diff --git a/README.md b/README.md index 1f2a9ab..d454d73 100644 --- a/README.md +++ b/README.md @@ -1,11 +1,11 @@
-# ARGUS +# ARGUS Enterprise Web Security Platform -### Enterprise Web Security Platform +### A real-time security operations platform for the modern web edge -[![License](https://img.shields.io/badge/License-Proprietary-lightgrey?style=for-the-badge)](LICENSE) -[![Docker](https://img.shields.io/badge/Docker-ready-2496ED?style=for-the-badge&logo=docker&logoColor=white)](https://github.com/alleyviper/argus/pkgs/container/argus-secure-api) +[![License](https://img.shields.io/badge/License-Commercial-lightgrey?style=for-the-badge)](LICENSE) +[![Platform](https://img.shields.io/badge/Platform-Docker-2496ED?style=for-the-badge&logo=docker&logoColor=white)]() [![Nginx](https://img.shields.io/badge/Nginx-1.30-009639?style=for-the-badge&logo=nginx&logoColor=white)](https://nginx.org/) [![ModSecurity](https://img.shields.io/badge/ModSecurity-v3-red?style=for-the-badge)](https://modsecurity.org/) @@ -13,16 +13,18 @@ [![HTTP/3](https://img.shields.io/badge/HTTP/3-QUIC-blue?style=for-the-badge)]()

- A real-time security operations platform for the modern web edge.
- Reverse proxy, Web Application Firewall, bot defense, DNS protection, and live threat - investigation — in one appliance.
+ ARGUS combines a reverse proxy, Web Application Firewall, bot and AI-crawler defense, + DNS security engine, threat intelligence integration, GeoIP and cloud-provider access control, + automated SSL, rate limiting and auto-ban, real-time attack visualization, incident + investigation, load balancing, TCP/UDP stream proxying, enterprise user management, and a full + REST API — one complete web security appliance for protecting modern applications.

✨ Features🚀 Installation🛠 Operations • - 📚 API + 📄 Licensing & Support

--- @@ -31,17 +33,15 @@ > **This is the public ARGUS installer repository.** It contains no proprietary source > code — only installation scripts, configuration templates, and public documentation. -> Application source lives in private repos under the Weboria organization on Gitea: -> [`argus-appliance`](https://git-cloud.weboria.eu/weboria/argus-appliance) and -> [`anis-intelligence-server`](https://git-cloud.weboria.eu/weboria/anis-intelligence-server). -> Build/release automation lives in -> [`argus-build`](https://git-cloud.weboria.eu/weboria/argus-build). Never commit -> application source, internal docs, or credentials into this repo. +> Application source is developed privately by Weboria and distributed exclusively as +> published container images. You do not need, and will not be given, access to the source +> to install, run, or operate ARGUS. > -> **Known gap, not yet built:** `install.sh` today pulls public GHCR images with no -> license validation — it does not yet implement the "validate license → authenticate -> against a private registry → pull official images" flow. That needs a licensing -> service and private-registry auth design before `install.sh` can be updated to match. +> **Known gap, not yet built:** production images are currently distributed from GitHub +> Container Registry while Weboria's own private registry (`registry.weboria.eu`) is +> provisioned. License-key validation during install is not yet implemented — that needs a +> licensing service design before `install.sh` can enforce it. Both are tracked, not silently +> assumed to already work. ## ✨ Key Features @@ -77,7 +77,8 @@ Let's Encrypt with automatic renewal, including wildcard certificates via DNS-01 ### ⚡ Rate Limiting & Auto-Ban Configurable per-IP/per-URI rate limits, automatic banning on repeated WAF violations, and -optional community threat-intelligence-driven blocking. +optional community threat-intelligence-driven blocking via ANIS (enabled by default, no +license key required for the free Community