feat: first commit

This commit is contained in:
kodacci committed 2026-10-11 00:13:32 +03:00
commit 5fdf790556
25 files changed
+1957

No files matched your search

+4
View File
@@ -0,0 +1,4 @@
.venv
.vscode
*.pem
+2
View File
@@ -0,0 +1,2 @@
# VPS setup ansible script
Setup VPS for basic needs with ansible playbook
+38
View File
@@ -0,0 +1,38 @@
// prime the server with knowledge of the root servers
//zone "." {
// type hint;
// file "/usr/share/dns/root.hints";
//};
// be authoritative for the localhost forward and reverse zones, and for
// broadcast zones as per RFC 1912
view "ext" {
match-clients{"any";};
zone "." {
type hint;
file "/usr/share/dns/root.hints";
};
zone "localhost" {
type master;
file "/etc/bind/db.local";
};
zone "127.in-addr.arpa" {
type master;
file "/etc/bind/db.127";
};
zone "0.in-addr.arpa" {
type master;
file "/etc/bind/db.0";
};
zone "255.in-addr.arpa" {
type master;
file "/etc/bind/db.255";
};
};
+36
View File
@@ -0,0 +1,36 @@
//
// Do any local configuration here
//
// Consider adding the 1918 zones here, if they are not used in your
// organization
//include "/etc/bind/zones.rfc1918";
acl "int-8" {10.8.0.0/24;};
acl "int-9" {10.9.0.0/24;};
view "int-8" {
match-clients{"int-8";};
zone "ra-tech.pro" {
type master;
file "/etc/bind/zones/db.ra-tech.pro";
};
zone "0.8.10.in-addr.arpa" {
type master;
file "/etc/bind/zones/db.10.8.0";
};
};
view "int-9" {
match-clients{"int-9";};
zone "ra-tech.pro" {
type master;
file "/etc/bind/zones/db.v9.ra-tech.pro";
};
zone "0.9.10.in-addr.arpa" {
type master;
file "/etc/bind/zones/db.10.9.0";
};
};
+36
View File
@@ -0,0 +1,36 @@
options {
directory "/var/cache/bind";
// If there is a firewall between you and nameservers you want
// to talk to, you may need to fix the firewall to allow multiple
// ports to talk. See http://www.kb.cert.org/vuls/id/800113
// If your ISP provided one or more IP addresses for stable
// nameservers, you probably want to use them as forwarders.
// Uncomment the following block, and insert the addresses replacing
// the all-0's placeholder.
// forwarders {
// 0.0.0.0;
// };
//========================================================================
// If BIND logs error messages about the root key being expired,
// you will need to update your keys. See https://www.isc.org/bind-keys
//========================================================================
dnssec-validation auto;
listen-on {
10.8.0.0/24;
10.9.0.0/24;
};
allow-query { any; };
forwarders {
8.8.8.8;
8.8.4.4;
};
//listen-on-v6 { any; };
};
+7
View File
@@ -0,0 +1,7 @@
view "ext" {
// prime the server with knowledge of the root servers
zone "." {
type hint;
file "/usr/share/dns/root.hints";
};
}
+41
View File
@@ -0,0 +1,41 @@
;
; BIND reverse data file for local loopback interface
;
$TTL 604800
$ORIGIN 0.8.10.in-addr.arpa.
@ IN SOA ns.ra-tech.pro. admin.ra-tech.pro. (
1 ; Serial
604800 ; Refresh
86400 ; Retry
2419200 ; Expire
604800 ) ; Negative Cache TTL
;
; name servers
IN NS ns.ra-tech.pro.
; PTR Records
1 IN PTR ns.ra-tech.pro.
1 IN PTR vps.ra-tech.pro.
10 IN PTR odroid.ra-tech.pro.
10 IN PTR jenkins.ra-tech.pro.
10 IN PTR nexus.ra-tech.pro.
10 IN PTR docker.ra-tech.pro.
10 IN PTR sonar.ra-tech.pro.
10 IN PTR cloud.ra-tech.pro.
10 IN PTR db.ra-tech.pro.
10 IN PTR dashboard.cloud.ra-tech.pro.
10 IN PTR garden-manager.db.ra-tech.pro.
10 IN PTR giga-ai-agent.db.ra-tech.pro.
10 IN PTR vault.ra-tech.pro.
10 IN PTR docker-registry.ra-tech.pro.
10 IN PTR snapshots.docker-registry.ra-tech.pro.
10 IN PTR prometheus.ra-tech.pro.
10 IN PTR pki.ra-tech.pro.
10 IN PTR grafana.ra-tech.pro.
10 IN PTR hfs.ra-tech.pro.
10 IN PTR kafka-1.ra-tech.pro.
10 IN PTR kafka.ra-tech.pro.
10 IN PTR elasticsearch.ra-tech.pro.
10 IN PTR kibana.ra-tech.pro.
10 IN PTR chrome.selenium.ra-tech.pro.
10 IN PTR git.ra-tech.pro.
+41
View File
@@ -0,0 +1,41 @@
;
; BIND reverse data file for local loopback interface
;
$TTL 604800
$ORIGIN 0.9.10.in-addr.arpa.
@ IN SOA ns.ra-tech.pro. admin.ra-tech.pro. (
1 ; Serial
604800 ; Refresh
86400 ; Retry
2419200 ; Expire
604800 ) ; Negative Cache TTL
;
; name servers
IN NS ns.ra-tech.pro.
; PTR Records
1 IN PTR ns.ra-tech.pro.
1 IN PTR vps.ra-tech.pro.
10 IN PTR odroid.ra-tech.pro.
10 IN PTR jenkins.ra-tech.pro.
10 IN PTR nexus.ra-tech.pro.
10 IN PTR docker.ra-tech.pro.
10 IN PTR sonar.ra-tech.pro.
10 IN PTR cloud.ra-tech.pro.
10 IN PTR db.ra-tech.pro.
10 IN PTR dashboard.cloud.ra-tech.pro.
10 IN PTR garden-manager.db.ra-tech.pro.
10 IN PTR giga-ai-agent.db.ra-tech.pro.
10 IN PTR vault.ra-tech.pro.
10 IN PTR docker-registry.ra-tech.pro.
10 IN PTR snapshots.docker-registry.ra-tech.pro.
10 IN PTR prometheus.ra-tech.pro.
10 IN PTR pki.ra-tech.pro.
10 IN PTR grafana.ra-tech.pro.
10 IN PTR hfs.ra-tech.pro.
10 IN PTR kafka-1.ra-tech.pro.
10 IN PTR kafka.ra-tech.pro.
10 IN PTR elasticsearch.ra-tech.pro.
10 IN PTR kibana.ra-tech.pro.
10 IN PTR chrome.selenium.ra-tech.pro.
10 IN PTR git.ra-tech.pro.
+54
View File
@@ -0,0 +1,54 @@
;
; BIND data file for local loopback interface
;
$TTL 604800
@ IN SOA ns.ra-tech.pro. admin.ra-tech.pro. (
1 ; Serial
604800 ; Refresh
86400 ; Retry
2419200 ; Expire
604800 ) ; Negative Cache TTL
; name servers - NS records
IN NS ns.ra-tech.pro.
