[packages/crowdsec-firewall-bouncer] Initial
arekm
arekm at pld-linux.org
Mon Sep 21 23:06:17 CEST 2026
commit 18915092cfc37734c166a2937bdd73beaf094f11
Author: Arkadiusz Miśkiewicz <arekm at maven.pl>
Date: Mon Sep 21 23:05:38 2026 +0200
Initial
crowdsec-firewall-bouncer.init | 110 ++++++++++++++++++++++++++++++++++++++
crowdsec-firewall-bouncer.service | 30 +++++++++++
crowdsec-firewall-bouncer.spec | 105 ++++++++++++++++++++++++++++++++++++
3 files changed, 245 insertions(+)
---
diff --git a/crowdsec-firewall-bouncer.spec b/crowdsec-firewall-bouncer.spec
new file mode 100644
index 0000000..7a47041
--- /dev/null
+++ b/crowdsec-firewall-bouncer.spec
@@ -0,0 +1,105 @@
+Summary: CrowdSec firewall bouncer - enforces CrowdSec decisions with nftables or iptables
+Summary(pl.UTF-8): Bouncer zaporowy CrowdSec - egzekwuje decyzje CrowdSec przez nftables lub iptables
+Name: crowdsec-firewall-bouncer
+Version: 0.0.37
+Release: 1
+License: MIT
+Group: Networking/Daemons
+#Source0Download: https://github.com/crowdsecurity/cs-firewall-bouncer/releases
+Source0: https://github.com/crowdsecurity/cs-firewall-bouncer/archive/refs/tags/v%{version}/%{name}-%{version}.tar.gz
+# Source0-md5: 31050ad2a3992678b6747a15c36adb8d
+# cd cs-firewall-bouncer-%{version}
+# go mod vendor
+# tar cJf ../%{name}-vendor-%{version}.tar.xz vendor
+Source1: %{name}-vendor-%{version}.tar.xz
+# Source1-md5: 7edcbe6a9e88422c591cdc12801e6ce5
+Source2: %{name}.init
+Source3: %{name}.service
+URL: https://github.com/crowdsecurity/cs-firewall-bouncer
+BuildRequires: golang >= 1.25.2
+BuildRequires: rpmbuild(macros) >= 2.009
+BuildRequires: xz
+Requires(post,preun): /sbin/chkconfig
+Requires(post,preun,postun): systemd-units >= 38
+Requires: rc-scripts
+Requires: systemd-units >= 38
+# iptables mode shells out to iptables and ipset; nftables mode talks netlink directly
+Suggests: crowdsec
+Suggests: ipset
+Suggests: iptables
+ExclusiveArch: %go_arches
+BuildRoot: %{tmpdir}/%{name}-%{version}-root-%(id -u -n)
+
+# pure Go, static binary: nothing for debugsource to carry
+%undefine _debugsource_packages
+
+%description
+The firewall bouncer polls decisions from the CrowdSec local API and
+blocks the offending IP addresses with the host firewall. It supports
+nftables (through netlink, the default) and iptables with ipset. The
+bouncer needs an API key issued by the local API with 'cscli bouncers
+add'; put it in /etc/crowdsec/bouncers/crowdsec-firewall-bouncer.yaml.
+
+%description -l pl.UTF-8
+Bouncer zaporowy pobiera decyzje z lokalnego API CrowdSec i blokuje
+wskazane adresy IP w zaporze hosta. Obsługuje nftables (przez netlink,
+domyślnie) oraz iptables z ipset. Bouncer wymaga klucza API wydanego
+przez lokalne API poleceniem 'cscli bouncers add'; należy go wpisać do
+/etc/crowdsec/bouncers/crowdsec-firewall-bouncer.yaml.
+
+%prep
+%setup -q -n cs-firewall-bouncer-%{version} -a1
+
+%{__mkdir_p} .go-cache
+
+%build
+CGO_ENABLED=0 \
+%__go build -v -mod=vendor -buildmode=pie -trimpath -tags netgo \
+ -ldflags "-X github.com/crowdsecurity/go-cs-lib/version.Version=v%{version} \
+ -X github.com/crowdsecurity/go-cs-lib/version.Tag=%{release}" \
+ -o %{name} .
