Repository navigation
Expand file tree
/
Copy pathcompose.yaml
More file actions
349 lines (305 loc) · 19.7 KB
/
Copy pathcompose.yaml
File metadata and controls
349 lines (305 loc) · 19.7 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
# ╔══════════════════════════════════════════════════════════════════════════════╗
# ║ ShieldPM — Docker Compose (Full Configuration) ║
# ║ ║
# ║ Quick Start: ║
# ║ 1. Set your timezone (TZ) below ║
# ║ 2. Uncomment features you need (remove the leading '#') ║
# ║ 3. docker compose up -d ║
# ║ ║
# ║ For a simpler setup, see compose.easy.yaml ║
# ╚══════════════════════════════════════════════════════════════════════════════╝
services:
# ┌──────────────────────────────────────────────────────────────────────────┐
# │ SHIELDPM — Main Application │
# └──────────────────────────────────────────────────────────────────────────┘
shieldpm:
image: ghcr.io/shedowe19/shieldpm:develop
container_name: shieldpm
restart: always
network_mode: host
volumes:
- "/opt/shieldpm:/data"
# - "/var/www:/var/www" # Mount for custom HTML/PHP sites
# - "shm-volume:/dev/shm/check-point" # Required for OpenAppSec (enable volume below + ipc: host)
environment:
# ── System ─────────────────────────────────────────────────────────────
- "TZ=Europe/Berlin" # REQUIRED — https://en.wikipedia.org/wiki/List_of_tz_database_time_zones
# - "PUID=0" # User ID (≥99 or 0), default: 0
# - "PGID=0" # Group ID (≥99 or 0), default: 0
# - "CSRF_SECRET=your-secure-random-secret" # Min 32 chars. Generate: openssl rand -hex 32
# ── Ports & Network ────────────────────────────────────────────────────
# - "NPM_PORT=81" # UI port, default: 81
# - "GOA_PORT=91" # GoAccess port, default: 91
# - "HTTP_PORT=80" # HTTP port, default: 80
# - "HTTPS_PORT=443" # HTTPS port (TCP+UDP), default: 443
# - "HTTP3_ALT_SVC_PORT=443" # Alt-Svc port for HTTP/3, default: 443
# - "DISABLE_HTTP=false" # Stop listening on port 80
# - "DISABLE_H3_QUIC=false" # Fully disable HTTP/3 + QUIC
# - "LISTEN_PROXY_PROTOCOL=false" # Use PROXY protocol (disables H3)
# ── Bind Addresses ─────────────────────────────────────────────────────
# - "IPV4_BINDING=127.0.0.1" # IPv4 bind for all hosts
# - "NPM_IPV4_BINDING=127.0.0.1" # IPv4 bind for UI only
# - "GOA_IPV4_BINDING=127.0.0.1" # IPv4 bind for GoAccess only
# - "IPV6_BINDING=[::1]" # IPv6 bind for all hosts
# - "NPM_IPV6_BINDING=[::1]" # IPv6 bind for UI only
# - "GOA_IPV6_BINDING=[::1]" # IPv6 bind for GoAccess only
# - "DISABLE_IPV6=true" # Fully disable IPv6
# - "NPM_LISTEN_LOCALHOST=true" # Bind UI to localhost only
# - "GOA_LISTEN_LOCALHOST=true" # Bind GoAccess to localhost only
# ── Database (SQLite by default) ───────────────────────────────────────
#
# MySQL / MariaDB:
# - "DB_MYSQL_HOST=127.0.0.1"
# - "DB_MYSQL_PORT=3306"
# - "DB_MYSQL_USER=npm"
# - "DB_MYSQL_PASSWORD=npm"
# - "DB_MYSQL_NAME=npm"
# - "DB_MYSQL_SSL=false"
# - "DB_MYSQL_SSL_REJECT_UNAUTHORIZED=true"
# - "DB_MYSQL_SSL_VERIFY_IDENTITY=true"
#
# PostgreSQL:
# - "DB_POSTGRES_HOST=127.0.0.1"
# - "DB_POSTGRES_PORT=5432"
# - "DB_POSTGRES_USER=npm"
# - "DB_POSTGRES_PASSWORD=npm"
# - "DB_POSTGRES_NAME=npm"
# ── SSL & ACME ────────────────────────────────────────────────────────
# - "ACME_EMAIL=your-email" # Recommended (required for ZeroSSL/Google)
# - "ACME_SERVER=https://acme-v02.api.letsencrypt.org/directory"
# - "ACME_EAB_KID=123456789abcdef" # External Account Binding key
# - "ACME_EAB_HMAC_KEY=123456789abcdef" # External Account Binding HMAC
# - "ACME_MUST_STAPLE=true" # Enable must-staple extension
# - "ACME_OCSP_STAPLING=true" # Enable OCSP stapling
# - "ACME_PROFILE=shortlived" # ACME profile, default: none
# - "ACME_KEY_TYPE=rsa" # Key type: ecdsa (default) or rsa
# - "ACME_SERVER_TLS_VERIFY=false" # Verify ACME server TLS cert
# - "DEFAULT_CERT_ID=1" # Use cert ID instead of dummy certs
# - "CUSTOM_OCSP_STAPLING=true" # OCSP stapling for custom certs
# - "CRT=72" # Hours between cert renewal checks, default: 23
# ── Logging & Analytics ────────────────────────────────────────────────
# - "LOGROTATE=true" # Enable access logs + daily rotation
# - "LOGROTATIONS=7" # Keep N rotated logs, default: 3
# - "NGINX_LOG_NOT_FOUND=true" # Log 404s to docker logs
# - "GOA=true" # Enable GoAccess (implies LOGROTATE=true)
# - "GOACLA=--agent-list --real-os --double-decode --anonymize-ip --anonymize-level=2 --keep-last=7 --with-output-resolver --no-query-string"
# ── PHP ────────────────────────────────────────────────────────────────
# - "PHP82=true"
# - "PHP82_APKS=php8.2-curl php8.2-openssl"
# - "PHP83=true"
# - "PHP83_APKS=php8.3-curl php8.3-openssl"
# - "PHP84=true"
# - "PHP84_APKS=php8.4-curl php8.4-openssl"
# ── Advanced Nginx ─────────────────────────────────────────────────────
# - "NGINX_QUIC_BPF=true" # Requires cap_add: BPF, PERFMON, NET_ADMIN
# - "NGINX_DISABLE_PROXY_BUFFERING=true" # Disable proxy buffering globally
# - "NGINX_404_REDIRECT=true" # Redirect 404 → /
# - "NGINX_HSTS_SUBDOMAINS=false" # HSTS for subdomains, default: true
# - "X_FRAME_OPTIONS=deny" # deny | sameorigin | none
# - "NGINX_WORKER_PROCESSES=8" # default: auto
# - "NGINX_WORKER_CONNECTIONS=1024" # default: 512
# - "DISABLE_NGINX_BEAUTIFIER=true" # Skip config beautification
# - "FULLCLEAN=true" # Remove unused config folders
# - "SKIP_IP_RANGES=false" # Skip Cloudflare IP range fetch, default: true
# - "IPRT=3" # Hours between IP range updates, default: 1
# ── GeoIP Databases ───────────────────────────────────────────────────
# - "GEOIP_AUTO_UPDATE=false" # Default: true; disable for offline/custom database updates
# ── Nginx Modules ─────────────────────────────────────────────────────
# - "NGINX_LOAD_OPENAPPSEC_ATTACHMENT_MODULE=true" # OpenAppSec WAF (requires ipc: host + shm-volume)
# - "NGINX_LOAD_GEOIP2_MODULE=true" # GeoIP2 module
# - "NGINX_LOAD_NJS_MODULE=true" # njs (JavaScript) module
# - "NGINX_LOAD_NTLM_MODULE=true" # NTLM auth module
# - "NGINX_LOAD_VHOST_TRAFFIC_STATUS_MODULE=true" # VHost traffic stats
# ── Docker Discovery ───────────────────────────────────────────────────
# - "DOCKER_HOSTS=tcp://10.10.10.1:2375,tcp://10.10.10.2:2375" # Additional remote Docker hosts
# ── Initialization (first start only) ──────────────────────────────────
# - "INITIAL_ADMIN_EMAIL=<initial@email.tld>"
# - "INITIAL_ADMIN_PASSWORD=<initial-password>"
# - "INITIAL_DEFAULT_PAGE=444"
# - "ENABLE_PRERUN=true"
# ── Tor Onion Services ─────────────────────────────────────────────────
# - "TOR_ENABLED=true" # default: true
# ── WireGuard Tunnel ───────────────────────────────────────────────────
# Settings (endpoint, subnet, port) are configured in the ShieldPM UI.
# To enable, uncomment cap_add and devices below, and configure host routing.
# ── Capabilities ───────────────────────────────────────────────────────
# Uncomment for QUIC BPF and/or WireGuard Tunnels:
# cap_add:
# - BPF # QUIC BPF
# - PERFMON # QUIC BPF
# - NET_ADMIN # WireGuard + QUIC BPF
# - NET_RAW # WireGuard
# ── Kernel Parameters ──────────────────────────────────────────────────
# With network_mode: host, Docker does not allow network sysctls here.
# Configure WireGuard routing on the Docker host instead:
# sudo sysctl -w net.ipv4.ip_forward=1
# sudo sysctl -w net.ipv4.conf.all.src_valid_mark=1
# Persist those values in the host's /etc/sysctl.d/ configuration as needed.
# ── Devices ────────────────────────────────────────────────────────────
# Uncomment for WireGuard TUN interface:
# devices:
# - /dev/net/tun:/dev/net/tun
# ── DNS Override ───────────────────────────────────────────────────────
# dns:
# - 1.1.1.1
# - 1.0.0.1
# ── IPC ────────────────────────────────────────────────────────────────
# ipc: host # Required for OpenAppSec
# ┌──────────────────────────────────────────────────────────────────────────┐
# │ OPTIONAL SERVICES — Uncomment entire blocks to enable │
# └──────────────────────────────────────────────────────────────────────────┘
# ── CrowdSec (IPS) ──────────────────────────────────────────────────────
# crowdsec:
# container_name: crowdsec
# image: docker.io/crowdsecurity/crowdsec:latest
# restart: always
# network_mode: bridge
# ports:
# - "127.0.0.1:7422:7422"
# - "127.0.0.1:8080:8080"
# environment:
# - "TZ=Europe/Berlin"
# - "USE_WAL=true"
# - "COLLECTIONS=crowdsecurity/nginx crowdsecurity/base-http-scenarios crowdsecurity/http-cve crowdsecurity/modsecurity crowdsecurity/appsec-virtual-patching crowdsecurity/appsec-generic-rules"
