From 358c4178dd4209dc4b9f42dbd4dc7b5fdd6a239b Mon Sep 17 00:00:00 2001 From: "github-action[bot]" <> Date: Tue, 1 Sep 2026 08:28:11 +0000 Subject: [PATCH] Create Flex endpoint --- acencyril.sentinelle-bundle.0.3.json | 78 ++++++++++++++++++++++++++++ index.json | 20 +++++++ 2 files changed, 98 insertions(+) create mode 100644 acencyril.sentinelle-bundle.0.3.json create mode 100644 index.json diff --git a/acencyril.sentinelle-bundle.0.3.json b/acencyril.sentinelle-bundle.0.3.json new file mode 100644 index 00000000..be573c50 --- /dev/null +++ b/acencyril.sentinelle-bundle.0.3.json @@ -0,0 +1,78 @@ +{ + "manifests": { + "acencyril/sentinelle-bundle": { + "manifest": { + "bundles": { + "Acencyril\\SentinelleBundle\\SentinelleBundle": [ + "all" + ] + }, + "copy-from-recipe": { + "config/": "%CONFIG_DIR%/" + }, + "env": { + "#1": "Where security alerts are sent.", + "SENTINELLE_ALERT_EMAIL": "admin@example.com", + "#2": "IPs or CIDRs, comma separated, that must never be blocked.", + "#3": "PUT YOUR OWN OUTBOUND ADDRESS HERE before going live:", + "#4": "without it, an automatic block can lock you out of your own site.", + "SENTINELLE_ALLOWLIST": "" + }, + "post-install-output": [ + " Sentinelle is installed. Three things before going live:", + "", + " * Set SENTINELLE_ALLOWLIST in your .env \u2014 at minimum your own", + " outbound address. Without it, an automatic block can lock you out of", + " your own site.", + "", + " * Create the schema:", + " php bin/console doctrine:migrations:diff", + " php bin/console doctrine:migrations:migrate", + "", + " * Check it can do its job:", + " php bin/console sentinelle:check", + "", + " Sentinelle starts in dry-run: it detects, logs and alerts, but blocks", + " nothing. Watch /admin/activity for a few days, then set", + " sentinelle.dry_run to false.", + "", + " And schedule the purge, without which strike counters never reset:", + " 0 4 * * * php bin/console sentinelle:purge", + "" + ] + }, + "files": { + "config/packages/sentinelle.yaml": { + "contents": [ + "sentinelle:", + " # Dry-run: Sentinelle detects, logs and alerts, but blocks NOTHING.", + " # Nobody wires automatic blocking into a production site without knowing", + " # what it will shut out. Watch the dashboard for a few days, ask yourself", + " # \"would I have wanted to block that one?\", then switch it off.", + " dry_run: true", + " alert:", + " recipient: '%env(SENTINELLE_ALERT_EMAIL)%'", + " access:", + " role: ROLE_ADMIN", + " never_block:", + " # At minimum your own outbound address. Private ranges are protected", + " # by default, but yours is not: one wrong move locks you out.", + " ips: '%env(default::SENTINELLE_ALLOWLIST)%'", + "" + ], + "executable": false + }, + "config/routes/sentinelle.yaml": { + "contents": [ + "sentinelle:", + " resource: '@SentinelleBundle/config/routes.php'", + " type: php", + "" + ], + "executable": false + } + }, + "ref": "f8fdd404ae3f91c5c64a07c46a00a032767d006b" + } + } +} diff --git a/index.json b/index.json new file mode 100644 index 00000000..e29ab392 --- /dev/null +++ b/index.json @@ -0,0 +1,20 @@ +{ + "aliases": [], + "recipes": { + "acencyril/sentinelle-bundle": [ + "0.3" + ] + }, + "recipe-conflicts": [], + "versions": [], + "branch": "main", + "is_contrib": true, + "_links": { + "repository": "github.com/symfony/recipes-contrib", + "origin_template": "{package}:{version}@github.com/symfony/recipes-contrib:main", + "recipe_template": "https://raw.githubusercontent.com/symfony/recipes-contrib/flex/pull-2040/{package_dotted}.{version}.json", + "recipe_template_relative": "{package_dotted}.{version}.json", + "archived_recipes_template": "https://raw.githubusercontent.com/symfony/recipes-contrib/flex/pull-2040/archived/{package_dotted}/{ref}.json", + "archived_recipes_template_relative": "archived/{package_dotted}/{ref}.json" + } +}