fail2ban: require the firewall capability, not the non-existent intrusion-prevention

The whole-mesh dry-run found fail2ban unassignable on every node: it declared
`capabilities: ["intrusion-prevention"]`, which mesh-host has no detector for
(its detectors are container-runtime, package-manager, service-manager,
firewall, overlay, graphical-session, seat, privileged). intrusion-prevention
is what fail2ban PROVIDES, not a host capability it needs. It bans via
iptables/ufw, so it needs `firewall` — the same capability the firewall module
declares. The `the-intrusion-prevention` claim (node-exclusive) is unchanged.

Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
This commit is contained in:
2026-09-08 18:27:34 +02:00
parent e0456746c3
commit 75fb16bbfb
+1 -1
View File
@@ -2,7 +2,7 @@
"module": "fail2ban",
"version": "1",
"capabilities": [
"intrusion-prevention"
"firewall"
],
"claims": [
{