Skip to content

v0.3.20

Choose a tag to compare

@github-actions github-actions released this 06 Oct 15:42
· 146 commits to master since this release
fa8d4a1

追加

  • 状態を API とメトリクスで分かるように(#115)
    • GET /rules に all_targets_down(L4 で宛先がすべて down)と down_services(http のルールで、up の転送先がないサービス)
    • GET /config に crowdsec(LAPI に今つながっているか・最後に取れた時刻・最後の誤り・判定の数)
    • /metrics に rproxy_rule_all_targets_down・rproxy_http_service_down・rproxy_crowdsec_connected・rproxy_crowdsec_last_success_timestamp_seconds・rproxy_log_suppressed_total
  • SIEM・CrowdSec 向けのログ(#167 の一部)
    • 制御 API の 401 / 403 を event=audit に出すようにしました(client=送信元の IP、Unix ソケットからは unix、401 は reason=missing / invalid / expired)。トークンは出しません。ルールの変更と設定の読み直しの audit にも client が付きます。
    • http.access に refused_by(断ったミドルウェアの種類)・middleware(設定での名前)・user(basic_auth で通ったユーザー)・auth_error(basic_auth で断った理由)。パスワードは出しません。CrowdSec のパーサーもこれらを読みます。

修正

  • UDP で allow_from と CrowdSec で断ったときの conn.denied が debug でしか出ず、既定のログ・CrowdSec の検知・SIEM に届いていなかったのを直しました(info で出します)。ログは送信元ごと(続けて 20 行、その後は 1 秒 1 行)と全体(続けて 200 行、その後は 1 秒 50 行)で間引き、省いた行の数は次の行の suppressed と /metrics に出します。stats.denied は今までどおり 1 つずつ数えます。

変更

  • allow_listen_ports の範囲外で断ったルールの変更の audit の outcome が error から forbidden になりました。

Added

  • State in the API and metrics (#115)
    • GET /rules adds all_targets_down (all L4 targets down) and down_services (HTTP services with no healthy backend).
    • GET /config adds crowdsec (whether LAPI is reachable now, last success, last error, decision count).
    • /metrics adds rproxy_rule_all_targets_down, rproxy_http_service_down, rproxy_crowdsec_connected, rproxy_crowdsec_last_success_timestamp_seconds and rproxy_log_suppressed_total.
  • Logs for SIEM and CrowdSec (part of #167)
    • Control-API 401 / 403 responses are logged as event=audit with client (peer IP, or unix) and, for 401, reason (missing / invalid / expired). Tokens are never logged. Rule changes and config reloads also get client.
    • http.access adds refused_by (which middleware refused), middleware (its configured name), user (the basic_auth user) and auth_error (why basic_auth refused). Passwords are never logged. The CrowdSec parser reads them.

Fixed

  • UDP conn.denied for allow_from and CrowdSec was only logged at debug, so it never reached the default log, CrowdSec detection or a SIEM. It is now info, throttled per source (20 lines, then 1 per second) and overall (200, then 50 per second); the number of skipped lines goes to the next line's suppressed and to /metrics. stats.denied still counts every datagram.

Changed

  • Rule changes refused by allow_listen_ports now have audit outcome forbidden instead of error.