add fail2ban class

This commit is contained in:
Arne Teuke
2025-02-14 12:01:01 +01:00
parent 78f5f6d87c
commit 20dba070d6
2 changed files with 26 additions and 1 deletions

View File

@@ -22,7 +22,20 @@ class cd_haproxy::monitoring::fail2ban (
seltype => etc_t, seltype => etc_t,
seluser => system_u, seluser => system_u,
content => template('cd_haproxy/fail2ban/f2b_haproxy.conf.erb'), content => template('cd_haproxy/fail2ban/f2b_haproxy.conf.erb'),
notify => Service[$fn_service], notify => Service['fail2ban'],
}
file { '/etc/fail2ban/jail.d/010-haproxy.conf':
ensure => file,
owner => 'root',
group => 'root',
mode => '0644',
selrange => s0,
selrole => object_r,
seltype => etc_t,
seluser => system_u,
content => template('cd_haproxy/fail2ban/010_jaild_haproxy.conf.erb'),
notify => Service['fail2ban'],
} }
} }
} }

View File

@@ -0,0 +1,12 @@
################################################################################
##### fail2ban jail for haproxy.conf created by Puppet #####
################################################################################
[haproxy-http-auth]
enabled = true
filter = haproxy
action = iptables[name=haproxy, port="http,https", protocol=tcp]
logpath = /var/log/haproxy.log
maxretry = 5
findtime = 600
bantime = 3600