[packages/crowdsec-firewall-bouncer] Initial

arekm arekm at pld-linux.org
Mon Sep 21 23:06:17 CEST 2026


commit 18915092cfc37734c166a2937bdd73beaf094f11
Author: Arkadiusz Miśkiewicz <arekm at maven.pl>
Date:   Mon Sep 21 23:05:38 2026 +0200

    Initial

 crowdsec-firewall-bouncer.init    | 110 ++++++++++++++++++++++++++++++++++++++
 crowdsec-firewall-bouncer.service |  30 +++++++++++
 crowdsec-firewall-bouncer.spec    | 105 ++++++++++++++++++++++++++++++++++++
 3 files changed, 245 insertions(+)
---
diff --git a/crowdsec-firewall-bouncer.spec b/crowdsec-firewall-bouncer.spec
new file mode 100644
index 0000000..7a47041
--- /dev/null
+++ b/crowdsec-firewall-bouncer.spec
@@ -0,0 +1,105 @@
+Summary:	CrowdSec firewall bouncer - enforces CrowdSec decisions with nftables or iptables
+Summary(pl.UTF-8):	Bouncer zaporowy CrowdSec - egzekwuje decyzje CrowdSec przez nftables lub iptables
+Name:		crowdsec-firewall-bouncer
+Version:	0.0.37
+Release:	1
+License:	MIT
+Group:		Networking/Daemons
+#Source0Download: https://github.com/crowdsecurity/cs-firewall-bouncer/releases
+Source0:	https://github.com/crowdsecurity/cs-firewall-bouncer/archive/refs/tags/v%{version}/%{name}-%{version}.tar.gz
+# Source0-md5:	31050ad2a3992678b6747a15c36adb8d
+# cd cs-firewall-bouncer-%{version}
+# go mod vendor
+# tar cJf ../%{name}-vendor-%{version}.tar.xz vendor
+Source1:	%{name}-vendor-%{version}.tar.xz
+# Source1-md5:	7edcbe6a9e88422c591cdc12801e6ce5
+Source2:	%{name}.init
+Source3:	%{name}.service
+URL:		https://github.com/crowdsecurity/cs-firewall-bouncer
+BuildRequires:	golang >= 1.25.2
+BuildRequires:	rpmbuild(macros) >= 2.009
+BuildRequires:	xz
+Requires(post,preun):	/sbin/chkconfig
+Requires(post,preun,postun):	systemd-units >= 38
+Requires:	rc-scripts
+Requires:	systemd-units >= 38
+# iptables mode shells out to iptables and ipset; nftables mode talks netlink directly
+Suggests:	crowdsec
+Suggests:	ipset
+Suggests:	iptables
+ExclusiveArch:	%go_arches
+BuildRoot:	%{tmpdir}/%{name}-%{version}-root-%(id -u -n)
+
+# pure Go, static binary: nothing for debugsource to carry
+%undefine	_debugsource_packages
+
+%description
+The firewall bouncer polls decisions from the CrowdSec local API and
+blocks the offending IP addresses with the host firewall. It supports
+nftables (through netlink, the default) and iptables with ipset. The
+bouncer needs an API key issued by the local API with 'cscli bouncers
+add'; put it in /etc/crowdsec/bouncers/crowdsec-firewall-bouncer.yaml.
+
+%description -l pl.UTF-8
+Bouncer zaporowy pobiera decyzje z lokalnego API CrowdSec i blokuje
+wskazane adresy IP w zaporze hosta. Obsługuje nftables (przez netlink,
+domyślnie) oraz iptables z ipset. Bouncer wymaga klucza API wydanego
+przez lokalne API poleceniem 'cscli bouncers add'; należy go wpisać do
+/etc/crowdsec/bouncers/crowdsec-firewall-bouncer.yaml.
+
+%prep
