Commit Graph

439 Commits

Author SHA1 Message Date
packetcat 863e1b5cd0 Remove old Pimeyes IPs, most likely reassigned to other Hetzner customers 2022-08-17 10:10:11 -04:00
packetcat db7df90dc4 re-enable ssl_ciphers 2022-08-14 17:40:57 -04:00
packetcat f15053e70c turn off cipher selection in elaine.asininetech.net.yml 2022-08-14 17:37:06 -04:00
packetcat 515f1b0737 turn off access logging for nitter.ca 2022-08-11 22:13:34 -04:00
packetcat 0713103201 let's try setting tcp_nodelay on; to the proxy 2022-08-11 17:32:58 -04:00
packetcat bf4596f342 add proxy tuning back in 2022-08-11 15:13:30 -04:00
packetcat 713ad5e5be nope causes nitter to crash 2022-08-11 14:52:13 -04:00
packetcat ae171c173a back to 1024 worker connections 2022-08-11 14:49:06 -04:00
packetcat c718d51575 let's try tweaking the proxy params 2022-08-11 14:48:48 -04:00
packetcat c21fba3e42 again... 2022-08-11 14:39:48 -04:00
packetcat 960d8ca26d let's try this again 2022-08-11 14:38:20 -04:00
packetcat ae000335d1 remove invalid worker parameter 2022-08-11 14:36:16 -04:00
packetcat 40a1a39808 change nginx worker parameters 2022-08-11 14:33:51 -04:00
packetcat 2abce115ab add sadiqsaif.ca vhost with redirect 2022-07-30 18:33:43 -04:00
packetcat 3f7b3a32af redirect for sadiq.ae should be to sadiqsaif.com 2022-07-18 20:27:42 -04:00
packetcat f89dd5ff0d add vhost with redirect for sadiq.ae 2022-07-18 18:11:58 -04:00
packetcat ab893263c8 change SSL cert for wiki.packetcat.ca 2022-07-16 15:26:19 -04:00
packetcat 774f1b5276 change wiki.staticsafe.ca vhosts to wiki.packetcat.ca 2022-07-16 15:21:06 -04:00
Sadiq Saif 923f7595a0 update pgbackrest version to 2.39 2022-07-02 10:01:16 -04:00
Sadiq Saif fb53c7808c add ssl config for sanya.asininetech.net.yml 2022-07-01 20:50:42 -04:00
Sadiq Saif eb726493db add ubuntu/sanya.asininetech.net.yml 2022-07-01 20:46:14 -04:00
Sadiq Saif 797d48b52f add support for 22.04 in ubuntu/roles/common/tasks/main.yml 2022-06-26 16:05:11 -04:00
packetcat f06823a062 add 157.90.177.214 to deirdre.asininetech.net.ipset 2022-04-04 12:49:13 -04:00
staticsafe 2955428f01 add 2002:2d8d:56bb::2d8d:56bb to deirdre.asininetech.net.rules.v6 2022-01-13 09:30:24 -05:00
staticsafe 66e206d7c8 add AS206728 to deirdre and erlking ipsets 2022-01-12 12:37:00 -05:00
staticsafe 0cf1563566 change pgbackrest version to 2.36 2021-12-31 09:29:21 -05:00
staticsafe 47eb6aa778 add redirect for asininetech.com to nullrouted.space 2021-12-29 20:59:22 -05:00
staticsafe 4f7fe6dc39 change certs for nullrouted.space to proper ones 2021-12-29 20:46:28 -05:00
staticsafe d4466fa486 add initial config for nullrouted.space 2021-12-29 20:41:23 -05:00
staticsafe 5f0de6725c add tailscale ipv6 addresses to allow list 2021-11-21 12:38:51 -05:00
staticsafe 834890958b add tailscale subnet to allow list 2021-11-20 23:07:47 -05:00
staticsafe fa5dc5c4b4 oops..fix syntax error in deirdre.asininetech.net.ipset 2021-10-27 18:18:01 -04:00
staticsafe 7ee004dbce add 101.200.169.64 to deirdre.asininetech.net.ipset 2021-10-27 18:16:29 -04:00