; name servers - A records
ns.ra-tech.pro. IN A 10.8.0.1
; 10.8.0.0/24 - A records
vps.ra-tech.pro. IN A 10.8.0.1
odroid.ra-tech.pro. IN A 10.8.0.10
jenkins.ra-tech.pro. IN A 10.8.0.10
nexus.ra-tech.pro. IN A 10.8.0.10
docker.ra-tech.pro. IN A 10.8.0.10
sonar.ra-tech.pro. IN A 10.8.0.10
cloud.ra-tech.pro. IN A 10.8.0.10
dashboard.cloud.ra-tech.pro. IN A 10.8.0.10
db.ra-tech.pro. IN A 10.8.0.10
garden-manager.db.ra-tech.pro. IN A 10.8.0.10
giga-ai-agent.db.ra-tech.pro. IN A 10.8.0.10
vault.ra-tech.pro. IN A 10.8.0.10
docker-registry.ra-tech.pro. IN A 10.8.0.10
snapshots.docker-registry.ra-tech.pro. IN A 10.8.0.10
pki.ra-tech.pro. IN A 10.8.0.10
prometheus.ra-tech.pro. IN A 10.8.0.10
grafana.ra-tech.pro. IN A 10.8.0.10
syncthing.ra-tech.pro. IN A 10.8.0.10
kuber.ra-tech.pro. IN A 10.8.0.10
garden-manager.cloud.ra-tech.pro. IN A 10.8.0.10
garden-manager.test.cloud.ra-tech.pro. IN A 10.8.0.10
api.garden-manager.cloud.ra-tech.pro. IN A 10.8.0.10
api.garden-manager.test.cloud.ra-tech.pro. IN A 10.8.0.10
solr.ra-tech.pro. IN A 10.8.0.10
auth.ra-tech.pro. IN A 10.8.0.10
api.giga-ai-agent.cloud.ra-tech.pro. IN A 10.8.0.10
api.giga-ai-agent.test.cloud.ra-tech.pro. IN A 10.8.0.10
giga-ai-agent.cloud.ra-tech.pro. IN A 10.8.0.10
giga-ai-agent.test.cloud.ra-tech.pro. IN A 10.8.0.10
hfs.ra-tech.pro. IN A 10.8.0.10
kafka-1.ra-tech.pro. IN A 10.8.0.10
kafka.ra-tech.pro. IN A 10.8.0.10
elasticsearch.ra-tech.pro. IN A 10.8.0.10
kibana.ra-tech.pro. IN A 10.8.0.10
chrome.selenium.ra-tech.pro. IN A 10.8.0.10
git.ra-tech.pro. IN A 10.8.0.10
+54
View File
@@ -0,0 +1,54 @@
;
; BIND data file for local loopback interface
;
$TTL 604800
@ IN SOA ns.ra-tech.pro. admin.ra-tech.pro. (
1 ; Serial
604800 ; Refresh
86400 ; Retry
2419200 ; Expire
604800 ) ; Negative Cache TTL
; name servers - NS records
IN NS ns.ra-tech.pro.
; name servers - A records
ns.ra-tech.pro. IN A 10.9.0.1
; 10.8.0.0/24 - A records
vps.ra-tech.pro. IN A 10.9.0.1
odroid.ra-tech.pro. IN A 10.9.0.10
jenkins.ra-tech.pro. IN A 10.9.0.10
nexus.ra-tech.pro. IN A 10.9.0.10
docker.ra-tech.pro. IN A 10.9.0.10
sonar.ra-tech.pro. IN A 10.9.0.10
cloud.ra-tech.pro. IN A 10.9.0.10
dashboard.cloud.ra-tech.pro. IN A 10.9.0.10
db.ra-tech.pro. IN A 10.9.0.10
garden-manager.db.ra-tech.pro. IN A 10.9.0.10
giga-ai-agent.db.ra-tech.pro. IN A 10.9.0.10
vault.ra-tech.pro. IN A 10.9.0.10
docker-registry.ra-tech.pro. IN A 10.9.0.10
snapshots.docker-registry.ra-tech.pro. IN A 10.9.0.10
pki.ra-tech.pro. IN A 10.9.0.10
prometheus.ra-tech.pro. IN A 10.9.0.10
grafana.ra-tech.pro. IN A 10.9.0.10
syncthing.ra-tech.pro. IN A 10.9.0.10
kuber.ra-tech.pro. IN A 10.9.0.10
garden-manager.cloud.ra-tech.pro. IN A 10.9.0.10
garden-manager.test.cloud.ra-tech.pro. IN A 10.9.0.10
api.garden-manager.cloud.ra-tech.pro. IN A 10.9.0.10
api.garden-manager.test.cloud.ra-tech.pro. IN A 10.9.0.10
solr.ra-tech.pro. IN A 10.9.0.10
auth.ra-tech.pro. IN A 10.9.0.10
api.giga-ai-agent.cloud.ra-tech.pro. IN A 10.9.0.10
api.giga-ai-agent.test.cloud.ra-tech.pro. IN A 10.9.0.10
giga-ai-agent.cloud.ra-tech.pro. IN A 10.9.0.10
giga-ai-agent.test.cloud.ra-tech.pro. IN A 10.9.0.10
hfs.ra-tech.pro. IN A 10.9.0.10
kafka-1.ra-tech.pro. IN A 10.9.0.10
kafka.ra-tech.pro. IN A 10.9.0.10
elasticsearch.ra-tech.pro. IN A 10.9.0.10
kibana.ra-tech.pro. IN A 10.9.0.10
chrome.selenium.ra-tech.pro. IN A 10.9.0.10
git.ra-tech.pro. IN A 10.9.0.10
+12
View File
@@ -0,0 +1,12 @@
[Unit]
Description=Cloak server
After=network.target
[Service]
ExecStart=/usr/local/bin/ck-server -c /etc/cloak/server.json
Restart=always
Type=exec
User=cloak
[Install]
WantedBy=default.target
+21
View File
@@ -0,0 +1,21 @@
{
"ProxyBook": {
"openvpn": [
"tcp",
"{{ public_ip }}:5690"
]
},
"BindAddr": [
":5691"
],
"BypassUID": [
"hs3Zsj/9mvt7+3bhgkg7Tw==",
"VF3YuD37EPGcMyfJOBM+zw==",
"2GT18pqRxb6BOqJWQK42rg==",
"LN9ESPPnGDN5bU4qJJGm3Q=="
],
"RedirAddr": "vk.ru",
"PrivateKey": "cFMDGEt3L8Rm7APM9creW3KBrYrVP3pIjZvlNgV32Fs=",
"AdminUID": "rVobMUVWAh1Do4QF/wzdVw==",
"DatabasePath": "/opt/cloak/userinfo.db"
}
+200
View File
@@ -0,0 +1,200 @@
hosts:
- ra-tech.dev
- xmpp.ra-itech.ru
hosts_alias:
"64.188.58.223": "ra-tech.dev"
language: ru
loglevel: info
certfiles:
- /etc/ejabberd/server.pem
- /etc/ejabberd/server-key.pem
- /etc/ejabberd/certs/fullchain.pem
- /etc/ejabberd/certs/privkey.pem
auth_method: internal
auth_password_format: scram
auth_scram_hash: sha512
sql_database: /opt/ejabberd/sqlite/db.sqlite
sql_type: sqlite
sql_pool_size: 1
s2s_access:
deny: all
acl:
admin:
user:
- kodacci@ra-tech.dev
- kodacci@xmpp.ra-itech.ru
disabled_servers:
server:
- "p2.siacs.eu"
access_rules:
configure:
allow: admin
announce:
allow: admin
c2s:
deny: blocked
allow: all
pubsub_createnode:
allow: admin
s2s:
deny: disabled_servers
shaper:
fast: 3000000
shaper_rules:
