Commit Graph

472 Commits

Author SHA1 Message Date
staticsafe
9aa40b3967 Clean up site.yml and move some other roles into their own yml files 2020-08-22 16:21:24 -04:00
staticsafe
b2bd30101b ssh-enforcement role should be run for unsetup hosts as well. 2020-08-22 15:59:38 -04:00
staticsafe
2bfed5b9ed add ssh-enforcement playbook 2020-08-22 15:47:23 -04:00
Sadiq Saif
b6946a3e26
Update pgbackrest version to 2.28 2020-08-18 08:40:19 -04:00
staticsafe
c73f1f6b7c add woff2 to static resources to be cached 2020-07-30 17:57:33 -04:00
staticsafe
d2b0e47564 add Adsbot IPs to webserver ipsets 2020-07-29 08:46:33 -04:00
staticsafe
36086ba967 fix an extraneous space in erlking.asininetech.net.yml 2020-07-27 15:26:12 -04:00
staticsafe
3715879e77 add WP caching config to other sites now 2020-07-27 13:42:50 -04:00
staticsafe
33c6fc78e2 fix extra bracket 2020-07-27 13:37:43 -04:00
staticsafe
b604283ce5 improve WP caching setup
testing on asininetech.com
2020-07-27 13:33:52 -04:00
staticsafe
91404bb5f1 remove extraneous ; 2020-07-26 19:27:42 -04:00
staticsafe
377568f7cd remove quotes 2020-07-26 19:26:46 -04:00
staticsafe
2e468240fd add new Access-Control-Allow-Origin header for Mastodon 3.2.0 2020-07-26 19:24:05 -04:00
staticsafe
1b6e048e43 cleanup as393949.net 2020-07-18 22:41:10 -04:00
staticsafe
8dd8505d0a remove as393949.net 2020-07-18 22:21:41 -04:00
staticsafe
4ea258d17b add 149.248.4.242 to deirdre.asininetech.net.ipset 2020-07-05 14:34:47 -04:00
staticsafe
71fc82ed22 remove namshiel.asininetech.net.rules.* 2020-07-05 14:33:29 -04:00
staticsafe
f5f09ebc58 add 2001:19f0:6001:5aa0:5400:2ff:fecf:eee5 to drop for deirdre 2020-07-05 14:31:44 -04:00
staticsafe
7426c88be2 add 75.64.236.168/32 to deirdre and waldo ipset 2020-06-27 17:31:15 -04:00
staticsafe
f091373a1b add yet another pimeyes.com crawler IP to ipset 2020-06-01 23:31:36 -04:00
staticsafe
07badc1ff1 add another pimeyes crawler IP to ipset 2020-06-01 23:17:07 -04:00
staticsafe
c69b2dda9a add another pimeyes.com crawler IP 2020-05-27 21:05:14 -04:00
staticsafe
146fd41a7f add pimeeyes.com crawler IP to nasties ipset 2020-05-27 21:01:18 -04:00
staticsafe
e1c36822fa add a centurybot IP to nasties ipset 2020-05-27 13:44:27 -04:00
staticsafe
4fbedfec4e add Aspiegel bot range to nasties ipset 2020-05-19 13:24:00 -04:00
staticsafe
1a633fb947 sadiqsaif.com does not need a custom 404 page anymore. 2020-05-07 16:48:02 -04:00
staticsafe
4c573cb5a0 remove python-pip and python-dev from common role 2020-04-23 16:55:18 -04:00
staticsafe
27b9e93b0d reference nasties ipset for erlking and waldo 2020-04-15 10:54:52 -04:00
staticsafe
fd475f98cb add some more ipsets for erlking and waldo 2020-04-15 10:52:33 -04:00
staticsafe
d8f5681c52 fix typo in ipset.service 2020-04-15 10:26:29 -04:00
staticsafe
dd4d335302 make ipset.service import even if ipset already exists and then reload in main.yml 2020-04-15 10:24:02 -04:00
staticsafe
05176fb83e don't destroy ipset in main.yml 2020-04-15 10:15:37 -04:00
staticsafe
3fb3507d40 make some more explicit requirements in ipset.service 2020-04-15 10:14:05 -04:00
staticsafe
8aa1d869ba clean up unnecessary comments in firewall rulesets 2020-04-14 22:41:05 -04:00
staticsafe
a7888e95bf set FLUSH_ON_STOP to 0 2020-04-14 22:36:13 -04:00
staticsafe
358b88ea60 we use a default file for netfilter-persistent 2020-04-14 22:29:56 -04:00
staticsafe
14c62687a7 ipset service stop destroy 2020-04-14 22:16:02 -04:00
staticsafe
53d62d54f5 let's try this again with destroy 2020-04-14 22:15:06 -04:00
staticsafe
377a5bcebf temporarily comment out firewall rule 2020-04-14 22:12:03 -04:00
staticsafe
58c0b0e2c1 always reload systemd 2020-04-14 22:09:46 -04:00
staticsafe
3abbcbbd9e use flush instead of destroy in ipset everywhere 2020-04-14 22:07:16 -04:00
staticsafe
92f286bbd6 should be src for ipset based rule 2020-04-14 22:03:31 -04:00
staticsafe
c267ec243f use ipset instead of a bunch of INPUTs 2020-04-14 22:02:50 -04:00
staticsafe
0d7df674ec dont use handler 2020-04-14 21:56:14 -04:00
staticsafe
02a376b367 restart ipset service instead of start and use handler 2020-04-14 21:52:51 -04:00
staticsafe
1430497f5c move order of ipset destroy up 2020-04-14 21:47:16 -04:00
staticsafe
696bf3348f fix syntax error in ubuntu/roles/ipset-deploy/tasks/main.yml 2020-04-14 21:44:55 -04:00
staticsafe
ce39f769a2 add ipset-deploy role 2020-04-14 21:42:03 -04:00
staticsafe
835384a24d add rulesets for uriel.asininetech.net. 2020-04-04 19:19:53 -04:00
staticsafe
66eebc37d3 add moz.com crawler to firewall block list on web servers 2020-03-28 23:10:00 -04:00