# CrowdSec Envoy bouncer, chart ghcr.io/kdwils/charts/envoy-proxy-bouncer 0.8.0 # gRPC ext_authz service that Envoy Gateway calls for every request on protected # listeners. Checks the client IP against LAPI decisions and (WAF) forwards the # request to CrowdSec AppSec for inline inspection. # # NOTE: this is a community project ("not tested in production, use at your own # risk"). It is used behind failOpen: true (see the SecurityPolicy), so a bouncer # outage lets traffic through rather than blocking your services. # Fixed name so the SecurityPolicy backendRef / ReferenceGrant can target it. fullnameOverride: crowdsec-envoy-bouncer service: type: ClusterIP grpcPort: 8080 httpPort: 8081 config: server: grpcPort: 8080 httpPort: 8081 logLevel: "info" # Envoy (public proxy) is the immediate hop and, with externalTrafficPolicy: # Local on the LB service, presents the real client IP. If you later put another # proxy in front (e.g. Cloudflare), set trustedProxies / trustedIPHeader so the # bouncer reads the true client IP from X-Forwarded-For instead of banning the # proxy. trustedProxies: [] exemptIPs: [] # IP-decision enforcement against LAPI (same namespace). bouncer: enabled: true lapiURL: "http://crowdsec-service:8080" apiKeySecretRef: name: crowdsec-secrets key: bouncer-key # WAF / AppSec inline inspection (same namespace). waf: enabled: true appSecURL: "http://crowdsec-appsec-service:7422" apiKeySecretRef: name: crowdsec-secrets key: bouncer-key # Chart default is false, which would deny every request if AppSec is down. failOpen: true