Every request that leaves the host
The whole list; nothing on it is on until you switch it on. Three destinations are fixed
— api.github.com, telemetry.wdkro.de and ClamAV's mirrors.
Every other one is a server you name.
| Request, switched on by | Destination | How often | Carries |
|---|---|---|---|
Update check UPDATE_CHECK_ENABLED=true |
api.github.com — fixed |
at every start, then daily at 04:00 UTC | a GET for the latest release; the User-Agent names the version |
Installation count the setup wizard or Admin → System, or TELEMETRY_ENABLED=true |
telemetry.wdkro.de — fixed |
once a day | a random identifier and the version, in full below |
Email NOTIFY_EMAIL_ENABLED=true |
NOTIFY_SMTP_HOST — yours |
a digest every NOTIFICATION_BATCH_MINUTES; SLA reminders (REMINDER_ENABLED, checked every 30 min); a security alert at once on suspected password spraying; a reply notice when a case manager answers |
counts and case numbers to your admins; a bare "you have a reply" to a whistleblower's own address |
Webhook NOTIFY_WEBHOOK_ENABLED=true |
NOTIFY_WEBHOOK_URL — yours |
the digest, SLA reminders and the security alert, as for email | counts only, never a case number (Notifications) |
Virus signatures COMPOSE_PROFILES=clamav |
ClamAV's mirrors — fixed, from the clamav container's freshclam, not the app |
freshclam's schedule | nothing from OpenWhistle |
Tor network ONION_LOCATION and the Tor daemon you run (Offering an onion address) |
Tor relays, from that daemon, not the app | continuously while it runs | the hidden service's own circuits; nothing from OpenWhistle |
Attachment storage STORAGE_BACKEND=s3 |
S3_ENDPOINT_URL — yours |
on upload and download | encrypted attachments under random keys |
Sign-in OIDC_ENABLED / LDAP_ENABLED |
OIDC_SERVER_METADATA_URL / LDAP_SERVER — yours |
at an admin sign-in | the admin's credentials, to your identity provider |
None carries a whistleblower's words or files in readable form: attachments reach S3 encrypted, and notifications never include report content.
Through a proxy: the update check, the installation count, webhooks,
OIDC and S3 honour HTTPS_PROXY, ALL_PROXY and
NO_PROXY in the app container (SSL_CERT_FILE for a proxy's CA).
SMTP and LDAP connect directly.