mirror of
https://github.com/SquidSec/SquidC5
synced 2026-08-09 12:22:26 +00:00
docs: public-repo readiness — scrub private paths, fix links, CI notes
Remove personal OneDrive paths and wrong GitHub owner; document self-hosted CI for external contributors; fix env prefix table, deploy lab script, UFW guidance, pyproject URLs, and tighten gitignore for secrets.
This commit is contained in:
@@ -45,8 +45,13 @@ payloads/out/
|
||||
.secrets/
|
||||
admin_token.txt
|
||||
**/admin_token.txt
|
||||
implant_psk.txt
|
||||
**/implant_psk.txt
|
||||
*.pem
|
||||
!docs/**/*.pem
|
||||
data/*
|
||||
!data/.gitkeep
|
||||
# Local operator CLI config (contains tokens)
|
||||
.config/squidc5/
|
||||
**/squidc5/config.json
|
||||
**/config/squidc5/
|
||||
|
||||
@@ -50,9 +50,7 @@ When adding features: **deny by default**, enable via admin feature flags or env
|
||||
|
||||
## Development pipeline (mandatory)
|
||||
|
||||
Source of truth also: Windows SquidSec workspace
|
||||
`/mnt/c/Users/ynot_/OneDrive/Desktop/Company Data/SquidSec/AGENTS.md` + `knowledge-base/MEMORY.md`
|
||||
-> **Development cycles (git repos)**.
|
||||
Source of truth for this project: this repo’s **`AGENTS.md`**, **`docs/`**, and **`CONTRIBUTING.md`**.
|
||||
|
||||
### Git cycle (every change)
|
||||
|
||||
@@ -74,7 +72,7 @@ merge main -> CI builds Linux/Windows binaries -> GitHub Release published
|
||||
-> deploy Linux squidc5 binary ONLY (from Release assets or workflow Artifacts)
|
||||
```
|
||||
|
||||
Releases: `https://github.com/DotNetRussell/SquidC5/releases` (created by CI job `github-release` on main/master only).
|
||||
Releases: `https://github.com/SquidSec/SquidC5/releases` (created by CI job `github-release` on `master` only).
|
||||
|
||||
- **Never** commit/push straight to `main`/`master`
|
||||
- **Never** rsync WIP source or `docker compose up --build` to prod
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
# CLAUDE.md
|
||||
|
||||
**SquidC5 is a military-grade, security-first, AI-native C2 under active development** for authorized red team / pen-test use only.
|
||||
**SquidC5 is a security-first, AI-native C5 teamserver** (Command · Control · Cognitive · Collaborative · Coordination) under active development for authorized red team / pen-test use only.
|
||||
|
||||
Follow **[AGENTS.md](AGENTS.md)** as the primary agent memory for this repository.
|
||||
|
||||
|
||||
+3
-2
@@ -35,8 +35,9 @@ ruff check src tests
|
||||
|
||||
## CI
|
||||
|
||||
- **CI** workflow: pytest (3.11/3.12), ruff, Docker smoke, pip-audit, binaries on `master`.
|
||||
- **SquidGate** (`SquidSec/SquidGate@v1.0.0-build.4`): PR security gate. Set repository secret `LLM_API_KEY` to enable full analysis.
|
||||
- **CI** workflow: pytest (3.11/3.12), ruff, Docker smoke, pip-audit; Linux/Windows binaries + GitHub Release on push to `master`.
|
||||
- Workflows run on **SquidSec self-hosted runners** and only schedule jobs for **same-repo** PRs (fork code is not executed on org runners). If Actions looks empty on a fork PR, that is expected — run the local checks above and note results in the PR.
|
||||
- **SquidGate** (when configured): optional PR security gate via `SquidSec/SquidGate`. Repository secret `LLM_API_KEY` enables full analysis when available.
|
||||
|
||||
## Docs
|
||||
|
||||
|
||||
@@ -14,12 +14,11 @@
|
||||
</p>
|
||||
|
||||
<p align="center">
|
||||
<!-- Private repo: GitHub/shields status APIs return "not found" unauthenticated - static link badges only -->
|
||||
<a href="https://github.com/SquidSec/SquidC5/actions/workflows/ci.yml"><img src="https://img.shields.io/badge/CI-workflow-2088FF?logo=githubactions&logoColor=white" alt="CI"></a>
|
||||
<a href="https://github.com/SquidSec/SquidC5/actions/workflows/squidgate.yml"><img src="https://img.shields.io/badge/SquidGate-workflow-6f42c1?logo=githubactions&logoColor=white" alt="SquidGate"></a>
|
||||
<a href="https://github.com/SquidSec/SquidC5/releases"><img src="https://img.shields.io/badge/releases-GitHub-181717?logo=github&logoColor=white" alt="Releases"></a>
|
||||
<a href="https://github.com/SquidSec/SquidC5/actions/workflows/ci.yml"><img src="https://img.shields.io/github/actions/workflow/status/SquidSec/SquidC5/ci.yml?branch=master&label=CI&logo=githubactions&logoColor=white" alt="CI"></a>
|
||||
<a href="https://github.com/SquidSec/SquidC5/releases/latest"><img src="https://img.shields.io/github/v/release/SquidSec/SquidC5?label=release&logo=github" alt="Release"></a>
|
||||
<a href="https://www.python.org/downloads/"><img src="https://img.shields.io/badge/python-3.11%2B-blue" alt="Python"></a>
|
||||
<a href="LICENSE"><img src="https://img.shields.io/badge/license-MIT-green" alt="License"></a>
|
||||
<a href="https://github.com/SquidSec/SquidC5"><img src="https://img.shields.io/badge/C5-teamserver-e91e8c" alt="C5"></a>
|
||||
</p>
|
||||
|
||||
**Command / Control / Cognitive / Collaborative / Coordination**
|
||||
@@ -170,18 +169,18 @@ Docs follow [Diátaxis](https://diataxis.fr/): tutorials & how-tos (runbook/depl
|
||||
|
||||
## Configuration
|
||||
|
||||
See [.env.example](.env.example). Prefix `SQUIDC5_`.
