Compare commits

...
2 Commits
Author SHA1 Message Date
acencyrilandGitHub 07f7809541 Add acencyril/sentinelle-bundle recipe (#2040)
* Add acencyril/sentinelle-bundle recipe

* Remove aliases, not supported in contrib

* Target 0.2

* Target 0.3, English configuration

* Add trailing newlines

* Fix indentation

* Trailing newline, remove IDE files

* Fix YAML indentation
2026-09-04 10:37:23 +04:00
Diego D'amicoandGitHub 42c7572f9a Add recipe for odiseoteam/sylius-rbac-plugin (#2044) 2026-09-04 10:32:46 +04:00
7 changed files with 88 additions and 0 deletions
@@ -0,0 +1,14 @@
sentinelle:
# Dry-run: Sentinelle detects, logs and alerts, but blocks NOTHING.
# Nobody wires automatic blocking into a production site without knowing
# what it will shut out. Watch the dashboard for a few days, ask yourself
# "would I have wanted to block that one?", then switch it off.
dry_run: true
alert:
recipient: '%env(SENTINELLE_ALERT_EMAIL)%'
access:
role: ROLE_ADMIN
never_block:
# At minimum your own outbound address. Private ranges are protected
# by default, but yours is not: one wrong move locks you out.
ips: '%env(default::SENTINELLE_ALLOWLIST)%'
@@ -0,0 +1,3 @@
sentinelle:
resource: '@SentinelleBundle/config/routes.php'
type: php
@@ -0,0 +1,40 @@
{
"bundles": {
"Acencyril\\SentinelleBundle\\SentinelleBundle": [
"all"
]
},
"copy-from-recipe": {
"config/": "%CONFIG_DIR%/"
},
"env": {
"#1": "Where security alerts are sent.",
"SENTINELLE_ALERT_EMAIL": "admin@example.com",
"#2": "IPs or CIDRs, comma separated, that must never be blocked.",
"#3": "PUT YOUR OWN OUTBOUND ADDRESS HERE before going live:",
"#4": "without it, an automatic block can lock you out of your own site.",
"SENTINELLE_ALLOWLIST": ""
},
"post-install-output": [
" <bg=blue;fg=white>Sentinelle is installed.</> Three things before going live:",
"",
" * Set <comment>SENTINELLE_ALLOWLIST</comment> in your <comment>.env</comment> — at minimum your own",
" outbound address. Without it, an automatic block can lock you out of",
" your own site.",
"",
" * Create the schema:",
" <comment>php bin/console doctrine:migrations:diff</comment>",
" <comment>php bin/console doctrine:migrations:migrate</comment>",
"",
" * Check it can do its job:",
" <comment>php bin/console sentinelle:check</comment>",
"",
" Sentinelle starts in <comment>dry-run</comment>: it detects, logs and alerts, but blocks",
" nothing. Watch <comment>/admin/activity</comment> for a few days, then set",
" <comment>sentinelle.dry_run</comment> to <comment>false</comment>.",
"",
" And schedule the purge, without which strike counters never reset:",
" <comment>0 4 * * * php bin/console sentinelle:purge</comment>",
""
]
}
@@ -0,0 +1,2 @@
imports:
- { resource: "@OdiseoSyliusRbacPlugin/config/config.yaml" }
@@ -0,0 +1,3 @@
odiseo_sylius_rbac_admin:
resource: "@OdiseoSyliusRbacPlugin/config/routes/admin.yaml"
prefix: /admin
@@ -0,0 +1,8 @@
{
"bundles": {
"Odiseo\\SyliusRbacPlugin\\OdiseoSyliusRbacPlugin": ["all"]
},
"copy-from-recipe": {
"config/": "%CONFIG_DIR%/"
}
}
@@ -0,0 +1,18 @@
<bg=blue;fg=white> </>
<bg=blue;fg=white> What's next? </>
<bg=blue;fg=white> </>
* <fg=blue>Make</> your AdminUser administration-role aware: add
<comment>AdministrationRoleAwareInterface</> and <comment>AdministrationRoleAwareTrait</>
to your <comment>AdminUser</> entity. This plugin cannot do it for you -- that class is
yours, and may already extend or implement other things.
* <fg=blue>Update</> your database schema:
<comment>bin/console doctrine:migrations:migrate</>
* <fg=blue>Grant</> yourself access. A fresh install denies every administrator
everything, including the screen that assigns roles:
<comment>bin/console odiseo:rbac:grant <username-or-email> super_admin --create</>
* <fg=blue>Read</> the full installation guide, including the AdminUser snippet, at
<comment>https://github.com/odiseoteam/SyliusRbacPlugin/blob/master/doc/installation.md</>