| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
| Name | Name | Last commit date | ||
|---|---|---|---|---|
Built as a fresh, independent open-source SaaS application.
GuardScale is an AI-powered infrastructure guardian that detects attacks and application failures, alerts teams via WhatsApp and email, and lets operators safely respond in real time. It is source-available under AGPL-3.0-or-later (see LICENSE); a separate commercial license is available for embedding, redistribution, or operation without AGPL obligations (see COMMERCIAL-LICENSE.md).
Agent-swarm traffic can now pass for ordinary human browsing one request at a time. Coordinated agents can rotate across distributed clients, use plausible browser fingerprints, traverse varied URLs, preserve cookies and referers, and remain below conventional per-IP limits. In aggregate, a short burst can still exhaust web workers, PHP-FPM pools, database capacity, sockets, and file descriptors before traditional controls recognize one offender.
GuardScale correlates behavior at the origin: aggregate velocity, unique-URL traversal, query shapes, pagination depth, shared client patterns, direct-origin bypass, slow-stack repetition, worker saturation, resource pressure, and availability degradation. It never treats a browser version, country, or distributed traffic alone as proof of abuse. The objective is to preserve bounded evidence, explain what happened, and apply only predefined, reversible survival controls.
Start the complete local stack and open http://localhost:
cp .env.example .env
docker compose up --build -dFor local development, the compose defaults are username root and password guardscale-local-change-me. Replace GUARDSCALE_ROOT_PASSWORD and GUARDSCALE_SESSION_SECRET in .env before exposing the application beyond localhost. Agent enrollment no longer uses a shared token — each organization gets its own enrollment secret, issued from the Nodes page.
Stripe checkout is disabled until STRIPE_SECRET_KEY, STRIPE_WEBHOOK_SECRET, STRIPE_STARTER_PRICE_ID, and STRIPE_SCALE_PRICE_ID are configured. Card data is handled by Stripe Checkout and is never stored by GuardScale.
Requires Go 1.23+. Copy configs/config.example.yaml, use opaque server/tenant identifiers, and set local log paths.
go test ./...
go build -o bin/guardscale ./cmd/guardscale
bin/guardscale test-config --config config.yaml
bin/guardscale replay --config config.yaml --php-slow sample-slow.log sample-access.logThe GuardScale log format is tab-separated: RFC3339 timestamp, X-Forwarded-For, immediate peer, Host, method, URI, status, bytes, duration milliseconds, Referer, User-Agent, and verification state (valid, missing, or invalid). Forwarded identity is used only when the immediate peer matches proxy.trusted_cidrs; chains are evaluated right-to-left.
Incident bundles are bounded by storage.max_evidence_lines. Query values and referers are removed and user agents fingerprinted. Protection ships disabled and dry-run; Phase 1 never mutates Apache, PHP-FPM, or firewall state.
Install the binary at /usr/local/bin/guardscale, configuration at /etc/guardscale/config.yaml, then install systemd/guardscale.service. Its hardening permits only the state directory; future opt-in protection will require separately documented privileges.
For an existing Linux EC2 instance, open Nodes → Add node and use the generated values with the checksum-verifying bootstrap installer:
curl -fsSLo /tmp/install-guardscale.sh https://guardscale.s3.us-east-1.amazonaws.com/agent/latest/install-agent.sh
sudo bash /tmp/install-guardscale.sh --enrollment-key '<tenant-id>.<enrollment-token>'The command is reusable across a fleet. On EC2, the installer uses IMDSv2 to derive a stable node ID from the instance ID and creates the agent ID automatically; non-EC2 Linux hosts use a one-way machine identity. Architecture is detected automatically. The running agent sends a heartbeat every 30 seconds and at most one sanitized request signal per second. Raw log lines, query values, client IPs, referers, and user-agent strings stay on the monitored node.
See architecture, security model, contributing, and commercial licensing.
| Back | FazBrowse Home | New Git URL |