Commit Graph

414 Commits

Author SHA1 Message Date
staticsafe 05176fb83e don't destroy ipset in main.yml 2020-04-15 10:15:37 -04:00
staticsafe 3fb3507d40 make some more explicit requirements in ipset.service 2020-04-15 10:14:05 -04:00
staticsafe 8aa1d869ba clean up unnecessary comments in firewall rulesets 2020-04-14 22:41:05 -04:00
staticsafe a7888e95bf set FLUSH_ON_STOP to 0 2020-04-14 22:36:13 -04:00
staticsafe 358b88ea60 we use a default file for netfilter-persistent 2020-04-14 22:29:56 -04:00
staticsafe 14c62687a7 ipset service stop destroy 2020-04-14 22:16:02 -04:00
staticsafe 53d62d54f5 let's try this again with destroy 2020-04-14 22:15:06 -04:00
staticsafe 377a5bcebf temporarily comment out firewall rule 2020-04-14 22:12:03 -04:00
staticsafe 58c0b0e2c1 always reload systemd 2020-04-14 22:09:46 -04:00
staticsafe 3abbcbbd9e use flush instead of destroy in ipset everywhere 2020-04-14 22:07:16 -04:00
staticsafe 92f286bbd6 should be src for ipset based rule 2020-04-14 22:03:31 -04:00
staticsafe c267ec243f use ipset instead of a bunch of INPUTs 2020-04-14 22:02:50 -04:00
staticsafe 0d7df674ec dont use handler 2020-04-14 21:56:14 -04:00
staticsafe 02a376b367 restart ipset service instead of start and use handler 2020-04-14 21:52:51 -04:00
staticsafe 1430497f5c move order of ipset destroy up 2020-04-14 21:47:16 -04:00
staticsafe 696bf3348f fix syntax error in ubuntu/roles/ipset-deploy/tasks/main.yml 2020-04-14 21:44:55 -04:00
staticsafe ce39f769a2 add ipset-deploy role 2020-04-14 21:42:03 -04:00
staticsafe 835384a24d add rulesets for uriel.asininetech.net. 2020-04-04 19:19:53 -04:00
staticsafe 66eebc37d3 add moz.com crawler to firewall block list on web servers 2020-03-28 23:10:00 -04:00
staticsafe 07cf97fa21 add rpcbind to list of packages we remove on setup 2020-03-27 13:08:12 -04:00
staticsafe 114970ec4b Use a more generic sshd_config with our options. 2020-03-24 11:15:43 -04:00
staticsafe 1f1bf5147b common role is now copying over a sshd_config 2020-03-24 10:27:23 -04:00
staticsafe 1de56b96b9 remove grevane.asininetech.net.rules.*, not needed anymore 2020-03-23 11:26:08 -04:00
staticsafe c1b3d2a171 clean up nginx_remove_sites 2020-03-09 20:38:56 -04:00
staticsafe 6613d75162 remove sadiqsaif.ca and staticsafe.ca vhosts 2020-03-09 19:26:22 -04:00
staticsafe 7fb64da246 no need for 127/8 rules in demonreach.asininetech.net.rules.v4 2020-03-08 22:56:18 -04:00
staticsafe 10c45c850b DNS resolving issues in demonreach.asininetech.net.rules.v4? 2020-03-08 15:58:13 -04:00
staticsafe f9e74ee5aa allow TCP DNS as well for VPN subnet 2020-03-04 17:50:43 -05:00
staticsafe 13f9b1575c add 2620:98:4002::/48 to port 53 for demonreach.asininetech.net.rules.v6 2020-03-04 17:16:48 -05:00
staticsafe a0d1c0598d remove port 1723 from demonreach.asininetech.net.rules.v4 2020-03-04 13:49:55 -05:00
staticsafe 12e58f3c01 add port 1723 to demonreach.asininetech.net.rules.v4 2020-03-04 13:45:18 -05:00
staticsafe 907b86492b add a DROP rule in deirdre.asininetech.net.rules.v4 2020-02-25 23:31:22 -05:00
staticsafe e866d062a9 add AlkonavtNetwork subnet to drop list on deirdre.asininetech.net.rules.v4 2020-02-20 14:46:21 -05:00
