docs: public-repo readiness — scrub private paths, fix links, CI notes

Remove personal OneDrive paths and wrong GitHub owner; document self-hosted
CI for external contributors; fix env prefix table, deploy lab script, UFW
guidance, pyproject URLs, and tighten gitignore for secrets.
This commit is contained in:
Mr. The Plague
2026-08-04 09:05:50 -04:00
parent 169ec40460
commit d3b2fcfe79
9 changed files with 63 additions and 34 deletions
+5
View File
@@ -45,8 +45,13 @@ payloads/out/
.secrets/
admin_token.txt
**/admin_token.txt
implant_psk.txt
**/implant_psk.txt
*.pem
!docs/**/*.pem
data/*
!data/.gitkeep
# Local operator CLI config (contains tokens)
.config/squidc5/
**/squidc5/config.json
**/config/squidc5/
+2 -4
View File
@@ -50,9 +50,7 @@ When adding features: **deny by default**, enable via admin feature flags or env
## Development pipeline (mandatory)
Source of truth also: Windows SquidSec workspace
`/mnt/c/Users/ynot_/OneDrive/Desktop/Company Data/SquidSec/AGENTS.md` + `knowledge-base/MEMORY.md`
-> **Development cycles (git repos)**.
Source of truth for this project: this repo’s **`AGENTS.md`**, **`docs/`**, and **`CONTRIBUTING.md`**.
### Git cycle (every change)
@@ -74,7 +72,7 @@ merge main -> CI builds Linux/Windows binaries -> GitHub Release published
-> deploy Linux squidc5 binary ONLY (from Release assets or workflow Artifacts)
```
Releases: `https://github.com/DotNetRussell/SquidC5/releases` (created by CI job `github-release` on main/master only).
Releases: `https://github.com/SquidSec/SquidC5/releases` (created by CI job `github-release` on `master` only).
- **Never** commit/push straight to `main`/`master`
- **Never** rsync WIP source or `docker compose up --build` to prod
+1 -1
View File
@@ -1,6 +1,6 @@
# CLAUDE.md
**SquidC5 is a military-grade, security-first, AI-native C2 under active development** for authorized red team / pen-test use only.
**SquidC5 is a security-first, AI-native C5 teamserver** (Command · Control · Cognitive · Collaborative · Coordination) under active development for authorized red team / pen-test use only.
Follow **[AGENTS.md](AGENTS.md)** as the primary agent memory for this repository.
+3 -2
View File
@@ -35,8 +35,9 @@ ruff check src tests
## CI
- **CI** workflow: pytest (3.11/3.12), ruff, Docker smoke, pip-audit, binaries on `master`.
- **SquidGate** (`SquidSec/SquidGate@v1.0.0-build.4`): PR security gate. Set repository secret `LLM_API_KEY` to enable full analysis.
- **CI** workflow: pytest (3.11/3.12), ruff, Docker smoke, pip-audit; Linux/Windows binaries + GitHub Release on push to `master`.
- Workflows run on **SquidSec self-hosted runners** and only schedule jobs for **same-repo** PRs (fork code is not executed on org runners). If Actions looks empty on a fork PR, that is expected — run the local checks above and note results in the PR.
- **SquidGate** (when configured): optional PR security gate via `SquidSec/SquidGate`. Repository secret `LLM_API_KEY` enables full analysis when available.
## Docs
+15 -14
View File
@@ -14,12 +14,11 @@
</p>
<p align="center">
<!-- Private repo: GitHub/shields status APIs return "not found" unauthenticated - static link badges only -->
<a href="https://github.com/SquidSec/SquidC5/actions/workflows/ci.yml"><img src="https://img.shields.io/badge/CI-workflow-2088FF?logo=githubactions&logoColor=white" alt="CI"></a>
<a href="https://github.com/SquidSec/SquidC5/actions/workflows/squidgate.yml"><img src="https://img.shields.io/badge/SquidGate-workflow-6f42c1?logo=githubactions&logoColor=white" alt="SquidGate"></a>
<a href="https://github.com/SquidSec/SquidC5/releases"><img src="https://img.shields.io/badge/releases-GitHub-181717?logo=github&logoColor=white" alt="Releases"></a>
<a href="https://github.com/SquidSec/SquidC5/actions/workflows/ci.yml"><img src="https://img.shields.io/github/actions/workflow/status/SquidSec/SquidC5/ci.yml?branch=master&label=CI&logo=githubactions&logoColor=white" alt="CI"></a>
<a href="https://github.com/SquidSec/SquidC5/releases/latest"><img src="https://img.shields.io/github/v/release/SquidSec/SquidC5?label=release&logo=github" alt="Release"></a>
<a href="https://www.python.org/downloads/"><img src="https://img.shields.io/badge/python-3.11%2B-blue" alt="Python"></a>
<a href="LICENSE"><img src="https://img.shields.io/badge/license-MIT-green" alt="License"></a>
<a href="https://github.com/SquidSec/SquidC5"><img src="https://img.shields.io/badge/C5-teamserver-e91e8c" alt="C5"></a>
</p>
**Command / Control / Cognitive / Collaborative / Coordination**
@@ -170,18 +169,18 @@ Docs follow [Diátaxis](https://diataxis.fr/): tutorials & how-tos (runbook/depl
## Configuration
See [.env.example](.env.example). Prefix `SQUIDC5_`.
See [.env.example](.env.example). All settings use the **`SQUIDC5_`** prefix.
| Variable | Default | Notes |
|----------|---------|--------|
| `TLS_ENABLED` | `true` | HTTPS |
| `MCP_ENABLED` | `false` | External AI tools |
| `IMPLANT_REQUIRE_AUTH` | `true` | AEAD beacons |
| `LOCAL_LLM_ENABLED` | `false` | Opt-in Ollama path |
| `LOCAL_LLM_BASE_URL` | `http://127.0.0.1:11434/v1` | Ollama-compatible |
| `LOCAL_LLM_MODEL` | `llama3.2` | Model id when enabled |
| `RATE_LIMIT_PER_MINUTE` | `60` | Raise for ops UI (e.g. 600) |
| `PUBLIC_HOST` | empty | Stage-2 / SOCKS data host |
| `SQUIDC5_TLS_ENABLED` | `true` | HTTPS |
| `SQUIDC5_MCP_ENABLED` | `false` | External AI tools |
| `SQUIDC5_IMPLANT_REQUIRE_AUTH` | `true` | AEAD beacons |
| `SQUIDC5_LOCAL_LLM_ENABLED` | `false` | Opt-in Ollama path |
| `SQUIDC5_LOCAL_LLM_BASE_URL` | `http://127.0.0.1:11434/v1` | Ollama-compatible |
| `SQUIDC5_LOCAL_LLM_MODEL` | `llama3.2` | Model id when enabled |
| `SQUIDC5_RATE_LIMIT_PER_MINUTE` | `60` | Raise for ops UI (e.g. 600) |
| `SQUIDC5_PUBLIC_HOST` | empty | Stage-2 / SOCKS data host |
## Security model
@@ -199,7 +198,9 @@ ruff check src tests
# optional: cd agents/sc5beacon && go build .
```
Git cycle: feature branch -> tests -> PR -> green CI -> merge `master`. Never push straight to master.
Git cycle: feature branch → tests → PR → green CI → merge `master`. Never push straight to master.
**CI note:** org workflows run on SquidSec self-hosted runners and only execute same-repo PRs (fork PRs are not scheduled on those runners). External contributors should run `pytest -q` and `ruff check src tests` locally before opening a PR. See [CONTRIBUTING.md](CONTRIBUTING.md).
## About SquidSec
+16 -2
View File
@@ -96,14 +96,28 @@ sc5 listeners list # status running
### Context
Dedicated C2 lab host pattern: allow inbound so reverse-shell listener ports work without re-opening UFW each time. Only SSH + SquidC5 should listen publicly on a hardened prod host (tighten as required by your ROE).
Dedicated lab host: open only the ports you need for SSH, the teamserver, and any reverse-shell / OAST listeners. **Never** copy a wide-open firewall policy to an internet-facing production host.
### Configuration
Lab-permissive example:
**Hardened default (recommended):**
```bash
ufw --force reset
ufw default deny incoming
ufw default allow outgoing
ufw allow OpenSSH
ufw allow 8443/tcp comment 'squidc5 teamserver'
# add listener ports as needed, e.g.:
# ufw allow 443/tcp comment 'rev shell / https front'
ufw --force enable
```
**Lab-only permissive** (isolated lab VMs — **not** for prod):
```bash
# DANGEROUS on the public internet — lab VMs only
ufw --force reset
ufw default allow incoming
ufw default allow outgoing
ufw allow OpenSSH
+1 -1
View File
@@ -16,7 +16,7 @@
## Mandatory git cycle (every change)
From SquidSec `AGENTS.md` + `knowledge-base/MEMORY.md` and SquidC5 `AGENTS.md`:
From this repo’s [AGENTS.md](../AGENTS.md) and [CONTRIBUTING.md](../CONTRIBUTING.md):
1. Checkout and update `master` (pull latest).
2. Create a **feature branch** named for the change only.
+9 -1
View File
@@ -10,7 +10,7 @@ readme = "README.md"
license = { text = "MIT" }
requires-python = ">=3.11"
authors = [{ name = "SquidC5 Contributors" }]
keywords = ["c2", "red-team", "penetration-testing", "mcp", "security"]
keywords = ["c5", "c2", "red-team", "penetration-testing", "mcp", "security"]
classifiers = [
"Development Status :: 3 - Alpha",
"Intended Audience :: Information Technology",
@@ -19,6 +19,14 @@ classifiers = [
"Programming Language :: Python :: 3.12",
"Topic :: Security",
]
# Package version stays 0.1.x alpha; GitHub Releases (v0.1.<run>-<sha>) are the version of record for binaries.
[project.urls]
Homepage = "https://github.com/SquidSec/SquidC5"
Documentation = "https://github.com/SquidSec/SquidC5/blob/master/docs/README.md"
Repository = "https://github.com/SquidSec/SquidC5"
"Bug Tracker" = "https://github.com/SquidSec/SquidC5/issues"
Changelog = "https://github.com/SquidSec/SquidC5/blob/master/CHANGELOG.md"
dependencies = [
"fastapi>=0.115.0",
"uvicorn[standard]>=0.32.0",
+11 -9
View File
@@ -1,12 +1,13 @@
#!/usr/bin/env bash
# Deploy SquidC5 to a DigitalOcean droplet (Docker)
# Lab-only: rsync source + Docker Compose to a cloud VM.
# NOT for production. Prod = main CI squidc5 binary only (docs/deployment.md).
set -euo pipefail
DROPLET_IP="${1:?Usage: $0 <droplet-ip> [ssh-user]}"
DROPLET_IP="${1:?Usage: $0 <host-ip> [ssh-user]}"
SSH_USER="${2:-root}"
REMOTE_DIR="/opt/squidc5"
echo "==> Deploying SquidC5 to ${SSH_USER}@${DROPLET_IP}"
echo "==> [LAB] Deploying SquidC5 (Docker) to ${SSH_USER}@${DROPLET_IP}"
ssh -o StrictHostKeyChecking=accept-new "${SSH_USER}@${DROPLET_IP}" bash -s <<'REMOTE'
set -euo pipefail
@@ -41,13 +42,14 @@ docker compose down || true
docker compose up --build -d
sleep 5
docker compose ps
echo "---- admin token ----"
docker compose exec -T squidc5 cat /data/admin_token.txt || \
docker exec squidc5 cat /data/admin_token.txt
echo "---- admin token (lab only; written once under data/) ----"
echo "(retrieve with: docker compose exec -T squidc5 cat /data/admin_token.txt)"
echo "---- health ----"
curl -sf http://127.0.0.1:8443/api/v1/health
curl -skf https://127.0.0.1:8443/api/v1/health || curl -sf http://127.0.0.1:8443/api/v1/health || true
echo
REMOTE
echo "==> Deployed: http://${DROPLET_IP}:8443"
echo " Docs: http://${DROPLET_IP}:8443/docs"
echo "==> Lab deploy: https://${DROPLET_IP}:8443/ops"
echo " Docs (GitHub): https://github.com/SquidSec/SquidC5/blob/master/docs/README.md"
echo " Note: server has no public /docs or OpenAPI (by design)."
echo " Prod path is binary-from-Release only — see docs/deployment.md"