Commit Graph

403 Commits

Author SHA1 Message Date
staticsafe
340637ef19 add another subnet of Aspiegel bot 2020-09-12 12:19:39 -04:00
staticsafe
c28997cd60 add another adsbot IP to nasties ipset 2020-09-11 19:47:15 -04:00
staticsafe
4f7b399783 add another adsbot IP to ipset list 2020-09-09 09:27:07 -04:00
staticsafe
10ba23f5d6 add another Adsbot IP to the nasties ipset 2020-09-07 12:40:23 -04:00
staticsafe
4d0660e162 quotes needed 2020-08-22 19:03:10 -04:00
staticsafe
1bd0269944 make sure to set hostname on new nodes and turn off motd news on focal 2020-08-22 19:00:56 -04:00
staticsafe
2d45e87d98 remove sshd_config copy in common role
its in ssh-enforcement now
2020-08-22 18:43:35 -04:00
staticsafe
e574b1d4de remove catsith.asininetech.net.yml
no longer needed
2020-08-22 16:44:50 -04:00
staticsafe
9aa40b3967 Clean up site.yml and move some other roles into their own yml files 2020-08-22 16:21:24 -04:00
staticsafe
b2bd30101b ssh-enforcement role should be run for unsetup hosts as well. 2020-08-22 15:59:38 -04:00
staticsafe
2bfed5b9ed add ssh-enforcement playbook 2020-08-22 15:47:23 -04:00
Sadiq Saif
b6946a3e26
Update pgbackrest version to 2.28 2020-08-18 08:40:19 -04:00
staticsafe
c73f1f6b7c add woff2 to static resources to be cached 2020-07-30 17:57:33 -04:00
staticsafe
d2b0e47564 add Adsbot IPs to webserver ipsets 2020-07-29 08:46:33 -04:00
staticsafe
36086ba967 fix an extraneous space in erlking.asininetech.net.yml 2020-07-27 15:26:12 -04:00
staticsafe
3715879e77 add WP caching config to other sites now 2020-07-27 13:42:50 -04:00
staticsafe
33c6fc78e2 fix extra bracket 2020-07-27 13:37:43 -04:00
staticsafe
b604283ce5 improve WP caching setup
testing on asininetech.com
2020-07-27 13:33:52 -04:00
staticsafe
91404bb5f1 remove extraneous ; 2020-07-26 19:27:42 -04:00
staticsafe
377568f7cd remove quotes 2020-07-26 19:26:46 -04:00
staticsafe
2e468240fd add new Access-Control-Allow-Origin header for Mastodon 3.2.0 2020-07-26 19:24:05 -04:00
staticsafe
1b6e048e43 cleanup as393949.net 2020-07-18 22:41:10 -04:00
staticsafe
8dd8505d0a remove as393949.net 2020-07-18 22:21:41 -04:00
staticsafe
4ea258d17b add 149.248.4.242 to deirdre.asininetech.net.ipset 2020-07-05 14:34:47 -04:00
staticsafe
71fc82ed22 remove namshiel.asininetech.net.rules.* 2020-07-05 14:33:29 -04:00
staticsafe
f5f09ebc58 add 2001:19f0:6001:5aa0:5400:2ff:fecf:eee5 to drop for deirdre 2020-07-05 14:31:44 -04:00
staticsafe
7426c88be2 add 75.64.236.168/32 to deirdre and waldo ipset 2020-06-27 17:31:15 -04:00
staticsafe
f091373a1b add yet another pimeyes.com crawler IP to ipset 2020-06-01 23:31:36 -04:00
staticsafe
07badc1ff1 add another pimeyes crawler IP to ipset 2020-06-01 23:17:07 -04:00
staticsafe
c69b2dda9a add another pimeyes.com crawler IP 2020-05-27 21:05:14 -04:00
staticsafe
146fd41a7f add pimeeyes.com crawler IP to nasties ipset 2020-05-27 21:01:18 -04:00
staticsafe
e1c36822fa add a centurybot IP to nasties ipset 2020-05-27 13:44:27 -04:00
staticsafe
4fbedfec4e add Aspiegel bot range to nasties ipset 2020-05-19 13:24:00 -04:00
staticsafe
1a633fb947 sadiqsaif.com does not need a custom 404 page anymore. 2020-05-07 16:48:02 -04:00
staticsafe
4c573cb5a0 remove python-pip and python-dev from common role 2020-04-23 16:55:18 -04:00
staticsafe
27b9e93b0d reference nasties ipset for erlking and waldo 2020-04-15 10:54:52 -04:00
staticsafe
fd475f98cb add some more ipsets for erlking and waldo 2020-04-15 10:52:33 -04:00
staticsafe
d8f5681c52 fix typo in ipset.service 2020-04-15 10:26:29 -04:00
staticsafe