staticsafe db59ab205e add rule to drop SearchAtlas crawler 2020-02-20 14:26:02 -05:00
staticsafe c6997dcd39 add drop for Seekport crawler IP to deirdre and waldo 2020-02-14 19:29:13 -05:00
staticsafe 9766d2ced5 Add vhost for ultonomy.com. 2020-01-22 10:46:15 -05:00
staticsafe 2af73d2d4e allow ES traffic over Tinc VPN 2020-01-19 10:35:58 -05:00
staticsafe bc92c9d437 Port opening for Tinc 2020-01-18 20:49:05 -05:00
staticsafe a4c0bcde30 min heap size 4g 2020-01-18 18:56:24 -05:00
staticsafe 42bf05965b increase min heap size to 2g 2020-01-18 18:54:41 -05:00
staticsafe 2c83554698 elasticsearch_version should be 6.x 2020-01-18 18:49:03 -05:00
staticsafe 869d80e6f7 we need to secure port 9300 on namshiel as well 2020-01-18 18:00:08 -05:00
staticsafe 201f4a35ca min heap size to 1g? 2020-01-18 17:39:47 -05:00
staticsafe 6f0febf806 needs min heap size? 2020-01-18 17:36:56 -05:00
staticsafe d810ba667e let's try again? 2020-01-18 17:34:00 -05:00
staticsafe d0976ca7fb fix formatting on namshiel-elasticsearch.asininetech.net.yml? 2020-01-18 17:33:01 -05:00
staticsafe e306a60ea6 add namshiel related files 2020-01-18 17:29:03 -05:00
staticsafe a0e26301cf deirdre should be able to talk outbound 9200 for ES 2020-01-18 17:17:51 -05:00
staticsafe d384b41e75 cleanup i.asininetech.com. 2020-01-16 18:17:01 -05:00
staticsafe 748ddb1008 remove i.asininetech.com. 2020-01-16 18:09:51 -05:00
staticsafe 9e1e20d33f Remove port 4949 from allowed ports
deirdre no longer using munin-node
2020-01-06 10:17:29 -05:00
staticsafe da2f7aef93 Remove catsith.asininetech.net.rules.v4 and catsith.asininetech.net.rules.v6
catsith is gone
2020-01-06 10:16:20 -05:00
staticsafe 3b73edf491 add firewall rule to drop aggressive crawler in catsith.asininetech.net.rules.v6 2019-12-23 18:40:54 -05:00
staticsafe 85d19dd3a0 add ipset package install to ubuntu/roles/firewall-ruleset-deploy/tasks/main.yml 2019-11-17 16:22:27 -05:00
staticsafe 48e67daf37 remove duplicity/python-boto, add postfix, mailutils 2019-11-16 23:12:22 -05:00
staticsafe 7cc0101f0d change Unattended-Upgrade::Remove-Unused-Dependencies in 50unattended-upgrades 2019-10-29 12:06:14 -04:00
staticsafe 87e7452be6 Remove apt-maintenance.sh as it isn't needed anymore. 2019-10-29 10:39:54 -04:00
staticsafe da7c56eeb5 Update ubuntu/site.yml for unattended-upgrades task 2019-10-29 10:37:11 -04:00
staticsafe 18188cb971 Switch to using unattended-upgrades for apt-maintenance. 2019-10-29 10:35:24 -04:00
staticsafe 5703b44e75 update last task name in ubuntu/roles/apt-maintenance/tasks/main.yml 2019-10-29 10:18:09 -04:00
staticsafe c951fe766d We are disabling the apt-maintenance cron job for now. 2019-10-29 10:13:27 -04:00
staticsafe 4d30f0245e add vhost for irreverent.space to ubuntu/erlking.asininetech.net.yml 2019-10-23 23:35:15 -04:00
staticsafe 05283b00ef Copy pgbackrest logrotate config as well 2019-10-20 21:53:09 -04:00
staticsafe fbb5391eae Permissions for pgbackrest binary should be 755. 2019-10-20 21:28:45 -04:00
staticsafe 665d24a6cb fix typo in ubuntu/site.yml 2019-10-20 21:04:25 -04:00
staticsafe 74f35940f3 Add pgbackrest-install role 2019-10-20 21:02:36 -04:00
