mirror of
https://github.com/maxlerebourg/crowdsec-bouncer-traefik-plugin.git
synced 2026-09-02 20:28:50 +02:00
Compare commits
33
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
2569f26805 | ||
|
|
773f001239 | ||
|
|
6b46c63287 | ||
|
|
c8f59c2233 | ||
|
|
2110c70bbd | ||
|
|
00bbcfdb94 | ||
|
|
a6012015e6 | ||
|
|
feb40d9b5f | ||
|
|
6ab8ccb9db | ||
|
|
dd36df5147 | ||
|
|
ae959e4e0d | ||
|
|
7f5f69d134 | ||
|
|
1d7c5948f2 | ||
|
|
2559c71930 | ||
|
|
593681fd53 | ||
|
|
c7714cb793 | ||
|
|
75267a1746 | ||
|
|
45eca85f3a | ||
|
|
1d9bd3fab0 | ||
|
|
0aff6e1789 | ||
|
|
0abf1b7390 | ||
|
|
cb65e48a37 | ||
|
|
cba7c1231f | ||
|
|
da47ef320d | ||
|
|
bbbb5acac5 | ||
|
|
6cf89bfc15 | ||
|
|
f39317263f | ||
|
|
6dbd498212 | ||
|
|
7c2ac9830d | ||
|
|
b985f2d748 | ||
|
|
a8758eb2e0 | ||
|
|
aad92013d1 | ||
|
|
4843b86b45 |
@@ -3,7 +3,7 @@ name: Main
|
||||
on:
|
||||
push:
|
||||
branches:
|
||||
- master
|
||||
- main
|
||||
pull_request:
|
||||
|
||||
jobs:
|
||||
|
||||
+3
-4
@@ -4,10 +4,9 @@ iconPath: .assets/icon.png
|
||||
|
||||
import: github.com/maxlerebourg/crowdsec-bouncer-traefik-plugin
|
||||
|
||||
summary: 'Crowdsec Bouncer Traefik Plugin'
|
||||
summary: Middleware plugin which forwards the request IP to local Crowdsec agent, which can be used to allow/deny the request
|
||||
|
||||
testData:
|
||||
bouncer:
|
||||
enabled: true
|
||||
crowdsecLapiKey: 40796d93c2958f9e58345514e67740e5
|
||||
Enabled: false
|
||||
CrowdsecLapiKey: 40796d93c2958f9e58345514e67740e5
|
||||
|
||||
|
||||
@@ -1,4 +1,8 @@
|
||||
[](https://github.com/maxlerebourg/crowdsec-bouncer-traefik-plugin/actions)
|
||||

|
||||

|
||||

|
||||
[](https://github.com/maxlerebourg/crowdsec-bouncer-traefik-plugin/actions)
|
||||
[](https://goreportcard.com/badge/github.com/maxlerebourg/crowdsec-bouncer-traefik-plugin)
|
||||
|
||||
# Crowdsec Bouncer Traefik plugin
|
||||
|
||||
@@ -6,13 +10,13 @@ This plugins aims to implement a Crowdsec Bouncer into a traefik plugin.
|
||||
> [CrowdSec](https://www.crowdsec.net/) is an open-source and collaborative IPS (Intrusion Prevention System) and a security suite.
|
||||
> We leverage local behavior analysis and crowd power to build the largest CTI network in the world.
|
||||
|
||||
The purpose is to enable treafik to authorize and block requests from IP based and their reputation and behavior.
|
||||
The purpose is to enable treafik to authorize or block requests from IP based and their reputation and behavior.
|
||||
|
||||
The crowdsec utility will provide the community blocklist which contains highly reported and validated IP banned from the crowdsec network.
|
||||
|
||||
When used with crowdsec it will leverage the local API which will analyze traefik logs and take decisions on the requests made by users/bots. Malicious actors will be banned based on patterns against your website.
|
||||
|
||||
There is 3 operating mode for this plugin:
|
||||
There are 3 operating modes (CrowdsecMode) for this plugin:
|
||||
- none -> If the client IP is on ban list, it will get a http code 403 response.
