diff --git a/README.md b/README.md
index 1f2a9ab..d454d73 100644
--- a/README.md
+++ b/README.md
@@ -1,11 +1,11 @@
-# ARGUS
+# ARGUS Enterprise Web Security Platform
-### Enterprise Web Security Platform
+### A real-time security operations platform for the modern web edge
-[](LICENSE)
-[](https://github.com/alleyviper/argus/pkgs/container/argus-secure-api)
+[](LICENSE)
+[]()
[](https://nginx.org/)
[](https://modsecurity.org/)
@@ -13,16 +13,18 @@
[]()
- A real-time security operations platform for the modern web edge.
- Reverse proxy, Web Application Firewall, bot defense, DNS protection, and live threat
- investigation — in one appliance.
+ ARGUS combines a reverse proxy, Web Application Firewall, bot and AI-crawler defense,
+ DNS security engine, threat intelligence integration, GeoIP and cloud-provider access control,
+ automated SSL, rate limiting and auto-ban, real-time attack visualization, incident
+ investigation, load balancing, TCP/UDP stream proxying, enterprise user management, and a full
+ REST API — one complete web security appliance for protecting modern applications.
✨ Features •
🚀 Installation •
🛠 Operations •
- 📚 API
+ 📄 Licensing & Support
---
@@ -31,17 +33,15 @@
> **This is the public ARGUS installer repository.** It contains no proprietary source
> code — only installation scripts, configuration templates, and public documentation.
-> Application source lives in private repos under the Weboria organization on Gitea:
-> [`argus-appliance`](https://git-cloud.weboria.eu/weboria/argus-appliance) and
-> [`anis-intelligence-server`](https://git-cloud.weboria.eu/weboria/anis-intelligence-server).
-> Build/release automation lives in
-> [`argus-build`](https://git-cloud.weboria.eu/weboria/argus-build). Never commit
-> application source, internal docs, or credentials into this repo.
+> Application source is developed privately by Weboria and distributed exclusively as
+> published container images. You do not need, and will not be given, access to the source
+> to install, run, or operate ARGUS.
>
-> **Known gap, not yet built:** `install.sh` today pulls public GHCR images with no
-> license validation — it does not yet implement the "validate license → authenticate
-> against a private registry → pull official images" flow. That needs a licensing
-> service and private-registry auth design before `install.sh` can be updated to match.
+> **Known gap, not yet built:** production images are currently distributed from GitHub
+> Container Registry while Weboria's own private registry (`registry.weboria.eu`) is
+> provisioned. License-key validation during install is not yet implemented — that needs a
+> licensing service design before `install.sh` can enforce it. Both are tracked, not silently
+> assumed to already work.
## ✨ Key Features
@@ -77,7 +77,8 @@ Let's Encrypt with automatic renewal, including wildcard certificates via DNS-01
### ⚡ Rate Limiting & Auto-Ban
Configurable per-IP/per-URI rate limits, automatic banning on repeated WAF violations, and
-optional community threat-intelligence-driven blocking.
+optional community threat-intelligence-driven blocking via ANIS (enabled by default, no
+license key required for the free Community tier).
### 👥 Full User Management
Role-based access, per-user session control, forced password resets, account lock/unlock, MFA,
@@ -99,18 +100,20 @@ HTTP/3 (QUIC) and post-quantum-ready TLS (ML-KEM hybrid key exchange).
### Requirements
-- A Linux host with Docker 24.0+ and the Docker Compose plugin (`docker compose`)
+- A Linux host with Docker Engine 24.0+ and the Docker Compose plugin (`docker compose`)
+- 2 vCPU / 4 GB RAM minimum for evaluation; see production sizing guidance in `docs/` for
+ real traffic volumes
- Ports 80/443 available for the reverse proxy, and 81 for the admin panel (all configurable)
### One-line install
```bash
-curl -fsSL https://raw.githubusercontent.com/alleyviper/argus/main/install.sh | bash
+curl -fsSL https://git-cloud.weboria.eu/weboria/argus-installer/raw/branch/main/install.sh | bash
```
-This downloads the deployment files, generates a secure database password, creates the
+This downloads the deployment files, generates secure database/application secrets, creates the
required Docker network, pulls the production images, starts ARGUS, and prints your admin
-login at the end. Installs to `~/argus` by default — set `ARGUS_INSTALL_DIR` first to change
+login at the end. Installs to `/opt/argus` by default — set `ARGUS_INSTALL_DIR` first to change
that.
