{"repo":"shgew/cs-firewall-bouncer-docker","free":true,"listed":false,"github":"https://github.com/shgew/cs-firewall-bouncer-docker","clone":"git clone https://github.com/shgew/cs-firewall-bouncer-docker.git","description":"A dockerized version of https://github.com/crowdsecurity/cs-firewall-bouncer","language":"Shell","stars":38,"topics":["bouncer","crowdsec","docker","firewall","homelab","nftables","security","truenas","attacks-prevention","detection"],"license":"MIT","category":"deployment-docker-iac","readme_excerpt":"CrowdSec Firewall Bouncer Docker Docker image for CrowdSec Firewall Bouncer, based on Alpine. What this image does - Runs crowdsec-firewall-bouncer in a container. - Substitutes environment variables in /config/crowdsec-firewall-bouncer.yaml at startup. Tags Tag Description ----- ------------- latest Newest stable release stable Same as latest rc Newest release overall (including release candidates; equals the stable image when no newer RC exists) vX.Y.Z Immutable stable version vX.Y.Z-rcN Immutable release candidate vX.Y.Z-patchN Image-only rebuild of vX.Y.Z (git tag vX.Y.Z+patchN ) latest never points at a release candidate. When one sync moves both channels to different versions it creates two releases, each publishing in its own run, so rc and stable can briefly disagree. Runtime requirements - network mode: host - cap add: [NET ADMIN, NET RAW] - Config file mounted at /config/crowdsec-firewall-bouncer.yaml Docker Compose Configuration Start from the upstream example config: https://github.com/crowdsecurity/cs-firewall-bouncer/blob/main/config/crowdsec-firewall-bouncer.yaml At startup, the entrypoint runs envsubst (GNU gettext) on the config file. Placeholders like ${API KEY} are replaced with values from container environment variables. All ${VAR} references are substituted; undefined variables become empty strings. Example: - Config: api key: ${API KEY} - Container env: API KEY=abc123 - Runtime config: api key: abc123 Release flow A daily sync reads the upstream release","default_branch":null,"files":null,"tree":[],"storefront":"/r/shgew","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/shgew/cs-firewall-bouncer-docker/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}