+%setup -q -n cs-firewall-bouncer-%{version} -a1
+
+%{__mkdir_p} .go-cache
+
+%build
+CGO_ENABLED=0 \
+%__go build -v -mod=vendor -buildmode=pie -trimpath -tags netgo \
+	-ldflags "-X github.com/crowdsecurity/go-cs-lib/version.Version=v%{version} \
+	-X github.com/crowdsecurity/go-cs-lib/version.Tag=%{release}" \
+	-o %{name} .
+
+%install
+rm -rf $RPM_BUILD_ROOT
+install -d $RPM_BUILD_ROOT{%{_sbindir},%{systemdunitdir},/etc/rc.d/init.d,/var/log} \
+	$RPM_BUILD_ROOT%{_sysconfdir}/crowdsec/bouncers
+
+install -p %{name} $RPM_BUILD_ROOT%{_sbindir}/%{name}
+install -p %{SOURCE2} $RPM_BUILD_ROOT/etc/rc.d/init.d/%{name}
+
+# upstream template: ${BACKEND} is filled in by the distro package,
+# ${API_KEY} stays for the admin (see %%description)
+%{__sed} -e 's/\${BACKEND}/nftables/' config/%{name}.yaml \
+	> $RPM_BUILD_ROOT%{_sysconfdir}/crowdsec/bouncers/%{name}.yaml
+cp -p %{SOURCE3} $RPM_BUILD_ROOT%{systemdunitdir}/%{name}.service
+
+:> $RPM_BUILD_ROOT/var/log/%{name}.log
+
+%clean
+rm -rf $RPM_BUILD_ROOT
+
+%post
+/sbin/chkconfig --add %{name}
+%service %{name} restart
+%systemd_post %{name}.service
+
+%preun
+if [ "$1" = "0" ]; then
+	%service -q %{name} stop
+	/sbin/chkconfig --del %{name}
+fi
+%systemd_preun %{name}.service
+
+%postun
+%systemd_reload
+
+%files
+%defattr(644,root,root,755)
+%doc LICENSE README.md
+%attr(754,root,root) /etc/rc.d/init.d/%{name}
+%attr(755,root,root) %{_sbindir}/%{name}
+%{systemdunitdir}/%{name}.service
+%dir %{_sysconfdir}/crowdsec
+%dir %{_sysconfdir}/crowdsec/bouncers
+%attr(600,root,root) %config(noreplace) %verify(not md5 mtime size) %{_sysconfdir}/crowdsec/bouncers/%{name}.yaml
+%ghost %attr(600,root,root) /var/log/%{name}.log
diff --git a/crowdsec-firewall-bouncer.init b/crowdsec-firewall-bouncer.init
new file mode 100755
index 0000000..a5fe1d9
--- /dev/null
+++ b/crowdsec-firewall-bouncer.init
@@ -0,0 +1,110 @@
+#!/bin/sh
+#
+# crowdsec-firewall-bouncer	CrowdSec firewall bouncer
+#
+# chkconfig:	345 21 07
+# description:	crowdsec-firewall-bouncer pulls decisions from the CrowdSec \
+#		local API and blocks the addresses with nftables or iptables.
+# processname:	crowdsec-firewall-bouncer
+# config:	/etc/crowdsec/bouncers/crowdsec-firewall-bouncer.yaml
+# pidfile:	/var/run/crowdsec-firewall-bouncer.pid
+
+# Source function library
+. /etc/rc.d/init.d/functions
+
+# Get network config
+. /etc/sysconfig/network
+
+SERVICE=crowdsec-firewall-bouncer
+LOCKFILE=/var/lock/subsys/$SERVICE
+PIDFILE=/var/run/$SERVICE.pid
+CONFIG=/etc/crowdsec/bouncers/crowdsec-firewall-bouncer.yaml
+PROG=/usr/sbin/crowdsec-firewall-bouncer
+
+# Check that networking is up
+if is_yes "${NETWORKING}"; then
+	if [ ! -f /var/lock/subsys/network -a "$1" != stop -a "$1" != status ]; then
+		msg_network_down "CrowdSec firewall bouncer"
+		exit 1
+	fi
+else
+	exit 0
+fi
+
+configtest() {
+	$PROG -c "$CONFIG" -t
+}
+
+start() {
+	if [ -f "$LOCKFILE" ]; then
+		msg_already_running "CrowdSec firewall bouncer"
+		return
+	fi
+	if ! configtest; then
+		msg_starting "CrowdSec firewall bouncer"
+		fail
+		RETVAL=1
+		return
+	fi
+	msg_starting "CrowdSec firewall bouncer"
+	# the bouncer runs in the foreground (systemd Type=notify); sysv has to
+	# background it and track the pid itself.
+	/sbin/start-stop-daemon --start --quiet --background \
+		--make-pidfile --pidfile "$PIDFILE" \
+		--exec $PROG -- -c "$CONFIG" && ok || fail
+	RETVAL=$?
+	[ $RETVAL -eq 0 ] && touch "$LOCKFILE"
+}
+
+stop() {
+	if [ ! -f "$LOCKFILE" ]; then
+		msg_not_running "CrowdSec firewall bouncer"
+		return
+	fi
+	msg_stopping "CrowdSec firewall bouncer"
+	killproc --pidfile "$PIDFILE" crowdsec-firewall-bouncer
+	rm -f "$LOCKFILE" "$PIDFILE" >/dev/null 2>&1
+}
+
+condrestart() {
+	if [ -f "$LOCKFILE" ]; then
+		stop
+		start
+	else
+		msg_not_running "CrowdSec firewall bouncer"
+		RETVAL=$1
+	fi
+}
+
+RETVAL=0
+case "$1" in
+  start)
+	start
+	;;
+  stop)
+	stop
+	;;
+  restart)
+	stop
+	start
+	;;
+  try-restart)
+	condrestart 0
+	;;
+  force-reload)
+	condrestart 7
+	;;
+  configtest)
+	configtest
+	RETVAL=$?
+	;;
+  status)
+	status --pidfile "$PIDFILE" crowdsec-firewall-bouncer
+	exit $?
+	;;
+  *)
+	msg_usage "$0 {start|stop|restart|try-restart|force-reload|configtest|status}"
+	exit 3
+esac
+
+exit $RETVAL
diff --git a/crowdsec-firewall-bouncer.service b/crowdsec-firewall-bouncer.service
new file mode 100644
index 0000000..6ab9b45
--- /dev/null
+++ b/crowdsec-firewall-bouncer.service
@@ -0,0 +1,30 @@
+[Unit]
+Description=CrowdSec firewall bouncer
+After=syslog.target network.target remote-fs.target nss-lookup.target crowdsec.service
+
+[Service]
+Type=notify
+ExecStartPre=/usr/sbin/crowdsec-firewall-bouncer -c /etc/crowdsec/bouncers/crowdsec-firewall-bouncer.yaml -t
+ExecStart=/usr/sbin/crowdsec-firewall-bouncer -c /etc/crowdsec/bouncers/crowdsec-firewall-bouncer.yaml
+Restart=always
+RestartSec=10
+LimitNOFILE=65536
+# don't send a termination signal to the children processes,
+# because the iptables backend needs to run ipset multiple times to properly shutdown
+KillMode=mixed
+
+# root only for the firewall: nftables over netlink, iptables/ipset via exec
+CapabilityBoundingSet=CAP_NET_ADMIN CAP_NET_RAW
+RestrictAddressFamilies=AF_NETLINK AF_UNIX AF_INET AF_INET6
+ProtectHome=true
+PrivateDevices=true
+ProtectHostname=true
+ProtectClock=true
+ProtectKernelTunables=true
+ProtectKernelModules=true
+ProtectKernelLogs=true
+ProtectControlGroups=true
+RestrictRealtime=true
+
+[Install]
+WantedBy=multi-user.target
================================================================

---- gitweb:

http://git.pld-linux.org/gitweb.cgi/packages/crowdsec-firewall-bouncer.git/commitdiff/18915092cfc37734c166a2937bdd73beaf094f11



More information about the pld-cvs-commit mailing list