CrowdSec real enforcement: edge WAF (proxied) + firewall-bouncer (direct) #2
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "wizard/crowdsec-enforcement"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Replaces the dead Traefik Yaegi plugin. Foundation: whitelist internal CIDRs + register kvsync/firewall bouncer keys. Proxied: CF IP Lists + zone WAF rule (block/managed_challenge) covering all proxied hosts, fed by a LAPI->CF-list sync CronJob. Direct: cs-firewall-bouncer DaemonSet (nftables, pinned to k8s-node2 for one-node validation). See commits.