From db132c9f9242971c9f750ed6fad524726776957c Mon Sep 17 00:00:00 2001 From: Weboria Migration Date: Sat, 25 Jul 2026 17:06:47 +0000 Subject: [PATCH] refactor: trim env.example to genuinely customer-facing config only Full review of what belongs in the public installer vs. what customers should never need to see, per an explicit audit request: - Removed DB_USER/DB_NAME as customer-configurable env vars entirely -- nothing outside this compose stack ever connects to Postgres directly, so there was no real reason a customer would ever change these. Hardcoded to postgres/argus in docker-compose.yml and the two scripts that referenced them (backup.sh, restore.sh); DB_PASSWORD remains the one real secret, still auto-generated by install.sh. - Removed ANIS_ADMIN_KEY entirely -- confirmed dead in a prior session's audit: it's ANIS's own admin-dashboard credential, unrelated to the ARGUS<->ANIS intelligence protocol, which ARGUS never sends. Carried over into this file by copy-paste from ANIS's own env template, not because ARGUS ever uses it. - Reordered/re-commented env.example around what a customer actually might touch (timezone, ANIS bootstrap trio, network ports for conflict resolution, DOCKER_API_VERSION for NAS platforms) versus what's fully automated (DB_PASSWORD) -- with an explicit note that ongoing product configuration (WAF, DNS, users, policies) happens in the dashboard, not this file. - ANIS_ENABLED/ANIS_URL defaults aligned with the Community Edition auto-provisioning decision (true / https://anis.weboria.eu) -- previously still showed the pre-decision false/empty defaults since this repo's initial population predated that change landing. - Flagged CHANGELOG.md as stale (last entry v3.29.0, well behind the current shipped version) with an honest note rather than silently leaving a misleading "GitHub Releases page" pointer or backfilling invented descriptions of past releases. No file needed to move to the private repo -- everything here (install/ update/backup/restore/healthcheck/uninstall scripts, the compose manifest, license/notice docs) is either required for the customer to install and operate ARGUS or a legal-transparency requirement. None of it is build logic, dev configuration, or reproducible source. --- CHANGELOG.md | 10 ++++-- backup.sh | 2 +- docker-compose.yml | 26 ++++++++++------ env.example | 77 ++++++++++++++++++++++++---------------------- restore.sh | 2 +- 5 files changed, 67 insertions(+), 50 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 09c4d80..6c64529 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -27,5 +27,11 @@ Versioning follows [Semantic Versioning](https://semver.org/). ## [3.26.0] and earlier -Earlier release history predates this distribution's changelog. See the GitHub Releases -page for this repository going forward — every release from here on is documented here. +Earlier release history predates this distribution's changelog. + +--- + +**Note (2026-07-25):** this file is not currently kept in sync with every release — the most +recent entry above predates the current shipped version. Updating this changelog needs to +become part of the standard release process going forward, not backfilled retroactively with +invented descriptions of past changes. diff --git a/backup.sh b/backup.sh index 2c230dd..5ccc6a1 100755 --- a/backup.sh +++ b/backup.sh @@ -24,7 +24,7 @@ bold "Backing up ARGUS..." WORKDIR="$(mktemp -d)" trap 'rm -rf "$WORKDIR"' EXIT -docker compose exec -T db pg_dump -U "${DB_USER:-postgres}" "${DB_NAME:-argus}" | gzip > "$WORKDIR/db.sql.gz" +docker compose exec -T db pg_dump -U postgres argus | gzip > "$WORKDIR/db.sql.gz" ok "Database dumped" docker run --rm -v argus_api_data:/data -v "$WORKDIR":/backup alpine \ diff --git a/docker-compose.yml b/docker-compose.yml index aa8d6e1..e15418a 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -11,14 +11,18 @@ services: max-file: "3" environment: TZ: ${TZ:-UTC} - POSTGRES_USER: ${DB_USER:-postgres} + # Internal database credentials, not customer-configurable — nothing + # outside this compose stack ever connects to Postgres directly, so + # there's no real reason to let these vary. Only the password (below) + # needs to be a real secret; the username/db name are just labels. + POSTGRES_USER: postgres POSTGRES_PASSWORD: ${DB_PASSWORD:-postgres} - POSTGRES_DB: ${DB_NAME:-argus} + POSTGRES_DB: argus command: postgres -c timezone=${TZ:-UTC} -c log_timezone=${TZ:-UTC} -c shared_preload_libraries=timescaledb -c timescaledb.telemetry_level=off -c max_locks_per_transaction=512 volumes: - postgres_data:/var/lib/postgresql/data healthcheck: - test: ["CMD-SHELL", "pg_isready -U ${DB_USER:-postgres}"] + test: ["CMD-SHELL", "pg_isready -U postgres"] interval: 10s timeout: 5s retries: 10 @@ -104,7 +108,7 @@ services: environment: TZ: ${TZ:-UTC} PORT: "8080" - DATABASE_URL: postgres://${DB_USER:-postgres}:${DB_PASSWORD:-postgres}@db:5432/${DB_NAME:-argus}?sslmode=disable + DATABASE_URL: postgres://postgres:${DB_PASSWORD:-postgres}@db:5432/argus?sslmode=disable REDIS_URL: redis://valkey:6379/0 ENVIRONMENT: ${ENVIRONMENT:-production} NGINX_CONTAINER: argus-proxy @@ -118,12 +122,16 @@ services: NGINX_HTTPS_PORT: ${NGINX_HTTPS_PORT:-} API_HOST_PORT: ${API_HOST_PORT:-9080} API_HOST: ${API_HOST:-} - # ANIS community intelligence — optional, off by default. Set these to - # connect this instance to an already-running ANIS hub. - ANIS_ENABLED: ${ANIS_ENABLED:-false} - ANIS_URL: ${ANIS_URL:-} + # ANIS community intelligence — on by default against the public + # Community Edition hub (empty license key = community tier, no signup + # required). These three only matter on first boot; manage the + # connection afterward from Threat Intel -> ANIS Connection in the + # dashboard. (No ANIS_ADMIN_KEY here: it's ANIS's own admin-dashboard + # credential, unrelated to the ARGUS<->ANIS protocol, which ARGUS never + # sends — a prior version of this file carried it by mistake.) + ANIS_ENABLED: ${ANIS_ENABLED:-true} + ANIS_URL: ${ANIS_URL:-https://anis.weboria.eu} ANIS_LICENSE_KEY: ${ANIS_LICENSE_KEY:-} - ANIS_ADMIN_KEY: ${ANIS_ADMIN_KEY:-} ANIS_SHARE_ATTACKERS: ${ANIS_SHARE_ATTACKERS:-false} DNS_SECURITY_LISTEN_ADDR: ":53" ports: diff --git a/env.example b/env.example index 62d3878..82e2c9a 100644 --- a/env.example +++ b/env.example @@ -1,65 +1,68 @@ -# ARGUS — Environment Configuration -# Copy this file to .env and modify as needed. install.sh does this for you -# automatically, including generating a secure DB_PASSWORD. +# ARGUS Enterprise Web Security Platform — Installation Configuration +# +# install.sh generates this file for you automatically, including a secure +# database password. Most installs need nothing beyond the defaults below. +# +# Everything else — WAF policy, DNS security, threat intelligence tuning, +# proxy hosts, users, security policies — is configured from the ARGUS +# dashboard after your first login, not from this file. # =========================================== -# Required Settings +# Database (do not edit) # =========================================== - -# Database password — install.sh generates this for you. -# Manual value: openssl rand -base64 24 +# install.sh replaces this with a securely generated value on first install +# and never touches it again. There's nothing to fill in here yourself. DB_PASSWORD=change-me-in-production # =========================================== -# Optional Settings +# Timezone # =========================================== - +# Should match the timezone you select in the dashboard's first-run setup +# wizard (Regional Settings) — the wizard checks for a mismatch and will +# warn you if this file and your dashboard selection disagree. TZ=UTC -DB_USER=postgres -DB_NAME=argus # =========================================== -# ANIS — Threat Intelligence Integration +# Threat Intelligence (ANIS) # =========================================== -# ANIS is a separate product, deployed independently (self-hosted or via a -# community instance). These vars configure how THIS ARGUS instance talks to -# an already-running ANIS service — they do not start one. -# -# Set ANIS_ENABLED=true and ANIS_URL to turn on reporting WAF auto-bans to -# ANIS and pulling its community threat-intelligence feed. - -ANIS_ENABLED=false -# ANIS_URL=https://anis.example.com:8090 +# ARGUS connects to ANIS, Weboria's threat-intelligence network, by default +# — no license key needed for the free Community tier. These three values +# only matter on first boot; manage the connection afterward from +# Threat Intel -> ANIS Connection in the dashboard. +ANIS_ENABLED=true +ANIS_URL=https://anis.weboria.eu ANIS_LICENSE_KEY= -# Must match the ANIS instance's own ANIS_ADMIN_KEY. Generate: openssl rand -hex 32 -ANIS_ADMIN_KEY= + +# Share this instance's confirmed attacker IPs back to the community feed? ANIS_SHARE_ATTACKERS=false # =========================================== -# Docker Compatibility (Synology DSM, etc.) -# =========================================== - -# Leave empty for auto-detection. Only set if auto-detection fails. -# Synology DSM typically needs: 1.41 or 1.43 -# DOCKER_API_VERSION=1.41 - -# =========================================== -# Network & Port Settings +# Network Ports # =========================================== +# Only change these if the defaults conflict with something else already +# running on this host. # Admin panel port (default: 81) # UI_PORT=81 -# Nginx listen ports — change if 80/443 are already in use -# (e.g. Synology Web Station) +# Reverse-proxy listen ports — change if 80/443 are already in use # NGINX_HTTP_PORT=8080 # NGINX_HTTPS_PORT=8443 -# API host port — exposed for nginx-to-API communication. +# Internal port used for nginx<->API communication. # MUST NOT conflict with NGINX_HTTP_PORT. # API_HOST_PORT=9080 # DNS Security Engine listen address — host-only (127.0.0.1) by default. -# Set to an internal interface IP to route real client DNS traffic through -# it. Never 0.0.0.0 unless this host is on a fully trusted network. +# Set to an internal interface IP only if you intend to route real client +# DNS traffic through ARGUS. Never 0.0.0.0 unless this host is on a fully +# trusted network — an open forwarding resolver is exactly the profile +# abused for DNS amplification attacks against third parties. # DNS_LISTEN_HOST=127.0.0.1 + +# =========================================== +# Advanced / Troubleshooting +# =========================================== +# Only needed on some NAS platforms (e.g. Synology DSM) where Docker's API +# version needs to be pinned manually. Leave commented out otherwise. +# DOCKER_API_VERSION=1.41 diff --git a/restore.sh b/restore.sh index 7a97a5f..98e7bcc 100755 --- a/restore.sh +++ b/restore.sh @@ -38,7 +38,7 @@ bold "Stopping the API (keeping the database up)..." docker compose stop api ui nginx >/dev/null bold "Restoring database..." -gunzip -c "$WORKDIR/db.sql.gz" | docker compose exec -T db psql -U "${DB_USER:-postgres}" "${DB_NAME:-argus}" >/dev/null +gunzip -c "$WORKDIR/db.sql.gz" | docker compose exec -T db psql -U postgres argus >/dev/null ok "Database restored" bold "Restoring application data..."