feat(security): external IP blocklist sync for the local CrowdSec engine
Gitea Actions Runner Test / test-job (push) Successful in 0s
CI / check (push) Successful in 30s
CI / tests-integration (push) Successful in 1m42s
CI / tests-unit (push) Successful in 1m43s
CI / tests-ui (push) Successful in 2m35s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m3s
Gitea Actions Runner Test / test-job (push) Successful in 0s
CI / check (push) Successful in 30s
CI / tests-integration (push) Successful in 1m42s
CI / tests-unit (push) Successful in 1m43s
CI / tests-ui (push) Successful in 2m35s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m3s
This commit is contained in:
1 parent
84d53139a9
commit
9562a75378
6 files changed
+263
-2
No files matched your search
@@ -126,6 +126,18 @@ CROWDSEC_LAPI_PORT=18080
|
||||
CROWDSEC_LAPI_URL=http://127.0.0.1:18080
|
||||
# Generated by `bash cms security`; keep in .env, never commit a value.
|
||||
CROWDSEC_LAPI_API_KEY=
|
||||
# IP blocklist sync (`bash cms security blocklists`): space-separated URLs, by
|
||||
# default Spamhaus DROP/EDROP, DShield, CINS, Greensnow, StopForumSpam,
|
||||
# blocklist.de, Emerging Threats, abuse.ch Feodo/SSLBL/URLhaus, IPsum,
|
||||
# Firehol ipsets and Tor exit nodes. Requires internet to fetch; detection and
|
||||
# blocking stay local.
|
||||
#CROWDSEC_BLOCKLIST_SOURCES=https://www.spamhaus.org/drop/drop.txt https://example.org/list.txt
|
||||
# Expiration for each blocklist decision (re-synced keeps them fresh).
|
||||
#CROWDSEC_BLOCKLIST_DURATION=24h
|
||||
# Combined cap per sync (safety valve against excessive decisions).
|
||||
#CROWDSEC_BLOCKLIST_MAX_DECISIONS=250000
|
||||
# Comma-separated IPs/CIDRs that a sync must always skip (allowlist).
|
||||
#CROWDSEC_BLOCKLIST_ALLOW=1.2.3.4,10.0.0.0/8
|
||||
|
||||
# --- PATHS ---
|
||||
BADGE_UPLOAD_DIR=./public/assets/images/badges
|
||||
|
||||
Reference in new issue
Block a user