# ARGUS Enterprise Web Security Platform — Installation Configuration # # install.sh generates this file for you automatically, including a secure # database password. Most installs need nothing beyond the defaults below. # # Everything else — WAF policy, DNS security, threat intelligence tuning, # proxy hosts, users, security policies — is configured from the ARGUS # dashboard after your first login, not from this file. # =========================================== # Database (do not edit) # =========================================== # install.sh replaces this with a securely generated value on first install # and never touches it again. There's nothing to fill in here yourself. DB_PASSWORD=change-me-in-production # =========================================== # Timezone # =========================================== # Should match the timezone you select in the dashboard's first-run setup # wizard (Regional Settings) — the wizard checks for a mismatch and will # warn you if this file and your dashboard selection disagree. TZ=UTC # =========================================== # Threat Intelligence (ANIS) # =========================================== # ARGUS connects to ANIS, Weboria's threat-intelligence network, by default # — no license key needed for the free Community tier. These three values # only matter on first boot; manage the connection afterward from # Threat Intel -> ANIS Connection in the dashboard. ANIS_ENABLED=true ANIS_URL=https://anis.weboria.eu ANIS_LICENSE_KEY= # Share this instance's confirmed attacker IPs back to the community feed? ANIS_SHARE_ATTACKERS=false # =========================================== # Network Ports # =========================================== # Only change these if the defaults conflict with something else already # running on this host. # Admin panel port (default: 81) # UI_PORT=81 # Reverse-proxy listen ports — change if 80/443 are already in use # NGINX_HTTP_PORT=8080 # NGINX_HTTPS_PORT=8443 # Internal port used for nginx<->API communication. # MUST NOT conflict with NGINX_HTTP_PORT. # API_HOST_PORT=9080 # DNS Security Engine listen address — host-only (127.0.0.1) by default. # Set to an internal interface IP only if you intend to route real client # DNS traffic through ARGUS. Never 0.0.0.0 unless this host is on a fully # trusted network — an open forwarding resolver is exactly the profile # abused for DNS amplification attacks against third parties. # DNS_LISTEN_HOST=127.0.0.1 # =========================================== # Advanced / Troubleshooting # =========================================== # Only needed on some NAS platforms (e.g. Synology DSM) where Docker's API # version needs to be pinned manually. Leave commented out otherwise. # DOCKER_API_VERSION=1.41