|
||||
Otherwise, request will continue as usual. All request call the Crowdsec LAPI
|
||||
|
||||
@@ -42,7 +46,7 @@ The following declaration (given here in YAML) defines a plugin:
|
||||
# Static configuration
|
||||
|
||||
experimental:
|
||||
localPlugins:
|
||||
plugins:
|
||||
bouncer:
|
||||
moduleName: github.com/maxlerebourg/crowdsec-bouncer-traefik-plugin
|
||||
```
|
||||
@@ -58,7 +62,7 @@ http:
|
||||
entryPoints:
|
||||
- web
|
||||
middlewares:
|
||||
- my-plugin
|
||||
- crowdsec
|
||||
|
||||
services:
|
||||
service-foo:
|
||||
@@ -70,14 +74,15 @@ http:
|
||||
crowdsec:
|
||||
plugin:
|
||||
bouncer:
|
||||
enabled: true
|
||||
crowdseclapikey: 40796d93c2958f9e58345514e67740e5
|
||||
enabled: false
|
||||
crowdsecLapiKey: privateKey
|
||||
crowdsecLapiHost: crowdsec:8080
|
||||
crowdsecLapiScheme: http
|
||||
crowdsecMode: stream
|
||||
updateIntervalSeconds: 60
|
||||
defaultDecisionSeconds: 60
|
||||
crowdsecLapiHost:
|
||||
crowdsecLapiScheme:
|
||||
crowdsecMode: stream
|
||||
```
|
||||
Except for the crowdsecLapiKey, these are the default value of the plugin.
|
||||
|
||||
### Local Mode
|
||||
|
||||
@@ -103,8 +108,35 @@ The source code of the plugin should be organized as follows:
|
||||
└── vendor/*
|
||||
```
|
||||
|
||||
For local developpement a docker-compose-local.yml is provided and reproduce the directory layout needed by traefik. This works once you have generated and filled your LAPI-KEY, if not look below for informations
|
||||
For local developpement a docker-compose.local.yml is provided and reproduce the directory layout needed by traefik. This works once you have generated and filled your LAPI-KEY (crowdsecLapiKey), if not look below for informations
|
||||
|
||||
```bash
|
||||
docker-compose -f docker-compose.local.yml up -d
|
||||
```
|
||||
|
||||
#### Generate LAPI-KEY
|
||||
You need to generate a crowdsec API key for the LAPI.
|
||||
You can follow the documentation here: https://docs.crowdsec.net/docs/user_guides/lapi_mgmt/
|
||||
|
||||
```bash
|
||||
docker-compose -f docker-compose.local.yml up -d crowdsec
|
||||
docker exec crowdsec cscli bouncers add TRAEFIK
|
||||
```
|
||||
|
||||
This LApi key must be set where is noted FIXME-LAPI-KEY in the docker-compose-test.yml
|
||||
```yaml
|
||||
...
|
||||
whoami:
|
||||
labels:
|
||||
- "traefik.http.middlewares.crowdsec.plugin.bouncer.crowdseclapikey=FIXME-LAPI-KEY"
|
||||
...
|
||||
crowdsec:
|
||||
environment:
|
||||
BOUNCER_KEY_TRAEFIK: FIXME-LAPI-KEY
|
||||
...
|
||||
```
|
||||
|
||||
You can then run all the containers:
|
||||
```bash
|
||||
docker-compose -f docker-compose-local.yml up -d
|
||||
```
|
||||
@@ -140,16 +172,17 @@ docker-compose -f docker-compose-local.yml up -d
|
||||
|
||||
```bash
|
||||
docker-compose -f docker-compose-local.yml up -d crowdsec
|
||||
docker exec crowdsec cscli decisions add --ip 10.0.0.10
|
||||
docker exec crowdsec cscli decisions add --ip 10.0.0.10 # this will be effective 4h
|
||||
docker exec crowdsec cscli decisions remove --ip 10.0.0.10
|
||||
```
|
||||
|
||||
### About
|
||||
|
||||
[maxlerebourg](https://github.com/maxlerebourg) and [I](https://github.com/mhanotaux) have been using traefik since 2020.
|
||||
We come from developper and security engineer background and wanted to add the power of a very promesing technologie (Crowdsec) into the edge router we love.
