Skip to content
Snippets Groups Projects
  1. Feb 18, 2024
    • Kristian Klausen's avatar
      fail2ban: Use a managed firewalld ipset · 95e19506
      Kristian Klausen authored
      The firewalld direct interface is deprecated and will be removed in a
      future release[1]. Recently IPv4 connectivity inside docker containers
      on our runners broke and after some troubleshooting, the issue was
      pinpointed to the start of the fail2ban service. We also had issues in
      the past where sometimes firewalld had to be restarted after boot before
      network connectivity worked in libvirt on our runners.
      
      The issuse may be due to a bug in the way fail2ban use the direct
      interface, a bug in firewalld or a combination thereof. Let's just avoid
      the direct interface altogether and create a clean separation, with
      firewalld handling the blocking and fail2ban maintaining the ipset.
      
      [1] https://firewalld.org/documentation/man-pages/firewalld.direct.html
      Verified
      95e19506
  2. Mar 26, 2023
  3. Feb 18, 2023
  4. Oct 04, 2022
  5. Aug 29, 2022
  6. Aug 23, 2022
  7. Jul 12, 2021
  8. Jul 11, 2021
  9. May 23, 2021
  10. Feb 14, 2021
    • Kristian Klausen's avatar
      Make ansible-lint happy · 4112bdf9
      Kristian Klausen authored
      yaml: truthy value should be one of [false, true] (truthy)
      yaml: wrong indentation: expected 4 but found 2 (indentation)
      yaml: too few spaces before comment (comments)
      yaml: missing starting space in comment (comments)
      yaml: too many blank lines (1 > 0) (empty-lines)
      yaml: too many spaces after colon (colons)
      yaml: comment not indented like content (comments-indentation)
      yaml: no new line character at the end of file (new-line-at-end-of-file)
      load-failure: Failed to load or parse file
      parser-error: couldn't resolve module/action 'hosts'. This often indicates a misspelling, missing collection, or incorrect module path.
      4112bdf9
  11. Jun 12, 2020
  12. May 28, 2020
  13. Nov 09, 2019
  14. Oct 30, 2019
  15. Oct 25, 2019
  16. Sep 02, 2019
  17. Sep 01, 2019
    • Jelle van der Waa's avatar
      Add fail2ban for apollo · 0c40d331
      Jelle van der Waa authored
      This bans all requests exceeding 1/min in a time period of 30 minutes.
      This might be too harse and can be adjusted later.
      0c40d331
Loading