### Manual install
@@ -118,10 +121,10 @@ that.
If you'd rather see every step:
```bash
-mkdir -p ~/argus/docker-socket-proxy && cd ~/argus
-curl -fsSL https://raw.githubusercontent.com/alleyviper/argus/main/docker-compose.yml -o docker-compose.yml
-curl -fsSL https://raw.githubusercontent.com/alleyviper/argus/main/.env.example -o .env
-curl -fsSL https://raw.githubusercontent.com/alleyviper/argus/main/docker-socket-proxy/haproxy.cfg.template -o docker-socket-proxy/haproxy.cfg.template
+mkdir -p /opt/argus/docker-socket-proxy && cd /opt/argus
+curl -fsSL https://git-cloud.weboria.eu/weboria/argus-installer/raw/branch/main/docker-compose.yml -o docker-compose.yml
+curl -fsSL https://git-cloud.weboria.eu/weboria/argus-installer/raw/branch/main/.env.example -o .env
+curl -fsSL https://git-cloud.weboria.eu/weboria/argus-installer/raw/branch/main/docker-socket-proxy/haproxy.cfg.template -o docker-socket-proxy/haproxy.cfg.template
# Generate a secure database password
sed -i "s/DB_PASSWORD=.*/DB_PASSWORD=$(openssl rand -base64 24)/" .env
@@ -133,19 +136,30 @@ docker compose pull
docker compose up -d
```
-Then log in at `https://localhost:81` with `admin` / `admin` and change the password
+Then log in at `https://
:81` with `admin` / `admin` and change the password
immediately — the one-line installer does this rotation for you automatically.
**Do not expose the admin panel (port 81) to the internet.** Keep it on your LAN/VPN, or put
it behind its own proxy host with access lists and 2FA enabled.
+### Next steps after install
+
+1. Open the administration panel at the access URL printed at the end of install.
+2. Complete the first-run setup wizard — regional settings and a guided review of every
+ protection module.
+3. Confirm your administrator password was rotated (the installer does this automatically).
+4. Configure domains and reverse proxy hosts under **Proxy Hosts**.
+5. Review the ANIS threat intelligence connection under **Threat Intel** — on by default
+ against the public Community Edition hub.
+6. Review security policies in the **Security Policy Center**.
+
---
## 🛠 Operations
-Five scripts cover day-to-day operation — download them once alongside `docker-compose.yml`
-(the one-line installer already does this for you), then run from `~/argus` (or wherever you
-installed):
+All lifecycle management is Docker-based — five scripts cover day-to-day operation, downloaded
+once alongside `docker-compose.yml` (the one-line installer already does this for you), then run
+from `/opt/argus` (or wherever you installed):
| Script | Purpose |
|--------|---------|
@@ -155,21 +169,24 @@ installed):
| `./restore.sh ` | Restore a backup onto a fresh installation |
| `./uninstall.sh [--remove-data]` | Stop ARGUS; data is kept unless you explicitly opt in to removing it |
+You never manually download application files or modify containers directly — every update is
+delivered as a new published image version.
+
### Upgrading
```bash
-cd ~/argus
-./update.sh
+cd /opt/argus
+docker compose pull
+docker compose up -d
```
-New versions are published to GHCR as soon as they're released — `update.sh` always pulls the
-current stable release. This is the only supported upgrade path; there is no separate migration
-step to run.
+(`./update.sh` wraps the same two commands with a before/after version check.) This is the only
+supported upgrade path; there is no separate migration step to run.