|
||||
We come from web developper and security engineer background and wanted to add the power of a very promesing technology (Crowdsec) into the edge router we love.
|
||||
|
||||
We initially run into this project: https://github.com/fbonalair/traefik-crowdsec-bouncer
|
||||
It was using traefik and forward auth middleware to verify every requests.
|
||||
They had to go through a webserver which then contacts of another webservice (the crowdsec LAPI) to make a decision based on the source IP.
|
||||
We initially proposed some improvement by implementing a streaming mode and a local cache
|
||||
We initially proposed some improvement by implementing a streaming mode and a local cache.
|
||||
With the Traefik hackathon we deciced to implement our solution directly as a traefik plugin which could be found by every one on plugins.traefik.io and be more performant.
|
||||
+107
-108
@@ -5,6 +5,7 @@ import (
|
||||
"context"
|
||||
"encoding/json"
|
||||
"fmt"
|
||||
"io"
|
||||
"io/ioutil"
|
||||
"log"
|
||||
"net"
|
||||
@@ -24,8 +25,7 @@ const (
|
||||
cacheNoBannedValue = "f"
|
||||
)
|
||||
|
||||
var cache = ttl_map.New()
|
||||
|
||||
// Config the plugin configuration.
|
||||
type Config struct {
|
||||
Enabled bool `json:"enabled,omitempty"`
|
||||
CrowdsecMode string `json:"crowdsecMode,omitempty"`
|
||||
@@ -36,6 +36,7 @@ type Config struct {
|
||||
DefaultDecisionSeconds int64 `json:"defaultDecisionSeconds,omitempty"`
|
||||
}
|
||||
|
||||
// CreateConfig creates the default plugin configuration.
|
||||
func CreateConfig() *Config {
|
||||
return &Config{
|
||||
Enabled: false,
|
||||
@@ -48,6 +49,7 @@ func CreateConfig() *Config {
|
||||
}
|
||||
}
|
||||
|
||||
// Bouncer a Bouncer plugin.
|
||||
type Bouncer struct {
|
||||
next http.Handler
|
||||
name string
|
||||
@@ -62,6 +64,7 @@ type Bouncer struct {
|
||||
updateInterval int64
|
||||
defaultDecisionTimeout int64
|
||||
client *http.Client
|
||||
cache *ttl_map.Heap
|
||||
}
|
||||
|
||||
// New creates the crowdsec bouncer plugin.
|
||||
@@ -102,12 +105,12 @@ func New(ctx context.Context, next http.Handler, config *Config, name string) (h
|
||||
if !contains([]string{"http", "https"}, config.CrowdsecLapiScheme) {
|
||||
return nil, fmt.Errorf("CrowdsecLapiScheme must be one of: http, https")
|
||||
}
|
||||
testUrl := url.URL{
|
||||
testURL := url.URL{
|
||||
Scheme: config.CrowdsecLapiScheme,
|
||||
Host: config.CrowdsecLapiHost,
|
||||
Path: crowdsecRoute,
|
||||
}
|
||||
_, err := http.NewRequest(http.MethodGet, testUrl.String(), nil)
|
||||
_, err := http.NewRequest(http.MethodGet, testURL.String(), nil)
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("CrowdsecLapiScheme://CrowdsecLapiHost: '%v://%v' must be an URL", config.CrowdsecLapiScheme, config.CrowdsecLapiHost)
|
||||
}
|
||||
@@ -132,23 +135,23 @@ func New(ctx context.Context, next http.Handler, config *Config, name string) (h
|
||||
},
|
||||
Timeout: 5 * time.Second,
|
||||
},
|
||||
cache: ttl_map.New(),
|
||||
}
|
||||
// if we are on a stream mode, we fetch in a go routine every minute the new decisions
|
||||
// if we are on a stream mode, we fetch in a go routine every minute the new decisions.
|
||||
if config.CrowdsecMode == "stream" {
|
||||
go handleStreamCache(bouncer, true)
|
||||
}
|
||||
return bouncer, nil
|
||||
}
|
||||
|
||||
// TODO the serve HTTP should be split as it's too long
|
||||
// ServeHTTP principal function of plugin.
