mirror of
https://github.com/CyberMind-FR/secubox-deb.git
synced 2026-07-29 16:37:04 +00:00
Foundation to replace Authelia with SecuBox's own users (reuses the argon2 user_store; those hashes can't feed nginx Basic auth, but a verify endpoint can validate them). Source-only — no live cutover yet. - auth.py: /login now also sets an HttpOnly, parent-domain-scoped session cookie (secubox_session = the JWT). New GET /auth/verify validates the cookie (or Bearer) via the same checks as require_jwt and echoes Remote-User/Remote-Groups for the proxied app (200 allow / 401 deny). New POST /auth/logout clears the cookie. - secubox.conf.example: api.sso_cookie_domain (parent domain, e.g. ".gk2.secubox.in"; empty = host-only). Remaining for #400 (follow-up, careful + board-specific): confirm which socket serves /auth/verify given secubox-auth overrides /login; ship the nginx auth_request snippet with the real SecuBox login-page redirect; live cutover one vhost first (lyrion/zigbee) then all; stop+disable Authelia.
187 lines
8.4 KiB
Plaintext
187 lines
8.4 KiB
Plaintext
# /etc/secubox/secubox.conf — Configuration SecuBox-DEB
|
||
# Format TOML — généré par firstboot.sh, éditable ensuite
|
||
# Recharger : systemctl restart secubox-\*
|
||
|
||
# ── Global ────────────────────────────────────────────────────────
|
||
[global]
|
||
hostname = "secubox-01"
|
||
timezone = "Europe/Paris"
|
||
board = "mochabin" # mochabin | espressobin-v7 | espressobin-ultra
|
||
debug = false
|
||
log_level = "warning" # debug | info | warning | error
|
||
|
||
# ── API / Auth ────────────────────────────────────────────────────
|
||
[api]
|
||
socket_dir = "/run/secubox" # Dossier des Unix sockets
|
||
jwt_secret = "" # Généré au firstboot — ne pas modifier
|
||
# SSO-lite (#400): domaine parent du cookie de session pour le gating
|
||
# nginx auth_request (/auth/verify) — un seul login couvre tous les vhosts
|
||
# *.<domaine>. Vide = cookie host-only. Ex: ".gk2.secubox.in"
|
||
sso_cookie_domain = ""
|
||
|
||
# Utilisateurs locaux (fallback si pas d'OAuth)
|
||
[auth]
|
||
|
||
[auth.users.admin]
|
||
password = "secubox" # À changer impérativement !
|
||
# password_hash = "$2b$12$..." # bcrypt recommandé (TODO Phase 5)
|
||
|
||
# ── CrowdSec ──────────────────────────────────────────────────────
|
||
[crowdsec]
|
||
lapi_url = "http://127.0.0.1:8080"
|
||
lapi_key = "" # Généré par : cscli bouncers add secubox-bouncer
|
||
|
||
# ── DPI / netifyd ─────────────────────────────────────────────────
|
||
[dpi]
|
||
mode = "inline" # inline | passive
|
||
engine = "netifyd" # netifyd | ndpid
|
||
interface = "eth0" # Interface à surveiller (WAN)
|
||
mirror_if = "ifb0" # Interface miroir pour DPI inline
|
||
|
||
# ── WireGuard ─────────────────────────────────────────────────────
|
||
[wireguard]
|
||
interface = "wg0"
|
||
listen_port = 51820
|
||
|
||
# ── NAC / DHCP ────────────────────────────────────────────────────
|
||
[nac]
|
||
dhcp_interface = "br-lan"
|
||
dhcp_range = "192.168.1.100,192.168.1.254,12h"
|
||
dns_servers = ["9.9.9.9", "149.112.112.112"]
|
||
# Zones : lan_allowed, iot_zone, guest_zone, quarantine
|
||
default_zone = "quarantine" # Nouveaux clients en quarantaine par défaut
|
||
|
||
# ── QoS / Bandwidth ───────────────────────────────────────────────
|
||
[qos]
|
||
interface = "eth0" # Interface WAN pour le shaping
|
||
upload_mbps = 100
|
||
download_mbps = 200
|
||
enabled = false
|
||
|
||
# ── CDN Cache ─────────────────────────────────────────────────────
|
||
[cdn]
|
||
engine = "nginx" # nginx | squid
|
||
cache_dir = "/var/cache/secubox-cdn"
|
||
cache_size = "5g"
|
||
listen_port = 3128
|
||
|
||
# ── VirtualHosts ──────────────────────────────────────────────────
|
||
[vhost]
|
||
nginx_sites_dir = "/etc/nginx/sites-available"
|
||
certbot_email = "admin@example.com"
|
||
default_ssl_mode = "selfsigned" # selfsigned | letsencrypt
|
||
|
||
# ── OAuth2 providers (secubox-auth) ───────────────────────────────
|
||
[oauth]
|
||
# [oauth.google]
|
||
# client_id = ""
|
||
# client_secret = ""
|
||
|
||
# [oauth.github]
|
||
# client_id = ""
|
||
# client_secret = ""
|
||
|
||
# ── Réseau modes ──────────────────────────────────────────────────
|
||
[netmodes]
|
||
current_mode = "router"
|
||
backup_dir = "/var/lib/secubox/netmodes-backup"
|
||
confirm_timeout = 300 # Secondes avant rollback auto si pas confirmé
|
||
|
||
# ── Notifications ─────────────────────────────────────────────────
|
||
[notifications]
