mirror of
https://github.com/MengMengCode/CLICD.git
synced 2026-08-05 05:36:07 +08:00
a45e063fc2
- Introduced Container Management documentation covering lifecycle operations, resource management, and console access. - Added Dashboard documentation detailing metrics and related APIs. - Created Host Report documentation summarizing host environment and resource status. - Included Image Management documentation for template handling and management actions. - Documented Networking and Routing features including NAT4 and IPv6 management. - Added Security Alerts documentation outlining alert scenarios and API usage. - Created Snapshot Management documentation for snapshot operations and scheduling. - Documented Sub-user management for granting access to specific containers. - Added Configuration guide detailing runtime settings and security recommendations. - Created Installation guide for setting up CLICD with requirements and steps. - Added Introduction and Quick Start guides for new users. - Documented Upgrade process with version checking and pre-upgrade checklist. - Created Deployment guide for service exposure and firewall recommendations. - Added FAQ section addressing common questions and concerns. - Documented Troubleshooting steps for common issues encountered.
32 lines
1.0 KiB
Markdown
32 lines
1.0 KiB
Markdown
# Security Alerts
|
|
|
|
CLICD includes lightweight security alerts based on connection behavior. It does not keep full normal connection logs; it focuses on abnormal behavior and high-risk patterns.
|
|
|
|
## Covered Scenarios
|
|
|
|
- Port scanning.
|
|
- Lateral scanning.
|
|
- Brute-force tendencies.
|
|
- SMTP abuse.
|
|
- UDP reflection risk.
|
|
- Suspicious ports related to mining, proxies, VPNs, Tor, and similar services.
|
|
|
|
## APIs
|
|
|
|
```http
|
|
GET /api/v1/security/alerts
|
|
POST /api/v1/security/check
|
|
GET /api/v1/security/logs?container={name}
|
|
GET /api/v1/security/summary
|
|
GET /api/v1/security/settings
|
|
PUT /api/v1/security/settings
|
|
```
|
|
|
|
## Automatic Shutdown
|
|
|
|
Security settings can enable automatic shutdown after alerts. Before enabling it, observe for a while and make sure the rules do not affect normal services.
|
|
|
|
## Logging Advice
|
|
|
|
Security alerts are risk signals. They should not replace a professional firewall, intrusion detection, or centralized logging system. For public services, still combine them with security groups, firewall rules, Fail2ban, and similar tools.
|