feat: first commit
This commit is contained in:
commit
5fdf790556
25 files changed
+1957
No files matched your search
@@ -0,0 +1,4 @@
|
||||
.venv
|
||||
.vscode
|
||||
|
||||
*.pem
|
||||
@@ -0,0 +1,2 @@
|
||||
# VPS setup ansible script
|
||||
Setup VPS for basic needs with ansible playbook
|
||||
@@ -0,0 +1,38 @@
|
||||
// prime the server with knowledge of the root servers
|
||||
//zone "." {
|
||||
// type hint;
|
||||
// file "/usr/share/dns/root.hints";
|
||||
//};
|
||||
|
||||
// be authoritative for the localhost forward and reverse zones, and for
|
||||
// broadcast zones as per RFC 1912
|
||||
|
||||
view "ext" {
|
||||
match-clients{"any";};
|
||||
|
||||
zone "." {
|
||||
type hint;
|
||||
file "/usr/share/dns/root.hints";
|
||||
};
|
||||
|
||||
zone "localhost" {
|
||||
type master;
|
||||
file "/etc/bind/db.local";
|
||||
};
|
||||
|
||||
zone "127.in-addr.arpa" {
|
||||
type master;
|
||||
file "/etc/bind/db.127";
|
||||
};
|
||||
|
||||
zone "0.in-addr.arpa" {
|
||||
type master;
|
||||
file "/etc/bind/db.0";
|
||||
};
|
||||
|
||||
zone "255.in-addr.arpa" {
|
||||
type master;
|
||||
file "/etc/bind/db.255";
|
||||
};
|
||||
|
||||
};
|
||||
@@ -0,0 +1,36 @@
|
||||
//
|
||||
// Do any local configuration here
|
||||
//
|
||||
|
||||
// Consider adding the 1918 zones here, if they are not used in your
|
||||
// organization
|
||||
//include "/etc/bind/zones.rfc1918";
|
||||
|
||||
acl "int-8" {10.8.0.0/24;};
|
||||
acl "int-9" {10.9.0.0/24;};
|
||||
|
||||
view "int-8" {
|
||||
match-clients{"int-8";};
|
||||
|
||||
zone "ra-tech.pro" {
|
||||
type master;
|
||||
file "/etc/bind/zones/db.ra-tech.pro";
|
||||
};
|
||||
zone "0.8.10.in-addr.arpa" {
|
||||
type master;
|
||||
file "/etc/bind/zones/db.10.8.0";
|
||||
};
|
||||
};
|
||||
|
||||
view "int-9" {
|
||||
match-clients{"int-9";};
|
||||
|
||||
zone "ra-tech.pro" {
|
||||
type master;
|
||||
file "/etc/bind/zones/db.v9.ra-tech.pro";
|
||||
};
|
||||
zone "0.9.10.in-addr.arpa" {
|
||||
type master;
|
||||
file "/etc/bind/zones/db.10.9.0";
|
||||
};
|
||||
};
|
||||
@@ -0,0 +1,36 @@
|
||||
options {
|
||||
directory "/var/cache/bind";
|
||||
|
||||
// If there is a firewall between you and nameservers you want
|
||||
// to talk to, you may need to fix the firewall to allow multiple
|
||||
// ports to talk. See http://www.kb.cert.org/vuls/id/800113
|
||||
|
||||
// If your ISP provided one or more IP addresses for stable
|
||||
// nameservers, you probably want to use them as forwarders.
|
||||
// Uncomment the following block, and insert the addresses replacing
|
||||
// the all-0's placeholder.
|
||||
|
||||
// forwarders {
|
||||
// 0.0.0.0;
|
||||
// };
|
||||
|
||||
//========================================================================
|
||||
// If BIND logs error messages about the root key being expired,
|
||||
// you will need to update your keys. See https://www.isc.org/bind-keys
|
||||
//========================================================================
|
||||
dnssec-validation auto;
|
||||
|
||||
listen-on {
|
||||
10.8.0.0/24;
|
||||
10.9.0.0/24;
|
||||
};
|
||||
|
||||
allow-query { any; };
|
||||
|
||||
forwarders {
|
||||
8.8.8.8;
|
||||
8.8.4.4;
|
||||
};
|
||||
|
||||
//listen-on-v6 { any; };
|
||||
};
|
||||
@@ -0,0 +1,7 @@
|
||||
view "ext" {
|
||||
// prime the server with knowledge of the root servers
|
||||
zone "." {
|
||||
type hint;
|
||||
file "/usr/share/dns/root.hints";
|
||||
};
|
||||
}
|
||||
@@ -0,0 +1,41 @@
|
||||
;
|
||||
; BIND reverse data file for local loopback interface
|
||||
;
|
||||
$TTL 604800
|
||||
$ORIGIN 0.8.10.in-addr.arpa.
|
||||
@ IN SOA ns.ra-tech.pro. admin.ra-tech.pro. (
|
||||
1 ; Serial
|
||||
604800 ; Refresh
|
||||
86400 ; Retry
|
||||
2419200 ; Expire
|
||||
604800 ) ; Negative Cache TTL
|
||||
;
|
||||
; name servers
|
||||
IN NS ns.ra-tech.pro.
|
||||
|
||||
; PTR Records
|
||||
1 IN PTR ns.ra-tech.pro.
|
||||
1 IN PTR vps.ra-tech.pro.
|
||||
10 IN PTR odroid.ra-tech.pro.
|
||||
10 IN PTR jenkins.ra-tech.pro.
|
||||
10 IN PTR nexus.ra-tech.pro.
|
||||
10 IN PTR docker.ra-tech.pro.
|
||||
10 IN PTR sonar.ra-tech.pro.
|
||||
10 IN PTR cloud.ra-tech.pro.
|
||||
10 IN PTR db.ra-tech.pro.
|
||||
10 IN PTR dashboard.cloud.ra-tech.pro.
|
||||
10 IN PTR garden-manager.db.ra-tech.pro.
|
||||
10 IN PTR giga-ai-agent.db.ra-tech.pro.
|
||||
10 IN PTR vault.ra-tech.pro.
|
||||
10 IN PTR docker-registry.ra-tech.pro.
|
||||
10 IN PTR snapshots.docker-registry.ra-tech.pro.
|
||||
10 IN PTR prometheus.ra-tech.pro.
|
||||
10 IN PTR pki.ra-tech.pro.
|
||||
10 IN PTR grafana.ra-tech.pro.
|
||||
10 IN PTR hfs.ra-tech.pro.
|
||||
10 IN PTR kafka-1.ra-tech.pro.
|
||||
10 IN PTR kafka.ra-tech.pro.
|
||||
10 IN PTR elasticsearch.ra-tech.pro.
|
||||
10 IN PTR kibana.ra-tech.pro.
|
||||
10 IN PTR chrome.selenium.ra-tech.pro.
|
||||
10 IN PTR git.ra-tech.pro.
|
||||
@@ -0,0 +1,41 @@
|
||||
;
|
||||
; BIND reverse data file for local loopback interface
|
||||
;
|
||||
$TTL 604800
|
||||
$ORIGIN 0.9.10.in-addr.arpa.
|
||||
@ IN SOA ns.ra-tech.pro. admin.ra-tech.pro. (
|
||||
1 ; Serial
|
||||
604800 ; Refresh
|
||||
86400 ; Retry
|
||||
2419200 ; Expire
|
||||
604800 ) ; Negative Cache TTL
|
||||
;
|
||||
; name servers
|
||||
IN NS ns.ra-tech.pro.
|
||||
|
||||
; PTR Records
|
||||
1 IN PTR ns.ra-tech.pro.
|
||||
1 IN PTR vps.ra-tech.pro.
|
||||
10 IN PTR odroid.ra-tech.pro.
|
||||
10 IN PTR jenkins.ra-tech.pro.
|
||||
10 IN PTR nexus.ra-tech.pro.
|
||||
10 IN PTR docker.ra-tech.pro.
|
||||
10 IN PTR sonar.ra-tech.pro.
|
||||
10 IN PTR cloud.ra-tech.pro.
|
||||
10 IN PTR db.ra-tech.pro.
|
||||
10 IN PTR dashboard.cloud.ra-tech.pro.
|
||||
10 IN PTR garden-manager.db.ra-tech.pro.
|
||||
10 IN PTR giga-ai-agent.db.ra-tech.pro.
|
||||
10 IN PTR vault.ra-tech.pro.
|
||||
10 IN PTR docker-registry.ra-tech.pro.
|
||||
10 IN PTR snapshots.docker-registry.ra-tech.pro.
|
||||
10 IN PTR prometheus.ra-tech.pro.
|
||||
10 IN PTR pki.ra-tech.pro.
|
||||
10 IN PTR grafana.ra-tech.pro.
|
||||
10 IN PTR hfs.ra-tech.pro.
|
||||
10 IN PTR kafka-1.ra-tech.pro.
|
||||
10 IN PTR kafka.ra-tech.pro.
|
||||
10 IN PTR elasticsearch.ra-tech.pro.
|
||||
10 IN PTR kibana.ra-tech.pro.
|
||||
10 IN PTR chrome.selenium.ra-tech.pro.
|
||||
10 IN PTR git.ra-tech.pro.
|
||||
@@ -0,0 +1,54 @@
|
||||
;
|
||||
; BIND data file for local loopback interface
|
||||
;
|
||||
$TTL 604800
|
||||
@ IN SOA ns.ra-tech.pro. admin.ra-tech.pro. (
|
||||
1 ; Serial
|
||||
604800 ; Refresh
|
||||
86400 ; Retry
|
||||
2419200 ; Expire
|
||||
604800 ) ; Negative Cache TTL
|
||||
|
||||
; name servers - NS records
|
||||
IN NS ns.ra-tech.pro.