# volumes:
# - "/opt/crowdsec/conf:/etc/crowdsec"
# - "/opt/crowdsec/data:/var/lib/crowdsec/data"
# - "/opt/shieldpm/nginx:/opt/shieldpm/nginx:ro"
# - "/opt/shieldpm/crowdsec/parser.yaml:/etc/crowdsec/parsers/s01-parse/shieldpm-logs.yaml:ro"
# - "/opt/shieldpm/crowdsec/collection.yaml:/etc/crowdsec/collections/shieldpm.yaml:ro"
# - "/opt/shieldpm/crowdsec/shieldpm-acquis.yaml:/etc/crowdsec/acquis.d/shieldpm.yaml:ro"
# - "/opt/openappsec/logs:/opt/openappsec/logs:ro" # Only if using openappsec-agent
# ── MySQL ───────────────────────────────────────────────────────────────
# db:
# container_name: shieldpm-db
# image: mysql:8 # or mariadb:10
# restart: always
# network_mode: bridge
# environment:
# - "MYSQL_ROOT_PASSWORD=npm"
# - "MYSQL_DATABASE=npm"
# - "MYSQL_USER=npm"
# - "MYSQL_PASSWORD=npm"
# ports:
# - "3306:3306"
# volumes:
# - "db_data:/var/lib/mysql"
# ── PostgreSQL ──────────────────────────────────────────────────────────
# db:
# container_name: shieldpm-db
# image: postgres:17-bookworm
# restart: always
# network_mode: bridge
# environment:
# - "POSTGRES_DB=npm"
# - "POSTGRES_USER=npm"
# - "POSTGRES_PASSWORD=npm"
# ports:
# - "5432:5432"
# volumes:
# - "/opt/shieldpm/postgres:/var/lib/postgresql/data"
# ── Optional MaxMind Update (shared Analytics/firewall databases) ───────
# Custom alternative: set GEOIP_AUTO_UPDATE=false on ShieldPM first.
# geoipupdate:
# container_name: shieldpm-geoipupdate
# image: ghcr.io/maxmind/geoipupdate:latest
# restart: always
# network_mode: bridge
# environment:
# - "TZ=Europe/Berlin"
# - "GEOIPUPDATE_EDITION_IDS=GeoLite2-Country GeoLite2-City GeoLite2-ASN"
# - "GEOIPUPDATE_ACCOUNT_ID=<your-account-id>"
# - "GEOIPUPDATE_LICENSE_KEY=<your-license-key>"
# - "GEOIPUPDATE_FREQUENCY=24"
# volumes:
# - "/opt/shieldpm/nginx:/usr/share/GeoIP"
# ── Caddy (HTTP→HTTPS Redirector) ───────────────────────────────────────
# shieldpm-caddy:
# container_name: shieldpm-caddy
# image: ghcr.io/shedowe19/shieldpm:caddy
# restart: always
# network_mode: bridge
# ports:
# - "80:80"
# environment:
# - "TZ=Europe/Berlin"
# ┌──────────────────────────────────────────────────────────────────────────┐
# │ OPENAPPSEC (Advanced AI WAF) │
# │ Requirements: Uncomment 'ipc: host' and 'shm-volume' in shieldpm above │
