fail2ban holds the intrusion seat's verbs and composes the jails; mail, forge and proxy declare theirs (hq ADR 0179, to-be 31) #225

Merged
mesh-admin merged 1 commits from feat/the-intrusion-seat-serves-its-verbs into main 2026-10-02 15:19:20 +00:00
Contributor
  • fail2ban: claims the seat's four verbs, gains a runtime (mesh-fail2ban: the tool runtime plus the fail2ban client, the daemon's socket shared in), declares jailing so the controller's composition lands in jail.d/mesh.conf and filter.d, restarts the daemon on the composed file, and tightens the base: three in a day for a day; twice banned in two weeks for four. The mesh's own range stays never banned.
  • mailu, route-proxy, gitea: the container logs to the journal and the module declares a jail reading it by container name (backend systemd). Each container is recreated once on push.

Merge last, after mesh-host and mesh-controller have rolled. Then mesh-controller.issue {module: fail2ban, node} for every node before pushing (the runtime needs a bus credential), broker node first.

Tests: modules/fail2ban/test/client.test.ts over a fake runner with the shapes fail2ban 1.1.0 printed live.

- fail2ban: claims the seat's four verbs, gains a runtime (`mesh-fail2ban`: the tool runtime plus the fail2ban client, the daemon's socket shared in), declares `jailing` so the controller's composition lands in `jail.d/mesh.conf` and `filter.d`, restarts the daemon on the composed file, and tightens the base: three in a day for a day; twice banned in two weeks for four. The mesh's own range stays never banned. - mailu, route-proxy, gitea: the container logs to the journal and the module declares a jail reading it by container name (backend systemd). Each container is recreated once on push. Merge last, after mesh-host and mesh-controller have rolled. Then `mesh-controller.issue {module: fail2ban, node}` for every node before pushing (the runtime needs a bus credential), broker node first. Tests: `modules/fail2ban/test/client.test.ts` over a fake runner with the shapes fail2ban 1.1.0 printed live.
mesh-admin added 1 commit 2026-10-02 15:03:21 +00:00
The module gains a runtime carrying only the fail2ban client with the daemon's socket shared in,
serving status/banned/ban/unban and its own fail2ban_settings. It declares jailing, so the
controller's composition lands in jail.d/mesh.conf and filter.d; mailu, route-proxy and gitea log to
the journal and declare a jail reading it by container name. The base is strict: three in a day for
a day, twice banned in two weeks for four; the mesh's range stays never banned.
mesh-admin merged commit 3c3c5c6e03 into main 2026-10-02 15:19:20 +00:00
mesh-admin deleted branch feat/the-intrusion-seat-serves-its-verbs 2026-10-02 15:19:21 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-catalog#225