|
||||
|
||||
; name servers - A records
|
||||
ns.ra-tech.pro. IN A 10.8.0.1
|
||||
|
||||
; 10.8.0.0/24 - A records
|
||||
vps.ra-tech.pro. IN A 10.8.0.1
|
||||
odroid.ra-tech.pro. IN A 10.8.0.10
|
||||
jenkins.ra-tech.pro. IN A 10.8.0.10
|
||||
nexus.ra-tech.pro. IN A 10.8.0.10
|
||||
docker.ra-tech.pro. IN A 10.8.0.10
|
||||
sonar.ra-tech.pro. IN A 10.8.0.10
|
||||
cloud.ra-tech.pro. IN A 10.8.0.10
|
||||
dashboard.cloud.ra-tech.pro. IN A 10.8.0.10
|
||||
db.ra-tech.pro. IN A 10.8.0.10
|
||||
garden-manager.db.ra-tech.pro. IN A 10.8.0.10
|
||||
giga-ai-agent.db.ra-tech.pro. IN A 10.8.0.10
|
||||
vault.ra-tech.pro. IN A 10.8.0.10
|
||||
docker-registry.ra-tech.pro. IN A 10.8.0.10
|
||||
snapshots.docker-registry.ra-tech.pro. IN A 10.8.0.10
|
||||
pki.ra-tech.pro. IN A 10.8.0.10
|
||||
prometheus.ra-tech.pro. IN A 10.8.0.10
|
||||
grafana.ra-tech.pro. IN A 10.8.0.10
|
||||
syncthing.ra-tech.pro. IN A 10.8.0.10
|
||||
kuber.ra-tech.pro. IN A 10.8.0.10
|
||||
garden-manager.cloud.ra-tech.pro. IN A 10.8.0.10
|
||||
garden-manager.test.cloud.ra-tech.pro. IN A 10.8.0.10
|
||||
api.garden-manager.cloud.ra-tech.pro. IN A 10.8.0.10
|
||||
api.garden-manager.test.cloud.ra-tech.pro. IN A 10.8.0.10
|
||||
solr.ra-tech.pro. IN A 10.8.0.10
|
||||
auth.ra-tech.pro. IN A 10.8.0.10
|
||||
api.giga-ai-agent.cloud.ra-tech.pro. IN A 10.8.0.10
|
||||
api.giga-ai-agent.test.cloud.ra-tech.pro. IN A 10.8.0.10
|
||||
giga-ai-agent.cloud.ra-tech.pro. IN A 10.8.0.10
|
||||
giga-ai-agent.test.cloud.ra-tech.pro. IN A 10.8.0.10
|
||||
hfs.ra-tech.pro. IN A 10.8.0.10
|
||||
kafka-1.ra-tech.pro. IN A 10.8.0.10
|
||||
kafka.ra-tech.pro. IN A 10.8.0.10
|
||||
elasticsearch.ra-tech.pro. IN A 10.8.0.10
|
||||
kibana.ra-tech.pro. IN A 10.8.0.10
|
||||
chrome.selenium.ra-tech.pro. IN A 10.8.0.10
|
||||
git.ra-tech.pro. IN A 10.8.0.10
|
||||
@@ -0,0 +1,54 @@
|
||||
;
|
||||
; BIND data file for local loopback interface
|
||||
;
|
||||
$TTL 604800
|
||||
@ IN SOA ns.ra-tech.pro. admin.ra-tech.pro. (
|
||||
1 ; Serial
|
||||
604800 ; Refresh
|
||||
86400 ; Retry
|
||||
2419200 ; Expire
|
||||
604800 ) ; Negative Cache TTL
|
||||
|
||||
; name servers - NS records
|
||||
IN NS ns.ra-tech.pro.
|
||||
|
||||
; name servers - A records
|
||||
ns.ra-tech.pro. IN A 10.9.0.1
|
||||
|
||||
; 10.8.0.0/24 - A records
|
||||
vps.ra-tech.pro. IN A 10.9.0.1
|
||||
odroid.ra-tech.pro. IN A 10.9.0.10
|
||||
jenkins.ra-tech.pro. IN A 10.9.0.10
|
||||
nexus.ra-tech.pro. IN A 10.9.0.10
|
||||
docker.ra-tech.pro. IN A 10.9.0.10
|
||||
sonar.ra-tech.pro. IN A 10.9.0.10
|
||||
cloud.ra-tech.pro. IN A 10.9.0.10
|
||||
dashboard.cloud.ra-tech.pro. IN A 10.9.0.10
|
||||
db.ra-tech.pro. IN A 10.9.0.10
|
||||
garden-manager.db.ra-tech.pro. IN A 10.9.0.10
|
||||
giga-ai-agent.db.ra-tech.pro. IN A 10.9.0.10
|
||||
vault.ra-tech.pro. IN A 10.9.0.10
|
||||
docker-registry.ra-tech.pro. IN A 10.9.0.10
|
||||
snapshots.docker-registry.ra-tech.pro. IN A 10.9.0.10
|
||||
pki.ra-tech.pro. IN A 10.9.0.10
|
||||
prometheus.ra-tech.pro. IN A 10.9.0.10
|
||||
grafana.ra-tech.pro. IN A 10.9.0.10
|
||||
syncthing.ra-tech.pro. IN A 10.9.0.10
|
||||
kuber.ra-tech.pro. IN A 10.9.0.10
|
||||
garden-manager.cloud.ra-tech.pro. IN A 10.9.0.10
|
||||
garden-manager.test.cloud.ra-tech.pro. IN A 10.9.0.10
|
||||
api.garden-manager.cloud.ra-tech.pro. IN A 10.9.0.10
|
||||
api.garden-manager.test.cloud.ra-tech.pro. IN A 10.9.0.10
|
||||
solr.ra-tech.pro. IN A 10.9.0.10
|
||||
auth.ra-tech.pro. IN A 10.9.0.10
|
||||
api.giga-ai-agent.cloud.ra-tech.pro. IN A 10.9.0.10
|
||||
api.giga-ai-agent.test.cloud.ra-tech.pro. IN A 10.9.0.10
|
||||
giga-ai-agent.cloud.ra-tech.pro. IN A 10.9.0.10
|
||||
giga-ai-agent.test.cloud.ra-tech.pro. IN A 10.9.0.10
|
||||
hfs.ra-tech.pro. IN A 10.9.0.10
|
||||
kafka-1.ra-tech.pro. IN A 10.9.0.10
|
||||
kafka.ra-tech.pro. IN A 10.9.0.10
|
||||
elasticsearch.ra-tech.pro. IN A 10.9.0.10
|
||||
kibana.ra-tech.pro. IN A 10.9.0.10
|
||||
chrome.selenium.ra-tech.pro. IN A 10.9.0.10
|
||||
git.ra-tech.pro. IN A 10.9.0.10
|
||||
@@ -0,0 +1,12 @@
|
||||
[Unit]
|
||||
Description=Cloak server
|
||||
After=network.target
|
||||
|
||||
[Service]
|
||||
ExecStart=/usr/local/bin/ck-server -c /etc/cloak/server.json
|
||||
Restart=always
|
||||
Type=exec
|
||||
User=cloak
|
||||
|
||||
[Install]
|
||||
WantedBy=default.target
|
||||
@@ -0,0 +1,21 @@
|
||||
{
|
||||
"ProxyBook": {
|
||||
"openvpn": [
|
||||
"tcp",
|
||||
"{{ public_ip }}:5690"
|
||||
]
|
||||
},
|
||||
"BindAddr": [
|
||||
":5691"
|
||||
],
|
||||
"BypassUID": [
|
||||
"hs3Zsj/9mvt7+3bhgkg7Tw==",
|
||||
"VF3YuD37EPGcMyfJOBM+zw==",
|
||||
"2GT18pqRxb6BOqJWQK42rg==",
|
||||
"LN9ESPPnGDN5bU4qJJGm3Q=="
|
||||
],
|
||||
"RedirAddr": "vk.ru",
|
||||
"PrivateKey": "cFMDGEt3L8Rm7APM9creW3KBrYrVP3pIjZvlNgV32Fs=",
|
||||
"AdminUID": "rVobMUVWAh1Do4QF/wzdVw==",
|
||||
"DatabasePath": "/opt/cloak/userinfo.db"
|
||||
}
|
||||
@@ -0,0 +1,200 @@
|
||||
hosts:
|
||||
- ra-tech.dev
|
||||
- xmpp.ra-itech.ru
|
||||
|
||||
hosts_alias:
|
||||
"64.188.58.223": "ra-tech.dev"
|
||||
|
||||
language: ru
|
||||
|
||||
loglevel: info
|
||||
|
||||
certfiles:
|
||||
- /etc/ejabberd/server.pem
|
||||
- /etc/ejabberd/server-key.pem
|
||||
- /etc/ejabberd/certs/fullchain.pem
|
||||
- /etc/ejabberd/certs/privkey.pem
|
||||
|
||||
auth_method: internal
|
||||
auth_password_format: scram
|
||||
auth_scram_hash: sha512
|
||||
|
||||
sql_database: /opt/ejabberd/sqlite/db.sqlite
|
||||
sql_type: sqlite
|
||||
sql_pool_size: 1
|
||||
|
||||
s2s_access:
|
||||
deny: all
|
||||
|
||||
acl:
|
||||
admin:
|
||||
user:
|
||||
- kodacci@ra-tech.dev
|
||||
- kodacci@xmpp.ra-itech.ru
|
||||
disabled_servers:
|
||||
server:
|
||||
- "p2.siacs.eu"
|
||||
|
||||
access_rules:
|
||||
configure:
|
||||
allow: admin
|
||||
announce:
|
||||
allow: admin
|
||||
c2s:
|
||||
deny: blocked
|
||||
allow: all
|
||||
pubsub_createnode:
|
||||
allow: admin
|
||||
s2s:
|
||||
deny: disabled_servers
|
||||
|
||||
shaper:
|
||||
fast: 3000000
|
||||
|
||||
shaper_rules:
|
||||
max_user_sessions: 50
|
||||
max_user_offline_messages: 5000
|
||||
c2s_shaper: fast
|
