
Docker configuration to quickly setup your own Canarytokens.
by Thinkst Applied Research
Canarytokens help track activity and actions on your network.
If you have any issues please check out our FAQ over here, or create an issue and we'll try to get back to you as soon as possible.
This project and everyone participating in it is governed by the Code of Conduct. By participating, you are expected to uphold this code. Please report unacceptable behavior to [email protected].
docker compose -f docker-compose.yml down
or docker compose -f docker-compose-letsencrypt.yml downdocker-compose no longer works, and you will need to run docker network prune before bringing up your Canarytokens instance with docker compose. Canarytokens v2 will still work.canarytokens-docker repo.docker compose -f docker-compose.yml up -d
or docker compose -f docker-compose-letsencrypt.yml up -dNB: The updated canarytokens-docker repo no longer has the Dockerfile for Canarytokens v2, so running that requires using the tagged image thinkst/canarytokens:v2_latest. We highly recommend moving to v3. Please contact us if you're battling with the migration.
$ git clone https://github.com/thinkst/canarytokens-docker
$ cd canarytokens-docker
$ sudo apt-get install python3-pip python3-dev
$ sudo pip install -U docker-compose
#if this breaks with PyYAML errors, install the libyaml development package
# sudo apt-get install libyaml-dev
switchboard.env.dist and frontend.env.dist. You'll need to copy/rename them to switchboard.env and frontend.env respectively (this ensures that your configuration doesn't get blown away if you pull changes). Once that is done, you can edit them:Please go through both your newly created configuration files, switchboard.env and frontend.env, and fill in the Required Settings section. The Optional Settings are not required to work and have sane defaults so don't change them if you don't need to.
Next decide on which email provider you want to use to send alerts. You will have to decide between mailgun, SMTP and sendgrid. The relevant required details can be found in the relevant .env file.
Generate a single unique WireGuard key seed to set as CANARY_WG_PRIVATE_KEY_SEED in both switchboard.env and frontend.env with the command:
dd bs=32 count=1 if=/dev/urandom 2>/dev/null | base64
the domains example1.com, example2.com, and example3.com (PDFs) for canarytoken triggers via switchboard
the public IP 1.1.1.1 for the switchboard triggers
the domain 'my.domain' to serve the frontend
the Mailgun Domain Name 'x.y' and API Key 'zzzzzzzzzz'
the WireGuard key seed vk/GD+frlhve/hDTTSUvqpQ/WsQtioKAri0Rt5mg7dw=
frontend.env
#These domains are used for general purpose tokens
CANARY_PUBLIC_IP=1.1.1.1
CANARY_DOMAINS=example1.com,example2.com
#These domains are only used for PDF tokens
CANARY_NXDOMAINS=example3.com
#Requires a Google Cloud API key to generate an incident map on the history page with the Maps JavaScript API
CANARY_GOOGLE_API_KEY=<grab google maps api key>
LOG_FILE=frontend.log
CANARY_PUBLIC_DOMAIN=mydomain.com
LOG_FILE=switchboard.log
CANARY_MAILGUN_DOMAIN_NAME=x.y
CANARY_MAILGUN_API_KEY=zzzzzzzzzz
[email protected]
CANARY_ALERT_EMAIL_FROM_DISPLAY="Example Canarytokens"
CANARY_ALERT_EMAIL_SUBJECT="Canarytoken"
CANARY_WG_PRIVATE_KEY_SEED=vk/GD+frlhve/hDTTSUvqpQ/WsQtioKAri0Rt5mg7dw=
$ docker compose up
$ docker compose up -d
NOTE: If you only own one domain, and would like to use pdf tokens, you can use subdomains for CANARY_NXDOMAINS. Using example.com as our domain, you can set CANARY_NXDOMAINS to nx.example.com. Then log into your DNS manager console (where you can edit your domain DNS records) and add an NS record of nx.example.com mapping to example.com.
The tokens are saved in a Redis database file that exists outside of the Docker containers. Look for dump.rdb in the canarytokens-docker/data directory.
If you want to wipe all your tokens, delete dump.rdb.
We have a separate docker-compose file that will automate (mostly) getting you up and running a Canarytokens server with HTTPS. You will need to do the following:
certbot.env. You will need to provide your domain and email address (these are necessary for the certbot's registration process).
E.g.# Specify a single domain name
MY_DOMAIN_NAME=example.com
# or multiple domains names with this different key (comment out MY_DOMAIN_NAME above if you do):
# MY_DOMAIN_NAMES=example.com anotherexample.net thirdexample.org
[email protected]
Now when you want to bring up your server, you will use docker compose -f docker-compose-letsencrypt.yml up which will run the
server in the foreground so you can make sure everything gets started alright.
If everything is running, you may want to CTRL+C, run docker compose -f docker-compose-letsencrypt.yml down to get to a clean slate, and then rerun docker compose -f docker-compose-letsencrypt.yml up -d with the added -d to run the server in the background (in daemon mode)
Please keep in mind that using the HTTPS method will use the email you specified and the domain name to register the certificate. You can read about the let's encrypt process (using cerbot) over here. The process involves verifying that you are the owner of the domain you have specified and registering you with let's encrypt.
THERE IS A RATE LIMIT. So don't keep bringing this server up and down otherwise you will quickly hit a let's encrypt certificate generation limit. To avoid this, for testing purposes you may add --staging to the ./certbot-auto command in cerbot-nginx/start.sh which will test whether let's encrypt gives you the certificate.