feat: switch to Weboria's own registry, clean licensing docs, expand product copy
Registry: docker-compose.yml now pulls argus-api/argus-ui/argus-proxy from git-cloud.weboria.eu/weboria (Gitea's built-in container registry) instead of ghcr.io. Built and pushed real production images from main (v3.73.0) before switching — verified anonymous `docker pull` works for all three with zero login required, matching the public installer's no-friction promise. install.sh's registry comment updated to match; no more "gap." Licensing: reworked per a full commercial-distribution review. Removed MaxMind/GeoLite2 entirely (confirmed geoip2-golang isn't even in go.mod — GeoIP is RIR-based, not MaxMind-based, and has been for a while). Clarified TimescaleDB's licensing story (embedded component distributed as part of the appliance, not a hosted DB service) rather than leaving it under a vague "reviewed before bundling" note. Added missing real dependencies grounded against the actual Dockerfiles (Alpine Linux, PostgreSQL, Go runtime, Node.js build-time-only, OpenSSL, curl, BusyBox). Renamed THIRD_PARTY_LICENSES -> THIRD_PARTY_LICENSES.md, added a "Weboria Proprietary Components" section. Removed the "pending legal review" section that was specifically about MaxMind/TimescaleDB, now resolved by the above -- LICENSE's own placeholder-pending-final-terms disclaimer stays, since drafting real commercial license text is separate legal work, not something to paper over. README: removed the internal "this repo contains no proprietary code" meta-description (customers don't need to see project scaffolding notes) and the "known gap" callout (both gaps closed above). Expanded the feature list with a dedicated ANIS Threat Intelligence section and richer detail on DNS Security, Bot/AI-crawler defense, and the Guided Security Policy Center. Stronger positioning copy up top.
This commit is contained in:
@@ -13,11 +13,11 @@
|
||||
[]()
|
||||
|
||||
<p align="center">
|
||||
<strong>ARGUS combines a reverse proxy, Web Application Firewall, bot and AI-crawler defense,
|
||||
DNS security engine, threat intelligence integration, GeoIP and cloud-provider access control,
|
||||
automated SSL, rate limiting and auto-ban, real-time attack visualization, incident
|
||||
investigation, load balancing, TCP/UDP stream proxying, enterprise user management, and a full
|
||||
REST API — one complete web security appliance for protecting modern applications.</strong>
|
||||
<strong>Enterprise-grade protection for the modern web edge — in the same league as Fortinet,
|
||||
Palo Alto, and F5, purpose-built for how applications are actually attacked today.</strong><br/>
|
||||
<strong>Reverse proxy. Web Application Firewall. Bot and AI-crawler defense. DNS security.
|
||||
Real-time threat intelligence. Live attack visualization. Incident investigation. One
|
||||
appliance, one dashboard, zero blind spots.</strong>
|
||||
</p>
|
||||
|
||||
<p align="center">
|
||||
@@ -31,68 +31,91 @@
|
||||
|
||||
</div>
|
||||
|
||||
> **This is the public ARGUS installer repository.** It contains no proprietary source
|
||||
> code — only installation scripts, configuration templates, and public documentation.
|
||||
> Application source is developed privately by Weboria and distributed exclusively as
|
||||
> published container images. You do not need, and will not be given, access to the source
|
||||
> to install, run, or operate ARGUS.
|
||||
>
|
||||
> **Known gap, not yet built:** production images are currently distributed from GitHub
|
||||
> Container Registry while Weboria's own private registry (`registry.weboria.eu`) is
|
||||
> provisioned. License-key validation during install is not yet implemented — that needs a
|
||||
> licensing service design before `install.sh` can enforce it. Both are tracked, not silently
|
||||
> assumed to already work.
|
||||
|
||||
## ✨ Key Features
|
||||
|
||||
### 🛡️ Web Application Firewall
|
||||
ModSecurity v3 with the OWASP Core Rule Set. Paranoia levels 1–4, per-host rule exceptions,
|
||||
detection-only or blocking modes.
|
||||
ModSecurity v3 running the full OWASP Core Rule Set, tunable across paranoia levels 1–4 per
|
||||
site — start permissive on a new application, tighten as you learn its traffic. Detection-only
|
||||
or blocking mode per host, per-rule exceptions for known false positives, and a Rule Health
|
||||
view that tracks which rules are actually earning their keep versus generating noise, so tuning
|
||||
is based on evidence, not guesswork.
|
||||
|
||||
### 🧠 ANIS Threat Intelligence
|
||||
ARGUS ships connected by default to **ANIS (Argus Network Intelligence Server)**, a
|
||||
community-powered reputation network: every ARGUS deployment that opts in contributes
|
||||
confirmed-attacker IPs and receives the aggregated blocklist back in return, so your appliance
|
||||
gets smarter from day one using signal from every other protected site — no license key
|
||||
required for the free Community tier. Every dashboard, investigation view, and auto-ban
|
||||
decision is enriched with live ANIS reputation scoring. Prefer to keep intelligence in-house?
|
||||
Point ARGUS at your own self-hosted ANIS instance instead, or turn the integration off entirely.
|
||||
|
||||
### 🌐 Attack Origin Visualization
|
||||
A live global map of inbound attacks — real-time arcs from source to your infrastructure,
|
||||
severity-coded, with instant drill-down into any event's full detail.
|
||||
color-coded by severity, with a running feed of top attacking countries and IPs. Pause, rewind,
|
||||
and replay historical traffic, or click straight through to any single event's full detail.
|
||||
|
||||
### 🔎 Incident Investigation
|
||||
Pivot from any IP, log line, or dashboard event straight into that entity's complete history —
|
||||
affected hosts, triggered rules, geography, and live threat-intelligence reputation — without
|
||||
losing your place.
|
||||
every affected host it touched, every rule it triggered, its geography and ASN, and its live
|
||||
ANIS reputation score — all in one place, without losing your position in whatever you were
|
||||
looking at.
|
||||
|
||||
### 🤖 Bot & AI-Crawler Defense
|
||||
Blocks known-bad bots and AI scrapers automatically, with a search-engine allowlist so legitimate
|
||||
crawlers are never affected. Escalating challenge modes (browser check, proof-of-work, visual
|
||||
CAPTCHA) for suspicious traffic.
|
||||
Automatically blocks known-bad bots and scrapers, with a maintained allowlist so legitimate
|
||||
search engines are never caught in the net. Purpose-built detection for AI crawlers (GPTBot,
|
||||
ClaudeBot, and similar) lets you choose exactly which ones are welcome. Escalating challenge
|
||||
modes — silent browser verification, proof-of-work, visual CAPTCHA — apply exactly as much
|
||||
friction as suspicious traffic actually warrants, backed by a live risk-scoring engine so the
|
||||
decision is never a coin flip.
|
||||
|
||||
### 🧬 DNS Security Engine
|
||||
An embedded forwarding DNS resolver with real-time threat detection — DGA domains, DNS
|
||||
tunneling, fast-flux infrastructure, cache-poisoning attempts — and automatic mitigation via
|
||||
sinkholing.
|
||||
Passive DNS intelligence starts working the moment your first site is protected — no network
|
||||
reconfiguration required — scoring every domain your traffic touches for DGA patterns,
|
||||
fast-flux infrastructure, and other red flags, and cross-referencing that against real WAF
|
||||
activity for a much stronger signal than either check alone. An optional embedded resolver adds
|
||||
network-wide DNS tunneling detection, NXDOMAIN-flood protection, and automatic sinkholing for
|
||||
sites that want DNS-layer coverage too.
|
||||
|
||||
### 🌍 GeoIP & Cloud-Provider Access Control
|
||||
Allow or block traffic by country or hosting provider, with live visual feedback.
|
||||
Allow or block traffic by country or hosting provider, with live visual feedback as you tune
|
||||
the policy — see exactly what would have been blocked before you commit to it.
|
||||
|
||||
### 🔒 Automated SSL
|
||||
Let's Encrypt with automatic renewal, including wildcard certificates via DNS-01 challenge
|
||||
(Cloudflare, DuckDNS, Dynu, and more).
|
||||
across major DNS providers (Cloudflare, DuckDNS, Dynu, and more) — certificates that never
|
||||
expire on your watch.
|
||||
|
||||
### ⚡ Rate Limiting & Auto-Ban
|
||||
Configurable per-IP/per-URI rate limits, automatic banning on repeated WAF violations, and
|
||||
optional community threat-intelligence-driven blocking via ANIS (enabled by default, no
|
||||
license key required for the free Community tier).
|
||||
community-intelligence-driven blocking via ANIS — layered defenses that reinforce each other
|
||||
rather than working in isolation.
|
||||
|
||||
### 👥 Full User Management
|
||||
Role-based access, per-user session control, forced password resets, account lock/unlock, MFA,
|
||||
and a complete login history — everything a security team needs to administer access safely.
|
||||
### 👥 Enterprise User Management
|
||||
Role-based access control, per-user session management, forced password resets, account
|
||||
lock/unlock as a reversible incident-response tool, mandatory MFA for administrators, and a
|
||||
complete audit trail of every login and admin action — everything a security team needs to
|
||||
administer access with confidence.
|
||||
|
||||
### 📊 Real-Time Operations Dashboard
|
||||
Live traffic, security events, and system health, updated continuously — no manual refresh.
|
||||
Live traffic, security events, and system health updated continuously — a true operations
|
||||
console, not a page you have to remember to refresh. Guided, role-based dashboard profiles (SOC
|
||||
Analyst, Security Administrator, Network Administrator, Executive Overview) put the right view
|
||||
in front of the right person automatically.
|
||||
|
||||
### 🎯 Guided Security Policy Center
|
||||
Every protection module — WAF, DNS, GeoIP, Bot Protection, Rate Limiting, SSL/TLS, and more —
|
||||
comes with one-click policy tiers from Home to Maximum Protection, a plain-language impact
|
||||
preview before you apply anything, and an honest posture score that tells you exactly what's
|
||||
configured, what's missing, and why it matters. No security expertise required to deploy with
|
||||
confidence.
|
||||
|
||||
### 🔀 Load Balancing & Stream Proxying
|
||||
Multiple backend servers with health checks, plus TCP/UDP stream proxying with optional SNI
|
||||
routing.
|
||||
Multiple backend servers with active health checks, plus TCP/UDP stream proxying with optional
|
||||
SNI routing for non-HTTP services.
|
||||
|
||||
### 🔮 Modern Protocol Support
|
||||
HTTP/3 (QUIC) and post-quantum-ready TLS (ML-KEM hybrid key exchange).
|
||||
HTTP/3 (QUIC) and post-quantum-ready TLS (ML-KEM hybrid key exchange) — ready for where the web
|
||||
is headed, not just where it's been.
|
||||
|
||||
---
|
||||
|
||||
@@ -240,7 +263,7 @@ Full list with descriptions in `.env.example`.
|
||||
|
||||
ARGUS is commercial software licensed by Weboria — see [LICENSE](LICENSE). Third-party
|
||||
open-source components retain their own licenses — see
|
||||
[THIRD_PARTY_LICENSES](THIRD_PARTY_LICENSES) and [NOTICE](NOTICE).
|
||||
[THIRD_PARTY_LICENSES.md](THIRD_PARTY_LICENSES.md) and [NOTICE](NOTICE).
|
||||
|
||||
For licensing questions or support, contact the **Weboria Support Portal**.
|
||||
|
||||
|
||||
Reference in New Issue
Block a user