Real-time API discovery, Shadow API detection & ML anomaly detection dashboard for NGINX
260
๐ฐ๐ท ํ๊ตญ์ด ๋ฌธ์๋ ์ด ํ์ด์ง ์๋์ชฝ์ ์์ต๋๋ค. ยท Korean documentation follows below.
Find every API endpoint behind your NGINX โ including the ones nobody documented.
This image reads your existing NGINX / NGINX Plus access logs and turns them into a live API inventory: which endpoints actually receive traffic, which ones are missing from your OpenAPI spec (shadow APIs), which ones answer without an Authorization header, and which ones are behaving abnormally. No application changes, no instrumentation, no SDK.
This is the collector server + web dashboard (:8080). It needs a collection agent to send it logs:
๐ Agent image:
gusgh13900/api-discovery-agentโ โ runs on your NGINX host. Keep it on the same version tag as this image.
| Image | Role | Download | On disk | Runs on |
|---|---|---|---|---|
api-discovery-nginx (this image) | Collector server + web dashboard (:8080) | ~288 MB | ~1 GB | Dashboard host |
api-discovery-agent | NGINX log collector | ~21 MB | ~56 MB | NGINX host |
linux/amd64 (no ARM build)docker run -d --name api-discovery-nginx \
-p 8080:8080 \
-e INGEST_TOKEN=<a shared secret you choose> \
-v $PWD/output:/app/output \
gusgh13900/api-discovery-nginx:1.2.1
Open http://<dashboard-host>:8080.
โ ๏ธ Change the default password. The dashboard requires a session login and creates a default administrator
admin/admin1234on first start. Log in and change it immediately. Accounts live inoutput/auth_users.jsonon your volume, so they survive restarts and upgrades.
Then deploy gusgh13900/api-discovery-agentโ on your NGINX host with the same INGEST_TOKEN. Data starts arriving within one poll interval (30s by default).
If the dashboard shows "no agent connected", the cause is almost always an INGEST_TOKEN that does not match on both sides.
/users/{id}, /orders/{uuid}) so raw URIs collapse into real endpoints.Authorization header.admin and viewer roles.| Variable | Default | Description |
|---|---|---|
INGEST_TOKEN | (empty) | Shared secret the agent must present. Leaving it empty disables authentication on /api/ingest โ only acceptable on a trusted local network. |
DASHBOARD_SECRET | (generated) | Session cookie signing key. Generated into output/auth_secret if unset. Set explicitly if you run more than one instance. |
8080 (fixed inside the container)/app/output โ SQLite database, analysis results, trained models, user accounts, signing keyGET /healthzcurl -O https://raw.githubusercontent.com/VEEP09/api-discovery-for-nginx/main/docker-compose.yml
INGEST_TOKEN=<token> docker compose up -d
The agent has its own compose file โ see the agent image pageโ . Run it on your NGINX host, not here.
The agent expects a JSON access log. Add this to your NGINX configuration:
# /etc/nginx/nginx.conf
http {
log_format api_discovery escape=json
'{'
'"time":"$time_iso8601",'
'"remote_addr":"$remote_addr",'
'"method":"$request_method",'
'"uri":"$uri",'
'"query_string":"$query_string",'
'"status":$status,'
'"body_bytes_sent":$body_bytes_sent,'
'"request_length":$request_length,'
'"request_time":$request_time,'
'"http_user_agent":"$http_user_agent",'
'"http_referer":"$http_referer",'
'"http_x_forwarded_for":"$http_x_forwarded_for",'
'"http_authorization":"$http_authorization",'
'"http_content_type":"$http_content_type",'
'"http_accept":"$http_accept",'
'"upstream_response_time":"$upstream_response_time",'
'"host":"$host",'
'"request_id":"$request_id"'
'}';
access_log /var/log/nginx/api_access.log api_discovery;
}
Works with open-source NGINX. NGINX Plus is optional and only adds the extra REST API metrics.
| Tag | Description |
|---|---|
latest | Newest stable release (currently 1.2.1) |
1.2.1 | Fixes for the EN/KO switcher (help icons, re-render, 81 unkeyed strings). Release notesโ |
1.2.0 | English interface with an EN/KO switcher. Release notesโ |
1.1.0 | ~288 MB to pull, down from ~2.8 GB. Release notesโ |
1.0.0 | Initial release (~2.8 GB โ superseded, use 1.1.0) |
Pin a version tag in production rather than using latest, and keep the dashboard and agent on the same tag. Sizes above are compressed download sizes.
NGINX ๋ค์ ์ค์ ๋ก ์ด์ ์๋ API๋ฅผ ์ ๋ถ ์ฐพ์๋ ๋๋ค โ ์๋ฌด๋ ๋ฌธ์ํํ์ง ์์ ๊ฒ๊น์ง.
