staticsafe
|
f9e74ee5aa
|
allow TCP DNS as well for VPN subnet
|
2020-03-04 17:50:43 -05:00 |
staticsafe
|
13f9b1575c
|
add 2620:98:4002::/48 to port 53 for demonreach.asininetech.net.rules.v6
|
2020-03-04 17:16:48 -05:00 |
staticsafe
|
a0d1c0598d
|
remove port 1723 from demonreach.asininetech.net.rules.v4
|
2020-03-04 13:49:55 -05:00 |
staticsafe
|
12e58f3c01
|
add port 1723 to demonreach.asininetech.net.rules.v4
|
2020-03-04 13:45:18 -05:00 |
staticsafe
|
907b86492b
|
add a DROP rule in deirdre.asininetech.net.rules.v4
|
2020-02-25 23:31:22 -05:00 |
staticsafe
|
e866d062a9
|
add AlkonavtNetwork subnet to drop list on deirdre.asininetech.net.rules.v4
|
2020-02-20 14:46:21 -05:00 |
staticsafe
|
db59ab205e
|
add rule to drop SearchAtlas crawler
|
2020-02-20 14:26:02 -05:00 |
staticsafe
|
c6997dcd39
|
add drop for Seekport crawler IP to deirdre and waldo
|
2020-02-14 19:29:13 -05:00 |
staticsafe
|
9766d2ced5
|
Add vhost for ultonomy.com.
|
2020-01-22 10:46:15 -05:00 |
staticsafe
|
2af73d2d4e
|
allow ES traffic over Tinc VPN
|
2020-01-19 10:35:58 -05:00 |
staticsafe
|
bc92c9d437
|
Port opening for Tinc
|
2020-01-18 20:49:05 -05:00 |
staticsafe
|
a4c0bcde30
|
min heap size 4g
|
2020-01-18 18:56:24 -05:00 |
staticsafe
|
42bf05965b
|
increase min heap size to 2g
|
2020-01-18 18:54:41 -05:00 |
staticsafe
|
2c83554698
|
elasticsearch_version should be 6.x
|
2020-01-18 18:49:03 -05:00 |
staticsafe
|
869d80e6f7
|
we need to secure port 9300 on namshiel as well
|
2020-01-18 18:00:08 -05:00 |
staticsafe
|
201f4a35ca
|
min heap size to 1g?
|
2020-01-18 17:39:47 -05:00 |
staticsafe
|
6f0febf806
|
needs min heap size?
|
2020-01-18 17:36:56 -05:00 |
staticsafe
|
d810ba667e
|
let's try again?
|
2020-01-18 17:34:00 -05:00 |
staticsafe
|
d0976ca7fb
|
fix formatting on namshiel-elasticsearch.asininetech.net.yml?
|
2020-01-18 17:33:01 -05:00 |
staticsafe
|
e306a60ea6
|
add namshiel related files
|
2020-01-18 17:29:03 -05:00 |
staticsafe
|
a0e26301cf
|
deirdre should be able to talk outbound 9200 for ES
|
2020-01-18 17:17:51 -05:00 |
staticsafe
|
d384b41e75
|
cleanup i.asininetech.com.
|
2020-01-16 18:17:01 -05:00 |
staticsafe
|
748ddb1008
|
remove i.asininetech.com.
|
2020-01-16 18:09:51 -05:00 |
staticsafe
|
9e1e20d33f
|
Remove port 4949 from allowed ports
deirdre no longer using munin-node
|
2020-01-06 10:17:29 -05:00 |
staticsafe
|
da2f7aef93
|
Remove catsith.asininetech.net.rules.v4 and catsith.asininetech.net.rules.v6
catsith is gone
|
2020-01-06 10:16:20 -05:00 |
staticsafe
|
3b73edf491
|
add firewall rule to drop aggressive crawler in catsith.asininetech.net.rules.v6
|
2019-12-23 18:40:54 -05:00 |
staticsafe
|
85d19dd3a0
|
add ipset package install to ubuntu/roles/firewall-ruleset-deploy/tasks/main.yml
|
2019-11-17 16:22:27 -05:00 |
staticsafe
|
48e67daf37
|
remove duplicity/python-boto, add postfix, mailutils
|
2019-11-16 23:12:22 -05:00 |
staticsafe
|
7cc0101f0d
|
change Unattended-Upgrade::Remove-Unused-Dependencies in 50unattended-upgrades
|
2019-10-29 12:06:14 -04:00 |
staticsafe
|
87e7452be6
|
Remove apt-maintenance.sh as it isn't needed anymore.
|
2019-10-29 10:39:54 -04:00 |
staticsafe
|
da7c56eeb5
|
Update ubuntu/site.yml for unattended-upgrades task
|
2019-10-29 10:37:11 -04:00 |
staticsafe
|
18188cb971
|
Switch to using unattended-upgrades for apt-maintenance.
|
2019-10-29 10:35:24 -04:00 |
staticsafe
|
5703b44e75
|
update last task name in ubuntu/roles/apt-maintenance/tasks/main.yml
|
2019-10-29 10:18:09 -04:00 |
staticsafe
|
c951fe766d
|
We are disabling the apt-maintenance cron job for now.
|
2019-10-29 10:13:27 -04:00 |
staticsafe
|
4d30f0245e
|
add vhost for irreverent.space to ubuntu/erlking.asininetech.net.yml
|
2019-10-23 23:35:15 -04:00 |
staticsafe
|
05283b00ef
|
Copy pgbackrest logrotate config as well
|
2019-10-20 21:53:09 -04:00 |
staticsafe
|
fbb5391eae
|
Permissions for pgbackrest binary should be 755.
|
2019-10-20 21:28:45 -04:00 |
staticsafe
|
665d24a6cb
|
fix typo in ubuntu/site.yml
|
2019-10-20 21:04:25 -04:00 |
staticsafe
|
74f35940f3
|
Add pgbackrest-install role
|
2019-10-20 21:02:36 -04:00 |
staticsafe
|
ab33cd0200
|
Add yet another Bytespider range to block list to firewall rules.
|
2019-10-17 12:20:28 -04:00 |
staticsafe
|
7c7ff101e5
|
Missed a Bytespider crawler range
|
2019-10-17 12:03:15 -04:00 |
staticsafe
|
f5d7c6dc39
|
Block aggressive Bytespider crawler across web servers
|
2019-10-17 11:58:42 -04:00 |
staticsafe
|
afa8aa556c
|
Add firewall rules to drop kiwifarms subnets.
|
2019-10-11 00:00:45 -04:00 |
staticsafe
|
7152d8d5f2
|
should be multiports
|
2019-10-04 09:44:14 -04:00 |
staticsafe
|
d16ec626e1
|
add OUTPUT rules to allow DHCP on restricted nodes
|
2019-10-04 09:42:26 -04:00 |
staticsafe
|
90d4342ac2
|
cleanup some more
|
2019-09-29 22:54:53 -04:00 |
staticsafe
|
63490bb22b
|
char.packet.cat is now removed, clean up
|
2019-09-29 22:54:02 -04:00 |
staticsafe
|
4100790fa9
|
Remove char.packet.cat.
|
2019-09-29 22:50:57 -04:00 |
staticsafe
|
e419d3aefb
|
add drop rule for 159.149.133.66 to deirdre.asininetech.net.rules.v4
|
2019-09-16 12:05:46 -04:00 |
staticsafe
|
bd8a5c8435
|
Increase worker_connections across the board.
|
2019-09-03 14:20:40 -04:00 |