Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
f5d4852ad8 | ||
|
|
4dbb7613d9 | ||
|
|
db132c9f92 | ||
|
|
27be26f5f2 | ||
|
|
abab6775d6 |
@@ -1,65 +0,0 @@
|
||||
# ARGUS — Environment Configuration
|
||||
# Copy this file to .env and modify as needed. install.sh does this for you
|
||||
# automatically, including generating a secure DB_PASSWORD.
|
||||
|
||||
# ===========================================
|
||||
# Required Settings
|
||||
# ===========================================
|
||||
|
||||
# Database password — install.sh generates this for you.
|
||||
# Manual value: openssl rand -base64 24
|
||||
DB_PASSWORD=change-me-in-production
|
||||
|
||||
# ===========================================
|
||||
# Optional Settings
|
||||
# ===========================================
|
||||
|
||||
TZ=UTC
|
||||
DB_USER=postgres
|
||||
DB_NAME=argus
|
||||
|
||||
# ===========================================
|
||||
# ANIS — Threat Intelligence Integration
|
||||
# ===========================================
|
||||
# ANIS is a separate product, deployed independently (self-hosted or via a
|
||||
# community instance). These vars configure how THIS ARGUS instance talks to
|
||||
# an already-running ANIS service — they do not start one.
|
||||
#
|
||||
# Set ANIS_ENABLED=true and ANIS_URL to turn on reporting WAF auto-bans to
|
||||
# ANIS and pulling its community threat-intelligence feed.
|
||||
|
||||
ANIS_ENABLED=false
|
||||
# ANIS_URL=https://anis.example.com:8090
|
||||
ANIS_LICENSE_KEY=
|
||||
# Must match the ANIS instance's own ANIS_ADMIN_KEY. Generate: openssl rand -hex 32
|
||||
ANIS_ADMIN_KEY=
|
||||
ANIS_SHARE_ATTACKERS=false
|
||||
|
||||
# ===========================================
|
||||
# Docker Compatibility (Synology DSM, etc.)
|
||||
# ===========================================
|
||||
|
||||
# Leave empty for auto-detection. Only set if auto-detection fails.
|
||||
# Synology DSM typically needs: 1.41 or 1.43
|
||||
# DOCKER_API_VERSION=1.41
|
||||
|
||||
# ===========================================
|
||||
# Network & Port Settings
|
||||
# ===========================================
|
||||
|
||||
# Admin panel port (default: 81)
|
||||
# UI_PORT=81
|
||||
|
||||
# Nginx listen ports — change if 80/443 are already in use
|
||||
# (e.g. Synology Web Station)
|
||||
# NGINX_HTTP_PORT=8080
|
||||
# NGINX_HTTPS_PORT=8443
|
||||
|
||||
# API host port — exposed for nginx-to-API communication.
|
||||
# MUST NOT conflict with NGINX_HTTP_PORT.
|
||||
# API_HOST_PORT=9080
|
||||
|
||||
# DNS Security Engine listen address — host-only (127.0.0.1) by default.
|
||||
# Set to an internal interface IP to route real client DNS traffic through
|
||||
# it. Never 0.0.0.0 unless this host is on a fully trusted network.
|
||||
# DNS_LISTEN_HOST=127.0.0.1
|
||||
+8
-2
@@ -27,5 +27,11 @@ Versioning follows [Semantic Versioning](https://semver.org/).
|
||||
|
||||
## [3.26.0] and earlier
|
||||
|
||||
Earlier release history predates this distribution's changelog. See the GitHub Releases
|
||||
page for this repository going forward — every release from here on is documented here.
|
||||
Earlier release history predates this distribution's changelog.
|
||||
|
||||
---
|
||||
|
||||
**Note (2026-07-25):** this file is not currently kept in sync with every release — the most
|
||||
recent entry above predates the current shipped version. Updating this changelog needs to
|
||||
become part of the standard release process going forward, not backfilled retroactively with
|
||||
invented descriptions of past changes.
|
||||
|
||||
@@ -1,17 +1,18 @@
|
||||
ARGUS Secure — Proprietary Software License
|
||||
Copyright (c) 2025-2026 AI4SEC / lmelo. All rights reserved.
|
||||
ARGUS Enterprise Web Security Platform — Commercial License
|
||||
Copyright (c) 2025-2026 Weboria. All rights reserved.
|
||||
|
||||
** PLACEHOLDER — NOT A FINAL LICENSE **
|
||||
|
||||
This repository contains proprietary, commercial software. A complete commercial license
|
||||
agreement has not yet been finalized and this file is a placeholder pending legal review.
|
||||
This repository contains proprietary, commercial software developed by Weboria. A complete
|
||||
commercial license agreement has not yet been finalized and this file is a placeholder pending
|
||||
legal review — this is a real, open item, not boilerplate.
|
||||
|
||||
Until a final license is adopted, no rights are granted to use, copy, modify, merge, publish,
|
||||
distribute, sublicense, or sell copies of this software, in whole or in part, except as
|
||||
separately agreed in writing with the copyright holder.
|
||||
separately agreed in writing with Weboria.
|
||||
|
||||
This software incorporates third-party open-source components under their own licenses;
|
||||
see THIRD_PARTY_LICENSES and NOTICE for details. Nothing in this placeholder alters the terms
|
||||
of those third-party components.
|
||||
see THIRD_PARTY_LICENSES.md and NOTICE for details. Nothing in this placeholder alters the
|
||||
terms of those third-party components.
|
||||
|
||||
TODO before release: replace this file with final commercial/enterprise license text.
|
||||
|
||||
@@ -1,18 +1,25 @@
|
||||
ARGUS Secure
|
||||
Copyright (c) 2025-2026 AI4SEC / lmelo
|
||||
ARGUS Enterprise Web Security Platform
|
||||
|
||||
This product includes software developed by third parties under their own open-source
|
||||
licenses. Full license texts and attributions are listed in THIRD_PARTY_LICENSES.
|
||||
Copyright © 2025-2026 Weboria
|
||||
|
||||
ARGUS contains third-party open-source software.
|
||||
The licenses and notices for these components are available in:
|
||||
THIRD_PARTY_LICENSES.md
|
||||
|
||||
Notable components:
|
||||
- nginx (BSD-2-Clause) — Copyright (C) 2002-2024 Igor Sysoev, (C) 2011-2024 Nginx, Inc.
|
||||
- ModSecurity (Apache-2.0) — Copyright (C) 2002-2024 Trustwave Holdings, Inc.
|
||||
- OWASP Core Rule Set (Apache-2.0) — Copyright (C) 2006-2024 Trustwave Holdings, Inc.,
|
||||
OWASP Core Rule Set contributors
|
||||
- TimescaleDB Community Edition (Timescale License) — see THIRD_PARTY_LICENSES for
|
||||
redistribution terms
|
||||
- MaxMind GeoLite2 (GeoLite2 EULA) — "This product includes GeoLite2 data created by
|
||||
MaxMind, available from https://www.maxmind.com"
|
||||
- TimescaleDB (Timescale License / Apache 2.0 depending on component) — distributed as an
|
||||
embedded time-series storage component as part of the ARGUS Enterprise Appliance, not
|
||||
offered as a standalone database service. See THIRD_PARTY_LICENSES.md for detail.
|
||||
- Valkey (BSD-3-Clause)
|
||||
- PostgreSQL (PostgreSQL License), Alpine Linux, BusyBox, Go runtime, Node.js (build-time
|
||||
only), OpenSSL, curl — see THIRD_PARTY_LICENSES.md
|
||||
|
||||
This repository's own source code is proprietary; see LICENSE.
|
||||
The following ARGUS components are proprietary software developed by Weboria and are not
|
||||
covered by the third-party licenses above: ARGUS Core Platform, ARGUS Management Interface,
|
||||
ARGUS Security Automation Engine, ARGUS API Layer, ARGUS Threat Analysis Components, ARGUS
|
||||
Licensing System, ARGUS Enterprise Features, and Weboria Integrations. These are distributed
|
||||
under the ARGUS Commercial License — see LICENSE.
|
||||
|
||||
@@ -13,11 +13,11 @@
|
||||
[]()
|
||||
|
||||
<p align="center">
|
||||
<strong>ARGUS combines a reverse proxy, Web Application Firewall, bot and AI-crawler defense,
|
||||
DNS security engine, threat intelligence integration, GeoIP and cloud-provider access control,
|
||||
automated SSL, rate limiting and auto-ban, real-time attack visualization, incident
|
||||
investigation, load balancing, TCP/UDP stream proxying, enterprise user management, and a full
|
||||
REST API — one complete web security appliance for protecting modern applications.</strong>
|
||||
<strong>Enterprise-grade protection for the modern web edge — in the same league as Fortinet,
|
||||
Palo Alto, and F5, purpose-built for how applications are actually attacked today.</strong><br/>
|
||||
<strong>Reverse proxy. Web Application Firewall. Bot and AI-crawler defense. DNS security.
|
||||
Real-time threat intelligence. Live attack visualization. Incident investigation. One
|
||||
appliance, one dashboard, zero blind spots.</strong>
|
||||
</p>
|
||||
|
||||
<p align="center">
|
||||
@@ -31,68 +31,92 @@
|
||||
|
||||
</div>
|
||||
|
||||
> **This is the public ARGUS installer repository.** It contains no proprietary source
|
||||
> code — only installation scripts, configuration templates, and public documentation.
|
||||
> Application source is developed privately by Weboria and distributed exclusively as
|
||||
> published container images. You do not need, and will not be given, access to the source
|
||||
> to install, run, or operate ARGUS.
|
||||
>
|
||||
> **Known gap, not yet built:** production images are currently distributed from GitHub
|
||||
> Container Registry while Weboria's own private registry (`registry.weboria.eu`) is
|
||||
> provisioned. License-key validation during install is not yet implemented — that needs a
|
||||
> licensing service design before `install.sh` can enforce it. Both are tracked, not silently
|
||||
> assumed to already work.
|
||||
|
||||
## ✨ Key Features
|
||||
|
||||
### 🛡️ Web Application Firewall
|
||||
ModSecurity v3 with the OWASP Core Rule Set. Paranoia levels 1–4, per-host rule exceptions,
|
||||
detection-only or blocking modes.
|
||||
ModSecurity v3 running the full OWASP Core Rule Set, tunable across paranoia levels 1–4 per
|
||||
site — start permissive on a new application, tighten as you learn its traffic. Detection-only
|
||||
or blocking mode per host, per-rule exceptions for known false positives, and a Rule Health
|
||||
view that tracks which rules are actually earning their keep versus generating noise, so tuning
|
||||
is based on evidence, not guesswork.
|
||||
|
||||
### 🧠 ANIS Threat Intelligence
|
||||
ARGUS ships connected by default to **ANIS (Argus Network Intelligence Server)**, Weboria's
|
||||
community-powered reputation network: every ARGUS deployment that opts in contributes
|
||||
confirmed-attacker IPs and receives the aggregated blocklist back in return, so your appliance
|
||||
gets smarter from day one using signal from every other protected site — no license key
|
||||
required for the free Community tier. Every dashboard, investigation view, and auto-ban
|
||||
decision is enriched with live ANIS reputation scoring. A license key upgrades the tier —
|
||||
manage it entirely from Threat Intel → ANIS Connection in the dashboard, or turn the
|
||||
integration off entirely from the same page.
