Commit Graph

157 Commits

Author SHA1 Message Date
staticsafe
114970ec4b Use a more generic sshd_config with our options. 2020-03-24 11:15:43 -04:00
staticsafe
1f1bf5147b common role is now copying over a sshd_config 2020-03-24 10:27:23 -04:00
staticsafe
1de56b96b9 remove grevane.asininetech.net.rules.*, not needed anymore 2020-03-23 11:26:08 -04:00
staticsafe
7fb64da246 no need for 127/8 rules in demonreach.asininetech.net.rules.v4 2020-03-08 22:56:18 -04:00
staticsafe
10c45c850b DNS resolving issues in demonreach.asininetech.net.rules.v4? 2020-03-08 15:58:13 -04:00
staticsafe
f9e74ee5aa allow TCP DNS as well for VPN subnet 2020-03-04 17:50:43 -05:00
staticsafe
13f9b1575c add 2620:98:4002::/48 to port 53 for demonreach.asininetech.net.rules.v6 2020-03-04 17:16:48 -05:00
staticsafe
a0d1c0598d remove port 1723 from demonreach.asininetech.net.rules.v4 2020-03-04 13:49:55 -05:00
staticsafe
12e58f3c01 add port 1723 to demonreach.asininetech.net.rules.v4 2020-03-04 13:45:18 -05:00
staticsafe
907b86492b add a DROP rule in deirdre.asininetech.net.rules.v4 2020-02-25 23:31:22 -05:00
staticsafe
e866d062a9 add AlkonavtNetwork subnet to drop list on deirdre.asininetech.net.rules.v4 2020-02-20 14:46:21 -05:00
staticsafe
db59ab205e add rule to drop SearchAtlas crawler 2020-02-20 14:26:02 -05:00
staticsafe
c6997dcd39 add drop for Seekport crawler IP to deirdre and waldo 2020-02-14 19:29:13 -05:00
staticsafe
2af73d2d4e allow ES traffic over Tinc VPN 2020-01-19 10:35:58 -05:00
staticsafe
bc92c9d437 Port opening for Tinc 2020-01-18 20:49:05 -05:00
staticsafe
869d80e6f7 we need to secure port 9300 on namshiel as well 2020-01-18 18:00:08 -05:00
staticsafe
e306a60ea6 add namshiel related files 2020-01-18 17:29:03 -05:00
staticsafe
a0e26301cf deirdre should be able to talk outbound 9200 for ES 2020-01-18 17:17:51 -05:00
staticsafe
9e1e20d33f Remove port 4949 from allowed ports
deirdre no longer using munin-node
2020-01-06 10:17:29 -05:00
staticsafe
da2f7aef93 Remove catsith.asininetech.net.rules.v4 and catsith.asininetech.net.rules.v6
catsith is gone
2020-01-06 10:16:20 -05:00
staticsafe
3b73edf491 add firewall rule to drop aggressive crawler in catsith.asininetech.net.rules.v6 2019-12-23 18:40:54 -05:00
staticsafe
85d19dd3a0 add ipset package install to ubuntu/roles/firewall-ruleset-deploy/tasks/main.yml 2019-11-17 16:22:27 -05:00
staticsafe
48e67daf37 remove duplicity/python-boto, add postfix, mailutils 2019-11-16 23:12:22 -05:00
staticsafe
7cc0101f0d change Unattended-Upgrade::Remove-Unused-Dependencies in 50unattended-upgrades 2019-10-29 12:06:14 -04:00
staticsafe
87e7452be6 Remove apt-maintenance.sh as it isn't needed anymore. 2019-10-29 10:39:54 -04:00
staticsafe
18188cb971 Switch to using unattended-upgrades for apt-maintenance. 2019-10-29 10:35:24 -04:00
staticsafe
5703b44e75 update last task name in ubuntu/roles/apt-maintenance/tasks/main.yml 2019-10-29 10:18:09 -04:00
staticsafe
c951fe766d We are disabling the apt-maintenance cron job for now. 2019-10-29 10:13:27 -04:00
staticsafe
05283b00ef Copy pgbackrest logrotate config as well 2019-10-20 21:53:09 -04:00
staticsafe
fbb5391eae Permissions for pgbackrest binary should be 755. 2019-10-20 21:28:45 -04:00
staticsafe
74f35940f3 Add pgbackrest-install role 2019-10-20 21:02:36 -04:00
staticsafe
ab33cd0200 Add yet another Bytespider range to block list to firewall rules. 2019-10-17 12:20:28 -04:00
staticsafe
