router: make CrowdSec opt-in (crowdsec.enable, default off)

Not every site wants the ban engine (hub sync needs internet at
activation, and it is one more moving part on a small box). Gate
crowdsec.nix on a new `crowdsec.enable` option like `omada.enable`.

gw-cnx-1 keeps it on; the VM test drops its mkForce overrides.
This commit is contained in:
2026-09-21 07:20:17 +00:00
parent e1e18dd9f3
commit 596ac1f4bb
6 changed files with 51 additions and 45 deletions
+2
View File
@@ -285,6 +285,8 @@ in
omada.enable = lib.mkEnableOption "TP-Link Omada SDN controller (podman container)";
crowdsec.enable = lib.mkEnableOption "CrowdSec (sshd log parsing) with the nftables bouncer";
proxy = {
enable = lib.mkEnableOption "internal reverse proxy (Caddy, wildcard cert via DNS-01)";