fail2ban's tools are a bundle the node's runtime serves; its container goes (hq to-be 38 WP4)
The second holder follows the packet filter: the container, its base images, the Dockerfile, and the bus credential and state directory only the container read are gone; the tools are a TypeScript bundle node-tools loads. The daemon's socket answers only to root, so the client runs through sudo without a prompt where the runtime's account is not root, naming sudo's absence or refusal by how it failed; client and daemon are the one package the module declares.
This commit is contained in:
@@ -55,7 +55,7 @@ export function getFail2banTools(fail2ban: Fail2banClient): ToolDefinition[] {
|
||||
];
|
||||
}
|
||||
|
||||
const fail2ban = Fail2banClient.fromEnv();
|
||||
const fail2ban = Fail2banClient.onThisMachine();
|
||||
// The seat's verbs under the seat's name: the runtime serves them on the seat's subjects where this
|
||||
// module holds it (ADR 0159, 0160). The module's own under its own.
|
||||
registerModuleTools("node-intrusion-prevention", () => getSeatVerbs(fail2ban));
|
||||
|
||||
Reference in New Issue
Block a user