7c7ff101e5 Missed a Bytespider crawler range 2019-10-17 12:03:15 -04:00
staticsafe
f5d7c6dc39 Block aggressive Bytespider crawler across web servers 2019-10-17 11:58:42 -04:00
staticsafe
afa8aa556c Add firewall rules to drop kiwifarms subnets. 2019-10-11 00:00:45 -04:00
staticsafe
7152d8d5f2 should be multiports 2019-10-04 09:44:14 -04:00
staticsafe
d16ec626e1 add OUTPUT rules to allow DHCP on restricted nodes 2019-10-04 09:42:26 -04:00
staticsafe
e419d3aefb add drop rule for 159.149.133.66 to deirdre.asininetech.net.rules.v4 2019-09-16 12:05:46 -04:00
staticsafe
4c23562144 add handlers to firewall-ruleset-deploy 2019-08-25 21:08:39 -04:00
staticsafe
3002276209 clean up of firewall rulesets
remove byte counters, remove chains that didn't need to be there
2019-08-21 23:42:07 -04:00
staticsafe
8e471b7254 add COMMIT after end of filter 2019-08-21 23:23:58 -04:00
staticsafe
df177dd04b clear out packet values in demonreach.asininetech.net.rules.v4 2019-08-21 23:21:17 -04:00
staticsafe
83fcf86900 POSTROUTING should be in nat chain 2019-08-21 23:20:41 -04:00
staticsafe
e86367ed83 add firewall rulesets for demonreach.asininetech.net. 2019-08-21 23:18:16 -04:00
staticsafe
ab7979ce01 add firewall rulesets for grevane.asininetech.net. 2019-08-21 22:46:53 -04:00
staticsafe
135e9bd008 add firewall rulesets for erlking.asininetech.net. 2019-08-21 22:37:20 -04:00
staticsafe
d411bc74dd add firewall rulesets for deirdre.asininetech.net. 2019-08-21 22:26:34 -04:00
staticsafe
ee1e6fb76f add firewall rulesets for catsith.asininetech.net 2019-08-21 22:23:10 -04:00
staticsafe
8b77463939 turn off backups in firewall-ruleset-deploy/tasks/main.yml 2019-08-21 22:15:34 -04:00
staticsafe
985895c082 add firewall rulesets for waldo.asininetech.net. 2019-08-21 22:12:42 -04:00
staticsafe
df3044c9f3 fix another error in gard.asininetech.net.rules.v6 2019-08-21 22:07:24 -04:00
staticsafe
ecda411031 fix syntax error in gard.asininetech.net.rules.v6 2019-08-21 22:02:55 -04:00
staticsafe
70fb7c8212 maybe fully enclosed? 2019-08-21 22:00:48 -04:00
staticsafe
62530669c9 double quotes maybe? 2019-08-21 21:58:10 -04:00
staticsafe
89e35f402b add quotes around ansible_fqdn 2019-08-21 21:56:43 -04:00
staticsafe
f1623be2e9 add firewall-ruleset-deploy playbook and gard's ruleset 2019-08-21 21:52:12 -04:00
staticsafe
de780e0254 make sure iptables-persistent and netfilter-persistent is installed via common playbook 2019-08-21 18:45:56 -04:00
staticsafe
7b42ceeca2 Remove warn=false in ubuntu/roles/common/tasks/main.yml 2019-07-21 20:43:43 -04:00
staticsafe
8d6bcde072 set warn=False for non-module apt task 2019-07-21 20:43:06 -04:00
staticsafe
32190262bc stop using with_items for apt in ubuntu/roles/common/tasks/main.yml 2019-07-21 20:34:13 -04:00
staticsafe
26d749a670 make sure PATH is set in ubuntu/roles/apt-maintenance/files/apt-maintenance.sh 2019-07-14 08:18:44 -04:00
staticsafe
c82b4f2ccf remove MAILTO from apt-maintenance.sh 2019-07-12 23:42:20 -04:00
staticsafe
c1e39c3f73 remove insertafter from ubuntu/roles/apt-maintenance/tasks/main.yml 2019-07-12 23:40:21 -04:00
staticsafe
e7865d16c9 Add MAILTO variable addition into apt-maintenance/tasks/main.yml 2019-07-12 23:39:01 -04:00
staticsafe
616b5c1a83 make sure /root/scripts exists 2019-07-12 23:13:48 -04:00
staticsafe
1ca719c43f Copy script to dif location and add cronjob to root 2019-07-12 23:11:51 -04:00
staticsafe
e698c4a809 Change permission of script to 755 2019-07-12 11:30:46 -04:00
