fail2ban: require the firewall capability, not the non-existent intrusion-prevention
The whole-mesh dry-run found fail2ban unassignable on every node: it declared `capabilities: ["intrusion-prevention"]`, which mesh-host has no detector for (its detectors are container-runtime, package-manager, service-manager, firewall, overlay, graphical-session, seat, privileged). intrusion-prevention is what fail2ban PROVIDES, not a host capability it needs. It bans via iptables/ufw, so it needs `firewall` — the same capability the firewall module declares. The `the-intrusion-prevention` claim (node-exclusive) is unchanged. Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
This commit is contained in:
@@ -2,7 +2,7 @@
|
||||
"module": "fail2ban",
|
||||
"version": "1",
|
||||
"capabilities": [
|
||||
"intrusion-prevention"
|
||||
"firewall"
|
||||
],
|
||||
"claims": [
|
||||
{
|
||||
|
||||
Reference in New Issue
Block a user