# └──────────────────────────────────────────────────────────────────────────┘
# openappsec-agent:
# container_name: openappsec-agent
# image: ghcr.io/openappsec/agent:latest
# restart: always
# ipc: host
# volumes:
# - "shm-volume:/dev/shm/check-point"
# - "/opt/openappsec/conf:/etc/cp/conf"
# - "/opt/openappsec/data:/etc/cp/data"
# - "/opt/openappsec/logs:/var/log/nano_agent"
# - "/opt/openappsec/localconf:/ext/appsec"
# - "/opt/openappsec:/advanced-model"
# environment:
# - "TZ=Europe/Berlin"
# - "autoPolicyLoad=true"
# - "registered_server=ShieldPM"
# - "user_email=your-email"
# - "AGENT_TOKEN="
# - "SHARED_STORAGE_HOST=openappsec-shared-storage"
# - "LEARNING_HOST=openappsec-smartsync"
# - "TUNING_HOST=openappsec-tuning-svc"
# command: /cp-nano-agent
# openappsec-smartsync:
# container_name: openappsec-smartsync
# image: ghcr.io/openappsec/smartsync:latest
# restart: always
# environment:
# - "TZ=Europe/Berlin"
# - "SHARED_STORAGE_HOST=openappsec-shared-storage"
# depends_on:
# - openappsec-shared-storage
# openappsec-shared-storage:
# container_name: openappsec-shared-storage
# image: ghcr.io/openappsec/smartsync-shared-files:latest
# restart: always
# ipc: service:openappsec-agent
# user: root
# environment:
# - "TZ=Europe/Berlin"
# volumes:
# - "/opt/openappsec/storage:/db"
# openappsec-tuning-svc:
# container_name: openappsec-tuning-svc
# image: ghcr.io/openappsec/smartsync-tuning:latest
# restart: always
# environment:
# - "TZ=Europe/Berlin"
# - "SHARED_STORAGE_HOST=openappsec-shared-storage"
# - "QUERY_DB_HOST=openappsec-db"
# - "QUERY_DB_PASSWORD=password"
# - "QUERY_DB_USER=appsec"
# volumes:
# - "/opt/openappsec/conf:/etc/cp/conf"
# depends_on:
# - openappsec-shared-storage
# - openappsec-db
# openappsec-db:
# container_name: openappsec-db
# image: postgres:17-bookworm
# restart: always
# environment:
# - "TZ=Europe/Berlin"
# - "POSTGRES_PASSWORD=password"
# - "POSTGRES_USER=appsec"
# volumes:
# - "/opt/openappsec/pgdb:/var/lib/postgresql/data"
# ┌──────────────────────────────────────────────────────────────────────────────┐
# │ VOLUMES │
# └──────────────────────────────────────────────────────────────────────────────┘
# volumes:
# db_data:
# shm-volume:
# driver: local
# driver_opts:
# type: tmpfs
# device: tmpfs