Ban IPs from matching regex with multiple stream support
// readme
A lightweight intrusion prevention system written in Rust.
Banalize tails log files, extracts IP addresses via configurable regex patterns, and blocks offenders using iptables after a configurable number of matches within a time window.
Architecture
apps/
core/ — Rust binary API + iptables integration → :6040
ui/ — Vite + React dashboard (shadcn/ui) → :6041 (docker) / :5173 (dev)
How it works
log file → regex match → IP extracted → threshold reached → iptables DROP rule
→ auto-expires after ban_time
- Watchers tail one log file per config using inotify
- Matches are counted in an in-memory store (per config + IP) for fast threshold checks, rebuilt from the SQLite audit log on restart
- Bans are applied synchronously via iptables and persisted across restarts
- Events (match, ban, unban) are recorded asynchronously in SQLite for auditing
- Cleaner runs periodically to expire bans and matches outside their time windows
- REST API on port 6040 — documented at
GET /api/openapi.json, UI atGET /swagger - Dashboard at…