From 75fb16bbfb24048b68e2c02e5df3128250a06d46 Mon Sep 17 00:00:00 2001 From: jochen Date: Tue, 8 Sep 2026 18:27:34 +0200 Subject: [PATCH] fail2ban: require the `firewall` capability, not the non-existent `intrusion-prevention` MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The whole-mesh dry-run found fail2ban unassignable on every node: it declared `capabilities: ["intrusion-prevention"]`, which mesh-host has no detector for (its detectors are container-runtime, package-manager, service-manager, firewall, overlay, graphical-session, seat, privileged). intrusion-prevention is what fail2ban PROVIDES, not a host capability it needs. It bans via iptables/ufw, so it needs `firewall` — the same capability the firewall module declares. The `the-intrusion-prevention` claim (node-exclusive) is unchanged. Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF --- modules/fail2ban/module.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/modules/fail2ban/module.json b/modules/fail2ban/module.json index efbfe17..8b94092 100644 --- a/modules/fail2ban/module.json +++ b/modules/fail2ban/module.json @@ -2,7 +2,7 @@ "module": "fail2ban", "version": "1", "capabilities": [ - "intrusion-prevention" + "firewall" ], "claims": [ {