diff --git a/crowdsec/k8s/crowdsec-middleware.yaml b/crowdsec/k8s/crowdsec-middleware.yaml index 748e863..6d81c98 100644 --- a/crowdsec/k8s/crowdsec-middleware.yaml +++ b/crowdsec/k8s/crowdsec-middleware.yaml @@ -1,3 +1,17 @@ +# crowdsec/k8s is NOT managed by deploy.yaml - apply this by hand, and apply it +# together with a restart: +# kubectl apply -f crowdsec/k8s/crowdsec-middleware.yaml +# kubectl -n traefik rollout restart deploy/traefik +# +# The restart is not optional. In stream mode the plugin runs a package-level +# ticker goroutine (handleStreamTicker over the isCrowdsecStreamHealthy and +# updateFailure globals) that no reconfiguration stops. Applying a change +# wedges the instance: every route referencing it answers 404 and traefik logs +# 'invalid middleware crowdsec-crowdsec-bouncer@kubernetescrd' until the pod is +# replaced. Re-applying the previous config does NOT recover it, and the config +# is not the cause - a valid CIDR cannot fail NewChecker, which is a plain +# net.ParseCIDR. Only a new pod clears it. Measured cost: ~35s down for all +# 20 hosts behind this middleware. apiVersion: traefik.io/v1alpha1 kind: Middleware metadata: @@ -36,6 +50,14 @@ spec: - "169.254.0.0/16" - "fc00::/7" - "fe80::/10" + # The mobile operator range from forust/mobile-whitelist, repeated + # deliberately rather than relying on the parser whitelist alone. + # That whitelist drops the event before it reaches a bucket, so no + # decision is ever created - but it is one config away from not + # firing, and the bouncer would then enforce a ban that was never + # justified. This is the last line: even a decision that exists for + # any reason is not served against the phone. + - "84.245.64.0/18" # The name is HTTPTimeoutSeconds, an int in seconds (min 1) - there is # no CrowdsecLapiTimeout, and an unrecognised key is silently dropped, # which is how this sat at the 10s default. Nothing rides on it per