Roadmap
May 28, 2026 · View on GitHub
This plugin sits on top of alexandre-daubois/ember. The plugin's UX depends on what Ember itself exposes to plugins. Three release lines so far:
- v0.1.0 — MVP, pinned to Ember
v1.3.0 - v0.2.0 — Scroll-Window UX, Ember
v1.4.0,w-hotkey removed - v0.3.0 —
FooterRendereradopted, pinned to Emberv1.4.1
v0.1.0 (released) — pinned to Ember v1.3.0
The goal of v0.1.0 was to make the plugin installable from any Go-toolchain machine via go install github.com/rewulff/ember-crowdsec/cmd/ember-custom@v0.1.0 without local forks or replace-directives.
What works
- Decisions tab with origin filter (
?origins=crowdsec,cscliby default) - Alerts list (last 24h)
- Hotkey
c— toggle CAPI / community-list inclusion - Hotkey
d— confirm-unban prompt forcrowdsec/csclidecisions only (CAPI/list decisions are blocked because the next CAPI sync would re-pull them) - Hotkey
w— whitelist input flow with stepped duration selection (removed in v0.2.0, see below) - Status-count badge on the tab title (active local decisions count)
- Per-host JSON-Lines audit log of every write action (mode 0600, append-only, symlink-defended via
O_NOFOLLOW) - Two parallel auth stacks: bouncer X-Api-Key for
GET /v1/decisions, machine-account JWT for alerts and writes
Caveats with Ember v1.3.0
These were limitations imposed by the stock Ember plugin API in v0.1.0, not by the plugin itself.
| Limitation | Why | Workaround in v0.1.0 | Status |
|---|---|---|---|
| Whitelist duration is stepped, not free-form | Ember's tab-switch hotkey reserves digits 1..9 globally; the plugin never sees them | ↑/↓ to select duration from 30m / 1h / 4h / 12h / 24h / 7d, Enter to confirm | Obsolete — w hotkey removed in v0.2.0 |
| Plugin hotkey hints render inline in the tab body | Ember v1.3.0 has no plugin-side footer override, only the ?-overlay (which is unreachable from plugin tabs because plugins receive ? first) | One row of inline help text at the bottom of the plugin's render area | Tracked for v0.3.0 (FooterRenderer adoption, see below) |
| Broken-pipe loops in Caddy stderr after unclean ember exits | Ember v1.3.0 left dangling net-log writers after the sink-cleanup failed under contention | --log-listen 127.0.0.1:9210 as idempotent-restart workaround for the kill -9 case | Resolved in Ember v1.4.0 (PR #68) — picked up in v0.2.0 |
Pre-requisite
This plugin is designed to run on the same host as the CrowdSec LAPI (typically the Caddy LXC). It connects to the LAPI via http://127.0.0.1:8080 and is not designed for off-host LAPI access. Setup details in docs/CADDY-CROWDSEC-SETUP.md.
v0.2.0 (planned) — Ember v1.4.0 + UX cleanup
Pinned to Ember v1.4.0 (released 2026-05-11).
What's new
- Scroll-Window for the Decisions tab — the list of decisions now scrolls vertically with
↑/↓;↑ N earlier/↓ N moremarkers indicate hidden entries on either side. Resolves the 5-decision-cap visible in v0.1.0 (#7). - Ember v1.4.0 dependency — single-instance stance documented. The plugin opts out of the
MultiInstancePluginmarker, so Ember in multi-instance mode will disable the plugin with a warning. v1.4.0 also includes Ember PR #68 (sink-cleanup retry fix), which removes the broken-pipe-loop class of bug seen pre-v1.4 (#10, #11). - README "Whitelisting" section reworked — after maintainer feedback in hslatman/caddy-crowdsec-bouncer#116. New framing:
cscli decisions add --type whitelistis not an officially supported decision type; allow-functionality belongs in CrowdSec's engine via postoverflow YAMLs, not in any bouncer (#12, #15).
Breaking change
w(whitelist) hotkey removed. It produced atype=whitelistdecision viaPOST /v1/alertsthat CrowdSec does not treat as allow — every bouncer reads it as a block-marker (the existence of any decision is a block). Replacement: edit/etc/crowdsec/postoverflows/s01-whitelist/<name>.yamlandsystemctl reload crowdsec. Audit-log entries withaction: whitelistfrom v0.1.x persist; new writes only emitaction: unban(#13, #16).
Migration from v0.1.0
go install github.com/rewulff/ember-crowdsec/cmd/ember-custom@v0.2.0
Same env-vars, same audit-log format. The w hotkey is gone — any operator muscle memory that hit w should be redirected to the postoverflow YAML path above.
Out of scope for v0.2.0
FooterRendereradoption (replace inline-footer-row with global footer override) — needs Ember PR #70 released as a tagged version. Shipped in v1.4.1 (2026-05-25), unblocking v0.3.0. Tracked in #14.
v0.3.0 (released 2026-05-28) — FooterRenderer adoption
Pinned to Ember v1.4.1 (released 2026-05-25). Live-verified on CT 122.
- Upstream Ember releases tagged version with PR #70 — shipped in v1.4.1 (2026-05-25).
-
go.modbump fromv1.4.0→v1.4.1(PR #20). - Plugin implements
pkg/plugin.FooterRenderer— moved the inline↑/↓ select · c toggle CAPI · d unban (local only)hint into the global Ember footer; one extra decision row gained in the tab body. - Live-verified on CT 122 (2026-05-28).
Closed issues: #14, #2 (fetcher-error sanitisation completion).
Beyond v0.3.0 (no commitment, ideas)
- Multi-instance plugin: one ember-custom session can monitor multiple Caddy LXCs by switching their LAPI endpoints
- Streaming-endpoint (
/v1/decisions/stream) instead of polling for high-decision-volume nodes - Recent-Bans sub-tab via Ember's
MultiRenderer - Prometheus exporter via
Exporter-interface — surface plugin metrics on Ember's--expose :PORT - Filter / sort within the decision list via
HandleKey(by IP, origin, scenario) - Detail-view for a selected alert (events list, raw scenario hash)
- CI:
go test,go vet, lint via GitHub Actions / Forgejo Actions - Bulk operations: select multiple decisions, unban as one action
How to influence the roadmap
If you're using this plugin and one of the open caveats is hurting your operator workflow, the most direct lever is to comment on the relevant upstream Ember PR — that's the gating dependency, not anything on this side. The plugin is ready; we wait on Ember's plugin API to grow.
For plugin-internal bugs / improvements, file an issue on formin/ember-crowdsec (Forgejo) or rewulff/ember-crowdsec (GitHub mirror).