Repository navigation
Harden HoneySAP core lifecycle, event delivery, and Docker-first deployment - #14
Merged
Merged
Conversation
martingalloar
commented
Sep 21, 2026
Collaborator
- Harden configuration loading and startup:
- redact sensitive configuration values in logs;
- use restricted YAML loading;
- validate listener topology before launch;
- apply gevent monkey-patching at process startup.
- Improve event, session, and feed reliability:
- preserve binary evidence unambiguously in serialized events;
- add schema version, event ID, sequence, UTC timestamp, and campaign correlation;
- bound event/session/campaign retention and expose queue metrics;
- isolate feed delivery so one failing or slow feed does not block others.
- Improve routed and forwarded traffic handling:
- retain exact SAPRouter → Forwarder lineage through parent_session;
- add bounded concurrent relays shared by direct and virtual Forwarder paths;
- track active forwarding sockets for orderly shutdown;
- document how to interpret session, campaign, and parent_session.
- Refresh deployment and documentation:
- remove Vagrant/Ansible deployment paths in favor of Docker;
- align Docker Compose, Dockerfile, internal profile, and Message Server HTTP-to-ICM redirects;
- replace the static architecture asset with a generated diagram;
- add concise architecture, service-selection, event interpretation, and installation guidance.
- Add bounded session/feed queues, event metadata, safe config handling, topology validation, and entrypoint-only gevent patching. Isolate forwarder sessions and normalize DB event timestamps. - Bound session and campaign state, preflight service topology, scope DataStore contents, redact configuration-derived logs, and make logger setup idempotent. Add unique feed metrics and introduce event schema v1 with robust typed evidence serialization. - Bound service shutdown, isolate component configuration, add feed failure backoff, improve configuration diagnostics and include restrictions, and dispatch DataStore watchers asynchronously with bounded queues.
- Removed Vagrand and Ansible deploys since those were no longer maintained - Updated internal profile and docker componse definition
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.