No description
| defaults | ||
| meta | ||
| tasks | ||
| .gitignore | ||
| README.md | ||
ansible-roles-crowdsec
This role is designed to provide a reverse proxy in conjuction with another role based deployment such as a metrics stack
w
Task Configuration
- name: Setup crowdsec
hosts: somehost
become: true
roles:
- role: crowdsec
crowdsec_sites:
- name: some-test
url: somehost.com
srv: "{{ crowdsec_local_address }}:8080"
- role: firewalld
firewalld_services:
- http
- https
firewalld_forwards:
- port: 80
to: 8080
- port: 443
to: 8443
- port: 443
to: 8443
proto: udp
Current configuration generates a single dynamic config file, this could be reconfigured to read from a directory
crowdsec-static.yml.j2
providers:
providersThrottleDuration: 2s
file:
directory: /etc/crowdsec/dynamic
watch: {{ crowdsec_watch }}
Deployment and Removal
Sometimes you need to manually stop the running containers to get a clean run when re-deploying Services must be stopped as the respecitve user or another means to aquire the correct user scope for systemd
systemctl --user stop container-crowdsec.service
Deploy
ansible-playbook -i hosts site.yml --tags=firewalld,crowdsec --limit=somehost
Remove
ansible-playbook -i hosts site.yml --tags=firewalld,crowdsec --extra-vars "container_state=absent firewall_action=remove" --limit=somehost