dd4d335302 make ipset.service import even if ipset already exists and then reload in main.yml 2020-04-15 10:24:02 -04:00
staticsafe
05176fb83e don't destroy ipset in main.yml 2020-04-15 10:15:37 -04:00
staticsafe
3fb3507d40 make some more explicit requirements in ipset.service 2020-04-15 10:14:05 -04:00
staticsafe
8aa1d869ba clean up unnecessary comments in firewall rulesets 2020-04-14 22:41:05 -04:00
staticsafe
a7888e95bf set FLUSH_ON_STOP to 0 2020-04-14 22:36:13 -04:00
staticsafe
358b88ea60 we use a default file for netfilter-persistent 2020-04-14 22:29:56 -04:00
staticsafe
14c62687a7 ipset service stop destroy 2020-04-14 22:16:02 -04:00
staticsafe
53d62d54f5 let's try this again with destroy 2020-04-14 22:15:06 -04:00
staticsafe
377a5bcebf temporarily comment out firewall rule 2020-04-14 22:12:03 -04:00
staticsafe
58c0b0e2c1 always reload systemd 2020-04-14 22:09:46 -04:00
staticsafe
3abbcbbd9e use flush instead of destroy in ipset everywhere 2020-04-14 22:07:16 -04:00
staticsafe
92f286bbd6 should be src for ipset based rule 2020-04-14 22:03:31 -04:00
staticsafe
c267ec243f use ipset instead of a bunch of INPUTs 2020-04-14 22:02:50 -04:00
staticsafe
0d7df674ec dont use handler 2020-04-14 21:56:14 -04:00
staticsafe
02a376b367 restart ipset service instead of start and use handler 2020-04-14 21:52:51 -04:00
staticsafe
1430497f5c move order of ipset destroy up 2020-04-14 21:47:16 -04:00
staticsafe
696bf3348f fix syntax error in ubuntu/roles/ipset-deploy/tasks/main.yml 2020-04-14 21:44:55 -04:00
staticsafe
ce39f769a2 add ipset-deploy role 2020-04-14 21:42:03 -04:00
staticsafe
835384a24d add rulesets for uriel.asininetech.net. 2020-04-04 19:19:53 -04:00
staticsafe
66eebc37d3 add moz.com crawler to firewall block list on web servers 2020-03-28 23:10:00 -04:00
staticsafe
07cf97fa21 add rpcbind to list of packages we remove on setup 2020-03-27 13:08:12 -04:00
staticsafe
114970ec4b Use a more generic sshd_config with our options. 2020-03-24 11:15:43 -04:00
staticsafe
1f1bf5147b common role is now copying over a sshd_config 2020-03-24 10:27:23 -04:00
staticsafe
1de56b96b9 remove grevane.asininetech.net.rules.*, not needed anymore 2020-03-23 11:26:08 -04:00
staticsafe
c1b3d2a171 clean up nginx_remove_sites 2020-03-09 20:38:56 -04:00
staticsafe
6613d75162 remove sadiqsaif.ca and staticsafe.ca vhosts 2020-03-09 19:26:22 -04:00
staticsafe
7fb64da246 no need for 127/8 rules in demonreach.asininetech.net.rules.v4 2020-03-08 22:56:18 -04:00
staticsafe
10c45c850b DNS resolving issues in demonreach.asininetech.net.rules.v4? 2020-03-08 15:58:13 -04:00
staticsafe
f9e74ee5aa allow TCP DNS as well for VPN subnet 2020-03-04 17:50:43 -05:00
staticsafe
13f9b1575c add 2620:98:4002::/48 to port 53 for demonreach.asininetech.net.rules.v6 2020-03-04 17:16:48 -05:00
staticsafe
a0d1c0598d remove port 1723 from demonreach.asininetech.net.rules.v4 2020-03-04 13:49:55 -05:00
staticsafe
12e58f3c01 add port 1723 to demonreach.asininetech.net.rules.v4 2020-03-04 13:45:18 -05:00
staticsafe
907b86492b add a DROP rule in deirdre.asininetech.net.rules.v4 2020-02-25 23:31:22 -05:00
staticsafe
e866d062a9 add AlkonavtNetwork subnet to drop list on deirdre.asininetech.net.rules.v4 2020-02-20 14:46:21 -05:00
staticsafe
db59ab205e add rule to drop SearchAtlas crawler 2020-02-20 14:26:02 -05:00
staticsafe
c6997dcd39 add drop for Seekport crawler IP to deirdre and waldo 2020-02-14 19:29:13 -05:00
staticsafe
9766d2ced5 Add vhost for ultonomy.com. 2020-01-22 10:46:15 -05:00
staticsafe
2af73d2d4e allow ES traffic over Tinc VPN 2020-01-19 10:35:58 -05:00
staticsafe
