Production fail2ban with PJSIP jails and persistent state

FeatureKlusterServices
Shipped
April 25, 2026 at 3:45 PM UTC
Author
Kamo
Commit
e6d53d9

- Add fail2ban-configmap.yaml with [asterisk] and [freepbx-web] jails, incremental ban escalation (1h→24h→30d ceiling), LAN ignoreip, and a custom asterisk-security.conf filter targeting PJSIP SecurityEvent records - Mount fail2ban-config ConfigMap and hostPath /var/lib/pbx/fail2ban (ban state persists across pod restarts) in both k1m1 and k2m1 deployments - Wire configs in startup.sh before fail2ban-client start on both nodes

All changes

Like what you see shipping?

Every one of these updates lands in your workspace automatically. Start free and watch it grow week after week.

Start Free ForeverView Pricing