max_user_sessions: 50
max_user_offline_messages: 5000
c2s_shaper: fast
modules:
mod_adhoc: {}
mod_adhoc_api: {}
mod_admin_extra: {}
mod_announce:
access: announce
mod_avatar: {}
mod_blocking: {}
mod_bosh: {}
mod_caps: {}
mod_carboncopy: {}
mod_client_state: {}
mod_configure: {}
mod_disco: {}
mod_fail2ban: {}
mod_http_api: {}
mod_last: {}
mod_muc:
access_admin:
- allow: admin
mod_muc_admin: {}
mod_offline:
access_max_user_messages: max_user_offline_messages
mod_ping:
send_pings: true
ping_interval: 1 min
mod_privacy: {}
mod_private: {}
mod_push: {}
mod_push_keepalive: {}
mod_roster:
versioning: true
mod_s2s_bidi: {}
mod_s2s_dialback: {}
mod_shared_roster: {}
mod_stream_mgmt:
resend_on_timeout: if_offline
mod_stun_disco:
access: c2s
credentials_lifetime: 12h
services:
- host: xmpp.ra-itech.ru
port: 3478
type: stun
transport: udp
restricted: false
- host: xmpp.ra-itech.ru
port: 3478
type: turn
transport: udp
restricted: true
- host: xmpp.ra-itech.ru
port: 5349
type: stuns
transport: tcp
restricted: false
- host: xmpp.ra-itech.ru
port: 5349
type: turns
transport: tcp
restricted: true
mod_vcard: {}
mod_vcard_xupdate: {}
mod_version:
show_os: false
mod_pubsub:
access_createnode: pubsub_createnode
plugins:
- flat
- pep
force_node_config:
## Avoid buggy clients to make their bookmarks public
storage:bookmarks:
access_model: whitelist
mod_proxy65:
access: c2s
max_connections: 50
port: 7788
shaper: fast
mod_http_fileserver:
accesslog: /opt/ejabberd/logs/access.log
docroot:
/files: /opt/fileserver
mod_http_upload:
access: c2s
docroot: /opt/fileserver
put_url: "https://@HOST@:5443/upload"
get_url: "https://@HOST@:5443/files"
mod_mam:
access_preferences: c2s
db_type: sql
listen:
- port: 5222
ip: "::"
module: ejabberd_c2s
shaper: c2s_shaper
access: c2s
max_stanza_size: 262144
starttls: true
allow_unencrypted_sasl2: false
cafile: /etc/ejabberd/ca.pem
starttls_required: true
tls_verify: true
- port: 5223
ip: "::"
module: ejabberd_c2s
shaper: c2s_shaper
access: c2s
max_stanza_size: 262144
starttls: true
starttls_required: true
tls_verify: false
- port: 3478
transport: udp
module: ejabberd_stun
use_turn: true
turn_min_port: 49152
turn_max_port: 65535
turn_ip: 64.188.58.223
- port: 5349
transport: tcp
module: ejabberd_stun
use_turn: true
tls: true
turn_min_port: 49152
turn_max_port: 65535
ip: 64.188.58.223
turn_ip: 64.188.58.223
- port: 5443
ip: "::"
transport: tcp
module: ejabberd_http
tls: true
request_handlers:
/files: mod_http_fileserver
/upload: mod_http_upload
/bosh: mod_bosh
+58
View File
@@ -0,0 +1,58 @@
global
log /dev/log local0
log /dev/log local1 notice
chroot /var/lib/haproxy
stats socket /run/haproxy/admin.sock mode 660 level admin expose-fd listeners
stats timeout 30s
user haproxy
group haproxy
daemon
# Default SSL material locations
ca-base /etc/ssl/certs
crt-base /etc/ssl/private
# See: https://ssl-config.mozilla.org/#server=haproxy&server-version=2.0.3&config=intermediate
#ssl-default-bind-ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384
#ssl-default-bind-ciphersuites TLS_AES_128_GCM_SHA256:TLS_AES_256_GCM_SHA384:TLS_CHACHA20_POLY1305_SHA256
#ssl-default-bind-options ssl-min-ver TLSv1.2 no-tls-tickets
defaults
log global
mode http
option httplog
option dontlognull
timeout connect 5000
timeout client 50000
timeout server 50000
errorfile 400 /etc/haproxy/errors/400.http
errorfile 403 /etc/haproxy/errors/403.http
errorfile 408 /etc/haproxy/errors/408.http
errorfile 500 /etc/haproxy/errors/500.http
errorfile 502 /etc/haproxy/errors/502.http
errorfile 503 /etc/haproxy/errors/503.http
errorfile 504 /etc/haproxy/errors/504.http
frontend jenkins_webhook_front
mode http
bind :7777 ssl crt /etc/haproxy/certs/64.188.58.223.pem
http-request set-header X-Forwarded-For %[src]
use_backend jenkins_webhook_back if { path /github-webhook/ } || { path /github-webhook }
backend jenkins_webhook_back
mode http
http-request set-header Host jenkins.ra-tech.pro
server jenkins_main jenkins.ra-tech.pro:443 ssl verify none check resolvers nameservers
resolvers nameservers
nameserver ra-tech 10.8.0.1:53
#nameserver google 8.8.8.8:53
frontend stats
bind 10.8.0.1:8404
bind 10.9.0.1:8404
mode http
http-request use-service prometheus-exporter if { path /metrics }
stats enable
stats uri /stats
stats refresh 15s
+14
View File
@@ -0,0 +1,14 @@
vps_servers:
vars:
ansible_become: true
ansible_become_user: root
ansible_become_method: su
ansible_user: kodacci
hosts:
ru-vpn:
ansible_host: ru-vpn.ra-itech.ru
public_ip: 45.87.247.103
public_ip_iface: ens3
ansible_port: 12801
+15
View File
@@ -0,0 +1,15 @@
[Unit]
Description=Node Exporter
Wants=network-online.target
After=network-online.target
[Service]
User=node_exporter
Group=node_exporter
Type=simple
ExecStart=/usr/local/bin/node_exporter
Restart=always
RestartSec=3
[Install]
WantedBy=multi-user.target
+21
View File
@@ -0,0 +1,21 @@
#
# 2048 bit OpenVPN static key
#
-----BEGIN OpenVPN Static key V1-----
ca6b90a1782a8940fbfd685dd1c92cff
7958116231f3f096569271880c54a53f
0aeb0872933e9ca7c3efaaed3b63831b
21be29430b4dd8634200131a197470de
061d716c133e25f7edd3802beba11851
f5c1347f63c1ce072ba26219a9f68f13
76057ff561468d267792e0f249342956
d4df6c72efffcc21c7d09d1b5415cebc
bf4cdc0369bc8bc16a86a7b7c5f61ae5
9b87777aeccdbcf9d50f15aa4427adb8
2263df1c1475471989a8eff935e0c5ac
e85580b0f90633bf92570aaa15910850
d4017e502f0eeaf46f555ff9740c655c
26db7bf2f06948249e75a869d4d47e89
847ce8f14969a5cc3b60928838146305
797f11d4cf08d4c06223c47747ec8798
-----END OpenVPN Static key V1-----
+320
View File
@@ -0,0 +1,320 @@
#################################################
# Sample OpenVPN 2.0 config file for #
# multi-client server. #
# #
# This file is for the server side #
# of a many-clients <-> one-server #
# OpenVPN configuration. #
# #
# OpenVPN also supports #
# single-machine <-> single-machine #
# configurations (See the Examples page #
# on the web site for more info). #
# #
# This config should work on Windows #
# or Linux/BSD systems. Remember on #
# Windows to quote pathnames and use #
# double backslashes, e.g.: #
# "C:\\Program Files\\OpenVPN\\config\\foo.key" #
# #
# Comments are preceded with '#' or ';' #
#################################################
# Which local IP address should OpenVPN
# listen on? (optional)
;local a.b.c.d
# Which TCP/UDP port should OpenVPN listen on?
# If you want to run multiple OpenVPN instances
# on the same machine, use a different port
# number for each one. You will need to
# open up this port on your firewall.
# port 1194
port 5690
# TCP or UDP server?
proto tcp
;proto udp
# "dev tun" will create a routed IP tunnel,
# "dev tap" will create an ethernet tunnel.
# Use "dev tap0" if you are ethernet bridging
# and have precreated a tap0 virtual interface
# and bridged it with your ethernet interface.
# If you want to control access policies
# over the VPN, you must create firewall
# rules for the the TUN/TAP interface.
# On non-Windows systems, you can give
# an explicit unit number, such as tun0.
# On Windows, use "dev-node" for this.
# On most systems, the VPN will not function
# unless you partially or fully disable
# the firewall for the TUN/TAP interface.
;dev tap
dev tun
# Windows needs the TAP-Win32 adapter name
# from the Network Connections panel if you
# have more than one. On XP SP2 or higher,
# you may need to selectively disable the
# Windows firewall for the TAP adapter.
# Non-Windows systems usually don't need this.
;dev-node MyTap
# SSL/TLS root certificate (ca), certificate
# (cert), and private key (key). Each client
# and the server must have their own cert and
# key file. The server and all clients will
# use the same ca file.
#
# See the "easy-rsa" directory for a series
# of scripts for generating RSA certificates
# and private keys. Remember to use
# a unique Common Name for the server
# and each of the client certificates.
#
# Any X509 key management system can be used.
# OpenVPN can also use a PKCS #12 formatted key file
# (see "pkcs12" directive in man page).
ca ca.pem
cert server.pem
key server-key.pem # This file should be kept secret
# Diffie hellman parameters.
# Generate your own with:
# openssl dhparam -out dh2048.pem 2048
#dh dh2048.pem
dh none
# Network topology
# Should be subnet (addressing via IP)
# unless Windows clients v2.0.9 and lower have to
# be supported (then net30, i.e. a /30 per client)
# Defaults to net30 (not recommended)
;topology subnet
# Configure server mode and supply a VPN subnet
# for OpenVPN to draw client addresses from.
# The server will take 10.8.0.1 for itself,
# the rest will be made available to clients.
# Each client will be able to reach the server
# on 10.8.0.1. Comment this line out if you are
# ethernet bridging. See the man page for more info.
server 10.8.0.0 255.255.255.0
# Maintain a record of client <-> virtual IP address
# associations in this file. If OpenVPN goes down or
# is restarted, reconnecting clients can be assigned
# the same virtual IP address from the pool that was
# previously assigned.
ifconfig-pool-persist /var/log/openvpn/ipp.txt
# Configure server mode for ethernet bridging.
# You must first use your OS's bridging capability
# to bridge the TAP interface with the ethernet
# NIC interface. Then you must manually set the
# IP/netmask on the bridge interface, here we
# assume 10.8.0.4/255.255.255.0. Finally we
# must set aside an IP range in this subnet
# (start=10.8.0.50 end=10.8.0.100) to allocate
# to connecting clients. Leave this line commented
# out unless you are ethernet bridging.
;server-bridge 10.8.0.4 255.255.255.0 10.8.0.50 10.8.0.100
# Configure server mode for ethernet bridging
# using a DHCP-proxy, where clients talk
# to the OpenVPN server-side DHCP server
# to receive their IP address allocation
# and DNS server addresses. You must first use
# your OS's bridging capability to bridge the TAP
# interface with the ethernet NIC interface.
# Note: this mode only works on clients (such as
# Windows), where the client-side TAP adapter is
# bound to a DHCP client.
;server-bridge
# Push routes to the client to allow it
# to reach other private subnets behind
# the server. Remember that these
# private subnets will also need
# to know to route the OpenVPN client
# address pool (10.8.0.0/255.255.255.0)
# back to the OpenVPN server.
;push "route 192.168.10.0 255.255.255.0"
;push "route 192.168.20.0 255.255.255.0"
# To assign specific IP addresses to specific
# clients or if a connecting client has a private
# subnet behind it that should also have VPN access,
# use the subdirectory "ccd" for client-specific
# configuration files (see man page for more info).
# EXAMPLE: Suppose the client
# having the certificate common name "Thelonious"
# also has a small subnet behind his connecting
# machine, such as 192.168.40.128/255.255.255.248.
# First, uncomment out these lines:
;client-config-dir ccd
;route 192.168.40.128 255.255.255.248
# Then create a file ccd/Thelonious with this line:
# iroute 192.168.40.128 255.255.255.248
# This will allow Thelonious' private subnet to
# access the VPN. This example will only work
# if you are routing, not bridging, i.e. you are
# using "dev tun" and "server" directives.
# EXAMPLE: Suppose you want to give
# Thelonious a fixed VPN IP address of 10.9.0.1.
# First uncomment out these lines:
;client-config-dir ccd
;route 10.9.0.0 255.255.255.252
# Then add this line to ccd/Thelonious:
# ifconfig-push 10.9.0.1 10.9.0.2
# Suppose that you want to enable different
# firewall access policies for different groups
# of clients. There are two methods:
# (1) Run multiple OpenVPN daemons, one for each
# group, and firewall the TUN/TAP interface
# for each group/daemon appropriately.
# (2) (Advanced) Create a script to dynamically
# modify the firewall in response to access
# from different clients. See man
# page for more info on learn-address script.
;learn-address ./script
# If enabled, this directive will configure
# all clients to redirect their default
# network gateway through the VPN, causing
# all IP traffic such as web browsing and
# and DNS lookups to go through the VPN
# (The OpenVPN server machine may need to NAT
# or bridge the TUN/TAP interface to the internet
# in order for this to work properly).
push "redirect-gateway def1 bypass-dhcp"