staticsafe
cd6efefd3f turn off backups for apt-maintenance/tasks/main.yml 2019-07-10 10:15:54 -04:00
staticsafe
d0452a3e95 modify apt-maintenance.sh to add a mailto addr 2019-07-10 10:13:44 -04:00
staticsafe
acdb50458f Add apt-maintenance role 2019-07-07 20:00:42 -04:00
staticsafe
e0f2bedf62 Use variable method for listing package installs in ubuntu/roles/icinga-client/tasks/main.yml 2019-02-03 13:35:19 -05:00
staticsafe
279b4e10f0 Modify icinga-client role to add some systemd options 2019-02-03 13:11:39 -05:00
Sadiq Saif
94ae12002a
Update package removal list
add snapd and lxcfs to removal list
2019-01-15 21:22:27 -05:00
staticsafe
1f81721ab6 Remove letsencrypt from packages list. 2019-01-12 15:13:10 -05:00
staticsafe
482bbc8cf1 add turn-off-motd-news role 2018-09-25 20:38:53 -04:00
staticsafe
40e6a57afa Add GD to the PHP extensions list 2018-06-10 15:40:42 -04:00
staticsafe
f5d3828f3c Add some Ubuntu version conditionals to ubuntu/roles/php/tasks/main.yml 2018-06-10 13:11:12 -04:00
staticsafe
02e8237c42 Add MySQL server role 2018-06-10 12:41:02 -04:00
staticsafe
f5683efd4b Make the icinga role Ubuntu version agnostic 2018-06-03 18:15:46 -04:00
staticsafe
bf36cacc89 Remove LetsEncrypt role, it is no longer useful. 2018-04-08 14:35:06 -04:00
Sadiq Saif
2dd075b853
Check that chrony service is enabled instead of ntpd 2018-02-12 17:21:28 -05:00
Sadiq Saif
0aad55187b
Replace ntpd with chrony 2018-02-12 17:20:52 -05:00
staticsafe
8174e2d60f Fix missing repo string in ubuntu/roles/icinga-client/tasks/main.yml 2017-11-27 14:26:24 -05:00
staticsafe
6a74202168 Add icinga-client role. 2017-11-27 14:20:22 -05:00
Sadiq Saif
62709d3731 Add some custom APT periodic task configuration
Ensure that the periodic APT cron task clears out old kernels and does unattended security upgrades
2017-08-06 16:24:25 -04:00
Sadiq Saif
7969f8908d Add 10periodic file, APT Periodic task config 2017-08-06 16:21:10 -04:00
Sadiq Saif
3f9ab5a693 Add unattended-upgrades to package list
subversion was removed as we don't need it anymore
2017-08-06 16:03:17 -04:00
Sadiq Saif
7bb3478ea7 add netdata LE and change to webroot use 2017-07-17 22:55:15 -04:00
Sadiq Saif
fb6039aebf Update letsencrypt-renew
changes for webroot renewal
2017-07-16 19:43:34 -04:00
staticsafe
2da2ba0312 add sadiqsaif.com to LE domain list. 2017-03-17 02:34:27 +00:00
staticsafe
ef896a0f2f letsencrypt renew script had invalid arguments 2017-01-14 14:41:07 +00:00
staticsafe
0897a454ae PHP role is now installing required PHP libs.
Close issue #2
2017-01-14 14:17:50 +00:00
staticsafe
0d09eae129 Add nginx service conditional to LetsEncrypt role.
Resolve issue #1
2017-01-14 03:51:43 +00:00
staticsafe
03276432f4 Add LetsEncrypt roles for webserver use. 2017-01-13 22:21:21 +00:00
staticsafe
baf710fc32 PHP-FPM daemon should be in a started state. 2017-01-13 02:49:33 +00:00
staticsafe
eb644482c3 Fix YAML syntax error in roles/php/tasks/main.yml 2017-01-13 02:45:22 +00:00
staticsafe
2ed429d06a Add new basic PHP role. 2017-01-13 02:43:11 +00:00
staticsafe
f73a0972f5 Remove unbound from boot check list. 2017-01-12 20:27:22 +00:00
staticsafe
7bfc6267e1 We are no longer modifying host resolvers.
VPS provider defaults are sufficient.
2017-01-12 20:24:45 +00:00
staticsafe
05b4122862 Remove appservers-php and webservers-nginx roles.
We are going to be using Galaxy roles going forward.
2017-01-12 20:20:40 +00:00