mirror of
https://github.com/maxlerebourg/crowdsec-bouncer-traefik-plugin.git
synced 2026-07-21 11:38:59 +02:00
Add initial readme, update com on bouncer
This commit is contained in:
@@ -0,0 +1,74 @@
|
|||||||
|
[](https://github.com/maxlerebourg/crowdsec-bouncer-traefik-plugin/actions)
|
||||||
|
|
||||||
|
# Crowdsec Bouncer Traefik plugin
|
||||||
|
|
||||||
|
This plugins aims to implement a Crowdsec Bouncer into a traefik plugin
|
||||||
|
|
||||||
|
## Usage
|
||||||
|
|
||||||
|
|
||||||
|
### Configuration
|
||||||
|
|
||||||
|
For each plugin, the Traefik static configuration must define the module name (as is usual for Go packages).
|
||||||
|
|
||||||
|
The following declaration (given here in YAML) defines a plugin:
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
# Static configuration
|
||||||
|
|
||||||
|
experimental:
|
||||||
|
localPlugins:
|
||||||
|
bouncer:
|
||||||
|
moduleName: github.com/maxlerebourg/crowdsec-bouncer-traefik-plugin
|
||||||
|
```
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
# Dynamic configuration
|
||||||
|
|
||||||
|
http:
|
||||||
|
routers:
|
||||||
|
my-router:
|
||||||
|
rule: host(`woami.localhost`)
|
||||||
|
service: service-foo
|
||||||
|
entryPoints:
|
||||||
|
- web
|
||||||
|
middlewares:
|
||||||
|
- my-plugin
|
||||||
|
|
||||||
|
services:
|
||||||
|
service-foo:
|
||||||
|
loadBalancer:
|
||||||
|
servers:
|
||||||
|
- url: http://127.0.0.1:5000
|
||||||
|
|
||||||
|
middlewares:
|
||||||
|
crowdsec:
|
||||||
|
plugin:
|
||||||
|
bouncer:
|
||||||
|
enabled: true
|
||||||
|
crowdseclapikey: 40796d93c2958f9e58345514e67740e5
|
||||||
|
```
|
||||||
|
|
||||||
|
### Local Mode
|
||||||
|
|
||||||
|
Traefik also offers a developer mode that can be used for temporary testing of plugins not hosted on GitHub.
|
||||||
|
To use a plugin in local mode, the Traefik static configuration must define the module name (as is usual for Go packages) and a path to a [Go workspace](https://golang.org/doc/gopath_code.html#Workspaces), which can be the local GOPATH or any directory.
|
||||||
|
|
||||||
|
The plugins must be placed in `./plugins-local` directory,
|
||||||
|
which should be in the working directory of the process running the Traefik binary.
|
||||||
|
The source code of the plugin should be organized as follows:
|
||||||
|
|
||||||
|
```
|
||||||
|
./plugins-local/
|
||||||
|
└── src
|
||||||
|
└── github.com
|
||||||
|
└── maxlerebourg
|
||||||
|
└── crowdsec-bouncer-traefik-plugin
|
||||||
|
├── bouncer.go
|
||||||
|
├── bouncer_test.go
|
||||||
|
├── go.mod
|
||||||
|
├── LICENSE
|
||||||
|
├── Makefile
|
||||||
|
├── readme.md
|
||||||
|
└── vendor/*
|
||||||
|
```
|
||||||
@@ -140,6 +140,7 @@ func New(ctx context.Context, next http.Handler, config *Config, name string) (h
|
|||||||
return bouncer, nil
|
return bouncer, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// TODO the serve HTTP should be split as it's too long
|
||||||
func (a *Bouncer) ServeHTTP(rw http.ResponseWriter, req *http.Request) {
|
func (a *Bouncer) ServeHTTP(rw http.ResponseWriter, req *http.Request) {
|
||||||
if !a.enabled {
|
if !a.enabled {
|
||||||
log.Printf("Crowdsec Bouncer not enabled")
|
log.Printf("Crowdsec Bouncer not enabled")
|
||||||
|
|||||||
Reference in New Issue
Block a user