don't jail registry /v2 401 auth handshakes — unblocks CI push (#127) #179
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!179
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "fix/fail2ban-registry-v2"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Regression fix (self-inflicted by #127/#175). The bitborg-web deploy hung >15 min then failed (run 165) / got stuck (run 168) because the
caddy-authfail2ban jail was banning the CI runner mid-image-push.Root cause: the OCI/Docker registry (Forgejo serves it under
/v2/ongit.gitborg.se) answers an unauthenticated request with 401 by protocol to advertise the token endpoint — the client then retries with a bearer token. A single image push emits many/v2/401s; the jail (maxretry 10) counted them and banned the runner's egress IP → the push blocked until timeout. Confirmed against the live log: 16/16 recent 401s were on/v2/, 15 from one runner egress IP.Fix: add an
ignoreregexfor 401s whose request URI is under/v2/. Real auth brute force (/user/login,/api, git-over-HTTPS Basic auth) still matchesfailregexand is jailed — verified with synthetic path tests.Applied to prod (this PR captures it): filter reinstalled + fail2ban restarted (flushes stale bans).
caddy-authnow shows 0 banned; sshd jail unaffected. Closes the deploy blockage.Refs #127.