diff --git a/bouncer.go b/bouncer.go index 26cd6db..934ba84 100644 --- a/bouncer.go +++ b/bouncer.go @@ -85,7 +85,7 @@ func New(ctx context.Context, next http.Handler, config *configuration.Config, n crowdsecStreamRoute := "" crowdsecHeader := "" if config.CrowdsecMode == configuration.AloneMode { - config.CrowdsecCapiMachineID, _ = configuration.GetVariable(config, "CrowdsecCapiMachineId") + config.CrowdsecCapiMachineID, _ = configuration.GetVariable(config, "CrowdsecCapiMachineID") config.CrowdsecCapiPassword, _ = configuration.GetVariable(config, "CrowdsecCapiPassword") config.CrowdsecLapiHost = "api.crowdsec.net" config.CrowdsecLapiScheme = "https" diff --git a/exemples/standalone-mode/README.md b/exemples/standalone-mode/README.md index ee0d73a..c52221e 100644 --- a/exemples/standalone-mode/README.md +++ b/exemples/standalone-mode/README.md @@ -11,10 +11,11 @@ These CAPI credentials must be set in your docker-compose.yml or in your config ... whoami: labels: + - "traefik.http.middlewares.crowdsec.plugin.bouncer.enabled=true" + - "traefik.http.middlewares.crowdsec.plugin.bouncer.crowdsecMode=alone" - "traefik.http.middlewares.crowdsec.plugin.bouncer.crowdsecCapiMachineId=LOGIN" - "traefik.http.middlewares.crowdsec.plugin.bouncer.crowdsecCapiPassword=PASSWORD" - - "traefik.http.middlewares.crowdsec.plugin.bouncer.crowdseccapiscenarios=crowdsecurity/http-generic-bf,crowdsecurity/http-xss-probing,..." - - "traefik.http.middlewares.crowdsec.plugin.bouncer.enabled=true" + - "traefik.http.middlewares.crowdsec.plugin.bouncer.crowdsecCapiScenarios=crowdsecurity/http-generic-bf,crowdsecurity/http-xss-probing,..." ``` You can then run all the containers: diff --git a/exemples/standalone-mode/docker-compose.alone.yml b/exemples/standalone-mode/docker-compose.alone.yml new file mode 100644 index 0000000..93e3607 --- /dev/null +++ b/exemples/standalone-mode/docker-compose.alone.yml @@ -0,0 +1,45 @@ +version: "3.8" + +services: + traefik: + image: "traefik:v2.9.6" + container_name: "traefik" + restart: unless-stopped + command: + # - "--log.level=DEBUG" + - "--accesslog" + - "--accesslog.filepath=/var/log/traefik/access.log" + - "--api.insecure=true" + - "--providers.docker=true" + - "--providers.docker.exposedbydefault=false" + - "--entrypoints.web.address=:80" + + - "--experimental.plugins.bouncer.modulename=github.com/maxlerebourg/crowdsec-bouncer-traefik-plugin" + - "--experimental.plugins.bouncer.version=v1.1.7" + volumes: + - /var/run/docker.sock:/var/run/docker.sock:ro + ports: + - 80:80 + - 8080:8080 + + whoami-foo: + image: traefik/whoami + container_name: "simple-service-foo" + restart: unless-stopped + labels: + - "traefik.enable=true" + - "traefik.http.routers.router-foo.rule=Path(`/foo`)" + - "traefik.http.routers.router-foo.entrypoints=web" + - "traefik.http.routers.router-foo.middlewares=crowdsec-foo@docker" + - "traefik.http.services.service-foo.loadbalancer.server.port=80" + + - "traefik.http.middlewares.crowdsec-foo.plugin.bouncer.enabled=true" + # - "traefik.http.middlewares.crowdsec-foo.plugin.bouncer.loglevel=DEBUG" + - "traefik.http.middlewares.crowdsec-foo.plugin.bouncer.crowdsecmode=alone" + - "traefik.http.middlewares.crowdsec-foo.plugin.bouncer.crowdseclapikey=40796d93c2958f9e58345514e67740e5" + - "traefik.http.middlewares.crowdsec-foo.plugin.bouncer.CrowdsecCapiMachineId=logincacacalfkrjebfreifgzfblezgyfoerxsqxsqxsqxsr" + - "traefik.http.middlewares.crowdsec-foo.plugin.bouncer.CrowdsecCapiPassword=Password2" + - "traefik.http.middlewares.crowdsec-foo.plugin.bouncer.crowdseccapiscenarios=crowdsecurity/sshd,crowdsecurity/asterisk_bf,crowdsecurity/asterisk_user_enum,crowdsecurity/base-http-scenarios" + +volumes: + logs-local: diff --git a/pkg/configuration/configuration.go b/pkg/configuration/configuration.go index e12a579..f01c826 100644 --- a/pkg/configuration/configuration.go +++ b/pkg/configuration/configuration.go @@ -129,7 +129,7 @@ func ValidateParams(config *Config) error { } if config.CrowdsecMode == AloneMode { - if _, err := GetVariable(config, "CrowdsecCapiMachineId"); err != nil { + if _, err := GetVariable(config, "CrowdsecCapiMachineID"); err != nil { return err } if _, err := GetVariable(config, "CrowdsecCapiPassword"); err != nil {