X-Git-Url: https://git.openstreetmap.org./chef.git/blobdiff_plain/a68415b8f2bf106b6ea5948b0605c897b516ef4f..1bc8da5f3a3bfd6c3f0ba374f12d489d13831460:/cookbooks/fail2ban/recipes/default.rb?ds=sidebyside diff --git a/cookbooks/fail2ban/recipes/default.rb b/cookbooks/fail2ban/recipes/default.rb index 50b31d1b3..216572989 100644 --- a/cookbooks/fail2ban/recipes/default.rb +++ b/cookbooks/fail2ban/recipes/default.rb @@ -1,14 +1,14 @@ # -# Cookbook Name:: fail2ban +# Cookbook:: fail2ban # Recipe:: default # -# Copyright 2013, OpenStreetMap Foundation +# Copyright:: 2013, OpenStreetMap Foundation # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. # You may obtain a copy of the License at # -# http://www.apache.org/licenses/LICENSE-2.0 +# https://www.apache.org/licenses/LICENSE-2.0 # # Unless required by applicable law or agreed to in writing, software # distributed under the License is distributed on an "AS IS" BASIS, @@ -17,40 +17,42 @@ # limitations under the License. # -package "fail2ban" +include_recipe "prometheus" -if node[:lsb][:release].to_f >= 14.04 - file "/etc/fail2ban/jail.local" do - action :delete - end -else - directory "/etc/fail2ban/jail.d" do - owner "root" - group "root" - mode 0o755 - end +package %w[ + fail2ban + python3-systemd + ruby-webrick +] - template "/etc/fail2ban/jail.local" do - source "jail.local.erb" - owner "root" - group "root" - mode 0o644 - subscribes :create, "template[/etc/fail2ban/jail.d/00-default.conf]" - notifies :reload, "service[fail2ban]" - end +if platform?("debian") + package "python3-inotify" +else + package "gamin" end template "/etc/fail2ban/jail.d/00-default.conf" do source "jail.default.erb" owner "root" group "root" - mode 0o644 - notifies :reload, "service[fail2ban]" + mode "644" + notifies :restart, "service[fail2ban]" +end + +template "/etc/fail2ban/paths-overrides.local" do + source "paths-overrides.local.erb" + owner "root" + group "root" + mode "644" + notifies :restart, "service[fail2ban]" end service "fail2ban" do action [:enable, :start] - supports :status => true, :reload => true, :restart => true end -munin_plugin "fail2ban" +prometheus_exporter "fail2ban" do + port 9635 + user "root" + restrict_address_families "AF_UNIX" +end