disable crowdsec for now

This commit is contained in:
2025-12-28 10:08:05 +01:00
parent 9bf8b1b545
commit e10e4f2c6c
4 changed files with 41 additions and 29 deletions

View File

@@ -0,0 +1,8 @@
apiVersion: traefik.containo.us/v1alpha1
kind: Middleware
metadata:
name: adminbasicauth
namespace: kube-system
spec:
basicAuth:
secret: admin-basic-auth-credentials

View File

@@ -0,0 +1,13 @@
apiVersion: traefik.containo.us/v1alpha1
kind: Middleware
metadata:
name: crowdsec-bouncer
namespace: kube-system
spec:
plugin:
crowdsec-bouncer-traefik-plugin:
Enabled: true
CrowdsecMode: live
CrowdsecLapiUrl: "http://crowdsec-service.kube-system.svc.cluster.local:8080"
CrowdsecLapiKey: "${CROWDSEC_BOUNCER_API_KEY}"
UpdateIntervalSeconds: 10

View File

@@ -0,0 +1,11 @@
apiVersion: traefik.containo.us/v1alpha1
kind: Middleware
metadata:
name: localipfilter
namespace: kube-system
spec:
ipWhiteList:
sourceRange:
- 192.168.0.0/24
- 172.16.0.0/16
- 10.0.0.0/8

View File

@@ -69,32 +69,12 @@ spec:
size: 1Gi size: 1Gi
storageClass: longhorn storageClass: longhorn
path: /data path: /data
extraObjects: #experimental:
- apiVersion: traefik.containo.us/v1alpha1 # plugins:
kind: Middleware # crowdsec-bouncer-traefik-plugin:
metadata: # moduleName: github.com/maxlerebourg/crowdsec-bouncer-traefik-plugin
name: localipfilter # version: v1.4.6
namespace: kube-system #additionalArguments:
spec: # - "--providers.kubernetescrd"
ipWhiteList: # - "--entrypoints.web.http.middlewares=crowdsec-bouncer@kubernetescrd"
sourceRange: # - "--entrypoints.websecure.http.middlewares=kube-system-crowdsec-bouncer@kubernetescrd"
- 192.168.0.0/24
- 172.16.0.0/16
- 10.0.0.0/8
- apiVersion: traefik.containo.us/v1alpha1
kind: Middleware
metadata:
name: adminbasicauth
namespace: kube-system
spec:
basicAuth:
secret: adminbasicauthsecret
experimental:
plugins:
crowdsec-bouncer-traefik-plugin:
moduleName: github.com/maxlerebourg/crowdsec-bouncer-traefik-plugin
version: v1.4.6
additionalArguments:
- "--providers.kubernetescrd"
- "--entrypoints.web.http.middlewares=crowdsec-bouncer@kubernetescrd"
- "--entrypoints.websecure.http.middlewares=internal-crowdsec-bouncer@kubernetescrd"