Sign inSign up

ttionya/fail2ban

By ttionya

•Updated 1 day ago

Upstream `crazymax/fail2ban:debian` supports systemd; we regularly build an enhanced image on it.

Image
Web servers
Monitoring & observability
Web analytics
0

10K+

ttionya/fail2ban repository overview

⁠fail2ban

Docker Image Version (latest by date) Docker Pulls GitHub

This project is forked from crazy-max/docker-fail2ban⁠ and modified from it. Any subsequent mention of upstream refers to that project.

Starting with Fail2Ban 1.1.1, this project no longer builds from a modified copy of the upstream source code. Instead, it periodically builds from the crazymax/fail2ban:<version>-debian image published by the upstream project, with additional enhancements. The last version built the old way, Fail2Ban 1.1.0, is available in the 1.1.0 branch⁠.

Note: If you are NOT looking for this project with a strong purpose, please use the crazymax/fail2ban⁠ image directly.

⁠About

This project is rebuilt from the upstream crazymax/fail2ban:<version>-debian image with the following modifications:

  1. Keep dependencies up to date.

    To ensure timely security updates, all dependencies are updated on every rebuild. As a result, the image size may vary depending on the updated dependencies.

  2. Built-in inotify-tools, including the inotifywait command.

    If your log file names rotate over time, you can use inotifywait to monitor file creation or deletion and reload Fail2Ban.

⁠Usage

⁠fail2ban

The configuration for Fail2Ban is the same as upstream, please refer to the crazy-max/docker-fail2ban documentation⁠.

⁠inotifywait

You can use the built-in inotifywait to monitor the creation and removal of log files.

To enable it, mount a configuration file at /etc/inotifywait.conf. This configuration file is specific to this image.

The typical configuration file is as follows:

# fail2ban-client reload (for all)
-m -e create,moved_from --include .*\.access\..*\.log$ /var/log/nginx

# fail2ban-client reload nginx
-m -e create,moved_from --include .*\.access\..*\.log$ /var/log/nginx [nginx]

# fail2ban-client reload nginx && fail2ban-client reload httpd
-m -e create,moved_from --include .*\.access\..*\.log$ /var/log/nginx [nginx httpd]
  1. Each line contains the arguments passed to inotifywait, excluding the command name itself.
  2. Blank lines and lines starting with # are ignored.
  3. The trailing [jail] is OPTIONAL and represents which jails need to be reloaded when the watch is triggered, separated by SPACES.

⁠Example

docker run -d \
  --network host \
  --cap-add NET_ADMIN \
  --cap-add NET_RAW \
  --mount type=bind,source=/path/to/fail2ban/data,target=/data \
  --mount type=bind,source=/path/to/inotifywait.conf,target=/etc/inotifywait.conf,readonly \
  --mount type=bind,source=/run/log/journal,target=/run/log/journal,readonly \
  --mount type=bind,source=/var/log/journal,target=/var/log/journal,readonly \
  --mount type=bind,source=/etc/machine-id,target=/etc/machine-id,readonly \
  --mount type=bind,source=/var/log/nginx,target=/var/log/nginx,readonly \
  ttionya/fail2ban

⁠Versioning

The version is divided into three parts, separated by hyphens (-).

PartVersionDescription
11.1.0fail2ban version number
2r1Upstream version number
31 or b1Project version number (b for beta, number for stable)

⁠Schedule

To ensure the use of the latest dependencies, this image is rebuilt every Monday at 06:00 UTC.

⁠Thanks

⁠License

MIT

Tag summary

Content type

Image

Digest

sha256:855474f55…

Size

71.1 MB

Last updated

1 day ago

docker pull ttionya/fail2ban