staticsafe ab33cd0200 Add yet another Bytespider range to block list to firewall rules. 2019-10-17 12:20:28 -04:00
staticsafe 7c7ff101e5 Missed a Bytespider crawler range 2019-10-17 12:03:15 -04:00
staticsafe f5d7c6dc39 Block aggressive Bytespider crawler across web servers 2019-10-17 11:58:42 -04:00
staticsafe afa8aa556c Add firewall rules to drop kiwifarms subnets. 2019-10-11 00:00:45 -04:00
staticsafe 7152d8d5f2 should be multiports 2019-10-04 09:44:14 -04:00
staticsafe d16ec626e1 add OUTPUT rules to allow DHCP on restricted nodes 2019-10-04 09:42:26 -04:00
staticsafe 90d4342ac2 cleanup some more 2019-09-29 22:54:53 -04:00
staticsafe 63490bb22b char.packet.cat is now removed, clean up 2019-09-29 22:54:02 -04:00
staticsafe 4100790fa9 Remove char.packet.cat. 2019-09-29 22:50:57 -04:00
staticsafe e419d3aefb add drop rule for 159.149.133.66 to deirdre.asininetech.net.rules.v4 2019-09-16 12:05:46 -04:00
staticsafe bd8a5c8435 Increase worker_connections across the board. 2019-09-03 14:20:40 -04:00
staticsafe e9ec840823 increase nginx worker_connections to 1024 in ubuntu/deirdre.asininetech.net.yml 2019-09-03 14:07:14 -04:00
staticsafe 0a3cae443f rename some files to new hostnames. 2019-09-03 14:03:12 -04:00
staticsafe 4c23562144 add handlers to firewall-ruleset-deploy 2019-08-25 21:08:39 -04:00
staticsafe 3002276209 clean up of firewall rulesets
remove byte counters, remove chains that didn't need to be there
2019-08-21 23:42:07 -04:00
staticsafe 8e471b7254 add COMMIT after end of filter 2019-08-21 23:23:58 -04:00
staticsafe df177dd04b clear out packet values in demonreach.asininetech.net.rules.v4 2019-08-21 23:21:17 -04:00
staticsafe 83fcf86900 POSTROUTING should be in nat chain 2019-08-21 23:20:41 -04:00
staticsafe e86367ed83 add firewall rulesets for demonreach.asininetech.net. 2019-08-21 23:18:16 -04:00
staticsafe ab7979ce01 add firewall rulesets for grevane.asininetech.net. 2019-08-21 22:46:53 -04:00
staticsafe 135e9bd008 add firewall rulesets for erlking.asininetech.net. 2019-08-21 22:37:20 -04:00
staticsafe d411bc74dd add firewall rulesets for deirdre.asininetech.net. 2019-08-21 22:26:34 -04:00
staticsafe ee1e6fb76f add firewall rulesets for catsith.asininetech.net 2019-08-21 22:23:10 -04:00
staticsafe 8b77463939 turn off backups in firewall-ruleset-deploy/tasks/main.yml 2019-08-21 22:15:34 -04:00
staticsafe 985895c082 add firewall rulesets for waldo.asininetech.net. 2019-08-21 22:12:42 -04:00
staticsafe df3044c9f3 fix another error in gard.asininetech.net.rules.v6 2019-08-21 22:07:24 -04:00
staticsafe ecda411031 fix syntax error in gard.asininetech.net.rules.v6 2019-08-21 22:02:55 -04:00
staticsafe 70fb7c8212 maybe fully enclosed? 2019-08-21 22:00:48 -04:00
staticsafe 62530669c9 double quotes maybe? 2019-08-21 21:58:10 -04:00
staticsafe 89e35f402b add quotes around ansible_fqdn 2019-08-21 21:56:43 -04:00
staticsafe 7705504cf7 add firewall-ruleset-deploy to site.yml 2019-08-21 21:53:38 -04:00
staticsafe f1623be2e9 add firewall-ruleset-deploy playbook and gard's ruleset 2019-08-21 21:52:12 -04:00
staticsafe de780e0254 make sure iptables-persistent and netfilter-persistent is installed via common playbook 2019-08-21 18:45:56 -04:00