||||
|
||||
modules:
|
||||
mod_adhoc: {}
|
||||
mod_adhoc_api: {}
|
||||
mod_admin_extra: {}
|
||||
mod_announce:
|
||||
access: announce
|
||||
mod_avatar: {}
|
||||
mod_blocking: {}
|
||||
mod_bosh: {}
|
||||
mod_caps: {}
|
||||
mod_carboncopy: {}
|
||||
mod_client_state: {}
|
||||
mod_configure: {}
|
||||
mod_disco: {}
|
||||
mod_fail2ban: {}
|
||||
mod_http_api: {}
|
||||
mod_last: {}
|
||||
mod_muc:
|
||||
access_admin:
|
||||
- allow: admin
|
||||
mod_muc_admin: {}
|
||||
mod_offline:
|
||||
access_max_user_messages: max_user_offline_messages
|
||||
mod_ping:
|
||||
send_pings: true
|
||||
ping_interval: 1 min
|
||||
mod_privacy: {}
|
||||
mod_private: {}
|
||||
mod_push: {}
|
||||
mod_push_keepalive: {}
|
||||
mod_roster:
|
||||
versioning: true
|
||||
mod_s2s_bidi: {}
|
||||
mod_s2s_dialback: {}
|
||||
mod_shared_roster: {}
|
||||
mod_stream_mgmt:
|
||||
resend_on_timeout: if_offline
|
||||
mod_stun_disco:
|
||||
access: c2s
|
||||
credentials_lifetime: 12h
|
||||
services:
|
||||
- host: xmpp.ra-itech.ru
|
||||
port: 3478
|
||||
type: stun
|
||||
transport: udp
|
||||
restricted: false
|
||||
- host: xmpp.ra-itech.ru
|
||||
port: 3478
|
||||
type: turn
|
||||
transport: udp
|
||||
restricted: true
|
||||
- host: xmpp.ra-itech.ru
|
||||
port: 5349
|
||||
type: stuns
|
||||
transport: tcp
|
||||
restricted: false
|
||||
- host: xmpp.ra-itech.ru
|
||||
port: 5349
|
||||
type: turns
|
||||
transport: tcp
|
||||
restricted: true
|
||||
mod_vcard: {}
|
||||
mod_vcard_xupdate: {}
|
||||
mod_version:
|
||||
show_os: false
|
||||
mod_pubsub:
|
||||
access_createnode: pubsub_createnode
|
||||
plugins:
|
||||
- flat
|
||||
- pep
|
||||
force_node_config:
|
||||
## Avoid buggy clients to make their bookmarks public
|
||||
storage:bookmarks:
|
||||
access_model: whitelist
|
||||
mod_proxy65:
|
||||
access: c2s
|
||||
max_connections: 50
|
||||
port: 7788
|
||||
shaper: fast
|
||||
mod_http_fileserver:
|
||||
accesslog: /opt/ejabberd/logs/access.log
|
||||
docroot:
|
||||
/files: /opt/fileserver
|
||||
mod_http_upload:
|
||||
access: c2s
|
||||
docroot: /opt/fileserver
|
||||
put_url: "https://@HOST@:5443/upload"
|
||||
get_url: "https://@HOST@:5443/files"
|
||||
mod_mam:
|
||||
access_preferences: c2s
|
||||
db_type: sql
|
||||
|
||||
listen:
|
||||
- port: 5222
|
||||
ip: "::"
|
||||
module: ejabberd_c2s
|
||||
shaper: c2s_shaper
|
||||
access: c2s
|
||||
max_stanza_size: 262144
|
||||
starttls: true
|
||||
allow_unencrypted_sasl2: false
|
||||
cafile: /etc/ejabberd/ca.pem
|
||||
starttls_required: true
|
||||
tls_verify: true
|
||||
|
||||
- port: 5223
|
||||
ip: "::"
|
||||
module: ejabberd_c2s
|
||||
shaper: c2s_shaper
|
||||
access: c2s
|
||||
max_stanza_size: 262144
|
||||
starttls: true
|
||||
starttls_required: true
|
||||
tls_verify: false
|
||||
|
||||
- port: 3478
|
||||
transport: udp
|
||||
module: ejabberd_stun
|
||||
use_turn: true
|
||||
turn_min_port: 49152
|
||||
turn_max_port: 65535
|
||||
turn_ip: 64.188.58.223
|
||||
|
||||
- port: 5349
|
||||
transport: tcp
|
||||
module: ejabberd_stun
|
||||
use_turn: true
|
||||
tls: true
|
||||
turn_min_port: 49152
|
||||
turn_max_port: 65535
|
||||
ip: 64.188.58.223
|
||||
turn_ip: 64.188.58.223
|
||||
|
||||
- port: 5443
|
||||
ip: "::"
|
||||
transport: tcp
|
||||
module: ejabberd_http
|
||||
tls: true
|
||||
request_handlers:
|
||||
/files: mod_http_fileserver
|
||||
/upload: mod_http_upload
|
||||
/bosh: mod_bosh
|
||||
@@ -0,0 +1,58 @@
|
||||
global
|
||||
log /dev/log local0
|
||||
log /dev/log local1 notice
|
||||
chroot /var/lib/haproxy
|
||||
stats socket /run/haproxy/admin.sock mode 660 level admin expose-fd listeners
|
||||
stats timeout 30s
|
||||
user haproxy
|
||||
group haproxy
|
||||
daemon
|
||||
|
||||
# Default SSL material locations
|
||||
ca-base /etc/ssl/certs
|
||||
crt-base /etc/ssl/private
|
||||
|
||||
# See: https://ssl-config.mozilla.org/#server=haproxy&server-version=2.0.3&config=intermediate
|
||||
#ssl-default-bind-ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384
|
||||
#ssl-default-bind-ciphersuites TLS_AES_128_GCM_SHA256:TLS_AES_256_GCM_SHA384:TLS_CHACHA20_POLY1305_SHA256
|
||||
#ssl-default-bind-options ssl-min-ver TLSv1.2 no-tls-tickets
|
||||
|
||||
defaults
|
||||
log global
|
||||
mode http
|
||||
option httplog
|
||||
option dontlognull
|
||||
timeout connect 5000
|
||||
timeout client 50000
|
||||
timeout server 50000
|
||||
errorfile 400 /etc/haproxy/errors/400.http
|
||||
errorfile 403 /etc/haproxy/errors/403.http
|
||||
errorfile 408 /etc/haproxy/errors/408.http
|
||||
errorfile 500 /etc/haproxy/errors/500.http
|
||||
errorfile 502 /etc/haproxy/errors/502.http
|
||||
errorfile 503 /etc/haproxy/errors/503.http
|
||||
errorfile 504 /etc/haproxy/errors/504.http
|
||||
|
||||
frontend jenkins_webhook_front
|
||||
mode http
|
||||
bind :7777 ssl crt /etc/haproxy/certs/64.188.58.223.pem
|
||||
http-request set-header X-Forwarded-For %[src]
|
||||
use_backend jenkins_webhook_back if { path /github-webhook/ } || { path /github-webhook }
|
||||
|
||||
backend jenkins_webhook_back
|
||||
mode http
|
||||
http-request set-header Host jenkins.ra-tech.pro
|
||||
server jenkins_main jenkins.ra-tech.pro:443 ssl verify none check resolvers nameservers
|
||||
|
||||
resolvers nameservers
|
||||
nameserver ra-tech 10.8.0.1:53
|
||||
#nameserver google 8.8.8.8:53
|
||||
|
||||
frontend stats
|
||||
bind 10.8.0.1:8404
|
||||
bind 10.9.0.1:8404
|
||||
mode http
|
||||
http-request use-service prometheus-exporter if { path /metrics }
|
||||
stats enable
|
||||
stats uri /stats
|
||||
stats refresh 15s
|
||||
@@ -0,0 +1,14 @@
|
||||
vps_servers:
|
||||
vars:
|
||||
ansible_become: true
|
||||
ansible_become_user: root
|
||||
ansible_become_method: su
|
||||
ansible_user: kodacci
|
||||
hosts:
|
||||
ru-vpn:
|
||||
ansible_host: ru-vpn.ra-itech.ru
|
||||
public_ip: 45.87.247.103
|
||||
public_ip_iface: ens3
|
||||
ansible_port: 12801
|
||||
|
||||
|
||||
@@ -0,0 +1,15 @@
|
||||
[Unit]
|
||||
Description=Node Exporter
|
||||
Wants=network-online.target
|
||||
After=network-online.target
|
||||
|
||||
[Service]