+
+%install
+rm -rf $RPM_BUILD_ROOT
+install -d $RPM_BUILD_ROOT{%{_sbindir},%{systemdunitdir},/etc/rc.d/init.d,/var/log} \
+ $RPM_BUILD_ROOT%{_sysconfdir}/crowdsec/bouncers
+
+install -p %{name} $RPM_BUILD_ROOT%{_sbindir}/%{name}
+install -p %{SOURCE2} $RPM_BUILD_ROOT/etc/rc.d/init.d/%{name}
+
+# upstream template: ${BACKEND} is filled in by the distro package,
+# ${API_KEY} stays for the admin (see %%description)
+%{__sed} -e 's/\${BACKEND}/nftables/' config/%{name}.yaml \
+ > $RPM_BUILD_ROOT%{_sysconfdir}/crowdsec/bouncers/%{name}.yaml
+cp -p %{SOURCE3} $RPM_BUILD_ROOT%{systemdunitdir}/%{name}.service
+
+:> $RPM_BUILD_ROOT/var/log/%{name}.log
+
+%clean
+rm -rf $RPM_BUILD_ROOT
+
+%post
+/sbin/chkconfig --add %{name}
+%service %{name} restart
+%systemd_post %{name}.service
+
+%preun
+if [ "$1" = "0" ]; then
+ %service -q %{name} stop
+ /sbin/chkconfig --del %{name}
+fi
+%systemd_preun %{name}.service
+
+%postun
+%systemd_reload
+
+%files
+%defattr(644,root,root,755)
+%doc LICENSE README.md
+%attr(754,root,root) /etc/rc.d/init.d/%{name}
+%attr(755,root,root) %{_sbindir}/%{name}
+%{systemdunitdir}/%{name}.service
+%dir %{_sysconfdir}/crowdsec
+%dir %{_sysconfdir}/crowdsec/bouncers
+%attr(600,root,root) %config(noreplace) %verify(not md5 mtime size) %{_sysconfdir}/crowdsec/bouncers/%{name}.yaml
+%ghost %attr(600,root,root) /var/log/%{name}.log
diff --git a/crowdsec-firewall-bouncer.init b/crowdsec-firewall-bouncer.init
new file mode 100755
index 0000000..a5fe1d9
--- /dev/null
+++ b/crowdsec-firewall-bouncer.init
@@ -0,0 +1,110 @@
+#!/bin/sh
+#
+# crowdsec-firewall-bouncer CrowdSec firewall bouncer
+#
+# chkconfig: 345 21 07
+# description: crowdsec-firewall-bouncer pulls decisions from the CrowdSec \
+# local API and blocks the addresses with nftables or iptables.
+# processname: crowdsec-firewall-bouncer
+# config: /etc/crowdsec/bouncers/crowdsec-firewall-bouncer.yaml
+# pidfile: /var/run/crowdsec-firewall-bouncer.pid
+
+# Source function library
+. /etc/rc.d/init.d/functions
+
+# Get network config
+. /etc/sysconfig/network
+
+SERVICE=crowdsec-firewall-bouncer
+LOCKFILE=/var/lock/subsys/$SERVICE
+PIDFILE=/var/run/$SERVICE.pid
+CONFIG=/etc/crowdsec/bouncers/crowdsec-firewall-bouncer.yaml
+PROG=/usr/sbin/crowdsec-firewall-bouncer
+
+# Check that networking is up
+if is_yes "${NETWORKING}"; then
+ if [ ! -f /var/lock/subsys/network -a "$1" != stop -a "$1" != status ]; then
+ msg_network_down "CrowdSec firewall bouncer"
+ exit 1
+ fi
+else
+ exit 0
+fi
+
+configtest() {
+ $PROG -c "$CONFIG" -t
+}
+
+start() {
+ if [ -f "$LOCKFILE" ]; then
+ msg_already_running "CrowdSec firewall bouncer"
+ return
+ fi
+ if ! configtest; then
+ msg_starting "CrowdSec firewall bouncer"
+ fail
+ RETVAL=1
+ return
+ fi
+ msg_starting "CrowdSec firewall bouncer"
+ # the bouncer runs in the foreground (systemd Type=notify); sysv has to
+ # background it and track the pid itself.
