[packages/crowdsec] Initial

arekm arekm at pld-linux.org
Mon Sep 21 23:09:34 CEST 2026


commit 26f3fd34c48e17307da03237372751bcb414e205
Author: Arkadiusz Miśkiewicz <arekm at maven.pl>
Date:   Mon Sep 21 23:06:54 2026 +0200

    Initial

 crowdsec-hubupdate.timer |  10 ++
 crowdsec.cron            |  18 ++++
 crowdsec.init            | 127 +++++++++++++++++++++++
 crowdsec.service         |  29 ++++++
 crowdsec.spec            | 259 +++++++++++++++++++++++++++++++++++++++++++++++
 5 files changed, 443 insertions(+)
---
diff --git a/crowdsec.spec b/crowdsec.spec
new file mode 100644
index 0000000..d1271f3
--- /dev/null
+++ b/crowdsec.spec
@@ -0,0 +1,259 @@
+Summary:	CrowdSec - behaviour detection engine with a crowd-sourced IP reputation database
+Summary(pl.UTF-8):	CrowdSec - silnik wykrywania zachowań z rozproszoną bazą reputacji adresów IP
+Name:		crowdsec
+Version:	1.8.1
+Release:	1
+License:	MIT
+Group:		Daemons
+#Source0Download: https://github.com/crowdsecurity/crowdsec/releases
+Source0:	https://github.com/crowdsecurity/crowdsec/archive/refs/tags/v%{version}/%{name}-%{version}.tar.gz
+# Source0-md5:	849e4e841ca4b70349f0752b88f4d5bc
+# cd %{name}-%{version}
+# go mod vendor
+# tar cJf ../%{name}-vendor-%{version}.tar.xz vendor
+Source1:	%{name}-vendor-%{version}.tar.xz
+# Source1-md5:	0e7f8ce016350ad4c15e706fc3a3b5a8
+Source2:	%{name}.init
+Source3:	%{name}.cron
+Source4:	%{name}.service
+Source5:	%{name}-hubupdate.timer
+URL:		https://www.crowdsec.net/
+BuildRequires:	golang >= 1.26.1
+BuildRequires:	libstdc++-devel
+BuildRequires:	pkgconfig
+BuildRequires:	re2-devel
+BuildRequires:	rpmbuild(macros) >= 2.009
+BuildRequires:	sqlite3-devel
+BuildRequires:	xz
+Requires(post,preun):	/sbin/chkconfig
+Requires(post,preun,postun):	systemd-units >= 38
+# hub and central API are reached over https
+Requires:	ca-certificates
+Requires:	rc-scripts
+Requires:	systemd-units >= 38
+Suggests:	crowdsec-firewall-bouncer
+ExclusiveArch:	%go_arches
+BuildRoot:	%{tmpdir}/%{name}-%{version}-root-%(id -u -n)
+
+# Go binaries built with -trimpath carry no source paths, debugsource would be empty
+%undefine	_debugsource_packages
+
+%define		plugindir	%{_libexecdir}/%{name}/plugins
+
+%description
+CrowdSec is a behaviour detection engine. It parses logs from local
+files, journald, syslog, containers or cloud services, matches them
+against scenarios published on the CrowdSec Hub and issues decisions
+(bans, captchas, throttling) against offending IP addresses. Decisions
+are enforced by separate remediation components such as the firewall
+bouncer. Signals about detected attacks are shared with the CrowdSec
+community, and the engine receives a curated blocklist of currently
+malicious IP addresses in return.
+
+This package installs the crowdsec engine, the cscli management tool
+and the notification plugins (email, file, http, slack, splunk,
+sentinel). Hub content (collections, parsers, scenarios) is fetched at
+runtime with 'cscli hub update'.
+
+%description -l pl.UTF-8
+CrowdSec to silnik wykrywania zachowań. Analizuje logi z plików
+lokalnych, journald, sysloga, kontenerów lub usług chmurowych,
+dopasowuje je do scenariuszy publikowanych w CrowdSec Hub i wydaje
+decyzje (blokada, captcha, ograniczenie ruchu) wobec adresów IP
+atakujących. Decyzje egzekwują osobne komponenty (np. bouncer
+zaporowy). Sygnały o wykrytych atakach są dzielone ze społecznością
+CrowdSec, a w zamian silnik otrzymuje listę adresów IP aktualnie
+uznawanych za złośliwe.
+
+Pakiet zawiera silnik crowdsec, narzędzie zarządzające cscli oraz
+wtyczki powiadomień (email, file, http, slack, splunk, sentinel).