staticsafe a4b94b8ded add char.packet.cat conf 2019-07-27 11:57:05 -04:00
staticsafe c074a6bb0a add wiki.tenforward.social configs 2019-07-27 11:28:12 -04:00
staticsafe b7f3e9b2c2 removed erroneous block 2019-07-26 23:42:18 -04:00
staticsafe 74d3a686a5 add as393949.net vhost 2019-07-26 23:39:26 -04:00
staticsafe 7b42ceeca2 Remove warn=false in ubuntu/roles/common/tasks/main.yml 2019-07-21 20:43:43 -04:00
staticsafe 8d6bcde072 set warn=False for non-module apt task 2019-07-21 20:43:06 -04:00
staticsafe 32190262bc stop using with_items for apt in ubuntu/roles/common/tasks/main.yml 2019-07-21 20:34:13 -04:00
staticsafe 26d749a670 make sure PATH is set in ubuntu/roles/apt-maintenance/files/apt-maintenance.sh 2019-07-14 08:18:44 -04:00
staticsafe c82b4f2ccf remove MAILTO from apt-maintenance.sh 2019-07-12 23:42:20 -04:00
staticsafe c1e39c3f73 remove insertafter from ubuntu/roles/apt-maintenance/tasks/main.yml 2019-07-12 23:40:21 -04:00
staticsafe e7865d16c9 Add MAILTO variable addition into apt-maintenance/tasks/main.yml 2019-07-12 23:39:01 -04:00
staticsafe 616b5c1a83 make sure /root/scripts exists 2019-07-12 23:13:48 -04:00
staticsafe 1ca719c43f Copy script to dif location and add cronjob to root 2019-07-12 23:11:51 -04:00
staticsafe e698c4a809 Change permission of script to 755 2019-07-12 11:30:46 -04:00
staticsafe cd6efefd3f turn off backups for apt-maintenance/tasks/main.yml 2019-07-10 10:15:54 -04:00
staticsafe d0452a3e95 modify apt-maintenance.sh to add a mailto addr 2019-07-10 10:13:44 -04:00
staticsafe 4761744224 add apt-maintenance defs in ubuntu/site.yml 2019-07-07 20:04:04 -04:00
staticsafe acdb50458f Add apt-maintenance role 2019-07-07 20:00:42 -04:00
Sadiq Saif 785924e5ba
Update dev-glitch nginx to use TLSv1.3 2019-07-03 21:11:04 -04:00
Sadiq Saif 178a01cba2
Delete mercy.sickstack.com.yml
server terminated
2019-07-03 21:07:42 -04:00
Sadiq Saif 06ddcd9929
Delete mei.sickstack.com.yml
server terminated
2019-07-03 21:07:06 -04:00
Sadiq Saif ebfc8eff5c
Delete ivy.asininetech.com.yml
server terminated
2019-07-03 21:06:48 -04:00
Sadiq Saif b1e6c25fbf
Delete aphrodite.selfie.town config
Server terminated
2019-07-03 21:06:26 -04:00
Sadiq Saif 6241b2e321
Update tfmain nginx to use TLSv1.3 2019-07-03 21:06:03 -04:00
Sadiq Saif 075c8cd1ec
Update mastodon.zombocloud.com's nginx config to use TLSv1.3 2019-07-03 21:05:08 -04:00
Sadiq Saif b21cf6176c
Update webserver1 nginx config to use TLSv1.3 2019-07-03 21:04:35 -04:00
staticsafe c76ff142ab Rename the yml file for ivy 2019-03-23 19:42:51 -04:00
staticsafe ad9cc8af24 remove invalid variables in grafana 2019-03-23 16:42:01 -04:00
staticsafe 8c4b104f35 Change grafana listen to localhost 2019-03-23 16:37:13 -04:00
staticsafe e4563e9c30 add webserver config to ubuntu/prometheus.sickstack.com.yml 2019-03-23 15:45:38 -04:00
staticsafe 07c937e944 remove include from ubuntu/prometheus.sickstack.com.yml 2019-03-23 13:13:58 -04:00
staticsafe a6b4f8fafc include should in vars? 2019-03-23 12:59:59 -04:00
staticsafe be0c6f6c32 include secrets.yml for ubuntu/prometheus.sickstack.com.yml 2019-03-23 12:54:10 -04:00