tier). ### 👥 Full User Management Role-based access, per-user session control, forced password resets, account lock/unlock, MFA, @@ -99,18 +100,20 @@ HTTP/3 (QUIC) and post-quantum-ready TLS (ML-KEM hybrid key exchange). ### Requirements -- A Linux host with Docker 24.0+ and the Docker Compose plugin (`docker compose`) +- A Linux host with Docker Engine 24.0+ and the Docker Compose plugin (`docker compose`) +- 2 vCPU / 4 GB RAM minimum for evaluation; see production sizing guidance in `docs/` for + real traffic volumes - Ports 80/443 available for the reverse proxy, and 81 for the admin panel (all configurable) ### One-line install ```bash -curl -fsSL https://raw.githubusercontent.com/alleyviper/argus/main/install.sh | bash +curl -fsSL https://git-cloud.weboria.eu/weboria/argus-installer/raw/branch/main/install.sh | bash ``` -This downloads the deployment files, generates a secure database password, creates the +This downloads the deployment files, generates secure database/application secrets, creates the required Docker network, pulls the production images, starts ARGUS, and prints your admin -login at the end. Installs to `~/argus` by default — set `ARGUS_INSTALL_DIR` first to change +login at the end. Installs to `/opt/argus` by default — set `ARGUS_INSTALL_DIR` first to change that. ### Manual install @@ -118,10 +121,10 @@ that. If you'd rather see every step: ```bash -mkdir -p ~/argus/docker-socket-proxy && cd ~/argus -curl -fsSL https://raw.githubusercontent.com/alleyviper/argus/main/docker-compose.yml -o docker-compose.yml -curl -fsSL https://raw.githubusercontent.com/alleyviper/argus/main/.env.example -o .env -curl -fsSL https://raw.githubusercontent.com/alleyviper/argus/main/docker-socket-proxy/haproxy.cfg.template -o docker-socket-proxy/haproxy.cfg.template +mkdir -p /opt/argus/docker-socket-proxy && cd /opt/argus +curl -fsSL https://git-cloud.weboria.eu/weboria/argus-installer/raw/branch/main/docker-compose.yml -o docker-compose.yml +curl -fsSL https://git-cloud.weboria.eu/weboria/argus-installer/raw/branch/main/.env.example -o .env +curl -fsSL https://git-cloud.weboria.eu/weboria/argus-installer/raw/branch/main/docker-socket-proxy/haproxy.cfg.template -o docker-socket-proxy/haproxy.cfg.template # Generate a secure database password sed -i "s/DB_PASSWORD=.*/DB_PASSWORD=$(openssl rand -base64 24)/" .env @@ -133,19 +136,30 @@ docker compose pull docker compose up -d ``` -Then log in at `https://localhost:81` with `admin` / `admin` and change the password +Then log in at `https://:81` with `admin` / `admin` and change the password immediately — the one-line installer does this rotation for you automatically. **Do not expose the admin panel (port 81) to the internet.** Keep it on your LAN/VPN, or put it behind its own proxy host with access lists and 2FA enabled. +### Next steps after install + +1. Open the administration panel at the access URL printed at the end of install. +2. Complete the first-run setup wizard — regional settings and a guided review of every + protection module. +3. Confirm your administrator password was rotated (the installer does this automatically). +4. Configure domains and reverse proxy hosts under **Proxy Hosts**. +5. Review the ANIS threat intelligence connection under **Threat Intel** — on by default + against the public Community Edition hub. +6. Review security policies in the **Security Policy Center**. + --- ## 🛠 Operations -Five scripts cover day-to-day operation — download them once alongside `docker-compose.yml` -(the one-line installer already does this for you), then run from `~/argus` (or wherever you -installed): +All lifecycle management is Docker-based — five scripts cover day-to-day operation, downloaded +once alongside `docker-compose.yml` (the one-line installer already does this for you), then run +from `/opt/argus` (or wherever you