|
||||
func (a *Bouncer) ServeHTTP(rw http.ResponseWriter, req *http.Request) {
|
||||
if !a.enabled {
|
||||
log.Printf("Crowdsec Bouncer not enabled")
|
||||
a.next.ServeHTTP(rw, req)
|
||||
return
|
||||
}
|
||||
|
||||
// TODO Make sur remote address does not include the port
|
||||
// TODO Make sur remote address does not include the port.
|
||||
remoteHost, _, err := net.SplitHostPort(req.RemoteAddr)
|
||||
if err != nil {
|
||||
log.Printf("failed to extract ip from remote address: %v", err)
|
||||
@@ -157,7 +160,7 @@ func (a *Bouncer) ServeHTTP(rw http.ResponseWriter, req *http.Request) {
|
||||
}
|
||||
|
||||
if a.crowdsecMode == "stream" || a.crowdsecMode == "live" {
|
||||
isBanned, err := getDecision(remoteHost)
|
||||
isBanned, err := getDecision(a.cache, remoteHost)
|
||||
if err == nil {
|
||||
if isBanned {
|
||||
rw.WriteHeader(http.StatusForbidden)
|
||||
@@ -168,78 +171,24 @@ func (a *Bouncer) ServeHTTP(rw http.ResponseWriter, req *http.Request) {
|
||||
}
|
||||
}
|
||||
|
||||
// Right here if we cannot join the stream we forbid the request to go on
|
||||
// Right here if we cannot join the stream we forbid the request to go on.
|
||||
if a.crowdsecMode == "stream" {
|
||||
if a.crowdsecStreamHealthy {
|
||||
a.next.ServeHTTP(rw, req)
|
||||
} else {
|
||||
rw.WriteHeader(http.StatusForbidden)
|
||||
}
|
||||
return
|
||||
} else {
|
||||
handleNoStreamCache(a, rw, req, remoteHost)
|
||||
}
|
||||
|
||||
// We are now in none or live mode
|
||||
noneUrl := url.URL{
|
||||
Scheme: a.crowdsecScheme,
|
||||
Host: a.crowdsecHost,
|
||||
Path: crowdsecRoute,
|
||||
RawQuery: fmt.Sprintf("ip=%v&banned=true", remoteHost),
|
||||
}
|
||||
request, _ := http.NewRequest(http.MethodGet, noneUrl.String(), nil)
|
||||
request.Header.Add(crowdsecAuthHeader, a.crowdsecKey)
|
||||
res, err := a.client.Do(request)
|
||||
if err != nil {
|
||||
log.Printf("failed to get decision: %s", err)
|
||||
rw.WriteHeader(http.StatusForbidden)
|
||||
return
|
||||
}
|
||||
defer res.Body.Close()
|
||||
if res.StatusCode != 200 {
|
||||
log.Printf("failed to get decision, status code: %d", res.StatusCode)
|
||||
rw.WriteHeader(http.StatusForbidden)
|
||||
return
|
||||
}
|
||||
body, err := ioutil.ReadAll(res.Body)
|
||||
if err != nil {
|
||||
log.Printf("failed to read body: %s", err)
|
||||
rw.WriteHeader(http.StatusForbidden)
|
||||
return
|
||||
}
|
||||
if !bytes.Equal(body, []byte("null")) {
|
||||
var decisions []Decision
|
||||
err = json.Unmarshal(body, &decisions)
|
||||
if err != nil {
|
||||
log.Printf("failed to parse body: %s", err)
|
||||
rw.WriteHeader(http.StatusForbidden)
|
||||
return
|
||||
}
|
||||
if len(decisions) == 0 {
|
||||
if a.crowdsecMode == "live" {
|
||||
setDecision(remoteHost, false, a.defaultDecisionTimeout)
|
||||
}
|
||||
a.next.ServeHTTP(rw, req)
|
||||
return
|
||||
}
|
||||
duration, err := time.ParseDuration(decisions[0].Duration)
|
||||
if err != nil {
|
||||
log.Printf("failed to parse duration: %s", err)
|
||||
rw.WriteHeader(http.StatusForbidden)
|
||||
return
|
||||
}
|
||||
rw.WriteHeader(http.StatusForbidden)
|
||||
setDecision(remoteHost, true, int64(duration.Seconds()))
|
||||
return
|
||||
}
|
||||
if a.crowdsecMode == "live" {
|
||||
setDecision(remoteHost, false, a.defaultDecisionTimeout)
|
||||
}
|
||||
a.next.ServeHTTP(rw, req)
|
||||
}
|
||||
|
||||
// CUSTOM CODE
|
||||
// TODO place in another file
|
||||
// CUSTOM CODE.
