{"id":20318000,"url":"https://github.com/crowdsecurity/cs-cloud-firewall-bouncer","last_synced_at":"2025-07-12T04:35:33.653Z","repository":{"id":55482394,"uuid":"323207302","full_name":"crowdsecurity/cs-cloud-firewall-bouncer","owner":"crowdsecurity","description":"Crowdsec Cloud Firewall Bouncer","archived":false,"fork":false,"pushed_at":"2023-12-27T14:05:10.000Z","size":158,"stargazers_count":15,"open_issues_count":10,"forks_count":4,"subscribers_count":5,"default_branch":"main","last_synced_at":"2025-04-11T18:02:55.372Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"","language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/crowdsecurity.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2020-12-21T02:08:19.000Z","updated_at":"2023-12-21T17:30:38.000Z","dependencies_parsed_at":"2024-06-19T05:16:07.004Z","dependency_job_id":"349d1f24-bff5-48f8-a669-242b0790f165","html_url":"https://github.com/crowdsecurity/cs-cloud-firewall-bouncer","commit_stats":{"total_commits":26,"total_committers":2,"mean_commits":13.0,"dds":"0.46153846153846156","last_synced_commit":"5bc2bd7577e47403dcc163c0b20cdada644a6d9f"},"previous_names":["fallard84/cs-cloud-firewall-bouncer"],"tags_count":6,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/crowdsecurity%2Fcs-cloud-firewall-bouncer","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/crowdsecurity%2Fcs-cloud-firewall-bouncer/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/crowdsecurity%2Fcs-cloud-firewall-bouncer/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/crowdsecurity%2Fcs-cloud-firewall-bouncer/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/crowdsecurity","download_url":"https://codeload.github.com/crowdsecurity/cs-cloud-firewall-bouncer/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":248456374,"owners_count":21106602,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-11-14T18:37:47.209Z","updated_at":"2025-04-11T18:07:18.757Z","avatar_url":"https://github.com/crowdsecurity.png","language":"Go","funding_links":[],"categories":[],"sub_categories":[],"readme":"\u003cp align=\"center\"\u003e\n\u003ca href=\"https://github.com/crowdsecurity/crowdsec\"\u003e\u003cimg src=\"https://github.com/crowdsecurity/crowdsec/raw/master/docs/assets/images/crowdsec_logo.png\" alt=\"CrowdSec\" title=\"CrowdSec\" width=\"400\" height=\"240\" style=\"max-width:100%;\"\u003e\u003c/a\u003e\n\u003c/p\u003e\n\u003cp align=\"center\"\u003e\n\u003ca href='https://github.com/fallard84/cs-cloud-firewall-bouncer/actions?query=workflow%3Abuild'\u003e\u003cimg src='https://github.com/fallard84/cs-cloud-firewall-bouncer/workflows/build/badge.svg' alt='Build Status' /\u003e\u003c/a\u003e\n\u003ca href='https://github.com/fallard84/cs-cloud-firewall-bouncer/actions?query=branch%3Amain+workflow%3Atests'\u003e\u003cimg src='https://github.com/fallard84/cs-cloud-firewall-bouncer/workflows/tests/badge.svg?branch=main' alt='Tests Status' /\u003e\u003c/a\u003e\n\u003ca href='https://coveralls.io/github/fallard84/cs-cloud-firewall-bouncer?branch=main'\u003e\u003cimg src='https://coveralls.io/repos/github/fallard84/cs-cloud-firewall-bouncer/badge.svg?branch=main' alt='Coverage Status' /\u003e\u003c/a\u003e\n\u003ca href='https://goreportcard.com/report/github.com/fallard84/cs-cloud-firewall-bouncer'\u003e\u003cimg src='https://goreportcard.com/badge/github.com/fallard84/cs-cloud-firewall-bouncer' alt='Go Report Card' /\u003e\u003c/a\u003e\n\u003ca href='https://opensource.org/licenses/MIT'\u003e\u003cimg src='https://img.shields.io/badge/License-MIT-yellow.svg' alt='License: MIT' /\u003e\u003c/a\u003e\n\n\u003c/p\u003e\n\n\u003cp align=\"center\"\u003e\n\u0026#x1F4DA; \u003ca href=\"#installation-as-a-systemd-service\"\u003eDocumentation\u003c/a\u003e\n\u0026#x1F4A0; \u003ca href=\"https://hub.crowdsec.net\"\u003eHub\u003c/a\u003e\n\u0026#128172; \u003ca href=\"https://discourse.crowdsec.net\"\u003eDiscourse \u003c/a\u003e\n\u003c/p\u003e\n\n# CrowdSec Cloud Firewall Bouncer\n\nBouncer for cloud firewalls to use with [Crowdsec](https://github.com/crowdsecurity/crowdsec).