X-Git-Url: https://git.openstreetmap.org./chef.git/blobdiff_plain/ba65c5618d3113373c0f3306ce993917fc2af23a..d18cd92a98384aebf371376383a4408485f12374:/cookbooks/fail2ban/recipes/default.rb?ds=sidebyside diff --git a/cookbooks/fail2ban/recipes/default.rb b/cookbooks/fail2ban/recipes/default.rb index 81bb4cd40..216572989 100644 --- a/cookbooks/fail2ban/recipes/default.rb +++ b/cookbooks/fail2ban/recipes/default.rb @@ -17,15 +17,25 @@ # limitations under the License. # -include_recipe "munin" +include_recipe "prometheus" -package "fail2ban" +package %w[ + fail2ban + python3-systemd + ruby-webrick +] + +if platform?("debian") + package "python3-inotify" +else + package "gamin" +end template "/etc/fail2ban/jail.d/00-default.conf" do source "jail.default.erb" owner "root" group "root" - mode 0o644 + mode "644" notifies :restart, "service[fail2ban]" end @@ -33,7 +43,7 @@ template "/etc/fail2ban/paths-overrides.local" do source "paths-overrides.local.erb" owner "root" group "root" - mode 0o644 + mode "644" notifies :restart, "service[fail2ban]" end @@ -41,4 +51,8 @@ service "fail2ban" do action [:enable, :start] end -munin_plugin "fail2ban" +prometheus_exporter "fail2ban" do + port 9635 + user "root" + restrict_address_families "AF_UNIX" +end