### Backups
```bash
-cd ~/argus
+cd /opt/argus
./backup.sh # writes argus-backup-.tar.gz to the current directory
./restore.sh # onto a fresh installation only — see the script's own header
```
@@ -184,12 +201,13 @@ Add `--username ` to target a specific account, or `--password '...'` to s
value instead of generating one. See `docker compose exec api ./server reset-password --help`
for the rest of the options (clearing 2FA, etc.).
-### Threat intelligence integration (optional)
+### Threat intelligence integration
-ARGUS can connect to **ANIS**, a separately-deployed threat-intelligence hub, to share confirmed
-attacker IPs and receive a community blocklist in return. It's off by default — set
-`ANIS_ENABLED=true` and `ANIS_URL` in `.env` to turn it on. See the comments in `.env.example`
-for the full set of options.
+ARGUS connects to **ANIS**, Weboria's threat-intelligence hub, to share confirmed attacker IPs
+and receive a community blocklist in return. Enabled by default against the public Community
+Edition hub — no license key required. Point `ANIS_URL` at your own self-hosted ANIS instead if
+you run one, or set `ANIS_ENABLED=false` to turn this off entirely. See the comments in
+`.env.example` for the full set of options.
---
@@ -198,7 +216,7 @@ for the full set of options.
ARGUS exposes a full REST API for automation. Authenticate with a JWT (`POST
/api/v1/auth/login`) for interactive use, or an API token (`Authorization: Bearer ng_`,
created from the admin panel) for CI/CD and scripted access. Interactive API documentation is
-served at `https://localhost:81/api/docs` once ARGUS is running.
+served at `https://:81/api/docs` once ARGUS is running.
---
@@ -212,24 +230,22 @@ served at `https://localhost:81/api/docs` once ARGUS is running.
| `NGINX_HTTP_PORT` / `NGINX_HTTPS_PORT` | Reverse-proxy listen ports | `80` / `443` |
| `API_HOST_PORT` | Internal API port exposed to the host | `9080` |
| `DNS_LISTEN_HOST` | DNS Security Engine bind address | `127.0.0.1` |
-| `ANIS_ENABLED` / `ANIS_URL` | Optional threat-intel hub integration | `false` / *(empty)* |
+| `ANIS_ENABLED` / `ANIS_URL` | Threat-intel hub integration | `true` / `https://anis.weboria.eu` |
Full list with descriptions in `.env.example`.
---
-## 📄 License
+## 📄 Licensing & Support
-This is proprietary, commercial software — see [LICENSE](LICENSE). Third-party open-source
-components retain their own licenses — see [THIRD_PARTY_LICENSES](THIRD_PARTY_LICENSES) and
-[NOTICE](NOTICE).
+ARGUS is commercial software licensed by Weboria — see [LICENSE](LICENSE). Third-party
+open-source components retain their own licenses — see
+[THIRD_PARTY_LICENSES](THIRD_PARTY_LICENSES) and [NOTICE](NOTICE).
-## 💬 Support
-
-[GitHub Issues](https://github.com/alleyviper/argus/issues) — bug reports and feature requests.
+For licensing questions or support, contact the **Weboria Support Portal**.
---
- © 2025-2026 ARGUS — AI4SEC.
+ © 2025-2026 Weboria. ARGUS Enterprise Web Security Platform.
diff --git a/install.sh b/install.sh
index 5235a8e..aeee2bb 100755
--- a/install.sh
+++ b/install.sh
@@ -1,15 +1,22 @@
#!/usr/bin/env bash
#
-# ARGUS installer — fetches the production compose stack, generates secrets,
-# starts the platform, and prints your admin credentials.
+# ARGUS Enterprise Web Security Platform — installer. Fetches the production
+# compose stack, generates secrets, starts the platform, and prints your
+# admin credentials.
