# Trellis / WordFence: Maintain plugin data folder in /web/app on deploy

**URL:** https://discourse.roots.io/t/trellis-wordfence-maintain-plugin-data-folder-in-web-app-on-deploy/18105
**Category:** trellis
**Created:** 2020-04-25T21:09:28Z
**Posts:** 8

## Post 1 by @stuartcusackie — 2020-04-25T21:09:28Z

I am using Wordfence for additional protection on my websites. It saves some data in the current/web/app/wflogs folder, and I am guessing that this data contains the current firewall settings and a list of blocked IPs.

The problem is when deploying with Trellis, this folder is lost, or at least I think it is. If this is true, then all WF firewall rules are lost on deploy. This is causing problems for me as all blocked IPs are regaining access to the website on each deploy. The Wordfence firewall takes 1 week to re-learn.

Is there a way to maintain the wflogs folder?

Thanks!

---

## Post 2 by @strarsis — 2020-04-25T23:43:39Z

Related:

> [@Trellis + WordFence WAF](https://discourse.roots.io/t/trellis-wordfence-waf/9437/18):
>
> At the very least, Wordfence let’s me know when I need to update plugins, and I can keep an eye on user logins.

---

## Post 3 by @adleviton — 2020-04-26T00:43:39Z

Yep:

> <https://github.com/adleviton/trellis-wordfence/issues/1#issuecomment-578845878>
>
> @adleviton: For installing this role using ansible-galaxy,
> it apparently needs a meta/main.yml file in this repository.
> It would also great to have this...

---

## Post 4 by @stuartcusackie — 2020-04-26T10:21:16Z

Thanks guys. This seems to work well. It will take a couple of weeks to truly test it but I will report back if there any issues.

I’ll add my personal installation notes here which might save somebody some time:

**INSTALLING WORDFENCE WITH TRELLIS**

WF needs files and folders to work: user.ini, wordfence-waf.php and /wflogs/. There is an ansible package for making this compatible with Trellis. To set up:

**From trellis folder run: (use WSL with windows)**

`ansible-galaxy install adleviton.trellis_wordfence`

**Create file: deploy-hooks/build-after.yml with contents:**

```
- name: Setup Wordfence
  include_role:
  name: adleviton.trellis_wordfence
```

**Add entry to roles/deploy/defaults/main.yml:**

```
deploy_build_after:
  - "{{ playbook_dir }}/roles/deploy/hooks/build-after.yml"
  - "{{ playbook_dir }}/deploy-hooks/build-after.yml"
  # - "{{ playbook_dir }}/deploy-hooks/sites/{{ site }}-build-after.yml"
```

**Deploy**

* * *

Notes:

- We should add _wflogs_ to .gitignore
- The _wflogs_ folder now sits in the root folder, along with _shared_ and _releases_.

---

## Post 5 by @adleviton — 2020-04-29T15:45:10Z

My .gitignore file excludes wflogs/.

My /wflogs folder is actually in /srv/www/mysite.com/web/app. That’s where it’s always been by default for me, and that’s created by the Wordfence plugin.

Moving /wflogs to the shared folder would be cleaner, but adding `wflogs/` to .gitignore is a pretty quick and harmless fix for right now. Not sure if I want to overcomplicate things.

I’m not sure what you mean … aren’t all ‘deploys’ considered to be ‘remote’? In any case, it would need to be run on every deploy.

---

## Post 6 by @stuartcusackie — 2020-04-30T10:21:51Z

Thank you for clearing this up and your ansible package is working great on all the websites that I have tried it on.

I’m not sure what I meant with my deployment question. I think I was worried about how your hooks would work with my local vagrant box. I believe placing the hook in a _mywebsite.com-build-after.yml_ file would mean that it would only run on _[mywebsite.com](http://mywebsite.com)_ and not _mywebsite.test_.

Thanks again!

---

## Post 7 by @adleviton — 2020-04-30T16:16:41Z

On local, I leave Wordfence disabled, so it’s never been an issue for me. And I also never run deployments locally. But I would expect any hooks to work just as they would remotely.

---

## Post 8 by @stuartcusackie — 2020-04-30T16:37:38Z

ah yes, of course. I was wrongly assuming that Trellis performed some kind of deployment on the provisioning of local vagrant boxes. I guess I’m not quite used to Trellis yet.

Thanks again for your help and your ansible package.

---

## Post 9 by @system — 2020-06-06T21:13:52Z

This topic was automatically closed after 42 days. New replies are no longer allowed.
