Architettura — accesso riservato
◈ORIONEYEv4.0

Architettura di sistema local-first

Piattaforma di threat intelligence geospaziale. Un piano cloud classico (browser → nginx → Node → SQLite) e un piano local-first in cui i dati sensibili — log, vault cifrato, LLM privato — non lasciano mai la macchina del cliente. La sovranità sui dati cresce con il livello di licenza; la governance resta all'Owner.

Free · cloud Pro · Hardware Vault USB (mTLS) Enterprise · Docker on-prem Owner · governance Grace AI · BYO-LLM
01

Piano cloud — il percorso della richiesta

richiesta HTTPS / API fetch server-side posta (SMTP)
BROWSER Dashboard SPA — mappa + pannelli laterali LANDING Home · /piani B2B /registrati (stand) ADMIN CONSOLE analytics · keys · leads summit · qr — owner gn_token NGINX — TLS termination (Let's Encrypt) / → dist (static) /api/ → Node (reverse proxy) serve /api STATIC · dist/ Vite bundle app.js · landing/admin .html NODE · server-final.js JWT HS256 · scrypt · gate requireAdmin / requireUsbPro Auth Feed + moderation SSH threats WiFi survey Campaigns Tracker · analytics hwkey · USB license · mTLS enterprise grace · IOC lead summit tts · Piper console · net Owner CA · EC prime256v1 — firma cert + licenze Pro USB & Enterprise → vedi Piano local-first (02) better-sqlite3 sendmail SQLite orioneye.db · 12 tabelle POSTFIX → Thunderbird fetch · API key server SERVIZI ESTERNI Gemini — multi-LLM AIbriefing · chat · vision Google Mapsbase map · geocoding AbuseIPDB · Wikipediaenrichment IP + entità OSINT feedsNASA EONET · RIPE Atlas · ESAtraffic cams · IP geo Piper TTSvoce neurale (VPS /opt/piper) BYO-LLM · Ollama / vLLMprivato, locale — usato da Grace(mai dal cloud — vedi 02)
Il piano standard. Ogni client carica i file statici da nginx e chiama /api sullo stesso host; una sola login owner (gn_token) copre l'intera console admin. Il Node è l'unico a parlare con SQLite, con il mail server (notifiche lead) e con i servizi esterni — le chiavi API restano lato server, mai nel browser.
02

Piano local-first — Pro USB & Enterprise

attraversa il confine (firmato) loopback locale — non esce mai
PRO · MACCHINA DEL CLIENTE — i dati non escono USB OmniAgent orioneye.key · client.crt/.key vault.db.enc · cacert.pem usb-agent.py key → login → browser #omni=JWT vault-daemon · 127.0.0.1:8770 AES-256-GCM → SQLite in-memory Browser · dashboard legge vault + Grace via loopback (locale) grace.py · 127.0.0.1:8771 fail2ban · auth.log · socket → JSON BYO-LLM — Ollama / vLLM privato, in rete locale ENTERPRISE · ON-PREM / VPS — Docker Compose OrionEye image Node + SQLite + dist (isolato) licensing sidecar HW fingerprint · phone-home grace period 72h → active / grace / locked → read-only (scritture HTTP 423) ORIONEYE CLOUD Node API + Owner CA (EC p256) /api/hwkey/loginverifica key_id+secret → JWT (pro) /api/license/verifycert vs Owner CA + nonce firmato → vault_key /api/grace/ioc · /contributecross-check community DB (HITL) → coda di moderazione Owner /api/enterprise/heartbeatbind fingerprint · clone_detected · scadenza Owner CA — firma cert + licenze login (key + secret) nonce firmato · mTLS-grade IOC · consenso heartbeat · fingerprint
Sovranità dei dati per costruzione. Log di sistema, LLM privato e il vault decifrato restano dentro il confine tratteggiato: dialogano col browser solo in loopback (127.0.0.1). Attraversano il confine soltanto un login firmato, un nonce di licenza verificato contro la Owner CA, gli heartbeat con hardware-fingerprint anti-clone e gli IOC che l'operatore sceglie di condividere — che passano comunque dalla coda di moderazione Owner.
03

Dove vivono i dati, per livello

Free

Utente registrato
Dati: cloud (SQLite server)
  • Login email + password
  • Mappa OSINT pubblica
  • Feed in sola lettura
  • Cyber Intel base

Pro

OmniAgent USB
Dati: vault locale cifrato
  • Login hardware mTLS
  • Vault AES-256-GCM :8770
  • Grace AI BYO-LLM :8771
  • WiFi · SSH · HITL

Enterprise

On-prem / VPS
Dati: infrastruttura propria
  • Docker Compose
  • Licensing heartbeat
  • Anti-clone fingerprint
  • Grace 72h → read-only

Owner

Governance · Sam
Ruolo: controllo piattaforma
  • Moderazione Feed / IOC
  • Analytics & tracking
  • Chiavi + licenze
  • Owner CA (firma)
04

Riferimento tecnico

SUPERFICIE API · /api

authlogin · register · stats
feedfeed · feed/pending · approve · reject
threatssh/ingest · campaigns · fail2ban/ban
wifiwifi/ingest · wifi
trackerevent · stats · visitors · briefing
usb / prohwkey/{issue,login,bind,revoke} · license/{nonce,verify} · my-vault
enterpriseissue · heartbeat · list · revoke · status
graceioc · contribute · iocs
growthlead · leads · summit/{visitor,visitors,export,status}
media / nettts/piper · ping · trace · dns · market/assess

MODELLO DATI · orioneye.db

usersauth_eventsuser_avatars postsssh_threatswifi_aps track_eventshardware_keysenterprise_licences grace_iocsleadssummit_visitors

SQLite via better-sqlite3. Nel piano Pro lo stesso schema (ssh_threats, wifi_aps) vive cifrato nel vault locale, servito in memoria dal daemon.

FRONTEND · src/

shellmap/*feedcampaigns sshthreatswifigraceomni market · assessconsoletrackpresenceauth

DAEMON LOCAL-FIRST · Python

:—usb-agent.py — rileva la chiave, login passwordless, apre il browser (#omni)
:8770vault-daemon — decifra vault.db.enc (AES-256-GCM) in memoria, loopback API
:8771grace.py — struttura i log, cross-check community, risponde col BYO-LLM
:—licensing_client.py — fingerprint, heartbeat firmato, grace period

Solo stdlib + cryptography. cacert.pem è impacchettato sulla chiavetta: TLS verificato senza nulla installato sul PC del cliente.

INFRASTRUTTURA & SICUREZZA

edgenginx — TLS termination, static + reverse proxy
runtimeNode zero-framework · PM2 · SQLite
authJWT HS256 · scrypt · rate-limit · isFeedAdmin (owner id 1)
pkiOwner CA EC prime256v1 (root-only) — firma cert client + licenze ECDSA
vaultAES-256-GCM · chiave = sha256(fingerprint cert + JWT_SECRET)
mailPostfix + Dovecot — notifiche lead (SPF/DKIM)