|
||||
// TODO place in another file.
|
||||
|
||||
// Decision Body returned from Crowdsec LAPI.
|
||||
type Decision struct {
|
||||
Id int `json:"id"`
|
||||
ID int `json:"id"`
|
||||
Origin string `json:"origin"`
|
||||
Type string `json:"type"`
|
||||
Scope string `json:"scope"`
|
||||
@@ -249,6 +198,7 @@ type Decision struct {
|
||||
Simulated bool `json:"simulated"`
|
||||
}
|
||||
|
||||
// Stream Body returned from Crowdsec Stream LAPI.
|
||||
type Stream struct {
|
||||
Deleted []Decision `json:"deleted"`
|
||||
New []Decision `json:"new"`
|
||||
@@ -263,21 +213,18 @@ func contains(source []string, target string) bool {
|
||||
return false
|
||||
}
|
||||
|
||||
// Get Decision check in the cache if the IP has the banned / not banned value
|
||||
// Otherwise return with an error to add the IP in cache if we are on
|
||||
func getDecision(clientIP string) (bool, error) {
|
||||
isBanned, ok := cache.Get(clientIP)
|
||||
if ok && len(isBanned.(string)) > 0 {
|
||||
if isBanned == cacheNoBannedValue {
|
||||
return false, nil
|
||||
} else {
|
||||
return true, nil
|
||||
// Get Decision check in the cache if the IP has the banned / not banned value.
|
||||
// Otherwise return with an error to add the IP in cache if we are on.
|
||||
func getDecision(cache *ttl_map.Heap, clientIP string) (bool, error) {
|
||||
banned, isCached := cache.Get(clientIP)
|
||||
bannedString, isValid := banned.(string)
|
||||
if isCached && isValid && len(bannedString) > 0 {
|
||||
return bannedString == cacheBannedValue, nil
|
||||
}
|
||||
}
|
||||
return false, fmt.Errorf("no data")
|
||||
return false, fmt.Errorf("no cache data")
|
||||
}
|
||||
|
||||
func setDecision(clientIP string, isBanned bool, duration int64) {
|
||||
func setDecision(cache *ttl_map.Heap, clientIP string, isBanned bool, duration int64) {
|
||||
if isBanned {
|
||||
cache.Set(clientIP, cacheBannedValue, duration)
|
||||
} else {
|
||||
@@ -285,39 +232,61 @@ func setDecision(clientIP string, isBanned bool, duration int64) {
|
||||
}
|
||||
}
|
||||
|
||||
func handleNoStreamCache(a *Bouncer, rw http.ResponseWriter, req *http.Request, remoteHost string) {
|
||||
// We are now in none or live mode.
|
||||
routeURL := url.URL{
|
||||
Scheme: a.crowdsecScheme,
|
||||
Host: a.crowdsecHost,
|
||||
Path: crowdsecRoute,
|
||||
RawQuery: fmt.Sprintf("ip=%v&banned=true", remoteHost),
|
||||
}
|
||||
body := crowdsecQuery(a, routeURL.String())
|
||||
|
||||
if bytes.Equal(body, []byte("null")) {
|
||||
if a.crowdsecMode == "live" {
|
||||
setDecision(a.cache, remoteHost, false, a.defaultDecisionTimeout)
|
||||
}
|
||||
a.next.ServeHTTP(rw, req)
|
||||
return
|
||||
}
|
||||
|
||||
var decisions []Decision
|
||||
err := json.Unmarshal(body, &decisions)
|
||||
if err != nil {
|
||||
log.Printf("failed to parse body: %s", err)
|
||||
rw.WriteHeader(http.StatusForbidden)
|
||||
return
|
||||
}
|
||||
if len(decisions) == 0 {
|
||||
if a.crowdsecMode == "live" {
|
||||
setDecision(a.cache, remoteHost, false, a.defaultDecisionTimeout)
|
||||
}
|
||||
a.next.ServeHTTP(rw, req)
|
||||
return
|
||||
}
|
||||
rw.WriteHeader(http.StatusForbidden)
|
||||
duration, err := time.ParseDuration(decisions[0].Duration)
|
||||
if err != nil {
|
||||
log.Printf("failed to parse duration: %s", err)
|
||||
return
|
||||
}
|
||||
setDecision(a.cache, remoteHost, true, int64(duration.Seconds()))
|
||||
}
|
||||
|
||||
func handleStreamCache(a *Bouncer, initialized bool) {
|
||||
// TODO clean properly on exit
|
||||
// TODO clean properly on exit.
