docs: CrowdSec enforcement = firewall-bouncer + CF WAF (plugin removed) #11
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "wizard/crowdsec-docs"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
The dead Traefik Yaegi
crowdsec-bouncer-traefik-plugin(handler never invoked on Traefik 3.7.5, enforced nothing) was removed. This rewrites the docs to describe the replacement two-surface, out-of-band enforcement model:cs-firewall-bouncerDaemonSet (drops in both theinputandforwardhooks; pulls all decisions incl. the ~31k CAPI blocklist; bouncer keyfirewall).crowdsec_banRules List + a zone WAF block rule, fed by thecrowdsec-cf-syncCronJob (excludes CAPI; bouncer keykvsync).Both add zero per-request latency and fail open. Whitelist covers RFC1918 + tailnet + internal CIDRs.
Files updated:
docs/architecture/security.md(primary: section rewrite + diagram + components + troubleshooting + supersession note),docs/architecture/networking.md(overview, both mermaid diagrams, middleware chain, decision section, troubleshooting),.claude/CLAUDE.md(Networking & Resilience bullet + CrowdSec service-notes row).Docs-only; no terragrunt/apply. The preserved Aetherinox
api-token-middleware(paperless-mcp) is untouched.🤖 Generated with Claude Code