Compare commits
2
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
d1aa3a0c87 | ||
|
|
96edc98103 |
@@ -1,11 +1,11 @@
|
||||
<div align="center">
|
||||
|
||||
# ARGUS
|
||||
# ARGUS Enterprise Web Security Platform
|
||||
|
||||
### Enterprise Web Security Platform
|
||||
### A real-time security operations platform for the modern web edge
|
||||
|
||||
[](LICENSE)
|
||||
[](https://github.com/alleyviper/argus/pkgs/container/argus-secure-api)
|
||||
[](LICENSE)
|
||||
[]()
|
||||
|
||||
[](https://nginx.org/)
|
||||
[](https://modsecurity.org/)
|
||||
@@ -13,22 +13,36 @@
|
||||
[]()
|
||||
|
||||
<p align="center">
|
||||
<strong>A real-time security operations platform for the modern web edge.<br/>
|
||||
Reverse proxy, Web Application Firewall, bot defense, DNS protection, and live threat
|
||||
investigation — in one appliance.</strong>
|
||||
<strong>ARGUS combines a reverse proxy, Web Application Firewall, bot and AI-crawler defense,
|
||||
DNS security engine, threat intelligence integration, GeoIP and cloud-provider access control,
|
||||
automated SSL, rate limiting and auto-ban, real-time attack visualization, incident
|
||||
investigation, load balancing, TCP/UDP stream proxying, enterprise user management, and a full
|
||||
REST API — one complete web security appliance for protecting modern applications.</strong>
|
||||
</p>
|
||||
|
||||
<p align="center">
|
||||
<a href="#-key-features">✨ Features</a> •
|
||||
<a href="#-installation">🚀 Installation</a> •
|
||||
<a href="#-operations">🛠 Operations</a> •
|
||||
<a href="#-api">📚 API</a>
|
||||
<a href="#-licensing--support">📄 Licensing & Support</a>
|
||||
</p>
|
||||
|
||||
---
|
||||
|
||||
</div>
|
||||
|
||||
> **This is the public ARGUS installer repository.** It contains no proprietary source
|
||||
> code — only installation scripts, configuration templates, and public documentation.
|
||||
> Application source is developed privately by Weboria and distributed exclusively as
|
||||
> published container images. You do not need, and will not be given, access to the source
|
||||
> to install, run, or operate ARGUS.
|
||||
>
|
||||
> **Known gap, not yet built:** production images are currently distributed from GitHub
|
||||
> Container Registry while Weboria's own private registry (`registry.weboria.eu`) is
|
||||
> provisioned. License-key validation during install is not yet implemented — that needs a
|
||||
> licensing service design before `install.sh` can enforce it. Both are tracked, not silently
|
||||
> assumed to already work.
|
||||
|
||||
## ✨ Key Features
|
||||
|
||||
### 🛡️ Web Application Firewall
|
||||
@@ -63,7 +77,8 @@ Let's Encrypt with automatic renewal, including wildcard certificates via DNS-01
|
||||
|
||||
### ⚡ Rate Limiting & Auto-Ban
|
||||
Configurable per-IP/per-URI rate limits, automatic banning on repeated WAF violations, and
|
||||
optional community threat-intelligence-driven blocking.
|
||||
optional community threat-intelligence-driven blocking via ANIS (enabled by default, no
|
||||
license key required for the free Community tier).
|
||||
|
||||
### 👥 Full User Management
|
||||
Role-based access, per-user session control, forced password resets, account lock/unlock, MFA,
|
||||
@@ -85,18 +100,20 @@ HTTP/3 (QUIC) and post-quantum-ready TLS (ML-KEM hybrid key exchange).
|
||||
|
||||
### Requirements
|
||||
|
||||
- A Linux host with Docker 24.0+ and the Docker Compose plugin (`docker compose`)
|
||||
- A Linux host with Docker Engine 24.0+ and the Docker Compose plugin (`docker compose`)
|
||||
- 2 vCPU / 4 GB RAM minimum for evaluation; see production sizing guidance in `docs/` for
|
||||
real traffic volumes
|
||||
- Ports 80/443 available for the reverse proxy, and 81 for the admin panel (all configurable)
|
||||
|
||||
### One-line install
|
||||
|
||||
```bash
|
||||
curl -fsSL https://raw.githubusercontent.com/alleyviper/argus/main/install.sh | bash
|
||||
curl -fsSL https://git-cloud.weboria.eu/weboria/argus-installer/raw/branch/main/install.sh | bash
|
||||
```
|
||||
|
||||
This downloads the deployment files, generates a secure database password, creates the
|
||||
This downloads the deployment files, generates secure database/application secrets, creates the
|
||||
required Docker network, pulls the production images, starts ARGUS, and prints your admin
|
||||
login at the end. Installs to `~/argus` by default — set `ARGUS_INSTALL_DIR` first to change
|
||||
login at the end. Installs to `/opt/argus` by default — set `ARGUS_INSTALL_DIR` first to change
|
||||
that.
