# shieldlist-console

The controller's own log, read by the agent on the machine that runs it:
sign-ins and credentials it refused. One rule, `shieldlist-panel`,
bans the guesser. Its `web` policy ships in the pack; the rule needs the
log input in agent.yaml (see the rule file).

## shieldlist-unblock-abuse (2026-08-17)

`shieldlist-unblock-refused` reads the controller's `public page refused`
lines (rate limit, captcha) and `shieldlist-unblock-abuse` bans an
address refused repeatedly — 10 in 10 minutes at standard. Same `web`
policy. The agent that reads the controller's journal
(`unit: shieldlist-controller.service`, category `shieldlist`) is the
one on the controller's machine.
