Skip to content
Snippets Groups Projects
Verified Commit cf0bef90 authored by Sheogorath's avatar Sheogorath :european_castle:
Browse files

removal(crowdsec): Dropping crowdsec

After some testing and fiddling around, I don't think it's worth the
hassle. Not only was ingress-nginx much less stable since integrating
the crowdsec bouncer plugin, but also just providing some questionable
log parsers etc, mainly focusing on bruteforce attacks for passwords,
which is useless when everything goes to SSO anyway.

Finally there were some other technical faux pas, like hardcoded
passwords on the integrated dashboard (which is also mostly useless),
expired GPG keys on the Fedora repository and finally a lack of bouncer
modules on current Fedora releases, depsite the docs claiming otherwise.
And given the issues date back to march, it doesn't seem to be a
something that will be resolved any time soon.

I guess my biggest critique is that the whole "fail2ban of the modern
area" limits itself to IP addresses only. No additional metadata to
block or mitigate attacks or identify attackers. Relying on IP addresses
only in 2023 is not on time. The whole being distributed with the lapi
server, is nice, but not enough to make this acceptable.
parent a90f5115
Loading
Showing
with 3 additions and 3992 deletions
Loading
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment