mirror of
https://github.com/SquidSec/SquidC5
synced 2026-08-09 12:22:26 +00:00
- shell_auto_stabilize default false (config, features, env, compose)
- Runtime auto controlled by feature flag; Admin feature checkboxes
- POST /sessions/{id}/stabilize: OS auto-detect Linux/Windows stage-2
- Context rail Stabilize shell button
49 lines
1.7 KiB
YAML
49 lines
1.7 KiB
YAML
services:
|
|
squidc5:
|
|
build: .
|
|
image: squidc5:latest
|
|
container_name: squidc5
|
|
restart: unless-stopped
|
|
# Host networking so reverse-shell / TCP listeners can bind any host port
|
|
# (bridge mode only publishes ports listed under `ports:`).
|
|
network_mode: host
|
|
# Compose loads project `.env` for ${VAR} substitution (do not commit .env)
|
|
environment:
|
|
SQUIDC5_HOST: ${SQUIDC5_HOST:-0.0.0.0}
|
|
SQUIDC5_PORT: ${SQUIDC5_PORT:-8443}
|
|
SQUIDC5_DATA_DIR: ${SQUIDC5_DATA_DIR:-/data}
|
|
# Secure-by-default: MCP off until explicitly needed
|
|
SQUIDC5_MCP_ENABLED: ${SQUIDC5_MCP_ENABLED:-false}
|
|
SQUIDC5_AI_ENABLED: ${SQUIDC5_AI_ENABLED:-true}
|
|
SQUIDC5_SHELL_AUTO_STABILIZE: ${SQUIDC5_SHELL_AUTO_STABILIZE:-false}
|
|
SQUIDC5_EXPOSE_HEALTH_DETAILS: ${SQUIDC5_EXPOSE_HEALTH_DETAILS:-false}
|
|
SQUIDC5_SECURITY_HEADERS: ${SQUIDC5_SECURITY_HEADERS:-true}
|
|
# Stage-2 reconnect callback host - set in .env (never commit real IPs)
|
|
SQUIDC5_PUBLIC_HOST: ${SQUIDC5_PUBLIC_HOST:-}
|
|
# CORS empty by default - /ops is same-origin
|
|
volumes:
|
|
- squidc5-data:/data
|
|
healthcheck:
|
|
# TLS is on by default - match Dockerfile (unverified localhost probe)
|
|
test:
|
|
[
|
|
"CMD",
|
|
"python",
|
|
"-c",
|
|
"import ssl,urllib.request; ctx=ssl._create_unverified_context(); urllib.request.urlopen('https://127.0.0.1:8443/api/v1/health', timeout=3, context=ctx)",
|
|
]
|
|
interval: 30s
|
|
timeout: 5s
|
|
retries: 3
|
|
start_period: 20s
|
|
deploy:
|
|
resources:
|
|
limits:
|
|
cpus: "1.0"
|
|
memory: 512M
|
|
reservations:
|
|
memory: 128M
|
|
|
|
volumes:
|
|
squidc5-data:
|