|
||||
User=node_exporter
|
||||
Group=node_exporter
|
||||
Type=simple
|
||||
ExecStart=/usr/local/bin/node_exporter
|
||||
Restart=always
|
||||
RestartSec=3
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
@@ -0,0 +1,21 @@
|
||||
#
|
||||
# 2048 bit OpenVPN static key
|
||||
#
|
||||
-----BEGIN OpenVPN Static key V1-----
|
||||
ca6b90a1782a8940fbfd685dd1c92cff
|
||||
7958116231f3f096569271880c54a53f
|
||||
0aeb0872933e9ca7c3efaaed3b63831b
|
||||
21be29430b4dd8634200131a197470de
|
||||
061d716c133e25f7edd3802beba11851
|
||||
f5c1347f63c1ce072ba26219a9f68f13
|
||||
76057ff561468d267792e0f249342956
|
||||
d4df6c72efffcc21c7d09d1b5415cebc
|
||||
bf4cdc0369bc8bc16a86a7b7c5f61ae5
|
||||
9b87777aeccdbcf9d50f15aa4427adb8
|
||||
2263df1c1475471989a8eff935e0c5ac
|
||||
e85580b0f90633bf92570aaa15910850
|
||||
d4017e502f0eeaf46f555ff9740c655c
|
||||
26db7bf2f06948249e75a869d4d47e89
|
||||
847ce8f14969a5cc3b60928838146305
|
||||
797f11d4cf08d4c06223c47747ec8798
|
||||
-----END OpenVPN Static key V1-----
|
||||
@@ -0,0 +1,320 @@
|
||||
#################################################
|
||||
# Sample OpenVPN 2.0 config file for #
|
||||
# multi-client server. #
|
||||
# #
|
||||
# This file is for the server side #
|
||||
# of a many-clients <-> one-server #
|
||||
# OpenVPN configuration. #
|
||||
# #
|
||||
# OpenVPN also supports #
|
||||
# single-machine <-> single-machine #
|
||||
# configurations (See the Examples page #
|
||||
# on the web site for more info). #
|
||||
# #
|
||||
# This config should work on Windows #
|
||||
# or Linux/BSD systems. Remember on #
|
||||
# Windows to quote pathnames and use #
|
||||
# double backslashes, e.g.: #
|
||||
# "C:\\Program Files\\OpenVPN\\config\\foo.key" #
|
||||
# #
|
||||
# Comments are preceded with '#' or ';' #
|
||||
#################################################
|
||||
|
||||
# Which local IP address should OpenVPN
|
||||
# listen on? (optional)
|
||||
;local a.b.c.d
|
||||
|
||||
# Which TCP/UDP port should OpenVPN listen on?
|
||||
# If you want to run multiple OpenVPN instances
|
||||
# on the same machine, use a different port
|
||||
# number for each one. You will need to
|
||||
# open up this port on your firewall.
|
||||
# port 1194
|
||||
port 5690
|
||||
|
||||
# TCP or UDP server?
|
||||
proto tcp
|
||||
;proto udp
|
||||
|
||||
# "dev tun" will create a routed IP tunnel,
|
||||
# "dev tap" will create an ethernet tunnel.
|
||||
# Use "dev tap0" if you are ethernet bridging
|
||||
# and have precreated a tap0 virtual interface
|
||||
# and bridged it with your ethernet interface.
|
||||
# If you want to control access policies
|
||||
# over the VPN, you must create firewall
|
||||
# rules for the the TUN/TAP interface.
|
||||
# On non-Windows systems, you can give
|
||||
# an explicit unit number, such as tun0.
|
||||
# On Windows, use "dev-node" for this.
|
||||
# On most systems, the VPN will not function
|
||||
# unless you partially or fully disable
|
||||
# the firewall for the TUN/TAP interface.
|
||||
;dev tap
|
||||
dev tun
|
||||
|
||||
# Windows needs the TAP-Win32 adapter name
|
||||
# from the Network Connections panel if you
|
||||
# have more than one. On XP SP2 or higher,
|
||||
# you may need to selectively disable the
|
||||
# Windows firewall for the TAP adapter.
|
||||
# Non-Windows systems usually don't need this.
|
||||
;dev-node MyTap
|
||||
|
||||
# SSL/TLS root certificate (ca), certificate
|
||||
# (cert), and private key (key). Each client
|
||||
# and the server must have their own cert and
|
||||
# key file. The server and all clients will
|
||||
# use the same ca file.
|
||||
#
|
||||
# See the "easy-rsa" directory for a series
|
||||
# of scripts for generating RSA certificates
|
||||
# and private keys. Remember to use
|
||||
# a unique Common Name for the server
|
||||
# and each of the client certificates.
|
||||
#
|
||||
# Any X509 key management system can be used.
|
||||
# OpenVPN can also use a PKCS #12 formatted key file
|
||||
# (see "pkcs12" directive in man page).
|
||||
ca ca.pem
|
||||
cert server.pem
|
||||
key server-key.pem # This file should be kept secret
|
||||
|
||||
# Diffie hellman parameters.
|
||||
# Generate your own with:
|
||||
# openssl dhparam -out dh2048.pem 2048
|
||||
#dh dh2048.pem
|
||||
dh none
|
||||
|
||||
# Network topology
|
||||
# Should be subnet (addressing via IP)
|
||||
# unless Windows clients v2.0.9 and lower have to
|
||||
# be supported (then net30, i.e. a /30 per client)
|
||||
# Defaults to net30 (not recommended)
|
||||
;topology subnet
|
||||
|
||||
# Configure server mode and supply a VPN subnet
|
||||
# for OpenVPN to draw client addresses from.
|
||||
# The server will take 10.8.0.1 for itself,
|
||||
# the rest will be made available to clients.
|
||||
# Each client will be able to reach the server
|
||||
# on 10.8.0.1. Comment this line out if you are
|
||||
# ethernet bridging. See the man page for more info.
|
||||
server 10.8.0.0 255.255.255.0
|
||||
|
||||
# Maintain a record of client <-> virtual IP address
|
||||
# associations in this file. If OpenVPN goes down or
|
||||
# is restarted, reconnecting clients can be assigned
|
||||
# the same virtual IP address from the pool that was
|
||||
# previously assigned.
|
||||
ifconfig-pool-persist /var/log/openvpn/ipp.txt
|
||||
|
||||
# Configure server mode for ethernet bridging.
|
||||
# You must first use your OS's bridging capability
|
||||
# to bridge the TAP interface with the ethernet
|
||||
# NIC interface. Then you must manually set the
|
||||
# IP/netmask on the bridge interface, here we
|
||||
# assume 10.8.0.4/255.255.255.0. Finally we
|
||||
# must set aside an IP range in this subnet
|
||||
# (start=10.8.0.50 end=10.8.0.100) to allocate
|
||||
# to connecting clients. Leave this line commented
|
||||
# out unless you are ethernet bridging.
|
||||
;server-bridge 10.8.0.4 255.255.255.0 10.8.0.50 10.8.0.100
|
||||
|
||||
# Configure server mode for ethernet bridging
|
||||
# using a DHCP-proxy, where clients talk
|
||||
# to the OpenVPN server-side DHCP server
|
||||
# to receive their IP address allocation
|
||||
# and DNS server addresses. You must first use
|
||||
# your OS's bridging capability to bridge the TAP
|
||||
# interface with the ethernet NIC interface.
|
||||
# Note: this mode only works on clients (such as
|
||||
# Windows), where the client-side TAP adapter is
|
||||
# bound to a DHCP client.
|
||||
;server-bridge
|
||||
|
||||
# Push routes to the client to allow it
|
||||
# to reach other private subnets behind
|
||||
# the server. Remember that these
|
||||
# private subnets will also need
|
||||
# to know to route the OpenVPN client
|
||||
# address pool (10.8.0.0/255.255.255.0)
|
||||
# back to the OpenVPN server.
|
||||
;push "route 192.168.10.0 255.255.255.0"
|
||||
;push "route 192.168.20.0 255.255.255.0"
