Configurations anti-bots
Utiliser les fonctionnalités de GitLab
Les limites ne sont pas activées par défaut
Il est possible de définir des limites sur le nombre de connexions authentifiées ou non authentifiées à GitLab, directement dans la console d’administration.
Ces limites sont désactivées par défaut. Il est conseillé de les activer.
Config iocaine pour gitlab
Contribué par Mathrice.
Config fail2ban
Contribuée par Remy Dernat
Fichier /etc/fail2ban/filter.d/gitlab-llm-bots.conf:
[Definition]
failregex = <HOST> -.* "GET .*" 403.* ".*(AmazonBuyForMe|Amzn-SearchBot|Amzn-User|Anomura|ApifyBot|ApifyWebsiteContentCrawler|Aranet-SearchBot|AzureAI-SearchBot|Bravebot|BuddyBot|Channel3Bot|ChatGLM-Spider|Cloudflare-AutoRAG|Crawl4AI|DeepSeekBot|ExaBot|Google-Agent|Google-Firebase|Google-NotebookLM|IbouBot|KlaviyoAIBot|KunatoCrawler|LAIONDownloader|LCC|LingueeBot|LinkupBot|Manus-User|NotebookLM|Poggio-Citations|ShapBot|Spider|TavilyBot|TerraCotta|TwinAgent|WRTNBot|ZanistaBot|amazon-kendra|atlassian-bot|iAskBot|imageSpider|laion-huggingface-processor|meta-webindexer|webzio-extended|Grok|DeepSeekBot|OAI-AdsBot|Microsoft-Copilot|Googlebot-Genie|Databricks-Agent|GPTBot|ChatGPT-User|AppleBot-Extended|ClaudeBot|Claude-SearchBot|PerplexityBot|Perplexity-User|Google-Extended|OAI-SearchBot|AmazonBot|Meta-ExternalAgent|Bytespider|cohere-ai|DuckAssistBot|FacebookBot|Gemini-User|MistralAI-User|YouBot|CCBot).*"
# Alternative si le code statut n'est pas toujours présent ou si vous voulez juste capturer l'user-agent quel que soit le code
# Note: On utilise <HOST> au début pour capturer l'IP, et on cherche la chaîne dans le User-Agent (généralement après le code HTTP ou à la fin)
# Regex optimisée pour le format standard Nginx (Host - UserAgent [Date] "Request" Status "Referrer")
^<HOST> .+ ".*" .* ".*".*(AmazonBuyForMe|Amzn-SearchBot|Amzn-User|Anomura|ApifyBot|ApifyWebsiteContentCrawler|Aranet-SearchBot|AzureAI-SearchBot|Bravebot|BuddyBot|Channel3Bot|ChatGLM-Spider|Cloudflare-AutoRAG|Crawl4AI|DeepSeekBot|ExaBot|Google-Agent|Google-Firebase|Google-NotebookLM|IbouBot|KlaviyoAIBot|KunatoCrawler|LAIONDownloader|LCC|LingueeBot|LinkupBot|Manus-User|NotebookLM|Poggio-Citations|ShapBot|Spider|TavilyBot|TerraCotta|TwinAgent|WRTNBot|ZanistaBot|amazon-kendra|atlassian-bot|iAskBot|imageSpider|laion-huggingface-processor|meta-webindexer|webzio-extended|Grok|DeepSeekBot|OAI-AdsBot|Microsoft-Copilot|Googlebot-Genie|Databricks-Agent|GPTBot|ChatGPT-User|AppleBot-Extended|ClaudeBot|Claude-SearchBot|PerplexityBot|Perplexity-User|Google-Extended|OAI-SearchBot|AmazonBot|Meta-ExternalAgent|Bytespider|cohere-ai|DuckAssistBot|FacebookBot|Gemini-User|MistralAI-User|YouBot|CCBot).*$
ignoreregex =
Dans paths-common.conf rajouter :
gitlab_nginx_error_log = /var/log/gitlab/nginx/*error.log
gitlab_nginx_access_log = /var/log/gitlab/nginx/*access.log
Fichier /etc/fail2ban/jail.d/gitlab-llm-bots.conf :
[gitlab-llm-bots]
enabled = true
filter = gitlab-llm-bots
#logpath = /var/log/gitlab/nginx/gitlab_access.log
logpath = %(gitlab_nginx_access_log)s
maxretry = 1
findtime = 600
bantime = 86400
On teste avec
fail2ban-regex /var/log/gitlab/nginx/gitlab_access.log gitlab-llm-bots
puis
systemctl restart fail2ban.service
fail2ban-client status gitlab-llm-bots
tail -f /var/log/fail2ban.log | grep gitlab-llm-bots