apiVersion: traefik.io/v1alpha1 kind: Middleware metadata: name: crowdsec-bouncer namespace: crowdsec spec: plugin: crowdsec-bouncer: enabled: true LogLevel: INFO CrowdsecMode: live CrowdsecLapiScheme: http CrowdsecLapiHost: crowdsec-service.crowdsec.svc.cluster.local:8080 CrowdsecLapiKeyFile: "/etc/traefik/secrets/traefik-api-key" # LAPI lookup is SYNCHRONOUS and per-request: the plugin blocks on # `GET /v1/decisions?ip=...&banned=true` before the request reaches # the backend, and fails CLOSED (403) if the lookup exceeds the # timeout. Unset, the fork defaults to 10s, which is an eternity for # a request path: a single slow LAPI (idle 1.3-7.4s here) turned # every request into a 10s hang and then a self-inflicted 403. # 2s keeps the fail-closed path fast and bounded; with the LAPI # resourced properly (see crowdsec-values.yaml) the lookup is # sub-100ms and this budget is never hit. CrowdsecLapiTimeout: "2s"