wallarm/README.md
admin 157373ea16 refactor: rename wallarm → deploy, deploy.sh → setup.sh
- setup.sh bootstraps /opt/wallarm/ structure, builds deploy binary
- deploy binary at /opt/wallarm/deploy (renamed from wallarm)
- /opt/wallarm/source/ — Go source for local rebuilds
- /opt/wallarm/nodes/{instance}/ — per-node directories
- cmd/deploy/main.go replaces cmd/wallarm/main.go
2026-08-01 15:39:56 +00:00

90 lines
2.8 KiB
Markdown

# Wallarm Native Node Manager
Single-binary deployment and management for Wallarm Native Nodes (connector mode, no Docker).
One command to get started, one TUI to manage everything.
## Quick Start
```bash
curl -fsSL "https://git.sechpoint.app/customer-engineering/wallarm/raw/branch/main/setup.sh" | bash
sudo /opt/wallarm/deploy
```
That's it. The binary runs preflight checks, then opens an interactive TUI:
- **First run**: configuration wizard (cloud region, API token, node name, listen address)
- **Subsequent runs**: dashboard with node list, add/remove/configure actions
## Features
- **Single binary** — 2MB, zero runtime dependencies, works on any Linux
- **Interactive TUI** — bubbletea-powered forms and dashboard
- **Preflight checks** — runs on every start: system, network, cloud reachability, resources
- **Multi-node** — manage multiple Wallarm nodes on the same host via systemd
- **Remote tunnel** — `wallarm --tunnel` opens a reverse SSH tunnel over TLS:443 via Zoraxy
- **State persistence** — `~/.wallarm/state.json` tracks all deployments
## Commands
```
deploy Interactive TUI (wizard or dashboard)
deploy --tunnel Start reverse SSH tunnel to sechpoint.app
deploy --version Show version
deploy --help Show help
```
## Dashboard
```
📊 Wallarm Dashboard
Type: native | Cloud: EU (api.wallarm.com)
──────────────────────────────────────────────────
Nodes:
● srv1 — running (0.0.0.0:8081)
● srv2 — running (0.0.0.0:8082)
Actions:
[a] Add node
[c] Configure
[r] Remove node
[t] Start tunnel
[q] Quit
```
## Architecture
```
wallarm/
├── cmd/wallarm/main.go Entrypoint: preflight → TUI
├── internal/
│ ├── shared/ System detection, validation, connectivity
│ ├── preflight/ Mandatory checks on every start
│ ├── state/ ~/.wallarm/state.json persistence
│ ├── native/ Systemd units, installer, node management
│ ├── tunnel/ Reverse SSH over TLS:443 via Zoraxy
│ └── ui/ Bubbletea TUI (wizard + dashboard)
├── bin/
│ └── wallarm-linux-amd64 Pre-built binary
├── deploy.sh One-command bootstrap
├── go.mod / go.sum
└── Makefile Cross-compile targets
```
## Building from Source
```bash
go build -ldflags "-s -w -X main.version=$(git describe --tags)" -o wallarm ./cmd/wallarm/
make linux-amd64 # Cross-compile
make all # All targets
```
## Prerequisites
- Linux (systemd required)
- x86_64 or aarch64
- 2GB+ RAM, 10GB+ disk
- Outbound connectivity to Wallarm cloud (US/EU)
## License
Proprietary — see repository for terms.