fix(traefik): upgrade fail2ban plugin to v0.9.0 and fix config schema
v0.7.1 caused 403 on all routes. v0.9.0 renamed whitelist→allowlist, changed ip to a comma-separated string, and added enabled/statuscode fields. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
+1
-1
@@ -24,7 +24,7 @@ services:
|
|||||||
- "--certificatesresolvers.resolver.acme.email=${ACME_EMAIL}"
|
- "--certificatesresolvers.resolver.acme.email=${ACME_EMAIL}"
|
||||||
- "--certificatesresolvers.resolver.acme.storage=/letsencrypt/acme.json"
|
- "--certificatesresolvers.resolver.acme.storage=/letsencrypt/acme.json"
|
||||||
- "--experimental.plugins.fail2ban.moduleName=github.com/tomMoulard/fail2ban"
|
- "--experimental.plugins.fail2ban.moduleName=github.com/tomMoulard/fail2ban"
|
||||||
- "--experimental.plugins.fail2ban.version=v0.7.1"
|
- "--experimental.plugins.fail2ban.version=v0.9.0"
|
||||||
ports:
|
ports:
|
||||||
- "80:80"
|
- "80:80"
|
||||||
- "443:443"
|
- "443:443"
|
||||||
|
|||||||
@@ -3,13 +3,11 @@ http:
|
|||||||
fail2ban:
|
fail2ban:
|
||||||
plugin:
|
plugin:
|
||||||
fail2ban:
|
fail2ban:
|
||||||
|
allowlist:
|
||||||
|
ip: "127.0.0.1/8,10.0.0.0/8,172.16.0.0/12,192.168.0.0/16,::1"
|
||||||
rules:
|
rules:
|
||||||
bantime: "3h"
|
bantime: "3h"
|
||||||
findtime: "10m"
|
findtime: "10m"
|
||||||
maxretry: 5
|
maxretry: 5
|
||||||
whitelist:
|
enabled: true
|
||||||
ip:
|
statuscode: "400,401,403-499"
|
||||||
- "127.0.0.1/8"
|
|
||||||
- "10.0.0.0/8"
|
|
||||||
- "172.16.0.0/12"
|
|
||||||
- "192.168.0.0/16"
|
|
||||||
|
|||||||
Reference in New Issue
Block a user