deleted crowdsec stack from the repo. will figure something else
ci / lint-prettier (push) Successful in 18s
ci / lint-ruff (push) Successful in 6s
ci / lint-yaml (push) Successful in 6s
ci / lint-dockerfiles (push) Successful in 5s
ci / validate (push) Successful in 6s
ci / build (push) Successful in 43s

Signed-off-by: mr-forust <vzlomdsisma@gmail.com>
This commit is contained in:
forust committed 2026-07-19 23:16:14 +02:00
1 parent 87ca3fd40c
commit 92aa731e44
23 files changed
+5 -158

No files matched your search

-14
View File
@@ -1,14 +0,0 @@
apiVersion: traefik.io/v1alpha1
kind: Middleware
metadata:
name: crowdsec-bouncer
namespace: crowdsec
spec:
plugin:
crowdsec-bouncer:
enabled: true
LogLevel: INFO
CrowdsecMode: live
CrowdsecLapiScheme: http
CrowdsecLapiHost: crowdsec-service.crowdsec.svc.cluster.local:8080
CrowdsecLapiKeyFile: "/etc/traefik/secrets/traefik-api-key"
-65
View File
@@ -1,65 +0,0 @@
container_runtime: containerd
agent:
env:
- name: COLLECTIONS
value: "crowdsecurity/traefik crowdsecurity/base-http-scenarios crowdsecurity/sshd"
extraVolumes:
- name: journal-dir
hostPath:
path: /var/log/journal
type: DirectoryOrCreate
- name: run-journal-dir
hostPath:
path: /run/log/journal
type: DirectoryOrCreate
extraVolumeMounts:
- name: journal-dir
mountPath: /var/log/journal
readOnly: true
- name: run-journal-dir
mountPath: /run/log/journal
readOnly: true
acquisition:
- namespace: traefik
podName: "*traefik*"
program: traefik
poll_without_inotify: true
acquisitionCustom: |
- source: journalctl
journalctl_filter:
- _SYSTEMD_UNIT=sshd.service
labels:
type: syslog
resources:
requests:
cpu: 50m
memory: 100Mi
limits:
cpu: 200m
memory: 500Mi
lapi:
env:
- name: COLLECTIONS
value: "crowdsecurity/traefik crowdsecurity/base-http-scenarios crowdsecurity/sshd"
service:
type: NodePort
nodePort: 30011
resources:
requests:
cpu: 50m
memory: 150Mi
limits:
cpu: 200m
memory: 500Mi
metrics:
enabled: true
serviceMonitor:
additionalLabels:
release: prometheus-stack
enabled: true
namespace: prometheus
-10
View File
@@ -1,10 +0,0 @@
#!/bin/sh
kubectl patch daemonset -n crowdsec crowdsec-agent --type='json' -p='[{
"op": "replace",
"path": "/spec/template/spec/initContainers/0/command",
"value": ["sh", "-c", "until nc \"$LAPI_HOST\" \"$LAPI_PORT\" -z; do echo waiting for lapi to start; sleep 5; done; ln -s /staging/etc/crowdsec /etc/crowdsec; cscli lapi register --machine \"$USERNAME\" -u \"$LAPI_URL\" --token \"$REGISTRATION_TOKEN\" 2>/dev/null || true; cp /etc/crowdsec/local_api_credentials.yaml /tmp_config/local_api_credentials.yaml 2>/dev/null || true"]
}]' 2>&1
kubectl rollout restart -n crowdsec daemonset/crowdsec-agent 2>&1
kubectl rollout status -n crowdsec daemonset/crowdsec-agent --timeout=120s 2>&1