fail2ban's tools are a bundle the node's runtime serves; its container goes (hq to-be 38 WP4) #240

Merged
mesh-admin merged 1 commits from feat/fail2ban-tools-as-a-bundle into main 2026-10-03 13:07:35 +00:00
Contributor

The second holder follows the packet filter (design 38 WP4: "then the fail2ban holder follows the same way").

modules/fail2ban:

  • module.json: the runtime container, both build.on base images, own-secrets and the mesh-state directory go (only the container read that credential; the runtime speaks with the node's). Tools declared as build.artifacts: [{tools, bundle, typescript, entrypoints: [tools/index.js]}]. The package, directories, jails, actions, logrotate and service stay as they were.
  • Dockerfile removed.
  • client.ts: fail2ban-client runs as given by root and through sudo -n otherwise — the daemon's socket is root's (verified on the laptop: refused as the operator account, pong through sudo). Sudo's absence, a refusal and a missing client are named by how they failed. Fail2banClient.onThisMachine().
  • test/client.test.ts: 8/8, escalation covered. Builder-style tsc (--rootDir ., against the SDK) clean; controller catalogue tests pass uncached against this tree.

Proof after the push: node-intrusion-prevention.status, banned, ban, unban and fail2ban.fail2ban_settings answer from node-tools on all four; docker ps shows no mesh-fail2ban; status well.

The second holder follows the packet filter (design 38 WP4: "then the fail2ban holder follows the same way"). `modules/fail2ban`: - `module.json`: the `runtime` container, both `build.on` base images, `own-secrets` and the `mesh-state` directory go (only the container read that credential; the runtime speaks with the node's). Tools declared as `build.artifacts: [{tools, bundle, typescript, entrypoints: [tools/index.js]}]`. The package, directories, jails, actions, logrotate and service stay as they were. - `Dockerfile` removed. - `client.ts`: `fail2ban-client` runs as given by root and through `sudo -n` otherwise — the daemon's socket is root's (verified on the laptop: refused as the operator account, `pong` through sudo). Sudo's absence, a refusal and a missing client are named by how they failed. `Fail2banClient.onThisMachine()`. - `test/client.test.ts`: 8/8, escalation covered. Builder-style tsc (`--rootDir .`, against the SDK) clean; controller catalogue tests pass uncached against this tree. Proof after the push: `node-intrusion-prevention.status`, `banned`, `ban`, `unban` and `fail2ban.fail2ban_settings` answer from node-tools on all four; `docker ps` shows no `mesh-fail2ban`; `status` well.
mesh-admin added 1 commit 2026-10-03 13:07:32 +00:00
The second holder follows the packet filter: the container, its base images, the Dockerfile,
and the bus credential and state directory only the container read are gone; the tools are a
TypeScript bundle node-tools loads. The daemon's socket answers only to root, so the client
runs through sudo without a prompt where the runtime's account is not root, naming sudo's
absence or refusal by how it failed; client and daemon are the one package the module declares.
mesh-admin merged commit d5269c8662 into main 2026-10-03 13:07:35 +00:00
mesh-admin deleted branch feat/fail2ban-tools-as-a-bundle 2026-10-03 13:07:35 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-catalog#240