build: multi-stage Alpine Dockerfile, compose, Makefile, README
This commit is contained in:
@@ -0,0 +1,61 @@
|
||||
# recon-triage — Docker-only workflow. No host-side tool installs required.
|
||||
#
|
||||
# AUTHORIZED USE ONLY. Recon & triage scope: this tool enumerates and references
|
||||
# findings; it never runs or generates exploits.
|
||||
|
||||
IMAGE ?= recon-triage:latest
|
||||
TEST_IMAGE ?= recon-triage:test
|
||||
SCOPE ?= scope.yaml
|
||||
TARGET ?= example.com
|
||||
OUT ?= $(CURDIR)/out
|
||||
FIXTURES ?= tests/fixtures
|
||||
|
||||
DOCKER ?= docker
|
||||
|
||||
.PHONY: help build test replay scan lint schema clean
|
||||
|
||||
help:
|
||||
@echo "recon-triage — Docker-only targets:"
|
||||
@echo " make build Build the runtime image"
|
||||
@echo " make test Build the test stage and run pytest (fully offline)"
|
||||
@echo " make replay Run the fixture demo -> ./out (no network)"
|
||||
@echo " make scan TARGET=t SCOPE=s Live recon (requires ./\$$SCOPE)"
|
||||
@echo " make lint Run ruff inside the test image"
|
||||
@echo " make schema Export JSON Schema to ./schemas"
|
||||
@echo " make clean Remove ./out"
|
||||
|
||||
# Build the final runtime image from a clean checkout (no host tool installs).
|
||||
build:
|
||||
$(DOCKER) build --target runtime -t $(IMAGE) .
|
||||
|
||||
# Build ONLY the test stage and run the suite. The pytest run happens during the
|
||||
# image build (RUN pytest) and is fully offline — fixtures + injected stubs.
|
||||
test:
|
||||
$(DOCKER) build --target test -t $(TEST_IMAGE) .
|
||||
|
||||
# Offline demo: full normalize -> ground -> report on committed fixtures.
|
||||
replay: build
|
||||
@mkdir -p $(OUT)
|
||||
$(DOCKER) run --rm \
|
||||
-v $(CURDIR)/$(FIXTURES):/app/tests/fixtures:ro \
|
||||
-v $(OUT):/data/out \
|
||||
$(IMAGE) replay --fixtures /app/tests/fixtures --out /data/out --scope /app/tests/fixtures/scope.yaml
|
||||
|
||||
# Live scan. Connect scans run unprivileged — no --cap-add needed.
|
||||
# For faster SYN scans you MAY add: --cap-add=NET_RAW --cap-add=NET_ADMIN (optional).
|
||||
scan: build
|
||||
@mkdir -p $(OUT)
|
||||
$(DOCKER) run --rm \
|
||||
-v $(CURDIR)/$(SCOPE):/data/scope.yaml:ro \
|
||||
-v $(OUT):/data/out \
|
||||
$(IMAGE) scan --scope /data/scope.yaml --target $(TARGET) --out /data/out
|
||||
|
||||
lint:
|
||||
$(DOCKER) build --target test -t $(TEST_IMAGE) .
|
||||
$(DOCKER) run --rm $(TEST_IMAGE) ruff check src tests
|
||||
|
||||
schema:
|
||||
$(DOCKER) run --rm -v $(CURDIR)/schemas:/out $(IMAGE) schema --out /out
|
||||
|
||||
clean:
|
||||
rm -rf $(OUT)
|
||||
Reference in New Issue
Block a user