+Zawartość Huba (kolekcje, parsery, scenariusze) jest pobierana w
+trakcie działania poleceniem 'cscli hub update'.
+
+%package -n bash-completion-cscli
+Summary:	Bash completion for cscli command line
+Summary(pl.UTF-8):	Bashowe dopełnianie linii poleceń programu cscli
+Group:		Applications/Shells
+Requires:	%{name} = %{version}-%{release}
+Requires:	bash-completion >= 2.0
+BuildArch:	noarch
+
+%description -n bash-completion-cscli
+Bash completion for cscli command line.
+
+%description -n bash-completion-cscli -l pl.UTF-8
+Bashowe dopełnianie linii poleceń programu cscli.
+
+%package -n fish-completion-cscli
+Summary:	Fish completion for cscli command line
+Summary(pl.UTF-8):	Dopełnianie linii poleceń programu cscli dla powłoki fish
+Group:		Applications/Shells
+Requires:	%{name} = %{version}-%{release}
+Requires:	fish
+BuildArch:	noarch
+
+%description -n fish-completion-cscli
+Fish completion for cscli command line.
+
+%description -n fish-completion-cscli -l pl.UTF-8
+Dopełnianie linii poleceń programu cscli dla powłoki fish.
+
+%package -n zsh-completion-cscli
+Summary:	Zsh completion for cscli command line
+Summary(pl.UTF-8):	Dopełnianie linii poleceń programu cscli dla powłoki zsh
+Group:		Applications/Shells
+Requires:	%{name} = %{version}-%{release}
+Requires:	zsh
+BuildArch:	noarch
+
+%description -n zsh-completion-cscli
+Zsh completion for cscli command line.
+
+%description -n zsh-completion-cscli -l pl.UTF-8
+Dopełnianie linii poleceń programu cscli dla powłoki zsh.
+
+%prep
+%setup -q -a1
+
+%{__mkdir_p} .go-cache bin
+
+%build
+# same tag set as the upstream Makefile (re2 via C++ library, sqlite via cgo),
+# plus libsqlite3 to link the system library instead of the bundled amalgamation
+GO_TAGS="netgo,osusergo,expr_debug,nomsgpack,sqlite_omit_load_extension,libsqlite3,re2_cgo"
+LDFLAGS="-X github.com/crowdsecurity/go-cs-lib/version.Version=v%{version} \
+	-X github.com/crowdsecurity/go-cs-lib/version.Tag=%{release} \
+	-X github.com/crowdsecurity/crowdsec/pkg/cwversion.Codename=alphaga \
+	-X github.com/crowdsecurity/crowdsec/pkg/cwversion.Libre2=C++"
+
+%__go build -v -mod=vendor -buildmode=pie -trimpath -tags "$GO_TAGS" -ldflags "$LDFLAGS" -o bin/crowdsec ./cmd/crowdsec
+%__go build -v -mod=vendor -buildmode=pie -trimpath -tags "$GO_TAGS" -ldflags "$LDFLAGS" -o bin/cscli ./cmd/crowdsec-cli
+for p in email file http sentinel slack splunk; do
+	%__go build -v -mod=vendor -buildmode=pie -trimpath -tags "$GO_TAGS" -ldflags "$LDFLAGS" -o bin/notification-$p ./cmd/notification-$p
+done
+
+bin/cscli completion bash > bin/cscli.bash
+bin/cscli completion fish > bin/cscli.fish
+bin/cscli completion zsh > bin/_cscli
+
+%install
+rm -rf $RPM_BUILD_ROOT
+install -d $RPM_BUILD_ROOT{%{_bindir},%{_sbindir},%{plugindir},%{systemdunitdir}} \
+	$RPM_BUILD_ROOT/etc/{rc.d/init.d,cron.daily} \
+	$RPM_BUILD_ROOT%{_sysconfdir}/%{name}/{acquis.d,console,hub,notifications,patterns} \
+	$RPM_BUILD_ROOT{%{bash_compdir},%{fish_compdir},%{zsh_compdir}} \
+	$RPM_BUILD_ROOT/var/{lib/%{name}/data,log}
+
+install -p bin/crowdsec $RPM_BUILD_ROOT%{_sbindir}/crowdsec
+install -p bin/cscli $RPM_BUILD_ROOT%{_bindir}/cscli
+for p in email file http sentinel slack splunk; do
+	install -p bin/notification-$p $RPM_BUILD_ROOT%{plugindir}/notification-$p
+	cp -p cmd/notification-$p/$p.yaml $RPM_BUILD_ROOT%{_sysconfdir}/%{name}/notifications
+done
+
+cp -p config/config.yaml config/console.yaml config/profiles.yaml config/simulation.yaml \
+	$RPM_BUILD_ROOT%{_sysconfdir}/%{name}
+cp -p config/context.yaml $RPM_BUILD_ROOT%{_sysconfdir}/%{name}/console
+cp -p config/patterns/* $RPM_BUILD_ROOT%{_sysconfdir}/%{name}/patterns
+cp -p config/detect.yaml $RPM_BUILD_ROOT/var/lib/%{name}/data
+%{__sed} -i -e 's,/usr/local/lib/crowdsec/plugins/,%{plugindir}/,' \
+	$RPM_BUILD_ROOT%{_sysconfdir}/%{name}/config.yaml
+
+install -p %{SOURCE2} $RPM_BUILD_ROOT/etc/rc.d/init.d/%{name}
+install -p %{SOURCE3} $RPM_BUILD_ROOT/etc/cron.daily/%{name}
+install -p debian/hubupdate.sh $RPM_BUILD_ROOT%{_libexecdir}/%{name}/hubupdate.sh
+
+cp -p %{SOURCE4} debian/crowdsec-hubupdate.service $RPM_BUILD_ROOT%{systemdunitdir}
+cp -p %{SOURCE5} $RPM_BUILD_ROOT%{systemdunitdir}/crowdsec-hubupdate.timer
+
+# cscli refuses to run without this file; it stays empty until 'cscli capi register'
+:> $RPM_BUILD_ROOT%{_sysconfdir}/%{name}/online_api_credentials.yaml
+# %%ghost entries created at runtime by crowdsec/cscli
+:> $RPM_BUILD_ROOT%{_sysconfdir}/%{name}/acquis.yaml
+:> $RPM_BUILD_ROOT%{_sysconfdir}/%{name}/local_api_credentials.yaml
+:> $RPM_BUILD_ROOT%{_sysconfdir}/%{name}/hub/.index.json
+:> $RPM_BUILD_ROOT/var/lib/%{name}/data/crowdsec.db
+:> $RPM_BUILD_ROOT/var/log/crowdsec.log
+:> $RPM_BUILD_ROOT/var/log/crowdsec_api.log
+
+cp -p bin/cscli.bash $RPM_BUILD_ROOT%{bash_compdir}/cscli
+cp -p bin/cscli.fish $RPM_BUILD_ROOT%{fish_compdir}/cscli.fish
+cp -p bin/_cscli $RPM_BUILD_ROOT%{zsh_compdir}/_cscli
+
+%clean
+rm -rf $RPM_BUILD_ROOT
+
+%post
+/sbin/chkconfig --add %{name}
+%service %{name} restart
+%systemd_post %{name}.service %{name}-hubupdate.timer
+if [ "$1" = "1" ]; then
+%banner -e %{name} <<EOF
+crowdsec needs local API credentials and Hub content before it can start:
+  cscli machines add -a
+  cscli hub update
+  cscli collections install crowdsecurity/linux
+  cscli setup unattended            # or write /etc/crowdsec/acquis.d/*.yaml by hand
+Optionally join the community blocklist with: cscli capi register
+EOF
+fi
+
+%preun
+if [ "$1" = "0" ]; then
+	%service -q %{name} stop
+	/sbin/chkconfig --del %{name}
+fi
+%systemd_preun %{name}.service %{name}-hubupdate.timer
+
+%postun
+%systemd_reload
+
+%files
+%defattr(644,root,root,755)
+%doc LICENSE README.md SECURITY.md
+%attr(754,root,root) /etc/rc.d/init.d/%{name}
+%attr(755,root,root) /etc/cron.daily/%{name}
+%attr(755,root,root) %{_bindir}/cscli
+%attr(755,root,root) %{_sbindir}/crowdsec
+%dir %{_libexecdir}/%{name}
+%attr(755,root,root) %{_libexecdir}/%{name}/hubupdate.sh
+%dir %{plugindir}
+%attr(755,root,root) %{plugindir}/notification-*
+%{systemdunitdir}/%{name}.service
+%{systemdunitdir}/%{name}-hubupdate.service
+%{systemdunitdir}/%{name}-hubupdate.timer
+%dir %{_sysconfdir}/%{name}
+%dir %{_sysconfdir}/%{name}/acquis.d
+%dir %{_sysconfdir}/%{name}/console
+%dir %{_sysconfdir}/%{name}/hub
+%dir %{_sysconfdir}/%{name}/notifications
+%dir %{_sysconfdir}/%{name}/patterns
+%attr(600,root,root) %config(noreplace) %verify(not md5 mtime size) %{_sysconfdir}/%{name}/config.yaml
+%config(noreplace) %verify(not md5 mtime size) %{_sysconfdir}/%{name}/console.yaml
+%config(noreplace) %verify(not md5 mtime size) %{_sysconfdir}/%{name}/profiles.yaml
+%config(noreplace) %verify(not md5 mtime size) %{_sysconfdir}/%{name}/simulation.yaml
+%config(noreplace) %verify(not md5 mtime size) %{_sysconfdir}/%{name}/console/context.yaml
+%attr(600,root,root) %config(noreplace) %verify(not md5 mtime size) %{_sysconfdir}/%{name}/notifications/*.yaml
+%config(noreplace) %verify(not md5 mtime size) %{_sysconfdir}/%{name}/patterns/*
+%ghost %config(noreplace) %{_sysconfdir}/%{name}/acquis.yaml
+%ghost %attr(600,root,root) %{_sysconfdir}/%{name}/local_api_credentials.yaml
+%attr(600,root,root) %config(noreplace) %verify(not md5 mtime size) %{_sysconfdir}/%{name}/online_api_credentials.yaml
+%ghost %attr(600,root,root) %{_sysconfdir}/%{name}/hub/.index.json
+%dir /var/lib/%{name}
+%dir /var/lib/%{name}/data
+%attr(640,root,root) /var/lib/%{name}/data/detect.yaml
+%ghost %attr(600,root,root) /var/lib/%{name}/data/crowdsec.db
+%ghost %attr(600,root,root) /var/log/crowdsec.log
+%ghost %attr(600,root,root) /var/log/crowdsec_api.log
+
+%files -n bash-completion-cscli
+%defattr(644,root,root,755)
+%{bash_compdir}/cscli
+
+%files -n fish-completion-cscli
+%defattr(644,root,root,755)
+%{fish_compdir}/cscli.fish
+
+%files -n zsh-completion-cscli
+%defattr(644,root,root,755)
+%{zsh_compdir}/_cscli
diff --git a/crowdsec-hubupdate.timer b/crowdsec-hubupdate.timer
new file mode 100644
index 0000000..1104495
--- /dev/null
+++ b/crowdsec-hubupdate.timer
@@ -0,0 +1,10 @@
+[Unit]
+Description=Daily CrowdSec Hub update
+
+[Timer]
+OnCalendar=daily
+RandomizedDelaySec=1h
+Persistent=true
+
+[Install]
+WantedBy=timers.target
diff --git a/crowdsec.cron b/crowdsec.cron
new file mode 100755
index 0000000..f60122a
--- /dev/null
+++ b/crowdsec.cron
@@ -0,0 +1,18 @@
+#!/bin/sh
+# Daily CrowdSec Hub update for sysv init; under systemd the
+# crowdsec-hubupdate.timer does the same job.
+
+[ -d /run/systemd/system ] && exit 0
+test -x /usr/bin/cscli || exit 0
+
+# splay hub upgrade and crowdsec reload
+sleep "$(seq 1 300 | shuf -n 1)"
+
+/usr/bin/cscli --error hub update >/dev/null
+
+upgraded=$(/usr/bin/cscli --error hub upgrade)
+if [ -n "$upgraded" ]; then
+	/sbin/service crowdsec reload >/dev/null
+fi
+
+exit 0
diff --git a/crowdsec.init b/crowdsec.init
new file mode 100755
index 0000000..447cdf3
--- /dev/null
+++ b/crowdsec.init
@@ -0,0 +1,127 @@
+#!/bin/sh
+#
+# crowdsec	CrowdSec behaviour detection engine
+#
+# chkconfig:	345 20 08
+# description:	crowdsec parses logs, matches them against Hub scenarios \
+#		and serves decisions to bouncers over the local API.
+# processname:	crowdsec
+# config:	/etc/crowdsec/config.yaml
+# pidfile:	/var/run/crowdsec.pid
+
+# Source function library
+. /etc/rc.d/init.d/functions
+
+# Get network config
+. /etc/sysconfig/network
+
+SERVICE=crowdsec
+LOCKFILE=/var/lock/subsys/$SERVICE
+PIDFILE=/var/run/$SERVICE.pid
+CONFIG=/etc/crowdsec/config.yaml
+PROG=/usr/sbin/crowdsec
+
+# Check that networking is up
+if is_yes "${NETWORKING}"; then
+	if [ ! -f /var/lock/subsys/network -a "$1" != stop -a "$1" != status ]; then
+		msg_network_down "CrowdSec"
+		exit 1
+	fi
+else
+	exit 0
+fi
+
+configtest() {
+	$PROG -c "$CONFIG" -t -error
+}
+
+start() {
+	if [ -f "$LOCKFILE" ]; then
+		msg_already_running "CrowdSec"
+		return
+	fi
+	if ! configtest; then
+		msg_starting "CrowdSec"
+		fail
+		RETVAL=1
+		return
+	fi
+	msg_starting "CrowdSec"
+	# crowdsec runs in the foreground (systemd Type=notify); sysv has to
+	# background it and track the pid itself.
+	/sbin/start-stop-daemon --start --quiet --background \
+		--make-pidfile --pidfile "$PIDFILE" \
+		--exec $PROG -- -c "$CONFIG" && ok || fail
+	RETVAL=$?
+	[ $RETVAL -eq 0 ] && touch "$LOCKFILE"
+}
+
+stop() {
+	if [ ! -f "$LOCKFILE" ]; then
+		msg_not_running "CrowdSec"
+		return
+	fi
+	msg_stopping "CrowdSec"
+	killproc --pidfile "$PIDFILE" crowdsec
+	rm -f "$LOCKFILE" "$PIDFILE" >/dev/null 2>&1
+}
+
+reload() {
+	if [ ! -f "$LOCKFILE" ]; then
+		msg_not_running "CrowdSec"
+		RETVAL=7
+		return
+	fi
+	if ! configtest; then
+		msg_reloading "CrowdSec"
+		fail
+		RETVAL=1
+		return
+	fi
+	msg_reloading "CrowdSec"
+	killproc --pidfile "$PIDFILE" crowdsec -HUP
+	RETVAL=$?
+}
+
+condrestart() {
+	if [ -f "$LOCKFILE" ]; then
+		stop
+		start
+	else
+		msg_not_running "CrowdSec"
+		RETVAL=$1
+	fi
+}
+
+RETVAL=0
+case "$1" in
+  start)
+	start
+	;;
+  stop)
+	stop
+	;;
+  restart)
+	stop
+	start
+	;;
+  reload|force-reload)
+	reload
+	;;
+  try-restart)
+	condrestart 0
+	;;
+  configtest)
+	configtest
+	RETVAL=$?
+	;;
+  status)
+	status --pidfile "$PIDFILE" crowdsec
+	exit $?
+	;;
+  *)
+	msg_usage "$0 {start|stop|restart|reload|force-reload|try-restart|configtest|status}"
+	exit 3
+esac
+
+exit $RETVAL
diff --git a/crowdsec.service b/crowdsec.service
new file mode 100644
index 0000000..0d5321a
--- /dev/null
+++ b/crowdsec.service
@@ -0,0 +1,29 @@
+[Unit]
+Description=CrowdSec agent
+After=syslog.target network.target remote-fs.target nss-lookup.target
+
+[Service]
+Type=notify
+Environment=LC_ALL=C LANG=C
+ExecStartPre=/usr/sbin/crowdsec -c /etc/crowdsec/config.yaml -t -error
+ExecStart=/usr/sbin/crowdsec -c /etc/crowdsec/config.yaml
+ExecReload=/usr/sbin/crowdsec -c /etc/crowdsec/config.yaml -t -error
+ExecReload=/bin/kill -HUP $MAINPID
+Restart=always
+RestartSec=60
+
+# crowdsec runs as root to read arbitrary log files and to start notification
+# plugins under an unprivileged user; keep the sandboxing to what does not
+# restrict filesystem reads or capabilities
+ProtectHome=true
+PrivateDevices=true
+ProtectHostname=true
+ProtectClock=true
+ProtectKernelTunables=true
+ProtectKernelModules=true
+ProtectKernelLogs=true
+ProtectControlGroups=true
+RestrictRealtime=true
+
+[Install]
+WantedBy=multi-user.target
================================================================

---- gitweb:

http://git.pld-linux.org/gitweb.cgi/packages/crowdsec.git/commitdiff/26f3fd34c48e17307da03237372751bcb414e205



More information about the pld-cvs-commit mailing list