|
||||
time.AfterFunc(time.Duration(a.updateInterval)*time.Second, func() {
|
||||
handleStreamCache(a, false)
|
||||
})
|
||||
streamUrl := url.URL{
|
||||
streamRouteURL := url.URL{
|
||||
Scheme: a.crowdsecScheme,
|
||||
Host: a.crowdsecHost,
|
||||
Path: crowdsecStreamRoute,
|
||||
RawQuery: fmt.Sprintf("startup=%t", initialized),
|
||||
}
|
||||
req, _ := http.NewRequest(http.MethodGet, streamUrl.String(), nil)
|
||||
req.Header.Add(crowdsecAuthHeader, a.crowdsecKey)
|
||||
res, err := a.client.Do(req)
|
||||
if err != nil || res.StatusCode == http.StatusForbidden {
|
||||
log.Printf("error while fetching decisions: %s", err)
|
||||
a.crowdsecStreamHealthy = false
|
||||
return
|
||||
}
|
||||
if res.StatusCode == http.StatusForbidden {
|
||||
log.Printf("error while fetching decisions, status code: %d", res.StatusCode)
|
||||
a.crowdsecStreamHealthy = false
|
||||
return
|
||||
}
|
||||
defer res.Body.Close()
|
||||
body, err := ioutil.ReadAll(res.Body)
|
||||
if err != nil {
|
||||
log.Printf("error while reading body: %s", err)
|
||||
a.crowdsecStreamHealthy = false
|
||||
return
|
||||
}
|
||||
body := crowdsecQuery(a, streamRouteURL.String())
|
||||
var stream Stream
|
||||
err = json.Unmarshal(body, &stream)
|
||||
err := json.Unmarshal(body, &stream)
|
||||
if err != nil {
|
||||
log.Printf("error while parsing body: %s", err)
|
||||
a.crowdsecStreamHealthy = false
|
||||
@@ -326,11 +295,41 @@ func handleStreamCache(a *Bouncer, initialized bool) {
|
||||
for _, decision := range stream.New {
|
||||
duration, err := time.ParseDuration(decision.Duration)
|
||||
if err == nil {
|
||||
setDecision(decision.Value, true, int64(duration.Seconds()))
|
||||
setDecision(a.cache, decision.Value, true, int64(duration.Seconds()))
|
||||
}
|
||||
}
|
||||
for _, decision := range stream.Deleted {
|
||||
cache.Del(decision.Value)
|
||||
a.cache.Del(decision.Value)
|
||||
}
|
||||
a.crowdsecStreamHealthy = true
|
||||
}
|
||||
|
||||
func crowdsecQuery(a *Bouncer, stringURL string) ([]byte) {
|
||||
req, _ := http.NewRequest(http.MethodGet, stringURL, nil)
|
||||
req.Header.Add(crowdsecAuthHeader, a.crowdsecKey)
|
||||
res, err := a.client.Do(req)
|
||||
if err != nil {
|
||||
log.Printf("error while fetching %v: %s", stringURL, err)
|
||||
a.crowdsecStreamHealthy = false
|
||||
return nil
|
||||
}
|
||||
if res.StatusCode == http.StatusForbidden {
|
||||
log.Printf("error while fetching %v, status code: %d", stringURL, res.StatusCode)
|
||||
a.crowdsecStreamHealthy = false
|
||||
return nil
|
||||
}
|
||||
defer func (body io.ReadCloser) {
|
||||
err = body.Close()
|
||||
if err != nil {
|
||||
log.Printf("failed to close body reader: %s", err)
