently affecting every new user, not just the seed account.
- Three independently-drifting install paths existed (public distribution
installer, private-repo SSH-ship installer, and a fully manual README/docs
flow). README/docs now lead with the public alleyviper/argus installer
(verified to actually exist and mirror distribution/); the manual path is
kept only as an explicit private/pre-release fallback.
- Both scripted installers auto-rotated admin/admin via the API as their
last step, silently warning (not failing) if it didn't work — inconsistent
with the manual path and capable of leaving defaults active undetected.
Removed; every install path now consistently lands on admin/admin + the
in-app wizard.
- ANIS_ADMIN_KEY was documented as required ("ARGUS fails closed without
it") but is never read anywhere in src/api — confirmed dead, not just
vestigial. Retired from env templates, compose files, and docs; ROADMAP's
existing "wire it up or retire it" item resolved for this variable.
- Proxy host creation returned an opaque 500 when given an unresolvable
forward_host (e.g. a Docker container name typed into the free-text
field — ARGUS's nginx runs in host-network mode with no embedded DNS).
nginx -t's real "host not found in upstream" failure now surfaces as an
actionable 400 instead of a generic internal error; placeholder text
fixed to stop inviting the failure. Live-verified both the failure path
(with NGINX_SKIP_TEST temporarily disabled in the sandbox to exercise the
real validation) and the no-regression path (valid IP still succeeds).
- LOG_COLLECTION silently disables the entire access-log/analytics/live-event
pipeline when set to anything but the exact string "true", with zero log
output anywhere. Added a boot-time WARN matching the existing
IsInitialSetupRequired nudge pattern.
Every fix live-verified against a genuinely fresh sandbox install
(docker/docker-compose.local-sandbox.yml, zero pre-existing volumes),
not just read from source.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
committed by
root
co-authored by
Claude Sonnet 5
parent
44f662afc0
commit
913615903b
+1
-1
@@ -123,7 +123,6 @@ services:
|
||||
ANIS_ENABLED: ${ANIS_ENABLED:-false}
|
||||
ANIS_URL: ${ANIS_URL:-}
|
||||
ANIS_LICENSE_KEY: ${ANIS_LICENSE_KEY:-}
|
||||
ANIS_ADMIN_KEY: ${ANIS_ADMIN_KEY:-}
|
||||
ANIS_SHARE_ATTACKERS: ${ANIS_SHARE_ATTACKERS:-false}
|
||||
DNS_SECURITY_LISTEN_ADDR: ":53"
|
||||
ports:
|
||||
@@ -196,6 +195,7 @@ services:
|
||||
max-file: "5"
|
||||
environment:
|
||||
TZ: ${TZ:-UTC}
|
||||
UI_PORT: ${UI_PORT:-81}
|
||||
ulimits:
|
||||
nofile:
|
||||
soft: 65535
|
||||
|
||||
Reference in New Issue
Block a user