|
||||
|
||||
### 🌐 Attack Origin Visualization
|
||||
A live global map of inbound attacks — real-time arcs from source to your infrastructure,
|
||||
severity-coded, with instant drill-down into any event's full detail.
|
||||
color-coded by severity, with a running feed of top attacking countries and IPs. Pause, rewind,
|
||||
and replay historical traffic, or click straight through to any single event's full detail.
|
||||
|
||||
### 🔎 Incident Investigation
|
||||
Pivot from any IP, log line, or dashboard event straight into that entity's complete history —
|
||||
affected hosts, triggered rules, geography, and live threat-intelligence reputation — without
|
||||
losing your place.
|
||||
every affected host it touched, every rule it triggered, its geography and ASN, and its live
|
||||
ANIS reputation score — all in one place, without losing your position in whatever you were
|
||||
looking at.
|
||||
|
||||
### 🤖 Bot & AI-Crawler Defense
|
||||
Blocks known-bad bots and AI scrapers automatically, with a search-engine allowlist so legitimate
|
||||
crawlers are never affected. Escalating challenge modes (browser check, proof-of-work, visual
|
||||
CAPTCHA) for suspicious traffic.
|
||||
Automatically blocks known-bad bots and scrapers, with a maintained allowlist so legitimate
|
||||
search engines are never caught in the net. Purpose-built detection for AI crawlers (GPTBot,
|
||||
ClaudeBot, and similar) lets you choose exactly which ones are welcome. Escalating challenge
|
||||
modes — silent browser verification, proof-of-work, visual CAPTCHA — apply exactly as much
|
||||
friction as suspicious traffic actually warrants, backed by a live risk-scoring engine so the
|
||||
decision is never a coin flip.
|
||||
|
||||
### 🧬 DNS Security Engine
|
||||
An embedded forwarding DNS resolver with real-time threat detection — DGA domains, DNS
|
||||
tunneling, fast-flux infrastructure, cache-poisoning attempts — and automatic mitigation via
|
||||
sinkholing.
|
||||
Passive DNS intelligence starts working the moment your first site is protected — no network
|
||||
reconfiguration required — scoring every domain your traffic touches for DGA patterns,
|
||||
fast-flux infrastructure, and other red flags, and cross-referencing that against real WAF
|
||||
activity for a much stronger signal than either check alone. An optional embedded resolver adds
|
||||
network-wide DNS tunneling detection, NXDOMAIN-flood protection, and automatic sinkholing for
|
||||
sites that want DNS-layer coverage too.
|
||||
|
||||
### 🌍 GeoIP & Cloud-Provider Access Control
|
||||
Allow or block traffic by country or hosting provider, with live visual feedback.
|
||||
Allow or block traffic by country or hosting provider, with live visual feedback as you tune
|
||||
the policy — see exactly what would have been blocked before you commit to it.
|
||||
|
||||
### 🔒 Automated SSL
|
||||
Let's Encrypt with automatic renewal, including wildcard certificates via DNS-01 challenge
|
||||
(Cloudflare, DuckDNS, Dynu, and more).
|
||||
across major DNS providers (Cloudflare, DuckDNS, Dynu, and more) — certificates that never
|
||||
expire on your watch.
|
||||
|
||||
### ⚡ Rate Limiting & Auto-Ban
|
||||
Configurable per-IP/per-URI rate limits, automatic banning on repeated WAF violations, and
|
||||
optional community threat-intelligence-driven blocking via ANIS (enabled by default, no
|
||||
license key required for the free Community tier).
|
||||
community-intelligence-driven blocking via ANIS — layered defenses that reinforce each other
|
||||
rather than working in isolation.
|
||||
|
||||
### 👥 Full User Management
|
||||
Role-based access, per-user session control, forced password resets, account lock/unlock, MFA,
|
||||
and a complete login history — everything a security team needs to administer access safely.
|
||||
### 👥 Enterprise User Management
|
||||
Role-based access control, per-user session management, forced password resets, account
|
||||
lock/unlock as a reversible incident-response tool, mandatory MFA for administrators, and a
|
||||
complete audit trail of every login and admin action — everything a security team needs to
|
||||
administer access with confidence.
|
||||
|
||||
### 📊 Real-Time Operations Dashboard
|
||||
Live traffic, security events, and system health, updated continuously — no manual refresh.
|
||||
Live traffic, security events, and system health updated continuously — a true operations
|
||||
console, not a page you have to remember to refresh. Guided, role-based dashboard profiles (SOC
|
||||
Analyst, Security Administrator, Network Administrator, Executive Overview) put the right view
|
||||
in front of the right person automatically.
|
||||
|
||||
### 🎯 Guided Security Policy Center
|
||||
Every protection module — WAF, DNS, GeoIP, Bot Protection, Rate Limiting, SSL/TLS, and more —
|
||||
comes with one-click policy tiers from Home to Maximum Protection, a plain-language impact
|
||||
preview before you apply anything, and an honest posture score that tells you exactly what's
|
||||
configured, what's missing, and why it matters. No security expertise required to deploy with
|
||||
confidence.
|
||||
|
||||
### 🔀 Load Balancing & Stream Proxying
|
||||
Multiple backend servers with health checks, plus TCP/UDP stream proxying with optional SNI
|
||||
routing.
|
||||
Multiple backend servers with active health checks, plus TCP/UDP stream proxying with optional
|
||||
SNI routing for non-HTTP services.
|
||||
|
||||
### 🔮 Modern Protocol Support
|
||||
HTTP/3 (QUIC) and post-quantum-ready TLS (ML-KEM hybrid key exchange).
|
||||
HTTP/3 (QUIC) and post-quantum-ready TLS (ML-KEM hybrid key exchange) — ready for where the web
|
||||
is headed, not just where it's been.
|
||||
|
||||
---
|
||||
|
||||
@@ -123,11 +147,11 @@ If you'd rather see every step:
|
||||
```bash
|
||||
mkdir -p /opt/argus/docker-socket-proxy && cd /opt/argus
|
||||
curl -fsSL https://git-cloud.weboria.eu/weboria/argus-installer/raw/branch/main/docker-compose.yml -o docker-compose.yml
|
||||
curl -fsSL https://git-cloud.weboria.eu/weboria/argus-installer/raw/branch/main/.env.example -o .env
|
||||
curl -fsSL https://git-cloud.weboria.eu/weboria/argus-installer/raw/branch/main/env.example -o .env
|
||||
curl -fsSL https://git-cloud.weboria.eu/weboria/argus-installer/raw/branch/main/docker-socket-proxy/haproxy.cfg.template -o docker-socket-proxy/haproxy.cfg.template
|
||||
|
||||
# Generate a secure database password
|
||||
sed -i "s/DB_PASSWORD=.*/DB_PASSWORD=$(openssl rand -base64 24)/" .env
|
||||
sed -i "s/DB_PASSWORD=.*/DB_PASSWORD=$(openssl rand -hex 32)/" .env
|
||||
|
||||
# ARGUS expects this network to already exist
|
||||
docker network create argus-network
|
||||
@@ -205,9 +229,9 @@ for the rest of the options (clearing 2FA, etc.).
|
||||
|
||||
ARGUS connects to **ANIS**, Weboria's threat-intelligence hub, to share confirmed attacker IPs
|
||||
and receive a community blocklist in return. Enabled by default against the public Community
|
||||
Edition hub — no license key required. Point `ANIS_URL` at your own self-hosted ANIS instead if
|
||||
you run one, or set `ANIS_ENABLED=false` to turn this off entirely. See the comments in
|
||||
`.env.example` for the full set of options.
|
||||
Edition hub — no license key required. Set `ANIS_ENABLED=false` in `.env` to turn this off
|
||||
entirely. A license key upgrades the tier — set it from Threat Intel → ANIS Connection in the
|
||||
dashboard, not from `.env`.
|
||||
|
||||
---
|
||||
|
||||
@@ -230,9 +254,10 @@ served at `https://<your-server-address>:81/api/docs` once ARGUS is running.
|
||||
| `NGINX_HTTP_PORT` / `NGINX_HTTPS_PORT` | Reverse-proxy listen ports | `80` / `443` |
|
||||
| `API_HOST_PORT` | Internal API port exposed to the host | `9080` |
|
||||
| `DNS_LISTEN_HOST` | DNS Security Engine bind address | `127.0.0.1` |
|
||||
| `ANIS_ENABLED` / `ANIS_URL` | Threat-intel hub integration | `true` / `https://anis.weboria.eu` |
|
||||
| `ANIS_ENABLED` | Threat-intel hub integration | `true` |
|
||||
|
||||
Full list with descriptions in `.env.example`.
|
||||
Full list with descriptions in `env.example`. ANIS's URL is fixed (`https://anis.weboria.eu`,
|
||||
not configurable) and its license key is dashboard-only — neither is an env var.
|
||||
|
||||
---
|
||||
|
||||
@@ -240,7 +265,7 @@ Full list with descriptions in `.env.example`.
|
||||
|
||||
ARGUS is commercial software licensed by Weboria — see [LICENSE](LICENSE). Third-party
|
||||
open-source components retain their own licenses — see
|
||||
[THIRD_PARTY_LICENSES](THIRD_PARTY_LICENSES) and [NOTICE](NOTICE).
|
||||
[THIRD_PARTY_LICENSES.md](THIRD_PARTY_LICENSES.md) and [NOTICE](NOTICE).
|
||||
|
||||
For licensing questions or support, contact the **Weboria Support Portal**.
|
||||
|
||||
|
||||
@@ -1,16 +1,26 @@
|
||||
# Third-Party Licenses
|
||||
|
||||
ARGUS Secure uses the following third-party software:
|
||||
ARGUS uses the following third-party software.
|
||||
|
||||
## Core Components
|
||||
|
||||
### TimescaleDB
|
||||
- **License**: Timescale License (TSL)
|
||||
- **Website**: https://github.com/timescale/timescaledb
|
||||
- **License URL**: https://github.com/timescale/timescaledb/blob/main/tsl/LICENSE-TIMESCALE
|
||||
- **Note**: TimescaleDB Community Edition is used for time-series data storage and compression.
|
||||
The Timescale License carries redistribution conditions beyond plain open source — reviewed
|
||||
before bundling with a commercial, proprietary product; see legal review note below.
|
||||
- **License**: Timescale License (TSL) / Apache 2.0 depending on component
|
||||
- **Website**: https://www.timescale.com/
|
||||
|
||||
ARGUS uses TimescaleDB as an embedded time-series storage component for security events,
|
||||
telemetry, and operational metrics.
|
||||
|
||||
TimescaleDB is distributed as part of the ARGUS Enterprise Appliance and is not offered as a
|
||||
standalone database service. Customers receive ARGUS as a complete security appliance;
|
||||
TimescaleDB remains subject to its original license terms.
|
||||
|
||||
### PostgreSQL
|
||||
- **License**: PostgreSQL License (permissive, BSD/MIT-style)
|
||||
- **Website**: https://www.postgresql.org/
|
||||
|
||||
TimescaleDB is distributed as a PostgreSQL extension; PostgreSQL itself is the underlying
|
||||
database engine.