+ /sbin/start-stop-daemon --start --quiet --background \
+ --make-pidfile --pidfile "$PIDFILE" \
+ --exec $PROG -- -c "$CONFIG" && ok || fail
+ RETVAL=$?
+ [ $RETVAL -eq 0 ] && touch "$LOCKFILE"
+}
+
+stop() {
+ if [ ! -f "$LOCKFILE" ]; then
+ msg_not_running "CrowdSec firewall bouncer"
+ return
+ fi
+ msg_stopping "CrowdSec firewall bouncer"
+ killproc --pidfile "$PIDFILE" crowdsec-firewall-bouncer
+ rm -f "$LOCKFILE" "$PIDFILE" >/dev/null 2>&1
+}
+
+condrestart() {
+ if [ -f "$LOCKFILE" ]; then
+ stop
+ start
+ else
+ msg_not_running "CrowdSec firewall bouncer"
+ RETVAL=$1
+ fi
+}
+
+RETVAL=0
+case "$1" in
+ start)
+ start
+ ;;
+ stop)
+ stop
+ ;;
+ restart)
+ stop
+ start
+ ;;
+ try-restart)
+ condrestart 0
+ ;;
+ force-reload)
+ condrestart 7
+ ;;
+ configtest)
+ configtest
+ RETVAL=$?
+ ;;
+ status)
+ status --pidfile "$PIDFILE" crowdsec-firewall-bouncer
+ exit $?
+ ;;
+ *)
+ msg_usage "$0 {start|stop|restart|try-restart|force-reload|configtest|status}"
+ exit 3
+esac
+
+exit $RETVAL
diff --git a/crowdsec-firewall-bouncer.service b/crowdsec-firewall-bouncer.service
new file mode 100644
index 0000000..6ab9b45
--- /dev/null
+++ b/crowdsec-firewall-bouncer.service
@@ -0,0 +1,30 @@
+[Unit]
+Description=CrowdSec firewall bouncer
+After=syslog.target network.target remote-fs.target nss-lookup.target crowdsec.service
+
+[Service]
+Type=notify
+ExecStartPre=/usr/sbin/crowdsec-firewall-bouncer -c /etc/crowdsec/bouncers/crowdsec-firewall-bouncer.yaml -t
+ExecStart=/usr/sbin/crowdsec-firewall-bouncer -c /etc/crowdsec/bouncers/crowdsec-firewall-bouncer.yaml
+Restart=always
+RestartSec=10
+LimitNOFILE=65536
+# don't send a termination signal to the children processes,
+# because the iptables backend needs to run ipset multiple times to properly shutdown
+KillMode=mixed
+
+# root only for the firewall: nftables over netlink, iptables/ipset via exec
+CapabilityBoundingSet=CAP_NET_ADMIN CAP_NET_RAW
+RestrictAddressFamilies=AF_NETLINK AF_UNIX AF_INET AF_INET6
+ProtectHome=true
+PrivateDevices=true
+ProtectHostname=true
+ProtectClock=true
+ProtectKernelTunables=true
+ProtectKernelModules=true
+ProtectKernelLogs=true
+ProtectControlGroups=true
+RestrictRealtime=true
+
+[Install]
+WantedBy=multi-user.target
================================================================
---- gitweb:
http://git.pld-linux.org/gitweb.cgi/packages/crowdsec-firewall-bouncer.git/commitdiff/18915092cfc37734c166a2937bdd73beaf094f11
More information about the pld-cvs-commit
mailing list