\n\n:warning: This is not an official Crowdsec bouncer.\n\nThe Cloud Firewall Bouncer will periodically fetch new and expired/removed decisions from the CrowdSec Local API and update cloud firewall rules accordingly.\n\nSupported cloud providers:\n\n- Google Cloud Platform (GCP) Network Firewall:heavy_check_mark:\n- Google Cloud Platform (GCP) Cloud Armor:heavy_check_mark:\n- Amazon Web Services (AWS) Network Firewall :heavy_check_mark:\n\n## Usage with example\n\nA complete step-by-step example of using the bouncer docker image with the GCP provider is available [here](docs/example-gcp.md).\n\n## Using Docker\n\nYou can run this bouncer using the [docker image](https://hub.docker.com/r/fallard/cs-cloud-firewall-bouncer).\n\nYou will need to create the configuration file and mount it on the docker container. By default, the bouncer will look for the config at `/etc/crowdsec/config.d/config.yaml` but this can be overridden with the `CONFIG_PATH` environment variable.\n\n## Installation (as a systemd service)\n\n### With installer\n\nFirst, download the latest [`cs-cloud-firewall-bouncer` release](https://github.com/fallard84/cs-cloud-firewall-bouncer/releases).\n\n```sh\n$ tar xzvf cs-cloud-firewall-bouncer.tgz\n$ sudo ./install.sh\n```\n\n### From source\n\nRun the following commands:\n\n```bash\ngit clone https://github.com/fallard84/cs-cloud-firewall-bouncer.git\ncd cs-cloud-firewall-bouncer/\nmake release\ntar xzvf cs-cloud-firewall-bouncer.tgz\ncd cs-cloud-firewall-bouncer-v*/\nsudo ./install.sh\n```\n\n### Start\n\nIf your bouncer run on the same machine as your crowdsec local API, you can start the service directly since the `install.sh` took care of the configuration.\n\n```sh\nsudo systemctl start cs-cloud-firewall-bouncer\n```\n\n### Upgrade\n\nIf you already have `cs-cloud-firewall-bouncer` installed as a service, please download the [latest release](https://github.com/fallard84/cs-cloud-firewall-bouncer/releases) and run the following commands to upgrade it:\n\n```bash\ntar xzvf cs-cloud-firewall-bouncer.tgz\ncd cs-cloud-firewall-bouncer-v*/\nsudo ./upgrade.sh\n```\n\n## Configuration\n\nBefore starting the `cs-cloud-firewall-bouncer` service, please edit the configuration to add your cloud provider configuration, as well as the crowdsec local API url and key.\nThe default configuration file is located under : `/etc/crowdsec/cs-cloud-firewall-bouncer/`\n\n```sh\n$ vim /etc/crowdsec/cs-cloud-firewall-bouncer/cs-cloud-firewall-bouncer.yaml\n```\n\n```yaml\ncloud_providers: # 1 or more provider needs to be specified\n  gcp:\n    project_id: gcp-project-id # optional if using application default credentials, will override project id of the application default credentials\n    network: default # mandatory. This is the VPC network where the firewall rules will be created\n    priority: 0 # optional, defaults to 0 (highest priority). Additional rules will be incremented by 1.\n    max_rules: 10 # optional, defaults to 10. This is the maximum number of rules to create. One GCP network firewall rule can contain at most 256 source ranges. Using the default of 10 means 2560 source ranges at most can be created. A GCP project has a default quota of 100 rules across all VPC networks. See https://cloud.google.com/vpc/docs/quota for more info.\n  aws:\n    region: us-east-1 # mandatory\n    firewall_policy: policy-name # mandatory, this is the firewall policy which will contain the rule group. The firewall policy must exist.