Go to file
CyberMind 355767935c
Round image: drop dead ifupdown config, give secubox sudo, fix misleading OTG comment (closes #139) (#143)
* fix(round): remove dead ifupdown config + secubox sudo + clarify gadget IP comment (closes #139)

Three small cleanups against the round image, all triggered by the
follow-up to PR #137's OTG bench:

1. Drop `remote-ui/round/files/etc/network/interfaces.d/usb0` — the
   stanza configured `usb0` via `ifupdown`, but `ifupdown` is not in
   the apt list, `networking.service` is inactive, and the actual IP
   binding happens in `secubox-otg-gadget.sh` (which configures `usb1`
   programmatically with `ip addr add`). Keeping the file on disk
   misleads diagnostics — it cost a round trip during the 2026-05-15
   bench when I assumed `usb0`/10.55.0.2 must be where the IP would
   land. Deleting it.

2. Add `sudo` to the `secubox` user's group list in
   `build-eye-remote-image.sh`. Without it, ACM serial console
   recovery is impossible — the user can log in but can't fix
   anything. The round previously needed `pi/raspberry` (which the
   build script does not provision) as a fallback; now `secubox` can
   recover networking from the only path that survives a broken IP
   link.

3. Rewrite the misleading comment block in `secubox-otg-gadget.sh`
   about which kernel interface name belongs to which gadget function.
   The legacy comment claimed `usb1 = ECM` and tied the binding choice
   to "Linux uses cdc_ether"; in reality both RNDIS and ECM share the
   same host_addr so the host can reach 10.55.0.2 via either function
   (verified on Pop!_OS 22.04 host: ping succeeded with 10.55.0.1
   bound on the host's RNDIS leg). Comment now states the actual
   contract: bind on `usb1` (the second-registered network function),
   independent of which transport carries the packets.

Test plan
---------

- [ ] Rebuild the round image and flash to Pi Zero W 1st gen.
- [ ] Verify boot still reaches OFFLINE-mode radar on the HyperPixel.
- [ ] `id secubox` on the booted device shows `sudo` in groups.
- [ ] `ls /etc/network/interfaces.d/usb0` returns "no such file".
- [ ] `systemctl is-active secubox-otg-gadget` returns `active`.
- [ ] Host ping 10.55.0.2 succeeds (regression check — the comment
      rewrite is documentation-only, must not change behaviour).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(round): also drop inline heredoc that recreates dead ifupdown stanza (ref #139)

The previous commit deleted remote-ui/round/files/etc/network/interfaces.d/usb0
but missed that build-eye-remote-image.sh writes the same file inline at
build time via heredoc. Without removing that block too, the dead config
keeps shipping to the rootfs.

Verified on the just-rebuilt image: file still present after first
attempt at the fix. With both source-tree deletion AND the heredoc gone,
the config never lands.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: CyberMind-FR <gandalf@Gk2.net>
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-15 13:26:32 +02:00
.claude docs(wip): expand #135/PR #140 with this session's fixups + hardware bench 2026-05-15 13:22:04 +02:00
.github/workflows feat(remote-ui): Phase 1 — extract common/ shared core (ref #127) 2026-05-14 05:59:40 +02:00
.superpowers/brainstorm/1465198-1777214258
.vscode
apt
board
cache/repo
cmd/secubox
common
config
daemon
docs docs: Phase 1 rollback recipe (pre-issue) 2026-05-15 13:16:16 +02:00
doctrine/opad
hardware
image
kernel-build
packages Mail stack: Phase 1 — source-catch-up + legacy package cleanup (#141) 2026-05-15 13:26:21 +02:00
profiles
prototypes
redroid
remote-ui Round image: drop dead ifupdown config, give secubox sudo, fix misleading OTG comment (closes #139) (#143) 2026-05-15 13:26:32 +02:00
repo
schemas
scripts
templates
tests Mail stack: Phase 1 — source-catch-up + legacy package cleanup (#141) 2026-05-15 13:26:21 +02:00
tools
vm
wiki
.gitignore
build-eye-remote-full.sh
CLAUDE.md
LICENCE-CMSD-1.0.md
LICENSE-CMSD-1.0.en.md
LICENSING.md
PROMPT_SYSTEM.md
pytest.ini
README.md
REPORT-2026-04-10.md
secubox.conf.example
setup-dev.sh
TOOLS.md

SecuBox

SecuBox OS - Network Security Appliance

Your Network Security Appliance — Plug, Protect, Peace of Mind

Release Packages Live USB Installer License: CMSD-1.0


License — CyberMind Source-Disclosed (CMSD-1.0)

Source disclosed, rights reserved.

