Repository navigation
Configuration
| Variable | Required | Purpose |
|---|---|---|
TELEGRAM_BOT_TOKEN |
Yes | Authenticates the Telegram bot used by aiogram. |
TELEGRAM_ALLOWED_CHAT_IDS |
Recommended | Comma-separated numeric chat IDs allowed to use the bot. |
AI_PROVIDER |
No | Provider preset. Defaults to ollama. |
AI_MODEL |
Provider-dependent | Model identifier. Defaults to qwen3:8b with Ollama. |
AI_BASE_URL |
Provider-dependent | OpenAI-compatible chat-completions endpoint. |
AI_API_KEY |
Provider-dependent | Credential for providers that require authentication. |
AI_TEMPERATURE |
No | Sampling temperature; defaults to 0. |
GEMINI_API_KEY |
Legacy only | Backward-compatible fallback when AI_PROVIDER=gemini. |
Create a local configuration from the example:
cp .env.example .envDo not commit real values. The repository .gitignore excludes .env, but
contributors must still review commits and logs for accidental secrets.
Lophiarch uses one OpenAI-compatible provider interface across local and hosted models.
AI_PROVIDER |
Default endpoint | Default model | API key |
|---|---|---|---|
ollama |
http://localhost:11434/v1/chat/completions |
qwen3:8b |
Not required |
vllm |
http://localhost:8000/v1/chat/completions |
Qwen/Qwen3-8B |
Not required by default |
lmstudio |
http://localhost:1234/v1/chat/completions |
local-model |
Not required by default |
llamacpp |
http://localhost:8080/v1/chat/completions |
local-model |
Not required by default |
gemini |
Google OpenAI-compatible endpoint | gemini-3.5-flash-lite |
Required |
openai-compatible |
Set with AI_BASE_URL
|
Set with AI_MODEL
|
Provider-dependent |
A local default configuration:
AI_PROVIDER=ollama
AI_MODEL=qwen3:8b
AI_BASE_URL=http://localhost:11434/v1/chat/completions
AI_API_KEY=
AI_TEMPERATURE=0For an unlisted service, use AI_PROVIDER=openai-compatible and supply its
chat-completions URL, model identifier, and API key when required.
The current scanner modules expect these exact tags:
| Capability | Image |
|---|---|
| Nmap | lophiarch-nmap:latest |
| Ffuf | lophiarch-ffuf:latest |
| Nuclei | lophiarch-nuclei:latest |
| Subfinder | projectdiscovery/subfinder:latest |
| dnsx | projectdiscovery/dnsx:latest |
If a custom build uses different names, update the corresponding engine module or retag the image.
| Mode | Current behavior |
|---|---|
quick |
Adds -F for the common-port set. |
default |
Uses service detection with -sV -Pn. |
deep |
Adds all-port scanning and default scripts with -p- -sC. |
All modes request XML output for parsing.
| Mode | Wordlist |
|---|---|
quick or default
|
/wordlists/quick.txt |
deep |
/wordlists/deep.txt |
The custom image downloads its wordlists from SecLists during image build.
The chart exposes provider-neutral values:
telegram:
botToken: ""
allowedChatIds: ""
ai:
provider: ollama
model: qwen3:8b
baseUrl: http://ollama.default.svc.cluster.local:11434/v1/chat/completions
temperature: "0"
apiKey: ""
geminiApiKey: "" # legacy fallback onlyOverride secrets at installation time or through a secure values workflow. Avoid committing plaintext production values.
PDFs are created in generated_reports/. The directory is ignored by Git.
Inside a disposable main container, reports disappear when the container is
removed unless a volume is mounted.