The module gains a runtime carrying only the fail2ban client with the daemon's socket shared in, serving status/banned/ban/unban and its own fail2ban_settings. It declares jailing, so the controller's composition lands in jail.d/mesh.conf and filter.d; mailu, route-proxy and gitea log to the journal and declare a jail reading it by container name. The base is strict: three in a day for a day, twice banned in two weeks for four; the mesh's range stays never banned.
24 lines
1.1 KiB
Docker
24 lines
1.1 KiB
Docker
# fail2ban's runtime: the tool runtime, carrying the intrusion prevention's verbs and the client they
|
|
# speak through.
|
|
#
|
|
# Built from this module's own directory and nothing else (novox/hq ADR 0069). Two bases, named in
|
|
# module.json's `build.on`: the image this is compiled in and the image it runs in.
|
|
ARG BUILD_BASE
|
|
ARG RUNTIME_BASE
|
|
|
|
FROM ${BUILD_BASE} AS build
|
|
WORKDIR /app/modules/fail2ban
|
|
COPY . .
|
|
RUN node /app/node_modules/typescript/bin/tsc client.ts tools/index.ts \
|
|
--module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist
|
|
|
|
FROM ${RUNTIME_BASE}
|
|
# The daemon runs on the machine, declared by this module; what runs here is only its client, which
|
|
# speaks to the daemon over the socket the machine shares into this container (novox/hq ADR 0179).
|
|
# The package brings the client and the daemon together; the daemon is never started here.
|
|
RUN apt-get update \
|
|
&& apt-get install -y --no-install-recommends fail2ban \
|
|
&& rm -rf /var/lib/apt/lists/*
|
|
COPY --from=build /app/modules/fail2ban/dist /app/modules/fail2ban/dist
|
|
ENV MESH_TOOL_MODULES=/app/modules/fail2ban/dist/tools/index.js
|