feat(security): external IP blocklist sync for the local CrowdSec engine
Gitea Actions Runner Test / test-job (push) Successful in 0s
CI / check (push) Successful in 30s
CI / tests-integration (push) Successful in 1m42s
CI / tests-unit (push) Successful in 1m43s
CI / tests-ui (push) Successful in 2m35s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m3s

This commit is contained in:
openhands committed 2026-09-24 18:39:38 +02:00
1 parent 84d53139a9
commit 9562a75378
6 files changed
+263 -2

No files matched your search

+30
View File
@@ -827,6 +827,36 @@ bash cms security disable
Stops the container and sets `CROWDSEC_LOCAL_ENABLED=false`. Volumes and the
`.env` key are kept.
### Step 5 — Load external IP blocklists (optional)
The engine has no built-in lists, so provide your own via a one-shot sync
(fetches the sources, replaces every previous `cscli-import` decision):
```bash
bash cms security blocklists
```
Defaults: Spamhaus DROP/EDROP, DShield, CINS, Greensnow, StopForumSpam,
Binary Defense, blocklist.de, Emerging Threats, BruteForceBlocker, abuse.ch
Feodo/SSLBL/URLhaus, Botvrij, IPsum, Firehol ipsets and Tor exit nodes
(26 sources). The largest commercial/crowdsourced lists (AbuseIPDB, MaxMind,
Cisco Talos, AlienVault OTX) are not included because they require an account
or API key; IPsum already aggregates ~30 additional feeds. No account is
needed, but internet access is — only for fetching; detection and blocking
remain local. Sync hourly as a cron job:
```bash
bash cms security blocklists-install-cron
```
Removal: `bash cms security blocklists-uninstall-cron`. Dry-run without
touching LAPI: `bash cms security blocklists --dry-run`. Override the sources,
duration, a combined cap or an allowlist in `.env`
(`CROWDSEC_BLOCKLIST_SOURCES`, `CROWDSEC_BLOCKLIST_DURATION`,
`CROWDSEC_BLOCKLIST_MAX_DECISIONS`, `CROWDSEC_BLOCKLIST_ALLOW`). Existing
`cscli-import` decisions are replaced on every sync, so removed entries
expire.
### Environment variables
| Variable | Default | Purpose |