Sign inSign up

christianmaier/base-crowdsec

By christianmaier

•Updated 1 day ago

CrowdSec engine built from source, hub content pinned: bans scanners found in base 2 proxy logs

Image
0

772

christianmaier/base-crowdsec repository overview

⁠base-crowdsec

The CrowdSec engine of base 2. It reads the access log of base-caddy, recognises scans and attacks, and keeps the bans that the bouncer in Caddy enforces. Not meant as a general-purpose CrowdSec image.

⁠What is inside

  • CrowdSec 1.8.1 (crowdsec, cscli), built from the release source with Go 1.26 and updated libraries; statically linked, SQLite through cgo, re2 as WebAssembly
  • Hub content installed at build time from a fixed commit of crowdsecurity/hub: the Caddy log parser, the HTTP and CVE scenarios, and allowlists for private networks and well-known crawlers
  • A small start script instead of upstream's: registers the engine, optionally the Central API, and the bouncer key it is given
  • No notification plugins, no yq

⁠Configuration

  • CROWDSEC_BOUNCER_KEY: key of the bouncer in Caddy (required)
  • CROWDSEC_CAPI_FILE: where the Central API login is kept; empty runs the engine on its own
  • State (database, credentials) in /var/lib/crowdsec

⁠Build

  • Multi-arch (linux/amd64, linux/arm64), cross-compiled without emulation
  • Passes the same Trivy gate as the other base 2 images
  • Runs as an unprivileged user (10001) without capabilities

⁠Tags

One tag per release of base 2 (e.g. 2.5.0). Deployments pull by digest.

Tag summary

Content type

Image

Digest

sha256:cd5c76ea9…

Size

78.5 MB

Last updated

1 day ago

docker pull christianmaier/base-crowdsec:2.9.4