Enable fail2ban for tile caches
authorTom Hughes <tom@compton.nu>
Sat, 12 Oct 2019 10:54:44 +0000 (11:54 +0100)
committerTom Hughes <tom@compton.nu>
Sat, 12 Oct 2019 10:54:44 +0000 (11:54 +0100)
cookbooks/tilecache/metadata.rb
cookbooks/tilecache/recipes/default.rb

index 20ea55c..a207486 100644 (file)
@@ -10,3 +10,4 @@ depends           "ssl"
 depends           "squid"
 depends           "nginx"
 depends           "munin"
+depends           "fail2ban"
index f3b8382..4afda55 100644 (file)
@@ -22,6 +22,7 @@ require "ipaddr"
 include_recipe "ssl"
 include_recipe "squid"
 include_recipe "nginx"
+include_recipe "fail2ban"
 
 package "apache2" do
   action :remove
@@ -135,6 +136,10 @@ template "/etc/logrotate.d/nginx" do
   mode 0o644
 end
 
+fail2ban_jail "squid" do
+  maxretry 1000
+end
+
 tilerenders.each do |render|
   munin_plugin "ping_#{render[:fqdn]}" do
     target "ping_"