add crowdsec role, move config logs site -> global, remove caddy_ca_root, modularized Caddy build and config
Some checks failed
Publish collection to Galaxy / publish (push) Failing after 42s
Some checks failed
Publish collection to Galaxy / publish (push) Failing after 42s
This commit is contained in:
5
seb4itik/byow/roles/crowdsec/README.md
Normal file
5
seb4itik/byow/roles/crowdsec/README.md
Normal file
@@ -0,0 +1,5 @@
|
||||
# BYOW - Build Your Own WAF
|
||||
|
||||
A WAF _à la carte_.
|
||||
|
||||
## CrowdSec
|
||||
4
seb4itik/byow/roles/crowdsec/defaults/main.yml
Normal file
4
seb4itik/byow/roles/crowdsec/defaults/main.yml
Normal file
@@ -0,0 +1,4 @@
|
||||
crowdsec_collections: []
|
||||
crowdsec_bouncers: []
|
||||
# - name: <name>
|
||||
# key: <LAPI key>
|
||||
4
seb4itik/byow/roles/crowdsec/handlers/main.yml
Normal file
4
seb4itik/byow/roles/crowdsec/handlers/main.yml
Normal file
@@ -0,0 +1,4 @@
|
||||
- name: Restart Crowdsec Securiy Engine
|
||||
ansible.builtin.systemd_service:
|
||||
name: "crowdsec"
|
||||
state: "restarted"
|
||||
70
seb4itik/byow/roles/crowdsec/tasks/main.yml
Normal file
70
seb4itik/byow/roles/crowdsec/tasks/main.yml
Normal file
@@ -0,0 +1,70 @@
|
||||
# FIXME: cluster
|
||||
# FIXME: BdD PostgreSQL
|
||||
# FIXME: sudo cscli console enroll cmmszy92r000402l1kugvmw76
|
||||
# FIXME: AppSec
|
||||
|
||||
- name: Add Crowdsec repository
|
||||
ansible.builtin.deb822_repository:
|
||||
name: "crowdsec"
|
||||
uris: "https://packagecloud.io/crowdsec/crowdsec/any/"
|
||||
suites: "any"
|
||||
components: "main"
|
||||
signed_by: "https://packagecloud.io/crowdsec/crowdsec/gpgkey"
|
||||
|
||||
- name: Install Crowdsec Security Engine
|
||||
ansible.builtin.apt:
|
||||
name:
|
||||
- "crowdsec"
|
||||
update_cache: true
|
||||
notify:
|
||||
- "Restart Crowdsec Securiy Engine"
|
||||
|
||||
- name: Configure Crowdsec
|
||||
ansible.builtin.template:
|
||||
src: "templates/config.yaml"
|
||||
dest: "/etc/crowdsec/config.yaml"
|
||||
mode: "0600"
|
||||
notify:
|
||||
- "Restart Crowdsec Securiy Engine"
|
||||
|
||||
- name: Enable and start Crowdsec Securiy Engine
|
||||
ansible.builtin.systemd_service:
|
||||
name: "crowdsec"
|
||||
state: "started"
|
||||
enabled: true
|
||||
|
||||
- name: Get collections list
|
||||
ansible.builtin.shell:
|
||||
executable: "/usr/bin/bash"
|
||||
cmd: |
|
||||
set -o pipefail
|
||||
cscli collection list --output=json |jq -r '.collections[] |.name'
|
||||
register: "crowdsec_out_list_collections"
|
||||
changed_when: false
|
||||
|
||||
- name: Install collections
|
||||
loop: "{{ crowdsec_collections }}"
|
||||
when: "item not in crowdsec_out_list_collections.stdout_lines"
|
||||
ansible.builtin.command:
|
||||
cmd: "cscli collections install {{ item }}"
|
||||
changed_when: true
|
||||
notify:
|
||||
- "Restart Crowdsec Securiy Engine"
|
||||
|
||||
- name: Get bouncers list
|
||||
ansible.builtin.shell:
|
||||
executable: "/usr/bin/bash"
|
||||
cmd: |
|
||||
set -o pipefail
|
||||
cscli bouncers list --output=json |jq -r '.[] |.name'
|
||||
register: "crowdsec_out_list_bouncers"
|
||||
changed_when: false
|
||||
|
||||
- name: Create bouncers API keys
|
||||
loop: "{{ crowdsec_bouncers }}"
|
||||
when: "item.name not in crowdsec_out_list_bouncers.stdout_lines"
|
||||
ansible.builtin.command:
|
||||
cmd: "cscli bouncers add {{ item.name }} --key '{{ item.key }}'"
|
||||
changed_when: true
|
||||
notify:
|
||||
- "Restart Crowdsec Securiy Engine"
|
||||
66
seb4itik/byow/roles/crowdsec/templates/config.yaml
Normal file
66
seb4itik/byow/roles/crowdsec/templates/config.yaml
Normal file
@@ -0,0 +1,66 @@
|
||||
common:
|
||||
daemonize: true
|
||||
log_media: "file"
|
||||
log_level: "info"
|
||||
log_dir: "/var/log/"
|
||||
log_max_size: 20
|
||||
compress_logs: true
|
||||
log_max_files: 10
|
||||
|
||||
config_paths:
|
||||
config_dir: "/etc/crowdsec/"
|
||||
data_dir: "/var/lib/crowdsec/data/"
|
||||
simulation_path: "/etc/crowdsec/simulation.yaml"
|
||||
hub_dir: "/etc/crowdsec/hub/"
|
||||
index_path: "/etc/crowdsec/hub/.index.json"
|
||||
notification_dir: "/etc/crowdsec/notifications/"
|
||||
plugin_dir: "/usr/lib/crowdsec/plugins/"
|
||||
|
||||
crowdsec_service:
|
||||
#console_context_path: "/etc/crowdsec/console/context.yaml"
|
||||
#acquisition_path: "/etc/crowdsec/acquis.yaml"
|
||||
acquisition_dir: "/etc/crowdsec/acquis.d"
|
||||
parser_routines: 1
|
||||
|
||||
cscli:
|
||||
output: "human"
|
||||
color: "auto"
|
||||
|
||||
db_config:
|
||||
log_level: "info"
|
||||
type: "sqlite"
|
||||
db_path: "/var/lib/crowdsec/data/crowdsec.db"
|
||||
#max_open_conns: 100
|
||||
#user:
|
||||
#password:
|
||||
#db_name:
|
||||
#host:
|
||||
#port:
|
||||
flush:
|
||||
max_items: 5000
|
||||
max_age: "7d"
|
||||
|
||||
plugin_config:
|
||||
user: "nobody"
|
||||
group: "nogroup"
|
||||
|
||||
api:
|
||||
client:
|
||||
insecure_skip_verify: false
|
||||
credentials_path: "/etc/crowdsec/local_api_credentials.yaml"
|
||||
server:
|
||||
log_level: "info"
|
||||
listen_uri: "127.0.0.1:8080"
|
||||
profiles_path: "/etc/crowdsec/profiles.yaml"
|
||||
console_path: "/etc/crowdsec/console.yaml"
|
||||
online_client: # Central API credentials (to push signals and receive bad IPs)
|
||||
credentials_path: "/etc/crowdsec/online_api_credentials.yaml"
|
||||
trusted_ips: # IP ranges, or IPs which can have admin API access
|
||||
- "127.0.0.1"
|
||||
- "::1"
|
||||
# tls:
|
||||
# cert_file: "/etc/crowdsec/ssl/cert.pem"
|
||||
# key_file: "/etc/crowdsec/ssl/key.pem"
|
||||
|
||||
prometheus:
|
||||
enabled: false
|
||||
Reference in New Issue
Block a user