Commit Graph

  • 5f0de6725c add tailscale ipv6 addresses to allow list staticsafe 2021-11-21 12:38:51 -0500
  • 834890958b add tailscale subnet to allow list staticsafe 2021-11-20 23:07:41 -0500
  • fa5dc5c4b4 oops..fix syntax error in deirdre.asininetech.net.ipset staticsafe 2021-10-27 18:17:53 -0400
  • 7ee004dbce add 101.200.169.64 to deirdre.asininetech.net.ipset staticsafe 2021-10-27 18:16:23 -0400
  • 0bc698d2a3 use proper cert for wiki.bastetrix.org staticsafe 2021-10-17 12:00:40 -0400
  • 417fe5bba3 add wiki.bastetrix.org staticsafe 2021-10-17 11:55:10 -0400
  • 4965c02d78 wp sites should use the wp_with_supercache snippet now staticsafe 2021-10-17 11:49:13 -0400
  • 14f4f9e564 use proper certs for poetry.packetcat.ca staticsafe 2021-10-17 11:43:19 -0400
  • 1cffac6a06 add poetry.packetcat.ca and php snippet staticsafe 2021-10-17 11:31:47 -0400
  • 30cd26621b use sslstapling snippet to consolidate configs staticsafe 2021-10-17 11:17:13 -0400
  • b6dfff5b55 use proper cert for bastetrix.com staticsafe 2021-10-17 11:15:13 -0400
  • a9cee4de3b use different resolver for ssl stapling snippet staticsafe 2021-10-17 11:12:03 -0400
  • 941ae1d6d5 oops wrong section staticsafe 2021-10-17 11:09:48 -0400
  • 90225209a8 add sslstapling_hsts snippet staticsafe 2021-10-17 11:09:09 -0400
  • 75a7f31a34 add bastetrix.com.https staticsafe 2021-10-17 11:06:33 -0400
  • 6760952018 add bastetrix.com.http staticsafe 2021-10-17 10:59:17 -0400
  • 4059278a32 include norobots.conf snippets staticsafe 2021-10-14 22:24:57 -0400
  • c425d6b291 turn on access logging in ubuntu/elaine.asininetech.net.yml staticsafe 2021-10-14 22:07:11 -0400
  • 07e9a24ce3 errors should be logged staticsafe 2021-09-07 18:17:08 -0400
  • 4c09da012d turn off access logging for nitter.ca staticsafe 2021-09-07 18:16:34 -0400
  • 1eb8567d07 remove dhparams parameter staticsafe 2021-09-07 17:29:29 -0400
  • 3a88e45cbc remove add_header staticsafe 2021-09-07 17:24:04 -0400
  • 0cdad6a443 remove robots.txt section staticsafe 2021-09-07 17:20:55 -0400
  • f5e67ae71d add https config for nitter.ca staticsafe 2021-09-07 17:20:06 -0400
  • d650f545b7 add ubuntu/elaine.asininetech.net.yml staticsafe 2021-09-07 16:57:03 -0400
  • 3ffa834b4a fix typo in demonreach.asininetech.net.rules.v4 staticsafe 2021-09-04 13:50:34 -0400
  • c8a274c39a fix more incorrect syntax in demonreach.asininetech.net.rules.v6 staticsafe 2021-09-04 13:49:17 -0400
  • 1a658b71a0 fix NAT rules in demonreach.asininetech.net.rules.v6 staticsafe 2021-09-04 13:47:59 -0400
  • cac6aab56a add some wireguard specific rules to demonreach staticsafe 2021-09-04 13:45:02 -0400
  • d1c8a3eb55 add TinyBotTestUA to block list staticsafe 2021-07-16 15:07:44 -0400
  • d38daabc0c add TinyTestBot to bot block list staticsafe 2021-06-29 14:32:51 -0400
  • 32e5b1396a use custom 404 page for sadiqsaif.com staticsafe 2021-06-13 16:16:19 -0400
  • 1b2227555c change webroot for sadiqsaif.com staticsafe 2021-06-13 15:49:29 -0400
  • d4bd7cfcf9 add lanaibot useragent to block list in deirdre.asininetech.net.yml staticsafe 2021-05-18 11:30:09 -0400