installed): | Script | Purpose | |--------|---------| @@ -155,21 +169,24 @@ installed): | `./restore.sh ` | Restore a backup onto a fresh installation | | `./uninstall.sh [--remove-data]` | Stop ARGUS; data is kept unless you explicitly opt in to removing it | +You never manually download application files or modify containers directly — every update is +delivered as a new published image version. + ### Upgrading ```bash -cd ~/argus -./update.sh +cd /opt/argus +docker compose pull +docker compose up -d ``` -New versions are published to GHCR as soon as they're released — `update.sh` always pulls the -current stable release. This is the only supported upgrade path; there is no separate migration -step to run. +(`./update.sh` wraps the same two commands with a before/after version check.) This is the only +supported upgrade path; there is no separate migration step to run. ### Backups ```bash -cd ~/argus +cd /opt/argus ./backup.sh # writes argus-backup-.tar.gz to the current directory ./restore.sh # onto a fresh installation only — see the script's own header ``` @@ -184,12 +201,13 @@ Add `--username ` to target a specific account, or `--password '...'` to s value instead of generating one. See `docker compose exec api ./server reset-password --help` for the rest of the options (clearing 2FA, etc.). -### Threat intelligence integration (optional) +### Threat intelligence integration -ARGUS can connect to **ANIS**, a separately-deployed threat-intelligence hub, to share confirmed -attacker IPs and receive a community blocklist in return. It's off by default — set -`ANIS_ENABLED=true` and `ANIS_URL` in `.env` to turn it on. See the comments in `.env.example` -for the full set of options. +ARGUS connects to **ANIS**, Weboria's threat-intelligence hub, to share confirmed attacker IPs +and receive a community blocklist in return. Enabled by default against the public Community +Edition hub — no license key required. Point `ANIS_URL` at your own self-hosted ANIS instead if +you run one, or set `ANIS_ENABLED=false` to turn this off entirely. See the comments in +`.env.example` for the full set of options. --- @@ -198,7 +216,7 @@ for the full set of options. ARGUS exposes a full REST API for automation. Authenticate with a JWT (`POST /api/v1/auth/login`) for interactive use, or an API token (`Authorization: Bearer ng_`, created from the admin panel) for CI/CD and scripted access. Interactive API documentation is -served at `https://localhost:81/api/docs` once ARGUS is running. +served at `https://:81/api/docs` once ARGUS is running. --- @@ -212,24 +230,22 @@ served at `https://localhost:81/api/docs` once ARGUS is running. | `NGINX_HTTP_PORT` / `NGINX_HTTPS_PORT` | Reverse-proxy listen ports | `80` / `443` | | `API_HOST_PORT` | Internal API port exposed to the host | `9080` | | `DNS_LISTEN_HOST` | DNS Security Engine bind address | `127.0.0.1` | -| `ANIS_ENABLED` / `ANIS_URL` | Optional threat-intel hub integration | `false` / *(empty)* | +| `ANIS_ENABLED` / `ANIS_URL` | Threat-intel hub integration | `true` / `https://anis.weboria.eu` | Full list with descriptions in `.env.example`. --- -## 📄 License +## 📄 Licensing & Support -This is proprietary, commercial software — see [LICENSE](LICENSE). Third-party open-source -components retain their own licenses — see [THIRD_PARTY_LICENSES](THIRD_PARTY_LICENSES) and -[NOTICE](NOTICE). +ARGUS is commercial software licensed by Weboria — see [LICENSE](LICENSE). Third-party +open-source components retain their own licenses — see +[THIRD_PARTY_LICENSES](THIRD_PARTY_LICENSES) and [NOTICE](NOTICE). -## 💬 Support - -[GitHub Issues](https://github.com/alleyviper/argus/issues) — bug reports and feature requests. +For licensing questions or support, contact the **Weboria Support Portal**. ---
- © 2025-2026 ARGUS — AI4SEC. + © 2025-2026 Weboria. ARGUS Enterprise Web Security Platform.
