KamoCRM

Never ban k3m1 — its node network joins the fail2ban allowlist

FixKlusterServices
Shipped
September 28, 2026 at 6:30 PM UTC
Author
Kamo
Commit
f689808

FreePBX runs with hostNetwork on k1m1. A pod on k3m1 reaches it SNATed to k3m1's InternalIP, 10.0.50.1, which none of the [DEFAULT] ignoreip ranges covered (the image's [asterisk] override already has 10/8). VOIPService reads voicemail over AMI from either node (SP99-T4-h), so five refused AMI logins from k3m1 inside ten minutes would ban every k3m1 pod off the PBX for a day. 10.0.50.0/24 is added, with a note that any new node needs its range here and in the AMI permit. A stdlib test pins that both jails' allowlists cover the pod, service, LAN and k3m1 networks.

All changes

Like what you see shipping?

All of it arrives in your workspace on its own. Start on the free plan and read this page again in a month.

Start Free ForeverView Pricing