Fail2ban with integrated http prometheus-client and geolocation
1.4K
version: '3.5'
services:
fail2ban:
container_name: fail2ban
image: phoenixashes/fail2ban:latest
network_mode: "host"
environment:
- NOIP_API_TOKEN=************ # noip access token is free for 50k request per month, if no token is specified you are limited to 1k/ day
- METRICS_PORT=9123 # Port to expose for prometheus metrics, default is 9123
- SCRAP_INTERVAL=300 # scrap interval in seconds, default is 300
volumes:
- fail2ban:/fail2ban # fail2ban config
# logs in read only mode
- "/var/log:/var/log:ro"
- openvpn_logs:/openvpn-logs/:ro
- nginx_logs:/container-logs/:ro
cap_add:
- NET_ADMIN
- NET_RAW
restart: unless-stopped
volumes:
fail2ban:
name: fail2ban
openvpn_logs:
external: true
nginx_logs:
external: true
Configure Fail2ban just like you would on a normal install
- action.d
- filter.d
- your filters...
- jail.d
- jail.local
Prometheus config
scrape_configs:
- job_name: fail2ban
static_configs:
- targets: ['host.docker.internal:9123'] # resolves to host ip
Make sure Prometheus is running with
extra_hosts:
- "host.docker.internal:host-gateway"
if you use other networks than the host network for prometheus since fail2ban has to run in network mode "host" in order to firewall.
Example Grafana dashboard: https://grafana.com/grafana/dashboards/16125
Content type
Image
Digest
sha256:31ad6a9c6…
Size
31.8 MB
Last updated
almost 4 years ago
docker pull phoenixashes/fail2ban