nominatim: reinstate fail2ban on restricted_ips.log
authorSarah Hoffmann <lonvia@denofr.de>
Wed, 7 Feb 2018 20:39:04 +0000 (21:39 +0100)
committerSarah Hoffmann <lonvia@denofr.de>
Wed, 7 Feb 2018 20:41:37 +0000 (21:41 +0100)
This file is smaller so that fail2ban hopefully can handle it.

cookbooks/nominatim/recipes/default.rb

index 05227bb..d667db3 100644 (file)
@@ -370,6 +370,19 @@ template "/etc/logrotate.d/apache2" do
   mode 0o644
 end
 
+include_recipe "fail2ban"
+
+fail2ban_filter "nominatim" do
+  failregex "Warning ignored: <HOST>"
+end
+
+fail2ban_jail "nominatim" do
+  filter "nominatim"
+  logpath "#{node[:nominatim][:logdir]}/restricted_ips.log"
+  ports [80, 443]
+  maxretry 3
+end
+
 munin_plugin_conf "nominatim" do
   template "munin.erb"
   variables :db => node[:nominatim][:dbname],