- Shell 100%
New trigger scenario r3y/mastodon-faker-user-agent bans Faker-generated user agents used by spam bots after registration. The test harness accepts an optional user-agent column and has a wider ban duration tolerance; 35 test cases cover bot and real clients. Add a guide for finding and suspending bot accounts and a note on manual range bans. |
||
|---|---|---|
| allowlists | ||
| decisions | ||
| docker/crowdsec-web-ui | ||
| docs | ||
| etc | ||
| scripts | ||
| tests | ||
| .gitignore | ||
| LICENSE | ||
| README.en.md | ||
| README.md | ||
CrowdSec scenarios for Fediverse servers
Tested CrowdSec scenarios, parsers, profiles and operations helpers for Fediverse instances (focus: Mastodon) and the servers around them. The directory layout mirrors CrowdSec's own (etc/crowdsec/...), so you can clone the repository and copy the files into place.
Everything here runs in production on one Mastodon instance and five more servers with a central LAPI. The rules are built so that they do not ban federation traffic, detect bots while registration is closed or approval-based, and avoid hitting real users. All rule sets ship with tests (tests/) that run in an isolated CrowdSec instance.
The documentation is in German (see README.md and docs/). Quick start:
git clone https://forge.chrislo.de/FediSuite/CrowdSec-Szenarien.git && cd CrowdSec-Szenarien
sudo cscli collections install crowdsecurity/nginx crowdsecurity/base-http-scenarios crowdsecurity/http-cve
sudo scripts/install.sh --domain social.example.org --dry-run
sudo scripts/install.sh --domain social.example.org --restart
# optional: test scenarios and profiles in an isolated instance first
sudo scripts/test-scenarios.sh --cases tests/mastodon-registration.tsv \
--rules etc/crowdsec --profiles etc/crowdsec/profiles.yaml.local
Requirements: CrowdSec 1.7 or newer, Nginx in front of Mastodon writing a per-domain access log (/var/log/nginx/<domain>.access.log, default format). Scenario names start with r3y/; the profiles match on that prefix.
License
AGPL-3.0-or-later, see LICENSE. Copyright (C) 2026 Christin Löhner.