rebrand: remove GitHub/alleyviper references, position as Weboria enterprise product
README rewritten with the "ARGUS Enterprise Web Security Platform" positioning and full feature list. install.sh/update.sh now fetch deployment files from this Gitea repo (git-cloud.weboria.eu) instead of raw.githubusercontent.com, default install directory changed to /opt/argus, next-steps messaging aligned with the full onboarding journey (first-run wizard, proxy hosts, ANIS, policy center). Support link changed from GitHub Issues to the Weboria Support Portal. Deliberately NOT changed: docker-compose.yml's image: lines still pull from ghcr.io — Weboria's own private registry (registry.weboria.eu) resolves in DNS but has no registry service listening yet (confirmed via direct check), so switching now would break every real install. Both README and install.sh document this as a known, tracked gap rather than silently pointing at infrastructure that doesn't work. Same treatment for license-key validation during install — not implemented, since there's no licensing service to validate against yet.
This commit is contained in:
@@ -1,11 +1,11 @@
|
||||
<div align="center">
|
||||
|
||||
# ARGUS
|
||||
# ARGUS Enterprise Web Security Platform
|
||||
|
||||
### Enterprise Web Security Platform
|
||||
### A real-time security operations platform for the modern web edge
|
||||
|
||||
[](LICENSE)
|
||||
[](https://github.com/alleyviper/argus/pkgs/container/argus-secure-api)
|
||||
[](LICENSE)
|
||||
[]()
|
||||
|
||||
[](https://nginx.org/)
|
||||
[](https://modsecurity.org/)
|
||||
@@ -13,16 +13,18 @@
|
||||
[]()
|
||||
|
||||
<p align="center">
|
||||
<strong>A real-time security operations platform for the modern web edge.<br/>
|
||||
Reverse proxy, Web Application Firewall, bot defense, DNS protection, and live threat
|
||||
investigation — in one appliance.</strong>
|
||||
<strong>ARGUS combines a reverse proxy, Web Application Firewall, bot and AI-crawler defense,
|
||||
DNS security engine, threat intelligence integration, GeoIP and cloud-provider access control,
|
||||
automated SSL, rate limiting and auto-ban, real-time attack visualization, incident
|
||||
investigation, load balancing, TCP/UDP stream proxying, enterprise user management, and a full
|
||||
REST API — one complete web security appliance for protecting modern applications.</strong>
|
||||
</p>
|
||||
|
||||
<p align="center">
|
||||
<a href="#-key-features">✨ Features</a> •
|
||||
<a href="#-installation">🚀 Installation</a> •
|
||||
<a href="#-operations">🛠 Operations</a> •
|
||||
<a href="#-api">📚 API</a>
|
||||
<a href="#-licensing--support">📄 Licensing & Support</a>
|
||||
</p>
|
||||
|
||||
---
|
||||
@@ -31,17 +33,15 @@
|
||||
|
||||
> **This is the public ARGUS installer repository.** It contains no proprietary source
|
||||
> code — only installation scripts, configuration templates, and public documentation.
|
||||
> Application source lives in private repos under the Weboria organization on Gitea:
|
||||
> [`argus-appliance`](https://git-cloud.weboria.eu/weboria/argus-appliance) and
|
||||
> [`anis-intelligence-server`](https://git-cloud.weboria.eu/weboria/anis-intelligence-server).
|
||||
> Build/release automation lives in
|
||||
> [`argus-build`](https://git-cloud.weboria.eu/weboria/argus-build). Never commit
|
||||
> application source, internal docs, or credentials into this repo.
|
||||
> Application source is developed privately by Weboria and distributed exclusively as
|
||||
> published container images. You do not need, and will not be given, access to the source
|
||||
> to install, run, or operate ARGUS.
|
||||
>
|
||||
> **Known gap, not yet built:** `install.sh` today pulls public GHCR images with no
|
||||
> license validation — it does not yet implement the "validate license → authenticate
|
||||
> against a private registry → pull official images" flow. That needs a licensing
|
||||
> service and private-registry auth design before `install.sh` can be updated to match.
|
||||
> **Known gap, not yet built:** production images are currently distributed from GitHub
|
||||
> Container Registry while Weboria's own private registry (`registry.weboria.eu`) is
|
||||
> provisioned. License-key validation during install is not yet implemented — that needs a
|
||||
> licensing service design before `install.sh` can enforce it. Both are tracked, not silently
|
||||
> assumed to already work.
|
||||
|
||||
## ✨ Key Features
|
||||
|
||||
@@ -77,7 +77,8 @@ Let's Encrypt with automatic renewal, including wildcard certificates via DNS-01
|
||||
|
||||
### ⚡ Rate Limiting & Auto-Ban
|
||||
Configurable per-IP/per-URI rate limits, automatic banning on repeated WAF violations, and
|
||||
optional community threat-intelligence-driven blocking.
|
||||
optional community threat-intelligence-driven blocking via ANIS (enabled by default, no
|
||||
license key required for the free Community tier).
