jail.local named ufw as the ban action. Two machines on this mesh have no ufw, and fail2ban does not check: it starts, the jail reads the log, counts the attempts, runs the ban command, gets 127 -- 'ufw: command not found' -- and logs an error nobody reads. The service is active, the mesh reports the module applied, and the machine is not protected. Proven by banning a documentation address on such a machine today. The replacement is this module's own dualchain action, already used by the recidive jail on all four machines, so it is not a new dependency. It bans in DOCKER-USER as well as INPUT, which ufw's action did not, and it bans all ports, which ufw's action did.
89 lines
4.7 KiB
JSON
89 lines
4.7 KiB
JSON
{
|
|
"module": "fail2ban",
|
|
"version": "1",
|
|
"capabilities": [
|
|
"firewall"
|
|
],
|
|
"claims": [
|
|
{
|
|
"name": "node-intrusion-prevention",
|
|
"scope": "node"
|
|
}
|
|
],
|
|
"resources": [
|
|
{
|
|
"id": "package",
|
|
"type": "package",
|
|
"package": "fail2ban"
|
|
},
|
|
{
|
|
"id": "jail-d",
|
|
"type": "directory",
|
|
"path": "/etc/fail2ban/jail.d",
|
|
"mode": "0755"
|
|
},
|
|
{
|
|
"id": "action-d",
|
|
"type": "directory",
|
|
"path": "/etc/fail2ban/action.d",
|
|
"mode": "0755"
|
|
},
|
|
{
|
|
"id": "jail-local",
|
|
"type": "file",
|
|
"path": "/etc/fail2ban/jail.local",
|
|
"mode": "0644",
|
|
"content": "[INCLUDES]\n\nbefore = paths-arch.conf\n\n[DEFAULT]\n\n# Never act on the machine itself or on a tunnel peer: the mesh's private range is\n# ${machine:mesh-range}, named here rather than written as a value the module cannot\n# know (novox/hq ADR 0112). Without this, fail2ban could ban the mesh's own nodes.\nignoreip = 127.0.0.1/8 ::1 ${machine:mesh-range}\n\nbantime = 10m\nfindtime = 10m\nmaxretry = 5\n\n# Ban through iptables, not through a firewall front-end the machine may not have. ufw is\n# installed on two of this mesh's machines and absent on the other two, and fail2ban finds out\n# only at ban time: the service reports healthy, the jail counts the attempt, the ban command\n# exits 127, and nothing is blocked. Proven on 2026-09-28 -- 'ufw: command not found' on a\n# machine the mesh reported as protected.\n#\n# The action below is this module's own, already used by the recidive jail on every machine\n# here, and it bans in DOCKER-USER as well as INPUT, so a container's published port is\n# covered too.\nbanaction = iptables-allports-dualchain\nbanaction_allports = iptables-allports-dualchain\n\n[sshd]\nenabled = true\nport = ssh\nlogpath = %(sshd_log)s\nbackend = %(sshd_backend)s\n"
|
|
},
|
|
{
|
|
"id": "jail-sshd",
|
|
"type": "file",
|
|
"path": "/etc/fail2ban/jail.d/sshd.conf",
|
|
"mode": "0644",
|
|
"content": "[sshd]\nenabled = true\nport = ssh\nlogpath = %(sshd_log)s\nbackend = %(sshd_backend)s\nmaxretry = 5\n"
|
|
},
|
|
{
|
|
"id": "log",
|
|
"type": "file",
|
|
"path": "/var/log/fail2ban.log",
|
|
"mode": "0640",
|
|
"create-once": true,
|
|
"content": ""
|
|
},
|
|
{
|
|
"id": "jail-recidive",
|
|
"type": "file",
|
|
"path": "/etc/fail2ban/jail.d/recidive.conf",
|
|
"mode": "0644",
|
|
"content": "[recidive]\nenabled = true\nlogpath = /var/log/fail2ban.log\n# Ban in both INPUT (host services like SSH) and DOCKER-USER (container services)\nbanaction = iptables-allports-dualchain\nbantime = 1w\nfindtime = 1d\n"
|
|
},
|
|
{
|
|
"id": "action-dualchain",
|
|
"type": "file",
|
|
"path": "/etc/fail2ban/action.d/iptables-allports-dualchain.conf",
|
|
"mode": "0644",
|
|
"content": "# Fail2Ban action: ban in both INPUT and DOCKER-USER chains\n# Used by recidive to block repeat offenders from both host and Docker services\n\n[INCLUDES]\n\nbefore = iptables.conf\n\n[Definition]\n\ntype = allports\n\nactionstart = { <iptables> -C f2b-<name> -j <returntype> >/dev/null 2>&1; } || { <iptables> -N f2b-<name> || true; <iptables> -A f2b-<name> -j <returntype>; }\n { <iptables> -C INPUT -p <protocol> -j f2b-<name> >/dev/null 2>&1; } || { <iptables> -I INPUT -p <protocol> -j f2b-<name>; }\n { <iptables> -C DOCKER-USER -p <protocol> -j f2b-<name> >/dev/null 2>&1; } || { <iptables> -I DOCKER-USER -p <protocol> -j f2b-<name>; }\n\nactionstop = <iptables> -D INPUT -p <protocol> -j f2b-<name> 2>/dev/null || true\n <iptables> -D DOCKER-USER -p <protocol> -j f2b-<name> 2>/dev/null || true\n <iptables> -F f2b-<name>\n <iptables> -X f2b-<name>\n\nactioncheck = <iptables> -n -L f2b-<name> >/dev/null\n\nactionban = <iptables> -I f2b-<name> 1 -s <ip> -j <blocktype>\n\nactionunban = <iptables> -D f2b-<name> -s <ip> -j <blocktype>\n\n[Init]\n\nchain = INPUT\nname = default\nprotocol = tcp\nblocktype = REJECT --reject-with icmp-port-unreachable\nreturntype = RETURN\nlockingopt = -w\niptables = iptables <lockingopt>\n\n[Init?family=inet6]\n\nblocktype = REJECT --reject-with icmp6-port-unreachable\niptables = ip6tables <lockingopt>\n"
|
|
},
|
|
{
|
|
"id": "logrotate",
|
|
"type": "file",
|
|
"path": "/etc/logrotate.d/fail2ban",
|
|
"mode": "0644",
|
|
"content": "/var/log/fail2ban.log {\n missingok\n notifempty\n postrotate\n /usr/bin/fail2ban-client flushlogs >/dev/null || true\n endscript\n}\n"
|
|
},
|
|
{
|
|
"id": "run",
|
|
"type": "service",
|
|
"unit": "fail2ban.service",
|
|
"state": "running",
|
|
"boot": "enabled",
|
|
"restart-on": [
|
|
"jail-local",
|
|
"jail-sshd",
|
|
"jail-recidive",
|
|
"action-dualchain"
|
|
]
|
|
}
|
|
]
|
|
}
|