|
||||
|
||||
# To assign specific IP addresses to specific
|
||||
# clients or if a connecting client has a private
|
||||
# subnet behind it that should also have VPN access,
|
||||
# use the subdirectory "ccd" for client-specific
|
||||
# configuration files (see man page for more info).
|
||||
|
||||
# EXAMPLE: Suppose the client
|
||||
# having the certificate common name "Thelonious"
|
||||
# also has a small subnet behind his connecting
|
||||
# machine, such as 192.168.40.128/255.255.255.248.
|
||||
# First, uncomment out these lines:
|
||||
;client-config-dir ccd
|
||||
;route 192.168.40.128 255.255.255.248
|
||||
# Then create a file ccd/Thelonious with this line:
|
||||
# iroute 192.168.40.128 255.255.255.248
|
||||
# This will allow Thelonious' private subnet to
|
||||
# access the VPN. This example will only work
|
||||
# if you are routing, not bridging, i.e. you are
|
||||
# using "dev tun" and "server" directives.
|
||||
|
||||
# EXAMPLE: Suppose you want to give
|
||||
# Thelonious a fixed VPN IP address of 10.9.0.1.
|
||||
# First uncomment out these lines:
|
||||
;client-config-dir ccd
|
||||
;route 10.9.0.0 255.255.255.252
|
||||
# Then add this line to ccd/Thelonious:
|
||||
# ifconfig-push 10.9.0.1 10.9.0.2
|
||||
|
||||
# Suppose that you want to enable different
|
||||
# firewall access policies for different groups
|
||||
# of clients. There are two methods:
|
||||
# (1) Run multiple OpenVPN daemons, one for each
|
||||
# group, and firewall the TUN/TAP interface
|
||||
# for each group/daemon appropriately.
|
||||
# (2) (Advanced) Create a script to dynamically
|
||||
# modify the firewall in response to access
|
||||
# from different clients. See man
|
||||
# page for more info on learn-address script.
|
||||
;learn-address ./script
|
||||
|
||||
# If enabled, this directive will configure
|
||||
# all clients to redirect their default
|
||||
# network gateway through the VPN, causing
|
||||
# all IP traffic such as web browsing and
|
||||
# and DNS lookups to go through the VPN
|
||||
# (The OpenVPN server machine may need to NAT
|
||||
# or bridge the TUN/TAP interface to the internet
|
||||
# in order for this to work properly).
|
||||
push "redirect-gateway def1 bypass-dhcp"
|
||||
|
||||
# Certain Windows-specific network settings
|
||||
# can be pushed to clients, such as DNS
|
||||
# or WINS server addresses. CAVEAT:
|
||||
# http://openvpn.net/faq.html#dhcpcaveats
|
||||
# The addresses below refer to the public
|
||||
# DNS servers provided by opendns.com.
|
||||
# push "dhcp-option DNS 208.67.222.222"
|
||||
push "dhcp-option DNS 10.8.0.1"
|
||||
push "dhcp-option DNS 208.67.220.220"
|
||||
|
||||
# Uncomment this directive to allow different
|
||||
# clients to be able to "see" each other.
|
||||
# By default, clients will only see the server.
|
||||
# To force clients to only see the server, you
|
||||
# will also need to appropriately firewall the
|
||||
# server's TUN/TAP interface.
|
||||
;client-to-client
|
||||
|
||||
# Uncomment this directive if multiple clients
|
||||
# might connect with the same certificate/key
|
||||
# files or common names. This is recommended
|
||||
# only for testing purposes. For production use,
|
||||
# each client should have its own certificate/key
|
||||
# pair.
|
||||
#
|
||||
# IF YOU HAVE NOT GENERATED INDIVIDUAL
|
||||
# CERTIFICATE/KEY PAIRS FOR EACH CLIENT,
|
||||
# EACH HAVING ITS OWN UNIQUE "COMMON NAME",
|
||||
# UNCOMMENT THIS LINE OUT.
|
||||
;duplicate-cn
|
||||
|
||||
# The keepalive directive causes ping-like
|
||||
# messages to be sent back and forth over
|
||||
# the link so that each side knows when
|
||||
# the other side has gone down.
|
||||
# Ping every 10 seconds, assume that remote
|
||||
# peer is down if no ping received during
|
||||
# a 120 second time period.
|
||||
keepalive 10 120
|
||||
|
||||
# For extra security beyond that provided
|
||||
# by SSL/TLS, create an "HMAC firewall"
|
||||
# to help block DoS attacks and UDP port flooding.
|
||||
#
|
||||
# Generate with:
|
||||
# openvpn --genkey --secret ta.key
|
||||
#
|
||||
# The server and each client must have
|
||||
# a copy of this key.
|
||||
# The second parameter should be '0'
|
||||
# on the server and '1' on the clients.
|
||||
#tls-auth ta.key 0 # This file is secret
|
||||
tls-crypt ta.key
|
||||
|
||||
# Select a cryptographic cipher.
|
||||
# This config item must be copied to
|
||||
# the client config file as well.
|
||||
# Note that v2.4 client/server will automatically
|
||||
# negotiate AES-256-GCM in TLS mode.
|
||||
# See also the ncp-cipher option in the manpage
|
||||
cipher AES-256-GCM
|
||||
auth SHA256
|
||||
|
||||
# Enable compression on the VPN link and push the
|
||||
# option to the client (v2.4+ only, for earlier
|
||||
# versions see below)
|
||||
;compress lz4-v2
|
||||
;push "compress lz4-v2"
|
||||
|
||||
# For compression compatible with older clients use comp-lzo
|
||||
# If you enable it here, you must also
|
||||
# enable it in the client config file.
|
||||
;comp-lzo
|
||||
|
||||
# The maximum number of concurrently connected
|
||||
# clients we want to allow.
|
||||
;max-clients 100
|
||||
|
||||
# It's a good idea to reduce the OpenVPN
|
||||
# daemon's privileges after initialization.
|
||||
#
|
||||
# You can uncomment this out on
|
||||
# non-Windows systems.
|
||||
user nobody
|
||||
group nogroup
|
||||
|
||||
# The persist options will try to avoid
|
||||
# accessing certain resources on restart
|
||||
# that may no longer be accessible because
|
||||
# of the privilege downgrade.
|
||||
persist-key
|
||||
persist-tun
|
||||
|
||||
# Output a short status file showing
|
||||
# current connections, truncated
|
||||
# and rewritten every minute.
|
||||
status /var/log/openvpn/openvpn-status.log
|
||||
|
||||
# By default, log messages will go to the syslog (or
|
||||
# on Windows, if running as a service, they will go to
|
||||
# the "\Program Files\OpenVPN\log" directory).
|
||||
# Use log or log-append to override this default.
|
||||
# "log" will truncate the log file on OpenVPN startup,
|
||||
# while "log-append" will append to it. Use one
|
||||
# or the other (but not both).
|
||||
;log /var/log/openvpn/openvpn.log
|
||||
;log-append /var/log/openvpn/openvpn.log
|
||||
|
||||
# Set the appropriate level of log
|
||||
# file verbosity.
|
||||
#
|
||||
# 0 is silent, except for fatal errors
|
||||
# 4 is reasonable for general usage
|
||||
# 5 and 6 can help to debug connection problems
|
||||
# 9 is extremely verbose
|
||||
verb 3
|
||||
|
||||
# Silence repeating messages. At most 20
|
||||
# sequential messages of the same message
|
||||
# category will be output to the log.
|
||||
;mute 20
|
||||
|
||||
# Notify the client that when the server restarts so it
|
||||
# can automatically reconnect.
|
||||
explicit-exit-notify 1
|
||||
+503
@@ -0,0 +1,503 @@
|
||||
