-
Notifications
You must be signed in to change notification settings - Fork 4
/
fail2ban.yml
97 lines (86 loc) · 2.48 KB
/
fail2ban.yml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
---
- hosts: homelab
vars:
application: "fail2ban"
docker_network:
name: "host"
handlers:
- name: Restart
community.docker.docker_container:
name: "{{ application }}"
restart: true
comparisons:
'*': ignore
tasks:
- name: Update apt cache
ansible.builtin.apt:
update_cache: true
cache_valid_time: 600
changed_when: false
- name: Install nftables
ansible.builtin.apt:
name: nftables
state: present
update_cache: true
cache_valid_time: 3600
register: result
until: result is success
retries: 5
delay: 5
- name: Use iptables tooling without nftables backend
community.general.alternatives:
name: "{{ item.name }}"
path: "{{ item.path }}"
loop:
-
name: iptables
path: /usr/sbin/iptables-legacy
-
name: ip6tables
path: /usr/sbin/ip6tables-legacy
- name: Create config folders
ansible.builtin.file:
path: "{{ config_directory }}"
state: directory
owner: "{{ common_root_id }}"
group: "{{ common_group }}"
mode: "0771"
loop:
- "{{ config_directory }}"
- "{{ config_directory }}/action.d"
- "{{ config_directory }}/filter.d"
- "{{ config_directory }}/jail.d"
- name: Create container
ansible.builtin.include_role:
name: docker_container
vars:
image: crazymax/fail2ban:1.1.0
env:
TZ: "{{ common_timezone }}"
SSMTP_HOST: "{{ common_email_server }}"
SSMTP_PORT: "{{ common_email_port | string }}"
SSMTP_USER: "{{ common_email_username }}"
SSMTP_PASSWORD: "{{ common_email_password }}"
SSMTP_SECURE: "YES"
SSMTP_TLS: "YES"
SSMTP_STARTTLS: "YES"
volumes:
- "{{ config_directory }}:/data"
- /var/log:/var/log:ro
capabilities:
- NET_ADMIN
- NET_RAW
network_mode: "host"
privileged: true
- name: Synchronise rules
ansible.builtin.template:
src: "{{ item }}"
dest: "{{ config_directory }}/{{ item.split('/')[-2] }}"
owner: "{{ common_root_id }}"
group: "{{ common_group }}"
mode: "0744"
notify: Restart
with_fileglob:
- "{{ files_directory }}/action.d/*"
- "{{ files_directory }}/filter.d/*"
- "{{ files_directory }}/jail.d/*"