staticsafe 7992363f14 add grafana to ubuntu/prometheus.sickstack.com.yml 2019-03-23 12:48:55 -04:00
staticsafe 49f6e93d96 add netdata.internal.sickstack.com to server_name
in ubuntu/mei.sickstack.com.yml
2019-03-23 11:51:59 -04:00
staticsafe e94bc70c6d eh? 2019-03-23 11:28:49 -04:00
staticsafe d63b44bc6f okay maybe this one? 2019-03-23 11:22:49 -04:00
staticsafe 9aae6acae5 okay I think this is the right format? 2019-03-23 11:20:55 -04:00
staticsafe 19250e5b21 let's try a different format 2019-03-23 11:17:52 -04:00
staticsafe 89c3f8d997 complete prometheus.sickstack.com.yml 2019-03-23 11:16:03 -04:00
staticsafe faa099e917 add ubuntu/prometheus.sickstack.com.yml 2019-03-23 11:07:06 -04:00
staticsafe 6540d059d7 turn off access logging in netdata 2019-03-19 13:05:44 -04:00
staticsafe 2f54131368 Add ubuntu/mei.sickstack.com.yml 2019-03-19 11:11:14 -04:00
staticsafe e0f2bedf62 Use variable method for listing package installs in ubuntu/roles/icinga-client/tasks/main.yml 2019-02-03 13:35:19 -05:00
staticsafe 279b4e10f0 Modify icinga-client role to add some systemd options 2019-02-03 13:11:39 -05:00
staticsafe aa14f2f64f Merge branch 'nextgen' of github.com:staticsafe/ansible-playbooks into nextgen 2019-01-19 18:31:01 -05:00
staticsafe aff6f703ed Add ubuntu/dev.glitch.social.yml 2019-01-19 18:30:53 -05:00
Sadiq Saif 94ae12002a
Update package removal list
add snapd and lxcfs to removal list
2019-01-15 21:22:27 -05:00
staticsafe 1f81721ab6 Remove letsencrypt from packages list. 2019-01-12 15:13:10 -05:00
staticsafe 040efa346f Add ubuntu/aphrodite.selfie.town.yml 2018-12-29 11:43:19 -05:00
staticsafe d6dd8b95c3 Add ubuntu/aphrodite.selfie.town.yml and remove selfie.town config from mercy.sickstack.com.yml 2018-12-29 11:42:36 -05:00
staticsafe f27f5135a4 common configuration should include turning off MOTD 2018-09-25 21:02:34 -04:00
staticsafe df28d10f01 hosts group should be myubuntunodes 2018-09-25 20:40:33 -04:00
staticsafe 482bbc8cf1 add turn-off-motd-news role 2018-09-25 20:38:53 -04:00
Sadiq Saif eb4ca4c8fe
Update PHP upstream to 7.2 2018-08-26 12:04:52 -04:00
staticsafe 3ff719370f Remove pixelfed upstream from nginx config 2018-08-25 22:29:30 -04:00
staticsafe 05f8b1a1a0 client_max_body_size 0 for selfie.town 2018-08-25 21:47:01 -04:00
staticsafe f5a495818f Switch back to default pool for pixelfed 2018-08-25 21:38:28 -04:00
staticsafe c011cc7485 Use separate PHP upstream for pixelfed 2018-08-25 21:29:48 -04:00
staticsafe a887f9615b Add selfie.town vhost to ubuntu/mercy.sickstack.com.yml 2018-08-25 20:57:09 -04:00
staticsafe c1ebd44be3 Add HTTP to HTTPS redirect for wiki.sickstack.com 2018-06-10 15:53:16 -04:00
staticsafe 62f285f786 Add wiki.sickstack.com vhost 2018-06-10 15:51:31 -04:00
staticsafe 40e6a57afa Add GD to the PHP extensions list 2018-06-10 15:40:42 -04:00
staticsafe 7d06e18935 add PHP upstream config to ubuntu/mercy.sickstack.com.yml 2018-06-10 13:16:32 -04:00
staticsafe f5d3828f3c Add some Ubuntu version conditionals to ubuntu/roles/php/tasks/main.yml 2018-06-10 13:11:12 -04:00
staticsafe 4d992b8fc7 Add a LEMP stack combo to ubuntu/site.yml 2018-06-10 13:04:44 -04:00
staticsafe e0e30edeb0 Add MySQL role to ubuntu/site.yml 2018-06-10 12:47:46 -04:00
