The proxy's jail reads both refusals, each pattern naming the host once

fail2ban expands <HOST> to a named group, so two in one pattern is a duplicate group name and
the daemon refuses to start at all -- every jail on the machine, not just this one. Two patterns,
one <HOST> each: the certificate refused for an unserved name, and the request refused for one.
Caught live on the control node (hq ADR 0179).
This commit is contained in:
2026-10-02 17:23:42 +02:00
parent b547308e05
commit 23112b111c
+1 -1
View File
@@ -199,7 +199,7 @@
"jails": [
{
"name": "route-proxy",
"failregex": "^.*(?:TLS handshake error from <HOST>:\\d+: (?:no public route for|acme/autocert: missing server name)|refused: no route for .*, asked from <HOST>:\\d+)",
"failregex": "^.*TLS handshake error from <HOST>:\\d+: (?:no public route for|acme/autocert: missing server name)\n ^.*refused: no route for .*, asked from <HOST>:\\d+$",
"jail": "backend = systemd\njournalmatch = CONTAINER_NAME=route-proxy\nport = http,https\nmaxretry = 10\nfindtime = 1d\nbantime = 1d"
}
]