The edge CF IP List can't hold the ~31k CAPI community blocklist (already enforced in-kernel by the firewall-bouncer), so the sync now skips origin=CAPI and carries only high-signal local/curated decisions (+ a 9000 safety cap). Also fixes the list-items GET: per_page=1000 returned a misleading CF 400 'invalid or expired cursor' (10027); the endpoint max is 500. Verified live: crowdsec_ban populates (4 IPs) and the sync exits 0. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| worker | ||
| .terraform.lock.hcl | ||
| crowdsec_edge.tf | ||
| lapi_kv_sync.py | ||
| main.tf | ||
| providers.tf | ||
| secrets | ||
| terragrunt.hcl | ||