[caddy-4xx] enabled = true filter = caddy-4xx # Adjust if your Caddy writes elsewhere -- this must match the host path # mounted into the fail2ban container in docker-compose.yml. logpath = /var/log/caddy/access.log maxretry = 30 findtime = 2m bantime = 30m chain = DOCKER-USER banaction = iptables-allports action = iptables-allports[name=caddy-4xx, chain=DOCKER-USER]