diff --git a/etc/compose/collector.yml b/etc/compose/collector.yml index 204b31e6..81d044a2 100644 --- a/etc/compose/collector.yml +++ b/etc/compose/collector.yml @@ -64,6 +64,19 @@ services: #### NSM ################## +# Fatt service + fatt: + container_name: fatt + restart: always + network_mode: "host" + cap_add: + - NET_ADMIN + - SYS_NICE + - NET_RAW + image: "dtagdevsec/fatt:2006" + volumes: + - /data/fatt/log:/opt/fatt/log + # P0f service p0f: container_name: p0f @@ -113,7 +126,7 @@ services: restart: always environment: - bootstrap.memory_lock=true - - ES_JAVA_OPTS=-Xms1024m -Xmx1024m + - ES_JAVA_OPTS=-Xms2048m -Xmx2048m - ES_TMPDIR=/tmp cap_add: - IPC_LOCK @@ -193,22 +206,34 @@ services: nginx: container_name: nginx restart: always + environment: + ### If set to YES all changes within Heimdall will remain for the next start + ### Make sure to uncomment the corresponding volume statements below, or the setting will prevent a successful start of T-Pot. + - HEIMDALL_PERSIST=NO tmpfs: - /var/tmp/nginx/client_body - /var/tmp/nginx/proxy - /var/tmp/nginx/fastcgi - /var/tmp/nginx/uwsgi - - /var/tmp/nginx/scgi + - /var/tmp/nginx/scgi - /run + - /var/log/php7/ + - /var/lib/nginx/tmp:uid=100,gid=82 + - /var/lib/nginx/html/storage/logs:uid=100,gid=82 + - /var/lib/nginx/html/storage/framework/views:uid=100,gid=82 network_mode: "host" ports: - "64297:64297" + - "127.0.0.1:64304:64304" image: "dtagdevsec/nginx:2006" read_only: true volumes: - /data/nginx/cert/:/etc/nginx/cert/:ro - /data/nginx/conf/nginxpasswd:/etc/nginx/nginxpasswd:ro - /data/nginx/log/:/var/log/nginx/ + ### Enable the following volumes if you set HEIMDALL_PERSIST=YES + # - /data/nginx/heimdall/database:/var/lib/nginx/html/database + # - /data/nginx/heimdall/storage:/var/lib/nginx/html/storage # Spiderfoot service spiderfoot: diff --git a/etc/compose/industrial.yml b/etc/compose/industrial.yml index bd4d83c4..5a6ffd6c 100644 --- a/etc/compose/industrial.yml +++ b/etc/compose/industrial.yml @@ -240,6 +240,19 @@ services: #### NSM ################## +# Fatt service + fatt: + container_name: fatt + restart: always + network_mode: "host" + cap_add: + - NET_ADMIN + - SYS_NICE + - NET_RAW + image: "dtagdevsec/fatt:2006" + volumes: + - /data/fatt/log:/opt/fatt/log + # P0f service p0f: container_name: p0f @@ -289,7 +302,7 @@ services: restart: always environment: - bootstrap.memory_lock=true - - ES_JAVA_OPTS=-Xms1024m -Xmx1024m + - ES_JAVA_OPTS=-Xms2048m -Xmx2048m - ES_TMPDIR=/tmp cap_add: - IPC_LOCK @@ -369,22 +382,34 @@ services: nginx: container_name: nginx restart: always + environment: + ### If set to YES all changes within Heimdall will remain for the next start + ### Make sure to uncomment the corresponding volume statements below, or the setting will prevent a successful start of T-Pot. + - HEIMDALL_PERSIST=NO tmpfs: - /var/tmp/nginx/client_body - /var/tmp/nginx/proxy - /var/tmp/nginx/fastcgi - /var/tmp/nginx/uwsgi - - /var/tmp/nginx/scgi + - /var/tmp/nginx/scgi - /run + - /var/log/php7/ + - /var/lib/nginx/tmp:uid=100,gid=82 + - /var/lib/nginx/html/storage/logs:uid=100,gid=82 + - /var/lib/nginx/html/storage/framework/views:uid=100,gid=82 network_mode: "host" ports: - "64297:64297" + - "127.0.0.1:64304:64304" image: "dtagdevsec/nginx:2006" read_only: true volumes: - /data/nginx/cert/:/etc/nginx/cert/:ro - /data/nginx/conf/nginxpasswd:/etc/nginx/nginxpasswd:ro - /data/nginx/log/:/var/log/nginx/ + ### Enable the following volumes if you set HEIMDALL_PERSIST=YES + # - /data/nginx/heimdall/database:/var/lib/nginx/html/database + # - /data/nginx/heimdall/storage:/var/lib/nginx/html/storage # Spiderfoot service spiderfoot: diff --git a/etc/compose/nextgen.yml b/etc/compose/nextgen.yml index a704247d..d1174a99 100644 --- a/etc/compose/nextgen.yml +++ b/etc/compose/nextgen.yml @@ -366,21 +366,21 @@ services: - tanner_redis ## Tanner WEB Service -# tanner_web: -# container_name: tanner_web -# restart: always -# tmpfs: -# - /tmp/tanner:uid=2000,gid=2000 -# tty: true -# networks: -# - tanner_local -# image: "dtagdevsec/tanner:2006" -# command: tannerweb -# read_only: true -# volumes: -# - /data/tanner/log:/var/log/tanner -# depends_on: -# - tanner_redis +# tanner_web: +# container_name: tanner_web +# restart: always +# tmpfs: +# - /tmp/tanner:uid=2000,gid=2000 +# tty: true +# networks: +# - tanner_local +# image: "dtagdevsec/tanner:2006" +# command: tannerweb +# read_only: true +# volumes: +# - /data/tanner/log:/var/log/tanner +# depends_on: +# - tanner_redis ## Tanner Service tanner: @@ -399,7 +399,7 @@ services: - /data/tanner/files:/opt/tanner/files depends_on: - tanner_api -# - tanner_web +# - tanner_web - tanner_phpox ## Snare Service diff --git a/etc/compose/sensor.yml b/etc/compose/sensor.yml index 8b3c3d19..dcd61db6 100644 --- a/etc/compose/sensor.yml +++ b/etc/compose/sensor.yml @@ -345,21 +345,21 @@ services: - tanner_redis ## Tanner WEB Service - tanner_web: - container_name: tanner_web - restart: always - tmpfs: - - /tmp/tanner:uid=2000,gid=2000 - tty: true - networks: - - tanner_local - image: "dtagdevsec/tanner:2006" - command: tannerweb - read_only: true - volumes: - - /data/tanner/log:/var/log/tanner - depends_on: - - tanner_redis +# tanner_web: +# container_name: tanner_web +# restart: always +# tmpfs: +# - /tmp/tanner:uid=2000,gid=2000 +# tty: true +# networks: +# - tanner_local +# image: "dtagdevsec/tanner:2006" +# command: tannerweb +# read_only: true +# volumes: +# - /data/tanner/log:/var/log/tanner +# depends_on: +# - tanner_redis ## Tanner Service tanner: @@ -378,7 +378,7 @@ services: - /data/tanner/files:/opt/tanner/files depends_on: - tanner_api - - tanner_web +# - tanner_web - tanner_phpox ## Snare Service diff --git a/etc/compose/standard.yml b/etc/compose/standard.yml index b939e630..ffebd3d4 100644 --- a/etc/compose/standard.yml +++ b/etc/compose/standard.yml @@ -346,21 +346,21 @@ services: - tanner_redis ## Tanner WEB Service - tanner_web: - container_name: tanner_web - restart: always - tmpfs: - - /tmp/tanner:uid=2000,gid=2000 - tty: true - networks: - - tanner_local - image: "dtagdevsec/tanner:2006" - command: tannerweb - read_only: true - volumes: - - /data/tanner/log:/var/log/tanner - depends_on: - - tanner_redis +# tanner_web: +# container_name: tanner_web +# restart: always +# tmpfs: +# - /tmp/tanner:uid=2000,gid=2000 +# tty: true +# networks: +# - tanner_local +# image: "dtagdevsec/tanner:2006" +# command: tannerweb +# read_only: true +# volumes: +# - /data/tanner/log:/var/log/tanner +# depends_on: +# - tanner_redis ## Tanner Service tanner: @@ -379,7 +379,7 @@ services: - /data/tanner/files:/opt/tanner/files depends_on: - tanner_api - - tanner_web +# - tanner_web - tanner_phpox ## Snare Service @@ -400,6 +400,19 @@ services: #### NSM ################## +# Fatt service + fatt: + container_name: fatt + restart: always + network_mode: "host" + cap_add: + - NET_ADMIN + - SYS_NICE + - NET_RAW + image: "dtagdevsec/fatt:2006" + volumes: + - /data/fatt/log:/opt/fatt/log + # P0f service p0f: container_name: p0f @@ -449,7 +462,7 @@ services: restart: always environment: - bootstrap.memory_lock=true - - ES_JAVA_OPTS=-Xms1024m -Xmx1024m + - ES_JAVA_OPTS=-Xms2048m -Xmx2048m - ES_TMPDIR=/tmp cap_add: - IPC_LOCK @@ -529,22 +542,34 @@ services: nginx: container_name: nginx restart: always + environment: + ### If set to YES all changes within Heimdall will remain for the next start + ### Make sure to uncomment the corresponding volume statements below, or the setting will prevent a successful start of T-Pot. + - HEIMDALL_PERSIST=NO tmpfs: - /var/tmp/nginx/client_body - /var/tmp/nginx/proxy - /var/tmp/nginx/fastcgi - /var/tmp/nginx/uwsgi - - /var/tmp/nginx/scgi + - /var/tmp/nginx/scgi - /run + - /var/log/php7/ + - /var/lib/nginx/tmp:uid=100,gid=82 + - /var/lib/nginx/html/storage/logs:uid=100,gid=82 + - /var/lib/nginx/html/storage/framework/views:uid=100,gid=82 network_mode: "host" ports: - "64297:64297" + - "127.0.0.1:64304:64304" image: "dtagdevsec/nginx:2006" read_only: true volumes: - /data/nginx/cert/:/etc/nginx/cert/:ro - /data/nginx/conf/nginxpasswd:/etc/nginx/nginxpasswd:ro - /data/nginx/log/:/var/log/nginx/ + ### Enable the following volumes if you set HEIMDALL_PERSIST=YES + # - /data/nginx/heimdall/database:/var/lib/nginx/html/database + # - /data/nginx/heimdall/storage:/var/lib/nginx/html/storage # Spiderfoot service spiderfoot: