Compare commits

...
Author SHA1 Message Date
Max Lerebourg 7c2ac9830d 🍱 push .local 2022-09-29 07:45:23 +02:00
mathieuHaandMathieuHa b985f2d748 update main (#11)
* Update readme, add about sectioj

* Update readme about

* Change parameter with capitalized letters

* Add docker-compose local and docker-compose for real world utilization

* Update readme and .traefik

* update readme and docker-compose

* Update .traefik

Co-authored-by: MathieuHa <mathieu@hanotaux.fr>
2022-09-29 07:44:22 +02:00
Max Lerebourg a8758eb2e0 fix readme 2 2022-09-29 07:32:57 +02:00
Max Lerebourg aad92013d1 fix readme 2 2022-09-29 07:30:22 +02:00
Max Lerebourg 4843b86b45 fix readme 2022-09-29 07:19:36 +02:00
4 changed files with 46 additions and 16 deletions
+2 -3
View File
@@ -7,7 +7,6 @@ import: github.com/maxlerebourg/crowdsec-bouncer-traefik-plugin
summary: 'Crowdsec Bouncer Traefik Plugin' summary: 'Crowdsec Bouncer Traefik Plugin'
testData: testData:
bouncer: Enabled: false
enabled: true CrowdsecLapiKey: 40796d93c2958f9e58345514e67740e5
crowdsecLapiKey: 40796d93c2958f9e58345514e67740e5
+41 -12
View File
@@ -12,7 +12,7 @@ The crowdsec utility will provide the community blocklist which contains highly
When used with crowdsec it will leverage the local API which will analyze traefik logs and take decisions on the requests made by users/bots. Malicious actors will be banned based on patterns against your website. When used with crowdsec it will leverage the local API which will analyze traefik logs and take decisions on the requests made by users/bots. Malicious actors will be banned based on patterns against your website.
There is 3 operating mode for this plugin: There are 3 operating modes (CrowdsecMode) for this plugin:
- none -> If the client IP is on ban list, it will get a http code 403 response. - none -> If the client IP is on ban list, it will get a http code 403 response.
Otherwise, request will continue as usual. All request call the Crowdsec LAPI Otherwise, request will continue as usual. All request call the Crowdsec LAPI
@@ -42,7 +42,7 @@ The following declaration (given here in YAML) defines a plugin:
# Static configuration # Static configuration
experimental: experimental:
localPlugins: plugins:
bouncer: bouncer:
moduleName: github.com/maxlerebourg/crowdsec-bouncer-traefik-plugin moduleName: github.com/maxlerebourg/crowdsec-bouncer-traefik-plugin
``` ```
@@ -58,7 +58,7 @@ http:
entryPoints: entryPoints:
- web - web
middlewares: middlewares:
- my-plugin - crowdsec
services: services:
service-foo: service-foo:
@@ -70,14 +70,15 @@ http:
crowdsec: crowdsec:
plugin: plugin:
bouncer: bouncer:
enabled: true enabled: false
crowdseclapikey: 40796d93c2958f9e58345514e67740e5 crowdsecLapiKey: privateKey
crowdsecLapiHost: crowdsec:8080
crowdsecLapiScheme: http
crowdsecMode: stream
updateIntervalSeconds: 60 updateIntervalSeconds: 60
defaultDecisionSeconds: 60 defaultDecisionSeconds: 60
crowdsecLapiHost:
crowdsecLapiScheme:
crowdsecMode: stream
``` ```
Except for the crowdsecLapiKey, these are the default value of the plugin.
### Local Mode ### Local Mode
@@ -103,8 +104,35 @@ The source code of the plugin should be organized as follows:
└── vendor/* └── vendor/*
``` ```
For local developpement a docker-compose-local.yml is provided and reproduce the directory layout needed by traefik. This works once you have generated and filled your LAPI-KEY, if not look below for informations For local developpement a docker-compose.local.yml is provided and reproduce the directory layout needed by traefik. This works once you have generated and filled your LAPI-KEY (crowdsecLapiKey), if not look below for informations
```bash
docker-compose -f docker-compose.local.yml up -d
```
#### Generate LAPI-KEY
You need to generate a crowdsec API key for the LAPI.
You can follow the documentation here: https://docs.crowdsec.net/docs/user_guides/lapi_mgmt/
```bash
docker-compose -f docker-compose.local.yml up -d crowdsec
docker exec crowdsec cscli bouncers add TRAEFIK
```
This LApi key must be set where is noted FIXME-LAPI-KEY in the docker-compose-test.yml
```yaml
...
whoami:
labels:
- "traefik.http.middlewares.crowdsec.plugin.bouncer.crowdseclapikey=FIXME-LAPI-KEY"
...
crowdsec:
environment:
BOUNCER_KEY_TRAEFIK: FIXME-LAPI-KEY
...
```
You can then run all the containers:
```bash ```bash
docker-compose -f docker-compose-local.yml up -d docker-compose -f docker-compose-local.yml up -d
``` ```
@@ -140,16 +168,17 @@ docker-compose -f docker-compose-local.yml up -d
```bash ```bash
docker-compose -f docker-compose-local.yml up -d crowdsec docker-compose -f docker-compose-local.yml up -d crowdsec
docker exec crowdsec cscli decisions add --ip 10.0.0.10 docker exec crowdsec cscli decisions add --ip 10.0.0.10 # this will be effective 4h
docker exec crowdsec cscli decisions remove --ip 10.0.0.10
``` ```
### About ### About
[maxlerebourg](https://github.com/maxlerebourg) and [I](https://github.com/mhanotaux) have been using traefik since 2020. [maxlerebourg](https://github.com/maxlerebourg) and [I](https://github.com/mhanotaux) have been using traefik since 2020.
We come from developper and security engineer background and wanted to add the power of a very promesing technologie (Crowdsec) into the edge router we love. We come from web developper and security engineer background and wanted to add the power of a very promesing technology (Crowdsec) into the edge router we love.
We initially run into this project: https://github.com/fbonalair/traefik-crowdsec-bouncer We initially run into this project: https://github.com/fbonalair/traefik-crowdsec-bouncer
It was using traefik and forward auth middleware to verify every requests. It was using traefik and forward auth middleware to verify every requests.
They had to go through a webserver which then contacts of another webservice (the crowdsec LAPI) to make a decision based on the source IP. They had to go through a webserver which then contacts of another webservice (the crowdsec LAPI) to make a decision based on the source IP.
We initially proposed some improvement by implementing a streaming mode and a local cache We initially proposed some improvement by implementing a streaming mode and a local cache.
With the Traefik hackathon we deciced to implement our solution directly as a traefik plugin which could be found by every one on plugins.traefik.io and be more performant. With the Traefik hackathon we deciced to implement our solution directly as a traefik plugin which could be found by every one on plugins.traefik.io and be more performant.
@@ -12,6 +12,7 @@ services:
- "--providers.docker=true" - "--providers.docker=true"
- "--providers.docker.exposedbydefault=false" - "--providers.docker.exposedbydefault=false"
- "--entrypoints.web.address=:80" - "--entrypoints.web.address=:80"
- "--experimental.localplugins.bouncer.modulename=github.com/maxlerebourg/crowdsec-bouncer-traefik-plugin" - "--experimental.localplugins.bouncer.modulename=github.com/maxlerebourg/crowdsec-bouncer-traefik-plugin"
volumes: volumes:
- "/var/run/docker.sock:/var/run/docker.sock:ro" - "/var/run/docker.sock:/var/run/docker.sock:ro"
+2 -1
View File
@@ -12,7 +12,8 @@ services:
- "--providers.docker=true" - "--providers.docker=true"
- "--providers.docker.exposedbydefault=false" - "--providers.docker.exposedbydefault=false"
- "--entrypoints.web.address=:80" - "--entrypoints.web.address=:80"
- "--experimental.localplugins.bouncer.modulename=github.com/maxlerebourg/crowdsec-bouncer-traefik-plugin"
- "--experimental.plugins.bouncer.modulename=github.com/maxlerebourg/crowdsec-bouncer-traefik-plugin"
volumes: volumes:
- "/var/run/docker.sock:/var/run/docker.sock:ro" - "/var/run/docker.sock:/var/run/docker.sock:ro"
- "logs:/var/log/traefik" - "logs:/var/log/traefik"