71 Commits
Author SHA1 Message Date
tech b124e02886 chore: update latest-version pointer to v3.79.105 2026-09-12 13:12:28 +00:00
tech 145d031252 chore: update latest-version pointer to v3.79.103 2026-08-31 11:53:45 +00:00
tech bd7ca91132 chore: update latest-version pointer to v3.79.102 2026-08-30 04:15:32 +00:00
tech f1ae7ecd19 chore: update latest-version pointer to v3.79.101 2026-08-30 01:42:07 +00:00
tech b23109cdb9 chore: update latest-version pointer to v3.79.100 2026-08-26 10:18:13 +00:00
tech 92c16e61e3 chore: update latest-version pointer to v3.79.98 2026-08-15 08:43:55 +00:00
tech 2257e37d2c chore: update latest-version pointer to v3.79.97 2026-08-08 13:26:25 +00:00
tech 9be1dfedee chore: update latest-version pointer to v3.79.96 2026-08-07 23:23:39 +00:00
tech 62d47c257d chore: update latest-version pointer to v3.79.95 2026-08-07 21:45:58 +00:00
tech 5b5d411d4c chore: update latest-version pointer to v3.79.94 2026-08-07 20:47:28 +00:00
tech c93d9aaa0a chore: update latest-version pointer to v3.79.94 2026-08-07 20:31:12 +00:00
tech 19e3aeaf98 chore: update latest-version pointer to v3.79.93 2026-08-07 15:01:00 +00:00
tech cb18e4c1b0 chore: update latest-version pointer to v3.79.92 2026-08-07 13:08:12 +00:00
tech c11f8a4a3d chore: update latest-version pointer to v3.79.91 2026-08-06 13:14:30 +00:00
tech 06afa3935e chore: update latest-version pointer to v 2026-08-06 13:08:07 +00:00
tech 87e330fb0e chore: update latest-version pointer to v3.79.90 2026-08-05 17:48:07 +00:00
tech 93702e5b2e chore: update latest-version pointer to v3.79.90 2026-08-05 17:46:48 +00:00
tech d9627b2fad chore: update latest-version pointer to v3.79.89 2026-08-04 18:53:05 +00:00
tech d40f2fc292 chore: update latest-version pointer to v3.79.88 2026-08-04 15:29:19 +00:00
tech 0deb389b46 chore: update latest-version pointer to v3.79.87 2026-08-04 13:39:50 +00:00
tech 10065dbec9 chore: update latest-version pointer to v3.79.86 2026-08-04 11:00:57 +00:00
tech e58b75c01d chore: update latest-version pointer to v3.79.86 2026-08-04 10:59:44 +00:00
tech d63683a0c1 chore: update latest-version pointer to v3.79.85 2026-08-03 21:17:51 +00:00
tech 29abd6812a chore: update latest-version pointer to v3.79.84 2026-08-03 17:30:48 +00:00
tech 718f720464 chore: update latest-version pointer to v3.79.83 2026-08-03 15:57:29 +00:00
tech c598e122af chore: update latest-version pointer to v3.79.83 2026-08-03 15:56:07 +00:00
tech 1ceabcba90 chore: update latest-version pointer to v3.79.82 2026-08-03 10:15:05 +00:00
tech c3bee01b21 chore: update latest-version pointer to v3.79.82 2026-08-03 10:13:53 +00:00
tech fd7c50b476 chore: update latest-version pointer to v3.79.81 2026-08-03 09:09:08 +00:00
tech 99689783e1 chore: update latest-version pointer to v3.79.81 2026-08-03 09:07:43 +00:00
tech 2369c5c5e1 chore: update latest-version pointer to v3.79.80 2026-08-03 03:08:50 +00:00
tech 74021eacd9 chore: update latest-version pointer to v3.79.80 2026-08-03 03:07:30 +00:00
tech bcdf3c21ce chore: update latest-version pointer to v3.79.79 2026-08-03 03:06:02 +00:00
tech 5e4f06c031 chore: update latest-version pointer to v3.79.78 2026-08-03 01:04:59 +00:00
tech 293cc7dcff chore: update latest-version pointer to v3.79.78 2026-08-03 00:59:37 +00:00
tech 43a6766047 chore: update latest-version pointer to v3.79.76 2026-08-02 21:06:34 +00:00
tech 69374325a5 chore: update latest-version pointer to v3.79.75 2026-08-02 16:18:20 +00:00
tech 55b04f015e chore: update latest-version pointer to v3.79.74 2026-08-02 11:56:23 +00:00
tech 206f155ffb chore: update latest-version pointer to v3.79.73 2026-08-02 04:36:20 +00:00
tech 450ed2b9e0 chore: update latest-version pointer to v3.79.72 2026-08-02 00:44:39 +00:00
tech 92fdba7745 chore: update latest-version pointer to v3.79.71 2026-08-01 22:37:08 +00:00
tech a9e28520d2 chore: update latest-version pointer to v3.79.70 2026-08-01 17:07:54 +00:00
tech 2429aa27e7 chore: update latest-version pointer to v3.79.69 2026-08-01 15:27:09 +00:00
tech 674d5715c6 chore: update latest-version pointer to v3.79.68 2026-08-01 13:12:42 +00:00
tech 6847c12804 chore: update latest-version pointer to v3.79.66 2026-08-01 11:44:22 +00:00
tech 3ce9d59ee1 chore: update latest-version pointer to v3.79.65 2026-08-01 11:19:37 +00:00
tech 1ea42fb615 chore: update latest-version pointer to v3.79.58 2026-08-01 02:29:19 +00:00
tech 42f9894ad8 chore: update latest-version pointer to v3.79.56 2026-07-31 19:37:05 +00:00
tech e2a3592f4d chore: update latest-version pointer to v3.79.55 2026-07-31 16:21:57 +00:00
tech 4e8d2f9948 chore: update latest-version pointer to v3.79.54 2026-07-30 23:35:13 +00:00
tech 9a27ac22a5 chore: update latest-version pointer to v3.79.53 2026-07-30 19:44:49 +00:00
tech 68f2e4b594 chore: update latest-version pointer to v3.79.53 2026-07-30 19:42:55 +00:00
tech 6d76f4f6cd chore: update latest-version pointer to v3.79.52 2026-07-30 16:51:40 +00:00
tech 35acca3663 chore: update latest-version pointer to v3.79.51 2026-07-30 15:59:38 +00:00
tech 020ec07641 chore: update latest-version pointer to v3.79.50 2026-07-30 15:24:35 +00:00
tech 0bfc1b3e6b chore: update latest-version pointer to v3.79.49 2026-07-30 14:52:45 +00:00
tech 6cf4acf7ea chore: update latest-version pointer to v3.79.48 2026-07-30 13:36:22 +00:00
tech 80aa96033d chore: update latest-version pointer to v3.79.47 2026-07-30 12:39:09 +00:00
tech 0baf75c493 chore: update latest-version pointer to v3.79.46 2026-07-30 10:34:50 +00:00
tech 2761892c65 chore: update latest-version pointer to v3.79.45 2026-07-30 09:16:05 +00:00
tech ec12b66703 chore: revert test value, restore real latest-version pointer 2026-07-30 08:44:36 +00:00
tech 45ab7a9f80 test: temporary fake newer version for update-available UI verification 2026-07-30 08:43:29 +00:00
tech 7aa80e74b1 chore: correct latest-version pointer to actual last tagged release 2026-07-30 08:41:58 +00:00
tech 54a63652e9 chore: seed latest-version pointer for v3.79.45 2026-07-30 08:37:47 +00:00
tech f5d4852ad8 fix: hex password generation, safe DATABASE_URL, consistent /opt/argus default
Root cause of a real production failure on the first live install
(wap-proxy, 2026-07-25): DB_PASSWORD was generated with
`openssl rand -base64 24`, which can produce '/', '+', or '=' --
docker-compose.yml then naively interpolated the raw password into
postgres://postgres:${DB_PASSWORD}@db:5432/..., and a generated
password containing '/' broke the connection string outright. The API
never became healthy; log ingestion failed completely.

