Add fail2ban for traefik
Remote action coming soon
This commit is contained in:
4
ansible/roles/traefik/files/fail2ban/traefik-filter.conf
Normal file
4
ansible/roles/traefik/files/fail2ban/traefik-filter.conf
Normal file
@ -0,0 +1,4 @@
|
||||
[Definition]
|
||||
failregex = ^<HOST> \- \S+ \[\] \"(GET|POST|HEAD) .+\" .+$
|
||||
ignoreregex =
|
||||
mode = normal
|
9
ansible/roles/traefik/files/fail2ban/traefik-jail.conf
Normal file
9
ansible/roles/traefik/files/fail2ban/traefik-jail.conf
Normal file
@ -0,0 +1,9 @@
|
||||
[traefik]
|
||||
enabled = true
|
||||
bantime = 6000
|
||||
findtime = 600
|
||||
maxretry = 5
|
||||
filter = traefik
|
||||
logpath = /tmp/traefik-logs/access.log
|
||||
port = http,https
|
||||
ignoreip = {{ wireguard.cidr }},{{ nebula.cidr }},{{ pve_hosts.internal_cidr }}
|
Reference in New Issue
Block a user