Commit Graph

459 Commits

Author SHA1 Message Date
staticsafe
12e58f3c01 add port 1723 to demonreach.asininetech.net.rules.v4 2020-03-04 13:45:18 -05:00
staticsafe
907b86492b add a DROP rule in deirdre.asininetech.net.rules.v4 2020-02-25 23:31:22 -05:00
staticsafe
e866d062a9 add AlkonavtNetwork subnet to drop list on deirdre.asininetech.net.rules.v4 2020-02-20 14:46:21 -05:00
staticsafe
db59ab205e add rule to drop SearchAtlas crawler 2020-02-20 14:26:02 -05:00
staticsafe
c6997dcd39 add drop for Seekport crawler IP to deirdre and waldo 2020-02-14 19:29:13 -05:00
staticsafe
9766d2ced5 Add vhost for ultonomy.com. 2020-01-22 10:46:15 -05:00
staticsafe
2af73d2d4e allow ES traffic over Tinc VPN 2020-01-19 10:35:58 -05:00
staticsafe
bc92c9d437 Port opening for Tinc 2020-01-18 20:49:05 -05:00
staticsafe
a4c0bcde30 min heap size 4g 2020-01-18 18:56:24 -05:00
staticsafe
42bf05965b increase min heap size to 2g 2020-01-18 18:54:41 -05:00
staticsafe
2c83554698 elasticsearch_version should be 6.x 2020-01-18 18:49:03 -05:00
staticsafe
869d80e6f7 we need to secure port 9300 on namshiel as well 2020-01-18 18:00:08 -05:00
staticsafe
201f4a35ca min heap size to 1g? 2020-01-18 17:39:47 -05:00
staticsafe
6f0febf806 needs min heap size? 2020-01-18 17:36:56 -05:00
staticsafe
d810ba667e let's try again? 2020-01-18 17:34:00 -05:00
staticsafe
d0976ca7fb fix formatting on namshiel-elasticsearch.asininetech.net.yml? 2020-01-18 17:33:01 -05:00
staticsafe
e306a60ea6 add namshiel related files 2020-01-18 17:29:03 -05:00
staticsafe
a0e26301cf deirdre should be able to talk outbound 9200 for ES 2020-01-18 17:17:51 -05:00
staticsafe
d384b41e75 cleanup i.asininetech.com. 2020-01-16 18:17:01 -05:00
staticsafe
748ddb1008 remove i.asininetech.com. 2020-01-16 18:09:51 -05:00
staticsafe
9e1e20d33f Remove port 4949 from allowed ports
deirdre no longer using munin-node
2020-01-06 10:17:29 -05:00
staticsafe
da2f7aef93 Remove catsith.asininetech.net.rules.v4 and catsith.asininetech.net.rules.v6
catsith is gone
2020-01-06 10:16:20 -05:00
staticsafe
3b73edf491 add firewall rule to drop aggressive crawler in catsith.asininetech.net.rules.v6 2019-12-23 18:40:54 -05:00
staticsafe
85d19dd3a0 add ipset package install to ubuntu/roles/firewall-ruleset-deploy/tasks/main.yml 2019-11-17 16:22:27 -05:00
staticsafe
48e67daf37 remove duplicity/python-boto, add postfix, mailutils 2019-11-16 23:12:22 -05:00
staticsafe
7cc0101f0d change Unattended-Upgrade::Remove-Unused-Dependencies in 50unattended-upgrades 2019-10-29 12:06:14 -04:00
staticsafe
87e7452be6 Remove apt-maintenance.sh as it isn't needed anymore. 2019-10-29 10:39:54 -04:00
staticsafe
da7c56eeb5 Update ubuntu/site.yml for unattended-upgrades task 2019-10-29 10:37:11 -04:00
staticsafe
18188cb971 Switch to using unattended-upgrades for apt-maintenance. 2019-10-29 10:35:24 -04:00
staticsafe
5703b44e75 update last task name in ubuntu/roles/apt-maintenance/tasks/main.yml 2019-10-29 10:18:09 -04:00
staticsafe
c951fe766d We are disabling the apt-maintenance cron job for now. 2019-10-29 10:13:27 -04:00
staticsafe
4d30f0245e add vhost for irreverent.space to ubuntu/erlking.asininetech.net.yml 2019-10-23 23:35:15 -04:00
staticsafe
05283b00ef Copy pgbackrest logrotate config as well 2019-10-20 21:53:09 -04:00
staticsafe
fbb5391eae Permissions for pgbackrest binary should be 755. 2019-10-20 21:28:45 -04:00
staticsafe
665d24a6cb fix typo in ubuntu/site.yml 2019-10-20 21:04:25 -04:00
staticsafe
74f35940f3 Add pgbackrest-install role 2019-10-20 21:02:36 -04:00
staticsafe
ab33cd0200 Add yet another Bytespider range to block list to firewall rules. 2019-10-17 12:20:28 -04:00
staticsafe
7c7ff101e5 Missed a Bytespider crawler range 2019-10-17 12:03:15 -04:00
staticsafe
f5d7c6dc39 Block aggressive Bytespider crawler across web servers 2019-10-17 11:58:42 -04:00
staticsafe
afa8aa556c Add firewall rules to drop kiwifarms subnets. 2019-10-11 00:00:45 -04:00
staticsafe
7152d8d5f2 should be multiports 2019-10-04 09:44:14 -04:00
staticsafe
d16ec626e1 add OUTPUT rules to allow DHCP on restricted nodes 2019-10-04 09:42:26 -04:00
staticsafe
90d4342ac2 cleanup some more 2019-09-29 22:54:53 -04:00
staticsafe
63490bb22b char.packet.cat is now removed, clean up 2019-09-29 22:54:02 -04:00
staticsafe
4100790fa9 Remove char.packet.cat. 2019-09-29 22:50:57 -04:00
staticsafe
e419d3aefb add drop rule for 159.149.133.66 to deirdre.asininetech.net.rules.v4 2019-09-16 12:05:46 -04:00
staticsafe
bd8a5c8435 Increase worker_connections across the board. 2019-09-03 14:20:40 -04:00
staticsafe
e9ec840823 increase nginx worker_connections to 1024 in ubuntu/deirdre.asininetech.net.yml 2019-09-03 14:07:14 -04:00
staticsafe
0a3cae443f rename some files to new hostnames. 2019-09-03 14:03:12 -04:00
staticsafe
4c23562144 add handlers to firewall-ruleset-deploy 2019-08-25 21:08:39 -04:00