- install.sh now generates with `openssl rand -hex 32` (always
  [0-9a-f], can't produce this class of character). Same fix applied
  everywhere else openssl-rand-base64-24 was referenced.
- docker-compose.yml no longer builds DATABASE_URL by string
  interpolation -- DB_PASSWORD is passed as its own var and the API
  assembles the connection string safely internally using
  net/url.UserPassword (proper percent-encoding), a second,
  independent layer so the installer doesn't rely on the password
  generator alone. See the matching argus-appliance commit for the
  Go-side change and its regression test.
- backup.sh/healthcheck.sh/restore.sh/uninstall.sh still defaulted
  ARGUS_INSTALL_DIR to $HOME/argus, inconsistent with install.sh/
  update.sh's own /opt/argus default (changed in an earlier commit
  this session) -- confirmed live on the same install: healthcheck.sh
  and uninstall.sh reported "no installation found" when run from the
  real, correct directory. All five scripts now agree on /opt/argus.

Corresponding argus-appliance fix (config.go's buildDatabaseURL, v3.73.1)
already built and pushed to git-cloud.weboria.eu/weboria/argus-api.
2026-07-25 17:43:08 +00:00
tech 4dbb7613d9 fix: no self-hosted ANIS model, license key is dashboard-only, remove dead ANIS_SHARE_ATTACKERS
Three corrections, driven by explicit product decisions plus code
verification:

- There is no self-hosted-ANIS deployment model going forward. ANIS_URL
  is now hardcoded to https://anis.weboria.eu in docker-compose.yml, not
  a customer-configurable env var -- removed from env.example and the
  README entirely.
- The ANIS license key is dashboard-only (Threat Intel -> ANIS
  Connection, write-only there per the earlier security fix) -- never
  set via .env. ANIS_LICENSE_KEY hardcoded to an empty string in
  docker-compose.yml (community tier by default) rather than left as a
  pass-through env var with no real path to ever being set.
- Removed ANIS_SHARE_ATTACKERS -- confirmed dead via grep, zero
  references anywhere in the Go source. This was incorrectly kept as
  "real" in the previous env.example cleanup pass; ROADMAP.md in the
  appliance repo already documented this exact variable as dead.

ANIS_ENABLED remains the one real customer-facing ANIS toggle.
2026-07-25 17:16:57 +00:00
tech db132c9f92 refactor: trim env.example to genuinely customer-facing config only
Full review of what belongs in the public installer vs. what customers
should never need to see, per an explicit audit request:

- Removed DB_USER/DB_NAME as customer-configurable env vars entirely --
  nothing outside this compose stack ever connects to Postgres directly,
  so there was no real reason a customer would ever change these.
  Hardcoded to postgres/argus in docker-compose.yml and the two scripts
  that referenced them (backup.sh, restore.sh); DB_PASSWORD remains the
  one real secret, still auto-generated by install.sh.
- Removed ANIS_ADMIN_KEY entirely -- confirmed dead in a prior session's
  audit: it's ANIS's own admin-dashboard credential, unrelated to the
  ARGUS<->ANIS intelligence protocol, which ARGUS never sends. Carried
  over into this file by copy-paste from ANIS's own env template, not
  because ARGUS ever uses it.
- Reordered/re-commented env.example around what a customer actually
  might touch (timezone, ANIS bootstrap trio, network ports for
  conflict resolution, DOCKER_API_VERSION for NAS platforms) versus
  what's fully automated (DB_PASSWORD) -- with an explicit note that
  ongoing product configuration (WAF, DNS, users, policies) happens in
  the dashboard, not this file.
- ANIS_ENABLED/ANIS_URL defaults aligned with the Community Edition
  auto-provisioning decision (true / https://anis.weboria.eu) --
  previously still showed the pre-decision false/empty defaults since
  this repo's initial population predated that change landing.
- Flagged CHANGELOG.md as stale (last entry v3.29.0, well behind the
  current shipped version) with an honest note rather than silently
  leaving a misleading "GitHub Releases page" pointer or backfilling
  invented descriptions of past releases.

