Private
Public Access
2
0

add crowdsec role, move config logs site -> global, remove caddy_ca_root, modularized Caddy build and config
Some checks failed
Publish collection to Galaxy / publish (push) Failing after 42s

This commit is contained in:
2026-03-16 21:52:36 +03:00
parent 46089e1d7a
commit 5199567bda
17 changed files with 420 additions and 172 deletions

View File

@@ -0,0 +1,5 @@
# BYOW - Build Your Own WAF
A WAF _à la carte_.
## CrowdSec

View File

@@ -0,0 +1,4 @@
crowdsec_collections: []
crowdsec_bouncers: []
# - name: <name>
# key: <LAPI key>

View File

@@ -0,0 +1,4 @@
- name: Restart Crowdsec Securiy Engine
ansible.builtin.systemd_service:
name: "crowdsec"
state: "restarted"

View File

@@ -0,0 +1,70 @@
# FIXME: cluster
# FIXME: BdD PostgreSQL
# FIXME: sudo cscli console enroll cmmszy92r000402l1kugvmw76
# FIXME: AppSec
- name: Add Crowdsec repository
ansible.builtin.deb822_repository:
name: "crowdsec"
uris: "https://packagecloud.io/crowdsec/crowdsec/any/"
suites: "any"
components: "main"
signed_by: "https://packagecloud.io/crowdsec/crowdsec/gpgkey"
- name: Install Crowdsec Security Engine
ansible.builtin.apt:
name:
- "crowdsec"
update_cache: true
notify:
- "Restart Crowdsec Securiy Engine"
- name: Configure Crowdsec
ansible.builtin.template:
src: "templates/config.yaml"
dest: "/etc/crowdsec/config.yaml"
mode: "0600"
notify:
- "Restart Crowdsec Securiy Engine"
- name: Enable and start Crowdsec Securiy Engine
ansible.builtin.systemd_service:
name: "crowdsec"
state: "started"
enabled: true
- name: Get collections list
ansible.builtin.shell:
executable: "/usr/bin/bash"
cmd: |
set -o pipefail
cscli collection list --output=json |jq -r '.collections[] |.name'
register: "crowdsec_out_list_collections"
changed_when: false
- name: Install collections
loop: "{{ crowdsec_collections }}"
when: "item not in crowdsec_out_list_collections.stdout_lines"
ansible.builtin.command:
cmd: "cscli collections install {{ item }}"
changed_when: true
notify:
- "Restart Crowdsec Securiy Engine"
- name: Get bouncers list
ansible.builtin.shell:
executable: "/usr/bin/bash"
cmd: |
set -o pipefail
cscli bouncers list --output=json |jq -r '.[] |.name'
register: "crowdsec_out_list_bouncers"
changed_when: false
- name: Create bouncers API keys
loop: "{{ crowdsec_bouncers }}"
when: "item.name not in crowdsec_out_list_bouncers.stdout_lines"
ansible.builtin.command:
cmd: "cscli bouncers add {{ item.name }} --key '{{ item.key }}'"
changed_when: true
notify:
- "Restart Crowdsec Securiy Engine"

View File

@@ -0,0 +1,66 @@
common:
daemonize: true
log_media: "file"
log_level: "info"
log_dir: "/var/log/"
log_max_size: 20
compress_logs: true
log_max_files: 10
config_paths:
config_dir: "/etc/crowdsec/"
data_dir: "/var/lib/crowdsec/data/"
simulation_path: "/etc/crowdsec/simulation.yaml"
hub_dir: "/etc/crowdsec/hub/"
index_path: "/etc/crowdsec/hub/.index.json"
notification_dir: "/etc/crowdsec/notifications/"
plugin_dir: "/usr/lib/crowdsec/plugins/"
crowdsec_service:
#console_context_path: "/etc/crowdsec/console/context.yaml"
#acquisition_path: "/etc/crowdsec/acquis.yaml"
acquisition_dir: "/etc/crowdsec/acquis.d"
parser_routines: 1
cscli:
output: "human"
color: "auto"
db_config:
log_level: "info"
type: "sqlite"
db_path: "/var/lib/crowdsec/data/crowdsec.db"
#max_open_conns: 100
#user:
#password:
#db_name:
#host:
#port:
flush:
max_items: 5000
max_age: "7d"
plugin_config:
user: "nobody"
group: "nogroup"
api:
client:
insecure_skip_verify: false
credentials_path: "/etc/crowdsec/local_api_credentials.yaml"
server:
log_level: "info"
listen_uri: "127.0.0.1:8080"
profiles_path: "/etc/crowdsec/profiles.yaml"
console_path: "/etc/crowdsec/console.yaml"
online_client: # Central API credentials (to push signals and receive bad IPs)
credentials_path: "/etc/crowdsec/online_api_credentials.yaml"
trusted_ips: # IP ranges, or IPs which can have admin API access
- "127.0.0.1"
- "::1"
# tls:
# cert_file: "/etc/crowdsec/ssl/cert.pem"
# key_file: "/etc/crowdsec/ssl/key.pem"
prometheus:
enabled: false