No fail2ban jail for git-over-HTTPS / API brute force (only sshd is jailed) #127
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra#127
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "%!s()"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Severity: MEDIUM — pre-onboarding infra audit (2026-07-19).
ansible/roles/base/templates/jail.local.j2has only an[sshd]jail. HTTP Basic auth stays enabled (ENABLE_INTERNAL_SIGNIN=falseonly removes the web form), so git-over-HTTPS and API token auth can be brute-forced with no host-layer lockout — nothing tails Caddy/Forgejo logs for auth abuse.Ask
Add a fail2ban jail on the Caddy access log (or Forgejo auth log) for repeated 401s, prioritising auth/signup/API endpoints. Effort S–M. (Related to edge rate limiting #48.)
Follow-up: the jail (shipped in #175) caused a CI regression — it banned the ephemeral runner egress on the OCI registry
/v2401 auth handshake during image push (the registry 401s to advertise its token endpoint), which hung/failed the bitborg-web deploys (runs #165/#168) and blocked runners from even connecting.Fixed in PR #179: added
ignoreregexfor 401s under/v2/so registry handshakes are not counted, while real auth brute force (/user/login,/api, git-HTTPS Basic) is still jailed (verified against the live log + synthetic tests). Also had tofail2ban-client unbanthe stale runner-egress IP (158.174.210.225): fail2ban re-applies DB-stored bans across a restart withinbantime, so the pre-fix ban survived the#179reload and kept blocking runners until explicitly cleared.Verified 2026-07-21: caddy-auth jailing real 401s, ignoring
/v2; runner egress unbanned; CI run 173 + deploy run 174 both green with no re-ban. Learning: fail2ban bans persist across restart — clearing a bad ban needs an explicitunban, not just a filter fix + reload.