staticsafe 0bc698d2a3 use proper cert for wiki.bastetrix.org 2021-10-17 12:00:47 -04:00
staticsafe 417fe5bba3 add wiki.bastetrix.org 2021-10-17 11:55:15 -04:00
staticsafe 4965c02d78 wp sites should use the wp_with_supercache snippet now 2021-10-17 11:49:25 -04:00
staticsafe 14f4f9e564 use proper certs for poetry.packetcat.ca 2021-10-17 11:43:21 -04:00
staticsafe 1cffac6a06 add poetry.packetcat.ca and php snippet 2021-10-17 11:36:05 -04:00
staticsafe 30cd26621b use sslstapling snippet to consolidate configs 2021-10-17 11:17:26 -04:00
staticsafe b6dfff5b55 use proper cert for bastetrix.com 2021-10-17 11:15:22 -04:00
staticsafe a9cee4de3b use different resolver for ssl stapling snippet 2021-10-17 11:12:14 -04:00
staticsafe 941ae1d6d5 oops wrong section 2021-10-17 11:09:53 -04:00
staticsafe 90225209a8 add sslstapling_hsts snippet 2021-10-17 11:09:21 -04:00
staticsafe 75a7f31a34 add bastetrix.com.https 2021-10-17 11:06:40 -04:00
staticsafe 6760952018 add bastetrix.com.http 2021-10-17 10:59:25 -04:00
staticsafe 4059278a32 include norobots.conf snippets 2021-10-14 22:25:07 -04:00
staticsafe c425d6b291 turn on access logging in ubuntu/elaine.asininetech.net.yml 2021-10-14 22:07:23 -04:00
staticsafe 07e9a24ce3 errors should be logged 2021-09-07 18:17:14 -04:00
staticsafe 4c09da012d turn off access logging for nitter.ca 2021-09-07 18:16:47 -04:00
staticsafe 1eb8567d07 remove dhparams parameter 2021-09-07 17:29:36 -04:00
staticsafe 3a88e45cbc remove add_header 2021-09-07 17:24:11 -04:00
staticsafe 0cdad6a443 remove robots.txt section 2021-09-07 17:21:15 -04:00
staticsafe f5e67ae71d add https config for nitter.ca 2021-09-07 17:20:14 -04:00
staticsafe d650f545b7 add ubuntu/elaine.asininetech.net.yml 2021-09-07 16:57:04 -04:00
staticsafe 3ffa834b4a fix typo in demonreach.asininetech.net.rules.v4 2021-09-04 13:50:34 -04:00
staticsafe c8a274c39a fix more incorrect syntax in demonreach.asininetech.net.rules.v6 2021-09-04 13:49:25 -04:00
staticsafe 1a658b71a0 fix NAT rules in demonreach.asininetech.net.rules.v6 2021-09-04 13:48:06 -04:00
staticsafe cac6aab56a add some wireguard specific rules to demonreach 2021-09-04 13:45:10 -04:00
staticsafe d1c8a3eb55 add TinyBotTestUA to block list 2021-07-16 15:07:53 -04:00
staticsafe d38daabc0c add TinyTestBot to bot block list 2021-06-29 14:33:04 -04:00
staticsafe 32e5b1396a use custom 404 page for sadiqsaif.com 2021-06-13 16:16:29 -04:00
staticsafe 1b2227555c change webroot for sadiqsaif.com 2021-06-13 15:49:35 -04:00
staticsafe d4bd7cfcf9 add lanaibot useragent to block list in deirdre.asininetech.net.yml 2021-05-18 11:30:22 -04:00
staticsafe 736158c9b5 update pgbackrest-install/tasks/main.yml to use 2.33 2021-05-11 12:35:29 -04:00
staticsafe 9852a4ea21 remove tinc ports in deirdre 2021-04-05 09:18:44 -04:00
staticsafe 4085481ed0 remove elasticsearch ports from deirdre firewall rules 2021-04-05 09:18:06 -04:00
staticsafe 9aec73785d add rules to allow outbound NTP to deirdre 2021-04-05 08:29:25 -04:00
staticsafe 2fb9123db3 update IP range for Infegy bot to 173.244.135.0/25 2021-03-20 19:01:08 -04:00
