Conversation
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 04f53c3de3
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| healthcheck: | ||
| test: ["CMD", "mc", "ready", "local"] |
There was a problem hiding this comment.
Use a health check available in the MinIO image
The minio/minio server image does not include the separate mc client binary, so this healthcheck repeatedly exits with mc: not found and MinIO is never marked healthy. Because the opencti service explicitly waits on minio with condition: service_healthy (lines 115–116), a fresh deployment following this template never starts OpenCTI, its worker, or the Shodan profile.
Useful? React with 👍 / 👎.
|
Phase 1 ownership review found this PR is not correctly scoped for cybersecurity-playbook: every changed artifact is OpenCTI/Shodan deployment configuration, operational documentation, or Mayuri lab validation evidence. Per the ecosystem boundary, reusable detection content belongs here, while Mayuri deployment/current-state evidence belongs in mayuri-purple-team-lab. The branch is preserved for re-homing; no fresh live validation is claimed. Closing rather than merging cross-repository operational state. |
1|## Summary
2|- add a pinned, credential-free OpenCTI Community Compose template
3|- add the official Shodan internal-enrichment connector as an opt-in profile
4|- document deployment, hardening, backup, and upgrade gates
5|- record sanitized live enrichment and reboot-persistence validation from the authorized Mayuri lab
6|
7|## Live validation
8|- OpenCTI and dependencies were healthy on the designated CTI host
9|- only the application interface was published to the approved lab segment; backend services remained private to the container network
10|- the Shodan connector registered active for
ipv4-addrandindicator11|- one benign public IPv4 observable completed enrichment with zero connector errors
12|- platform, connector, and observable persisted across guest reboot
13|- a clean post-validation rollback snapshot was created
14|- runtime secrets remained root-only and absent from the repository
15|
16|Exact hostnames, addresses, VM identifiers, snapshot names, credentials, and live environment values are intentionally omitted.
17|
18|## Checks
19|-
docker compose --profile shodan config --quiet20|-
python3 automation/validators/check_markdown.py21|-
python3 playbook validate22|-
git diff --check23|- public-detail scan over PR files: no Mayuri internal address, CTI hostname, VM identifier, or named snapshot remains
24|
25|## Limitations
26|- this proves the historical authorized-lab enrichment path, not production readiness
27|- CTI remains advisory and analyst-triggered
28|- application-consistent backup/restore testing remains open work
29|