|
||||
|
||||
### Nginx
|
||||
- **License**: BSD-2-Clause
|
||||
@@ -27,17 +37,46 @@ ARGUS Secure uses the following third-party software:
|
||||
- **Website**: https://coreruleset.org/
|
||||
- **Copyright**: (C) 2006-2024 Trustwave Holdings, Inc., OWASP Core Rule Set contributors
|
||||
|
||||
### MaxMind GeoIP2 / GeoLite2
|
||||
- **License**: GeoLite2 End User License Agreement
|
||||
- **Website**: https://www.maxmind.com/
|
||||
- **Attribution**: This product includes GeoLite2 data created by MaxMind, available from
|
||||
https://www.maxmind.com. Redistribution terms are stricter than plain open source — reviewed
|
||||
before bundling; see legal review note below.
|
||||
|
||||
### Valkey
|
||||
- **License**: BSD-3-Clause
|
||||
- **Website**: https://valkey.io/
|
||||
|
||||
### Alpine Linux
|
||||
- **License**: Various (base OS, mostly MIT/BSD-style per-package licenses)
|
||||
- **Website**: https://alpinelinux.org/
|
||||
|
||||
Alpine Linux is the base image for the ARGUS API, UI build, and proxy container images.
|
||||
|
||||
### BusyBox
|
||||
- **License**: GPL-2.0
|
||||
- **Website**: https://busybox.net/
|
||||
|
||||
Bundled as part of the Alpine Linux base images above.
|
||||
|
||||
### Go Runtime
|
||||
- **License**: BSD-3-Clause
|
||||
- **Website**: https://go.dev/
|
||||
|
||||
The ARGUS API is built with Go; the compiled binary statically includes the Go runtime.
|
||||
|
||||
### Node.js (build-time only)
|
||||
- **License**: MIT (Node.js core) plus per-package licenses of the npm dependencies below
|
||||
- **Website**: https://nodejs.org/
|
||||
|
||||
Used to build the ARGUS web UI; not present in the running API/proxy containers.
|
||||
|
||||
### OpenSSL / TLS libraries
|
||||
- **License**: Apache License 2.0 (OpenSSL 3.x) / various
|
||||
- **Website**: https://www.openssl.org/
|
||||
|
||||
Used by the nginx proxy image for TLS termination.
|
||||
|
||||
### curl
|
||||
- **License**: MIT/X derivate (curl license)
|
||||
- **Website**: https://curl.se/
|
||||
|
||||
Used in container healthchecks and installer scripts.
|
||||
|
||||
## Backend (Go) Dependencies
|
||||
|
||||
| Package | License | Website |
|
||||
@@ -47,7 +86,6 @@ ARGUS Secure uses the following third-party software:
|
||||
| github.com/lib/pq | MIT | https://github.com/lib/pq |
|
||||
| github.com/google/uuid | BSD-3-Clause | https://github.com/google/uuid |
|
||||
| github.com/redis/go-redis/v9 | BSD-2-Clause | https://github.com/redis/go-redis |
|
||||
| github.com/oschwald/geoip2-golang | ISC | https://github.com/oschwald/geoip2-golang |
|
||||
| github.com/cloudflare/cloudflare-go | BSD-3-Clause | https://github.com/cloudflare/cloudflare-go |
|
||||
| golang.org/x/crypto | BSD-3-Clause | https://golang.org/x/crypto |
|
||||
|
||||
@@ -96,17 +134,25 @@ limitations under the License.
|
||||
|
||||
---
|
||||
|
||||
## GeoLite2 End User License Agreement
|
||||
|
||||
This product includes GeoLite2 data created by MaxMind, available from
|
||||
https://www.maxmind.com. GeoLite2 databases are offered under the
|
||||
GeoLite2 End User License Agreement. For the full license text, see:
|
||||
https://www.maxmind.com/en/geolite2/eula
|
||||
Third-party components have been reviewed for inclusion in ARGUS Enterprise deployments.
|
||||
Each component remains subject to its original license terms.
|
||||
|
||||
---
|
||||
|
||||
## Pending legal review before commercial distribution
|
||||
# Weboria Proprietary Components
|
||||
|
||||
TimescaleDB (Community Edition, TSL) and MaxMind GeoLite2 (EULA) both carry redistribution
|
||||
conditions beyond plain MIT/BSD/Apache terms. Confirm these terms are compatible with the
|
||||
proprietary commercial license in `LICENSE` before shipping a release build.
|
||||
The following ARGUS components are proprietary software developed by Weboria:
|
||||
|
||||
- ARGUS Core Platform
|
||||
- ARGUS Management Interface
|
||||
- ARGUS Security Automation Engine
|
||||
- ARGUS API Layer
|
||||
- ARGUS Threat Analysis Components
|
||||
- ARGUS Licensing System
|
||||
- ARGUS Enterprise Features
|
||||
- Weboria Integrations
|
||||
|
||||
These components are distributed under the ARGUS Commercial License.
|
||||
|
||||
Unauthorized copying, modification, redistribution, reverse engineering, or resale is
|
||||
prohibited.
|
||||
@@ -3,11 +3,11 @@
|
||||
# ARGUS backup — dumps the database and application data (certificates,
|
||||
# uploaded config) into a single, timestamped archive.
|
||||
#
|
||||
# cd ~/argus && ./backup.sh [output-directory]
|
||||
# cd /opt/argus && ./backup.sh [output-directory]
|
||||
#
|
||||
set -euo pipefail
|
||||
|
||||
INSTALL_DIR="${ARGUS_INSTALL_DIR:-$HOME/argus}"
|
||||
INSTALL_DIR="${ARGUS_INSTALL_DIR:-/opt/argus}"
|
||||
OUT_DIR="${1:-$PWD}"
|
||||
STAMP="$(date +%Y%m%d-%H%M%S)"
|
||||
ARCHIVE="${OUT_DIR}/argus-backup-${STAMP}.tar.gz"
|
||||
@@ -24,7 +24,7 @@ bold "Backing up ARGUS..."
