The second holder follows the packet filter (design 38 WP4: "then the fail2ban holder follows the same way").
modules/fail2ban:
module.json: the runtime container, both build.on base images, own-secrets and the mesh-state directory go (only the container read that credential; the runtime speaks with the node's). Tools declared as build.artifacts: [{tools, bundle, typescript, entrypoints: [tools/index.js]}]. The package, directories, jails, actions, logrotate and service stay as they were.
Dockerfile removed.
client.ts: fail2ban-client runs as given by root and through sudo -n otherwise — the daemon's socket is root's (verified on the laptop: refused as the operator account, pong through sudo). Sudo's absence, a refusal and a missing client are named by how they failed. Fail2banClient.onThisMachine().
test/client.test.ts: 8/8, escalation covered. Builder-style tsc (--rootDir ., against the SDK) clean; controller catalogue tests pass uncached against this tree.
Proof after the push: node-intrusion-prevention.status, banned, ban, unban and fail2ban.fail2ban_settings answer from node-tools on all four; docker ps shows no mesh-fail2ban; status well.
The second holder follows the packet filter (design 38 WP4: "then the fail2ban holder follows the same way").
`modules/fail2ban`:
- `module.json`: the `runtime` container, both `build.on` base images, `own-secrets` and the `mesh-state` directory go (only the container read that credential; the runtime speaks with the node's). Tools declared as `build.artifacts: [{tools, bundle, typescript, entrypoints: [tools/index.js]}]`. The package, directories, jails, actions, logrotate and service stay as they were.
- `Dockerfile` removed.
- `client.ts`: `fail2ban-client` runs as given by root and through `sudo -n` otherwise — the daemon's socket is root's (verified on the laptop: refused as the operator account, `pong` through sudo). Sudo's absence, a refusal and a missing client are named by how they failed. `Fail2banClient.onThisMachine()`.
- `test/client.test.ts`: 8/8, escalation covered. Builder-style tsc (`--rootDir .`, against the SDK) clean; controller catalogue tests pass uncached against this tree.
Proof after the push: `node-intrusion-prevention.status`, `banned`, `ban`, `unban` and `fail2ban.fail2ban_settings` answer from node-tools on all four; `docker ps` shows no `mesh-fail2ban`; `status` well.
The second holder follows the packet filter: the container, its base images, the Dockerfile,
and the bus credential and state directory only the container read are gone; the tools are a
TypeScript bundle node-tools loads. The daemon's socket answers only to root, so the client
runs through sudo without a prompt where the runtime's account is not root, naming sudo's
absence or refusal by how it failed; client and daemon are the one package the module declares.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
The second holder follows the packet filter (design 38 WP4: "then the fail2ban holder follows the same way").
modules/fail2ban:module.json: theruntimecontainer, bothbuild.onbase images,own-secretsand themesh-statedirectory go (only the container read that credential; the runtime speaks with the node's). Tools declared asbuild.artifacts: [{tools, bundle, typescript, entrypoints: [tools/index.js]}]. The package, directories, jails, actions, logrotate and service stay as they were.Dockerfileremoved.client.ts:fail2ban-clientruns as given by root and throughsudo -notherwise — the daemon's socket is root's (verified on the laptop: refused as the operator account,pongthrough sudo). Sudo's absence, a refusal and a missing client are named by how they failed.Fail2banClient.onThisMachine().test/client.test.ts: 8/8, escalation covered. Builder-style tsc (--rootDir ., against the SDK) clean; controller catalogue tests pass uncached against this tree.Proof after the push:
node-intrusion-prevention.status,banned,ban,unbanandfail2ban.fail2ban_settingsanswer from node-tools on all four;docker psshows nomesh-fail2ban;statuswell.