  • 736158c9b5 update pgbackrest-install/tasks/main.yml to use 2.33 staticsafe 2021-05-11 12:35:29 -0400
  • 9852a4ea21 remove tinc ports in deirdre staticsafe 2021-04-05 09:18:34 -0400
  • 4085481ed0 remove elasticsearch ports from deirdre firewall rules staticsafe 2021-04-05 09:17:49 -0400
  • 9aec73785d add rules to allow outbound NTP to deirdre staticsafe 2021-04-05 08:29:14 -0400
  • 2fb9123db3 update IP range for Infegy bot to 173.244.135.0/25 staticsafe 2021-03-20 19:00:59 -0400
  • 45935b847a remove old ipset block of Comcast dynamic IP staticsafe 2021-03-20 18:56:42 -0400
  • 53efc0c07c remove waldo.asininetech.net.yml host is decommissioned staticsafe 2021-03-20 18:44:03 -0400
  • 83f211675b change hosts value to specific hosts for webserver plays staticsafe 2021-03-20 18:43:15 -0400
  • 8cbf3b0e64 add blockbots nginx snippet and use it in TF vhost staticsafe 2021-03-20 18:41:23 -0400
  • 0b3265d75c add a new IP into deirdre and erlking ipsets remove waldo ipsets and rules staticsafe 2021-03-17 09:55:52 -0400
  • ae99eaef7b home nodes should be updated as well staticsafe 2021-01-17 19:15:42 -0500
  • 1541a24467 add package-update role staticsafe 2021-01-17 19:14:31 -0500
  • 3cb30d2985 add aliases copy task to common play staticsafe 2020-12-01 10:30:53 -0500
  • db53abe225 remove zsh from common packages install list staticsafe 2020-11-29 09:21:43 -0500
  • 2860f23b85 add net-tools to common packages install list staticsafe 2020-11-29 09:20:37 -0500
  • 2d2e5a78c5 we should set hostname before package installation staticsafe 2020-11-25 16:20:16 -0500
  • 42b6960609 add 217.160.142.105 to ipset staticsafe 2020-10-28 10:39:58 -0400
  • 8ac714f548 consolidate adsbot prefixes into two /24s staticsafe 2020-10-15 13:14:57 -0400
  • 0506ecb009 remove - in host group name in icinga-client-install.yml staticsafe 2020-10-12 09:11:51 -0400
  • 87c531e0c5 update adsbot prefixes staticsafe 2020-10-12 09:10:32 -0400
  • 4343fdf1f6 install python-is-python3 as part of common role staticsafe 2020-10-11 14:37:53 -0400
  • 016d71151a set phpfpm socket to 7.4 staticsafe 2020-10-03 22:02:17 -0400
  • 4e96352e88 add another adsbot IP into the ipset staticsafe 2020-09-23 10:59:46 -0400
  • 340637ef19 add another subnet of Aspiegel bot staticsafe 2020-09-12 12:19:30 -0400
  • c28997cd60 add another adsbot IP to nasties ipset staticsafe 2020-09-11 19:47:06 -0400
  • 4f7b399783 add another adsbot IP to ipset list staticsafe 2020-09-09 09:26:58 -0400
  • 10ba23f5d6 add another Adsbot IP to the nasties ipset staticsafe 2020-09-07 12:40:14 -0400
  • 4d0660e162 quotes needed staticsafe 2020-08-22 19:03:07 -0400
  • 1bd0269944 make sure to set hostname on new nodes and turn off motd news on focal staticsafe 2020-08-22 19:00:39 -0400
  • 2d45e87d98 remove sshd_config copy in common role its in ssh-enforcement now staticsafe 2020-08-22 18:43:14 -0400
  • e574b1d4de remove catsith.asininetech.net.yml no longer needed staticsafe 2020-08-22 16:44:42 -0400
  • 9aa40b3967 Clean up site.yml and move some other roles into their own yml files staticsafe 2020-08-22 16:21:24 -0400
  • b2bd30101b ssh-enforcement role should be run for unsetup hosts as well. staticsafe 2020-08-22 15:59:23 -0400
  • 2bfed5b9ed add ssh-enforcement playbook staticsafe 2020-08-22 15:47:16 -0400
  • b6946a3e26
    Update pgbackrest version to 2.28 Sadiq Saif 2020-08-18 08:40:19 -0400
  • c73f1f6b7c add woff2 to static resources to be cached staticsafe 2020-07-30 17:57:20 -0400
  • d2b0e47564 add Adsbot IPs to webserver ipsets staticsafe 2020-07-29 08:46:21 -0400
  • 36086ba967 fix an extraneous space in erlking.asininetech.net.yml staticsafe 2020-07-27 15:26:02 -0400
  • 3715879e77 add WP caching config to other sites now staticsafe 2020-07-27 13:42:39 -0400
  • 33c6fc78e2 fix extra bracket staticsafe 2020-07-27 13:37:42 -0400
  • b604283ce5 improve WP caching setup testing on asininetech.com staticsafe 2020-07-27 13:33:39 -0400
  • 91404bb5f1 remove extraneous ; staticsafe 2020-07-26 19:27:37 -0400
  • 377568f7cd remove quotes staticsafe 2020-07-26 19:26:42 -0400
  • 2e468240fd add new Access-Control-Allow-Origin header for Mastodon 3.2.0 staticsafe 2020-07-26 19:23:51 -0400
  • 1b6e048e43 cleanup as393949.net staticsafe 2020-07-18 22:41:02 -0400
  • 8dd8505d0a remove as393949.net staticsafe 2020-07-18 22:21:32 -0400
  • 4ea258d17b add 149.248.4.242 to deirdre.asininetech.net.ipset staticsafe 2020-07-05 14:34:42 -0400
  • 71fc82ed22 remove namshiel.asininetech.net.rules.* staticsafe 2020-07-05 14:33:22 -0400
  • f5f09ebc58 add 2001:19f0:6001:5aa0:5400:2ff:fecf:eee5 to drop for deirdre staticsafe 2020-07-05 14:31:34 -0400
  • 7426c88be2 add 75.64.236.168/32 to deirdre and waldo ipset staticsafe 2020-06-27 17:31:02 -0400
  • f091373a1b add yet another pimeyes.com crawler IP to ipset staticsafe 2020-06-01 23:31:36 -0400
  • 07badc1ff1 add another pimeyes crawler IP to ipset staticsafe 2020-06-01 23:16:57 -0400
  • c69b2dda9a add another pimeyes.com crawler IP staticsafe 2020-05-27 21:05:07 -0400
  • 146fd41a7f add pimeeyes.com crawler IP to nasties ipset staticsafe 2020-05-27 21:01:02 -0400
  • e1c36822fa add a centurybot IP to nasties ipset staticsafe 2020-05-27 13:44:16 -0400
  • 4fbedfec4e add Aspiegel bot range to nasties ipset staticsafe 2020-05-19 13:23:32 -0400
  • 1a633fb947 sadiqsaif.com does not need a custom 404 page anymore. staticsafe 2020-05-07 16:47:53 -0400
  • 4c573cb5a0 remove python-pip and python-dev from common role staticsafe 2020-04-23 16:55:03 -0400
  • 27b9e93b0d reference nasties ipset for erlking and waldo staticsafe 2020-04-15 10:54:43 -0400
  • fd475f98cb add some more ipsets for erlking and waldo staticsafe 2020-04-15 10:52:25 -0400
  • d8f5681c52 fix typo in ipset.service staticsafe 2020-04-15 10:26:22 -0400
  • dd4d335302 make ipset.service import even if ipset already exists and then reload in main.yml staticsafe 2020-04-15 10:23:45 -0400
  • 05176fb83e don't destroy ipset in main.yml staticsafe 2020-04-15 10:15:24 -0400
  • 3fb3507d40 make some more explicit requirements in ipset.service staticsafe 2020-04-15 10:13:53 -0400
  • 8aa1d869ba clean up unnecessary comments in firewall rulesets staticsafe 2020-04-14 22:40:54 -0400
  • a7888e95bf set FLUSH_ON_STOP to 0 staticsafe 2020-04-14 22:36:05 -0400