staticsafe 02e8237c42 Add MySQL server role 2018-06-10 12:41:02 -04:00
staticsafe 4874d5fcfc proxy_pass for gitea is using localhost now 2018-06-05 10:14:00 -04:00
staticsafe 53d757c46a Change gitea proxy_pass to use HTTPS 2018-06-05 09:47:20 -04:00
staticsafe 180f53774f Remove cryptpad.sickstack.com vhost 2018-06-04 22:53:20 -04:00
staticsafe eac8443003 Add cryptpad.sickstack.com vhost 2018-06-04 22:39:32 -04:00
staticsafe f5683efd4b Make the icinga role Ubuntu version agnostic 2018-06-03 18:15:46 -04:00
staticsafe 270497f949 should say git.sickstack.com for nginx config filenames 2018-06-03 18:09:26 -04:00
staticsafe dad8e5a6a4 Add ubuntu/mercy.sickstack.com.yml 2018-06-03 18:08:41 -04:00
Sadiq Saif 181d95e78e
add client_max_body_size 2018-04-13 15:36:22 -04:00
Sadiq Saif c7c6806689
Add client_max_body_size 2018-04-13 15:36:01 -04:00
staticsafe 9eb9954845 Add ubuntu/tfmain.tenforward.social.yml 2018-04-08 19:07:09 -04:00
staticsafe b99eea2a6c Forgot to remove some semi-colons in ubuntu/mastodon.zombocloud.com.yml 2018-04-08 18:56:10 -04:00
staticsafe 1128317729 Add ssl config to ubuntu/mastodon.zombocloud.com.yml 2018-04-08 18:55:33 -04:00
staticsafe 11f7b2f07e another quotes situation 2018-04-08 18:48:06 -04:00
staticsafe 2d229a436d god I hate this quote situation 2018-04-08 18:45:26 -04:00
staticsafe 6c65f62aa3 remove quotes around referrer-policy and add HSTS back in 2018-04-08 18:42:56 -04:00
staticsafe 829e337ef1 Remove HSTS header add 2018-04-08 18:40:39 -04:00
staticsafe 5828fd6d89 can we escape the semi-colons maybe? 2018-04-08 18:39:15 -04:00
staticsafe 539b844d5a another try 2018-04-08 18:36:39 -04:00
staticsafe 99d70a22af this quote situation is getting out of hand 2018-04-08 18:33:34 -04:00
staticsafe b1e0d39af1 add some quotes around add_header in ubuntu/mastodon.zombocloud.com.yml 2018-04-08 18:30:58 -04:00
staticsafe d8ebe62efd Remove some semi-colons from ubuntu/mastodon.zombocloud.com.yml 2018-04-08 18:28:02 -04:00
staticsafe 8eb16489c8 Remove comment from ubuntu/mastodon.zombocloud.com.yml 2018-04-08 18:26:26 -04:00
staticsafe ff0eee420b add ubuntu/mastodon.zombocloud.com.yml 2018-04-08 18:24:13 -04:00
staticsafe a85dfac3fc Move webserver1's nginx config to its own YAML file 2018-04-08 14:38:42 -04:00
staticsafe bf36cacc89 Remove LetsEncrypt role, it is no longer useful. 2018-04-08 14:35:06 -04:00
Sadiq Saif 2dd075b853
Check that chrony service is enabled instead of ntpd 2018-02-12 17:21:28 -05:00
Sadiq Saif 0aad55187b
Replace ntpd with chrony 2018-02-12 17:20:52 -05:00
staticsafe 3c428e0781 Replace 8.8.8.8 with [::1] in ubuntu/site.yml 2018-02-12 10:34:16 -05:00
staticsafe d0814a5657 Use wildcard v4 listeners in nginx 2018-02-06 11:42:11 -05:00
staticsafe 1874de7c22 nginx does not need to bind to a specific address
just bind to all addresses on the required ports
2018-01-14 20:28:16 -05:00
Sadiq Saif 6215dbcfc6
Remove netdata upstream 2017-12-17 23:58:00 -05:00
staticsafe 8174e2d60f Fix missing repo string in ubuntu/roles/icinga-client/tasks/main.yml 2017-11-27 14:26:24 -05:00
staticsafe 508e73ff39 Fix another typo in ubuntu/site.yml 2017-11-27 14:24:02 -05:00