feat(security): opt-in local CrowdSec LAPI bouncer on the Docker engine
Gitea Actions Runner Test / test-job (push) Successful in 0s
CI / check (push) Successful in 30s
CI / tests-unit (push) Successful in 1m37s
CI / tests-integration (push) Successful in 1m55s
CI / tests-ui (push) Successful in 2m23s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m38s
Gitea Actions Runner Test / test-job (push) Successful in 0s
CI / check (push) Successful in 30s
CI / tests-unit (push) Successful in 1m37s
CI / tests-integration (push) Successful in 1m55s
CI / tests-ui (push) Successful in 2m23s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m38s
This commit is contained in:
1 parent
3e1a3f92c8
commit
84d53139a9
15 files changed
+1002
-2
No files matched your search
+25
@@ -197,6 +197,23 @@ const schema = z
|
||||
.string()
|
||||
.url()
|
||||
.default("https://api.crowdsec.net/v3"),
|
||||
// Local CrowdSec engine shipped as an opt-in Docker stack in
|
||||
// deployment/crowdsec. When enabled, the anti-DDoS gate asks the local
|
||||
// LAPI (bouncer) for each client IP before its own buckets and blocks
|
||||
// ban/captcha decisions immediately. The key lives in env only.
|
||||
CROWDSEC_LOCAL_ENABLED: z
|
||||
.string()
|
||||
.optional()
|
||||
.transform((value) => value === "true" || value === "1"),
|
||||
CROWDSEC_LAPI_URL: z
|
||||
.string()
|
||||
.optional()
|
||||
.transform((value) =>
|
||||
value?.trim() ? value.trim() : "http://127.0.0.1:18080",
|
||||
)
|
||||
.pipe(z.string().url()),
|
||||
CROWDSEC_LAPI_API_KEY: z.string().optional(),
|
||||
CROWDSEC_LAPI_TIMEOUT_MS: z.coerce.number().int().positive().default(500),
|
||||
// Watcher credentials for signal push. When omitted, a stable pair is
|
||||
// generated once and persisted in Redis (48-char alnum machine id,
|
||||
// per the CAPI schema).
|
||||
@@ -232,6 +249,14 @@ const schema = z
|
||||
path: ["PAYPAL_CLIENT_ID"],
|
||||
});
|
||||
}
|
||||
if (data.CROWDSEC_LOCAL_ENABLED && !data.CROWDSEC_LAPI_API_KEY) {
|
||||
ctx.addIssue({
|
||||
code: "custom",
|
||||
message:
|
||||
"CROWDSEC_LAPI_API_KEY is required when CROWDSEC_LOCAL_ENABLED=true",
|
||||
path: ["CROWDSEC_LAPI_API_KEY"],
|
||||
});
|
||||
}
|
||||
});
|
||||
|
||||
type Env = z.infer<typeof schema>;
|
||||
|
||||
Reference in new issue
Block a user