{ "manifests": { "acencyril/sentinelle-bundle": { "manifest": { "bundles": { "Acencyril\\SentinelleBundle\\SentinelleBundle": [ "all" ] }, "copy-from-recipe": { "config/": "%CONFIG_DIR%/" }, "env": { "#1": "Where security alerts are sent.", "SENTINELLE_ALERT_EMAIL": "admin@example.com", "#2": "IPs or CIDRs, comma separated, that must never be blocked.", "#3": "PUT YOUR OWN OUTBOUND ADDRESS HERE before going live:", "#4": "without it, an automatic block can lock you out of your own site.", "SENTINELLE_ALLOWLIST": "" }, "post-install-output": [ " Sentinelle is installed. Three things before going live:", "", " * Set SENTINELLE_ALLOWLIST in your .env \u2014 at minimum your own", " outbound address. Without it, an automatic block can lock you out of", " your own site.", "", " * Create the schema:", " php bin/console doctrine:migrations:diff", " php bin/console doctrine:migrations:migrate", "", " * Check it can do its job:", " php bin/console sentinelle:check", "", " Sentinelle starts in dry-run: it detects, logs and alerts, but blocks", " nothing. Watch /admin/activity for a few days, then set", " sentinelle.dry_run to false.", "", " And schedule the purge, without which strike counters never reset:", " 0 4 * * * php bin/console sentinelle:purge", "" ] }, "files": { "config/packages/sentinelle.yaml": { "contents": [ "sentinelle:", " # Dry-run: Sentinelle detects, logs and alerts, but blocks NOTHING.", " # Nobody wires automatic blocking into a production site without knowing", " # what it will shut out. Watch the dashboard for a few days, ask yourself", " # \"would I have wanted to block that one?\", then switch it off.", " dry_run: true", " alert:", " recipient: '%env(SENTINELLE_ALERT_EMAIL)%'", " access:", " role: ROLE_ADMIN", " never_block:", " # At minimum your own outbound address. Private ranges are protected", " # by default, but yours is not: one wrong move locks you out.", " ips: '%env(default::SENTINELLE_ALLOWLIST)%'", "" ], "executable": false }, "config/routes/sentinelle.yaml": { "contents": [ "sentinelle:", " resource: '@SentinelleBundle/config/routes.php'", " type: php", "" ], "executable": false } }, "ref": "f8fdd404ae3f91c5c64a07c46a00a032767d006b" } } }