|
||||
WORKDIR="$(mktemp -d)"
|
||||
trap 'rm -rf "$WORKDIR"' EXIT
|
||||
|
||||
docker compose exec -T db pg_dump -U "${DB_USER:-postgres}" "${DB_NAME:-argus}" | gzip > "$WORKDIR/db.sql.gz"
|
||||
docker compose exec -T db pg_dump -U postgres argus | gzip > "$WORKDIR/db.sql.gz"
|
||||
ok "Database dumped"
|
||||
|
||||
docker run --rm -v argus_api_data:/data -v "$WORKDIR":/backup alpine \
|
||||
|
||||
+32
-14
@@ -11,14 +11,18 @@ services:
|
||||
max-file: "3"
|
||||
environment:
|
||||
TZ: ${TZ:-UTC}
|
||||
POSTGRES_USER: ${DB_USER:-postgres}
|
||||
# Internal database credentials, not customer-configurable — nothing
|
||||
# outside this compose stack ever connects to Postgres directly, so
|
||||
# there's no real reason to let these vary. Only the password (below)
|
||||
# needs to be a real secret; the username/db name are just labels.
|
||||
POSTGRES_USER: postgres
|
||||
POSTGRES_PASSWORD: ${DB_PASSWORD:-postgres}
|
||||
POSTGRES_DB: ${DB_NAME:-argus}
|
||||
POSTGRES_DB: argus
|
||||
command: postgres -c timezone=${TZ:-UTC} -c log_timezone=${TZ:-UTC} -c shared_preload_libraries=timescaledb -c timescaledb.telemetry_level=off -c max_locks_per_transaction=512
|
||||
volumes:
|
||||
- postgres_data:/var/lib/postgresql/data
|
||||
healthcheck:
|
||||
test: ["CMD-SHELL", "pg_isready -U ${DB_USER:-postgres}"]
|
||||
test: ["CMD-SHELL", "pg_isready -U postgres"]
|
||||
interval: 10s
|
||||
timeout: 5s
|
||||
retries: 10
|
||||
@@ -80,7 +84,7 @@ services:
|
||||
|
||||
# Go API Server
|
||||
api:
|
||||
image: ghcr.io/alleyviper/argus-secure-api:latest
|
||||
image: git-cloud.weboria.eu/weboria/argus-api:latest
|
||||
container_name: argus-api
|
||||
restart: unless-stopped
|
||||
# Container hardening: no-new-privileges blocks setuid privilege
|
||||
@@ -104,7 +108,14 @@ services:
|
||||
environment:
|
||||
TZ: ${TZ:-UTC}
|
||||
PORT: "8080"
|
||||
DATABASE_URL: postgres://${DB_USER:-postgres}:${DB_PASSWORD:-postgres}@db:5432/${DB_NAME:-argus}?sslmode=disable
|
||||
# DATABASE_URL is not set here — the API builds it internally from
|
||||
# DB_PASSWORD using net/url (proper percent-encoding), instead of this
|
||||
# file naively interpolating the password into a raw connection
|
||||
# string. A raw '${DB_PASSWORD}@...' interpolation breaks outright if
|
||||
# the password ever contains '@', ':', '/', or similar (confirmed
|
||||
# live: an openssl-rand-base64-generated password containing '/'
|
||||
# produced an unparseable URL and the API never became healthy).
|
||||
DB_PASSWORD: ${DB_PASSWORD:-postgres}
|
||||
REDIS_URL: redis://valkey:6379/0
|
||||
ENVIRONMENT: ${ENVIRONMENT:-production}
|
||||
NGINX_CONTAINER: argus-proxy
|
||||
@@ -118,13 +129,20 @@ services:
