Skip to content

Conversation

@MichaIng
Copy link
Owner

I almost went crazy with the Gitea systemd Fail2Ban integration: What journalctl -u gitea does not show, but only debugging like

fail2ban-regex --print-all-missed "systemd-journal" gitea
fail2ban-regex -l heavydebug "systemd-journal" gitea

reveals: Gitea logs color codes to the console and while journalctl does not show them, they are actually there, and Fail2Ban parses them. Hence the extended regex compared to when using file logging:

failregex = Failed authentication attempt for \x1b\[1m.+\x1b\[0m from \x1b\[1m<HOST>:\d+\x1b\[0m:

Sadly Gogs does not log failed login attempts at all, hence no Fail2Ban integration possible.

@MichaIng MichaIng added correction Content, spelling or syntax corrections extension Extend/complement existing pages Next DietPi release Changes related to changes made for the upcoming DietPi release. labels Dec 10, 2021
@MichaIng MichaIng linked an issue Dec 10, 2021 that may be closed by this pull request
2 tasks
@MichaIng MichaIng merged commit d2058c2 into dev Dec 10, 2021
@MichaIng MichaIng deleted the MichaIng-Gitea-Gogs branch December 10, 2021 15:07
@YeFei572
Copy link

YeFei572 commented Jan 6, 2022

Maybe we can use docker logs to get the fail logger?

Jan  6 02:05:54 sshd[419]: Received disconnect from 179.43.188.158 port 39692:11: Normal Shutdown, Thank you for playing [preauth]
Jan  6 02:05:54 sshd[419]: Disconnected from invalid user lfm 179.43.188.158 port 39692 [preauth]
Jan  6 02:05:58 sshd[421]: Invalid user wb from 179.43.188.158 port 37056
Jan  6 02:05:58 sshd[421]: Received disconnect from 179.43.188.158 port 37056:11: Normal Shutdown, Thank you for playing [preauth]
Jan  6 02:05:58 sshd[421]: Disconnected from invalid user wb 179.43.188.158 port 37056 [preauth]
Jan  6 02:06:02 sshd[423]: Invalid user zlx from 179.43.188.158 port 34432
Jan  6 02:06:02 sshd[423]: Received disconnect from 179.43.188.158 port 34432:11: Normal Shutdown, Thank you for playing [preauth]
Jan  6 02:06:02 sshd[423]: Disconnected from invalid user zlx 179.43.188.158 port 34432 [preauth]
Jan  6 02:06:06 sshd[425]: Invalid user liqi from 179.43.188.158 port 60036
Jan  6 02:06:06 sshd[425]: Received disconnect from 179.43.188.158 port 60036:11: Normal Shutdown, Thank you for playing [preauth]
Jan  6 02:06:06 sshd[425]: Disconnected from invalid user liqi 179.43.188.158 port 60036 [preauth]
Jan  6 02:06:10 sshd[427]: Invalid user xcc from 179.43.188.158 port 57402
Jan  6 02:06:10 sshd[427]: Received disconnect from 179.43.188.158 port 57402:11: Normal Shutdown, Thank you for playing [preauth]
Jan  6 02:06:10 sshd[427]: Disconnected from invalid user xcc 179.43.188.158 port 57402 [preauth]
Jan  6 02:06:14 sshd[429]: Invalid user fn from 179.43.188.158 port 54778
Jan  6 02:06:14 sshd[429]: Received disconnect from 179.43.188.158 port 54778:11: Normal Shutdown, Thank you for playing [preauth]
Jan  6 02:06:14 sshd[429]: Disconnected from invalid user fn 179.43.188.158 port 54778 [preauth]

@YeFei572
Copy link

YeFei572 commented Jan 6, 2022

I mean for gogs!

@MichaIng
Copy link
Owner Author

MichaIng commented Jan 6, 2022

Not sure what you mean. Our Gogs implementation does not use Docker, logs can be reviewed via:

journalctl -u gogs

and plain text files in

/var/log/gogs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

correction Content, spelling or syntax corrections extension Extend/complement existing pages Next DietPi release Changes related to changes made for the upcoming DietPi release.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Gogs/Gitea | Update docs

3 participants