Skip to content

Harden HoneySAP core lifecycle, event delivery, and Docker-first deployment - #14

Merged
martingalloar merged 6 commits into
master-0.2-devfrom
master-0.2-hardening
Sep 21, 2026
Merged

martingalloar merged 6 commits into
master-0.2-devfrom
master-0.2-hardening

Conversation

@martingalloar

Copy link
Copy Markdown
Collaborator
  • Harden configuration loading and startup:
    • redact sensitive configuration values in logs;
    • use restricted YAML loading;
    • validate listener topology before launch;
    • apply gevent monkey-patching at process startup.
  • Improve event, session, and feed reliability:
    • preserve binary evidence unambiguously in serialized events;
    • add schema version, event ID, sequence, UTC timestamp, and campaign correlation;
    • bound event/session/campaign retention and expose queue metrics;
    • isolate feed delivery so one failing or slow feed does not block others.
  • Improve routed and forwarded traffic handling:
    • retain exact SAPRouter → Forwarder lineage through parent_session;
    • add bounded concurrent relays shared by direct and virtual Forwarder paths;
    • track active forwarding sockets for orderly shutdown;
    • document how to interpret session, campaign, and parent_session.
  • Refresh deployment and documentation:
    • remove Vagrant/Ansible deployment paths in favor of Docker;
    • align Docker Compose, Dockerfile, internal profile, and Message Server HTTP-to-ICM redirects;
    • replace the static architecture asset with a generated diagram;
    • add concise architecture, service-selection, event interpretation, and installation guidance.

- Add bounded session/feed queues, event metadata, safe config handling,
topology validation, and entrypoint-only gevent patching. Isolate
forwarder sessions and normalize DB event timestamps.
- Bound session and campaign state, preflight service topology, scope
DataStore contents, redact configuration-derived logs, and make logger
setup idempotent. Add unique feed metrics and introduce event schema v1
with robust typed evidence serialization.
- Bound service shutdown, isolate component configuration, add feed failure
backoff, improve configuration diagnostics and include restrictions, and
dispatch DataStore watchers asynchronously with bounded queues.
- Removed Vagrand and Ansible deploys since those were no longer maintained
- Updated internal profile and docker componse definition
@martingalloar martingalloar self-assigned this Sep 21, 2026
@martingalloar
martingalloar merged commit 7249c3f into master-0.2-dev Sep 21, 2026
20 checks passed
@martingalloar
martingalloar deleted the master-0.2-hardening branch September 22, 2026 19:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant