]> git.openstreetmap.org Git - chef.git/blobdiff - cookbooks/nominatim/recipes/default.rb
Add https support for git.osm.org
[chef.git] / cookbooks / nominatim / recipes / default.rb
index 05227bb465bcbca205711d54dcf04a829b82c14c..d667db3cfe90d3d9cf061e1ef358f4e90a3e7a68 100644 (file)
@@ -370,6 +370,19 @@ template "/etc/logrotate.d/apache2" do
   mode 0o644
 end
 
+include_recipe "fail2ban"
+
+fail2ban_filter "nominatim" do
+  failregex "Warning ignored: <HOST>"
+end
+
+fail2ban_jail "nominatim" do
+  filter "nominatim"
+  logpath "#{node[:nominatim][:logdir]}/restricted_ips.log"
+  ports [80, 443]
+  maxretry 3
+end
+
 munin_plugin_conf "nominatim" do
   template "munin.erb"
   variables :db => node[:nominatim][:dbname],