Commit Graph

167 Commits

Author SHA1 Message Date
staticsafe
4085481ed0 remove elasticsearch ports from deirdre firewall rules 2021-04-05 09:18:06 -04:00
staticsafe
9aec73785d add rules to allow outbound NTP to deirdre 2021-04-05 08:29:25 -04:00
staticsafe
2fb9123db3 update IP range for Infegy bot to 173.244.135.0/25 2021-03-20 19:01:08 -04:00
staticsafe
45935b847a remove old ipset block of Comcast dynamic IP 2021-03-20 18:56:52 -04:00
staticsafe
0b3265d75c add a new IP into deirdre and erlking ipsets
remove waldo ipsets and rules
2021-03-17 09:56:10 -04:00
staticsafe
1541a24467 add package-update role 2021-01-17 19:14:41 -05:00
staticsafe
3cb30d2985 add aliases copy task to common play 2020-12-01 10:31:07 -05:00
staticsafe
db53abe225 remove zsh from common packages install list 2020-11-29 09:21:54 -05:00
staticsafe
2860f23b85 add net-tools to common packages install list 2020-11-29 09:21:03 -05:00
staticsafe
2d2e5a78c5 we should set hostname before package installation 2020-11-25 16:20:30 -05:00
staticsafe
42b6960609 add 217.160.142.105 to ipset 2020-10-28 10:40:14 -04:00
staticsafe
8ac714f548 consolidate adsbot prefixes into two /24s 2020-10-15 13:15:06 -04:00
staticsafe
87c531e0c5 update adsbot prefixes 2020-10-12 09:10:40 -04:00
staticsafe
4343fdf1f6 install python-is-python3 as part of common role 2020-10-11 14:37:53 -04:00
staticsafe
4e96352e88 add another adsbot IP into the ipset 2020-09-23 11:00:00 -04:00
staticsafe
340637ef19 add another subnet of Aspiegel bot 2020-09-12 12:19:39 -04:00
staticsafe
c28997cd60 add another adsbot IP to nasties ipset 2020-09-11 19:47:15 -04:00
staticsafe
4f7b399783 add another adsbot IP to ipset list 2020-09-09 09:27:07 -04:00
staticsafe
10ba23f5d6 add another Adsbot IP to the nasties ipset 2020-09-07 12:40:23 -04:00
staticsafe
4d0660e162 quotes needed 2020-08-22 19:03:10 -04:00
staticsafe
1bd0269944 make sure to set hostname on new nodes and turn off motd news on focal 2020-08-22 19:00:56 -04:00
staticsafe
2d45e87d98 remove sshd_config copy in common role
its in ssh-enforcement now
2020-08-22 18:43:35 -04:00
staticsafe
2bfed5b9ed add ssh-enforcement playbook 2020-08-22 15:47:23 -04:00
Sadiq Saif
b6946a3e26
Update pgbackrest version to 2.28 2020-08-18 08:40:19 -04:00
staticsafe
d2b0e47564 add Adsbot IPs to webserver ipsets 2020-07-29 08:46:33 -04:00
staticsafe
4ea258d17b add 149.248.4.242 to deirdre.asininetech.net.ipset 2020-07-05 14:34:47 -04:00
staticsafe
71fc82ed22 remove namshiel.asininetech.net.rules.* 2020-07-05 14:33:29 -04:00
staticsafe
f5f09ebc58 add 2001:19f0:6001:5aa0:5400:2ff:fecf:eee5 to drop for deirdre 2020-07-05 14:31:44 -04:00
staticsafe
7426c88be2 add 75.64.236.168/32 to deirdre and waldo ipset 2020-06-27 17:31:15 -04:00
staticsafe
f091373a1b add yet another pimeyes.com crawler IP to ipset 2020-06-01 23:31:36 -04:00
staticsafe
07badc1ff1 add another pimeyes crawler IP to ipset 2020-06-01 23:17:07 -04:00
staticsafe
c69b2dda9a add another pimeyes.com crawler IP 2020-05-27 21:05:14 -04:00
staticsafe
146fd41a7f add pimeeyes.com crawler IP to nasties ipset 2020-05-27 21:01:18 -04:00
staticsafe
e1c36822fa add a centurybot IP to nasties ipset 2020-05-27 13:44:27 -04:00
staticsafe
4fbedfec4e add Aspiegel bot range to nasties ipset 2020-05-19 13:24:00 -04:00
staticsafe
4c573cb5a0 remove python-pip and python-dev from common role 2020-04-23 16:55:18 -04:00
staticsafe
27b9e93b0d reference nasties ipset for erlking and waldo 2020-04-15 10:54:52 -04:00
staticsafe
fd475f98cb add some more ipsets for erlking and waldo 2020-04-15 10:52:33 -04:00
staticsafe
d8f5681c52 fix typo in ipset.service 2020-04-15 10:26:29 -04:00
staticsafe
dd4d335302 make ipset.service import even if ipset already exists and then reload in main.yml 2020-04-15 10:24:02 -04:00
staticsafe
05176fb83e don't destroy ipset in main.yml 2020-04-15 10:15:37 -04:00
staticsafe
3fb3507d40 make some more explicit requirements in ipset.service 2020-04-15 10:14:05 -04:00
staticsafe
8aa1d869ba clean up unnecessary comments in firewall rulesets 2020-04-14 22:41:05 -04:00
staticsafe
a7888e95bf set FLUSH_ON_STOP to 0 2020-04-14 22:36:13 -04:00
staticsafe
358b88ea60 we use a default file for netfilter-persistent 2020-04-14 22:29:56 -04:00
staticsafe
14c62687a7 ipset service stop destroy 2020-04-14 22:16:02 -04:00
staticsafe
53d62d54f5 let's try this again with destroy 2020-04-14 22:15:06 -04:00
staticsafe
377a5bcebf temporarily comment out firewall rule 2020-04-14 22:12:03 -04:00
staticsafe
58c0b0e2c1 always reload systemd 2020-04-14 22:09:46 -04:00
staticsafe
3abbcbbd9e use flush instead of destroy in ipset everywhere 2020-04-14 22:07:16 -04:00