The recidive jail reads /var/log/fail2ban.log and this module ships the logrotate file for it, but nothing ever told fail2ban to write there. Where the package default stands, fail2ban logs to the journal, the recidive jail finds no log file, and the whole service refuses to start -- taking the sshd jail with it. Two machines assigned this module today came up failed; the two where it worked had /etc/fail2ban/fail2ban.conf edited by hand, which a package upgrade would have undone. Declared in fail2ban.local, because fail2ban.conf belongs to the package.
88 lines
4.6 KiB
JSON
88 lines
4.6 KiB
JSON
{
|
|
"module": "fail2ban",
|
|
"version": "1",
|
|
"capabilities": [
|
|
"firewall"
|
|
],
|
|
"claims": [
|
|
{
|
|
"name": "node-intrusion-prevention",
|
|
"scope": "node"
|
|
}
|
|
],
|
|
"resources": [
|
|
{
|
|
"id": "package",
|
|
"type": "package",
|
|
"package": "fail2ban"
|
|
},
|
|
{
|
|
"id": "jail-d",
|
|
"type": "directory",
|
|
"path": "/etc/fail2ban/jail.d",
|
|
"mode": "0755"
|
|
},
|
|
{
|
|
"id": "action-d",
|
|
"type": "directory",
|
|
"path": "/etc/fail2ban/action.d",
|
|
"mode": "0755"
|
|
},
|
|
{
|
|
"id": "fail2ban-local",
|
|
"type": "file",
|
|
"path": "/etc/fail2ban/fail2ban.local",
|
|
"mode": "0644",
|
|
"content": "[Definition]\n\n# Where fail2ban writes its own log, declared rather than assumed. The recidive jail reads\n# this file to ban whoever keeps coming back, and the logrotate file this module ships\n# rotates it -- but nothing told fail2ban to write there. Where the package default stands,\n# fail2ban logs to the journal, the recidive jail finds no log file, and the whole service\n# refuses to start, taking the sshd jail with it.\n#\n# In .local, not in fail2ban.conf: that file belongs to the package.\nlogtarget = /var/log/fail2ban.log\n"
|
|
},
|
|
{
|
|
"id": "jail-local",
|
|
"type": "file",
|
|
"path": "/etc/fail2ban/jail.local",
|
|
"mode": "0644",
|
|
"content": "[INCLUDES]\n\nbefore = paths-arch.conf\n\n[DEFAULT]\n\n# Never act on the machine itself or on a tunnel peer: the mesh's private range is\n# ${machine:mesh-range}, named here rather than written as a value the module cannot\n# know (novox/hq ADR 0112). Without this, fail2ban could ban the mesh's own nodes.\nignoreip = 127.0.0.1/8 ::1 ${machine:mesh-range}\n\nbantime = 10m\nfindtime = 10m\nmaxretry = 5\n\nbanaction = ufw\nbanaction_allports = iptables-allports\n\n[sshd]\nenabled = true\nport = ssh\nlogpath = %(sshd_log)s\nbackend = %(sshd_backend)s\n"
|
|
},
|
|
{
|
|
"id": "jail-sshd",
|
|
"type": "file",
|
|
"path": "/etc/fail2ban/jail.d/sshd.conf",
|
|
"mode": "0644",
|
|
"content": "[sshd]\nenabled = true\nport = ssh\nlogpath = %(sshd_log)s\nbackend = %(sshd_backend)s\nmaxretry = 5\n"
|
|
},
|
|
{
|
|
"id": "jail-recidive",
|
|
"type": "file",
|
|
"path": "/etc/fail2ban/jail.d/recidive.conf",
|
|
"mode": "0644",
|
|
"content": "[recidive]\nenabled = true\nlogpath = /var/log/fail2ban.log\n# Ban in both INPUT (host services like SSH) and DOCKER-USER (container services)\nbanaction = iptables-allports-dualchain\nbantime = 1w\nfindtime = 1d\n"
|
|
},
|
|
{
|
|
"id": "action-dualchain",
|
|
"type": "file",
|
|
"path": "/etc/fail2ban/action.d/iptables-allports-dualchain.conf",
|
|
"mode": "0644",
|
|
"content": "# Fail2Ban action: ban in both INPUT and DOCKER-USER chains\n# Used by recidive to block repeat offenders from both host and Docker services\n\n[INCLUDES]\n\nbefore = iptables.conf\n\n[Definition]\n\ntype = allports\n\nactionstart = { <iptables> -C f2b-<name> -j <returntype> >/dev/null 2>&1; } || { <iptables> -N f2b-<name> || true; <iptables> -A f2b-<name> -j <returntype>; }\n { <iptables> -C INPUT -p <protocol> -j f2b-<name> >/dev/null 2>&1; } || { <iptables> -I INPUT -p <protocol> -j f2b-<name>; }\n { <iptables> -C DOCKER-USER -p <protocol> -j f2b-<name> >/dev/null 2>&1; } || { <iptables> -I DOCKER-USER -p <protocol> -j f2b-<name>; }\n\nactionstop = <iptables> -D INPUT -p <protocol> -j f2b-<name> 2>/dev/null || true\n <iptables> -D DOCKER-USER -p <protocol> -j f2b-<name> 2>/dev/null || true\n <iptables> -F f2b-<name>\n <iptables> -X f2b-<name>\n\nactioncheck = <iptables> -n -L f2b-<name> >/dev/null\n\nactionban = <iptables> -I f2b-<name> 1 -s <ip> -j <blocktype>\n\nactionunban = <iptables> -D f2b-<name> -s <ip> -j <blocktype>\n\n[Init]\n\nchain = INPUT\nname = default\nprotocol = tcp\nblocktype = REJECT --reject-with icmp-port-unreachable\nreturntype = RETURN\nlockingopt = -w\niptables = iptables <lockingopt>\n\n[Init?family=inet6]\n\nblocktype = REJECT --reject-with icmp6-port-unreachable\niptables = ip6tables <lockingopt>\n"
|
|
},
|
|
{
|
|
"id": "logrotate",
|
|
"type": "file",
|
|
"path": "/etc/logrotate.d/fail2ban",
|
|
"mode": "0644",
|
|
"content": "/var/log/fail2ban.log {\n missingok\n notifempty\n postrotate\n /usr/bin/fail2ban-client flushlogs >/dev/null || true\n endscript\n}\n"
|
|
},
|
|
{
|
|
"id": "run",
|
|
"type": "service",
|
|
"unit": "fail2ban.service",
|
|
"state": "running",
|
|
"boot": "enabled",
|
|
"restart-on": [
|
|
"jail-local",
|
|
"jail-sshd",
|
|
"jail-recidive",
|
|
"action-dualchain"
|
|
]
|
|
}
|
|
]
|
|
}
|