|
||||
}
|
||||
}(res.Body)
|
||||
body, err := ioutil.ReadAll(res.Body)
|
||||
if err != nil {
|
||||
log.Printf("error while reading body: %s", err)
|
||||
a.crowdsecStreamHealthy = false
|
||||
return nil
|
||||
}
|
||||
return body
|
||||
}
|
||||
|
||||
|
||||
@@ -12,6 +12,7 @@ services:
|
||||
- "--providers.docker=true"
|
||||
- "--providers.docker.exposedbydefault=false"
|
||||
- "--entrypoints.web.address=:80"
|
||||
|
||||
- "--experimental.localplugins.bouncer.modulename=github.com/maxlerebourg/crowdsec-bouncer-traefik-plugin"
|
||||
volumes:
|
||||
- "/var/run/docker.sock:/var/run/docker.sock:ro"
|
||||
@@ -20,6 +21,8 @@ services:
|
||||
ports:
|
||||
- 8000:80
|
||||
- 8080:8080
|
||||
depends_on:
|
||||
- 'crowdsec'
|
||||
|
||||
whoami:
|
||||
image: traefik/whoami
|
||||
@@ -30,7 +33,7 @@ services:
|
||||
- "traefik.http.routers.whoami.entrypoints=web"
|
||||
- "traefik.http.routers.whoami.middlewares=crowdsec@docker"
|
||||
- "traefik.http.middlewares.crowdsec.plugin.bouncer.enabled=true"
|
||||
- "traefik.http.middlewares.crowdsec.plugin.bouncer.crowdseclapikey=FIXME-LAPI-KEY"
|
||||
- "traefik.http.middlewares.crowdsec.plugin.bouncer.crowdseclapikey=40796d93c2958f9e58345514e67740e5"
|
||||
|
||||
crowdsec:
|
||||
image: crowdsecurity/crowdsec:v1.4.1
|
||||
@@ -39,9 +42,7 @@ services:
|
||||
environment:
|
||||
COLLECTIONS: crowdsecurity/traefik
|
||||
CUSTOM_HOSTNAME: crowdsec
|
||||
BOUNCER_KEY_TRAEFIK: FIXME-LAPI-KEY
|
||||
depends_on:
|
||||
- 'traefik'
|
||||
BOUNCER_KEY_TRAEFIK: 40796d93c2958f9e58345514e67740e5
|
||||
volumes:
|
||||
- ./acquis.yaml:/etc/crowdsec/acquis.yaml:ro
|
||||
- logs:/var/log/traefik:ro
|
||||
+4
-3
@@ -12,13 +12,16 @@ services:
|
||||
- "--providers.docker=true"
|
||||
- "--providers.docker.exposedbydefault=false"
|
||||
- "--entrypoints.web.address=:80"
|
||||
- "--experimental.localplugins.bouncer.modulename=github.com/maxlerebourg/crowdsec-bouncer-traefik-plugin"
|
||||
|
||||
- "--experimental.plugins.bouncer.modulename=github.com/maxlerebourg/crowdsec-bouncer-traefik-plugin"
|
||||
volumes:
|
||||
- "/var/run/docker.sock:/var/run/docker.sock:ro"
|
||||
- "logs:/var/log/traefik"
|
||||
ports:
|
||||
- 8000:80
|
||||
- 8080:8080
|
||||
depends_on:
|
||||
- 'crowdsec'
|
||||
|
||||
whoami:
|
||||
image: traefik/whoami
|
||||
@@ -39,8 +42,6 @@ services:
|
||||
COLLECTIONS: crowdsecurity/traefik
|
||||
CUSTOM_HOSTNAME: crowdsec
|
||||
BOUNCER_KEY_TRAEFIK: FIXME-LAPI-KEY
|
||||
depends_on:
|
||||
- 'traefik'
|
||||
volumes:
|
||||
- ./acquis.yaml:/etc/crowdsec/acquis.yaml:ro
|
||||
- logs:/var/log/traefik:ro
|
||||
|
||||
Reference in New Issue
Block a user