bc92c9d437 Port opening for Tinc 2020-01-18 20:49:05 -05:00
staticsafe
a4c0bcde30 min heap size 4g 2020-01-18 18:56:24 -05:00
staticsafe
42bf05965b increase min heap size to 2g 2020-01-18 18:54:41 -05:00
staticsafe
2c83554698 elasticsearch_version should be 6.x 2020-01-18 18:49:03 -05:00
staticsafe
869d80e6f7 we need to secure port 9300 on namshiel as well 2020-01-18 18:00:08 -05:00
staticsafe
201f4a35ca min heap size to 1g? 2020-01-18 17:39:47 -05:00
staticsafe
6f0febf806 needs min heap size? 2020-01-18 17:36:56 -05:00
staticsafe
d810ba667e let's try again? 2020-01-18 17:34:00 -05:00
staticsafe
d0976ca7fb fix formatting on namshiel-elasticsearch.asininetech.net.yml? 2020-01-18 17:33:01 -05:00
staticsafe
e306a60ea6 add namshiel related files 2020-01-18 17:29:03 -05:00
staticsafe
a0e26301cf deirdre should be able to talk outbound 9200 for ES 2020-01-18 17:17:51 -05:00
staticsafe
d384b41e75 cleanup i.asininetech.com. 2020-01-16 18:17:01 -05:00
staticsafe
748ddb1008 remove i.asininetech.com. 2020-01-16 18:09:51 -05:00
staticsafe
9e1e20d33f Remove port 4949 from allowed ports
deirdre no longer using munin-node
2020-01-06 10:17:29 -05:00
staticsafe
da2f7aef93 Remove catsith.asininetech.net.rules.v4 and catsith.asininetech.net.rules.v6
catsith is gone
2020-01-06 10:16:20 -05:00
staticsafe
3b73edf491 add firewall rule to drop aggressive crawler in catsith.asininetech.net.rules.v6 2019-12-23 18:40:54 -05:00
staticsafe
85d19dd3a0 add ipset package install to ubuntu/roles/firewall-ruleset-deploy/tasks/main.yml 2019-11-17 16:22:27 -05:00
staticsafe
48e67daf37 remove duplicity/python-boto, add postfix, mailutils 2019-11-16 23:12:22 -05:00
staticsafe
7cc0101f0d change Unattended-Upgrade::Remove-Unused-Dependencies in 50unattended-upgrades 2019-10-29 12:06:14 -04:00
staticsafe
87e7452be6 Remove apt-maintenance.sh as it isn't needed anymore. 2019-10-29 10:39:54 -04:00
staticsafe
da7c56eeb5 Update ubuntu/site.yml for unattended-upgrades task 2019-10-29 10:37:11 -04:00
staticsafe
18188cb971 Switch to using unattended-upgrades for apt-maintenance. 2019-10-29 10:35:24 -04:00
staticsafe
5703b44e75 update last task name in ubuntu/roles/apt-maintenance/tasks/main.yml 2019-10-29 10:18:09 -04:00
staticsafe
c951fe766d We are disabling the apt-maintenance cron job for now. 2019-10-29 10:13:27 -04:00
staticsafe
4d30f0245e add vhost for irreverent.space to ubuntu/erlking.asininetech.net.yml 2019-10-23 23:35:15 -04:00
staticsafe
05283b00ef Copy pgbackrest logrotate config as well 2019-10-20 21:53:09 -04:00
staticsafe
fbb5391eae Permissions for pgbackrest binary should be 755. 2019-10-20 21:28:45 -04:00
staticsafe
665d24a6cb fix typo in ubuntu/site.yml 2019-10-20 21:04:25 -04:00
staticsafe
74f35940f3 Add pgbackrest-install role 2019-10-20 21:02:36 -04:00
staticsafe
ab33cd0200 Add yet another Bytespider range to block list to firewall rules. 2019-10-17 12:20:28 -04:00
staticsafe
7c7ff101e5 Missed a Bytespider crawler range 2019-10-17 12:03:15 -04:00
staticsafe
f5d7c6dc39 Block aggressive Bytespider crawler across web servers 2019-10-17 11:58:42 -04:00
staticsafe
afa8aa556c Add firewall rules to drop kiwifarms subnets. 2019-10-11 00:00:45 -04:00
staticsafe
7152d8d5f2 should be multiports 2019-10-04 09:44:14 -04:00
staticsafe
d16ec626e1 add OUTPUT rules to allow DHCP on restricted nodes 2019-10-04 09:42:26 -04:00
staticsafe
90d4342ac2 cleanup some more 2019-09-29 22:54:53 -04:00
staticsafe
63490bb22b char.packet.cat is now removed, clean up 2019-09-29 22:54:02 -04:00
staticsafe
4100790fa9 Remove char.packet.cat. 2019-09-29 22:50:57 -04:00