staticsafe 45935b847a remove old ipset block of Comcast dynamic IP 2021-03-20 18:56:52 -04:00
staticsafe 53efc0c07c remove waldo.asininetech.net.yml
host is decommissioned
2021-03-20 18:44:17 -04:00
staticsafe 83f211675b change hosts value to specific hosts for webserver plays 2021-03-20 18:43:31 -04:00
staticsafe 8cbf3b0e64 add blockbots nginx snippet and use it in TF vhost 2021-03-20 18:41:38 -04:00
staticsafe 0b3265d75c add a new IP into deirdre and erlking ipsets
remove waldo ipsets and rules
2021-03-17 09:56:10 -04:00
staticsafe ae99eaef7b home nodes should be updated as well 2021-01-17 19:15:50 -05:00
staticsafe 1541a24467 add package-update role 2021-01-17 19:14:41 -05:00
staticsafe 3cb30d2985 add aliases copy task to common play 2020-12-01 10:31:07 -05:00
staticsafe db53abe225 remove zsh from common packages install list 2020-11-29 09:21:54 -05:00
staticsafe 2860f23b85 add net-tools to common packages install list 2020-11-29 09:21:03 -05:00
staticsafe 2d2e5a78c5 we should set hostname before package installation 2020-11-25 16:20:30 -05:00
staticsafe 42b6960609 add 217.160.142.105 to ipset 2020-10-28 10:40:14 -04:00
staticsafe 8ac714f548 consolidate adsbot prefixes into two /24s 2020-10-15 13:15:06 -04:00
staticsafe 0506ecb009 remove - in host group name in icinga-client-install.yml 2020-10-12 09:12:07 -04:00
staticsafe 87c531e0c5 update adsbot prefixes 2020-10-12 09:10:40 -04:00
staticsafe 4343fdf1f6 install python-is-python3 as part of common role 2020-10-11 14:37:53 -04:00
staticsafe 016d71151a set phpfpm socket to 7.4 2020-10-03 22:02:26 -04:00
staticsafe 4e96352e88 add another adsbot IP into the ipset 2020-09-23 11:00:00 -04:00
staticsafe 340637ef19 add another subnet of Aspiegel bot 2020-09-12 12:19:39 -04:00
staticsafe c28997cd60 add another adsbot IP to nasties ipset 2020-09-11 19:47:15 -04:00
staticsafe 4f7b399783 add another adsbot IP to ipset list 2020-09-09 09:27:07 -04:00
staticsafe 10ba23f5d6 add another Adsbot IP to the nasties ipset 2020-09-07 12:40:23 -04:00
staticsafe 4d0660e162 quotes needed 2020-08-22 19:03:10 -04:00
staticsafe 1bd0269944 make sure to set hostname on new nodes and turn off motd news on focal 2020-08-22 19:00:56 -04:00
staticsafe 2d45e87d98 remove sshd_config copy in common role
its in ssh-enforcement now
2020-08-22 18:43:35 -04:00
staticsafe e574b1d4de remove catsith.asininetech.net.yml
no longer needed
2020-08-22 16:44:50 -04:00
staticsafe 9aa40b3967 Clean up site.yml and move some other roles into their own yml files 2020-08-22 16:21:24 -04:00
staticsafe b2bd30101b ssh-enforcement role should be run for unsetup hosts as well. 2020-08-22 15:59:38 -04:00
staticsafe 2bfed5b9ed add ssh-enforcement playbook 2020-08-22 15:47:23 -04:00
Sadiq Saif b6946a3e26
Update pgbackrest version to 2.28 2020-08-18 08:40:19 -04:00
staticsafe c73f1f6b7c add woff2 to static resources to be cached 2020-07-30 17:57:33 -04:00
staticsafe d2b0e47564 add Adsbot IPs to webserver ipsets 2020-07-29 08:46:33 -04:00