# Certain Windows-specific network settings
# can be pushed to clients, such as DNS
# or WINS server addresses. CAVEAT:
# http://openvpn.net/faq.html#dhcpcaveats
# The addresses below refer to the public
# DNS servers provided by opendns.com.
# push "dhcp-option DNS 208.67.222.222"
push "dhcp-option DNS 10.8.0.1"
push "dhcp-option DNS 208.67.220.220"
# Uncomment this directive to allow different
# clients to be able to "see" each other.
# By default, clients will only see the server.
# To force clients to only see the server, you
# will also need to appropriately firewall the
# server's TUN/TAP interface.
;client-to-client
# Uncomment this directive if multiple clients
# might connect with the same certificate/key
# files or common names. This is recommended
# only for testing purposes. For production use,
# each client should have its own certificate/key
# pair.
#
# IF YOU HAVE NOT GENERATED INDIVIDUAL
# CERTIFICATE/KEY PAIRS FOR EACH CLIENT,
# EACH HAVING ITS OWN UNIQUE "COMMON NAME",
# UNCOMMENT THIS LINE OUT.
;duplicate-cn
# The keepalive directive causes ping-like
# messages to be sent back and forth over
# the link so that each side knows when
# the other side has gone down.
# Ping every 10 seconds, assume that remote
# peer is down if no ping received during
# a 120 second time period.
keepalive 10 120
# For extra security beyond that provided
# by SSL/TLS, create an "HMAC firewall"
# to help block DoS attacks and UDP port flooding.
#
# Generate with:
# openvpn --genkey --secret ta.key
#
# The server and each client must have
# a copy of this key.
# The second parameter should be '0'
# on the server and '1' on the clients.
#tls-auth ta.key 0 # This file is secret
tls-crypt ta.key
# Select a cryptographic cipher.
# This config item must be copied to
# the client config file as well.
# Note that v2.4 client/server will automatically
# negotiate AES-256-GCM in TLS mode.
# See also the ncp-cipher option in the manpage
cipher AES-256-GCM
auth SHA256
# Enable compression on the VPN link and push the
# option to the client (v2.4+ only, for earlier
# versions see below)
;compress lz4-v2
;push "compress lz4-v2"
# For compression compatible with older clients use comp-lzo
# If you enable it here, you must also
# enable it in the client config file.
;comp-lzo
# The maximum number of concurrently connected
# clients we want to allow.
;max-clients 100
# It's a good idea to reduce the OpenVPN
# daemon's privileges after initialization.
#
# You can uncomment this out on
# non-Windows systems.
user nobody
group nogroup
# The persist options will try to avoid
# accessing certain resources on restart
# that may no longer be accessible because
# of the privilege downgrade.
persist-key
persist-tun
# Output a short status file showing
# current connections, truncated
# and rewritten every minute.
status /var/log/openvpn/openvpn-status.log
# By default, log messages will go to the syslog (or
# on Windows, if running as a service, they will go to
# the "\Program Files\OpenVPN\log" directory).
# Use log or log-append to override this default.
# "log" will truncate the log file on OpenVPN startup,
# while "log-append" will append to it. Use one
# or the other (but not both).
;log /var/log/openvpn/openvpn.log
;log-append /var/log/openvpn/openvpn.log
# Set the appropriate level of log
# file verbosity.
#
# 0 is silent, except for fatal errors
# 4 is reasonable for general usage
# 5 and 6 can help to debug connection problems
# 9 is extremely verbose
verb 3
# Silence repeating messages. At most 20
# sequential messages of the same message
# category will be output to the log.
;mute 20
# Notify the client that when the server restarts so it
# can automatically reconnect.
explicit-exit-notify 1
+503
View File
@@ -0,0 +1,503 @@
- name: Setup ufw port forwarding for VPNs subnets
hosts: vps_servers
become: true
gather_facts: true
tasks:
- name: Install ufw
ansible.builtin.apt:
name: ufw
state: present
update_cache: true
# - name: Configure ufw port forwarding
# ansible.builtin.lineinfile:
# path: '/etc/sysctl.conf'
# regexp: '^#?net.ipv4.ip_forward='
# line: 'net.ipv4.ip_forward=1'
# state: present
# notify: Reload sysctl
- name: Configure ufw port forwarding
ansible.builtin.copy:
src: 'sysctl/99-ipv4-forward.conf'
dest: '/etc/sysctl.d/99-ipv4-forward.conf'
owner: root
group: root
mode: '0644'
notify: Reload sysctl
- name: Set ufw default forwarding policy
ansible.builtin.lineinfile:
path: '/etc/default/ufw'
regexp: '^DEFAULT_FORWARD_POLICY='
line: 'DEFAULT_FORWARD_POLICY="ACCEPT"'
state: present
notify: Reload ufw
- name: Add postrouting nat
ansible.builtin.blockinfile:
path: '/etc/ufw/before.rules'
insertbefore: '^\*filter'
block: |
# VPN NAT
*nat
:POSTROUTING ACCEPT [0:0]
-A POSTROUTING -s 10.9.0.0/24 -o {{ public_ip_iface }} -j MASQUERADE
-A POSTROUTING -s 10.8.0.0/24 -o {{ public_ip_iface }} -j MASQUERADE
-A POSTROUTING -s 10.10.0.0/24 -o {{ public_ip_iface }} -j MASQUERADE
COMMIT
# END VPN NAT
notify: Reload ufw
handlers:
- name: Reload sysctl
ansible.builtin.command: sysctl -p /etc/sysctl.d/99-ipv4-forward.conf
register: result
changed_when: result.rc == 0
- name: Reload ufw
ansible.builtin.command: ufw reload
register: result
changed_when: result.rc == 0
- name: Setup strongswan
hosts: vps_servers
become: true
gather_facts: true
tasks:
- name: Uninstall strongswan legacy packages if present
ansible.builtin.apt:
name:
- strongswan-starter
- strongswan-charon
state: absent
purge: true
autoremove: true
- name: Install strongswan with swanctl and vici
ansible.builtin.apt:
name:
- charon-systemd
- strongswan-swanctl
- libcharon-extra-plugins
state: present
update_cache: true
- name: Copy strongswan config
ansible.builtin.template:
src: 'strongswan/ra-tech.conf.j2'
dest: '/etc/swanctl/conf.d/ra-tech.conf'
owner: root
group: root
mode: '0644'
- name: Copy strongswan dhcp module config
ansible.builtin.template:
src: 'strongswan/charon/dhcp.conf.j2'
dest: '/etc/strongswan.d/charon/dhcp.conf'
owner: root
group: root
mode: '0644'
- name: Copy Root CA
ansible.builtin.copy:
src: 'strongswan/ca.pem'
