-
Notifications
You must be signed in to change notification settings - Fork 4
Expand file tree
/
Copy pathdocker-compose.yml
More file actions
342 lines (315 loc) · 9.24 KB
/
docker-compose.yml
File metadata and controls
342 lines (315 loc) · 9.24 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
# driver_analyzer production stack
# NOTE: AutoPiff services build from ../AutoPiff.
# When adding new AutoPiff stages, also add them to ../AutoPiff/docker-compose.yml.
version: '3'
services:
# --- MWDB Core Components ---
mwdb-postgres:
restart: unless-stopped
image: postgres:14-alpine
environment:
- POSTGRES_DB=mwdb
- POSTGRES_USER=mwdb
- POSTGRES_PASSWORD=${POSTGRES_PASSWORD:-mwdb-password}
volumes:
- mwdb-postgres-data:/var/lib/postgresql/data
mwdb-redis:
restart: unless-stopped
image: redis:6-alpine
mwdb-core:
restart: unless-stopped
image: certpl/mwdb:latest
ports:
- "8080:8080"
environment:
- MWDB_POSTGRES_URI=postgresql://mwdb:${POSTGRES_PASSWORD:-mwdb-password}@mwdb-postgres:5432/mwdb
- MWDB_REDIS_URI=redis://mwdb-redis:6379/0
- MWDB_SECRET_KEY=${MWDB_SECRET_KEY:-dev-secret-key-change-me}
- MWDB_ENABLE_KARTON=1
- MWDB_ADMIN_LOGIN=${MWDB_ADMIN_LOGIN:-admin}
- MWDB_ADMIN_PASSWORD=${MWDB_ADMIN_PASSWORD:-admin}
depends_on:
- mwdb-postgres
- mwdb-redis
- karton-redis
- karton-system
- minio
volumes:
- mwdb-uploads-data:/app/uploads
- ./karton.ini:/etc/karton/karton.ini:ro
mwdb-web:
restart: unless-stopped
image: certpl/mwdb-web:v2.16.1
ports:
- "8082:80"
environment:
- PROXY_BACKEND_URL=http://mwdb-core:8080
# volumes:
# - ./mwdb-ui:/usr/share/nginx/html
depends_on:
- mwdb-core
karton-driver-dashboard:
build: services/dashboard
container_name: driver_analyzer_dashboard
restart: on-failure
ports:
- "8088:5000"
environment:
- MWDB_API_URL=http://mwdb-core:8080/api/
- MWDB_API_KEY=${MWDB_API_KEY}
# networks:
# - karton-network
depends_on:
- mwdb-core
# --- Karton Core Components ---
karton-redis:
restart: unless-stopped
image: redis:6-alpine
karton-rabbitmq:
restart: unless-stopped
image: rabbitmq:3.8-management-alpine
ports:
- "5672:5672"
- "15672:15672"
environment:
- RABBITMQ_DEFAULT_USER=${RABBITMQ_USER:-karton}
- RABBITMQ_DEFAULT_PASS=${RABBITMQ_PASSWORD:-karton-password}
karton-system:
restart: unless-stopped
image: certpl/karton-system:latest
environment:
- KARTON_RABBITMQ_HOST=karton-rabbitmq
- KARTON_RABBITMQ_USER=${RABBITMQ_USER:-karton}
- KARTON_RABBITMQ_PASSWORD=${RABBITMQ_PASSWORD:-karton-password}
- KARTON_S3_ACCESS_KEY=${MINIO_ROOT_USER:-minio}
- KARTON_S3_SECRET_KEY=${MINIO_ROOT_PASSWORD:-minio-password}
- KARTON_S3_ADDRESS=http://minio:9000
- KARTON_S3_BUCKET=karton
- KARTON_REDIS_HOST=karton-redis
depends_on:
- karton-redis
- karton-rabbitmq
- minio
minio:
restart: unless-stopped
image: minio/minio:RELEASE.2023-09-30T07-02-29Z
command: server /data
ports:
- "9000:9000"
environment:
- MINIO_ROOT_USER=${MINIO_ROOT_USER:-minio}
- MINIO_ROOT_PASSWORD=${MINIO_ROOT_PASSWORD:-minio-password}
volumes:
- minio-data:/data
karton-dashboard:
restart: unless-stopped
image: certpl/karton-dashboard:latest
ports:
- "8081:5000"
environment:
- KARTON_RABBITMQ_HOST=karton-rabbitmq
- KARTON_RABBITMQ_USER=${RABBITMQ_USER:-karton}
- KARTON_RABBITMQ_PASSWORD=${RABBITMQ_PASSWORD:-karton-password}
- KARTON_S3_ACCESS_KEY=${MINIO_ROOT_USER:-minio}
- KARTON_S3_SECRET_KEY=${MINIO_ROOT_PASSWORD:-minio-password}
- PYTHONUNBUFFERED=1
- KARTON_S3_ADDRESS=http://minio:9000
- KARTON_S3_BUCKET=karton
- KARTON_REDIS_HOST=karton-redis
depends_on:
- karton-system
- minio
- karton-redis
# --- Integrations ---
mwdb-reporter:
restart: unless-stopped
image: certpl/karton-mwdb-reporter:latest
environment: &custom_karton_env
KARTON_RABBITMQ_HOST: karton-rabbitmq
KARTON_RABBITMQ_USER: ${RABBITMQ_USER:-karton}
KARTON_RABBITMQ_PASSWORD: ${RABBITMQ_PASSWORD:-karton-password}
KARTON_S3_ACCESS_KEY: ${MINIO_ROOT_USER:-minio}
KARTON_S3_SECRET_KEY: ${MINIO_ROOT_PASSWORD:-minio-password}
PYTHONUNBUFFERED: "1"
KARTON_S3_ADDRESS: http://minio:9000
KARTON_S3_BUCKET: karton
KARTON_S3_SECURE: "0"