|
||||
See [.env.example](.env.example). All settings use the **`SQUIDC5_`** prefix.
|
||||
|
||||
| Variable | Default | Notes |
|
||||
|----------|---------|--------|
|
||||
| `TLS_ENABLED` | `true` | HTTPS |
|
||||
| `MCP_ENABLED` | `false` | External AI tools |
|
||||
| `IMPLANT_REQUIRE_AUTH` | `true` | AEAD beacons |
|
||||
| `LOCAL_LLM_ENABLED` | `false` | Opt-in Ollama path |
|
||||
| `LOCAL_LLM_BASE_URL` | `http://127.0.0.1:11434/v1` | Ollama-compatible |
|
||||
| `LOCAL_LLM_MODEL` | `llama3.2` | Model id when enabled |
|
||||
| `RATE_LIMIT_PER_MINUTE` | `60` | Raise for ops UI (e.g. 600) |
|
||||
| `PUBLIC_HOST` | empty | Stage-2 / SOCKS data host |
|
||||
| `SQUIDC5_TLS_ENABLED` | `true` | HTTPS |
|
||||
| `SQUIDC5_MCP_ENABLED` | `false` | External AI tools |
|
||||
| `SQUIDC5_IMPLANT_REQUIRE_AUTH` | `true` | AEAD beacons |
|
||||
| `SQUIDC5_LOCAL_LLM_ENABLED` | `false` | Opt-in Ollama path |
|
||||
| `SQUIDC5_LOCAL_LLM_BASE_URL` | `http://127.0.0.1:11434/v1` | Ollama-compatible |
|
||||
| `SQUIDC5_LOCAL_LLM_MODEL` | `llama3.2` | Model id when enabled |
|
||||
| `SQUIDC5_RATE_LIMIT_PER_MINUTE` | `60` | Raise for ops UI (e.g. 600) |
|
||||
| `SQUIDC5_PUBLIC_HOST` | empty | Stage-2 / SOCKS data host |
|
||||
|
||||
## Security model
|
||||
|
||||
@@ -199,7 +198,9 @@ ruff check src tests
|
||||
# optional: cd agents/sc5beacon && go build .
|
||||
```
|
||||
|
||||
Git cycle: feature branch -> tests -> PR -> green CI -> merge `master`. Never push straight to master.
|
||||
Git cycle: feature branch → tests → PR → green CI → merge `master`. Never push straight to master.
|
||||
|
||||
**CI note:** org workflows run on SquidSec self-hosted runners and only execute same-repo PRs (fork PRs are not scheduled on those runners). External contributors should run `pytest -q` and `ruff check src tests` locally before opening a PR. See [CONTRIBUTING.md](CONTRIBUTING.md).
|
||||
|
||||
## About SquidSec
|
||||
|
||||
|
||||
+16
-2
@@ -96,14 +96,28 @@ sc5 listeners list # status running
|
||||
|
||||
### Context
|
||||
|
||||
Dedicated C2 lab host pattern: allow inbound so reverse-shell listener ports work without re-opening UFW each time. Only SSH + SquidC5 should listen publicly on a hardened prod host (tighten as required by your ROE).
|
||||
Dedicated lab host: open only the ports you need for SSH, the teamserver, and any reverse-shell / OAST listeners. **Never** copy a wide-open firewall policy to an internet-facing production host.
