packetcat
|
f06823a062
|
add 157.90.177.214 to deirdre.asininetech.net.ipset
|
2022-04-04 12:49:13 -04:00 |
staticsafe
|
2955428f01
|
add 2002:2d8d:56bb::2d8d:56bb to deirdre.asininetech.net.rules.v6
|
2022-01-13 09:30:24 -05:00 |
staticsafe
|
66e206d7c8
|
add AS206728 to deirdre and erlking ipsets
|
2022-01-12 12:37:00 -05:00 |
staticsafe
|
0cf1563566
|
change pgbackrest version to 2.36
|
2021-12-31 09:29:21 -05:00 |
staticsafe
|
47eb6aa778
|
add redirect for asininetech.com to nullrouted.space
|
2021-12-29 20:59:22 -05:00 |
staticsafe
|
4f7fe6dc39
|
change certs for nullrouted.space to proper ones
|
2021-12-29 20:46:28 -05:00 |
staticsafe
|
d4466fa486
|
add initial config for nullrouted.space
|
2021-12-29 20:41:23 -05:00 |
staticsafe
|
5f0de6725c
|
add tailscale ipv6 addresses to allow list
|
2021-11-21 12:38:51 -05:00 |
staticsafe
|
834890958b
|
add tailscale subnet to allow list
|
2021-11-20 23:07:47 -05:00 |
staticsafe
|
fa5dc5c4b4
|
oops..fix syntax error in deirdre.asininetech.net.ipset
|
2021-10-27 18:18:01 -04:00 |
staticsafe
|
7ee004dbce
|
add 101.200.169.64 to deirdre.asininetech.net.ipset
|
2021-10-27 18:16:29 -04:00 |
staticsafe
|
0bc698d2a3
|
use proper cert for wiki.bastetrix.org
|
2021-10-17 12:00:47 -04:00 |
staticsafe
|
417fe5bba3
|
add wiki.bastetrix.org
|
2021-10-17 11:55:15 -04:00 |
staticsafe
|
4965c02d78
|
wp sites should use the wp_with_supercache snippet now
|
2021-10-17 11:49:25 -04:00 |
staticsafe
|
14f4f9e564
|
use proper certs for poetry.packetcat.ca
|
2021-10-17 11:43:21 -04:00 |
staticsafe
|
1cffac6a06
|
add poetry.packetcat.ca and php snippet
|
2021-10-17 11:36:05 -04:00 |
staticsafe
|
30cd26621b
|
use sslstapling snippet to consolidate configs
|
2021-10-17 11:17:26 -04:00 |
staticsafe
|
b6dfff5b55
|
use proper cert for bastetrix.com
|
2021-10-17 11:15:22 -04:00 |
staticsafe
|
a9cee4de3b
|
use different resolver for ssl stapling snippet
|
2021-10-17 11:12:14 -04:00 |
staticsafe
|
941ae1d6d5
|
oops wrong section
|
2021-10-17 11:09:53 -04:00 |
staticsafe
|
90225209a8
|
add sslstapling_hsts snippet
|
2021-10-17 11:09:21 -04:00 |
staticsafe
|
75a7f31a34
|
add bastetrix.com.https
|
2021-10-17 11:06:40 -04:00 |
staticsafe
|
6760952018
|
add bastetrix.com.http
|
2021-10-17 10:59:25 -04:00 |
staticsafe
|
4059278a32
|
include norobots.conf snippets
|
2021-10-14 22:25:07 -04:00 |
staticsafe
|
c425d6b291
|
turn on access logging in ubuntu/elaine.asininetech.net.yml
|
2021-10-14 22:07:23 -04:00 |
staticsafe
|
07e9a24ce3
|
errors should be logged
|
2021-09-07 18:17:14 -04:00 |
staticsafe
|
4c09da012d
|
turn off access logging for nitter.ca
|
2021-09-07 18:16:47 -04:00 |
staticsafe
|
1eb8567d07
|
remove dhparams parameter
|
2021-09-07 17:29:36 -04:00 |
staticsafe
|
3a88e45cbc
|
remove add_header
|
2021-09-07 17:24:11 -04:00 |
staticsafe
|
0cdad6a443
|
remove robots.txt section
|
2021-09-07 17:21:15 -04:00 |
staticsafe
|
f5e67ae71d
|
add https config for nitter.ca
|
2021-09-07 17:20:14 -04:00 |
staticsafe
|
d650f545b7
|
add ubuntu/elaine.asininetech.net.yml
|
2021-09-07 16:57:04 -04:00 |
staticsafe
|
3ffa834b4a
|
fix typo in demonreach.asininetech.net.rules.v4
|
2021-09-04 13:50:34 -04:00 |
staticsafe
|
c8a274c39a
|
fix more incorrect syntax in demonreach.asininetech.net.rules.v6
|
2021-09-04 13:49:25 -04:00 |
staticsafe
|
1a658b71a0
|
fix NAT rules in demonreach.asininetech.net.rules.v6
|
2021-09-04 13:48:06 -04:00 |
staticsafe
|
cac6aab56a
|
add some wireguard specific rules to demonreach
|
2021-09-04 13:45:10 -04:00 |
staticsafe
|
d1c8a3eb55
|
add TinyBotTestUA to block list
|
2021-07-16 15:07:53 -04:00 |
staticsafe
|
d38daabc0c
|
add TinyTestBot to bot block list
|
2021-06-29 14:33:04 -04:00 |
staticsafe
|
32e5b1396a
|
use custom 404 page for sadiqsaif.com
|
2021-06-13 16:16:29 -04:00 |
staticsafe
|
1b2227555c
|
change webroot for sadiqsaif.com
|
2021-06-13 15:49:35 -04:00 |
staticsafe
|
d4bd7cfcf9
|
add lanaibot useragent to block list in deirdre.asininetech.net.yml
|
2021-05-18 11:30:22 -04:00 |
staticsafe
|
736158c9b5
|
update pgbackrest-install/tasks/main.yml to use 2.33
|
2021-05-11 12:35:29 -04:00 |
staticsafe
|
9852a4ea21
|
remove tinc ports in deirdre
|
2021-04-05 09:18:44 -04:00 |
staticsafe
|
4085481ed0
|
remove elasticsearch ports from deirdre firewall rules
|
2021-04-05 09:18:06 -04:00 |
staticsafe
|
9aec73785d
|
add rules to allow outbound NTP to deirdre
|
2021-04-05 08:29:25 -04:00 |
staticsafe
|
2fb9123db3
|
update IP range for Infegy bot to 173.244.135.0/25
|
2021-03-20 19:01:08 -04:00 |
staticsafe
|
45935b847a
|
remove old ipset block of Comcast dynamic IP
|
2021-03-20 18:56:52 -04:00 |
staticsafe
|
53efc0c07c
|
remove waldo.asininetech.net.yml
host is decommissioned
|
2021-03-20 18:44:17 -04:00 |
staticsafe
|
83f211675b
|
change hosts value to specific hosts for webserver plays
|
2021-03-20 18:43:31 -04:00 |
staticsafe
|
8cbf3b0e64
|
add blockbots nginx snippet and use it in TF vhost
|
2021-03-20 18:41:38 -04:00 |
staticsafe
|
0b3265d75c
|
add a new IP into deirdre and erlking ipsets
remove waldo ipsets and rules
|
2021-03-17 09:56:10 -04:00 |
staticsafe
|
ae99eaef7b
|
home nodes should be updated as well
|
2021-01-17 19:15:50 -05:00 |
staticsafe
|
1541a24467
|
add package-update role
|
2021-01-17 19:14:41 -05:00 |
staticsafe
|
3cb30d2985
|
add aliases copy task to common play
|
2020-12-01 10:31:07 -05:00 |
staticsafe
|
db53abe225
|
remove zsh from common packages install list
|
2020-11-29 09:21:54 -05:00 |
staticsafe
|
2860f23b85
|
add net-tools to common packages install list
|
2020-11-29 09:21:03 -05:00 |
staticsafe
|
2d2e5a78c5
|
we should set hostname before package installation
|
2020-11-25 16:20:30 -05:00 |
staticsafe
|
42b6960609
|
add 217.160.142.105 to ipset
|
2020-10-28 10:40:14 -04:00 |
staticsafe
|
8ac714f548
|
consolidate adsbot prefixes into two /24s
|
2020-10-15 13:15:06 -04:00 |
staticsafe
|
0506ecb009
|
remove - in host group name in icinga-client-install.yml
|
2020-10-12 09:12:07 -04:00 |
staticsafe
|
87c531e0c5
|
update adsbot prefixes
|
2020-10-12 09:10:40 -04:00 |
staticsafe
|
4343fdf1f6
|
install python-is-python3 as part of common role
|
2020-10-11 14:37:53 -04:00 |
staticsafe
|
016d71151a
|
set phpfpm socket to 7.4
|
2020-10-03 22:02:26 -04:00 |
staticsafe
|
4e96352e88
|
add another adsbot IP into the ipset
|
2020-09-23 11:00:00 -04:00 |
staticsafe
|
340637ef19
|
add another subnet of Aspiegel bot
|
2020-09-12 12:19:39 -04:00 |
staticsafe
|
c28997cd60
|
