The mechanism from to-be 31, modeled on Filtering: a module declares jails (name, failregex, jail stanza) naming no node/path; the intrusion-prevention holder declares jailing (where composed jails go); the mesh gathers every assigned module's jails into one jail.d file (a fixed id the fail2ban service restart-ons) plus a filter.d file per jail. A node not running a module has none of its jails. Tested (jailsInto composition + empty case). Behaviour-neutral until a service module declares a jail. The per-service content (postgres/mssql/mailu failregex + logpath, verified against how each container logs) is the follow-on — not in this PR.
The mechanism from to-be 31, modeled on `Filtering`: a module declares `jails` (name, failregex, jail stanza) naming no node/path; the intrusion-prevention holder declares `jailing` (where composed jails go); the mesh gathers every assigned module's jails into one `jail.d` file (a fixed id the fail2ban service `restart-on`s) plus a `filter.d` file per jail. A node not running a module has none of its jails. Tested (`jailsInto` composition + empty case). Behaviour-neutral until a service module declares a jail. The per-service content (postgres/mssql/mailu failregex + logpath, verified against how each container logs) is the follow-on — not in this PR.
The mechanism, mirroring Filtering: a module declares Jails (name, failregex,
jail stanza) naming no node/path (ADR 0112); the intrusion-prevention holder
declares Jailing (where composed jails go); the mesh gathers every assigned
module's jails into one jail.d file (a fixed id the fail2ban service restarts
on) plus a filter.d file per jail. A node not running a module has none of its
jails. Tested. Behaviour-neutral until a service module declares a jail — the
per-service content (postgres/mssql/mailu failregex+logpath) is authored next,
against how each container actually logs.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
The mechanism from to-be 31, modeled on
Filtering: a module declaresjails(name, failregex, jail stanza) naming no node/path; the intrusion-prevention holder declaresjailing(where composed jails go); the mesh gathers every assigned module's jails into onejail.dfile (a fixed id the fail2ban servicerestart-ons) plus afilter.dfile per jail. A node not running a module has none of its jails. Tested (jailsIntocomposition + empty case). Behaviour-neutral until a service module declares a jail. The per-service content (postgres/mssql/mailu failregex + logpath, verified against how each container logs) is the follow-on — not in this PR.