CrowdSec proxied: single CF list (block-only) + firewall-bouncer re-apply #5

Merged
viktor merged 1 commit from wizard/crowdsec-1list into master 2026-06-20 19:31:02 +00:00
Owner

CF account allows only 1 list; proxied uses one block list (ban+captcha->block). Retriggers crowdsec apply to recreate the firewall-bouncer DS.

CF account allows only 1 list; proxied uses one block list (ban+captcha->block). Retriggers crowdsec apply to recreate the firewall-bouncer DS.
viktor added 1 commit 2026-06-20 19:29:50 +00:00
CF account hard-limits to 1 Rules List, so proxied enforcement uses one crowdsec_ban
list + one WAF block rule; the sync writes both ban and captcha decisions into it
(captcha downgraded to block at the edge). Drops the second list + managed_challenge
rule. Trivial touch to firewall_bouncer.tf to make CI re-apply crowdsec and recreate
the DaemonSet (tar fix already in master; stale orphan was cleared).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
viktor merged commit 834c5e6a2a into master 2026-06-20 19:31:02 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference: viktor/infra#5
No description provided.