add another adsbot IP to nasties ipset
|
2020-09-11 19:47:15 -04:00 |
staticsafe
|
4f7b399783
|
add another adsbot IP to ipset list
|
2020-09-09 09:27:07 -04:00 |
staticsafe
|
10ba23f5d6
|
add another Adsbot IP to the nasties ipset
|
2020-09-07 12:40:23 -04:00 |
staticsafe
|
4d0660e162
|
quotes needed
|
2020-08-22 19:03:10 -04:00 |
staticsafe
|
1bd0269944
|
make sure to set hostname on new nodes and turn off motd news on focal
|
2020-08-22 19:00:56 -04:00 |
staticsafe
|
2d45e87d98
|
remove sshd_config copy in common role
its in ssh-enforcement now
|
2020-08-22 18:43:35 -04:00 |
staticsafe
|
e574b1d4de
|
remove catsith.asininetech.net.yml
no longer needed
|
2020-08-22 16:44:50 -04:00 |
staticsafe
|
9aa40b3967
|
Clean up site.yml and move some other roles into their own yml files
|
2020-08-22 16:21:24 -04:00 |
staticsafe
|
b2bd30101b
|
ssh-enforcement role should be run for unsetup hosts as well.
|
2020-08-22 15:59:38 -04:00 |
staticsafe
|
2bfed5b9ed
|
add ssh-enforcement playbook
|
2020-08-22 15:47:23 -04:00 |
Sadiq Saif
|
b6946a3e26
|
Update pgbackrest version to 2.28
|
2020-08-18 08:40:19 -04:00 |
staticsafe
|
c73f1f6b7c
|
add woff2 to static resources to be cached
|
2020-07-30 17:57:33 -04:00 |
staticsafe
|
d2b0e47564
|
add Adsbot IPs to webserver ipsets
|
2020-07-29 08:46:33 -04:00 |
staticsafe
|
36086ba967
|
fix an extraneous space in erlking.asininetech.net.yml
|
2020-07-27 15:26:12 -04:00 |
staticsafe
|
3715879e77
|
add WP caching config to other sites now
|
2020-07-27 13:42:50 -04:00 |
staticsafe
|
33c6fc78e2
|
fix extra bracket
|
2020-07-27 13:37:43 -04:00 |
staticsafe
|
b604283ce5
|
improve WP caching setup
testing on asininetech.com
|
2020-07-27 13:33:52 -04:00 |
staticsafe
|
91404bb5f1
|
remove extraneous ;
|
2020-07-26 19:27:42 -04:00 |
staticsafe
|
377568f7cd
|
remove quotes
|
2020-07-26 19:26:46 -04:00 |
staticsafe
|
2e468240fd
|
add new Access-Control-Allow-Origin header for Mastodon 3.2.0
|
2020-07-26 19:24:05 -04:00 |
staticsafe
|
1b6e048e43
|
cleanup as393949.net
|
2020-07-18 22:41:10 -04:00 |
staticsafe
|
8dd8505d0a
|
remove as393949.net
|
2020-07-18 22:21:41 -04:00 |
staticsafe
|
4ea258d17b
|
add 149.248.4.242 to deirdre.asininetech.net.ipset
|
2020-07-05 14:34:47 -04:00 |
staticsafe
|
71fc82ed22
|
remove namshiel.asininetech.net.rules.*
|
2020-07-05 14:33:29 -04:00 |
staticsafe
|
f5f09ebc58
|
add 2001:19f0:6001:5aa0:5400:2ff:fecf:eee5 to drop for deirdre
|
2020-07-05 14:31:44 -04:00 |
staticsafe
|
7426c88be2
|
add 75.64.236.168/32 to deirdre and waldo ipset
|
2020-06-27 17:31:15 -04:00 |
staticsafe
|
f091373a1b
|
add yet another pimeyes.com crawler IP to ipset
|
2020-06-01 23:31:36 -04:00 |
staticsafe
|
07badc1ff1
|
add another pimeyes crawler IP to ipset
|
2020-06-01 23:17:07 -04:00 |
staticsafe
|
c69b2dda9a
|
add another pimeyes.com crawler IP
|
2020-05-27 21:05:14 -04:00 |
staticsafe
|
146fd41a7f
|
add pimeeyes.com crawler IP to nasties ipset
|
2020-05-27 21:01:18 -04:00 |
staticsafe
|
e1c36822fa
|
add a centurybot IP to nasties ipset
|
2020-05-27 13:44:27 -04:00 |
staticsafe
|
4fbedfec4e
|
add Aspiegel bot range to nasties ipset
|
2020-05-19 13:24:00 -04:00 |
staticsafe
|
1a633fb947
|
sadiqsaif.com does not need a custom 404 page anymore.
|
2020-05-07 16:48:02 -04:00 |
staticsafe
|
4c573cb5a0
|
remove python-pip and python-dev from common role
|
2020-04-23 16:55:18 -04:00 |
staticsafe
|
27b9e93b0d
|
reference nasties ipset for erlking and waldo
|
2020-04-15 10:54:52 -04:00 |
staticsafe
|
fd475f98cb
|
add some more ipsets for erlking and waldo
|
2020-04-15 10:52:33 -04:00 |
staticsafe
|
d8f5681c52
|
fix typo in ipset.service
|
2020-04-15 10:26:29 -04:00 |
staticsafe
|
dd4d335302
|
make ipset.service import even if ipset already exists and then reload in main.yml
|
2020-04-15 10:24:02 -04:00 |
staticsafe
|
05176fb83e
|
don't destroy ipset in main.yml
|
2020-04-15 10:15:37 -04:00 |
staticsafe
|
3fb3507d40
|
make some more explicit requirements in ipset.service
|
2020-04-15 10:14:05 -04:00 |
staticsafe
|
8aa1d869ba
|
clean up unnecessary comments in firewall rulesets
|
2020-04-14 22:41:05 -04:00 |
staticsafe
|
a7888e95bf
|
set FLUSH_ON_STOP to 0
|
2020-04-14 22:36:13 -04:00 |
staticsafe
|
358b88ea60
|
we use a default file for netfilter-persistent
|
2020-04-14 22:29:56 -04:00 |
staticsafe
|
14c62687a7
|
ipset service stop destroy
|
2020-04-14 22:16:02 -04:00 |
staticsafe
|
53d62d54f5
|
let's try this again with destroy
|
2020-04-14 22:15:06 -04:00 |
staticsafe
|
377a5bcebf
|
temporarily comment out firewall rule
|
2020-04-14 22:12:03 -04:00 |
staticsafe
|
58c0b0e2c1
|
always reload systemd
|
2020-04-14 22:09:46 -04:00 |
staticsafe
|
3abbcbbd9e
|
use flush instead of destroy in ipset everywhere
|
2020-04-14 22:07:16 -04:00 |
staticsafe
|
92f286bbd6
|
should be src for ipset based rule
|
2020-04-14 22:03:31 -04:00 |
staticsafe
|
c267ec243f
|
use ipset instead of a bunch of INPUTs
|
2020-04-14 22:02:50 -04:00 |
staticsafe
|
0d7df674ec
|
dont use handler
|
2020-04-14 21:56:14 -04:00 |
staticsafe
|
02a376b367
|
restart ipset service instead of start and use handler
|
2020-04-14 21:52:51 -04:00 |
staticsafe
|
1430497f5c
|
move order of ipset destroy up
|
2020-04-14 21:47:16 -04:00 |
staticsafe
|
696bf3348f
|
fix syntax error in ubuntu/roles/ipset-deploy/tasks/main.yml
|
2020-04-14 21:44:55 -04:00 |
staticsafe
|
ce39f769a2
|
add ipset-deploy role
|
2020-04-14 21:42:03 -04:00 |
staticsafe
|
835384a24d
|
add rulesets for uriel.asininetech.net.
|
2020-04-04 19:19:53 -04:00 |
staticsafe
|
66eebc37d3
|
add moz.com crawler to firewall block list on web servers
|
2020-03-28 23:10:00 -04:00 |
staticsafe
|
07cf97fa21
|
add rpcbind to list of packages we remove on setup
|
2020-03-27 13:08:12 -04:00 |
staticsafe
|
114970ec4b
|
Use a more generic sshd_config with our options.
|
2020-03-24 11:15:43 -04:00 |
staticsafe
|
1f1bf5147b
|
common role is now copying over a sshd_config
|
2020-03-24 10:27:23 -04:00 |
staticsafe
|
1de56b96b9
|
remove grevane.asininetech.net.rules.*, not needed anymore
|
2020-03-23 11:26:08 -04:00 |
staticsafe
|
c1b3d2a171
|
clean up nginx_remove_sites
|
2020-03-09 20:38:56 -04:00 |
staticsafe
|
6613d75162
|
remove sadiqsaif.ca and staticsafe.ca vhosts
|
2020-03-09 19:26:22 -04:00 |
staticsafe
|
7fb64da246
|
no need for 127/8 rules in demonreach.asininetech.net.rules.v4
|
2020-03-08 22:56:18 -04:00 |
staticsafe
|
10c45c850b
|
DNS resolving issues in demonreach.asininetech.net.rules.v4?
|
2020-03-08 15:58:13 -04:00 |
staticsafe
|
f9e74ee5aa
|
allow TCP DNS as well for VPN subnet
|
2020-03-04 17:50:43 -05:00 |
staticsafe
|
13f9b1575c
|
add 2620:98:4002::/48 to port 53 for demonreach.asininetech.net.rules.v6
|
2020-03-04 17:16:48 -05:00 |
staticsafe
|
a0d1c0598d
|
remove port 1723 from demonreach.asininetech.net.rules.v4
|
2020-03-04 13:49:55 -05:00 |
staticsafe
|
12e58f3c01
|
add port 1723 to demonreach.asininetech.net.rules.v4
|
2020-03-04 13:45:18 -05:00 |
staticsafe
|
907b86492b
|
add a DROP rule in deirdre.asininetech.net.rules.v4
|
2020-02-25 23:31:22 -05:00 |
staticsafe
|
e866d062a9
|
add AlkonavtNetwork subnet to drop list on deirdre.asininetech.net.rules.v4
|
2020-02-20 14:46:21 -05:00 |
staticsafe
|
db59ab205e
|
add rule to drop SearchAtlas crawler
|
2020-02-20 14:26:02 -05:00 |
staticsafe
|
c6997dcd39
|
add drop for Seekport crawler IP to deirdre and waldo
|
2020-02-14 19:29:13 -05:00 |
staticsafe
|
9766d2ced5
|
Add vhost for ultonomy.com.
|
2020-01-22 10:46:15 -05:00 |
staticsafe
|
2af73d2d4e
|
allow ES traffic over Tinc VPN
|
2020-01-19 10:35:58 -05:00 |
staticsafe
|
bc92c9d437
|
Port opening for Tinc
|
2020-01-18 20:49:05 -05:00 |
staticsafe
|
a4c0bcde30
|
min heap size 4g
|
2020-01-18 18:56:24 -05:00 |
staticsafe
|
42bf05965b
|
increase min heap size to 2g
|
2020-01-18 18:54:41 -05:00 |
staticsafe
|
2c83554698
|
elasticsearch_version should be 6.x
|
2020-01-18 18:49:03 -05:00 |
staticsafe
|
869d80e6f7
|
we need to secure port 9300 on namshiel as well
|
2020-01-18 18:00:08 -05:00 |
staticsafe
|
201f4a35ca
|
min heap size to 1g?
|
2020-01-18 17:39:47 -05:00 |
staticsafe
|
6f0febf806
|
needs min heap size?
|
2020-01-18 17:36:56 -05:00 |
staticsafe
|
d810ba667e
|
let's try again?
|
2020-01-18 17:34:00 -05:00 |
staticsafe
|
d0976ca7fb
|
fix formatting on namshiel-elasticsearch.asininetech.net.yml?
|
2020-01-18 17:33:01 -05:00 |
staticsafe
|
e306a60ea6
|
add namshiel related files
|
2020-01-18 17:29:03 -05:00 |