์ด๋ฏธ ์์ด๊ณ ์๋ NGINX / NGINX Plus ์ก์ธ์ค ๋ก๊ทธ๋ฅผ ์ฝ์ด ์ค์๊ฐ API ์ธ๋ฒคํ ๋ฆฌ๋ฅผ ๊ตฌ์ฑํฉ๋๋ค. ์ด๋ค ์๋ํฌ์ธํธ์ ์ค์ ํธ๋ํฝ์ด ์ค๋์ง, OpenAPI ์คํ์ ์๋ ์๋ํฌ์ธํธ(Shadow API)๋ ๋ฌด์์ธ์ง, Authorization ํค๋ ์์ด ์๋ตํ๋ ์๋ํฌ์ธํธ๋ ์ด๋์ธ์ง, ํ์์ ๋ค๋ฅด๊ฒ ๋์ํ๋ ๊ฒ์ ๋ฌด์์ธ์ง๋ฅผ ๋ณด์ฌ์ค๋๋ค. ์ ํ๋ฆฌ์ผ์ด์
์์ ๋, ๊ณ์ธก ์ฝ๋๋, SDK๋ ํ์ ์์ต๋๋ค.
์ด ์ด๋ฏธ์ง๋ ์์ง ์๋ฒ + ์น ๋์๋ณด๋(:8080) ์
๋๋ค. ๋ก๊ทธ๋ฅผ ๋ณด๋ด์ค ์์ง ์์ด์ ํธ๊ฐ ํจ๊ป ํ์ํฉ๋๋ค.
๐ ์์ด์ ํธ ์ด๋ฏธ์ง:
gusgh13900/api-discovery-agentโ โ NGINX ์๋ฒ์์ ์คํ. ์ด ์ด๋ฏธ์ง์ ๋์ผํ ๋ฒ์ ํ๊ทธ๋ก ๋ง์ถฐ ์ฌ์ฉํ์ธ์.
| ์ด๋ฏธ์ง | ์ญํ | ๋ค์ด๋ก๋ | ๋์คํฌ | ์คํ ์์น |
|---|---|---|---|---|
api-discovery-nginx (์ด ์ด๋ฏธ์ง) | ์์ง ์๋ฒ + ์น ๋์๋ณด๋ (:8080) | ~288 MB | ~1 GB | ๋์๋ณด๋ ์๋ฒ |
api-discovery-agent | NGINX ๋ก๊ทธ ์์ง ์์ด์ ํธ | ~21 MB | ~56 MB | NGINX ์๋ฒ |
linux/amd64 (ARM ๋ฏธ์ง์)docker run -d --name api-discovery-nginx \
-p 8080:8080 \
-e INGEST_TOKEN=<์ง์ ์ ํ ๊ณต์ ํ ํฐ> \
-v $PWD/output:/app/output \
gusgh13900/api-discovery-nginx:1.2.1
๋ธ๋ผ์ฐ์ ์์ http://<๋์๋ณด๋-์๋ฒ>:8080 ์ ์.
โ ๏ธ ๊ธฐ๋ณธ ๋น๋ฐ๋ฒํธ๋ฅผ ๋ฐ๋์ ๋ณ๊ฒฝํ์ธ์. ๋์๋ณด๋๋ ์ธ์ ๋ก๊ทธ์ธ์ด ํ์ํ๋ฉฐ ์ต์ด ๊ธฐ๋ ์ ๊ธฐ๋ณธ ๊ด๋ฆฌ์
admin/admin1234๊ฐ ์์ฑ๋ฉ๋๋ค. ๋ก๊ทธ์ธ ํ ์ฆ์ ๋ณ๊ฒฝํ์ธ์. ๊ณ์ ์ ๋ณผ๋ฅจ์output/auth_users.json์ ์ ์ฅ๋์ด ์ฌ์์ยท์ ๊ทธ๋ ์ด๋์๋ ์ ์ง๋ฉ๋๋ค.
์ดํ gusgh13900/api-discovery-agentโ ๋ฅผ NGINX ์๋ฒ์ ๋์ผํ INGEST_TOKEN ์ผ๋ก ๋์ฐ๋ฉด ํด๋ง ์ฃผ๊ธฐ(๊ธฐ๋ณธ 30์ด) ๋ด์ ๋ฐ์ดํฐ๊ฐ ๋ค์ด์ค๊ธฐ ์์ํฉ๋๋ค.
๋์๋ณด๋์ "์์ด์ ํธ๊ฐ ์ฐ๊ฒฐ๋์ง ์์์ต๋๋ค" ๊ฐ ๊ณ์ ๋ณด์ธ๋ค๋ฉด, ์์ธ์ ๋๋ถ๋ถ ์์ชฝ INGEST_TOKEN ๋ถ์ผ์น์
๋๋ค.
/users/{id}, /orders/{uuid})ํด ์์ URI๋ฅผ ์ค์ ์๋ํฌ์ธํธ ๋จ์๋ก ๋ฌถ์ต๋๋ค.Authorization ํค๋ ์์ด ์๋ตํ๋ ์๋ํฌ์ธํธadmin / viewer ์ญํ | ๋ณ์ | ๊ธฐ๋ณธ๊ฐ | ์ค๋ช |
|---|---|---|
INGEST_TOKEN | (๋น ๊ฐ) | ์์ด์ ํธ๊ฐ ์ ์ํด์ผ ํ๋ ๊ณต์ ํ ํฐ. ๋น์ฐ๋ฉด /api/ingest ์ธ์ฆ์ด ๋นํ์ฑํ๋ฉ๋๋ค โ ์ ๋ขฐ๋ ๋ด๋ถ๋ง์์๋ง ์ฌ์ฉํ์ธ์. |
DASHBOARD_SECRET | (์๋ ์์ฑ) | ์ธ์
์ฟ ํค ์๋ช
ํค. ๋ฏธ์ง์ ์ output/auth_secret ์ ์์ฑยท๋ณด์กด. ์ธ์คํด์ค๋ฅผ ์ฌ๋ฌ ๊ฐ ์ด์ํ๋ฉด ๋ช
์์ ์ผ๋ก ์ง์ ํ์ธ์. |
8080 (์ปจํ
์ด๋ ๋ด๋ถ ๊ณ ์ )/app/output โ SQLite DB, ๋ถ์ ๊ฒฐ๊ณผ, ํ์ต๋ ๋ชจ๋ธ, ๊ณ์ , ์๋ช
ํคGET /healthzcurl -O https://raw.githubusercontent.com/VEEP09/api-discovery-for-nginx/main/docker-compose.yml
INGEST_TOKEN=<ํ ํฐ> docker compose up -d
์์ด์ ํธ๋ ๋ณ๋ compose ํ์ผ์ ์ฌ์ฉํฉ๋๋ค โ ์์ด์ ํธ ์ด๋ฏธ์ง ํ์ด์งโ ์ฐธ๊ณ . NGINX ์๋ฒ์์ ์คํํ์ธ์.
์์ด์ ํธ๋ JSON ์ก์ธ์ค ๋ก๊ทธ๋ฅผ ์ ์ ๋ก ํฉ๋๋ค. ์ ์๋ฌธ ์น์
์ log_format api_discovery ๋ธ๋ก์ NGINX ์ค์ ์ ์ถ๊ฐํ๊ณ access_log ๋ฅผ ์ง์ ํ์ธ์.
์คํ์์ค NGINX์์ ๋์ํฉ๋๋ค. NGINX Plus๋ ์ ํ์ด๋ฉฐ REST API ๋ฉํธ๋ฆญ์ด ์ถ๊ฐ๋ ๋ฟ์ ๋๋ค.
| ํ๊ทธ | ์ค๋ช |
|---|---|
latest | ์ต์ ์์ ๋ฒ์ (ํ์ฌ 1.2.1) |
1.2.1 | ์ธ์ด ์ ํ ๊ฒฐํจ ์์ (๋์๋ง ์์ด์ฝยท์ฌ๋ ๋ยท๋ฏธ๋ถ์ฌ ํค 81๊ฑด). ๋ฆด๋ฆฌ์ค ๋ ธํธโ |
1.2.0 | ์์ด UI + EN/KO ์ธ์ด ์ ํ. ๋ฆด๋ฆฌ์ค ๋ ธํธโ |
1.1.0 | ๋ค์ด๋ก๋ ~288 MB (๊ธฐ์กด ~2.8 GB์์ ์ถ์). ๋ฆด๋ฆฌ์ค ๋ ธํธโ |
1.0.0 | ์ต์ด ๋ฆด๋ฆฌ์ค (~2.8 GB โ 1.1.0 ์ฌ์ฉ ๊ถ์ฅ) |
ํ๋ก๋์
์์๋ latest ๋์ ๊ณ ์ ๋ฒ์ ํ๊ทธ๋ฅผ ์ฐ๊ณ , ๋์๋ณด๋์ ์์ด์ ํธ๋ฅผ ๊ฐ์ ํ๊ทธ๋ก ๋ง์ถ์ธ์. ์ ํฌ๊ธฐ๋ ์์ถ๋ ๋ค์ด๋ก๋ ๊ธฐ์ค์
๋๋ค.
NGINXยฎ is a registered trademark of F5, Inc. This project is an independent tool and is not affiliated with, endorsed by, or sponsored by F5 or NGINX. "NGINX" is used here only to describe compatibility.
Content type
Image
Digest
sha256:eb38b023eโฆ
Size
275.2 MB
Last updated
about 1 month ago
docker pull gusgh13900/api-discovery-nginx