Colander quick deploy
Welcome to Colander quick deploy.
Here you'll find all the necessary resources to get the entire Colander stack up and running as quickly as possible (or just the components you're interested in).
Requirements
You'll need docker and docker compose.
Download
You can download colander quick deploy from here.
This is licensed under GPLv3. You can find the sources on our Github repository (the archive above is based on colander-ansible/docker folder).
Using docker to deploy the PTS stack.
You can start some of the tools (using docker compose -f compose-xxx.yml up -d command like described
below) or you can start the whole stack by just going with docker compose up -d
Before starting
Most of the settings are pre-configured with sanely safe defaults. Some others are required before starting.
To boostrap your environment, please run compose-init.yml first:
docker compose -f compose-init.yml up -d
This will bootstrap a minimal .env file which will be used by docker. It contains some secrets
randomly generated for you.
If you want more control over how things are configured, please take a look at .env.example. There,
you'll find all the settings available with some comments that should help you in getting the hands on
PTS' configuration.
Start colander only
docker compose -f compose-colander.yml up -d
By default, colander should be available at:
- http://localhost:5000
- https://colander.local:4443 (if you put
colander.localas additional hostname on line starting by127.0.0.1)
Start threatr only
docker compose -f compose-threatr.yml up -d
By default, threatr should be available at:
- http://localhost:5001
- https://threatr.local:4443 (if you put
threatr.localas additional hostname on line starting by127.0.0.1)
Start mandolin only
docker compose -f compose-mandolin.yml up -d
By default, mandolin should be available at:
- http://localhost:5002
- https://mandolin.local:4443 (if you put
mandolin.localas additional hostname on line starting by127.0.0.1)
Start cyberchef only
docker compose -f compose-cyberchef.yml up -d
By default, mandolin should be available at:
- http://localhost:5003
- https://cyberchef.local:4443 (if you put
cyberchef.localas additional hostname on line starting by127.0.0.1)
Starting a "à la carte" stack (multiple tools)
Of course, you can pick more than one tool by giving the corresponding compose file as a value of -f argument of
the docker compose CLI:
docker compose -f compose-colander.yml -f compose-threatr.yml up -d
Starting the whole stack
The following command should get you up and running fairly quickly (by default, you may be able to start straight away.
But in some case you may need to adjust the .env file, so take a look to it. It should be self-explanatory):
docker compose up -d
# or the following if you cannot obtain a valid letsencrypt certificate because of your context/requirements (it
# will generate a self signed certificate ./data/traefik/certs/self-signed/cert.pem ; which you
# can add to your Pirogue's operating system trust store) so your pirogue will be able to connect to colander using
# https and this certificate (see below)
# This compose file will also expose Traefik's dashboard on port http://localhost:8080
docker compose -f compose-dev.yml up -d
This will :
- create a self signed certificate (allowing you to use pirogue tooling to connect to colander without requiring a certificate issued by a Certificate Authority).
- start the whole stack (colander, threatr, mandolin, etc.)
- you'll get access to:
Note: those tools can also be accessed through their respectie hostnames (if you add them to your /etc/hosts file):
Creating a Threatr integration for your colander
Below are the quick steps to connect your Colander to yoyr Threatr (this is also documented on our website):
- Creating super users on both tools:
docker compose -f compose-dev.yml exec colander-front /entrypoint python manage.py createsuperuser docker compose -f compose-dev.yml exec threatr-front /entrypoint python manage.py createsuperuser- Creating a simple user
colander-userin threatr (via https://threatr.local/admin)
- Creating a simple user
- Creating an API key for
colander-userin threatr (via https://threatr.local/admin)
- Creating an API key for
- Adding a Backend Credential in threatr with the following value (replace
thetokenby the token you just created in threatr):{ "api_key": "thetoken"}
- Adding a Backend Credential in threatr with the following value (replace
note: You can also run docker compose up -d but you'll not get access to Traefik's dashboard nor generate a self signed certificate.
compose.yml is the base file can be used as a base for production deployments. compose-dev.yml overrides some of the service definitions
of the compose.yml.