Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
16 commits
Select commit Hold shift + click to select a range
84eee38
docs(readme): correct sensor directory names, retired-worker row, pro…
Sep 27, 2026
a7153d8
docs(map): drop the nonexistent archive/ tree, add design-lab/ to the…
Sep 27, 2026
e7e6f87
docs(sensors): fix retired dashboard container, ES budget, TANNER ros…
Sep 27, 2026
f9e6d43
docs(deception): add the missing SonicWall SMA decoy row
Sep 27, 2026
2bce5f1
docs(sensors): correct the Suricata capture interface, ILM retention …
Xore Sep 27, 2026
f1abe23
docs(roadmap,design-lab): correct CAPEv2 build status, doc-sweep scop…
Xore Sep 27, 2026
2bb45c9
docs(security-fixes): date the CodeQL record and point its Go-era exa…
Xore Sep 27, 2026
988be8e
docs(sensors): state the ILM windows at the shipped HONEYPOT_RETENTIO…
Xore Sep 27, 2026
a5cfec6
docs(reporting,bistreams): redraw the reporter diagrams against the G…
Xore Sep 27, 2026
a19f666
docs(threat-intel): correct #153 to closed-and-implemented in the rep…
Xore Sep 27, 2026
35cee44
docs(threat-model): resolve two follow-ups the body still reported as…
Sep 27, 2026
4a61fa4
docs(ip-block,agent-intrusion): record the ip-block export path move …
Xore Sep 27, 2026
3f585c4
docs(llm-worker): name the deployed captured-data entry point from th…
Xore Sep 27, 2026
0d068d0
docs(ip-reporting): drop the Prometheus endpoint claim, make the test…
Sep 27, 2026
ee730f9
docs(ml-worker): correct the Tier 1 contract-check count to seven
Xore Sep 27, 2026
c9a5706
docs(ml-worker,writable-layer): seven contract checks, dated banner, …
Sep 27, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
15 changes: 9 additions & 6 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -25,8 +25,11 @@ flowchart LR
wg --> home["home APIARY stacks<br/>@ 10.8.0.2"]
```

**All core sensors run without compose profiles.** The only profile is the
optional on-demand `geoip-update` maintenance job. 39 deployment pieces —
**All core sensors run without compose profiles.** The only profiles are the
optional on-demand maintenance jobs `geoip-update` and `threat-intel` (both in
`honeypot-init`); the four `["legacy"]` worker stacks are defined for rollback
but do not run, and `sandbox/ghosts`'s `["test"]` client is not a sensor.
39 deployment pieces —
33 independent Arcane-managed stacks under `arcane/home/` plus 6 more at
their own repository-root paths, all at home, plus the VPS (see
[docs/ARCANE-GIT-SYNC.md](docs/ARCANE-GIT-SYNC.md) for how a repo commit
Expand All @@ -38,12 +41,12 @@ why the home side split into this many Compose stacks):
| `honeypot-keycloak` ([arcane/home/honeypot-keycloak/compose.yml](arcane/home/honeypot-keycloak/compose.yml)) | **home** | Arcane-managed Keycloak/PostgreSQL identity stack; only Keycloak is reachable from VPS Traefik over WireGuard |
| `honeypot-init` ([arcane/home/honeypot-init/compose.yml](arcane/home/honeypot-init/compose.yml)) | **home** | one-shot bootstrap jobs: log paths, Elasticsearch templates, Arkime schema, persona validation |
| `honeypot-cowrie`, `honeypot-dionaea`, `honeypot-conpot`, `honeypot-dnp3`, `honeypot-http`, `honeypot-multipot` (`arcane/home/honeypot-<name>/compose.yml`, one directory each) | **home** | the sensors: Cowrie, Dionaea (+ TFTP relay), Conpot personas, DNP3, HTTP/API honeypots, multipot |
