Full review of what belongs in the public installer vs. what customers
should never need to see, per an explicit audit request:
- Removed DB_USER/DB_NAME as customer-configurable env vars entirely --
nothing outside this compose stack ever connects to Postgres directly,
so there was no real reason a customer would ever change these.
Hardcoded to postgres/argus in docker-compose.yml and the two scripts
that referenced them (backup.sh, restore.sh); DB_PASSWORD remains the
one real secret, still auto-generated by install.sh.
- Removed ANIS_ADMIN_KEY entirely -- confirmed dead in a prior session's
audit: it's ANIS's own admin-dashboard credential, unrelated to the
ARGUS<->ANIS intelligence protocol, which ARGUS never sends. Carried
over into this file by copy-paste from ANIS's own env template, not
because ARGUS ever uses it.
- Reordered/re-commented env.example around what a customer actually
might touch (timezone, ANIS bootstrap trio, network ports for
conflict resolution, DOCKER_API_VERSION for NAS platforms) versus
what's fully automated (DB_PASSWORD) -- with an explicit note that
ongoing product configuration (WAF, DNS, users, policies) happens in
the dashboard, not this file.
- ANIS_ENABLED/ANIS_URL defaults aligned with the Community Edition
auto-provisioning decision (true / https://anis.weboria.eu) --
previously still showed the pre-decision false/empty defaults since
this repo's initial population predated that change landing.
- Flagged CHANGELOG.md as stale (last entry v3.29.0, well behind the
current shipped version) with an honest note rather than silently
leaving a misleading "GitHub Releases page" pointer or backfilling
invented descriptions of past releases.
No file needed to move to the private repo -- everything here (install/
update/backup/restore/healthcheck/uninstall scripts, the compose
manifest, license/notice docs) is either required for the customer to
install and operate ARGUS or a legal-transparency requirement. None of
it is build logic, dev configuration, or reproducible source.
Builds the customer-facing distribution: a curated distribution/ directory
containing only what an end customer needs (production docker-compose.yml
with no build: sections, install.sh/update.sh/uninstall.sh/healthcheck.sh/
backup.sh/restore.sh, a customer-facing CHANGELOG.md, and README/LICENSE/
NOTICE/THIRD_PARTY_LICENSES) — pushed as the initial content of the new
public alleyviper/argus repo.
install.sh: detects OS, validates Docker/Compose, fetches all deployment
files, generates a secure DB password, creates the required Docker
network, pulls images, starts the stack, waits for health, and rotates
the default admin/admin credentials via the auth API — printing the
generated password once at the end.
update.sh/healthcheck.sh/backup.sh/restore.sh/uninstall.sh formalize what
was previously ad-hoc README snippets into real, safe-by-default scripts
(uninstall.sh keeps data unless --remove-data is explicitly passed and
confirmed; restore.sh requires typed confirmation and documents that it
targets a fresh install, not a live merge).
Added a sync-distribution job to release.yml: after a successful release,
mirrors distribution/ into the public repo and creates a matching
(customer-facing, commit-log-free) release marker there. Needs a one-time
setup step — a fine-grained PAT scoped to alleyviper/argus added as the
ARGUS_PUBLIC_REPO_TOKEN secret — the job cleanly no-ops until that's added.
Not yet done: GHCR package visibility (argus-secure-api/-ui/-nginx) is
still private, which blocks a genuine end-to-end curl-install test from a
clean, unauthenticated environment — deferred at the user's request until
they flip it manually (GitHub does not expose this via API).