|
||||
|
||||
### 👥 Full User Management
|
||||
Role-based access, per-user session control, forced password resets, account lock/unlock, MFA,
|
||||
@@ -99,18 +100,20 @@ HTTP/3 (QUIC) and post-quantum-ready TLS (ML-KEM hybrid key exchange).
|
||||
|
||||
### Requirements
|
||||
|
||||
- A Linux host with Docker 24.0+ and the Docker Compose plugin (`docker compose`)
|
||||
- A Linux host with Docker Engine 24.0+ and the Docker Compose plugin (`docker compose`)
|
||||
- 2 vCPU / 4 GB RAM minimum for evaluation; see production sizing guidance in `docs/` for
|
||||
real traffic volumes
|
||||
- Ports 80/443 available for the reverse proxy, and 81 for the admin panel (all configurable)
|
||||
|
||||
### One-line install
|
||||
|
||||
```bash
|
||||
curl -fsSL https://raw.githubusercontent.com/alleyviper/argus/main/install.sh | bash
|
||||
curl -fsSL https://git-cloud.weboria.eu/weboria/argus-installer/raw/branch/main/install.sh | bash
|
||||
```
|
||||
|
||||
This downloads the deployment files, generates a secure database password, creates the
|
||||
This downloads the deployment files, generates secure database/application secrets, creates the
|
||||
required Docker network, pulls the production images, starts ARGUS, and prints your admin
|
||||
login at the end. Installs to `~/argus` by default — set `ARGUS_INSTALL_DIR` first to change
|
||||
login at the end. Installs to `/opt/argus` by default — set `ARGUS_INSTALL_DIR` first to change
|
||||
that.
|
||||
|
||||
### Manual install
|
||||
@@ -118,10 +121,10 @@ that.
|
||||
If you'd rather see every step:
|
||||
|
||||
```bash
|
||||
mkdir -p ~/argus/docker-socket-proxy && cd ~/argus
|
||||
curl -fsSL https://raw.githubusercontent.com/alleyviper/argus/main/docker-compose.yml -o docker-compose.yml
|
||||
curl -fsSL https://raw.githubusercontent.com/alleyviper/argus/main/.env.example -o .env
|
||||
curl -fsSL https://raw.githubusercontent.com/alleyviper/argus/main/docker-socket-proxy/haproxy.cfg.template -o docker-socket-proxy/haproxy.cfg.template
|
||||
mkdir -p /opt/argus/docker-socket-proxy && cd /opt/argus
|
||||
curl -fsSL https://git-cloud.weboria.eu/weboria/argus-installer/raw/branch/main/docker-compose.yml -o docker-compose.yml
|
||||
curl -fsSL https://git-cloud.weboria.eu/weboria/argus-installer/raw/branch/main/.env.example -o .env
|
||||
curl -fsSL https://git-cloud.weboria.eu/weboria/argus-installer/raw/branch/main/docker-socket-proxy/haproxy.cfg.template -o docker-socket-proxy/haproxy.cfg.template
|
||||
|
||||
# Generate a secure database password
|
||||
sed -i "s/DB_PASSWORD=.*/DB_PASSWORD=$(openssl rand -base64 24)/" .env
|
||||
@@ -133,19 +136,30 @@ docker compose pull
|
||||
docker compose up -d
|
||||
```
|
||||
|
||||
Then log in at `https://localhost:81` with `admin` / `admin` and change the password
|
||||
Then log in at `https://<your-server-address>:81` with `admin` / `admin` and change the password
|
||||
immediately — the one-line installer does this rotation for you automatically.
|
||||
|
||||
**Do not expose the admin panel (port 81) to the internet.** Keep it on your LAN/VPN, or put
|
||||
it behind its own proxy host with access lists and 2FA enabled.
|
||||
|
||||
### Next steps after install
|
||||
|
||||
1. Open the administration panel at the access URL printed at the end of install.
|
||||
2. Complete the first-run setup wizard — regional settings and a guided review of every
|
||||
protection module.
|
||||
3. Confirm your administrator password was rotated (the installer does this automatically).
|
||||
4. Configure domains and reverse proxy hosts under **Proxy Hosts**.
|
||||
5. Review the ANIS threat intelligence connection under **Threat Intel** — on by default
|
||||
against the public Community Edition hub.
|
||||
6. Review security policies in the **Security Policy Center**.
|
||||
|
||||
---
|
||||
|
||||
## 🛠 Operations
|
||||
|
||||
Five scripts cover day-to-day operation — download them once alongside `docker-compose.yml`
|
||||
(the one-line installer already does this for you), then run from `~/argus` (or wherever you
|
||||
installed):
|
||||
All lifecycle management is Docker-based — five scripts cover day-to-day operation, downloaded
|
||||
once alongside `docker-compose.yml` (the one-line installer already does this for you), then run
|
||||
from `/opt/argus` (or wherever you installed):
|
||||
|
||||
| Script | Purpose |
|
||||
|--------|---------|
|
||||
@@ -155,21 +169,24 @@ installed):
|
||||
| `./restore.sh <archive>` | Restore a backup onto a fresh installation |
|
||||
| `./uninstall.sh [--remove-data]` | Stop ARGUS; data is kept unless you explicitly opt in to removing it |
|
||||
|
||||
You never manually download application files or modify containers directly — every update is
|
||||
delivered as a new published image version.
