fail2ban holds the intrusion seat's verbs and composes the jails; mail, forge and proxy declare theirs (hq ADR 0179, to-be 31)
The module gains a runtime carrying only the fail2ban client with the daemon's socket shared in, serving status/banned/ban/unban and its own fail2ban_settings. It declares jailing, so the controller's composition lands in jail.d/mesh.conf and filter.d; mailu, route-proxy and gitea log to the journal and declare a jail reading it by container name. The base is strict: three in a day for a day, twice banned in two weeks for four; the mesh's range stays never banned.
This commit is contained in:
@@ -0,0 +1,23 @@
|
||||
# fail2ban's runtime: the tool runtime, carrying the intrusion prevention's verbs and the client they
|
||||
# speak through.
|
||||
#
|
||||
# Built from this module's own directory and nothing else (novox/hq ADR 0069). Two bases, named in
|
||||
# module.json's `build.on`: the image this is compiled in and the image it runs in.
|
||||
ARG BUILD_BASE
|
||||
ARG RUNTIME_BASE
|
||||
|
||||
FROM ${BUILD_BASE} AS build
|
||||
WORKDIR /app/modules/fail2ban
|
||||
COPY . .
|
||||
RUN node /app/node_modules/typescript/bin/tsc client.ts tools/index.ts \
|
||||
--module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist
|
||||
|
||||
FROM ${RUNTIME_BASE}
|
||||
# The daemon runs on the machine, declared by this module; what runs here is only its client, which
|
||||
# speaks to the daemon over the socket the machine shares into this container (novox/hq ADR 0179).
|
||||
# The package brings the client and the daemon together; the daemon is never started here.
|
||||
RUN apt-get update \
|
||||
&& apt-get install -y --no-install-recommends fail2ban \
|
||||
&& rm -rf /var/lib/apt/lists/*
|
||||
COPY --from=build /app/modules/fail2ban/dist /app/modules/fail2ban/dist
|
||||
ENV MESH_TOOL_MODULES=/app/modules/fail2ban/dist/tools/index.js
|
||||
Reference in New Issue
Block a user