|
||||
|
||||
### Manual install
|
||||
@@ -104,10 +121,10 @@ that.
|
||||
If you'd rather see every step:
|
||||
|
||||
```bash
|
||||
mkdir -p ~/argus/docker-socket-proxy && cd ~/argus
|
||||
curl -fsSL https://raw.githubusercontent.com/alleyviper/argus/main/docker-compose.yml -o docker-compose.yml
|
||||
curl -fsSL https://raw.githubusercontent.com/alleyviper/argus/main/.env.example -o .env
|
||||
curl -fsSL https://raw.githubusercontent.com/alleyviper/argus/main/docker-socket-proxy/haproxy.cfg.template -o docker-socket-proxy/haproxy.cfg.template
|
||||
mkdir -p /opt/argus/docker-socket-proxy && cd /opt/argus
|
||||
curl -fsSL https://git-cloud.weboria.eu/weboria/argus-installer/raw/branch/main/docker-compose.yml -o docker-compose.yml
|
||||
curl -fsSL https://git-cloud.weboria.eu/weboria/argus-installer/raw/branch/main/.env.example -o .env
|
||||
curl -fsSL https://git-cloud.weboria.eu/weboria/argus-installer/raw/branch/main/docker-socket-proxy/haproxy.cfg.template -o docker-socket-proxy/haproxy.cfg.template
|
||||
|
||||
# Generate a secure database password
|
||||
sed -i "s/DB_PASSWORD=.*/DB_PASSWORD=$(openssl rand -base64 24)/" .env
|
||||
@@ -119,19 +136,30 @@ docker compose pull
|
||||
docker compose up -d
|
||||
```
|
||||
|
||||
Then log in at `https://localhost:81` with `admin` / `admin` and change the password
|
||||
Then log in at `https://<your-server-address>:81` with `admin` / `admin` and change the password
|
||||
immediately — the one-line installer does this rotation for you automatically.
|
||||
|
||||
**Do not expose the admin panel (port 81) to the internet.** Keep it on your LAN/VPN, or put
|
||||
it behind its own proxy host with access lists and 2FA enabled.
|
||||
|
||||
### Next steps after install
|
||||
|
||||
1. Open the administration panel at the access URL printed at the end of install.
|
||||
2. Complete the first-run setup wizard — regional settings and a guided review of every
|
||||
protection module.
|
||||
3. Confirm your administrator password was rotated (the installer does this automatically).
|
||||
4. Configure domains and reverse proxy hosts under **Proxy Hosts**.
|
||||
5. Review the ANIS threat intelligence connection under **Threat Intel** — on by default
|
||||
against the public Community Edition hub.
|
||||
6. Review security policies in the **Security Policy Center**.
|
||||
|
||||
---
|
||||
|
||||
## 🛠 Operations
|
||||
|
||||
Five scripts cover day-to-day operation — download them once alongside `docker-compose.yml`
|
||||
(the one-line installer already does this for you), then run from `~/argus` (or wherever you
|
||||
installed):
|
||||
All lifecycle management is Docker-based — five scripts cover day-to-day operation, downloaded
|
||||
once alongside `docker-compose.yml` (the one-line installer already does this for you), then run
|
||||
from `/opt/argus` (or wherever you installed):
|
||||
|
||||
| Script | Purpose |
|
||||
|--------|---------|
|
||||
@@ -141,21 +169,24 @@ installed):
|
||||
| `./restore.sh <archive>` | Restore a backup onto a fresh installation |
|
||||
| `./uninstall.sh [--remove-data]` | Stop ARGUS; data is kept unless you explicitly opt in to removing it |
|
||||
|
||||
You never manually download application files or modify containers directly — every update is
|
||||
delivered as a new published image version.
|
||||
|
||||
### Upgrading
|
||||
|
||||
```bash
|
||||
cd ~/argus
|
||||
./update.sh
|
||||
cd /opt/argus
|
||||
docker compose pull
|
||||
docker compose up -d
|
||||
```
|
||||
|
||||
New versions are published to GHCR as soon as they're released — `update.sh` always pulls the
|
||||
current stable release. This is the only supported upgrade path; there is no separate migration
|
||||
step to run.
|
||||
(`./update.sh` wraps the same two commands with a before/after version check.) This is the only
|
||||
supported upgrade path; there is no separate migration step to run.