dest: '/etc/swanctl/x509ca/ca-crt.pem'
owner: root
group: root
mode: '0644'
- name: Copy keys
ansible.builtin.copy:
src: 'strongswan/keys/'
dest: '/etc/swanctl/rsa/'
owner: root
group: root
mode: '0640'
- name: Copy certificates
ansible.builtin.copy:
src: 'strongswan/certs/'
dest: '/etc/swanctl/x509/'
owner: root
group: root
mode: '0644'
notify:
- Restart strongswan service
- name: Configure ra0 iface
ansible.builtin.script: 'strongswan/iface-ra0-up.sh'
- name: Copy ra0 iface setup script
ansible.builtin.copy:
src: 'strongswan/iface-ra0-up.sh'
dest: '/usr/local/bin'
owner: root
group: root
mode: '0755'
- name: Copy ra0 startup service
ansible.builtin.copy:
src: 'strongswan/iface-ra0.service'
dest: '/etc/systemd/system/iface-ra0.service'
owner: root
group: root
mode: '0644'
notify:
- Reload ra0 startup service
- name: Ufw allow strongswan ports
community.general.ufw:
rule: allow
proto: udp
port: '{{ item }}'
loop:
- '500'
- '4500'
- name: Ufw allow from vpn subnet
community.general.ufw:
rule: allow
proto: any
src: '10.9.0.0/24'
handlers:
- name: Restart strongswan service
ansible.builtin.systemd:
name: strongswan
state: restarted
enabled: true
- name: Reload ra0 startup service
ansible.builtin.systemd:
name: iface-ra0.service
enabled: true
daemon_reload: true
- name: Setup cloak
hosts: vps_servers
become: true
tasks:
- name: Create go download directory
ansible.builtin.file:
path: /opt/go
state: directory
mode: '0755'
- name: Download go
ansible.builtin.get_url:
url: 'https://go.dev/dl/go1.26.0.linux-amd64.tar.gz'
dest: '/opt/go/go1.26.0.linux-amd64.tar.gz'
mode: '0644'
timeout: 60
- name: Unpack go
ansible.builtin.unarchive:
src: '/opt/go/go1.26.0.linux-amd64.tar.gz'
dest: '/usr/local'
remote_src: true
- name: Install git and make
ansible.builtin.apt:
name:
- git
- make
state: present
update_cache: true
- name: Clone cloak git repository
ansible.builtin.git:
repo: 'https://github.com/cbeuw/Cloak.git'
dest: '/opt/git/Cloak'
single_branch: true
version: master
- name: Build cloak
community.general.make:
chdir: '/opt/git/Cloak'
environment:
PATH: '{{ ansible_env.PATH }}:/usr/local/go/bin'
- name: Setup cloak server
ansible.builtin.copy:
src: '/opt/git/Cloak/build/ck-server'
remote_src: true
dest: '/usr/local/bin'
owner: 'root'
group: 'root'
mode: '0755'
- name: Add cloak group
ansible.builtin.group:
name: cloak
state: present
- name: Add user for cloak
ansible.builtin.user:
name: cloak
group: cloak
state: present
createhome: false
- name: Create cloak directory
ansible.builtin.file:
path: '/etc/cloak'
state: directory
mode: '0755'
- name: Setup cloak server configuration
ansible.builtin.template:
src: 'cloak/server.json.j2'
dest: '/etc/cloak/server.json'
owner: root
group: cloak
mode: '0644'
- name: Create cloak server data dir
ansible.builtin.file:
path: '/opt/cloak'
state: directory
owner: cloak
group: cloak
mode: '0755'
- name: Setup cloak systemd service
ansible.builtin.copy:
src: 'cloak/cloak.service'
dest: '/etc/systemd/system/cloak.service'
mode: '0644'
notify: Reload cloak service
- name: Ufw allow cloak port
community.general.ufw:
rule: allow
port: '5691'
proto: tcp
handlers:
- name: Reload cloak service
ansible.builtin.systemd:
name: cloak.service
state: started
enabled: false
daemon_reload: true
- name: Setup openvpn server
hosts: vps_servers
become: true
tasks:
- name: Install openvpn server
ansible.builtin.apt:
name: openvpn
state: present
update_cache: true
- name: Copy certificates
ansible.builtin.copy:
src: 'openvpn/certs/'
dest: '/etc/openvpn/server/'
owner: root
group: root
mode: '0640'
- name: Copy openvpn config
ansible.builtin.copy:
src: 'openvpn/server.conf'
dest: '/etc/openvpn/server/server.conf'
owner: root
group: root
mode: '0644'
notify:
- Restart openvpn server
- name: Ufw allow openvpn port
community.general.ufw:
rule: allow
proto: tcp
port: '5690'
- name: Ufw allow from vpn subnet
community.general.ufw:
rule: allow
proto: any
src: '10.8.0.0/24'
handlers:
- name: Restart openvpn server
ansible.builtin.systemd:
name: openvpn-server@server
state: restarted
enabled: true
- name: Setup bind9
hosts: vps_servers
become: true
tasks:
- name: Install bind9
ansible.builtin.apt:
name: bind9
state: present
update_cache: true
- name: Copy bind9 config
ansible.builtin.copy:
src: '{{ item }}'
dest: '/etc/bind/'
owner: root
group: bind
mode: '0644'
loop:
- 'bind9/named.conf.local'
- 'bind9/named.conf.options'
- 'bind9/named.conf.default-zones'
- 'bind9/named.conf.root-hints'
- name: Copy bind9 zones
ansible.builtin.copy:
src: 'bind9/zones/'
dest: '/etc/bind/zones/'
owner: root
group: bind
mode: '0644'
notify:
- Restart bind9
- name: Ufw allow bind9 ports
community.general.ufw:
rule: allow
name: Bind9
handlers:
- name: Restart bind9
ansible.builtin.systemd:
name: named
state: restarted
enabled: true
daemon_reload: true
- name: Setup prometheus node exporter
hosts: vps_servers
become: true
tasks:
- name: Create node-exporter download directory
ansible.builtin.file:
path: /opt/node-exporter
state: directory
mode: '0755'
- name: Download node exporter executable
ansible.builtin.get_url:
url: 'https://github.com/prometheus/node_exporter/releases/download/v1.10.2/node_exporter-1.10.2.linux-amd64.tar.gz'
dest: '/opt/node-exporter/node_exporter-1.10.2.linux-amd64.tar.gz'
mode: '0644'
- name: Extract node_exporter
ansible.builtin.unarchive:
src: '/opt/node-exporter/node_exporter-1.10.2.linux-amd64.tar.gz'
dest: '/usr/local/bin'
remote_src: true
include:
- 'node_exporter-1.10.2.linux-amd64/node_exporter'
extra_opts:
- '--strip-components=1'
- name: Add node-exporter group
ansible.builtin.group:
name: node_exporter
state: present
- name: Add user for node exporter
ansible.builtin.user:
name: node_exporter
group: node_exporter
state: present
createhome: false
- name: Setup node-exporter service
ansible.builtin.copy:
src: 'node-exporter/node-exporter.service'
dest: '/etc/systemd/system/node-exporter.service'
owner: root
group: root
mode: '0644'
notify: Reload node-exporter
handlers:
- name: Reload node-exporter
ansible.builtin.systemd:
name: node-exporter
state: started
enabled: true
daemon_reload: true
