Initial commit: Rampart v0.2.0

Multi-layer DDoS protection for Minecraft servers.

- rampart-core: Edge node with XDP/eBPF + Rust L7 filtering
- rampart-manager: REST API with JWT auth, Redis sync
- rampart-cli: CLI tool for operators
- velocity-plugin: Domain check, HMAC verify, server registry, load balancer
- paper-plugin: Auto-registration, heartbeat, HMAC verify
- dashboard: React + Vite web UI for management
This commit is contained in:
loki5512344 2026-07-20 20:53:32 +02:00
commit cf9608ce5d
Signed by: boba
GPG key ID: 253067914055423B
159 changed files with 15341 additions and 0 deletions

80
docker-compose.yml Normal file
View file

@ -0,0 +1,80 @@
version: "3.9"
services:
redis:
image: redis:7-alpine
container_name: rampart-redis
command: redis-server --requirepass "${REDIS_PASSWORD:-rampart_dev}" --appendonly yes
ports:
- "6379:6379"
volumes:
- redis-data:/data
healthcheck:
test: ["CMD", "redis-cli", "--raw", "incr", "ping"]
interval: 5s
timeout: 3s
retries: 5
restart: unless-stopped
nats:
image: nats:2-alpine
container_name: rampart-nats
ports:
- "4222:4222"
command: -js -c /etc/nats/nats.conf
volumes:
- nats-data:/data
healthcheck:
test: ["CMD", "nats", "server", "check"]
interval: 10s
timeout: 5s
retries: 3
restart: unless-stopped
clickhouse:
image: clickhouse/clickhouse-server:24-alpine
container_name: rampart-clickhouse
ports:
- "8123:8123" # HTTP
- "9000:9000" # Native TCP
volumes:
- clickhouse-data:/var/lib/clickhouse
- ./clickhouse-init:/docker-entrypoint-initdb.d
healthcheck:
test: ["CMD", "curl", "-f", "http://localhost:8123/ping"]
interval: 10s
timeout: 5s
retries: 5
restart: unless-stopped
prometheus:
image: prom/prometheus:latest
container_name: rampart-prometheus
ports:
- "9090:9090"
volumes:
- ./prometheus.yml:/etc/prometheus/prometheus.yml
- prometheus-data:/prometheus
command:
- '--config.file=/etc/prometheus/prometheus.yml'
- '--storage.tsdb.path=/prometheus'
restart: unless-stopped
grafana:
image: grafana/grafana:latest
container_name: rampart-grafana
ports:
- "3000:3000"
environment:
- GF_SECURITY_ADMIN_PASSWORD=${GRAFANA_PASSWORD:-admin}
volumes:
- grafana-data:/var/lib/grafana
- ./dashboards:/etc/grafana/provisioning/dashboards
restart: unless-stopped
volumes:
redis-data:
nats-data:
clickhouse-data:
prometheus-data:
grafana-data: