fix(proxy): exclude git-over-HTTPS 401s from traefik fail2ban jail

Git smart-HTTP always fires an unauthenticated request first, gets a
401 challenge, then retries with credentials. On a private repo, ~10
git operations in 5 minutes hit maxretry and ban the legitimate
client for an hour. Excludes 401s on info/refs, git-upload-pack and
git-receive-pack while leaving other 401 sources (UI, API) covered.

Closes #17
This commit is contained in:
Damien
2026-07-31 17:15:04 +02:00
parent 9927e4dec1
commit fe284d8a38
+5 -1
View File
@@ -158,7 +158,11 @@ main() {
# Two patterns cover both possible field orderings in the JSON. # Two patterns cover both possible field orderings in the JSON.
failregex = ^.*"ClientHost":"<HOST>".*"DownstreamStatus":(401|403|429|5[0-9]{2}) failregex = ^.*"ClientHost":"<HOST>".*"DownstreamStatus":(401|403|429|5[0-9]{2})
^.*"DownstreamStatus":(401|403|429|5[0-9]{2}).*"ClientHost":"<HOST>" ^.*"DownstreamStatus":(401|403|429|5[0-9]{2}).*"ClientHost":"<HOST>"
ignoreregex = # Git smart-HTTP always does an unauthenticated request first, gets a 401
# WWW-Authenticate challenge, then retries with credentials. That first 401
# is protocol, not abuse — without this exclusion a handful of git
# clone/fetch/push in a few minutes bans the client on a private repo.
ignoreregex = ^.*"RequestPath":"[^"]*/(info/refs|git-upload-pack|git-receive-pack)[^"]*".*"DownstreamStatus":401
EOF EOF
sudo tee /etc/fail2ban/jail.d/traefik.conf > /dev/null << 'EOF' sudo tee /etc/fail2ban/jail.d/traefik.conf > /dev/null << 'EOF'