- name: Setup haproxy
hosts: vps_servers
become: true
tasks:
- name: Install haproxy
ansible.builtin.apt:
name: haproxy
state: present
update_cache: true
- name: Create haproxy certs directory
ansible.builtin.file:
path: /etc/haproxy/certs/
state: directory
owner: root
group: haproxy
mode: '0755'
- name: Copy server certificate and key
ansible.builtin.copy:
src: 'haproxy/64.188.58.223.pem'
dest: '/etc/haproxy/certs/64.188.58.223.pem'
owner: root
group: haproxy
mode: '0640'
- name: Copy configuration
ansible.builtin.copy:
src: 'haproxy/haproxy.cfg'
dest: '/etc/haproxy/haproxy.cfg'
owner: root
group: haproxy
mode: '0644'
notify: Restart haproxy
- name: Allow ufw jenkins webhook port
community.general.ufw:
rule: allow
port: '7777'
proto: tcp
handlers:
- name: Restart haproxy
ansible.builtin.systemd:
name: haproxy
state: restarted
enabled: true
- name: Setup tiny proxy
hosts: vps_servers
become: true
tasks:
- name: Install tiny proxy
ansible.builtin.apt:
name: tinyproxy
state: present
update_cache: true
- name: Configure tiny proxy
ansible.builtin.copy:
src: 'tinyproxy/tinyproxy.conf'
dest: '/etc/tinyproxy/tinyproxy.conf'
mode: '0644'
notify: Restart tinyproxy
handlers:
- name: Restart tinyproxy
ansible.builtin.systemd:
name: tinyproxy
state: restarted
enabled: true
+6
View File
@@ -0,0 +1,6 @@
dhcp {
load = yes
force_server_address = yes
server = 10.9.0.255
interface = {{ public_ip_iface }}
}
+14
View File
@@ -0,0 +1,14 @@
#!/bin/bash
set +e
echo "Confiugring ra0 network interface at $(date)"
ip link add ra0 type xfrm if_id 0x21
ip link set ra0 up
ip addr add 10.9.0.1/24 brd + dev ra0
ip route add 10.9.0.0/24 dev ra0
set -e
exit 0
+11
View File
@@ -0,0 +1,11 @@
[Unit]
Description=Configure ra0 interface on startup
After=network.target
[Service]
ExecStart=/usr/local/bin/iface-ra0-up.sh
Type=oneshot
RemainAfterExit=yes
[Install]
WantedBy=multi-user.target
+92
View File
@@ -0,0 +1,92 @@
connections {
ra-tech {
pools = ra-tech-pool
local {
auth = pubkey
certs = vps-crt.pem
id = vps.ra-tech.dev
}
remote {
auth = pubkey
}
children {
ra-tech {
local_ts = 0.0.0.0/0
}
}
send_cert = always
if_id_in = 0x21
if_id_out = 0x21
}
ra-tech-ip {
pools = ra-tech-pool
local {
auth = pubkey
certs = ip-vps-crt.pem
id = {{ public_ip }}
}
remote {
auth = pubkey
}
children {
ra-tech-ip {
local_ts = 0.0.0.0/0
}
}
send_cert = always
if_id_in = 0x21
if_id_out = 0x21
}
ra-tech-subnet {
pools = ra-tech-pool
local {
auth = pubkey
certs = vpn-subnet-crt.pem
id = vpn-subnet.ra-tech.dev
}
remote {
auth = pubkey
}
children {
ra-tech-subnet {
local_ts = 10.9.0.0/24
}
}
send_cert = always
if_id_in = 0x21
if_id_out = 0x21
}
ra-tech-odroid {
pools = odroid-pool
local {
auth = pubkey
certs = odroid-vps-crt.pem
id = odroid-vps.ra-tech.dev
}
remote {
auth = pubkey
id = odroid@ra-tech.dev
}
children {
ra-tech-odroid {
local_ts = 0.0.0.0/0
}
}
if_id_in = 0x21
if_id_out = 0x21
}
}
pools {
ra-tech-pool {
addrs = 10.9.0.11 - 10.9.0.30
dns = 10.9.0.1
netmask = 255.255.255.0
}
odroid-pool {
addrs = 10.9.0.10
dns = 10.9.0.1
netmask = 255.255.255.0
}
}
+1
View File
@@ -0,0 +1 @@
net.ipv4.ip_forward=1
+356
View File
@@ -0,0 +1,356 @@
##
## tinyproxy.conf -- tinyproxy daemon configuration file
##
## This example tinyproxy.conf file contains example settings
## with explanations in comments. For decriptions of all
## parameters, see the tinproxy.conf(5) manual page.
##
#
# User/Group: This allows you to set the user and group that will be
# used for tinyproxy after the initial binding to the port has been done
# as the root user. Either the user or group name or the UID or GID
# number may be used.
#
User tinyproxy
Group tinyproxy
#
# Port: Specify the port which tinyproxy will listen on. Please note
# that should you choose to run on a port lower than 1024 you will need
# to start tinyproxy using root.
#
Port 8888
#
# Listen: If you have multiple interfaces this allows you to bind to
# only one. If this is commented out, tinyproxy will bind to all
# interfaces present.
#
Listen 10.9.0.1
Listen 10.8.0.1
#
# Bind: This allows you to specify which interface will be used for
# outgoing connections. This is useful for multi-home'd machines where
# you want all traffic to appear outgoing from one particular interface.
#
#Bind 192.168.0.1
#
# BindSame: If enabled, tinyproxy will bind the outgoing connection to the
# ip address of the incoming connection.
#
#BindSame yes
#
# Timeout: The maximum number of seconds of inactivity a connection is
# allowed to have before it is closed by tinyproxy.
#
Timeout 600
#
# ErrorFile: Defines the HTML file to send when a given HTTP error
# occurs. You will probably need to customize the location to your
# particular install. The usual locations to check are:
# /usr/local/share/tinyproxy
# /usr/share/tinyproxy
# /etc/tinyproxy
#
#ErrorFile 404 "/usr/share/tinyproxy/404.html"
#ErrorFile 400 "/usr/share/tinyproxy/400.html"
#ErrorFile 503 "/usr/share/tinyproxy/503.html"
#ErrorFile 403 "/usr/share/tinyproxy/403.html"
#ErrorFile 408 "/usr/share/tinyproxy/408.html"
#
# DefaultErrorFile: The HTML file that gets sent if there is no
# HTML file defined with an ErrorFile keyword for the HTTP error
# that has occured.
#
DefaultErrorFile "/usr/share/tinyproxy/default.html"
#
# StatHost: This configures the host name or IP address that is treated
# as the stat host: Whenever a request for this host is received,
# Tinyproxy will return an internal statistics page instead of
# forwarding the request to that host. The default value of StatHost is
# tinyproxy.stats.
#
StatHost "tinyproxy.stats"
#
#
# StatFile: The HTML file that gets sent when a request is made
# for the stathost. If this file doesn't exist a basic page is
# hardcoded in tinyproxy.
#
StatFile "/usr/share/tinyproxy/stats.html"
#
# LogFile: Allows you to specify the location where information should
# be logged to. If you would prefer to log to syslog, then disable this
# and enable the Syslog directive. These directives are mutually
# exclusive. If neither Syslog nor LogFile are specified, output goes
# to stdout.
#
LogFile "/var/log/tinyproxy/tinyproxy.log"
#
# Syslog: Tell tinyproxy to use syslog instead of a logfile. This
# option must not be enabled if the Logfile directive is being used.
# These two directives are mutually exclusive.
#
Syslog On
#
# LogLevel: Warning
#
# Set the logging level. Allowed settings are:
# Critical (least verbose)
# Set the logging level. Allowed settings are:
# Critical (least verbose)
# Error
# Warning
# Notice
# Connect (to log connections without Info's noise)
# Info (most verbose)
#
# The LogLevel logs from the set level and above. For example, if the
# LogLevel was set to Warning, then all log messages from Warning to
# Critical would be output, but Notice and below would be suppressed.
#
LogLevel Info
#
# PidFile: Write the PID of the main tinyproxy thread to this file so it
# can be used for signalling purposes.
# If not specified, no pidfile will be written.
#
PidFile "/run/tinyproxy/tinyproxy.pid"
#
# XTinyproxy: Tell Tinyproxy to include the X-Tinyproxy header, which
# contains the client's IP address.
#
#XTinyproxy Yes
#
# Upstream:
#
# Turns on upstream proxy support.
#
# The upstream rules allow you to selectively route upstream connections
# based on the host/domain of the site being accessed.
#
# Syntax: upstream type (user:pass@)ip:port ("domain")
# Or: upstream none "domain"
# The parts in parens are optional.
# Possible types are http, socks4, socks5, none
#
# For example:
# # connection to test domain goes through testproxy
# upstream http testproxy:8008 ".test.domain.invalid"
# upstream http testproxy:8008 ".our_testbed.example.com"
# upstream http testproxy:8008 "192.168.128.0/255.255.254.0"
#
# # upstream proxy using basic authentication
# upstream http user:pass@testproxy:8008 ".test.domain.invalid"
#
# # no upstream proxy for internal websites and unqualified hosts
# upstream none ".internal.example.com"
# upstream none "www.example.com"
# upstream none "10.0.0.0/8"
# upstream none "192.168.0.0/255.255.254.0"
# upstream none "."
#
# # connection to these boxes go through their DMZ firewalls
# upstream http cust1_firewall:8008 "testbed_for_cust1"
# upstream http cust2_firewall:8008 "testbed_for_cust2"
#
# # default upstream is internet firewall
# upstream http firewall.internal.example.com:80
#
# You may also use SOCKS4/SOCKS5 upstream proxies:
# upstream socks4 127.0.0.1:9050
# upstream socks5 socksproxy:1080
#
# The LAST matching rule wins the route decision. As you can see, you
# can use a host, or a domain:
# name matches host exactly
# .name matches any host in domain "name"
# . matches any host with no domain (in 'empty' domain)
# IP/bits matches network/mask
# IP/mask matches network/mask
#
#Upstream http some.remote.proxy:port
#
# MaxClients: This is the absolute highest number of threads which will
# be created. In other words, only MaxClients number of clients can be
# connected at the same time.
#
MaxClients 100
#
# MinSpareServers/MaxSpareServers: These settings set the upper and
# lower limit for the number of spare servers which should be available.
#
# If the number of spare servers falls below MinSpareServers then new
# server processes will be spawned. If the number of servers exceeds
# MaxSpareServers then the extras will be killed off.
#
MinSpareServers 5
MaxSpareServers 20
#
# StartServers: The number of servers to start initially.
#
StartServers 10
#
# MaxRequestsPerChild: The number of connections a thread will handle
# before it is killed. In practise this should be set to 0, which
# disables thread reaping. If you do notice problems with memory
# leakage, then set this to something like 10000.
#
MaxRequestsPerChild 0
#
# Allow: Customization of authorization controls. If there are any
# access control keywords then the default action is to DENY. Otherwise,
# the default action is ALLOW.
#
# The order of the controls are important. All incoming connections are
# tested against the controls based on order.
#
Allow 127.0.0.1
Allow 10.9.0.0/24
Allow 10.8.0.0/24
#Allow 192.168.0.0/16
#Allow 172.16.0.0/12
#Allow 10.0.0.0/8
# BasicAuth: HTTP "Basic Authentication" for accessing the proxy.
# If there are any entries specified, access is only granted for authenticated
# users.
#BasicAuth user password
#
# AddHeader: Adds the specified headers to outgoing HTTP requests that
# Tinyproxy makes. Note that this option will not work for HTTPS
# traffic, as Tinyproxy has no control over what headers are exchanged.
#
#AddHeader "X-My-Header" "Powered by Tinyproxy"
#
# ViaProxyName: The "Via" header is required by the HTTP RFC, but using
#
# ViaProxyName: The "Via" header is required by the HTTP RFC, but using
# the real host name is a security concern. If the following directive
# is enabled, the string supplied will be used as the host name in the
# Via header; otherwise, the server's host name will be used.
#
ViaProxyName "tinyproxy"
#
# DisableViaHeader: When this is set to yes, Tinyproxy does NOT add
# the Via header to the requests. This virtually puts Tinyproxy into
# stealth mode. Note that RFC 2616 requires proxies to set the Via
# header, so by enabling this option, you break compliance.
# Don't disable the Via header unless you know what you are doing...
#
#DisableViaHeader Yes
#
# Filter: This allows you to specify the location of the filter file.
#
#Filter "/etc/tinyproxy/filter"
#
# FilterURLs: Filter based on URLs rather than domains.
#
#FilterURLs On
#
# FilterExtended: Use POSIX Extended regular expressions rather than
# basic.
#
#FilterExtended On
#
# FilterCaseSensitive: Use case sensitive regular expressions.
#
#FilterCaseSensitive On
#
# FilterDefaultDeny: Change the default policy of the filtering system.
# If this directive is commented out, or is set to "No" then the default
# policy is to allow everything which is not specifically denied by the
# filter file.
#
# However, by setting this directive to "Yes" the default policy becomes
# to deny everything which is _not_ specifically allowed by the filter
# file.
#
#FilterDefaultDeny Yes
#
# Anonymous: If an Anonymous keyword is present, then anonymous proxying
# is enabled. The headers listed are allowed through, while all others
# are denied. If no Anonymous keyword is present, then all headers are
# allowed through. You must include quotes around the headers.
#
# Most sites require cookies to be enabled for them to work correctly, so
# you will need to allow Cookies through if you access those sites.
#
#Anonymous "Host"
#Anonymous "Authorization"
#Anonymous "Cookie"
#
# ConnectPort: This is a list of ports allowed by tinyproxy when the
# CONNECT method is used. To disable the CONNECT method altogether, set
# the value to 0. If no ConnectPort line is found, all ports are
# allowed.
#
# The following two ports are used by SSL.
#
ConnectPort 443
ConnectPort 563
#
# Configure one or more ReversePath directives to enable reverse proxy
# support. With reverse proxying it's possible to make a number of
# sites appear as if they were part of a single site.
#
# If you uncomment the following two directives and run tinyproxy
# on your own computer at port 8888, you can access Google using
# http://localhost:8888/google/ and Wired News using
# http://localhost:8888/wired/news/. Neither will actually work
# until you uncomment ReverseMagic as they use absolute linking.
#
#ReversePath "/google/" "http://www.google.com/"
#ReversePath "/wired/" "http://www.wired.com/"
#
# When using tinyproxy as a reverse proxy, it is STRONGLY recommended
# that the normal proxy is turned off by uncommenting the next directive.
#
#ReverseOnly Yes
#
# Use a cookie to track reverse proxy mappings. If you need to reverse
# proxy sites which have absolute links you must uncomment this.
#
#ReverseMagic Yes
#
# The URL that's used to access this reverse proxy. The URL is used to
# rewrite HTTP redirects so that they won't escape the proxy. If you
# have a chain of reverse proxies, you'll need to put the outermost
# URL here (the address which the end user types into his/her browser).
#
# If not set then no rewriting occurs.
#
#ReverseBaseURL "http://localhost:8888/"