feat(security): opt-in local CrowdSec LAPI bouncer on the Docker engine
Gitea Actions Runner Test / test-job (push) Successful in 0s
CI / check (push) Successful in 30s
CI / tests-unit (push) Successful in 1m37s
CI / tests-integration (push) Successful in 1m55s
CI / tests-ui (push) Successful in 2m23s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m38s
Gitea Actions Runner Test / test-job (push) Successful in 0s
CI / check (push) Successful in 30s
CI / tests-unit (push) Successful in 1m37s
CI / tests-integration (push) Successful in 1m55s
CI / tests-ui (push) Successful in 2m23s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m38s
This commit is contained in:
1 parent
3e1a3f92c8
commit
84d53139a9
15 files changed
+1002
-2
No files matched your search
@@ -112,6 +112,21 @@ CROWDSEC_REPORT_ENROLL_KEY=
|
||||
# Central API base — override only for tests/staging.
|
||||
CROWDSEC_CAPI_BASE_URL=https://api.crowdsec.net/v3
|
||||
|
||||
# --- CROWDSEC LOCAL (opt-in engine on this Docker host, no proxy changes) ---
|
||||
# App-layer LAPI bouncer: the anti-DDoS gate asks the local engine per client
|
||||
# IP (short-cached) and blocks ban/captcha decisions before its own buckets.
|
||||
# Start everything with `bash cms security`; it writes the key below into .env
|
||||
# and starts the CrowdSec engine bound to 127.0.0.1. Set to "true" to load the
|
||||
# bouncer without the local engine (not recommended).
|
||||
CROWDSEC_LOCAL_ENABLED=false
|
||||
# Host access-log directory mounted into the engine for detection (Nginx only).
|
||||
CROWDSEC_NGINX_LOG_DIR=/var/log/nginx
|
||||
# Change LAPI port AND LAPI URL together when 18080 is already taken.
|
||||
CROWDSEC_LAPI_PORT=18080
|
||||
CROWDSEC_LAPI_URL=http://127.0.0.1:18080
|
||||
# Generated by `bash cms security`; keep in .env, never commit a value.
|
||||
CROWDSEC_LAPI_API_KEY=
|
||||
|
||||
# --- PATHS ---
|
||||
BADGE_UPLOAD_DIR=./public/assets/images/badges
|
||||
EMULATOR_JAR_PATH=./emulator/Arcturus.jar
|
||||
|
||||
Reference in new issue
Block a user