diff --git a/install.sh b/install.sh index 5235a8e..aeee2bb 100755 --- a/install.sh +++ b/install.sh @@ -1,15 +1,22 @@ #!/usr/bin/env bash # -# ARGUS installer — fetches the production compose stack, generates secrets, -# starts the platform, and prints your admin credentials. +# ARGUS Enterprise Web Security Platform — installer. Fetches the production +# compose stack, generates secrets, starts the platform, and prints your +# admin credentials. # -# curl -fsSL https://raw.githubusercontent.com/alleyviper/argus/main/install.sh | bash +# curl -fsSL https://git-cloud.weboria.eu/weboria/argus-installer/raw/branch/main/install.sh | bash # set -euo pipefail -REPO_RAW_BASE="https://raw.githubusercontent.com/alleyviper/argus/main" -INSTALL_DIR="${ARGUS_INSTALL_DIR:-$HOME/argus}" +REPO_RAW_BASE="https://git-cloud.weboria.eu/weboria/argus-installer/raw/branch/main" +INSTALL_DIR="${ARGUS_INSTALL_DIR:-/opt/argus}" NETWORK_NAME="argus-network" +# The image registry is still ghcr.io (GitHub Container Registry) today — +# Weboria's own private registry (registry.weboria.eu) is provisioned but +# not yet serving images. docker-compose.yml's image: lines point at ghcr.io +# directly rather than a variable here, since that's the only registry that +# actually has published images right now; switching to registry.weboria.eu +# is a one-line change to those image: lines once it's live, not a rewrite. # ── Output helpers ──────────────────────────────────────────────────────────── bold() { printf '\033[1m%s\033[0m\n' "$1"; } @@ -127,9 +134,9 @@ UI_PORT="$(grep -oP '^UI_PORT=\K.*' .env 2>/dev/null || true)" UI_PORT="${UI_PORT:-81}" echo -bold "ARGUS is installed and running." +bold "ARGUS Enterprise Web Security Platform has been successfully installed." echo -info "Admin Panel: https://localhost:${UI_PORT} (accept the self-signed certificate)" +info "Access URL: https://$(hostname -I 2>/dev/null | awk '{print $1}' || echo localhost):${UI_PORT} (accept the self-signed certificate)" if [ "$CREDS_ROTATED" = "true" ]; then info "Username: ${ADMIN_USER}" info "Password: ${ADMIN_PASSWORD}" @@ -138,7 +145,22 @@ else info "Log in with your existing admin credentials." fi echo +bold "Next steps:" +info "1. Open the administration panel at the Access URL above." +if [ "$CREDS_ROTATED" != "true" ]; then + info "2. Complete the first-run setup wizard (regional settings, guided protection checklist)." + info "3. Change the initial administrator password if you haven't already." +else + info "2. Complete the first-run setup wizard — regional settings and a guided review of every" + info " protection module (your admin password was already rotated above)." +fi +info "4. Configure domains and reverse proxy hosts under Proxy Hosts." +info "5. Review the ANIS threat intelligence connection under Threat Intel — enabled by" +info " default against the public Community Edition hub, no license key required." +info "6. Review security policies in the Security Policy Center." +echo info "Configuration: ${INSTALL_DIR}/.env and ${INSTALL_DIR}/docker-compose.yml" info "Upgrade: cd ${INSTALL_DIR} && docker compose pull && docker compose up -d" -info "Backups: see https://github.com/alleyviper/argus#backups" +info "Backup: cd ${INSTALL_DIR} && ./backup.sh" +info "Docs/support: see README.md in this directory" echo diff --git a/update.sh b/update.sh index 4d13035..043d094 100755 --- a/update.sh +++ b/update.sh @@ -1,14 +1,15 @@ #!/usr/bin/env bash # -# ARGUS updater — pulls the latest published images and restarts the stack. +# ARGUS Enterprise Web Security Platform — updater. Pulls the latest +# published images and restarts the stack. # -# cd ~/argus && ./update.sh +# cd /opt/argus && ./update.sh # (or, if you don't have it locally yet) -# curl -fsSL https://raw.githubusercontent.com/alleyviper/argus/main/update.sh | bash +# curl -fsSL https://git-cloud.weboria.eu/weboria/argus-installer/raw/branch/main/update.sh | bash # set -euo pipefail -INSTALL_DIR="${ARGUS_INSTALL_DIR:-$HOME/argus}" +INSTALL_DIR="${ARGUS_INSTALL_DIR:-/opt/argus}" bold() { printf '\033[1m%s\033[0m\n' "$1"; } info() { printf ' %s\n' "$1"; }