This software is released under the CyberMind Source-Disclosed License v1.0 — a source-available license designed for transparency and security auditability while preserving all commercial rights.

What you CAN do What you CANNOT do
Read and study the source code Use in production (any environment)
Compile for isolated testing/audit Redistribute or create derivatives
Publish security research results Integrate into other products
Quote in academic/journalistic contexts Provide as hosted service (SaaS)

ANSSI CSPN Ready: The license explicitly authorizes audits by accredited security labs (CESTI, CC equivalents) without prior authorization.

See LICENCE-CMSD-1.0.md (French, authoritative) or LICENSE-CMSD-1.0.en.md (English, informative).

Metric Value
Packages 131 .deb packages
Migration 123/131 modules migrated
APIs FastAPI + JWT auth
![Arch](https://img.shields.io/badge/Architecture-amd64_ _arm64-orange)

SecuBox transforms any compatible device into a complete network security appliance with VPN, firewall, intrusion detection, and web dashboard — all preconfigured and ready to use.


What You Get

  • VPN Server — WireGuard with QR codes for mobile devices
  • Intrusion Detection — CrowdSec IDS/IPS with automatic threat blocking
  • Network Monitoring — Real-time traffic analysis and bandwidth control
  • Web Dashboard — Modern dark-themed interface accessible from any browser
  • Automatic Updates — Security patches applied automatically

Quick Start

Option 1: VirtualBox (Try It Now)

Download and run in VirtualBox — no hardware required:

# Download the image
wget https://github.com/CyberMind-FR/secubox-deb/releases/latest/download/secubox-live-amd64-bookworm.img.gz

# Extract
gunzip secubox-live-amd64-bookworm.img.gz

# Create VM (requires VBoxManage)
./scripts/create-secubox-vm.sh secubox-live-amd64-bookworm.img

Access: Open https://localhost:9443 in your browser Login: admin / secubox

Option 2: Live USB (Any PC)

Boot from USB on any x86_64 computer:

# Download
wget https://github.com/CyberMind-FR/secubox-deb/releases/latest/download/secubox-live-amd64-bookworm.img.gz

# Flash to USB (replace /dev/sdX with your USB device)
zcat secubox-live-amd64-bookworm.img.gz | sudo dd of=/dev/sdX bs=4M status=progress

Boot from USB, then access the dashboard at https://<device-ip>/

Option 3: Dedicated Hardware

For 24/7 operation, flash to dedicated hardware:

Device Best For Image
Raspberry Pi 4/5 Home use secubox-rpi-arm64-*.img.gz
ESPRESSObin Small office secubox-espressobin-v7-*.img.gz
MOCHAbin Enterprise secubox-mochabin-*.img.gz
Any x86_64 PC Repurposed hardware secubox-live-amd64-*.img.gz

Features

Security Dashboard

Central control panel showing system health, active threats, and quick actions.

VPN (WireGuard)

Create VPN connections with one click. Scan QR codes on mobile devices.

Intrusion Detection (CrowdSec)

Automatic threat detection and IP blocking with community threat intelligence.

Network Control

  • Bandwidth management (QoS)
  • Device access control
  • Deep packet inspection
  • Virtual hosts with SSL

System Management

  • Service control
  • Log viewer
  • Automatic backups
  • Easy updates

Eye Remote — External Dashboard

SecuBox Eye Remote

A standalone round display that connects to SecuBox via USB OTG, showing real-time metrics with a cyberpunk 3D visualization.

Feature Description
Hardware Raspberry Pi Zero W + HyperPixel 2.1 Round (480×480)
Connection USB OTG composite gadget (network + serial)
Display 3D rotating cube + rainbow ring metrics
Metrics CPU, Memory, Disk, Temperature, WiFi RSSI

Quick Start

# Download Eye Remote image
wget https://github.com/CyberMind-FR/secubox-deb/releases/download/v2.2.1-eye-remote/secubox-eye-remote-2.2.1.img.xz

# Flash to SD card
xzcat secubox-eye-remote-2.2.1.img.xz | sudo dd of=/dev/sdX bs=4M status=progress
  1. Insert SD in Pi Zero W with HyperPixel display
  2. Connect USB DATA port (middle) to SecuBox
  3. Dashboard appears automatically (~60s boot)

SSH: pi@10.55.0.2 (password: raspberry)

📖 Full documentation: remote-ui/round/README.md


Default Credentials

Service Username Password
Web Dashboard admin secubox
SSH root secubox

Change these immediately after first login!


