32 Console
Robin edited this page 2026-08-24 10:08:43 +00:00

Console

The console is served by the controller at / on the API listener — one page, no build, a client of the API and nothing else: everything it does is one request an operator token could make from a script, and everything it changes is a change to the configuration files.

Signing in. A name and a password; a one-time code as a second step once the account has enrolled one; an API token behind a link, as the alternative. Sessions slide with activity (twelve hours unless set — Settings → Accounts). Every action is recorded under the person's name in Activity.

Home. The sanctions as they land, and one search box: an address or its start, a rule, a server, a country code, a network by number or name — an exact address offers Open for its whole history across the fleet. The feed refreshes every few seconds (▶ Live / ❚❚ Paused), new rows flash; the state chips (everything, banned now, bans, detections, expired, lifted), a server, dates on demand; what only changes the display sits apart — rows, fields, Requests (the log lines behind each sanction under its row). Each sanction is a card, not a table row: the address with its flag, when, its network; then the server, the rule, the state, what was reported. Four numbers on top: servers connected, banned now, sanctions in the last hour, whether every server holds its configuration. The side panel (▤ to hide it) shows the servers — a click narrows the feed to one — and, under the current filters, the top countries, networks, rules and targets, each with its bans (blue) and hits being counted (yellow), figures compacted (688k; the exact number on hover), sorted by bans or by hits (sorted by … ⇅ — hits first is how false positives and noisy rules surface). A click filters on one; ctrl-click (⌘, shift) adds it — several countries or networks at once, the chip says the set; all … opens the full list, where ticking boxes does the same without a keyboard. ★ pins an entry at the top of its list. Bans by hand sit under the rules as their own line, out of the ranking.

The world map on Home paints each country by what it sent under the current filters (hover for the count, click to narrow the feed on it; ✕ hides it, remembered), and moves as the servers decide: each fresh ban or hit fires a ray from its source — the city itself when the city database places it — to the very point of the server it hit, a thin trail with a bright head riding its tip (red a ban, yellow a hit); several from one source follow each other on the same trail, so a stream reads as a stream. Your own servers sit as blue dots at their city (hover names them — the first three and "& n more" — and the city); a full-screen button, and arcs beside the legend turns the rays off. Outlines from Natural Earth (public domain), in the console itself — no tiles, no third party. Your account — click your name in the header: username, email, password (the current one is asked), two-factor, and Sign out. Next to it, the theme button cycles auto → dark → light, kept with your account.

What to show. Two axes, side by side above the feed. Prod / Test: what the enforcing rules did, or what the rules in test would have done (test bans, test hits — recorded, nothing enforced; the map greys and hatches in test). Then the stages — All, Bans, Hits, Expired, Exempted — cumulative chips: light the ones you want, nothing lit is everything; All interleaves the hits being counted with the sanctions as one timeline. Remembered by the browser. The map, the side panel and the chart follow the same choice.

Over time draws, per step, the bans and detections that started (bars) and, as lines on their own scale, the hits the rules scored in the step (every hit, banned or not — a flow the agents send on every sync) and the bans in force. Its boxes are its own; the feed's server, origin and date filters reach it. The step is yours (the small wheel under it — down to one second on the short windows), log switches the scale, and a click on a bar zooms the whole page into that step's dates. The first display is computed; every tick after asks for the tail alone.

Hits are the offenders the servers are counting but have not convicted — how many hits of how many, since when, one gauge per threshold, the nearest to a ban first, the requests behind them on demand — as each server last said (every sync). All carries them too, interleaved with the sanctions by time; an address's dialog shows its hits being counted above its sanctions. Every card offers the same three actions in the same place — Ban (red), Lift (green), Exempt (plain) — greyed when they do not apply. Every ban shows its duration ("6h ban") — the ladder reads at a glance. The chart's bars name their hour and counts on hover; a click narrows the feed to that hour. The report reads "reported · 100% confidence" and links to the address on AbuseIPDB.

The period. One setting for the whole page, at the right of the filters: a wheel of windows — last minute to 30 days, then Everything — turned by finger, wheel or drag, a click on a neighbour steps it; the white ring marks the choice. Custom… opens a dialog with two dates and their times, presets (Today, 7 days, This month) left open-ended — "→ now" keeps growing. The feed, the side panel, the map and the chart all read over that window. Remembered by the browser.

A server's clock. Every sync compares clocks; a machine more than thirty seconds off the controller's carries a clock off by … tag on its card and page, and Home's Servers card says so — check NTP on both; its windows, ban ends and place on the charts are off by that much.

Requests — the public unblock page. Under Settings → Unblock page (off by default) the controller serves /unblock — no account: a person blocked by one of your machines opens it, sees whether their own address is banned and lifts it in one click, logged. Repeated self-unblocks offer a whitelist request; anyone may check whether an address is banned and ask for another address to be unblocked — those wait under Requests (its own menu entry, the pending count as a badge, a notice when one arrives), where you Lift (let it in now, the rules keep watching), Exempt (never sanction it again) or Deny. The page is yours to brand — title, footer text and link, contact line — in the visitor's language (English or French) or the one you fix; the captcha is off, built-in (an arithmetic question, no third party) or Cloudflare Turnstile; two extra names of the console answering over one address family each let a dual-stack visitor unblock both their addresses.

Reputation. With an AbuseIPDB key in the controller's secrets.yaml, an address's dialog shows what the provider knows — confidence of abuse, reports, last report, ISP — held from an earlier check or one click away (each check spends one of the account's daily checks; the count left is shown). Every server's card carries the provider's word on the server's own address, checked daily: a listed server is worth knowing. Every ticket links to the address on AbuseIPDB.

Banning by hand. Ban on a hit, Ban… in an address's dialog, or type any address in the search box and press Ban… — on record here or not. Given from a detection, the dialog arrives set as the rule would have done — its policy's duration, its report preset, the server that saw it — and the report carries the detection's own facts; everything stays changeable. Otherwise the defaults are the considered ones: thirty days, reported. A choice of where (one server, or the fleet — machines enrolled later get it too), how long, a reason (kept as the ban's evidence, never sent out), and the report preset. Each server applies it at its next sync, within seconds, through the same checks as any sanction — an exempted address stays exempt. The standing bans by hand are listed under Lists → Banned by hand, one row per address. A range is never banned this way: the dialog turns it into a list — the firewall's job, a set on the machines, no sanction.

Narrowing. Every narrowing beyond the state chips — a server, one or several countries or networks, a username, a target, a search — shows as a chip with its ✕ next to them, whatever set it (the side panel, a flag, a network name, the map); clear all when several. A list a filter was chosen from keeps showing the others (with their true counts), so a second and a third can join the selection. Heavy views — panel counts, map, chart — refresh at once on a filter change, then on a cadence the window can afford (seconds on a live hour, slower on a week); they dim only while the question changes, never on a routine tick.

Settings (the panel itself): Accounts (people, two-factor, session length), Tokens (scoped API tokens — what a script or another Claude uses), Reporting (the AbuseIPDB switch, key, daily limit, and the day's two counts — what this controller sent, and what the provider says is left on the whole account), Unblock page, Notifications (the SMTP relay and who is told what), Configuration files (the tree, editable), Geo data (the databases, their editions, the refresh, the city switch), Display (this browser's preferences: time zone, theme, ban colour, feed cadence and rows), Maintenance (the store's size and counts, retention, flush and compact), Vitals (the controller's own pulse — what it handles a second and what one costs), Activity (who did what), About (versions, latest releases, credits).

Themes. Dark by default; the topbar button (next to your name) cycles auto → dark → light, and the choice is kept with your account — it follows you across browsers. The same setting sits under Settings → Display.

An address opens as a dialog wherever it appears — the feed, a server's bans, the fleet's bans, the lookup. Banned where, its reverse name, the provider's reputation on demand, its hits being counted, every sanction on record with the lines that convicted it, and Its network — the address, its prefix and the whole network side by side, each with what it did and its own ban. The actions: Ban… (set as the rule would have done when opened from a detection), Lift (the address is let back in now; the reason is optional) and Exempt (the red one — never sanctioned again, on any server, by any rule, while the exemption lasts; permanent or for a while, with a note; it can lift the bans in force at the same time). Lift and Exempt can also withdraw the AbuseIPDB report when something was reported.

Servers. Every enrolled machine with a pulse that says who is connected: agent version, when last seen, from which address and where the geo databases place it (its city with the city database), whether it holds the configuration it should, its level, state, how it takes part in the fleet, active bans. A server has five tabs:

  • Overview — active bans, state and level, its part in the fleet, the agent's uptime and counters, its address and place, its latest bans, what differs from the fleet's defaults; Ask for its full history again makes the machine send everything it holds, requests included (a machine enrolled again does so on its own).
  • Bans — the same feed, for this server only.
  • Rules — its level and its packs (each on or test, at the server's level or its own), then every rule it runs with the threshold it crosses on there and why. Override… opens a dialog (a level of the rule, thresholds of your own, state, policy — each field inherits unless set); Reset returns to the default.
  • Logs — where its logs are, of which kind, on which ports (see below).
  • Settings — level, state, whether it shares its bans with the fleet and enforces the fleet's, who may lift its bans, who reports its sanctions, a description. Saving writes agents/<hostname>.yaml, reloads and pushes; a refused edit is reverted and says why.

Rules. The rule language, editable in place — every edit is a file written on the controller, reloaded whole and pushed to the servers that run it, or refused with the loader's message and reverted. Five tabs:

  • Rules — the library, filed by category. New rule… and Edit… open the rule in its five blocks: what it recognises (parsers from the library — type to search — or a regex written here, with Try it on lines…), from how much (one threshold, or adaptive: several), what it does (a ban policy, and/or notify), what it says (a report preset), and More (state, count per address or network, share, distinct). Preview changes shows the file's diff before Save and push; Edit as file opens the YAML itself, checked by the real loader.
  • Packs — the grid: packs down, servers across, a tick gives the pack to the server. Edit… names the rules a pack lists.
  • Parsers — the library by source, with a tester (paste lines, see what matches and what is captured); regexes written inside rules are listed with their rule.
  • Ban policies — how long, on which ports, how long the machine remembers, tighten on repeat, longer on reputation.
  • Reports — what a ban says to AbuseIPDB and when; the built-in default is editable (writes reports/default.yaml).

A server's Rules tab: its level; its packs, each on or test, at the server's level or its own; rules added on their own; then everything it runs with the threshold it crosses on there and why, and Override… per rule. Its Logs tab: where its logs are, of which kind, on which ports — with layouts (Plesk, Debian nginx, Apache, sshd, mail) to start from — pushed to the agent when set.

Stats. Every row, not a top: countries, networks, rules, servers, usernames tried and targets over the window of your choosing (the wheel, or free dates), bans and — beside them — the hits being counted, prod or test. Counted from the sanctions themselves, so any range is exact; the fleet's copies and the lists' blocks are left out, and bans by hand sit in the header as their own count. Each table filters as you type, all … unfolds it whole, and CSV exports what is shown. A click opens the country, the network, the rule or the server.

Cities. Settings → Geo data → City database: with the DB-IP source, the city and region appear under every address — sanctions and hits alike — the search box finds them, the map's rays leave from the city itself and your servers sit at theirs; the cost is written beside the box. The sanctions keep the origin they had when they were decided; the live views resolve with the databases of the moment.

Sessions. A person's session lasts console_session (12 hours unless set — Settings → Accounts, Sessions end after…) after their last activity: every request pushes it out, so nobody at work is signed out; 30 days after sign-in at the very most. When the controller is updated under an open console, a notice appears bottom right with a Reload button; the page keeps working meanwhile.

Exemptions live under Lists → Exempted (below).

Lists. Two tabs. Blocked: your lists that ban preventively — a network (AS), a country, prefixes written down — where they block (the fleet or chosen servers) and how many prefixes they resolve to — pushed to the machines as one firewall set each, loaded in seconds whatever the size, the machine's own exemptions carved out first; the feed leaves the list-driven blocks out. The table sorts by any column (date added first, to the minute). Exempted: your lists that exempt, the published allow lists (search engines, CDNs, monitoring probes, presets — on/off, where, refresh, your own), and the exemptions by address (what the console added, per-server ones, the files on the controller). Block a network or a country… and Exempt a network or a country… open the same dialog: type a network's name or AS number, or a country's name or code, and pick from what matches — the dialog resolves it (prefixes, addresses) before anything is written; a list may block on some servers and exempt on others. A scope is the fleet, the servers running a pack (the web pack's hosts, never the DNS servers — the ones given the pack later too), or named servers; the published allow lists have the same choice in their Where column, and so does Exempt an address…: the fleet writes exemptions-cli.yaml, one server its own declaration, a pack's servers or several servers a one-prefix list (lists/exempt-<address>.yaml, permanent like every list). At the top of the Blocked tab, Published blocklists: the blocklists that ship (Romain Marcoux's aggregate of fifteen sources, 40 000 addresses, or the whole 550 000), one click to turn on — where — and off; Add a published list (URL)… makes one of your own (URL, format, cadence, Fetch & check before anything is written). A network's own dialog (from the rail or a ticket) shows the whole network at the top — IPv4 addresses, IPv6 /64 networks, how much of it is banned now — Ban this network…, and its activity, prefix by prefix: two readings of the same table, Bans (the addresses the rules convicted over a window of your choosing, share in addresses) and Hits (the addresses being counted right now and not banned — where slow probing spread across a big network shows), each prefix with Ban this prefix… — so you ban one prefix when one prefix carries it, and the network only when the network does. An address's dialog answers the same in three rows — the address, its prefix, the whole network — with the ban of each. Below the lists, Banned by hand: the standing manual bans, one row per address ("the fleet" or the servers named), sortable, each row opening the address with its evidence. The geo databases behind all this live under Settings → Geo data; a list naming a network or a country follows them (re-resolved after every update and every ten minutes — prefixes that left are lifted, prefixes that joined are blocked). The ⓘ marks explain in place; the pages stay quiet. Views: the whole filter of the Home feed — what to show, the server, the country, one or several networks, the search, the period — saved under a name with your account (Views ▾Save the current filters as a view…), listed first in the panel and applied in one click: the French addresses of the four big ISPs, say, to review false positives. The panel's ★ pins a country, a network, a target or a rule at the top of its list (this browser). The search box on Home also finds sanctions by target — the site or domain the convicting lines named.