diff --git a/project/db/lldap/lldap.yml b/project/db/lldap/lldap.yml index 670872e..495a270 100644 --- a/project/db/lldap/lldap.yml +++ b/project/db/lldap/lldap.yml @@ -46,4 +46,4 @@ services: - "traefik.http.services.lldap-service.loadbalancer.server.port=17170" - "traefik.http.services.lldap-service.loadbalancer.server.scheme=http" # middlewares - # - "traefik.http.routers.lldap.middlewares=crowdsec-bouncer@file" \ No newline at end of file + - "traefik.http.routers.lldap.middlewares=crowdsec-bouncer@file" \ No newline at end of file diff --git a/project/infrastructure/authelia/authelia.yml b/project/infrastructure/authelia/authelia.yml index 7df5f19..5c28dd8 100644 --- a/project/infrastructure/authelia/authelia.yml +++ b/project/infrastructure/authelia/authelia.yml @@ -42,4 +42,4 @@ services: - 'traefik.http.routers.authelia.service=authelia-svc' - 'traefik.http.services.authelia-svc.loadbalancer.server.port=9091' # Middleware - #- "traefik.http.routers.authelia.middlewares=crowdsec-bouncer@file" \ No newline at end of file + - "traefik.http.routers.authelia.middlewares=crowdsec-bouncer@file" \ No newline at end of file diff --git a/project/infrastructure/crowdsec/crowdsec.yml b/project/infrastructure/crowdsec/crowdsec.yml index 893deff..b352dc3 100644 --- a/project/infrastructure/crowdsec/crowdsec.yml +++ b/project/infrastructure/crowdsec/crowdsec.yml @@ -9,18 +9,16 @@ services: COLLECTIONS: crowdsecurity/traefik crowdsecurity/appsec-virtual-patching crowdsecurity/appsec-generic-rules crowdsecurity/http-cve CROWDSEC_BOUNCER_API_KEY: ${CROWDSEC_API_KEY} CUSTOM_HOSTNAME: crowdsec - expose: - - 8080 - ports: - - 6060:6060 networks: - ip4net - ip6net volumes: - - ${INFRA_PATH}/crowdsec/data:/var/lib/crowdsec/data + - ${INFRA_PATH}/crowdsec/config/acquis.yaml:/etc/crowdsec/acquis.yaml:ro - ${INFRA_PATH}/crowdsec/config:/etc/crowdsec + - ${INFRA_PATH}/crowdsec/data:/var/lib/crowdsec/data - /var/log/auth.log:/var/log/auth.log:ro - /var/log/crowdsec:/var/log/crowdsec:ro + - /var/log/syslog:/var/log/syslog:ro labels: # Watchtower - "com.centurylinklabs.watchtower.enable=true" \ No newline at end of file diff --git a/project/infrastructure/syncthing/syncthing.yml b/project/infrastructure/syncthing/syncthing.yml index fde4eb0..63c73cf 100644 --- a/project/infrastructure/syncthing/syncthing.yml +++ b/project/infrastructure/syncthing/syncthing.yml @@ -26,4 +26,4 @@ services: - "traefik.http.routers.syncthing.service=syncthing-svc" - "traefik.http.services.syncthing-svc.loadbalancer.server.port=8384" # Middlewares - - "traefik.http.routers.syncthing.middlewares=crowdsec-bouncer@file" \ No newline at end of file + #- "traefik.http.routers.syncthing.middlewares=crowdsec-bouncer@file" \ No newline at end of file diff --git a/project/infrastructure/traefik/html/ban.html b/project/infrastructure/traefik/html/ban.html new file mode 100644 index 0000000..e4a6501 --- /dev/null +++ b/project/infrastructure/traefik/html/ban.html @@ -0,0 +1,329 @@ + + + +
+This security check has been powered by
+ + + CrowdSec + +This security check has been powered by
+ + + CrowdSec + +