- name: Setup ufw port forwarding for VPNs subnets
|
||||
hosts: vps_servers
|
||||
become: true
|
||||
gather_facts: true
|
||||
tasks:
|
||||
- name: Install ufw
|
||||
ansible.builtin.apt:
|
||||
name: ufw
|
||||
state: present
|
||||
update_cache: true
|
||||
|
||||
# - name: Configure ufw port forwarding
|
||||
# ansible.builtin.lineinfile:
|
||||
# path: '/etc/sysctl.conf'
|
||||
# regexp: '^#?net.ipv4.ip_forward='
|
||||
# line: 'net.ipv4.ip_forward=1'
|
||||
# state: present
|
||||
# notify: Reload sysctl
|
||||
|
||||
- name: Configure ufw port forwarding
|
||||
ansible.builtin.copy:
|
||||
src: 'sysctl/99-ipv4-forward.conf'
|
||||
dest: '/etc/sysctl.d/99-ipv4-forward.conf'
|
||||
owner: root
|
||||
group: root
|
||||
mode: '0644'
|
||||
notify: Reload sysctl
|
||||
|
||||
- name: Set ufw default forwarding policy
|
||||
ansible.builtin.lineinfile:
|
||||
path: '/etc/default/ufw'
|
||||
regexp: '^DEFAULT_FORWARD_POLICY='
|
||||
line: 'DEFAULT_FORWARD_POLICY="ACCEPT"'
|
||||
state: present
|
||||
notify: Reload ufw
|
||||
|
||||
- name: Add postrouting nat
|
||||
ansible.builtin.blockinfile:
|
||||
path: '/etc/ufw/before.rules'
|
||||
insertbefore: '^\*filter'
|
||||
block: |
|
||||
# VPN NAT
|
||||
*nat
|
||||
:POSTROUTING ACCEPT [0:0]
|
||||
-A POSTROUTING -s 10.9.0.0/24 -o {{ public_ip_iface }} -j MASQUERADE
|
||||
-A POSTROUTING -s 10.8.0.0/24 -o {{ public_ip_iface }} -j MASQUERADE
|
||||
-A POSTROUTING -s 10.10.0.0/24 -o {{ public_ip_iface }} -j MASQUERADE
|
||||
COMMIT
|
||||
# END VPN NAT
|
||||
notify: Reload ufw
|
||||
|
||||
handlers:
|
||||
- name: Reload sysctl
|
||||
ansible.builtin.command: sysctl -p /etc/sysctl.d/99-ipv4-forward.conf
|
||||
register: result
|
||||
changed_when: result.rc == 0
|
||||
|
||||
- name: Reload ufw
|
||||
ansible.builtin.command: ufw reload
|
||||
register: result
|
||||
changed_when: result.rc == 0
|
||||
|
||||
- name: Setup strongswan
|
||||
hosts: vps_servers
|
||||
become: true
|
||||
gather_facts: true
|
||||
tasks:
|
||||
- name: Uninstall strongswan legacy packages if present
|
||||
ansible.builtin.apt:
|
||||
name:
|
||||
- strongswan-starter
|
||||
- strongswan-charon
|
||||
state: absent
|
||||
purge: true
|
||||
autoremove: true
|
||||
|
||||
- name: Install strongswan with swanctl and vici
|
||||
ansible.builtin.apt:
|
||||
name:
|
||||
- charon-systemd
|
||||
- strongswan-swanctl
|
||||
- libcharon-extra-plugins
|
||||
state: present
|
||||
update_cache: true
|
||||
|
||||
- name: Copy strongswan config
|
||||
ansible.builtin.template:
|
||||
src: 'strongswan/ra-tech.conf.j2'
|
||||
dest: '/etc/swanctl/conf.d/ra-tech.conf'
|
||||
owner: root
|
||||
group: root
|
||||
mode: '0644'
|
||||
|
||||
- name: Copy strongswan dhcp module config
|
||||
ansible.builtin.template:
|
||||
src: 'strongswan/charon/dhcp.conf.j2'
|
||||
dest: '/etc/strongswan.d/charon/dhcp.conf'
|
||||
owner: root
|
||||
group: root
|
||||
mode: '0644'
|
||||
|
||||
- name: Copy Root CA
|
||||
ansible.builtin.copy:
|
||||
src: 'strongswan/ca.pem'
|
||||
dest: '/etc/swanctl/x509ca/ca-crt.pem'
|
||||
owner: root
|
||||
group: root
|
||||
mode: '0644'
|
||||
|
||||
- name: Copy keys
|
||||
ansible.builtin.copy:
|
||||
src: 'strongswan/keys/'
|
||||
dest: '/etc/swanctl/rsa/'
|
||||
owner: root
|
||||
group: root
|
||||
mode: '0640'
|
||||
|
||||
- name: Copy certificates
|
||||
ansible.builtin.copy:
|
||||
src: 'strongswan/certs/'
|
||||
dest: '/etc/swanctl/x509/'
|
||||
owner: root
|
||||
group: root
|
||||
mode: '0644'
|
||||
notify:
|
||||
- Restart strongswan service
|
||||
|
||||
- name: Configure ra0 iface
|
||||
ansible.builtin.script: 'strongswan/iface-ra0-up.sh'
|
||||
|
||||
- name: Copy ra0 iface setup script
|
||||
ansible.builtin.copy:
|
||||
src: 'strongswan/iface-ra0-up.sh'
|
||||
dest: '/usr/local/bin'
|
||||
owner: root
|
||||
group: root
|
||||
mode: '0755'
|
||||
|
||||
- name: Copy ra0 startup service
|
||||
ansible.builtin.copy:
|
||||
src: 'strongswan/iface-ra0.service'
|
||||
dest: '/etc/systemd/system/iface-ra0.service'
|
||||
owner: root
|
||||
group: root
|
||||
mode: '0644'
|
||||
notify:
|
||||
- Reload ra0 startup service
|
||||
|
||||
- name: Ufw allow strongswan ports
|
||||
community.general.ufw:
|
||||
rule: allow
|
||||
proto: udp
|
||||
port: '{{ item }}'
|
||||
loop:
|
||||
- '500'
|
||||
- '4500'
|
||||
|
||||
- name: Ufw allow from vpn subnet
|
||||
community.general.ufw:
|
||||
rule: allow
|
||||
proto: any
|
||||
src: '10.9.0.0/24'
|
||||
|
||||
handlers:
|
||||
- name: Restart strongswan service
|
||||
ansible.builtin.systemd:
|
||||
name: strongswan
|
||||
state: restarted
|
||||
enabled: true
|
||||
|
||||
- name: Reload ra0 startup service
|
||||
ansible.builtin.systemd:
|
||||
name: iface-ra0.service
|
||||
enabled: true
|
||||
daemon_reload: true
|
||||
|
||||
- name: Setup cloak
|
||||
hosts: vps_servers
|
||||
become: true
|
||||
tasks:
|
||||
- name: Create go download directory
|
||||
ansible.builtin.file:
|
||||
path: /opt/go
|
||||
state: directory
|
||||
mode: '0755'
|
||||
|
||||
- name: Download go
|
||||
ansible.builtin.get_url:
|
||||
url: 'https://go.dev/dl/go1.26.0.linux-amd64.tar.gz'
|
||||
dest: '/opt/go/go1.26.0.linux-amd64.tar.gz'
|
||||
mode: '0644'
|
||||
timeout: 60
|
||||
|
||||
- name: Unpack go
|
||||
ansible.builtin.unarchive:
|
||||
src: '/opt/go/go1.26.0.linux-amd64.tar.gz'
|
||||
dest: '/usr/local'
|
||||
remote_src: true
|
||||
|
||||
- name: Install git and make
|
||||
ansible.builtin.apt:
|
||||
name:
|
||||
- git
|
||||
- make
|
||||
state: present
|
||||
update_cache: true
|
||||
|
||||
- name: Clone cloak git repository
|
||||
ansible.builtin.git:
|
||||
repo: 'https://github.com/cbeuw/Cloak.git'
|
||||
dest: '/opt/git/Cloak'
|
||||
single_branch: true
|
||||
version: master
|
||||
|
||||
- name: Build cloak
|
||||
community.general.make:
|
||||
chdir: '/opt/git/Cloak'
|
||||
environment:
|
||||
PATH: '{{ ansible_env.PATH }}:/usr/local/go/bin'
|
||||
|
||||
- name: Setup cloak server
|
||||
ansible.builtin.copy:
|
||||
src: '/opt/git/Cloak/build/ck-server'
|
||||
remote_src: true
|
||||
dest: '/usr/local/bin'
|
||||
owner: 'root'
|
||||
group: 'root'
|
||||
mode: '0755'
|
||||
|
||||
- name: Add cloak group
|
||||
ansible.builtin.group:
|
||||
name: cloak
|
||||
state: present
|
||||
|
||||
- name: Add user for cloak
|
||||
ansible.builtin.user:
|
||||
name: cloak
|
||||
group: cloak
|
||||
state: present
|
||||
createhome: false
|
||||
|
||||
- name: Create cloak directory
|
||||
ansible.builtin.file:
|
||||
path: '/etc/cloak'
|
||||
state: directory
|
||||
mode: '0755'
|
||||
|
||||
- name: Setup cloak server configuration
|
||||
ansible.builtin.template:
|
||||
src: 'cloak/server.json.j2'
|
||||
dest: '/etc/cloak/server.json'
|
||||
owner: root
|
||||
group: cloak
|
||||
mode: '0644'
|
||||
|
||||
- name: Create cloak server data dir
|
||||
ansible.builtin.file:
|
||||
path: '/opt/cloak'
|
||||
state: directory
|
||||
owner: cloak
|
||||
group: cloak
|
||||
mode: '0755'
|
||||
|
||||
- name: Setup cloak systemd service
|
||||
ansible.builtin.copy:
|
||||
src: 'cloak/cloak.service'
|
||||
dest: '/etc/systemd/system/cloak.service'
|
||||
mode: '0644'
|
||||
notify: Reload cloak service
|
||||
|
||||
- name: Ufw allow cloak port
|
||||
community.general.ufw:
|
||||
rule: allow
|
||||
port: '5691'
|
||||
proto: tcp
|
||||
|
||||
handlers:
|
||||
- name: Reload cloak service
|
||||
ansible.builtin.systemd:
|
||||
name: cloak.service
|
||||
state: started
|
||||
enabled: false
|
||||
daemon_reload: true
|
||||
|
||||
- name: Setup openvpn server
|
||||
hosts: vps_servers
|
||||
become: true
|
||||
tasks:
|
||||
- name: Install openvpn server
|
||||
ansible.builtin.apt:
|
||||
name: openvpn
|
||||
state: present
|
||||
update_cache: true
|
||||
|
||||
- name: Copy certificates
|
||||
ansible.builtin.copy:
|
||||
src: 'openvpn/certs/'
|
||||
dest: '/etc/openvpn/server/'
|
||||
owner: root
|
||||
group: root
|
||||
mode: '0640'
|
||||
|
||||
- name: Copy openvpn config
|
||||
ansible.builtin.copy:
|
||||
src: 'openvpn/server.conf'
|
||||
dest: '/etc/openvpn/server/server.conf'
|
||||
owner: root
|
||||
group: root
|
||||
mode: '0644'
|
||||
notify:
|
||||
- Restart openvpn server
|
||||
|
||||
- name: Ufw allow openvpn port
|
||||
community.general.ufw:
|
||||
rule: allow
|
||||
proto: tcp
|
||||
port: '5690'
|
||||
|
||||
- name: Ufw allow from vpn subnet
|
||||
community.general.ufw:
|
||||
rule: allow
|
||||
proto: any
|
||||
src: '10.8.0.0/24'
|
||||
|
||||
handlers:
|
||||
- name: Restart openvpn server
|
||||
ansible.builtin.systemd:
|
||||
name: openvpn-server@server
|
||||
state: restarted
|
||||
enabled: true
|
||||
|
||||
- name: Setup bind9
|
||||
hosts: vps_servers
|
||||
become: true
|
||||
tasks:
|
||||
- name: Install bind9
|
||||
ansible.builtin.apt:
|
||||
name: bind9
|
||||
state: present
|
||||
update_cache: true
|
||||
|
||||
- name: Copy bind9 config
|
||||
ansible.builtin.copy:
|
||||
src: '{{ item }}'
|
||||
dest: '/etc/bind/'
|
||||
owner: root
|
||||
group: bind
|
||||
mode: '0644'
|
||||
loop:
|
||||
- 'bind9/named.conf.local'
|
||||
- 'bind9/named.conf.options'
|
||||
- 'bind9/named.conf.default-zones'
|
||||
- 'bind9/named.conf.root-hints'
|
||||
|
||||
- name: Copy bind9 zones
|
||||
ansible.builtin.copy:
|
||||
src: 'bind9/zones/'
|
||||
dest: '/etc/bind/zones/'
|
||||
owner: root
|
||||
group: bind
|
||||
mode: '0644'
|
||||
notify:
|
||||
- Restart bind9
|
||||
|
||||
- name: Ufw allow bind9 ports
|
||||
community.general.ufw:
|
||||
rule: allow
|
||||
name: Bind9
|
||||
|
||||
handlers:
|
||||
- name: Restart bind9
|
||||
ansible.builtin.systemd:
|
||||
name: named
|
||||
state: restarted
|
||||
enabled: true
|
||||
daemon_reload: true
|
||||
|
||||
- name: Setup prometheus node exporter
|
||||
hosts: vps_servers
|
||||
become: true
|
||||
tasks:
|
||||
- name: Create node-exporter download directory
|
||||
ansible.builtin.file:
|
||||
path: /opt/node-exporter
|
||||
state: directory
|
||||
mode: '0755'
|
||||
|
||||
- name: Download node exporter executable
|
||||
ansible.builtin.get_url:
|
||||
url: 'https://github.com/prometheus/node_exporter/releases/download/v1.10.2/node_exporter-1.10.2.linux-amd64.tar.gz'
|
||||
dest: '/opt/node-exporter/node_exporter-1.10.2.linux-amd64.tar.gz'
|
||||
mode: '0644'
|
||||
|
||||
- name: Extract node_exporter
|
||||
ansible.builtin.unarchive:
|
||||
src: '/opt/node-exporter/node_exporter-1.10.2.linux-amd64.tar.gz'
|
||||
dest: '/usr/local/bin'
|
||||
remote_src: true
|
||||
include:
|
||||
- 'node_exporter-1.10.2.linux-amd64/node_exporter'
|
||||
extra_opts:
|
||||
- '--strip-components=1'
|
||||
|
||||
- name: Add node-exporter group
|
||||
ansible.builtin.group:
|
||||
name: node_exporter
|
||||
state: present
|
||||
|
||||
- name: Add user for node exporter
|
||||
ansible.builtin.user:
|
||||
name: node_exporter
|
||||
group: node_exporter
|
||||
state: present
|
||||
createhome: false
|
||||
|
||||
- name: Setup node-exporter service
|
||||
ansible.builtin.copy:
|
||||
src: 'node-exporter/node-exporter.service'
|
||||
dest: '/etc/systemd/system/node-exporter.service'
|
||||
owner: root
|
||||
group: root
|
||||
mode: '0644'
|
||||
notify: Reload node-exporter
|
||||
|
||||
handlers:
|
||||
- name: Reload node-exporter
|
||||
ansible.builtin.systemd:
|
||||
name: node-exporter
|
||||
state: started
|
||||
enabled: true
|
||||
daemon_reload: true
|
||||
|
||||
- name: Setup haproxy
|
||||
hosts: vps_servers
|
||||
become: true
|
||||
tasks:
|
||||
- name: Install haproxy
|
||||
ansible.builtin.apt:
|
||||
name: haproxy
|
||||
state: present
|
||||
update_cache: true
|
||||
|
||||
- name: Create haproxy certs directory
|
||||
ansible.builtin.file:
|
||||
path: /etc/haproxy/certs/
|
||||
state: directory
|
||||
owner: root
|
||||
group: haproxy
|
||||
mode: '0755'
|
||||
|
||||
- name: Copy server certificate and key
|
||||
ansible.builtin.copy:
|
||||
src: 'haproxy/64.188.58.223.pem'
|
||||
dest: '/etc/haproxy/certs/64.188.58.223.pem'
|
||||
owner: root
|
||||
group: haproxy
|
||||
mode: '0640'
|
||||
|
||||
- name: Copy configuration
|
||||
ansible.builtin.copy:
|
||||
src: 'haproxy/haproxy.cfg'
|
||||
dest: '/etc/haproxy/haproxy.cfg'
|
||||
owner: root
|
||||
group: haproxy
|
||||
mode: '0644'
|
||||
notify: Restart haproxy
|
||||
|
||||
- name: Allow ufw jenkins webhook port
|
||||
community.general.ufw:
|
||||
rule: allow
|
||||
port: '7777'
|
||||
proto: tcp
|
||||
|
||||
handlers:
|
||||
- name: Restart haproxy
|
||||
ansible.builtin.systemd:
|
||||
name: haproxy
|
||||
state: restarted
|
||||
enabled: true
|
||||
|
||||
- name: Setup tiny proxy
|
||||
hosts: vps_servers
|
||||
become: true
|
||||
tasks:
|
||||
- name: Install tiny proxy
|
||||
ansible.builtin.apt:
|
||||
name: tinyproxy
|
||||
state: present
|
||||
update_cache: true
|
||||
|
||||
- name: Configure tiny proxy
|
||||
ansible.builtin.copy:
|
||||
src: 'tinyproxy/tinyproxy.conf'
|
||||
dest: '/etc/tinyproxy/tinyproxy.conf'
|
||||
mode: '0644'
|
||||
notify: Restart tinyproxy
|
||||
|
||||
handlers:
|
||||
- name: Restart tinyproxy
|
||||
ansible.builtin.systemd:
|
||||
name: tinyproxy
|
||||
state: restarted
|
||||
enabled: true
|
||||
@@ -0,0 +1,6 @@
|
||||
dhcp {
|
||||
load = yes
|
||||
force_server_address = yes
|
||||
server = 10.9.0.255
|
||||
interface = {{ public_ip_iface }}
|
||||
}
|
||||
@@ -0,0 +1,14 @@
|
||||
#!/bin/bash
|
||||
|
||||
set +e
|
||||
|
||||
echo "Confiugring ra0 network interface at $(date)"
|
||||
|
||||
ip link add ra0 type xfrm if_id 0x21
|
||||
ip link set ra0 up
|
||||
ip addr add 10.9.0.1/24 brd + dev ra0
|
||||
ip route add 10.9.0.0/24 dev ra0
|
||||
|
||||
set -e
|
||||
|
||||
exit 0
|
||||
@@ -0,0 +1,11 @@
|
||||
[Unit]
|
||||
Description=Configure ra0 interface on startup
|
||||
After=network.target
|
||||
|
||||
[Service]
