# ARGUS Enterprise Web Security Platform
### A real-time security operations platform for the modern web edge
[](LICENSE)
[]()
[](https://nginx.org/)
[](https://modsecurity.org/)
[](https://coreruleset.org/)
[]()
ARGUS combines a reverse proxy, Web Application Firewall, bot and AI-crawler defense,
DNS security engine, threat intelligence integration, GeoIP and cloud-provider access control,
automated SSL, rate limiting and auto-ban, real-time attack visualization, incident
investigation, load balancing, TCP/UDP stream proxying, enterprise user management, and a full
REST API — one complete web security appliance for protecting modern applications.
✨ Features •
🚀 Installation •
🛠 Operations •
📄 Licensing & Support
---
> **This is the public ARGUS installer repository.** It contains no proprietary source
> code — only installation scripts, configuration templates, and public documentation.
> Application source is developed privately by Weboria and distributed exclusively as
> published container images. You do not need, and will not be given, access to the source
> to install, run, or operate ARGUS.
>
> **Known gap, not yet built:** production images are currently distributed from GitHub
> Container Registry while Weboria's own private registry (`registry.weboria.eu`) is
> provisioned. License-key validation during install is not yet implemented — that needs a
> licensing service design before `install.sh` can enforce it. Both are tracked, not silently
> assumed to already work.
## ✨ Key Features
### 🛡️ Web Application Firewall
ModSecurity v3 with the OWASP Core Rule Set. Paranoia levels 1–4, per-host rule exceptions,
detection-only or blocking modes.
### 🌐 Attack Origin Visualization
A live global map of inbound attacks — real-time arcs from source to your infrastructure,
severity-coded, with instant drill-down into any event's full detail.
### 🔎 Incident Investigation
Pivot from any IP, log line, or dashboard event straight into that entity's complete history —
affected hosts, triggered rules, geography, and live threat-intelligence reputation — without
losing your place.
### 🤖 Bot & AI-Crawler Defense
Blocks known-bad bots and AI scrapers automatically, with a search-engine allowlist so legitimate
crawlers are never affected. Escalating challenge modes (browser check, proof-of-work, visual
CAPTCHA) for suspicious traffic.
### 🧬 DNS Security Engine
An embedded forwarding DNS resolver with real-time threat detection — DGA domains, DNS
tunneling, fast-flux infrastructure, cache-poisoning attempts — and automatic mitigation via
sinkholing.
### 🌍 GeoIP & Cloud-Provider Access Control
Allow or block traffic by country or hosting provider, with live visual feedback.
### 🔒 Automated SSL
Let's Encrypt with automatic renewal, including wildcard certificates via DNS-01 challenge
(Cloudflare, DuckDNS, Dynu, and more).
### ⚡ Rate Limiting & Auto-Ban
Configurable per-IP/per-URI rate limits, automatic banning on repeated WAF violations, and
optional community threat-intelligence-driven blocking via ANIS (enabled by default, no
license key required for the free Community tier).
### 👥 Full User Management
Role-based access, per-user session control, forced password resets, account lock/unlock, MFA,
and a complete login history — everything a security team needs to administer access safely.
### 📊 Real-Time Operations Dashboard
Live traffic, security events, and system health, updated continuously — no manual refresh.
### 🔀 Load Balancing & Stream Proxying
Multiple backend servers with health checks, plus TCP/UDP stream proxying with optional SNI
routing.
### 🔮 Modern Protocol Support
HTTP/3 (QUIC) and post-quantum-ready TLS (ML-KEM hybrid key exchange).
---
## 🚀 Installation
### Requirements
- A Linux host with Docker Engine 24.0+ and the Docker Compose plugin (`docker compose`)
- 2 vCPU / 4 GB RAM minimum for evaluation; see production sizing guidance in `docs/` for
real traffic volumes
- Ports 80/443 available for the reverse proxy, and 81 for the admin panel (all configurable)
### One-line install
```bash
curl -fsSL https://git-cloud.weboria.eu/weboria/argus-installer/raw/branch/main/install.sh | bash
```
This downloads the deployment files, generates secure database/application secrets, creates the
required Docker network, pulls the production images, starts ARGUS, and prints your admin
login at the end. Installs to `/opt/argus` by default — set `ARGUS_INSTALL_DIR` first to change
that.
### Manual install
If you'd rather see every step:
```bash
mkdir -p /opt/argus/docker-socket-proxy && cd /opt/argus
curl -fsSL https://git-cloud.weboria.eu/weboria/argus-installer/raw/branch/main/docker-compose.yml -o docker-compose.yml
curl -fsSL https://git-cloud.weboria.eu/weboria/argus-installer/raw/branch/main/.env.example -o .env
curl -fsSL https://git-cloud.weboria.eu/weboria/argus-installer/raw/branch/main/docker-socket-proxy/haproxy.cfg.template -o docker-socket-proxy/haproxy.cfg.template
# Generate a secure database password
sed -i "s/DB_PASSWORD=.*/DB_PASSWORD=$(openssl rand -base64 24)/" .env
# ARGUS expects this network to already exist
docker network create argus-network
docker compose pull
docker compose up -d
```
Then log in at `https://