Support


License

CMSD-1.0 (CyberMind Source-Disclosed License) © 2026 CyberMind · Gérald Kerma See LICENCE-CMSD-1.0.md for terms.


Technical Reference (Click to Expand)

Architecture

OpenWrt / LuCI                   →    Debian bookworm
─────────────────────────────────────────────────────────
RPCD shell backend               →    FastAPI + Uvicorn (Unix socket)
UCI config /etc/config/          →    TOML /etc/secubox/secubox.conf
luci-app-*/htdocs/ (JS/CSS/HTML) →    Conservé + XHR réécrits
OpenWrt packages (.ipk)          →    Paquets Debian (.deb)
opkg                             →    apt + repo apt.secubox.in

Supported Hardware

Board SoC RAM Network Profile
MOCHAbin Armada 7040 Quad 1.8GHz 4 GB 2× SFP+ 10GbE + 4× GbE Pro
ESPRESSObin v7 Armada 3720 Dual 1.2GHz 12 GB WAN + 2× LAN DSA Lite
ESPRESSObin Ultra Armada 3720 Dual 1.2GHz 2 GB WAN PoE + 4× LAN + Wi-Fi Lite+
Raspberry Pi 4/400 BCM2711 Quad 1.5-1.8GHz 2-8 GB GbE + USB Lite
Raspberry Pi 5 BCM2712 Quad 2.4GHz 4-8 GB GbE + USB Full
VM x86_64 Any 2+ GB Virtio/NAT Full

Packages (126 modules)

Core: secubox-core, secubox-hub, secubox-portal, secubox-system

Security: secubox-crowdsec, secubox-wireguard, secubox-auth, secubox-nac, secubox-waf, secubox-users

Network: secubox-netmodes, secubox-dpi, secubox-qos, secubox-vhost, secubox-haproxy

Monitoring: secubox-netdata, secubox-mediaflow, secubox-cdn

DNS/Email: secubox-dns, secubox-mail, secubox-webmail

Publishing: secubox-droplet, secubox-streamlit, secubox-metablogizer, secubox-publish

API Reference

All modules expose REST APIs at /api/v1/<module>/

# Login
curl -X POST https://localhost/api/v1/portal/login \
  -H 'Content-Type: application/json' \
  -d '{"username":"admin","password":"secubox"}'

# Use token
curl https://localhost/api/v1/hub/status \
  -H 'Authorization: Bearer <token>'

Key Endpoints:

  • GET /api/v1/hub/dashboard — Dashboard data
  • GET /api/v1/crowdsec/decisions — Active bans
  • POST /api/v1/crowdsec/ban — Ban IP
  • GET /api/v1/wireguard/peers — VPN peers
  • GET /api/v1/wireguard/qrcode/{peer} — Peer QR code

Configuration

Main config: /etc/secubox/secubox.conf (TOML)

[general]
hostname = "secubox"
timezone = "Europe/Paris"

[auth]
jwt_secret = "your-secret-key"
session_timeout = 86400

[network]
wan_interface = "eth0"
lan_interface = "eth1"

Development

# Setup
bash setup-dev.sh && source .venv/bin/activate

# Run module API
cd packages/secubox-crowdsec
uvicorn api.main:app --reload --port 8001

# Build package
dpkg-buildpackage -us -uc -b

# Build image
sudo bash image/build-image.sh --board vm-x64 --vdi

UI Design Guidelines

Color Palette (Cyberpunk/Hermetic):

Variable Color Usage
--cosmos-black #0a0a0f Background
--gold-hermetic #c9a84c Accents, titles
--cinnabar #e63946 Alerts, errors
--matrix-green #00ff41 Success
--void-purple #6e40c9 Links
--cyber-cyan #00d4ff Info, hover
--text-primary #e8e6d9 Main text

Typography: Cinzel (titles), IM Fell English (body), JetBrains Mono (code)

Documentation