Add Crowdsec integration to Traefik
Configuration changes: - Enable Traefik experimental plugins support - Add Crowdsec bouncer plugin (maxlerebourg v1.3.3) - Configure Crowdsec middleware in config.yml - Connect Traefik to Crowdsec network - Add IP whitelist middleware for internal network - Update .gitignore to exclude crowdsec directory Security enhancements: - All routes now protected by Crowdsec threat intelligence - Internal network IP whitelist for Traefik dashboard - Crowdsec monitors all Traefik access logs - Real-time blocking of malicious IPs Protected services: - Mealie (recipes.pkartchner.com) - Gogs (git.pkartchner.com) - Traefik Dashboard (internal network only) 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude <noreply@anthropic.com>
This commit is contained in:
22
config.yml
22
config.yml
@@ -6,6 +6,9 @@ http:
|
||||
entryPoints:
|
||||
- https
|
||||
service: gogs
|
||||
middlewares:
|
||||
- secure-headers
|
||||
- crowdsec-bouncer
|
||||
tls:
|
||||
certResolver: letsencrypt
|
||||
|
||||
@@ -28,3 +31,22 @@ http:
|
||||
contentTypeNosniff: true
|
||||
browserXssFilter: true
|
||||
referrerPolicy: "same-origin"
|
||||
|
||||
# IP whitelist for internal network access only
|
||||
internal-whitelist:
|
||||
ipWhiteList:
|
||||
sourceRange:
|
||||
- "10.20.10.0/24"
|
||||
- "10.20.140.0/24"
|
||||
- "127.0.0.1/32"
|
||||
|
||||
# Crowdsec bouncer middleware
|
||||
crowdsec-bouncer:
|
||||
plugin:
|
||||
bouncer:
|
||||
enabled: true
|
||||
crowdsecMode: live
|
||||
crowdsecLapiKey: ***REMOVED***
|
||||
crowdsecLapiHost: crowdsec:8080
|
||||
crowdsecLapiScheme: http
|
||||
forwardedHeadersCustomName: X-Custom-Header
|
||||
|
||||
Reference in New Issue
Block a user