Full review of what belongs in the public installer vs. what customers
should never need to see, per an explicit audit request:
- Removed DB_USER/DB_NAME as customer-configurable env vars entirely --
nothing outside this compose stack ever connects to Postgres directly,
so there was no real reason a customer would ever change these.
Hardcoded to postgres/argus in docker-compose.yml and the two scripts
that referenced them (backup.sh, restore.sh); DB_PASSWORD remains the
one real secret, still auto-generated by install.sh.
- Removed ANIS_ADMIN_KEY entirely -- confirmed dead in a prior session's
audit: it's ANIS's own admin-dashboard credential, unrelated to the
ARGUS<->ANIS intelligence protocol, which ARGUS never sends. Carried
over into this file by copy-paste from ANIS's own env template, not
because ARGUS ever uses it.
- Reordered/re-commented env.example around what a customer actually
might touch (timezone, ANIS bootstrap trio, network ports for
conflict resolution, DOCKER_API_VERSION for NAS platforms) versus
what's fully automated (DB_PASSWORD) -- with an explicit note that
ongoing product configuration (WAF, DNS, users, policies) happens in
the dashboard, not this file.
- ANIS_ENABLED/ANIS_URL defaults aligned with the Community Edition
auto-provisioning decision (true / https://anis.weboria.eu) --
previously still showed the pre-decision false/empty defaults since
this repo's initial population predated that change landing.
- Flagged CHANGELOG.md as stale (last entry v3.29.0, well behind the
current shipped version) with an honest note rather than silently
leaving a misleading "GitHub Releases page" pointer or backfilling
invented descriptions of past releases.
No file needed to move to the private repo -- everything here (install/
update/backup/restore/healthcheck/uninstall scripts, the compose
manifest, license/notice docs) is either required for the customer to
install and operate ARGUS or a legal-transparency requirement. None of
it is build logic, dev configuration, or reproducible source.
Found live during a real install dry-run: fetching .env.example via the
Gitea raw URL returned a 403 with an ARGUS-branded WAF block page --
Weboria's own front-line WAF blocks any request path matching .env* as a
standard credential-harvesting-probe rule, and it caught this legitimate
static file served from Gitea too. Confirmed docker-compose.yml and other
non-.env-named files fetch fine; only the .env.example path was affected.
Renamed to env.example (no leading dot) rather than requesting a WAF
exception -- sidesteps the false positive without depending on
infrastructure access this session doesn't have. Still saved locally as
.env either way; only the remote filename changed.