Skip to content

Deployment

Muhammad amien edited this page Sep 24, 2026 · 3 revisions

Deployment

Docker Deployment

Build the worker images first:

docker build -f Dockerfile.nmap -t lophiarch-nmap:latest .
docker build -f Dockerfile.ffuf -t lophiarch-ffuf:latest .
docker build -f Dockerfile.nuclei -t lophiarch-nuclei:latest .

Build and run the main bot:

docker build -t lophiarch:local .

docker run -d \
  --name lophiarch-bot \
  --restart unless-stopped \
  --env-file .env \
  -v /var/run/docker.sock:/var/run/docker.sock \
  -v lophiarch-reports:/app/generated_reports \
  lophiarch:local

The report volume is optional. The Docker socket is required by the current worker architecture.

GitHub Container Registry

The CI workflow builds the main image on relevant pushes to main and publishes:

ghcr.io/amiencoy/lophiarch:latest
ghcr.io/amiencoy/lophiarch:sha-<short-commit>

Registry access depends on the package visibility and authentication configured in GitHub. Scanner worker images are currently built separately and are not published by the main-image workflow.

Helm Deployment

Validate the chart:

helm lint deploy/helm

Install:

helm install recon-bot deploy/helm \
  --set image.repository=ghcr.io/amiencoy/lophiarch \
  --set image.tag=2.2.0 \
  --set telegram.botToken="YOUR_TELEGRAM_TOKEN" \
  --set telegram.allowedChatIds="YOUR_CHAT_ID" \
  --set ai.provider=ollama \
  --set ai.model=qwen3:8b \
  --set ai.baseUrl="http://ollama.default.svc.cluster.local:11434/v1/chat/completions"

The Ollama Service URL must be reachable from the Lophiarch pod. To use a different local or hosted backend, set ai.provider, ai.model, ai.baseUrl, and ai.apiKey as required by that provider.

For production, prefer a protected values mechanism or external secret manager instead of placing secrets directly in shell history.

Kubernetes Runtime Limitation

The current chart mounts the host path /var/run/docker.sock. Therefore:

  • The node must expose a compatible Docker socket.
  • A containerd-only cluster, including many default K3s installations, will not work without an additional Docker-compatible setup or an architectural change.
  • The pod obtains powerful access to the host Docker daemon.
  • Required worker images must be available to that daemon.
  • The current chart does not configure imagePullSecrets for a private GHCR package.

Review these constraints before treating the chart as production-ready.

Upgrade

helm upgrade recon-bot deploy/helm \
  --reuse-values \
  --set image.tag=sha-<commit>

Pinning a commit tag is more reproducible than using latest.

Removal

helm uninstall recon-bot

Review generated Secrets, volumes, worker images, and reports separately; Helm does not necessarily remove every external artifact.

Migration

Read the migration guide before changing scanner image names or Helm deployments.

Clone this wiki locally