Sign inSign up

romanvaxman/cerberus-selfhost

By romanvaxman

•Updated 1 day ago

Self-hosted website scanner with Lighthouse, Nuclei, OWASP ZAP, and sqlmap.

Image
0

432

romanvaxman/cerberus-selfhost repository overview

Cerberus Scan

⁠Cerberus

Cerberus is a free, self-hosted website security and quality scanner with local users, scan history, reports, and optional AI analysis. It combines passive checks with local Lighthouse and explicitly authorized Nuclei, OWASP ZAP, and sqlmap testing.

This image is the application service, not the complete stack. Cerberus also uses isolated tools, ZAP, and secret-initialization containers. Use the Compose quick start below instead of running this image by itself.

⁠Install

Requirements: Docker Engine, Docker Compose v2, OpenSSL, Git, and roughly 8 GB of free disk space.

git clone https://github.com/vaxman14/cerberus-selfhost.git
cd cerberus-selfhost
./scripts/setup.sh

Setup generates local secrets, pulls the versioned Docker Hub images, starts the complete stack, waits for health, and prints the URL. Open http://127.0.0.1:8099⁠ and create the first local owner.

If Docker is on another machine, keep the safe localhost bind and create an SSH tunnel from your computer:

ssh -L 8099:127.0.0.1:8099 user@docker-host

Then open http://127.0.0.1:8099⁠ locally.

⁠Safe defaults

  • Binds only to 127.0.0.1
  • Requires a local owner login
  • Keeps the app database and provider vault on your Docker host
  • Publishes no scanner-worker ports
  • Disables active Nuclei, ZAP, and sqlmap scans
  • Runs containers with read-only roots, dropped capabilities, and no-new-privileges

To enable active tools, set CERBERUS_ENABLE_ACTIVE_SCANS=true in .env and run docker compose up -d. Every active run still requires explicit authorization and production-risk confirmation. Only scan systems you own or are authorized to assess.

⁠Operations

docker compose ps
docker compose logs --tail=200 cerberus
./scripts/backup.sh
./scripts/update.sh
docker compose down

Ordinary docker compose down preserves data. docker compose down --volumes permanently deletes local volumes. Back up secrets/cerberus_master_key separately from database archives; saved provider credentials cannot be decrypted without it.

⁠Images

  • romanvaxman/cerberus-selfhost:0.2.2
  • romanvaxman/cerberus-tools:0.2.2
  • romanvaxman/cerberus-zap:0.2.2
  • romanvaxman/cerberus-aio:0.2.2 — optional Docker-socket launcher

Images support linux/amd64 and linux/arm64.

Cerberus is free software. Contributions do not purchase support, features, or an SLA.

Tag summary

Content type

Image

Digest

sha256:454da9fb2…

Size

214.8 MB

Last updated

1 day ago

docker pull romanvaxman/cerberus-selfhost