fail2ban declares where it logs, so the recidive jail has a file to read #132

Merged
mesh-admin merged 1 commits from fix/fail2ban-declares-where-it-logs into main 2026-09-28 18:41:17 +00:00
Contributor
No description provided.
mesh-admin added 1 commit 2026-09-28 18:41:15 +00:00
The recidive jail reads /var/log/fail2ban.log and this module ships the
logrotate file for it, but nothing ever told fail2ban to write there. Where
the package default stands, fail2ban logs to the journal, the recidive jail
finds no log file, and the whole service refuses to start -- taking the sshd
jail with it. Two machines assigned this module today came up failed; the two
where it worked had /etc/fail2ban/fail2ban.conf edited by hand, which a
package upgrade would have undone.

Declared in fail2ban.local, because fail2ban.conf belongs to the package.
mesh-admin merged commit 87366c5f36 into main 2026-09-28 18:41:17 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-catalog#132