The previous commit enabled everything that passed the two mechanical
checks. Passing them is necessary, not sufficient: several of those apps
are singletons by role, and an instance of them would validate, clone,
start, and then not make sense.
Eight are now off by design, each saying why:
adguard a resolver is what clients point at
authelia the forward-auth provider every Traefik router points at
gluetun a network provider — apps join it by container name
headscale the control server a tailnet is defined by
libreportal_catalog LibrePortal's own catalog, internal plumbing
ollama one endpoint, and gigabytes of models per copy
trivy the updater resolves the scanner by a FIXED container
name, trivy-service, so a second copy would run and
never be the one CVE scanning uses
wireguard one stable published UDP endpoint; peers are tied to it
And one that should never have been touched: crowdsec ships no
docker-compose.yml, so the audit — which required a compose to read
service names from — skipped it, while the enabling pass only required a
config and did not. It got an unaudited true. There is nothing for
`instance create` to clone, and one decision engine watching the whole
box is the point of it. Now false, with that stated.
23 apps instanceable, 15 not: 6 that cannot be, 9 that should not be.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
76 lines
4.1 KiB
Plaintext
76 lines
4.1 KiB
Plaintext
#
|
|
# =============================================================================
|
|
# GENERAL CONFIGURATION
|
|
# =============================================================================
|
|
# APP_NAME = name of application for use in scripts
|
|
# HOST_INSTALL = true means apt + systemd install on the host, not Docker
|
|
# HOST_PACKAGE = dpkg package name; drives the "installed" badge
|
|
# HOST_SERVICES = all units; feeds the Services + Logs tabs
|
|
# HOST_LOG_FILES = <unit>|<path>,... mapping for the log viewer
|
|
# BACKUP = include in backup operations
|
|
# UPDATE_TYPE = auto: new image builds are applied automatically (a recovery snapshot is taken first), manual: only when you press Update
|
|
# MONITORING = if true, export this app's metrics to Prometheus + Grafana (needs both apps installed; ships the official CrowdSec Grafana dashboards)
|
|
# PROMETHEUS_LISTEN = address CrowdSec's metrics endpoint binds to; must be reachable from the Prometheus container (default: all interfaces, port 6060 — keep the :6060 port)
|
|
#
|
|
CFG_CROWDSEC_APP_NAME=crowdsec
|
|
# MULTI_INSTANCE = if true, this app can run as multiple isolated instances
|
|
# (own data/DB/subdomain/backups) via `libreportal instance create`. Only set on
|
|
# apps whose compose identity (container_name, Traefik routers, backup labels)
|
|
# is instance-safe — see scripts/instance/instance_create.sh.
|
|
# Not instanced by design. CrowdSec ships no docker-compose.yml at all — it is a
|
|
# host-level security agent plus Traefik bouncer, not a composed app, so there is
|
|
# no service identity for `instance create` to clone. It is also a singleton by
|
|
# nature: one decision engine watching the whole box is the point.
|
|
CFG_CROWDSEC_MULTI_INSTANCE=false
|
|
CFG_CROWDSEC_HOST_INSTALL=true
|
|
CFG_CROWDSEC_HOST_PACKAGE=crowdsec
|
|
CFG_CROWDSEC_HOST_SERVICES=crowdsec.service,crowdsec-firewall-bouncer.service
|
|
CFG_CROWDSEC_HOST_LOG_FILES="crowdsec.service|/var/log/crowdsec.log,crowdsec-firewall-bouncer.service|/var/log/crowdsec-firewall-bouncer.log"
|
|
CFG_CROWDSEC_BACKUP=true
|
|
CFG_CROWDSEC_BACKUP_STRATEGY=auto
|
|
CFG_CROWDSEC_UPDATE_TYPE=auto
|
|
CFG_CROWDSEC_MONITORING=false
|
|
CFG_CROWDSEC_PROMETHEUS_LISTEN=0.0.0.0:6060
|
|
#
|
|
# =============================================================================
|
|
# BEHAVIOUR
|
|
# =============================================================================
|
|
# ENABLED = master switch; false disables services (package stays)
|
|
# AUTO_UPDATE = pull hub parser/scenario updates from hub.crowdsec.net
|
|
# COMMUNITY_BLOCKLIST = subscribe to the free pooled blocklist (CAPI)
|
|
# CONSOLE_ENROLL = enroll this agent with the hosted SaaS at app.crowdsec.net (NOT the local dashboard)
|
|
# CONSOLE_TOKEN = enrollment token from app.crowdsec.net (only used when CONSOLE_ENROLL=true)
|
|
# BOUNCER = attach the Traefik bouncer middleware to every public route
|
|
#
|
|
CFG_CROWDSEC_ENABLED=true
|
|
CFG_CROWDSEC_COMMUNITY_BLOCKLIST=true
|
|
CFG_CROWDSEC_CONSOLE_ENROLL=false
|
|
CFG_CROWDSEC_CONSOLE_TOKEN=
|
|
CFG_CROWDSEC_BOUNCER=true
|
|
#
|
|
# =============================================================================
|
|
# METADATA
|
|
# =============================================================================
|
|
# CATEGORY = grouping in the app grid
|
|
# TITLE = display name
|
|
# DESCRIPTION = one-liner
|
|
# LONG_DESCRIPTION = card body text
|
|
# URL = source / docs link
|
|
# ACTIONS = available lifecycle verbs
|
|
#
|
|
CFG_CROWDSEC_CATEGORY="security,recommended"
|
|
CFG_CROWDSEC_TITLE="CrowdSec"
|
|
CFG_CROWDSEC_DESCRIPTION="Intrusion Prevention"
|
|
CFG_CROWDSEC_LONG_DESCRIPTION="An open-source intrusion prevention system: it spots brute-force, scans and web exploits in your logs and blocks the offending IPs at the firewall"
|
|
CFG_CROWDSEC_URL="https://www.crowdsec.net"
|
|
CFG_CROWDSEC_ACTIONS="configure|install|restart|shutdown|uninstall|tools"
|
|
#
|
|
# =============================================================================
|
|
# ADVANCED
|
|
# =============================================================================
|
|
# LAPI_HOST = LAPI bind address; 0.0.0.0 so Traefik can reach via host.docker.internal
|
|
# TRAEFIK_LAPI_KEY = auto-generated on install; use the "Rotate Traefik Bouncer Key" tool to replace it (editing this value does not re-register the bouncer)
|
|
#
|
|
CFG_CROWDSEC_LAPI_HOST=0.0.0.0:8080
|
|
CFG_CROWDSEC_TRAEFIK_LAPI_KEY=
|