No description
Find a file
admin 19d16b1e4a fix: deploy.sh uses Gitea releases API instead of raw branch
Binary is now distributed via Gitea releases (not committed to repo).
deploy.sh queries API for latest release tag and downloads the correct
architecture binary.
2026-08-01 14:32:03 +00:00
cmd/wallarm refactor: drop Docker, single-binary native-only world 2026-08-01 14:31:25 +00:00
common feat: add native deployment and separate docker|native structure 2026-08-01 08:36:37 +01:00
docker feat: Go binary — preflight, state, tunnel over TLS:443 2026-08-01 09:25:22 +00:00
internal refactor: drop Docker, single-binary native-only world 2026-08-01 14:31:25 +00:00
native feat: cloud region selection in native script, rename deploy script 2026-08-01 08:58:50 +00:00
.env chore: auto-commit 2026-05-04 12:12 2026-05-04 12:12:38 +01:00
.gitignore refactor: drop Docker, single-binary native-only world 2026-08-01 14:31:25 +00:00
changelog.md refactor: make wallarm-native.sh the sole native deployment script 2026-08-01 08:53:07 +01:00
deploy.sh fix: deploy.sh uses Gitea releases API instead of raw branch 2026-08-01 14:32:03 +00:00
go.mod feat: bubbletea TUI — wizard + dashboard 2026-08-01 13:16:08 +00:00
go.sum feat: bubbletea TUI — wizard + dashboard 2026-08-01 13:16:08 +00:00
Makefile feat: native and docker deployment packages + Makefile 2026-08-01 13:55:28 +00:00
README.md refactor: drop Docker, single-binary native-only world 2026-08-01 14:31:25 +00:00
setup.sh feat: bubbletea TUI — wizard + dashboard 2026-08-01 13:16:08 +00:00

Wallarm Native Node Manager

Single-binary deployment and management for Wallarm Native Nodes (connector mode, no Docker). One command to get started, one TUI to manage everything.

Quick Start

curl -fsSL "https://git.sechpoint.app/customer-engineering/wallarm/raw/branch/main/deploy.sh" | bash
sudo ./deploy/wallarm

That's it. The binary runs preflight checks, then opens an interactive TUI:

  • First run: configuration wizard (cloud region, API token, node name, listen address)
  • Subsequent runs: dashboard with node list, add/remove/configure actions

Features

  • Single binary — 7MB, zero runtime dependencies, works on any Linux
  • Interactive TUI — bubbletea-powered forms and dashboard
  • Preflight checks — runs on every start: system, network, cloud reachability, resources
  • Multi-node — manage multiple Wallarm nodes on the same host via systemd
  • Remote tunnelwallarm --tunnel opens a reverse SSH tunnel over TLS:443 via Zoraxy
  • State persistence~/.wallarm/state.json tracks all deployments

Commands

wallarm               Interactive TUI (wizard or dashboard)
wallarm --tunnel       Start reverse SSH tunnel to sechpoint.app
wallarm --version      Show version
wallarm --help         Show help

Dashboard

📊 Wallarm Dashboard
Type: native  |  Cloud: EU (api.wallarm.com)
──────────────────────────────────────────────────

Nodes:
  ● srv1 — running  (0.0.0.0:8081)
  ● srv2 — running  (0.0.0.0:8082)

Actions:
  [a] Add node
  [c] Configure
  [r] Remove node
  [t] Start tunnel
  [q] Quit

Architecture

wallarm/
├── cmd/wallarm/main.go         Entrypoint: preflight → TUI
├── internal/
│   ├── shared/                 System detection, validation, connectivity
│   ├── preflight/              Mandatory checks on every start
│   ├── state/                  ~/.wallarm/state.json persistence
│   ├── native/                 Systemd units, installer, node management
│   ├── tunnel/                 Reverse SSH over TLS:443 via Zoraxy
│   └── ui/                     Bubbletea TUI (wizard + dashboard)
├── bin/
│   └── wallarm-linux-amd64     Pre-built binary
├── deploy.sh                   One-command bootstrap
├── go.mod / go.sum
└── Makefile                    Cross-compile targets

Building from Source

go build -ldflags "-s -w -X main.version=$(git describe --tags)" -o wallarm ./cmd/wallarm/
make linux-amd64      # Cross-compile
make all              # All targets

Prerequisites

  • Linux (systemd required)
  • x86_64 or aarch64
  • 2GB+ RAM, 10GB+ disk
  • Outbound connectivity to Wallarm cloud (US/EU)

License

Proprietary — see repository for terms.