don't jail registry /v2 401 auth handshakes — unblocks CI push (#127) #179

Sammanfogat
supernaut sammanfogade 1 incheckning från fix/fail2ban-registry-v2 in i main 2026-07-20 21:20:57 +00:00
Ägare

Regression fix (self-inflicted by #127/#175). The bitborg-web deploy hung >15 min then failed (run 165) / got stuck (run 168) because the caddy-auth fail2ban jail was banning the CI runner mid-image-push.

Root cause: the OCI/Docker registry (Forgejo serves it under /v2/ on git.gitborg.se) answers an unauthenticated request with 401 by protocol to advertise the token endpoint — the client then retries with a bearer token. A single image push emits many /v2/ 401s; the jail (maxretry 10) counted them and banned the runner's egress IP → the push blocked until timeout. Confirmed against the live log: 16/16 recent 401s were on /v2/, 15 from one runner egress IP.

Fix: add an ignoreregex for 401s whose request URI is under /v2/. Real auth brute force (/user/login, /api, git-over-HTTPS Basic auth) still matches failregex and is jailed — verified with synthetic path tests.

Applied to prod (this PR captures it): filter reinstalled + fail2ban restarted (flushes stale bans). caddy-auth now shows 0 banned; sshd jail unaffected. Closes the deploy blockage.

Refs #127.

**Regression fix** (self-inflicted by #127/#175). The bitborg-web deploy hung >15 min then failed (run 165) / got stuck (run 168) because the `caddy-auth` fail2ban jail was **banning the CI runner mid-image-push**. **Root cause:** the OCI/Docker registry (Forgejo serves it under `/v2/` on `git.gitborg.se`) answers an unauthenticated request with **401 by protocol** to advertise the token endpoint — the client then retries with a bearer token. A single image push emits many `/v2/` 401s; the jail (maxretry 10) counted them and banned the runner's egress IP → the push blocked until timeout. Confirmed against the live log: 16/16 recent 401s were on `/v2/`, 15 from one runner egress IP. **Fix:** add an `ignoreregex` for 401s whose request URI is under `/v2/`. Real auth brute force (`/user/login`, `/api`, git-over-HTTPS Basic auth) still matches `failregex` and is jailed — verified with synthetic path tests. **Applied to prod** (this PR captures it): filter reinstalled + fail2ban restarted (flushes stale bans). `caddy-auth` now shows 0 banned; sshd jail unaffected. Closes the deploy blockage. Refs #127.
supernaut lade till 1 incheckning 2026-07-20 21:18:11 +00:00
fix(fail2ban): don't jail registry /v2 401 auth handshakes (#127)
Alla kontroller lyckades
ci / ci (pull_request) Successful in 1m25s
81e7f1b1b0
The OCI/Docker registry (Forgejo serves it under /v2/ on the same host) answers
an unauthenticated request with 401 by protocol to advertise the token endpoint;
the client then retries with a bearer token. A single image push emits many /v2
401s, which exceeded the caddy-auth jail's maxretry and banned the CI runner
mid-push — hanging the gitborg-web deploy (run 165 failed at ~15m; 168 stuck).

Add an ignoreregex for 401s whose request URI is under /v2/. Real auth brute
force (/user/login, /api, git-HTTPS) still hits failregex and is jailed.
Verified against the live log (16/16 /v2 401s ignored) + synthetic auth-path tests.
supernaut sammanfogade incheckning 316e7e9450 till main 2026-07-20 21:20:57 +00:00
supernaut tog bort grenen fix/fail2ban-registry-v2 2026-07-20 21:20:57 +00:00
Logga in för att delta i denna konversation.
Inga granskare
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra!179
Ingen beskrivning angiven.