No file needed to move to the private repo -- everything here (install/
update/backup/restore/healthcheck/uninstall scripts, the compose
manifest, license/notice docs) is either required for the customer to
install and operate ARGUS or a legal-transparency requirement. None of
it is build logic, dev configuration, or reproducible source.
2026-07-25 17:06:47 +00:00
tech 27be26f5f2 fix(installer): rename .env.example -> env.example, WAF blocks .env* paths
Found live during a real install dry-run: fetching .env.example via the
Gitea raw URL returned a 403 with an ARGUS-branded WAF block page --
Weboria's own front-line WAF blocks any request path matching .env* as a
standard credential-harvesting-probe rule, and it caught this legitimate
static file served from Gitea too. Confirmed docker-compose.yml and other
non-.env-named files fetch fine; only the .env.example path was affected.

Renamed to env.example (no leading dot) rather than requesting a WAF
exception -- sidesteps the false positive without depending on
infrastructure access this session doesn't have. Still saved locally as
.env either way; only the remote filename changed.
2026-07-25 16:38:58 +00:00
tech abab6775d6 feat: switch to Weboria's own registry, clean licensing docs, expand product copy
Registry: docker-compose.yml now pulls argus-api/argus-ui/argus-proxy from
git-cloud.weboria.eu/weboria (Gitea's built-in container registry) instead
of ghcr.io. Built and pushed real production images from main (v3.73.0)
before switching — verified anonymous `docker pull` works for all three
with zero login required, matching the public installer's no-friction
promise. install.sh's registry comment updated to match; no more "gap."

Licensing: reworked per a full commercial-distribution review. Removed
MaxMind/GeoLite2 entirely (confirmed geoip2-golang isn't even in go.mod —
GeoIP is RIR-based, not MaxMind-based, and has been for a while).
Clarified TimescaleDB's licensing story (embedded component distributed
as part of the appliance, not a hosted DB service) rather than leaving it
under a vague "reviewed before bundling" note. Added missing real
dependencies grounded against the actual Dockerfiles (Alpine Linux,
PostgreSQL, Go runtime, Node.js build-time-only, OpenSSL, curl, BusyBox).
Renamed THIRD_PARTY_LICENSES -> THIRD_PARTY_LICENSES.md, added a
"Weboria Proprietary Components" section. Removed the "pending legal
review" section that was specifically about MaxMind/TimescaleDB, now
resolved by the above -- LICENSE's own placeholder-pending-final-terms
disclaimer stays, since drafting real commercial license text is separate
legal work, not something to paper over.

README: removed the internal "this repo contains no proprietary code"
meta-description (customers don't need to see project scaffolding notes)
and the "known gap" callout (both gaps closed above). Expanded the
feature list with a dedicated ANIS Threat Intelligence section and richer
detail on DNS Security, Bot/AI-crawler defense, and the Guided Security
Policy Center. Stronger positioning copy up top.
2026-07-25 16:34:39 +00:00
tech d1aa3a0c87 rebrand: remove GitHub/alleyviper references, position as Weboria enterprise product
README rewritten with the "ARGUS Enterprise Web Security Platform" positioning
and full feature list. install.sh/update.sh now fetch deployment files from
this Gitea repo (git-cloud.weboria.eu) instead of raw.githubusercontent.com,
default install directory changed to /opt/argus, next-steps messaging aligned
with the full onboarding journey (first-run wizard, proxy hosts, ANIS, policy
center). Support link changed from GitHub Issues to the Weboria Support
Portal.

Deliberately NOT changed: docker-compose.yml's image: lines still pull from
ghcr.io — Weboria's own private registry (registry.weboria.eu) resolves in
DNS but has no registry service listening yet (confirmed via direct check),
so switching now would break every real install. Both README and install.sh
document this as a known, tracked gap rather than silently pointing at
infrastructure that doesn't work. Same treatment for license-key validation
during install — not implemented, since there's no licensing service to
validate against yet.
2026-07-25 16:12:17 +00:00
techandroot 96edc98103 docs: note the new repo split and the still-unbuilt license-validation flow 2026-07-25 16:00:18 +00:00