KARTON_REDIS_HOST: karton-redis
# mwdb-reporter expects [mwdb] section via KARTON_MWDB_...
KARTON_MWDB_API_URL: http://mwdb-core:8080/api/
# KARTON_MWDB_API_KEY should be set in environment or .env file
KARTON_MWDB_API_KEY: ${MWDB_API_KEY:-CHANGE_ME_TO_YOUR_MWDB_API_KEY}
# My custom services expect plain env vars
MWDB_API_URL: http://mwdb-core:8080/api/
MWDB_API_KEY: ${MWDB_API_KEY:-CHANGE_ME_TO_YOUR_MWDB_API_KEY}
depends_on:
- karton-system
- minio
- mwdb-core
- karton-redis
karton-classifier:
restart: unless-stopped
image: certpl/karton-classifier:latest
environment: *custom_karton_env
depends_on:
- karton-system
- minio
- karton-redis
# --- Custom Driver Services ---
karton-driver-classifier:
restart: unless-stopped
build: ./services/classifier
environment: *custom_karton_env
depends_on:
- karton-system
- minio
- karton-redis
karton-driver-signature:
restart: unless-stopped
build: ./services/signature
environment: *custom_karton_env
depends_on:
- karton-system
- minio
- karton-redis
karton-driver-ioctlance:
restart: unless-stopped
build: ./services/ioctlance
environment: *custom_karton_env
deploy:
replicas: 10
depends_on:
- karton-system
- minio
- karton-redis
karton-driver-reporter:
restart: unless-stopped
build: ./services/reporter
environment:
<<: *custom_karton_env
TELEGRAM_BOT_TOKEN: ${TELEGRAM_BOT_TOKEN:-}
depends_on:
- karton-system
- minio
- mwdb-core
- karton-redis
karton-telegram-bot:
restart: unless-stopped
build: ./services/telegram
environment:
<<: *custom_karton_env
TELEGRAM_BOT_TOKEN: ${TELEGRAM_BOT_TOKEN}
TELEGRAM_CHAT_ID: ${TELEGRAM_CHAT_ID:-}
depends_on:
- karton-redis
- mwdb-core
karton-driver-patch-differ:
restart: unless-stopped
# Now builds from AutoPiff instead of local duplicate
build:
context: ../AutoPiff
dockerfile: services/karton-patch-differ/Dockerfile
environment: *custom_karton_env
volumes:
- ../AutoPiff/rules:/app/rules:ro
depends_on:
- karton-system
- minio
- karton-redis
- mwdb-core
# --- AutoPiff Stage 5: Reachability Tagging ---
karton-driver-reachability:
restart: unless-stopped
build:
context: ../AutoPiff
dockerfile: services/karton-reachability/Dockerfile
environment: *custom_karton_env
depends_on:
- karton-system
- minio
- karton-redis
- mwdb-core
deploy:
resources:
limits:
memory: 8G
reservations:
memory: 4G
# --- AutoPiff Stage 6: Scoring & Ranking ---
karton-driver-ranking:
restart: unless-stopped
build:
context: ../AutoPiff
dockerfile: services/karton-ranking/Dockerfile
environment: *custom_karton_env
volumes:
- ../AutoPiff/rules:/app/rules:ro
depends_on:
- karton-system
- minio
- karton-redis
# --- AutoPiff Stage 7: Report Generation ---
karton-driver-report:
restart: unless-stopped
build:
context: ../AutoPiff
dockerfile: services/karton-report/Dockerfile
environment: *custom_karton_env
depends_on:
- karton-system
- minio
- karton-redis
- mwdb-core
# --- AutoPiff Alerter: Telegram alerts for high-scoring findings ---
autopiff-alerter:
restart: unless-stopped
build:
context: ../AutoPiff
dockerfile: services/autopiff-alerter/Dockerfile
environment:
<<: *custom_karton_env
TELEGRAM_BOT_TOKEN: ${TELEGRAM_BOT_TOKEN:-}
TELEGRAM_CHAT_ID: ${TELEGRAM_CHAT_ID:-}
AUTOPIFF_SCORE_THRESHOLD: "8.0"
depends_on:
- karton-system
- minio
- karton-redis
# --- DriverAtlas Triage: scores every driver's attack surface ---
autopiff-driver-triage:
restart: unless-stopped
build:
context: ../AutoPiff
dockerfile: services/karton-driver-triage/Dockerfile
additional_contexts:
driveratlas-src: ../DriverAtlas
environment:
<<: *custom_karton_env
TELEGRAM_BOT_TOKEN: ${TELEGRAM_BOT_TOKEN:-}
TELEGRAM_CHAT_ID: ${TELEGRAM_CHAT_ID:-}
DRIVERATLAS_SCORE_THRESHOLD: "8.0"
depends_on:
- karton-system
- minio
- karton-redis
- mwdb-core
# --- AutoPiff Driver Monitor: polls for new driver versions ---
autopiff-driver-monitor:
restart: unless-stopped
build:
context: ../AutoPiff
dockerfile: services/driver-monitor/Dockerfile
environment:
<<: *custom_karton_env
VT_API_KEY: ${VT_API_KEY:-}
WINBINDEX_INTERVAL_HOURS: "6"
VT_INTERVAL_HOURS: "4"
volumes:
- ../AutoPiff/services/driver-monitor/watchlist.yaml:/app/watchlist.yaml:ro
depends_on:
- karton-redis
- mwdb-core
volumes:
mwdb-postgres-data:
minio-data:
mwdb-uploads-data: