add fail2ban class
This commit is contained in:
@@ -22,7 +22,20 @@ class cd_haproxy::monitoring::fail2ban (
|
|||||||
seltype => etc_t,
|
seltype => etc_t,
|
||||||
seluser => system_u,
|
seluser => system_u,
|
||||||
content => template('cd_haproxy/fail2ban/f2b_haproxy.conf.erb'),
|
content => template('cd_haproxy/fail2ban/f2b_haproxy.conf.erb'),
|
||||||
notify => Service[$fn_service],
|
notify => Service['fail2ban'],
|
||||||
|
}
|
||||||
|
|
||||||
|
file { '/etc/fail2ban/jail.d/010-haproxy.conf':
|
||||||
|
ensure => file,
|
||||||
|
owner => 'root',
|
||||||
|
group => 'root',
|
||||||
|
mode => '0644',
|
||||||
|
selrange => s0,
|
||||||
|
selrole => object_r,
|
||||||
|
seltype => etc_t,
|
||||||
|
seluser => system_u,
|
||||||
|
content => template('cd_haproxy/fail2ban/010_jaild_haproxy.conf.erb'),
|
||||||
|
notify => Service['fail2ban'],
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
12
templates/fail2ban/010_jail.d_haproxy.conf.erb
Normal file
12
templates/fail2ban/010_jail.d_haproxy.conf.erb
Normal file
@@ -0,0 +1,12 @@
|
|||||||
|
################################################################################
|
||||||
|
##### fail2ban jail for haproxy.conf created by Puppet #####
|
||||||
|
################################################################################
|
||||||
|
|
||||||
|
[haproxy-http-auth]
|
||||||
|
enabled = true
|
||||||
|
filter = haproxy
|
||||||
|
action = iptables[name=haproxy, port="http,https", protocol=tcp]
|
||||||
|
logpath = /var/log/haproxy.log
|
||||||
|
maxretry = 5
|
||||||
|
findtime = 600
|
||||||
|
bantime = 3600
|
||||||
Reference in New Issue
Block a user