|
||||
|
||||
### Upgrading
|
||||
|
||||
```bash
|
||||
cd ~/argus
|
||||
./update.sh
|
||||
cd /opt/argus
|
||||
docker compose pull
|
||||
docker compose up -d
|
||||
```
|
||||
|
||||
New versions are published to GHCR as soon as they're released — `update.sh` always pulls the
|
||||
current stable release. This is the only supported upgrade path; there is no separate migration
|
||||
step to run.
|
||||
(`./update.sh` wraps the same two commands with a before/after version check.) This is the only
|
||||
supported upgrade path; there is no separate migration step to run.
|
||||
|
||||
### Backups
|
||||
|
||||
```bash
|
||||
cd ~/argus
|
||||
cd /opt/argus
|
||||
./backup.sh # writes argus-backup-<timestamp>.tar.gz to the current directory
|
||||
./restore.sh <archive> # onto a fresh installation only — see the script's own header
|
||||
```
|
||||
@@ -184,12 +201,13 @@ Add `--username <name>` to target a specific account, or `--password '...'` to s
|
||||
value instead of generating one. See `docker compose exec api ./server reset-password --help`
|
||||
for the rest of the options (clearing 2FA, etc.).
|
||||
|
||||
### Threat intelligence integration (optional)
|
||||
### Threat intelligence integration
|
||||
|
||||
ARGUS can connect to **ANIS**, a separately-deployed threat-intelligence hub, to share confirmed
|
||||
attacker IPs and receive a community blocklist in return. It's off by default — set
|
||||
`ANIS_ENABLED=true` and `ANIS_URL` in `.env` to turn it on. See the comments in `.env.example`
|
||||
for the full set of options.
|
||||
ARGUS connects to **ANIS**, Weboria's threat-intelligence hub, to share confirmed attacker IPs
|
||||
and receive a community blocklist in return. Enabled by default against the public Community
|
||||
Edition hub — no license key required. Point `ANIS_URL` at your own self-hosted ANIS instead if
|
||||
you run one, or set `ANIS_ENABLED=false` to turn this off entirely. See the comments in
|
||||
`.env.example` for the full set of options.
|
||||
|
||||
---
|
||||
|
||||
@@ -198,7 +216,7 @@ for the full set of options.
|
||||
ARGUS exposes a full REST API for automation. Authenticate with a JWT (`POST
|
||||
/api/v1/auth/login`) for interactive use, or an API token (`Authorization: Bearer ng_<token>`,
|
||||
created from the admin panel) for CI/CD and scripted access. Interactive API documentation is
|
||||
served at `https://localhost:81/api/docs` once ARGUS is running.
|
||||
served at `https://<your-server-address>:81/api/docs` once ARGUS is running.
|
||||
|
||||
---
|
||||
|
||||
@@ -212,24 +230,22 @@ served at `https://localhost:81/api/docs` once ARGUS is running.
|
||||
| `NGINX_HTTP_PORT` / `NGINX_HTTPS_PORT` | Reverse-proxy listen ports | `80` / `443` |
|
||||
| `API_HOST_PORT` | Internal API port exposed to the host | `9080` |
|
||||
| `DNS_LISTEN_HOST` | DNS Security Engine bind address | `127.0.0.1` |
|
||||
| `ANIS_ENABLED` / `ANIS_URL` | Optional threat-intel hub integration | `false` / *(empty)* |
|
||||
| `ANIS_ENABLED` / `ANIS_URL` | Threat-intel hub integration | `true` / `https://anis.weboria.eu` |
|
||||
|
||||
Full list with descriptions in `.env.example`.
|
||||
|
||||
---
|
||||
|
||||
## 📄 License
|
||||
## 📄 Licensing & Support
|
||||
|
||||
This is proprietary, commercial software — see [LICENSE](LICENSE). Third-party open-source
|
||||
components retain their own licenses — see [THIRD_PARTY_LICENSES](THIRD_PARTY_LICENSES) and
|
||||
[NOTICE](NOTICE).
|
||||
ARGUS is commercial software licensed by Weboria — see [LICENSE](LICENSE). Third-party
|
||||
open-source components retain their own licenses — see
|
||||
[THIRD_PARTY_LICENSES](THIRD_PARTY_LICENSES) and [NOTICE](NOTICE).
|
||||
|
||||
## 💬 Support
|
||||
|
||||
[GitHub Issues](https://github.com/alleyviper/argus/issues) — bug reports and feature requests.
|
||||
For licensing questions or support, contact the **Weboria Support Portal**.
|
||||
|
||||
---
|
||||
|
||||
<div align="center">
|
||||
<sub>© 2025-2026 ARGUS — AI4SEC.</sub>
|
||||
<sub>© 2025-2026 Weboria. ARGUS Enterprise Web Security Platform.</sub>
|
||||
</div>
|
||||
|
||||
Reference in New Issue
Block a user