From 2e6cc71f7aa9b6f7565433cbff23b261422c7fb8 Mon Sep 17 00:00:00 2001 From: jochens Date: Fri, 2 Oct 2026 23:23:35 +0200 Subject: [PATCH] gitea: the jail also bans what gitea's sshd refuses The jail read gitea's container journal, which carries its sshd's lines, but matched only the web login. 167 ssh attempts an hour from the internet went unbanned. Two patterns, one per attempt: an unknown user, and a user sshd refuses; tested against a day of the real log, 946 matches and none on an accepted login. --- modules/gitea/module.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/modules/gitea/module.json b/modules/gitea/module.json index 0b3cbbe..fe6e671 100644 --- a/modules/gitea/module.json +++ b/modules/gitea/module.json @@ -242,7 +242,7 @@ "jails": [ { "name": "gitea", - "failregex": "^.*Failed authentication attempt for .* from (?::\\d+)?\\s*$", + "failregex": "^.*Failed authentication attempt for .* from (?::\\d+)?\\s*$\n ^.*Invalid user .* from port \\d+\\s*$\n ^.*User \\S+ from not allowed because .*$", "jail": "backend = systemd\njournalmatch = CONTAINER_NAME=gitea\nport = http,https,222\nmaxretry = 3\nfindtime = 1d\nbantime = 1d" } ]