Files
SquidSec-SquidC5/docker-compose.yml
T
Mr. The Plague c8e1dd4651 feat: shell stabilize toggle (default off) + one-click Stabilize
- shell_auto_stabilize default false (config, features, env, compose)
- Runtime auto controlled by feature flag; Admin feature checkboxes
- POST /sessions/{id}/stabilize: OS auto-detect Linux/Windows stage-2
- Context rail Stabilize shell button
2026-08-03 16:06:01 -04:00

49 lines
1.7 KiB
YAML

services:
squidc5:
build: .
image: squidc5:latest
container_name: squidc5
restart: unless-stopped
# Host networking so reverse-shell / TCP listeners can bind any host port
# (bridge mode only publishes ports listed under `ports:`).
network_mode: host
# Compose loads project `.env` for ${VAR} substitution (do not commit .env)
environment:
SQUIDC5_HOST: ${SQUIDC5_HOST:-0.0.0.0}
SQUIDC5_PORT: ${SQUIDC5_PORT:-8443}
SQUIDC5_DATA_DIR: ${SQUIDC5_DATA_DIR:-/data}
# Secure-by-default: MCP off until explicitly needed
SQUIDC5_MCP_ENABLED: ${SQUIDC5_MCP_ENABLED:-false}
SQUIDC5_AI_ENABLED: ${SQUIDC5_AI_ENABLED:-true}
SQUIDC5_SHELL_AUTO_STABILIZE: ${SQUIDC5_SHELL_AUTO_STABILIZE:-false}
SQUIDC5_EXPOSE_HEALTH_DETAILS: ${SQUIDC5_EXPOSE_HEALTH_DETAILS:-false}
SQUIDC5_SECURITY_HEADERS: ${SQUIDC5_SECURITY_HEADERS:-true}
# Stage-2 reconnect callback host - set in .env (never commit real IPs)
SQUIDC5_PUBLIC_HOST: ${SQUIDC5_PUBLIC_HOST:-}
# CORS empty by default - /ops is same-origin
volumes:
- squidc5-data:/data
healthcheck:
# TLS is on by default - match Dockerfile (unverified localhost probe)
test:
[
"CMD",
"python",
"-c",
"import ssl,urllib.request; ctx=ssl._create_unverified_context(); urllib.request.urlopen('https://127.0.0.1:8443/api/v1/health', timeout=3, context=ctx)",
]
interval: 30s
timeout: 5s
retries: 3
start_period: 20s
deploy:
resources:
limits:
cpus: "1.0"
memory: 512M
reservations:
memory: 128M
volumes:
squidc5-data: