- Pocket-ID: ENCRYPTION_KEY contains $ — Komodo .env interpolation eats it. Inline with $$ YAML escape (value already in git history from master.yaml; rotate later). - photon: image dropped uv; use image default CMD, strip stale PATH/JAVA. - glances: PYTHON_VERSION must be 3.14 to match image venv.
30 lines
1.1 KiB
Bash
Executable File
30 lines
1.1 KiB
Bash
Executable File
#!/bin/bash
|
|
# Sync CrowdSec allowlist "home_ddns" with the current A record of thuis.arnoutvw.nl.
|
|
# Install: /usr/local/bin/crowdsec-home-allowlist.sh (chmod 755) on pangolin.arnoutvw.nl
|
|
# Cron: echo "*/5 * * * * root /usr/local/bin/crowdsec-home-allowlist.sh" > /etc/cron.d/crowdsec-home-allowlist
|
|
set -euo pipefail
|
|
HOST=thuis.arnoutvw.nl
|
|
LIST=home_ddns
|
|
CS="docker exec crowdsec cscli"
|
|
|
|
want=$(dig +short A "$HOST" @1.1.1.1 | grep -E '^[0-9.]+$' | sort -u || true)
|
|
if [ -z "$want" ]; then
|
|
logger -t crowdsec-home-allowlist "no A record for $HOST, keeping current allowlist"
|
|
exit 0
|
|
fi
|
|
have=$($CS allowlists inspect "$LIST" -o json \
|
|
| python3 -c 'import sys,json; [print(i["value"]) for i in (json.load(sys.stdin).get("items") or [])]' | sort -u)
|
|
|
|
for ip in $want; do
|
|
if ! grep -qxF "$ip" <<<"$have"; then
|
|
$CS allowlists add "$LIST" "$ip" -d "$HOST" >/dev/null
|
|
logger -t crowdsec-home-allowlist "added $ip"
|
|
fi
|
|
done
|
|
for ip in $have; do
|
|
if ! grep -qxF "$ip" <<<"$want"; then
|
|
$CS allowlists remove "$LIST" "$ip" >/dev/null
|
|
logger -t crowdsec-home-allowlist "removed $ip"
|
|
fi
|
|
done
|