|
||||
NGINX_HTTPS_PORT: ${NGINX_HTTPS_PORT:-}
|
||||
API_HOST_PORT: ${API_HOST_PORT:-9080}
|
||||
API_HOST: ${API_HOST:-}
|
||||
# ANIS community intelligence — optional, off by default. Set these to
|
||||
# connect this instance to an already-running ANIS hub.
|
||||
ANIS_ENABLED: ${ANIS_ENABLED:-false}
|
||||
ANIS_URL: ${ANIS_URL:-}
|
||||
ANIS_LICENSE_KEY: ${ANIS_LICENSE_KEY:-}
|
||||
ANIS_ADMIN_KEY: ${ANIS_ADMIN_KEY:-}
|
||||
ANIS_SHARE_ATTACKERS: ${ANIS_SHARE_ATTACKERS:-false}
|
||||
# ANIS community intelligence — on by default against the public
|
||||
# Community Edition hub (community tier, no signup required). There is
|
||||
# no self-hosted-ANIS deployment model: the URL is fixed, not
|
||||
# customer-configurable. A license key upgrades the tier, but is only
|
||||
# ever set from Threat Intel -> ANIS Connection in the dashboard
|
||||
# (write-only there — never round-trips back to the client), not from
|
||||
# this file, so it's seeded empty (community tier) here.
|
||||
# (No ANIS_ADMIN_KEY or ANIS_SHARE_ATTACKERS here: both confirmed dead
|
||||
# via grep, zero references anywhere in internal/config.go or the ANIS
|
||||
# client. A prior version of this file carried ANIS_ADMIN_KEY and
|
||||
# falsely claimed ARGUS "fails closed at startup" without it.)
|
||||
ANIS_ENABLED: ${ANIS_ENABLED:-true}
|
||||
ANIS_URL: https://anis.weboria.eu
|
||||
ANIS_LICENSE_KEY: ""
|
||||
DNS_SECURITY_LISTEN_ADDR: ":53"
|
||||
ports:
|
||||
- "127.0.0.1:${API_HOST_PORT:-9080}:8080"
|
||||
@@ -154,7 +172,7 @@ services:
|
||||
|
||||
# React UI (Admin Panel), served over HTTPS
|
||||
ui:
|
||||
image: ghcr.io/alleyviper/argus-secure-ui:latest
|
||||
image: git-cloud.weboria.eu/weboria/argus-ui:latest
|
||||
container_name: argus-ui
|
||||
restart: unless-stopped
|
||||
security_opt:
|
||||
@@ -180,7 +198,7 @@ services:
|
||||
# Nginx reverse proxy — host network mode, so real client IPs are visible
|
||||
# directly without needing PROXY protocol.
|
||||
nginx:
|
||||
image: ghcr.io/alleyviper/argus-secure-nginx:latest
|
||||
image: git-cloud.weboria.eu/weboria/argus-proxy:latest
|
||||
container_name: argus-proxy
|
||||
restart: always
|
||||
network_mode: host
|
||||
|
||||
+64
@@ -0,0 +1,64 @@
|
||||
# ARGUS Enterprise Web Security Platform — Installation Configuration
|
||||
#
|
||||
# install.sh generates this file for you automatically, including a secure
|
||||
# database password. Most installs need nothing beyond the defaults below.
|
||||
#
|
||||
# Everything else — WAF policy, DNS security, threat intelligence tuning,
|
||||
# proxy hosts, users, security policies — is configured from the ARGUS
|
||||
# dashboard after your first login, not from this file.
|
||||
|
||||
# ===========================================
|
||||
# Database (do not edit)
|
||||
# ===========================================
|
||||
# install.sh replaces this with a securely generated value on first install
|
||||
# and never touches it again. There's nothing to fill in here yourself.
|
||||
DB_PASSWORD=change-me-in-production
|
||||
|
||||
# ===========================================
|
||||
# Timezone
|
||||
# ===========================================
|
||||
# Should match the timezone you select in the dashboard's first-run setup
|
||||
# wizard (Regional Settings) — the wizard checks for a mismatch and will
|
||||
# warn you if this file and your dashboard selection disagree.
|
||||
TZ=UTC
|
||||
|
||||
# ===========================================
|
||||
# Threat Intelligence (ANIS)
|
||||
# ===========================================
|
||||
# ARGUS connects to ANIS, Weboria's threat-intelligence network, by default
|
||||
# — no license key needed for the free Community tier. There is no
|
||||
# self-hosted-ANIS deployment model, so there's no URL to configure here.
|
||||
# A license key upgrades the tier, but is only ever set from
|
||||
# Threat Intel -> ANIS Connection in the dashboard — never from this file.
|
||||
ANIS_ENABLED=true
|
||||
|
||||
# ===========================================
|
||||
# Network Ports
|
||||
# ===========================================
|
||||
# Only change these if the defaults conflict with something else already
|
||||
# running on this host.
|
||||
|
||||
# Admin panel port (default: 81)
|
||||
# UI_PORT=81
|
||||
|
||||
# Reverse-proxy listen ports — change if 80/443 are already in use
|
||||
# NGINX_HTTP_PORT=8080
|
||||
# NGINX_HTTPS_PORT=8443
|
||||
|
||||
# Internal port used for nginx<->API communication.
|
||||
# MUST NOT conflict with NGINX_HTTP_PORT.
|
||||
# API_HOST_PORT=9080
|
||||
|
||||
# DNS Security Engine listen address — host-only (127.0.0.1) by default.
|
||||
# Set to an internal interface IP only if you intend to route real client
|
||||
# DNS traffic through ARGUS. Never 0.0.0.0 unless this host is on a fully
|
||||
# trusted network — an open forwarding resolver is exactly the profile
|
||||
# abused for DNS amplification attacks against third parties.
|
||||
# DNS_LISTEN_HOST=127.0.0.1
|
||||
|
||||
# ===========================================
|
||||
# Advanced / Troubleshooting
|
||||
# ===========================================
|
||||
# Only needed on some NAS platforms (e.g. Synology DSM) where Docker's API
|
||||
# version needs to be pinned manually. Leave commented out otherwise.
|
||||
# DOCKER_API_VERSION=1.41
|
||||
+2
-2
@@ -2,11 +2,11 @@
|
||||
#
|
||||
# ARGUS health check — reports the status of every component.
|
||||
#
|
||||
# cd ~/argus && ./healthcheck.sh
|
||||
# cd /opt/argus && ./healthcheck.sh
|
||||
#
|
||||
set -euo pipefail
|
||||
|
||||
INSTALL_DIR="${ARGUS_INSTALL_DIR:-$HOME/argus}"
|
||||
INSTALL_DIR="${ARGUS_INSTALL_DIR:-/opt/argus}"
|
||||
|
||||
bold() { printf '\033[1m%s\033[0m\n' "$1"; }
|
||||
ok() { printf ' \033[32m✓\033[0m %s\n' "$1"; }
|
||||
|
||||
+19
-8
@@ -11,12 +11,10 @@ set -euo pipefail
|
||||
REPO_RAW_BASE="https://git-cloud.weboria.eu/weboria/argus-installer/raw/branch/main"
|
||||
INSTALL_DIR="${ARGUS_INSTALL_DIR:-/opt/argus}"
|
||||
NETWORK_NAME="argus-network"
|
||||
# The image registry is still ghcr.io (GitHub Container Registry) today —
|
||||
# Weboria's own private registry (registry.weboria.eu) is provisioned but
|
||||
# not yet serving images. docker-compose.yml's image: lines point at ghcr.io
|
||||
# directly rather than a variable here, since that's the only registry that
|
||||
# actually has published images right now; switching to registry.weboria.eu
|
||||
# is a one-line change to those image: lines once it's live, not a rewrite.
|
||||
# Production images are pulled from Weboria's own registry, built into
|
||||
# git-cloud.weboria.eu (Gitea's container registry) — docker-compose.yml's
|
||||
# image: lines reference git-cloud.weboria.eu/weboria/argus-{api,ui,proxy}
|
||||
# directly. Anonymous docker pull works with no login required.
|
||||
|
||||
# ── Output helpers ────────────────────────────────────────────────────────────
|
||||
bold() { printf '\033[1m%s\033[0m\n' "$1"; }
|
||||
@@ -56,16 +54,29 @@ for script in update.sh uninstall.sh healthcheck.sh backup.sh restore.sh; do
|
||||
fetch "$script" "$script"
|
||||
chmod +x "$script"
|
||||
done
|
||||
# The repo stores this as env.example (no leading dot) rather than .env.example
|
||||
# -- Weboria's own WAF blocks any request path matching .env* as a standard
|
||||
# credential-harvesting-probe rule, which also caught this legitimate static
|
||||
# file when served from Gitea. Renaming sidesteps it without needing a WAF
|
||||
# exception. Saved locally as .env either way.
|
||||
if [ ! -f .env ]; then
|
||||
fetch ".env.example" ".env"
|
||||
fetch "env.example" ".env"
|
||||
ok "Fetched deployment files into $INSTALL_DIR"
|
||||
else
|
||||
ok "Fetched compose file (kept your existing .env)"
|
||||
fi
|
||||
|
||||
# ── 4. Generate secrets (first install only — never overwrite an existing .env) ──
|
||||
# hex, not base64: base64 can produce '/', '+', '=', any of which breaks the
|
||||
# raw postgres://user:PASSWORD@host connection string if it ever ends up
|
||||
# interpolated unescaped (confirmed live on the first real production
|
||||
# install — see config.go's buildDatabaseURL for the second, independent
|
||||
# defensive layer this pairs with). Hex output is always [0-9a-f], which
|
||||
# can never produce that class of bug, at 4 bits/char vs base64's ~6 —
|
||||
# 32 hex chars (128 bits) is used in place of 24 base64 chars (~144 bits)
|
||||
# to keep entropy comparable rather than matching digit-count cosmetically.
|
||||
if grep -q '^DB_PASSWORD=change-me-in-production' .env 2>/dev/null; then
|
||||
DB_PASSWORD="$(openssl rand -base64 24 | tr -d '\n')"
|
||||
DB_PASSWORD="$(openssl rand -hex 32)"
|
||||
sed -i.bak "s#^DB_PASSWORD=.*#DB_PASSWORD=${DB_PASSWORD}#" .env && rm -f .env.bak
|
||||
ok "Generated a secure database password"
|
||||
fi
|
||||
|
||||
+3
-3
@@ -5,11 +5,11 @@
|
||||
# that already has data on it, uninstall.sh --remove-data && install.sh
|
||||
# first, then run this.
|
||||
#
|
||||
# cd ~/argus && ./restore.sh argus-backup-20260719-120000.tar.gz
|
||||
# cd /opt/argus && ./restore.sh argus-backup-20260719-120000.tar.gz
|
||||
#
|
||||
set -euo pipefail
|
||||
|
||||
INSTALL_DIR="${ARGUS_INSTALL_DIR:-$HOME/argus}"
|
||||
INSTALL_DIR="${ARGUS_INSTALL_DIR:-/opt/argus}"
|
||||
ARCHIVE="${1:-}"
|
||||
|
||||
bold() { printf '\033[1m%s\033[0m\n' "$1"; }
|
||||
@@ -38,7 +38,7 @@ bold "Stopping the API (keeping the database up)..."
|
||||
docker compose stop api ui nginx >/dev/null
|
||||
|
||||
bold "Restoring database..."
|
||||
gunzip -c "$WORKDIR/db.sql.gz" | docker compose exec -T db psql -U "${DB_USER:-postgres}" "${DB_NAME:-argus}" >/dev/null
|
||||
gunzip -c "$WORKDIR/db.sql.gz" | docker compose exec -T db psql -U postgres argus >/dev/null
|
||||
ok "Database restored"
|
||||
|
||||
bold "Restoring application data..."
|
||||
|
||||
+2
-2
@@ -6,13 +6,13 @@
|
||||
# it only stops and removes containers, so a plain re-install (install.sh)
|
||||
# picks up right where you left off.
|
||||
#
|
||||
# cd ~/argus && ./uninstall.sh # containers only, data kept
|
||||
# cd /opt/argus && ./uninstall.sh # containers only, data kept
|
||||
# ./uninstall.sh --remove-data # also destroys all data (asks to confirm)
|
||||
# ./uninstall.sh --remove-data --yes # non-interactive, for scripted use
|
||||
#
|
||||
set -euo pipefail
|
||||
|
||||
INSTALL_DIR="${ARGUS_INSTALL_DIR:-$HOME/argus}"
|
||||
INSTALL_DIR="${ARGUS_INSTALL_DIR:-/opt/argus}"
|
||||
REMOVE_DATA=false
|
||||
ASSUME_YES=false
|
||||
|
||||
|
||||
Reference in New Issue
Block a user