staticsafe
e419d3aefb add drop rule for 159.149.133.66 to deirdre.asininetech.net.rules.v4 2019-09-16 12:05:46 -04:00
staticsafe
bd8a5c8435 Increase worker_connections across the board. 2019-09-03 14:20:40 -04:00
staticsafe
e9ec840823 increase nginx worker_connections to 1024 in ubuntu/deirdre.asininetech.net.yml 2019-09-03 14:07:14 -04:00
staticsafe
0a3cae443f rename some files to new hostnames. 2019-09-03 14:03:12 -04:00
staticsafe
4c23562144 add handlers to firewall-ruleset-deploy 2019-08-25 21:08:39 -04:00
staticsafe
3002276209 clean up of firewall rulesets
remove byte counters, remove chains that didn't need to be there
2019-08-21 23:42:07 -04:00
staticsafe
8e471b7254 add COMMIT after end of filter 2019-08-21 23:23:58 -04:00
staticsafe
df177dd04b clear out packet values in demonreach.asininetech.net.rules.v4 2019-08-21 23:21:17 -04:00
staticsafe
83fcf86900 POSTROUTING should be in nat chain 2019-08-21 23:20:41 -04:00
staticsafe
e86367ed83 add firewall rulesets for demonreach.asininetech.net. 2019-08-21 23:18:16 -04:00
staticsafe
ab7979ce01 add firewall rulesets for grevane.asininetech.net. 2019-08-21 22:46:53 -04:00
staticsafe
135e9bd008 add firewall rulesets for erlking.asininetech.net. 2019-08-21 22:37:20 -04:00
staticsafe
d411bc74dd add firewall rulesets for deirdre.asininetech.net. 2019-08-21 22:26:34 -04:00
staticsafe
ee1e6fb76f add firewall rulesets for catsith.asininetech.net 2019-08-21 22:23:10 -04:00
staticsafe
8b77463939 turn off backups in firewall-ruleset-deploy/tasks/main.yml 2019-08-21 22:15:34 -04:00
staticsafe
985895c082 add firewall rulesets for waldo.asininetech.net. 2019-08-21 22:12:42 -04:00
staticsafe
df3044c9f3 fix another error in gard.asininetech.net.rules.v6 2019-08-21 22:07:24 -04:00
staticsafe
ecda411031 fix syntax error in gard.asininetech.net.rules.v6 2019-08-21 22:02:55 -04:00
staticsafe
70fb7c8212 maybe fully enclosed? 2019-08-21 22:00:48 -04:00
staticsafe
62530669c9 double quotes maybe? 2019-08-21 21:58:10 -04:00
staticsafe
89e35f402b add quotes around ansible_fqdn 2019-08-21 21:56:43 -04:00
staticsafe
7705504cf7 add firewall-ruleset-deploy to site.yml 2019-08-21 21:53:38 -04:00
staticsafe
f1623be2e9 add firewall-ruleset-deploy playbook and gard's ruleset 2019-08-21 21:52:12 -04:00
staticsafe
de780e0254 make sure iptables-persistent and netfilter-persistent is installed via common playbook 2019-08-21 18:45:56 -04:00
staticsafe
a4b94b8ded add char.packet.cat conf 2019-07-27 11:57:05 -04:00
staticsafe
c074a6bb0a add wiki.tenforward.social configs 2019-07-27 11:28:12 -04:00
staticsafe
b7f3e9b2c2 removed erroneous block 2019-07-26 23:42:18 -04:00
staticsafe
74d3a686a5 add as393949.net vhost 2019-07-26 23:39:26 -04:00
staticsafe
7b42ceeca2 Remove warn=false in ubuntu/roles/common/tasks/main.yml 2019-07-21 20:43:43 -04:00
staticsafe
8d6bcde072 set warn=False for non-module apt task 2019-07-21 20:43:06 -04:00
staticsafe
32190262bc stop using with_items for apt in ubuntu/roles/common/tasks/main.yml 2019-07-21 20:34:13 -04:00
staticsafe
26d749a670 make sure PATH is set in ubuntu/roles/apt-maintenance/files/apt-maintenance.sh 2019-07-14 08:18:44 -04:00
staticsafe
c82b4f2ccf remove MAILTO from apt-maintenance.sh 2019-07-12 23:42:20 -04:00
staticsafe
c1e39c3f73 remove insertafter from ubuntu/roles/apt-maintenance/tasks/main.yml 2019-07-12 23:40:21 -04:00
staticsafe
e7865d16c9 Add MAILTO variable addition into apt-maintenance/tasks/main.yml 2019-07-12 23:39:01 -04:00
staticsafe
616b5c1a83 make sure /root/scripts exists 2019-07-12 23:13:48 -04:00