|
||
# [notifications.email]
|
||
# smtp_host = "smtp.example.com"
|
||
# smtp_port = 587
|
||
# from = "secubox@example.com"
|
||
# to = "admin@example.com"
|
||
|
||
# [notifications.webhook]
|
||
# url = "https://hooks.example.com/secubox"
|
||
# secret = ""
|
||
|
||
# ── Remote UI / HyperPixel Dashboard ─────────────────────────────
|
||
# Configuration du dashboard kiosk HyperPixel 2.1 Round (480×480 px)
|
||
# sur RPi Zero W — Affichage des métriques SecuBox en temps réel.
|
||
#
|
||
# Déploiement :
|
||
# bash remote-ui/round/deploy.sh -h <rpi-ip> --api-url http://<secubox-ip>:8000
|
||
#
|
||
# Service systemd sur le RPi : secubox-remote-ui.service
|
||
# Ressources limitées : MemoryMax=256M, CPUQuota=80%
|
||
[remote_ui]
|
||
enabled = true
|
||
api_base = "/api/v1/system" # Endpoint métriques (servi par secubox-system)
|
||
refresh_ms = 5000 # Intervalle de rafraîchissement (ms)
|
||
simulate = false # Mode simulation (données fictives)
|
||
|
||
# Seuils d'alerte — CPU (%)
|
||
[remote_ui.thresholds.cpu]
|
||
warn = 70 # Niveau warning
|
||
crit = 85 # Niveau critique
|
||
|
||
# Seuils d'alerte — Mémoire (%)
|
||
[remote_ui.thresholds.mem]
|
||
warn = 75
|
||
crit = 90
|
||
|
||
# Seuils d'alerte — Disque (%)
|
||
[remote_ui.thresholds.disk]
|
||
warn = 80
|
||
crit = 95
|
||
|
||
# Seuils d'alerte — Température CPU (°C)
|
||
[remote_ui.thresholds.temp]
|
||
warn = 65
|
||
crit = 75
|
||
|
||
# Seuils d'alerte — WiFi RSSI (dBm, valeurs négatives)
|
||
[remote_ui.thresholds.wifi]
|
||
warn = -70 # Signal faible
|
||
crit = -80 # Signal critique
|
||
|
||
# Mapping services SecuBox vers les anneaux du dashboard
|
||
# Ordre : centre vers extérieur = AUTH → WALL → BOOT → MIND → ROOT → MESH
|
||
[remote_ui.modules]
|
||
AUTH = "secubox-auth" # Authentification / SSO
|
||
WALL = "secubox-crowdsec" # WAF / IDS / CrowdSec
|
||
BOOT = "secubox-hub" # Dashboard principal
|
||
MIND = "secubox-ai-insights" # IA / Insights
|
||
ROOT = "secubox-system" # Système / Métriques
|
||
MESH = "secubox-p2p" # Réseau mesh P2P
|
||
|
||
# Palette de couleurs (hex)
|
||
[remote_ui.colors]
|
||
AUTH = "#C04E24" # Rouge-orange
|
||
WALL = "#9A6010" # Bronze
|
||
BOOT = "#803018" # Marron foncé
|
||
MIND = "#3D35A0" # Violet/indigo
|
||
ROOT = "#0A5840" # Vert foncé
|
||
MESH = "#104A88" # Bleu marine
|
||
|
||
# ─────────────────────────────────────────────────────────────────────────────
|
||
# Cookie Audit (issue #156) — RGPD / ePrivacy compliance reconciler
|
||
# ─────────────────────────────────────────────────────────────────────────────
|
||
# When enabled, the mitmproxy cookie_audit addon writes a JSONL ledger of
|
||
# every Set-Cookie observed in transit, and the secubox-metrics
|
||
# CookieAuditAggregator reconciles it against browser snapshots posted to
|
||
# /api/v1/cookie-audit/ingest.
|
||
[cookie_audit]
|
||
enabled = false
|
||
ledger_path = "/var/log/secubox/cookie-audit/server.jsonl"
|
||
ingest_dir = "/var/lib/secubox/cookie-audit/ingest"
|
||
max_ingest_age_hours = 24
|
||
# When true, the operator patterns below REPLACE the built-in RGPD baseline.
|
||
# When false (default), they are merged on top — admins can extend but never
|
||
# silently drop the baseline.
|
||
classifier_override = false
|
||
|
||
# Custom classification patterns. Each list is matched (re.search) against
|
||
# the cookie name, in this order: strictly_necessary > functional > analytics
|
||
# > marketing. First match wins. Unmatched names land in "unclassified" and
|
||
# get flagged for review.
|
||
[cookie_audit.classifier]
|
||
# strictly_necessary = ["^app_session$"]
|
||
# functional = ["^app_theme$"]
|
||
# analytics = ["^my_analytics_"]
|
||
# marketing = ["^my_ad_id$"]
|