The module gains a runtime carrying only the fail2ban client with the daemon's socket shared in, serving status/banned/ban/unban and its own fail2ban_settings. It declares jailing, so the controller's composition lands in jail.d/mesh.conf and filter.d; mailu, route-proxy and gitea log to the journal and declare a jail reading it by container name. The base is strict: three in a day for a day, twice banned in two weeks for four; the mesh's range stays never banned.
19 lines
704 B
JSON
19 lines
704 B
JSON
{
|
|
"name": "@novox/module-fail2ban",
|
|
"version": "0.1.0",
|
|
"description": "fail2ban \u2014 intrusion prevention: the mesh composes the jails and keeps the daemon running; this module holds the node-intrusion-prevention seat and serves its verbs status, banned, ban and unban (novox/hq to-be 31, ADR 0179).",
|
|
"type": "module",
|
|
"private": true,
|
|
"dependencies": {
|
|
"@novox/mesh-sdk": "^0.1.1"
|
|
},
|
|
"devDependencies": {
|
|
"@types/node": "^22.0.0",
|
|
"typescript": "^5.6.0"
|
|
},
|
|
"scripts": {
|
|
"build": "tsc client.ts tools/index.ts --module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist",
|
|
"test": "node --test --experimental-strip-types 'test/*.test.ts'"
|
|
}
|
|
}
|