|
||||
|
||||
### Backups
|
||||
|
||||
```bash
|
||||
cd ~/argus
|
||||
cd /opt/argus
|
||||
./backup.sh # writes argus-backup-<timestamp>.tar.gz to the current directory
|
||||
./restore.sh <archive> # onto a fresh installation only — see the script's own header
|
||||
```
|
||||
@@ -170,12 +201,13 @@ Add `--username <name>` to target a specific account, or `--password '...'` to s
|
||||
value instead of generating one. See `docker compose exec api ./server reset-password --help`
|
||||
for the rest of the options (clearing 2FA, etc.).
|
||||
|
||||
### Threat intelligence integration (optional)
|
||||
### Threat intelligence integration
|
||||
|
||||
ARGUS can connect to **ANIS**, a separately-deployed threat-intelligence hub, to share confirmed
|
||||
attacker IPs and receive a community blocklist in return. It's off by default — set
|
||||
`ANIS_ENABLED=true` and `ANIS_URL` in `.env` to turn it on. See the comments in `.env.example`
|
||||
for the full set of options.
|
||||
ARGUS connects to **ANIS**, Weboria's threat-intelligence hub, to share confirmed attacker IPs
|
||||
and receive a community blocklist in return. Enabled by default against the public Community
|
||||
Edition hub — no license key required. Point `ANIS_URL` at your own self-hosted ANIS instead if
|
||||
you run one, or set `ANIS_ENABLED=false` to turn this off entirely. See the comments in
|
||||
`.env.example` for the full set of options.
|
||||
|
||||
---
|
||||
|
||||
@@ -184,7 +216,7 @@ for the full set of options.
|
||||
ARGUS exposes a full REST API for automation. Authenticate with a JWT (`POST
|
||||
/api/v1/auth/login`) for interactive use, or an API token (`Authorization: Bearer ng_<token>`,
|
||||
created from the admin panel) for CI/CD and scripted access. Interactive API documentation is
|
||||
served at `https://localhost:81/api/docs` once ARGUS is running.
|
||||
served at `https://<your-server-address>:81/api/docs` once ARGUS is running.
|
||||
|
||||
---
|
||||
|
||||
@@ -198,24 +230,22 @@ served at `https://localhost:81/api/docs` once ARGUS is running.
|
||||
| `NGINX_HTTP_PORT` / `NGINX_HTTPS_PORT` | Reverse-proxy listen ports | `80` / `443` |
|
||||
| `API_HOST_PORT` | Internal API port exposed to the host | `9080` |
|
||||
| `DNS_LISTEN_HOST` | DNS Security Engine bind address | `127.0.0.1` |
|
||||
| `ANIS_ENABLED` / `ANIS_URL` | Optional threat-intel hub integration | `false` / *(empty)* |
|
||||
| `ANIS_ENABLED` / `ANIS_URL` | Threat-intel hub integration | `true` / `https://anis.weboria.eu` |
|
||||
|
||||
Full list with descriptions in `.env.example`.
|
||||
|
||||
---
|
||||
|
||||
## 📄 License
|
||||
## 📄 Licensing & Support
|
||||
|
||||
This is proprietary, commercial software — see [LICENSE](LICENSE). Third-party open-source
|
||||
components retain their own licenses — see [THIRD_PARTY_LICENSES](THIRD_PARTY_LICENSES) and
|
||||
[NOTICE](NOTICE).
|
||||
ARGUS is commercial software licensed by Weboria — see [LICENSE](LICENSE). Third-party
|
||||
open-source components retain their own licenses — see
|
||||
[THIRD_PARTY_LICENSES](THIRD_PARTY_LICENSES) and [NOTICE](NOTICE).
|
||||
|
||||
## 💬 Support
|
||||
|
||||
[GitHub Issues](https://github.com/alleyviper/argus/issues) — bug reports and feature requests.
|
||||
For licensing questions or support, contact the **Weboria Support Portal**.
