Files
compose-files/pangolin/crowdsec-home-allowlist.sh
Arnout van Westen ec6a723776 fix: pocketid encryption key inline, photon image layout, glances py 3.14
- Pocket-ID: ENCRYPTION_KEY contains $ — Komodo .env interpolation
  eats it. Inline with $$ YAML escape (value already in git history
  from master.yaml; rotate later).
- photon: image dropped uv; use image default CMD, strip stale PATH/JAVA.
- glances: PYTHON_VERSION must be 3.14 to match image venv.
2026-10-02 16:21:53 +02:00

30 lines
1.1 KiB
Bash
Executable File

#!/bin/bash
# Sync CrowdSec allowlist "home_ddns" with the current A record of thuis.arnoutvw.nl.
# Install: /usr/local/bin/crowdsec-home-allowlist.sh (chmod 755) on pangolin.arnoutvw.nl
# Cron: echo "*/5 * * * * root /usr/local/bin/crowdsec-home-allowlist.sh" > /etc/cron.d/crowdsec-home-allowlist
set -euo pipefail
HOST=thuis.arnoutvw.nl
LIST=home_ddns
CS="docker exec crowdsec cscli"
want=$(dig +short A "$HOST" @1.1.1.1 | grep -E '^[0-9.]+$' | sort -u || true)
if [ -z "$want" ]; then
logger -t crowdsec-home-allowlist "no A record for $HOST, keeping current allowlist"
exit 0
fi
have=$($CS allowlists inspect "$LIST" -o json \
| python3 -c 'import sys,json; [print(i["value"]) for i in (json.load(sys.stdin).get("items") or [])]' | sort -u)
for ip in $want; do
if ! grep -qxF "$ip" <<<"$have"; then
$CS allowlists add "$LIST" "$ip" -d "$HOST" >/dev/null
logger -t crowdsec-home-allowlist "added $ip"
fi
done
for ip in $have; do
if ! grep -qxF "$ip" <<<"$want"; then
$CS allowlists remove "$LIST" "$ip" >/dev/null
logger -t crowdsec-home-allowlist "removed $ip"
fi
done