No description
| python | ||
| .gitignore | ||
| deploy.sh | ||
| JUMP_SERVER.md | ||
| README.md | ||
| setup.sh | ||
Wallarm Node Manager
Single-binary deployment and management for Wallarm filtering nodes. Interactive menu, multi-instance, zero runtime dependencies.
Quick Start
curl -fsSL "https://git.sechpoint.app/customer-engineering/wallarm/raw/branch/main/setup.sh" | bash
sudo /opt/fw/deploy
Commands
/opt/fw/deploy Interactive menu
/opt/fw/deploy --deploy-all Deploy all nodes from fw.conf
/opt/fw/deploy --version Show version
Menu
─── Main Menu ───
[1] Deploy a node
[2] Edit a node
[3] Show status
[4] Remove a node
[5] Remote tunnel
[6] Dashboard (TUI)
[q] Quit
Configuration
Node configuration is stored in /opt/fw/fw.conf:
{
"nodes": {
"srv1": {
"token": "...",
"cloud": "EU",
"port": "8081",
"upstream_ip": "10.1.0.10",
"upstream_port": "8081",
"labels": "group=srv1",
"mode": "monitoring"
}
}
}
Modes: monitoring, safe_blocking, block, off.
Architecture
cmd/deploy/main.go Entry point — menu, deploy, edit, remove
internal/
native/ Node deployment, systemd, nginx
preflight/ System checks (14)
state/ /opt/fw/state.json persistence
tunnel/ Reverse SSH over TLS:443
ui/ Bubbletea TUI (dashboard)
shared/ Validation, connectivity
setup.sh Bootstrap — clones repo, builds binary
Makefile Cross-compile targets
Directory Layout
/opt/fw/
├── deploy Go binary
├── fw.conf Node configuration (JSON)
├── state.json Deployment state
├── {name}/wallarm/ Per-instance files
│ ├── nginx/ Instance NGINX
│ ├── modules/ Wallarm modules
│ ├── etc/ Wallarm config
│ └── ...
└── wallarm-aio.sh Cached Wallarm installer
Requirements
- Linux with systemd
- x86_64 or aarch64
- 2GB+ RAM, 10GB+ disk
- Outbound to api.wallarm.com (EU) or us1.api.wallarm.com (US)
Remote Assistance
See JUMP_SERVER.md for jump server setup.