fail2ban holds the intrusion seat's verbs and composes the jails; mail, forge and proxy declare theirs (hq ADR 0179, to-be 31)
The module gains a runtime carrying only the fail2ban client with the daemon's socket shared in, serving status/banned/ban/unban and its own fail2ban_settings. It declares jailing, so the controller's composition lands in jail.d/mesh.conf and filter.d; mailu, route-proxy and gitea log to the journal and declare a jail reading it by container name. The base is strict: three in a day for a day, twice banned in two weeks for four; the mesh's range stays never banned.
This commit is contained in:
@@ -163,7 +163,8 @@
|
||||
"acme-env",
|
||||
"internal-trust",
|
||||
"internal-acme-env"
|
||||
]
|
||||
],
|
||||
"logging": "journald"
|
||||
}
|
||||
],
|
||||
"build": {
|
||||
@@ -194,5 +195,12 @@
|
||||
"image": "alpine@sha256:d9e853e87e55526f6b2917df91a2115c36dd7c696a35be12163d44e6e2a4b6bc"
|
||||
}
|
||||
]
|
||||
}
|
||||
},
|
||||
"jails": [
|
||||
{
|
||||
"name": "route-proxy",
|
||||
"failregex": "^.*(?:TLS handshake error from <HOST>:\\d+: (?:no public route for|acme/autocert: missing server name)|refused: no route for .*, asked from <HOST>:\\d+)$",
|
||||
"jail": "backend = systemd\njournalmatch = CONTAINER_NAME=route-proxy\nport = http,https\nmaxretry = 10\nfindtime = 1d\nbantime = 1d"
|
||||
}
|
||||
]
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user