| `honeypot-dicompot`, `honeypot-dns-honeypot`, `honeypot-citrix`, `honeypot-cisco-asa`, `honeypot-sonicwall-sma`, `honeypot-rdp`, `honeypot-endlessh`, `honeypot-beelzebub`, `honeypot-hellpot`, `honeypot-elasticpot`, `honeypot-galah`, `honeypot-sentrypeer`, `honeypot-mailoney` (`arcane/home/honeypot-<name>/compose.yml`, one directory each) | **home** | more sensors: DICOM medical-imaging decoy, DNS UDP reflection bait (response-capped, never a real amplification vector), Citrix ADC/NetScaler Gateway decoy (CVE-2019-19781), Cisco ASA WebVPN+IKE decoy (CVE-2018-0101), SonicWall SMA1000 Work Place/AMC decoy (CVE-2026-83548 Work Place SSRF), RDP decoy, SSH pre-auth tarpit, vendored multi-protocol deception runtime (SSH/LDAP/MCP/HTTP, #1418), vendored HTTP bot tarpit (#1419), vendored Elasticsearch decoy distinct from multipot's own (#1423), vendored LLM-powered HTTP honeypot behind its own broker-guarded bridge onto the shared Ollama instance (#1420), vendored SIP/VoIP fraud-detection honeypot (#1424), vendored SMTP honeypot taking over port 25 from multipot's own retired handler (#1422) — the row's `honeypot-wordpot` / WordPress/CMS decoy slot was removed when wordpot retired (#2381) |
| `honeypot-dicompot`, `honeypot-dns-honeypot`, `honeypot-citrix-honeypot`, `honeypot-cisco-asa-honeypot`, `honeypot-sonicwall-sma`, `honeypot-rdp-honeypot`, `honeypot-endlessh`, `honeypot-beelzebub`, `honeypot-hellpot`, `honeypot-elasticpot`, `honeypot-galah`, `honeypot-sentrypeer`, `honeypot-mailoney` (`arcane/home/honeypot-<name>/compose.yml`, one directory each) | **home** | more sensors: DICOM medical-imaging decoy, DNS UDP reflection bait (response-capped, never a real amplification vector), Citrix ADC/NetScaler Gateway decoy (CVE-2019-19781), Cisco ASA WebVPN+IKE decoy (CVE-2018-0101), SonicWall SMA1000 Work Place/AMC decoy (CVE-2026-83548 Work Place SSRF), RDP decoy, SSH pre-auth tarpit, vendored multi-protocol deception runtime (SSH/LDAP/MCP/HTTP, #1418), vendored HTTP bot tarpit (#1419), vendored Elasticsearch decoy distinct from multipot's own (#1423), vendored LLM-powered HTTP honeypot behind its own broker-guarded bridge onto the shared Ollama instance (#1420), vendored SIP/VoIP fraud-detection honeypot (#1424), vendored SMTP honeypot taking over port 25 from multipot's own retired handler (#1422) — the row's `honeypot-wordpot` / WordPress/CMS decoy slot was removed when wordpot retired (#2381) |
| `honeypot-canarytokens` ([arcane/home/honeypot-canarytokens/compose.yml](arcane/home/honeypot-canarytokens/compose.yml)) | **home** | self-hosted honeytoken platform (#1426) -- planted-artifact deception, not a listening protocol decoy; `canarytokens-adapter` translates its webhook alerts into this repo's shared JSON event shape. The dashboard's Settings > Canarytokens pane (#1487) creates PDF/Word/Excel/custom-image/Windows-Folder/QR tokens on demand for use *outside* this honeypot (#1662 dropped the stale design doc that described the pre-cutover plan; the shipped pane is authoritative) |
| `honeypot-tanner` ([arcane/home/honeypot-tanner/compose.yml](arcane/home/honeypot-tanner/compose.yml)) | **home** | SNARE + TANNER application-emulation boundary |
| `honeypot-elk` ([arcane/home/honeypot-elk/compose.yml](arcane/home/honeypot-elk/compose.yml)) | **home** | Filebeat, Elasticsearch, Kibana, EveBox, Arkime |
| `honeypot-agent-intrusion-worker` ([arcane/home/honeypot-agent-intrusion-worker/compose.yml](arcane/home/honeypot-agent-intrusion-worker/compose.yml)) | **home** | the labelled corpus plus the Tier 1 contract benchmark. The worker itself was ported to Rust in #1610 and now runs as `WORKER_LOOPS=agent-intrusion` inside `honeypot-dashboard`'s `backend-worker`; the Python stack is retained under the `legacy` profile for rollback only, and the live `agent-intrusion-campaigns` index is written by the Rust loop |
| `honeypot-attacker-identity-worker`, `honeypot-correlator-worker`, `honeypot-payload-inventory-worker` (`arcane/home/honeypot-<name>/compose.yml`, one directory each) | **home** | three more workers that had their own top-level compose file but had drifted out of the deploy/installer inventory before #1502's audit caught it (same class of gap #560 and #891 each fixed once before) -- attacker-identity correlation, cross-sensor campaign correlation, and payload inventory tracking |
| `honeypot-attacker-identity-worker`, `honeypot-correlator-worker`, `honeypot-payload-inventory-worker` (`arcane/home/honeypot-<name>/compose.yml`, one directory each) | **home** | three more workers that had their own top-level compose file but had drifted out of the deploy/installer inventory before #1502's audit caught it (same class of gap #560 and #891 each fixed once before) -- attacker-identity correlation, cross-sensor campaign correlation, and payload inventory tracking. All three were retired by the same #1649 pass as the agent-intrusion worker: #1610 ported them to Rust, where they now run as `WORKER_LOOPS=attacker-identity` and `WORKER_LOOPS=correlator` on `honeypot-dashboard`'s `backend-worker` and `WORKER_LOOPS=payload-inventory` on `backend-worker-payload-inventory`. Like row above, the Python stacks are kept under the `legacy` profile for rollback only and are not the live writers |
| `honeypot-dashboard` ([arcane/home/honeypot-dashboard/compose.yml](arcane/home/honeypot-dashboard/compose.yml)) | **home** | the live investigation dashboard: TanStack Start frontend (`dashboard-next`) in front of the Rust axum `backend-service` API tier, plus its worker containers (importer, networkless enrichment, the `WORKER_LOOPS` aggregation loops) and the services-adapter Docker control surface. Live since #1628's cutover completed 2026-08-22 -- the Go dashboard is deleted; see [docs/DASHBOARD-CUTOVER.md](docs/DASHBOARD-CUTOVER.md) and [docs/ARCHITECTURE.md](docs/ARCHITECTURE.md) |
| `honeypot-dashboard-backend` ([arcane/home/honeypot-dashboard-backend/compose.yml](arcane/home/honeypot-dashboard-backend/compose.yml)) | **home** | the unprivileged read-only `backend-service` API tier (:8081), split out from `honeypot-dashboard` by #1622 so Arcane can redeploy the API tier without touching `dashboard-next`; the write-capable, host-spool-mounted instance is `backend-service-mounted` (:8082), which stayed in `honeypot-dashboard` |
| `honeypot-payload-analysis` ([arcane/home/honeypot-payload-analysis/compose.yml](arcane/home/honeypot-payload-analysis/compose.yml)) | **home** | payload dedup + YARA scanning |
Expand Down Expand Up @@ -91,7 +94,7 @@ for where those fit.
| [docs/BACKUP-ESSENTIALS.md](docs/BACKUP-ESSENTIALS.md) | What is backed up so the stack can be rebuilt, where the three copies go, and the full restore procedure |
| [scripts/install.sh](scripts/install.sh) | Single entry point for host provisioning — `sudo ./scripts/install.sh --profile home\|vps`, which dispatches to the installer below (or [scripts/install-vps.sh](scripts/install-vps.sh)) with that profile's answers file. Both share their retry/step/logging framework via [scripts/lib/install-common.sh](scripts/lib/install-common.sh) ([#1609](https://github.com/Xore/APIARY/issues/1609)) |
| [scripts/install-homeserver.sh](scripts/install-homeserver.sh) | Unattended provisioning script (Docker, GPU/NVIDIA, WireGuard, Arcane, the stacks themselves) for a manually-installed base Ubuntu system — fill in [scripts/install-homeserver.conf.example](scripts/install-homeserver.conf.example) first, same idea as a Windows `autounattend.xml` answer file. First cut, see [#518](https://github.com/Xore/APIARY/issues/518) |
| [docs/ARCHITECTURE.md](docs/ARCHITECTURE.md) | System architecture and data flow — trust boundaries, container map, event ingestion, correlation/enrichment (p0f, HASSH/JA3/JA4, GeoIP), payload lifecycle, sandbox detonation, evidence types (6 diagrams) |
| [docs/ARCHITECTURE.md](docs/ARCHITECTURE.md) | System architecture and data flow — trust boundaries, container map, event ingestion, correlation/enrichment (p0f, HASSH/JA3/JA4, GeoIP), payload lifecycle, sandbox detonation, evidence types (4 diagrams) |
| [docs/SENSORS.md](docs/SENSORS.md) | The sensor table, resource budgets, investigation UIs, SNARE+TANNER, Suricata, Arkime, and how real attacker IPs survive the tunnel |
| [docs/OPERATIONS.md](docs/OPERATIONS.md) | Persona inventory, the seeded cowrie filesystem, GeoIP, and how to actually read the data (dashboard, Kibana, Arkime, backups) |
| [docs/ip-reporting-plan.md](docs/ip-reporting-plan.md) | Defensive IP-blocklist reporting (AbuseIPDB/Blocklist.de), dry-run by default |
Expand All @@ -104,7 +107,7 @@ for where those fit.
| [docs/CONTAINER-UPDATES.md](docs/CONTAINER-UPDATES.md) | How to check pinned images for updates, assess compatibility, verify empirically, and pin by digest |
| [docs/TESTING.md](docs/TESTING.md) | The three testing tiers -- CI, live feature smoke tests, and the full clean-reinstall release gate -- and how to repeat each one |
| [docs/STACK-REBUILD.md](docs/STACK-REBUILD.md) | Runbook for a full deliberate reset — stop order, what's preserved vs wiped, and the ordering/permission pitfalls to avoid |
| [deploy-profiles/](deploy-profiles/) | Named deployment shapes (full / ICS-only / web-only) — which of the 20 split home stacks run for a given deployment, plus a validator catching cross-stack drift before deploy |
| [deploy-profiles/](deploy-profiles/) | Named deployment shapes (full / ICS-only / web-only) — which of the 26 split home stacks run for a given deployment, plus a validator catching cross-stack drift before deploy |
| [docs/RECOVERY.md](docs/RECOVERY.md) | `factory-reset.sh` — one entry point for "back up, optionally wipe/reset, restart" on the same host |
| [docs/ROADMAP.md](docs/ROADMAP.md) / [docs/WORK-LEDGER.md](docs/WORK-LEDGER.md) | What order work happens in, and how issues are claimed/reviewed |
| [docs/ml-worker-plan.md](docs/ml-worker-plan.md), [docs/gpu-llm-analysis-worker.md](docs/gpu-llm-analysis-worker.md), [docs/gpu-ml-worker-acceleration.md](docs/gpu-ml-worker-acceleration.md) | The homeserver's NVIDIA GPU running local LLM log/payload analysis and CUDA-accelerated anomaly detection — no data leaves the machine |
Expand Down
1 change: 1 addition & 0 deletions docs/DECEPTION-EXTENSIONS.md
Original file line number Diff line number Diff line change
Expand Up @@ -109,6 +109,7 @@ traces back to at least one decision.
| RDP decoy (rdphoneypot lineage) | Integrated | `arcane/home/honeypot-rdp-honeypot/` | #238 batch, per-decoy plan #412 |
| Cisco ASA VPN gateway decoy | Integrated | `arcane/home/honeypot-cisco-asa-honeypot/` | #238 batch, CVE context #414 |
| Citrix ADC gateway decoy | Integrated | `arcane/home/honeypot-citrix-honeypot/` | #238 batch, CVE context #414 |
| SonicWall SMA1000 Work Place/AMC decoy | Integrated | `arcane/home/honeypot-sonicwall-sma/` | #3033; CVE-2026-83548 SSRF / CVE-2026-83549 AMC command-injection chain |
| DNS amplification bait | Integrated | `arcane/home/honeypot-dns-honeypot/` | #238 batch, safety-sensitive design #415 |
| Mailoney (SMTP) | Integrated | `arcane/home/honeypot-mailoney/` | #1422 |
| SentryPeer (VoIP/SIP) | Integrated | `arcane/home/honeypot-sentrypeer/` | #1424 |
Expand Down
6 changes: 3 additions & 3 deletions docs/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -97,8 +97,8 @@ Analysis and sandbox components:
era references inside are historical)](dashboard-manual-ip-block-design.md)

Subdirectories (`analysis/`, `research/`, `sandbox/`, `vps/`, `autoinstall/`,
`deploy-profiles/`, `archive/`) hold the same kinds of documents scoped to
`deploy-profiles/`, `design-lab/`) hold the same kinds of documents scoped to
their component. Every doc must be reachable from this page through links;
dated record trees (`research/`, `benchmarks/`, the VM-detection results,
`archive/`) are exempt. `scripts/check-docs-reachable.py` enforces this in CI
(#3332).
`design-lab/`, kept as a near-duplicate of `branding/design-lab/`) are
exempt. `scripts/check-docs-reachable.py` enforces this in CI (#3332).
27 changes: 21 additions & 6 deletions docs/ROADMAP.md
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,11 @@ Last audited: 2026-08-05
> Deleted by the 2026-08-30 bulk purge and restored verbatim by #2896/#2947
> on 2026-09-04. Nothing below was updated during that window — treat
> "last audited" above as still true, not as of the restore date.
>
> The *repository* did keep moving across that same window, though, so the
> audit date is not a safe lower bound for "still true": reconcile any status
> claim here against the code before relying on it. The CAPEv2 line above is
> one already re-verified (2026-09-27) and found stale.

## Current baseline

Expand All @@ -35,12 +40,22 @@ Last audited: 2026-08-05
booting; the end-to-end submit-to-report path is verified for the
Linux/Wine sandbox and GitHub-analysis publishing. The Windows-11 golden
image epic ([#47](https://github.com/Xore/APIARY/issues/47)) is
still open — see the Windows sandbox section below. CAPEv2 (#314-322)
remains unbuilt and is post-0.1.0 backlog.
- Documentation has been consolidated: every doc that used to be scattered
next to its source now lives under `docs/`, mirroring the source tree
([#670](https://github.com/Xore/APIARY/issues/670), closed
2026-08-05).
still open — see the Windows sandbox section below. CAPEv2 (#314-322) is
**authored, not deployed**: [#843](https://github.com/Xore/APIARY/issues/843)
(2026-09-01) landed `sandbox/cape/` — compose stack, Packer
`win11-cape.pkr.hcl`, CAPEv2 override units and a spool worker — but unlike
GHOSTS it has no entry in `arcane/manifests/home-production.json`, so nothing
Dockge-managed deploys it. Treat it as post-0.1.0 backlog whose build work
has already started, not as unbuilt.
- Documentation has been consolidated: the subsystem docs that used to be
scattered next to their source now live under `docs/`, mirroring the source
tree ([#670](https://github.com/Xore/APIARY/issues/670), closed
2026-08-05). The exceptions are deliberate and catalogued in
[`docs/README.md`](README.md) — per-stack and vendored `README.md` files stay
next to their code, and a few dated record trees are exempt from the
reachability gate (#3332). Root-level dated task records (`DIFF.md`,
`EVIDENCE.md`, `HANDOFF-3097.md`) are the residue of that sweep and are not
covered by it.
- The dashboard rewrite is done, not pending: the TanStack Start
frontend/BFF + Rust service tier
([#1608](https://github.com/Xore/APIARY/issues/1608) and its
Expand Down
Loading
Loading