|
||||
|
||||
### Configuration
|
||||
|
||||
Lab-permissive example:
|
||||
**Hardened default (recommended):**
|
||||
|
||||
```bash
|
||||
ufw --force reset
|
||||
ufw default deny incoming
|
||||
ufw default allow outgoing
|
||||
ufw allow OpenSSH
|
||||
ufw allow 8443/tcp comment 'squidc5 teamserver'
|
||||
# add listener ports as needed, e.g.:
|
||||
# ufw allow 443/tcp comment 'rev shell / https front'
|
||||
ufw --force enable
|
||||
```
|
||||
|
||||
**Lab-only permissive** (isolated lab VMs — **not** for prod):
|
||||
|
||||
```bash
|
||||
# DANGEROUS on the public internet — lab VMs only
|
||||
ufw --force reset
|
||||
ufw default allow incoming
|
||||
ufw default allow outgoing
|
||||
ufw allow OpenSSH
|
||||
|
||||
@@ -16,7 +16,7 @@
|
||||
|
||||
## Mandatory git cycle (every change)
|
||||
|
||||
From SquidSec `AGENTS.md` + `knowledge-base/MEMORY.md` and SquidC5 `AGENTS.md`:
|
||||
From this repo’s [AGENTS.md](../AGENTS.md) and [CONTRIBUTING.md](../CONTRIBUTING.md):
|
||||
|
||||
1. Checkout and update `master` (pull latest).
|
||||
2. Create a **feature branch** named for the change only.
|
||||
|
||||
+9
-1
@@ -10,7 +10,7 @@ readme = "README.md"
|
||||
license = { text = "MIT" }
|
||||
requires-python = ">=3.11"
|
||||
authors = [{ name = "SquidC5 Contributors" }]
|
||||
keywords = ["c2", "red-team", "penetration-testing", "mcp", "security"]
|
||||
keywords = ["c5", "c2", "red-team", "penetration-testing", "mcp", "security"]
|
||||
classifiers = [
|
||||
"Development Status :: 3 - Alpha",
|
||||
"Intended Audience :: Information Technology",
|
||||
@@ -19,6 +19,14 @@ classifiers = [
|
||||
"Programming Language :: Python :: 3.12",
|
||||
"Topic :: Security",
|
||||
]
|
||||
|
||||
# Package version stays 0.1.x alpha; GitHub Releases (v0.1.<run>-<sha>) are the version of record for binaries.
|
||||
[project.urls]
|
||||
Homepage = "https://github.com/SquidSec/SquidC5"
|
||||
Documentation = "https://github.com/SquidSec/SquidC5/blob/master/docs/README.md"
|
||||
Repository = "https://github.com/SquidSec/SquidC5"
|
||||
"Bug Tracker" = "https://github.com/SquidSec/SquidC5/issues"
|
||||
Changelog = "https://github.com/SquidSec/SquidC5/blob/master/CHANGELOG.md"
|
||||
dependencies = [
|
||||
"fastapi>=0.115.0",
|
||||
"uvicorn[standard]>=0.32.0",
|
||||
|
||||
@@ -1,12 +1,13 @@
|
||||
#!/usr/bin/env bash
|
||||
# Deploy SquidC5 to a DigitalOcean droplet (Docker)
|
||||
# Lab-only: rsync source + Docker Compose to a cloud VM.
|
||||
# NOT for production. Prod = main CI squidc5 binary only (docs/deployment.md).
|
||||
set -euo pipefail
|
||||
|
||||
DROPLET_IP="${1:?Usage: $0 <droplet-ip> [ssh-user]}"
|
||||
DROPLET_IP="${1:?Usage: $0 <host-ip> [ssh-user]}"
|
||||
SSH_USER="${2:-root}"
|
||||
REMOTE_DIR="/opt/squidc5"
|
||||
|
||||
echo "==> Deploying SquidC5 to ${SSH_USER}@${DROPLET_IP}"
|
||||
echo "==> [LAB] Deploying SquidC5 (Docker) to ${SSH_USER}@${DROPLET_IP}"
|
||||
|
||||
ssh -o StrictHostKeyChecking=accept-new "${SSH_USER}@${DROPLET_IP}" bash -s <<'REMOTE'
|
||||
set -euo pipefail
|
||||
@@ -41,13 +42,14 @@ docker compose down || true
|
||||
docker compose up --build -d
|
||||
sleep 5
|
||||
docker compose ps
|
||||
echo "---- admin token ----"
|
||||
docker compose exec -T squidc5 cat /data/admin_token.txt || \
|
||||
docker exec squidc5 cat /data/admin_token.txt
|
||||
echo "---- admin token (lab only; written once under data/) ----"
|
||||
echo "(retrieve with: docker compose exec -T squidc5 cat /data/admin_token.txt)"
|
||||
echo "---- health ----"
|
||||
curl -sf http://127.0.0.1:8443/api/v1/health
|
||||
curl -skf https://127.0.0.1:8443/api/v1/health || curl -sf http://127.0.0.1:8443/api/v1/health || true
|
||||
echo
|
||||
REMOTE
|
||||
|
||||
echo "==> Deployed: http://${DROPLET_IP}:8443"
|
||||
echo " Docs: http://${DROPLET_IP}:8443/docs"
|
||||
echo "==> Lab deploy: https://${DROPLET_IP}:8443/ops"
|
||||
echo " Docs (GitHub): https://github.com/SquidSec/SquidC5/blob/master/docs/README.md"
|
||||
echo " Note: server has no public /docs or OpenAPI (by design)."
|
||||
echo " Prod path is binary-from-Release only — see docs/deployment.md"
|
||||
|
||||
Reference in New Issue
Block a user