#
-# curl -fsSL https://raw.githubusercontent.com/alleyviper/argus/main/install.sh | bash
+# curl -fsSL https://git-cloud.weboria.eu/weboria/argus-installer/raw/branch/main/install.sh | bash
#
set -euo pipefail
-REPO_RAW_BASE="https://raw.githubusercontent.com/alleyviper/argus/main"
-INSTALL_DIR="${ARGUS_INSTALL_DIR:-$HOME/argus}"
+REPO_RAW_BASE="https://git-cloud.weboria.eu/weboria/argus-installer/raw/branch/main"
+INSTALL_DIR="${ARGUS_INSTALL_DIR:-/opt/argus}"
NETWORK_NAME="argus-network"
+# The image registry is still ghcr.io (GitHub Container Registry) today —
+# Weboria's own private registry (registry.weboria.eu) is provisioned but
+# not yet serving images. docker-compose.yml's image: lines point at ghcr.io
+# directly rather than a variable here, since that's the only registry that
+# actually has published images right now; switching to registry.weboria.eu
+# is a one-line change to those image: lines once it's live, not a rewrite.
# ── Output helpers ────────────────────────────────────────────────────────────
bold() { printf '\033[1m%s\033[0m\n' "$1"; }
@@ -127,9 +134,9 @@ UI_PORT="$(grep -oP '^UI_PORT=\K.*' .env 2>/dev/null || true)"
UI_PORT="${UI_PORT:-81}"
echo
-bold "ARGUS is installed and running."
+bold "ARGUS Enterprise Web Security Platform has been successfully installed."
echo
-info "Admin Panel: https://localhost:${UI_PORT} (accept the self-signed certificate)"
+info "Access URL: https://$(hostname -I 2>/dev/null | awk '{print $1}' || echo localhost):${UI_PORT} (accept the self-signed certificate)"
if [ "$CREDS_ROTATED" = "true" ]; then
info "Username: ${ADMIN_USER}"
info "Password: ${ADMIN_PASSWORD}"
@@ -138,7 +145,22 @@ else
info "Log in with your existing admin credentials."
fi
echo
+bold "Next steps:"
+info "1. Open the administration panel at the Access URL above."
+if [ "$CREDS_ROTATED" != "true" ]; then
+ info "2. Complete the first-run setup wizard (regional settings, guided protection checklist)."
+ info "3. Change the initial administrator password if you haven't already."
+else
+ info "2. Complete the first-run setup wizard — regional settings and a guided review of every"
+ info " protection module (your admin password was already rotated above)."
+fi
+info "4. Configure domains and reverse proxy hosts under Proxy Hosts."
+info "5. Review the ANIS threat intelligence connection under Threat Intel — enabled by"
+info " default against the public Community Edition hub, no license key required."
+info "6. Review security policies in the Security Policy Center."
+echo
info "Configuration: ${INSTALL_DIR}/.env and ${INSTALL_DIR}/docker-compose.yml"
info "Upgrade: cd ${INSTALL_DIR} && docker compose pull && docker compose up -d"
-info "Backups: see https://github.com/alleyviper/argus#backups"
+info "Backup: cd ${INSTALL_DIR} && ./backup.sh"
+info "Docs/support: see README.md in this directory"
echo
diff --git a/update.sh b/update.sh
index 4d13035..043d094 100755
--- a/update.sh
+++ b/update.sh
@@ -1,14 +1,15 @@
#!/usr/bin/env bash
#
-# ARGUS updater — pulls the latest published images and restarts the stack.
+# ARGUS Enterprise Web Security Platform — updater. Pulls the latest
+# published images and restarts the stack.
#
-# cd ~/argus && ./update.sh
+# cd /opt/argus && ./update.sh
# (or, if you don't have it locally yet)
-# curl -fsSL https://raw.githubusercontent.com/alleyviper/argus/main/update.sh | bash
+# curl -fsSL https://git-cloud.weboria.eu/weboria/argus-installer/raw/branch/main/update.sh | bash
#
set -euo pipefail
-INSTALL_DIR="${ARGUS_INSTALL_DIR:-$HOME/argus}"
+INSTALL_DIR="${ARGUS_INSTALL_DIR:-/opt/argus}"
bold() { printf '\033[1m%s\033[0m\n' "$1"; }
info() { printf ' %s\n' "$1"; }