fail2ban holds the intrusion seat's verbs and composes the jails; mail, forge and proxy declare theirs (hq ADR 0179, to-be 31)

The module gains a runtime carrying only the fail2ban client with the daemon's socket shared in,
serving status/banned/ban/unban and its own fail2ban_settings. It declares jailing, so the
controller's composition lands in jail.d/mesh.conf and filter.d; mailu, route-proxy and gitea log to
the journal and declare a jail reading it by container name. The base is strict: three in a day for
a day, twice banned in two weeks for four; the mesh's range stays never banned.
This commit is contained in:
2026-10-02 17:02:49 +02:00
parent 96b3d60a4a
commit 1601d5a335
9 changed files with 474 additions and 87 deletions
+10 -2
View File
@@ -163,7 +163,8 @@
"acme-env",
"internal-trust",
"internal-acme-env"
]
],
"logging": "journald"
}
],
"build": {
@@ -194,5 +195,12 @@
"image": "alpine@sha256:d9e853e87e55526f6b2917df91a2115c36dd7c696a35be12163d44e6e2a4b6bc"
}
]
}
},
"jails": [
{
"name": "route-proxy",
"failregex": "^.*(?:TLS handshake error from <HOST>:\\d+: (?:no public route for|acme/autocert: missing server name)|refused: no route for .*, asked from <HOST>:\\d+)$",
"jail": "backend = systemd\njournalmatch = CONTAINER_NAME=route-proxy\nport = http,https\nmaxretry = 10\nfindtime = 1d\nbantime = 1d"
}
]
}