fail2ban: require the firewall capability, not the non-existent intrusion-prevention
The whole-mesh dry-run found fail2ban unassignable on every node: it declared `capabilities: ["intrusion-prevention"]`, which mesh-host has no detector for (its detectors are container-runtime, package-manager, service-manager, firewall, overlay, graphical-session, seat, privileged). intrusion-prevention is what fail2ban PROVIDES, not a host capability it needs. It bans via iptables/ufw, so it needs `firewall` — the same capability the firewall module declares. The `the-intrusion-prevention` claim (node-exclusive) is unchanged. Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
This commit is contained in:
@@ -2,7 +2,7 @@
|
|||||||
"module": "fail2ban",
|
"module": "fail2ban",
|
||||||
"version": "1",
|
"version": "1",
|
||||||
"capabilities": [
|
"capabilities": [
|
||||||
"intrusion-prevention"
|
"firewall"
|
||||||
],
|
],
|
||||||
"claims": [
|
"claims": [
|
||||||
{
|
{
|
||||||
|
|||||||
Reference in New Issue
Block a user