mirror of
https://github.com/maxlerebourg/crowdsec-bouncer-traefik-plugin.git
synced 2026-09-02 20:28:50 +02:00
The redis scenario only set redisCacheHost, so it validated the writer but never the round-robin reader path this feature adds. Split the mock into two roles: the primary (--redis-addr) now answers every GET with a miss, while the replica (--redis-read-addr) serves the hardcoded verdicts. The scenario points redisCacheReadHosts at the replica (twice, to drive round-robin), so the banned-IP-blocked assertion only passes if the plugin actually reads decisions from the replica rather than the primary. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
31 lines
729 B
YAML
31 lines
729 B
YAML
http:
|
|
routers:
|
|
r:
|
|
rule: "PathPrefix(`/foo`)"
|
|
entryPoints:
|
|
- web
|
|
service: backend
|
|
middlewares:
|
|
- bouncer
|
|
services:
|
|
backend:
|
|
loadBalancer:
|
|
servers:
|
|
- url: "@@BACKEND_URL@@"
|
|
middlewares:
|
|
bouncer:
|
|
plugin:
|
|
bouncer:
|
|
enabled: "true"
|
|
crowdsecMode: live
|
|
crowdsecLapiScheme: http
|
|
crowdsecLapiHost: "@@LAPI_HOST@@"
|
|
crowdsecLapiKey: "@@APIKEY@@"
|
|
redisCacheEnabled: "true"
|
|
redisCacheHost: "@@REDIS_HOST@@"
|
|
redisCacheReadHosts:
|
|
- "@@REDIS_READ_HOST@@"
|
|
- "@@REDIS_READ_HOST@@"
|
|
forwardedHeadersTrustedIps:
|
|
- "127.0.0.1/32"
|