Repository navigation
Deployment
Build the worker images first:
docker build -f Dockerfile.nmap -t lophiarch-nmap:latest .
docker build -f Dockerfile.ffuf -t lophiarch-ffuf:latest .
docker build -f Dockerfile.nuclei -t lophiarch-nuclei:latest .Build and run the main bot:
docker build -t lophiarch:local .
docker run -d \
--name lophiarch-bot \
--restart unless-stopped \
--env-file .env \
-v /var/run/docker.sock:/var/run/docker.sock \
-v lophiarch-reports:/app/generated_reports \
lophiarch:localThe report volume is optional. The Docker socket is required by the current worker architecture.
The CI workflow builds the main image on relevant pushes to main and
publishes:
ghcr.io/amiencoy/lophiarch:latest
ghcr.io/amiencoy/lophiarch:sha-<short-commit>
Registry access depends on the package visibility and authentication configured in GitHub. Scanner worker images are currently built separately and are not published by the main-image workflow.
Validate the chart:
helm lint deploy/helmInstall:
helm install recon-bot deploy/helm \
--set image.repository=ghcr.io/amiencoy/lophiarch \
--set image.tag=2.2.0 \
--set telegram.botToken="YOUR_TELEGRAM_TOKEN" \
--set telegram.allowedChatIds="YOUR_CHAT_ID" \
--set ai.provider=ollama \
--set ai.model=qwen3:8b \
--set ai.baseUrl="http://ollama.default.svc.cluster.local:11434/v1/chat/completions"The Ollama Service URL must be reachable from the Lophiarch pod. To use a
different local or hosted backend, set ai.provider, ai.model, ai.baseUrl,
and ai.apiKey as required by that provider.
For production, prefer a protected values mechanism or external secret manager instead of placing secrets directly in shell history.
The current chart mounts the host path /var/run/docker.sock. Therefore:
- The node must expose a compatible Docker socket.
- A containerd-only cluster, including many default K3s installations, will not work without an additional Docker-compatible setup or an architectural change.
- The pod obtains powerful access to the host Docker daemon.
- Required worker images must be available to that daemon.
- The current chart does not configure
imagePullSecretsfor a private GHCR package.
Review these constraints before treating the chart as production-ready.
helm upgrade recon-bot deploy/helm \
--reuse-values \
--set image.tag=sha-<commit>Pinning a commit tag is more reproducible than using latest.
helm uninstall recon-botReview generated Secrets, volumes, worker images, and reports separately; Helm does not necessarily remove every external artifact.
Read the migration guide before changing scanner image names or Helm deployments.