Repository navigation
feat(waf): CrowdSec WAF and IP banning for DHIS2 - #113
Open
0xafrogeek wants to merge 6 commits into
Open
0xafrogeek wants to merge 6 commits into
0xafrogeek wants to merge 6 commits into
Conversation
documentation/ holds session handoffs, research notes and review harnesses that stay on the contributor's machine. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Opt-in with crowdsec_enabled on [web] hosts (LXD only). Installs the Security Engine and the OpenResty bouncer, with AppSec on by default (virtual-patching and generic rules). Request bodies over the AppSec limit are inspected partially, so DHIS2 imports up to 100M still pass. Also adds crowdsec_allowlist, an optional Prometheus scrape job, and removal when the bouncer or CrowdSec is switched off.
…ne memory - Set the bouncer conffile to 0600; the package ships it world-readable with the LAPI API key inside. Only the OpenResty master reads it. - After the final reload, wait for a stream-mode pull newer than the check start and fail with a diagnosis otherwise. A bouncer that never pulls (edited lua conf, stale key, wrong API_URL) used to let every request through silently. - Add crowdsec_memory_max (default 1G) as a systemd drop-in, removed on engine removal; daemon-reload on restart. - State what AppSec inspects over the body limit: form bodies up to the limit, JSON bodies not at all; URI, query and headers always. - Molecule verify: enforce a manual ban through the bouncer, check the conf mode and the memory ceiling.
…o blocking The engine runs as root, so its acquisition, AppSec and systemd drop-in files need no world-read bit. The apt keyring stays readable for apt. The crowdsec Molecule step has a green run on GitHub; drop the non-blocking fallback.
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.




Summary
New
crowdsecrole: CrowdSec Security Engine with AppSec (WAF) and the OpenResty bouncer, colocated on the[web]host. Off by default;crowdsec_enabled=trueunder[web:vars].crowdsec_online_api_enabled=false).crowdsec_allowlist) for shared egress IPs, optional captcha remediation, Prometheus metrics exposed only to the[monitoring]host, systemd memory ceiling.Requires
proxy=openrestyandansible_connection=lxd; the run fails in pre-flight otherwise. Operator guide:docs/CrowdSec-WAF.md.Testing
molecule test -s crowdsec(new scenario: converge, idempotence, verify incl. AppSec block, manual ban enforced through the bouncer, allowlist, metrics binding, conf mode, memory limit; side effect: bouncer off, engine off, rerun no-op). Green on Ubuntu 24.04 (CI amd64 and local arm64) and 22.04 (local arm64). The CI step is blocking.molecule/defaultscenario fails inprepare(instance unreachable) onmainas well; its step stays non-blocking and is out of scope here./.env403), 0 AppSec false positives on login app and API traffic, allowlist, metrics exposure on/off, both switch-off paths.ansible-lint --profile moderate: no findings in the new role or scenario.Follow-ups (separate PRs)
access.log,error.log,perf.logare not rotated today).unattended-upgradesorigins for the CrowdSec and OpenResty repositories.