\n    capacity: 1000 # optional, defaults to 1000. This is the capacity of the stateless rule group that the bouncer will create. A capacity of 1000 signify that the rule will contain at most 1000 source ranges. AWS has a default quota of 10,000 stateless capacity per account per region. See https://docs.aws.amazon.com/network-firewall/latest/developerguide/quotas.html for more info. This capacity is only used when the rule is being created and will not be updated afterwards.\n    priority: 1 # optional, defaults to 1 (highest priority). This is the priority of the rule group in the firewall policy.\n  cloudarmor:\n    project_id: gcp-project-id # optional if using application default credentials, will override project id of the application\n    policy: test-policy # mandatory, this is the cloud armor policy which will contain the rules. The cloud armor policy must exist.\n    priority: 0 # optional, defaults to 0 (highest priority). Additional rules will be incremented by 1.\n    max_rules: 100 # optional, defaults to 100. This is the maximum number of rules to create. One cloud armor rule can contain at most 10 source ranges. A GCP project has a default quota of 200 rules across all security policies. Using the default of 100 means 1000 source ranges at most can be created. See https://cloud.google.com/armor/quotas for more info.\nrule_name_prefix: crowdsec # mandatory, this is the prefix for the firewall rule name(s) to create/update\nupdate_frequency: 10s\ndaemonize: true\nlog_mode: stdout\nlog_dir: log/\nlog_level: info\napi_url: \u003cAPI_URL\u003e # when install, default is \"localhost:8080\"\napi_key: \u003cAPI_KEY\u003e # Add your API key generated with `cscli bouncers add --name \u003cbouncer_name\u003e`\n```\n\n### Rule name prefix requirements\n\nThe rule name prefix be 1-44 characters long and match the regular expression `^(?:[a-z](?:[-a-z0-9]{0,43})?)\\$`. The first character\nmust be a lowercase letter, and all following characters must be a dash, lowercase letter, or\ndigit. The name cannot contain two consecutive dash ('-') characters.\n\n## Authentication\n\n### GCP\n\nAuthentication to GCP is done through [Application Default Credentials](https://cloud.google.com/docs/authentication/production). If using a service account, the GCP project ID will be automatically determined (using the project ID of the service account) and does not have to be specified in the configuration. If the service account resides in a different project than the VPC network/Cloud Armor policy, the GCP project ID must be overridden in the configuration.\n\n#### Network Firewall\n\nThe service account will need the following permissions:\n\n- compute.firewalls.create\n- compute.firewalls.delete\n- compute.firewalls.get\n- compute.firewalls.list\n- compute.firewalls.update\n- compute.networks.updatePolicy\n\n#### Cloud Armor\n\nThe service account will need the following permissions:\n\n- compute.securityPolicies.get\n- compute.securityPolicies.update\n\nThe managed role `roles/compute.securityAdmin` already provides these permissions.\n\n### AWS\n\nAuthentication to AWS is done through the [default credential provider chain](https://docs.aws.amazon.com/sdk-for-go/api/aws/defaults/#CredChain).\n\nThe user account will need the following permissions:\n\n- ListFirewallPolicies\n- ListRuleGroups\n- DescribeFirewallPolicy\n- DescribeRuleGroup\n- CreateRuleGroup\n- DeleteRuleGroup\n- UpdateFirewallPolicy\n- UpdateRuleGroup\n\nThe managed role `NetworkFirewallManager` already provides these permissions.\n\n## Todo\n\n- Add Azure as a provider\n- Add AWS WAF as a provider\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fcrowdsecurity%2Fcs-cloud-firewall-bouncer","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fcrowdsecurity%2Fcs-cloud-firewall-bouncer","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fcrowdsecurity%2Fcs-cloud-firewall-bouncer/lists"}