fail2ban bans through an action every machine has #135

Merged
mesh-admin merged 1 commits from fix/fail2ban-bans-through-what-every-machine-has into main 2026-09-28 18:48:26 +00:00
Contributor
No description provided.
mesh-admin added 1 commit 2026-09-28 18:48:25 +00:00
jail.local named ufw as the ban action. Two machines on this mesh have no ufw,
and fail2ban does not check: it starts, the jail reads the log, counts the
attempts, runs the ban command, gets 127 -- 'ufw: command not found' -- and
logs an error nobody reads. The service is active, the mesh reports the module
applied, and the machine is not protected. Proven by banning a documentation
address on such a machine today.

The replacement is this module's own dualchain action, already used by the
recidive jail on all four machines, so it is not a new dependency. It bans in
DOCKER-USER as well as INPUT, which ufw's action did not, and it bans all
ports, which ufw's action did.
mesh-admin merged commit 4d7e37e319 into main 2026-09-28 18:48:26 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-catalog#135