|
||||
|
||||
---
|
||||
|
||||
<div align="center">
|
||||
<sub>© 2025-2026 ARGUS — AI4SEC.</sub>
|
||||
<sub>© 2025-2026 Weboria. ARGUS Enterprise Web Security Platform.</sub>
|
||||
</div>
|
||||
|
||||
+30
-8
@@ -1,15 +1,22 @@
|
||||
#!/usr/bin/env bash
|
||||
#
|
||||
# ARGUS installer — fetches the production compose stack, generates secrets,
|
||||
# starts the platform, and prints your admin credentials.
|
||||
# ARGUS Enterprise Web Security Platform — installer. Fetches the production
|
||||
# compose stack, generates secrets, starts the platform, and prints your
|
||||
# admin credentials.
|
||||
#
|
||||
# curl -fsSL https://raw.githubusercontent.com/alleyviper/argus/main/install.sh | bash
|
||||
# curl -fsSL https://git-cloud.weboria.eu/weboria/argus-installer/raw/branch/main/install.sh | bash
|
||||
#
|
||||
set -euo pipefail
|
||||
|
||||
REPO_RAW_BASE="https://raw.githubusercontent.com/alleyviper/argus/main"
|
||||
INSTALL_DIR="${ARGUS_INSTALL_DIR:-$HOME/argus}"
|
||||
REPO_RAW_BASE="https://git-cloud.weboria.eu/weboria/argus-installer/raw/branch/main"
|
||||
INSTALL_DIR="${ARGUS_INSTALL_DIR:-/opt/argus}"
|
||||
NETWORK_NAME="argus-network"
|
||||
# The image registry is still ghcr.io (GitHub Container Registry) today —
|
||||
# Weboria's own private registry (registry.weboria.eu) is provisioned but
|
||||
# not yet serving images. docker-compose.yml's image: lines point at ghcr.io
|
||||
# directly rather than a variable here, since that's the only registry that
|
||||
# actually has published images right now; switching to registry.weboria.eu
|
||||
# is a one-line change to those image: lines once it's live, not a rewrite.
|
||||
|
||||
# ── Output helpers ────────────────────────────────────────────────────────────
|
||||
bold() { printf '\033[1m%s\033[0m\n' "$1"; }
|
||||
@@ -127,9 +134,9 @@ UI_PORT="$(grep -oP '^UI_PORT=\K.*' .env 2>/dev/null || true)"
|
||||
UI_PORT="${UI_PORT:-81}"
|
||||
|
||||
echo
|
||||
bold "ARGUS is installed and running."
|
||||
bold "ARGUS Enterprise Web Security Platform has been successfully installed."
|
||||
echo
|
||||
info "Admin Panel: https://localhost:${UI_PORT} (accept the self-signed certificate)"
|
||||
info "Access URL: https://$(hostname -I 2>/dev/null | awk '{print $1}' || echo localhost):${UI_PORT} (accept the self-signed certificate)"
|
||||
if [ "$CREDS_ROTATED" = "true" ]; then
|
||||
info "Username: ${ADMIN_USER}"
|
||||
info "Password: ${ADMIN_PASSWORD}"
|
||||
@@ -138,7 +145,22 @@ else
|
||||
info "Log in with your existing admin credentials."
|
||||
fi
|
||||
echo
|
||||
bold "Next steps:"
|
||||
info "1. Open the administration panel at the Access URL above."
|
||||
if [ "$CREDS_ROTATED" != "true" ]; then
|
||||
info "2. Complete the first-run setup wizard (regional settings, guided protection checklist)."
|
||||
info "3. Change the initial administrator password if you haven't already."
|
||||
else
|
||||
info "2. Complete the first-run setup wizard — regional settings and a guided review of every"
|
||||
info " protection module (your admin password was already rotated above)."
|
||||
fi
|
||||
info "4. Configure domains and reverse proxy hosts under Proxy Hosts."
|
||||
info "5. Review the ANIS threat intelligence connection under Threat Intel — enabled by"
|
||||
info " default against the public Community Edition hub, no license key required."
|
||||
info "6. Review security policies in the Security Policy Center."
|
||||
echo
|
||||
info "Configuration: ${INSTALL_DIR}/.env and ${INSTALL_DIR}/docker-compose.yml"
|
||||
info "Upgrade: cd ${INSTALL_DIR} && docker compose pull && docker compose up -d"
|
||||
info "Backups: see https://github.com/alleyviper/argus#backups"
|
||||
info "Backup: cd ${INSTALL_DIR} && ./backup.sh"
|
||||
info "Docs/support: see README.md in this directory"
|
||||
echo
|
||||
|
||||
@@ -1,14 +1,15 @@
|
||||
#!/usr/bin/env bash
|
||||
#
|
||||
# ARGUS updater — pulls the latest published images and restarts the stack.
|
||||
# ARGUS Enterprise Web Security Platform — updater. Pulls the latest
|
||||
# published images and restarts the stack.
|
||||
#
|
||||
# cd ~/argus && ./update.sh
|
||||
# cd /opt/argus && ./update.sh
|
||||
# (or, if you don't have it locally yet)
|
||||
# curl -fsSL https://raw.githubusercontent.com/alleyviper/argus/main/update.sh | bash
|
||||
# curl -fsSL https://git-cloud.weboria.eu/weboria/argus-installer/raw/branch/main/update.sh | bash
|
||||
#
|
||||
set -euo pipefail
|
||||
|
||||
INSTALL_DIR="${ARGUS_INSTALL_DIR:-$HOME/argus}"
|
||||
INSTALL_DIR="${ARGUS_INSTALL_DIR:-/opt/argus}"
|
||||
|
||||
bold() { printf '\033[1m%s\033[0m\n' "$1"; }
|
||||
info() { printf ' %s\n' "$1"; }
|
||||
|
||||
Reference in New Issue
Block a user