No fail2ban jail for git-over-HTTPS / API brute force (only sshd is jailed) #127

Stängd
öppnade 2026-07-19 06:58:03 +00:00 av supernaut · 1 kommentar
Ägare

Severity: MEDIUM — pre-onboarding infra audit (2026-07-19).

ansible/roles/base/templates/jail.local.j2 has only an [sshd] jail. HTTP Basic auth stays enabled (ENABLE_INTERNAL_SIGNIN=false only removes the web form), so git-over-HTTPS and API token auth can be brute-forced with no host-layer lockout — nothing tails Caddy/Forgejo logs for auth abuse.

Ask

Add a fail2ban jail on the Caddy access log (or Forgejo auth log) for repeated 401s, prioritising auth/signup/API endpoints. Effort S–M. (Related to edge rate limiting #48.)

**Severity: MEDIUM** — pre-onboarding infra audit (2026-07-19). `ansible/roles/base/templates/jail.local.j2` has only an `[sshd]` jail. HTTP Basic auth stays enabled (`ENABLE_INTERNAL_SIGNIN=false` only removes the *web form*), so git-over-HTTPS and API token auth can be brute-forced with **no host-layer lockout** — nothing tails Caddy/Forgejo logs for auth abuse. ### Ask Add a fail2ban jail on the Caddy access log (or Forgejo auth log) for repeated 401s, prioritising auth/signup/API endpoints. Effort S–M. (Related to edge rate limiting #48.)
Upphovsperson
Ägare

Follow-up: the jail (shipped in #175) caused a CI regression — it banned the ephemeral runner egress on the OCI registry /v2 401 auth handshake during image push (the registry 401s to advertise its token endpoint), which hung/failed the bitborg-web deploys (runs #165/#168) and blocked runners from even connecting.

Fixed in PR #179: added ignoreregex for 401s under /v2/ so registry handshakes are not counted, while real auth brute force (/user/login, /api, git-HTTPS Basic) is still jailed (verified against the live log + synthetic tests). Also had to fail2ban-client unban the stale runner-egress IP (158.174.210.225): fail2ban re-applies DB-stored bans across a restart within bantime, so the pre-fix ban survived the #179 reload and kept blocking runners until explicitly cleared.

Verified 2026-07-21: caddy-auth jailing real 401s, ignoring /v2; runner egress unbanned; CI run 173 + deploy run 174 both green with no re-ban. Learning: fail2ban bans persist across restart — clearing a bad ban needs an explicit unban, not just a filter fix + reload.

Follow-up: the jail (shipped in #175) caused a **CI regression** — it banned the ephemeral runner egress on the OCI registry `/v2` **401 auth handshake** during image push (the registry 401s to advertise its token endpoint), which hung/failed the bitborg-web deploys (runs #165/#168) and blocked runners from even connecting. Fixed in **PR #179**: added `ignoreregex` for 401s under `/v2/` so registry handshakes are not counted, while real auth brute force (`/user/login`, `/api`, git-HTTPS Basic) is still jailed (verified against the live log + synthetic tests). Also had to **`fail2ban-client unban` the stale runner-egress IP** (158.174.210.225): fail2ban re-applies DB-stored bans across a restart within `bantime`, so the pre-fix ban survived the `#179` reload and kept blocking runners until explicitly cleared. Verified 2026-07-21: caddy-auth jailing real 401s, ignoring `/v2`; runner egress unbanned; CI run 173 + deploy run 174 both green with no re-ban. **Learning:** fail2ban bans persist across restart — clearing a bad ban needs an explicit `unban`, not just a filter fix + reload.
Logga in för att delta i denna konversation.
Ingen milstolpe
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra#127
Ingen beskrivning angiven.