.env.example covers every env var the canary stack reads: - Public: APP_NAME, NGINX_HOST_PORT, PUBLIC_BASE_URL, VITE_APP_TITLE, VITE_API_URL - Anti-bot: TURNSTILE_SITE_KEY/SECRET + VITE_TURNSTILE_SITE_KEY (frontend mirror) - Operator: OPERATOR_TOKEN (admin endpoints) - DB: POSTGRES_PASSWORD + POSTGRES_DEV_PORT - Cache: REDIS_DEV_PORT - GeoIP: MAXMIND_ACCOUNT_ID/LICENSE_KEY (optional) - Webhooks: WEBHOOK_HMAC_SECRET (optional) - Fake MySQL: MYSQL_FAKE_ENABLED + MYSQL_HOST_PORT (optional, off by default) - Logging: LOG_LEVEL, LOG_FORMAT - Telemetry: OTEL_ENABLED, OTEL_EXPORTER_OTLP_ENDPOINT + Jaeger ports - Tunnel: CLOUDFLARE_TUNNEL_TOKEN (for cloudflared.compose.yml) scripts/init.sh rewritten as idempotent setup helper: - Copies .env.example -> .env on first run - Generates POSTGRES_PASSWORD + OPERATOR_TOKEN via openssl rand -hex 32 if blank - Skips already-set values (idempotent) - Conditionally fetches GeoLite2-City.mmdb when MAXMIND creds present - All sed usage is operator-side (script run-time), not Claude tool-time scripts/randomize-ports.sh kept as-is (operator helper for spinning up sibling projects on non-conflicting ports). |
||
|---|---|---|
| .. | ||
| base64-tool | ||
| c2-beacon | ||
| caesar-cipher | ||
| canary-token-generator | ||
| dns-lookup | ||
| firewall-rule-engine | ||
| hash-cracker | ||
| keylogger | ||
| linux-cis-hardening-auditor | ||
| linux-ebpf-security-tracer | ||
| metadata-scrubber-tool | ||
| network-traffic-analyzer | ||
| simple-port-scanner | ||
| simple-vulnerability-scanner | ||
| systemd-persistence-scanner | ||