Repository navigation
v0.3.20
·
146 commits
to master
since this release
追加
- 状態を API とメトリクスで分かるように(#115)
GET /rulesにall_targets_down(L4 で宛先がすべて down)とdown_services(http のルールで、up の転送先がないサービス)GET /configにcrowdsec(LAPI に今つながっているか・最後に取れた時刻・最後の誤り・判定の数)/metricsにrproxy_rule_all_targets_down・rproxy_http_service_down・rproxy_crowdsec_connected・rproxy_crowdsec_last_success_timestamp_seconds・rproxy_log_suppressed_total
- SIEM・CrowdSec 向けのログ(#167 の一部)
- 制御 API の 401 / 403 を
event=auditに出すようにしました(client=送信元の IP、Unix ソケットからはunix、401 はreason=missing / invalid / expired)。トークンは出しません。ルールの変更と設定の読み直しの audit にもclientが付きます。 http.accessにrefused_by(断ったミドルウェアの種類)・middleware(設定での名前)・user(basic_auth で通ったユーザー)・auth_error(basic_auth で断った理由)。パスワードは出しません。CrowdSec のパーサーもこれらを読みます。
- 制御 API の 401 / 403 を
修正
- UDP で
allow_fromと CrowdSec で断ったときのconn.deniedが debug でしか出ず、既定のログ・CrowdSec の検知・SIEM に届いていなかったのを直しました(info で出します)。ログは送信元ごと(続けて 20 行、その後は 1 秒 1 行)と全体(続けて 200 行、その後は 1 秒 50 行)で間引き、省いた行の数は次の行のsuppressedと/metricsに出します。stats.deniedは今までどおり 1 つずつ数えます。
変更
allow_listen_portsの範囲外で断ったルールの変更の audit のoutcomeがerrorからforbiddenになりました。
Added
- State in the API and metrics (#115)
GET /rulesaddsall_targets_down(all L4 targets down) anddown_services(HTTP services with no healthy backend).GET /configaddscrowdsec(whether LAPI is reachable now, last success, last error, decision count)./metricsaddsrproxy_rule_all_targets_down,rproxy_http_service_down,rproxy_crowdsec_connected,rproxy_crowdsec_last_success_timestamp_secondsandrproxy_log_suppressed_total.
- Logs for SIEM and CrowdSec (part of #167)
- Control-API 401 / 403 responses are logged as
event=auditwithclient(peer IP, orunix) and, for 401,reason(missing / invalid / expired). Tokens are never logged. Rule changes and config reloads also getclient. http.accessaddsrefused_by(which middleware refused),middleware(its configured name),user(the basic_auth user) andauth_error(why basic_auth refused). Passwords are never logged. The CrowdSec parser reads them.
- Control-API 401 / 403 responses are logged as
Fixed
- UDP
conn.deniedforallow_fromand CrowdSec was only logged at debug, so it never reached the default log, CrowdSec detection or a SIEM. It is now info, throttled per source (20 lines, then 1 per second) and overall (200, then 50 per second); the number of skipped lines goes to the next line'ssuppressedand to/metrics.stats.deniedstill counts every datagram.
Changed
- Rule changes refused by
allow_listen_portsnow have auditoutcomeforbiddeninstead oferror.