|
||||
ExecStart=/usr/local/bin/iface-ra0-up.sh
|
||||
Type=oneshot
|
||||
RemainAfterExit=yes
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
@@ -0,0 +1,92 @@
|
||||
connections {
|
||||
ra-tech {
|
||||
pools = ra-tech-pool
|
||||
local {
|
||||
auth = pubkey
|
||||
certs = vps-crt.pem
|
||||
id = vps.ra-tech.dev
|
||||
}
|
||||
remote {
|
||||
auth = pubkey
|
||||
}
|
||||
children {
|
||||
ra-tech {
|
||||
local_ts = 0.0.0.0/0
|
||||
}
|
||||
}
|
||||
send_cert = always
|
||||
if_id_in = 0x21
|
||||
if_id_out = 0x21
|
||||
}
|
||||
ra-tech-ip {
|
||||
pools = ra-tech-pool
|
||||
local {
|
||||
auth = pubkey
|
||||
certs = ip-vps-crt.pem
|
||||
id = {{ public_ip }}
|
||||
}
|
||||
remote {
|
||||
auth = pubkey
|
||||
}
|
||||
children {
|
||||
ra-tech-ip {
|
||||
local_ts = 0.0.0.0/0
|
||||
}
|
||||
}
|
||||
send_cert = always
|
||||
if_id_in = 0x21
|
||||
if_id_out = 0x21
|
||||
}
|
||||
ra-tech-subnet {
|
||||
pools = ra-tech-pool
|
||||
local {
|
||||
auth = pubkey
|
||||
certs = vpn-subnet-crt.pem
|
||||
id = vpn-subnet.ra-tech.dev
|
||||
}
|
||||
remote {
|
||||
auth = pubkey
|
||||
}
|
||||
children {
|
||||
ra-tech-subnet {
|
||||
local_ts = 10.9.0.0/24
|
||||
}
|
||||
}
|
||||
send_cert = always
|
||||
if_id_in = 0x21
|
||||
if_id_out = 0x21
|
||||
}
|
||||
ra-tech-odroid {
|
||||
pools = odroid-pool
|
||||
local {
|
||||
auth = pubkey
|
||||
certs = odroid-vps-crt.pem
|
||||
id = odroid-vps.ra-tech.dev
|
||||
}
|
||||
remote {
|
||||
auth = pubkey
|
||||
id = odroid@ra-tech.dev
|
||||
}
|
||||
children {
|
||||
ra-tech-odroid {
|
||||
local_ts = 0.0.0.0/0
|
||||
}
|
||||
}
|
||||
if_id_in = 0x21
|
||||
if_id_out = 0x21
|
||||
}
|
||||
}
|
||||
|
||||
pools {
|
||||
ra-tech-pool {
|
||||
addrs = 10.9.0.11 - 10.9.0.30
|
||||
dns = 10.9.0.1
|
||||
netmask = 255.255.255.0
|
||||
}
|
||||
|
||||
odroid-pool {
|
||||
addrs = 10.9.0.10
|
||||
dns = 10.9.0.1
|
||||
netmask = 255.255.255.0
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1 @@
|
||||
net.ipv4.ip_forward=1
|
||||
@@ -0,0 +1,356 @@
|
||||
##
|
||||
## tinyproxy.conf -- tinyproxy daemon configuration file
|
||||
##
|
||||
## This example tinyproxy.conf file contains example settings
|
||||
## with explanations in comments. For decriptions of all
|
||||
## parameters, see the tinproxy.conf(5) manual page.
|
||||
##
|
||||
|
||||
#
|
||||
# User/Group: This allows you to set the user and group that will be
|
||||
# used for tinyproxy after the initial binding to the port has been done
|
||||
# as the root user. Either the user or group name or the UID or GID
|
||||
# number may be used.
|
||||
#
|
||||
User tinyproxy
|
||||
Group tinyproxy
|
||||
|
||||
#
|
||||
# Port: Specify the port which tinyproxy will listen on. Please note
|
||||
# that should you choose to run on a port lower than 1024 you will need
|
||||
# to start tinyproxy using root.
|
||||
#
|
||||
Port 8888
|
||||
|
||||
#
|
||||
# Listen: If you have multiple interfaces this allows you to bind to
|
||||
# only one. If this is commented out, tinyproxy will bind to all
|
||||
# interfaces present.
|
||||
#
|
||||
Listen 10.9.0.1
|
||||
Listen 10.8.0.1
|
||||
|
||||
#
|
||||
# Bind: This allows you to specify which interface will be used for
|
||||
# outgoing connections. This is useful for multi-home'd machines where
|
||||
# you want all traffic to appear outgoing from one particular interface.
|
||||
#
|
||||
#Bind 192.168.0.1
|
||||
|
||||
#
|
||||
# BindSame: If enabled, tinyproxy will bind the outgoing connection to the
|
||||
# ip address of the incoming connection.
|
||||
#
|
||||
#BindSame yes
|
||||
|
||||
#
|
||||
# Timeout: The maximum number of seconds of inactivity a connection is
|
||||
# allowed to have before it is closed by tinyproxy.
|
||||
#
|
||||
Timeout 600
|
||||
|
||||
#
|
||||
# ErrorFile: Defines the HTML file to send when a given HTTP error
|
||||
# occurs. You will probably need to customize the location to your
|
||||
# particular install. The usual locations to check are:
|
||||
# /usr/local/share/tinyproxy
|
||||
# /usr/share/tinyproxy
|
||||
# /etc/tinyproxy
|
||||
#
|
||||
#ErrorFile 404 "/usr/share/tinyproxy/404.html"
|
||||
#ErrorFile 400 "/usr/share/tinyproxy/400.html"
|
||||
#ErrorFile 503 "/usr/share/tinyproxy/503.html"
|
||||
#ErrorFile 403 "/usr/share/tinyproxy/403.html"
|
||||
#ErrorFile 408 "/usr/share/tinyproxy/408.html"
|
||||
|
||||
#
|
||||
# DefaultErrorFile: The HTML file that gets sent if there is no
|
||||
# HTML file defined with an ErrorFile keyword for the HTTP error
|
||||
# that has occured.
|
||||
#
|
||||
DefaultErrorFile "/usr/share/tinyproxy/default.html"
|
||||
|
||||
#
|
||||
# StatHost: This configures the host name or IP address that is treated
|
||||
# as the stat host: Whenever a request for this host is received,
|
||||
# Tinyproxy will return an internal statistics page instead of
|
||||
# forwarding the request to that host. The default value of StatHost is
|
||||
# tinyproxy.stats.
|
||||
#
|
||||
StatHost "tinyproxy.stats"
|
||||
#
|
||||
|
||||
#
|
||||
# StatFile: The HTML file that gets sent when a request is made
|
||||
# for the stathost. If this file doesn't exist a basic page is
|
||||
# hardcoded in tinyproxy.
|
||||
#
|
||||
StatFile "/usr/share/tinyproxy/stats.html"
|
||||
|
||||
#
|
||||
# LogFile: Allows you to specify the location where information should
|
||||
# be logged to. If you would prefer to log to syslog, then disable this
|
||||
# and enable the Syslog directive. These directives are mutually
|
||||
# exclusive. If neither Syslog nor LogFile are specified, output goes
|
||||
# to stdout.
|
||||
#
|
||||
LogFile "/var/log/tinyproxy/tinyproxy.log"
|
||||
|
||||
#
|
||||
# Syslog: Tell tinyproxy to use syslog instead of a logfile. This
|
||||
# option must not be enabled if the Logfile directive is being used.
|
||||
# These two directives are mutually exclusive.
|
||||
#
|
||||
Syslog On
|
||||
|
||||
#
|
||||
# LogLevel: Warning
|
||||
#
|
||||
# Set the logging level. Allowed settings are:
|
||||
# Critical (least verbose)
|
||||
# Set the logging level. Allowed settings are:
|
||||
# Critical (least verbose)
|
||||
# Error
|
||||
# Warning
|
||||
# Notice
|
||||
# Connect (to log connections without Info's noise)
|
||||
# Info (most verbose)
|
||||
#
|
||||
# The LogLevel logs from the set level and above. For example, if the
|
||||
# LogLevel was set to Warning, then all log messages from Warning to
|
||||
# Critical would be output, but Notice and below would be suppressed.
|
||||
#
|
||||
LogLevel Info
|
||||
|
||||
#
|
||||
# PidFile: Write the PID of the main tinyproxy thread to this file so it
|
||||
# can be used for signalling purposes.
|
||||
# If not specified, no pidfile will be written.
|
||||
#
|
||||
PidFile "/run/tinyproxy/tinyproxy.pid"
|
||||
|
||||
#
|
||||
# XTinyproxy: Tell Tinyproxy to include the X-Tinyproxy header, which
|
||||
# contains the client's IP address.
|
||||
#
|
||||
#XTinyproxy Yes
|
||||
|
||||
#
|
||||
# Upstream:
|
||||
#
|
||||
# Turns on upstream proxy support.
|
||||
#
|
||||
# The upstream rules allow you to selectively route upstream connections
|
||||
# based on the host/domain of the site being accessed.
|
||||
#
|
||||
# Syntax: upstream type (user:pass@)ip:port ("domain")
|
||||
# Or: upstream none "domain"
|
||||
# The parts in parens are optional.
|
||||
# Possible types are http, socks4, socks5, none
|
||||
#
|
||||
# For example:
|
||||
# # connection to test domain goes through testproxy
|
||||
# upstream http testproxy:8008 ".test.domain.invalid"
|
||||
# upstream http testproxy:8008 ".our_testbed.example.com"
|
||||
# upstream http testproxy:8008 "192.168.128.0/255.255.254.0"
|
||||
#
|
||||
# # upstream proxy using basic authentication
|
||||
# upstream http user:pass@testproxy:8008 ".test.domain.invalid"
|
||||
#
|
||||
# # no upstream proxy for internal websites and unqualified hosts
|
||||
# upstream none ".internal.example.com"
|
||||
# upstream none "www.example.com"
|
||||
# upstream none "10.0.0.0/8"
|
||||
# upstream none "192.168.0.0/255.255.254.0"
|
||||
# upstream none "."
|
||||
#
|
||||
# # connection to these boxes go through their DMZ firewalls
|
||||
# upstream http cust1_firewall:8008 "testbed_for_cust1"
|
||||
# upstream http cust2_firewall:8008 "testbed_for_cust2"
|
||||
#
|
||||
# # default upstream is internet firewall
|
||||
# upstream http firewall.internal.example.com:80
|
||||
#
|
||||
# You may also use SOCKS4/SOCKS5 upstream proxies:
|
||||
# upstream socks4 127.0.0.1:9050
|
||||
# upstream socks5 socksproxy:1080
|
||||
#
|
||||
# The LAST matching rule wins the route decision. As you can see, you
|
||||
# can use a host, or a domain:
|
||||
# name matches host exactly
|
||||
# .name matches any host in domain "name"
|
||||
# . matches any host with no domain (in 'empty' domain)
|
||||
# IP/bits matches network/mask
|
||||
# IP/mask matches network/mask
|
||||
#
|
||||
#Upstream http some.remote.proxy:port
|
||||
|
||||
#
|
||||
# MaxClients: This is the absolute highest number of threads which will
|
||||
# be created. In other words, only MaxClients number of clients can be
|
||||
# connected at the same time.
|
||||
#
|
||||
MaxClients 100
|
||||
|
||||
#
|
||||
# MinSpareServers/MaxSpareServers: These settings set the upper and
|
||||
# lower limit for the number of spare servers which should be available.
|
||||
#
|
||||
# If the number of spare servers falls below MinSpareServers then new
|
||||
# server processes will be spawned. If the number of servers exceeds
|
||||
# MaxSpareServers then the extras will be killed off.
|
||||
#
|
||||
MinSpareServers 5
|
||||
MaxSpareServers 20
|
||||
|
||||
#
|
||||
# StartServers: The number of servers to start initially.
|
||||
#
|
||||
StartServers 10
|
||||
|
||||
#
|
||||
# MaxRequestsPerChild: The number of connections a thread will handle
|
||||
# before it is killed. In practise this should be set to 0, which
|
||||
# disables thread reaping. If you do notice problems with memory
|
||||
# leakage, then set this to something like 10000.
|
||||
#
|
||||
MaxRequestsPerChild 0
|
||||
|
||||
#
|
||||
# Allow: Customization of authorization controls. If there are any
|
||||
# access control keywords then the default action is to DENY. Otherwise,
|
||||
# the default action is ALLOW.
|
||||
#
|
||||
# The order of the controls are important. All incoming connections are
|
||||
# tested against the controls based on order.
|
||||
#
|
||||
Allow 127.0.0.1
|
||||
Allow 10.9.0.0/24
|
||||
Allow 10.8.0.0/24
|
||||
#Allow 192.168.0.0/16
|
||||
#Allow 172.16.0.0/12
|
||||
#Allow 10.0.0.0/8
|
||||
|
||||
# BasicAuth: HTTP "Basic Authentication" for accessing the proxy.
|
||||
# If there are any entries specified, access is only granted for authenticated
|
||||
# users.
|
||||
#BasicAuth user password
|
||||
|
||||
#
|
||||
# AddHeader: Adds the specified headers to outgoing HTTP requests that
|
||||
# Tinyproxy makes. Note that this option will not work for HTTPS
|
||||
# traffic, as Tinyproxy has no control over what headers are exchanged.
|
||||
#
|
||||
#AddHeader "X-My-Header" "Powered by Tinyproxy"
|
||||
|
||||
#
|
||||
# ViaProxyName: The "Via" header is required by the HTTP RFC, but using
|
||||
#
|
||||
# ViaProxyName: The "Via" header is required by the HTTP RFC, but using
|
||||
# the real host name is a security concern. If the following directive
|
||||
# is enabled, the string supplied will be used as the host name in the
|
||||
# Via header; otherwise, the server's host name will be used.
|
||||
#
|
||||
ViaProxyName "tinyproxy"
|
||||
|
||||
#
|
||||
# DisableViaHeader: When this is set to yes, Tinyproxy does NOT add
|
||||
# the Via header to the requests. This virtually puts Tinyproxy into
|
||||
# stealth mode. Note that RFC 2616 requires proxies to set the Via
|
||||
# header, so by enabling this option, you break compliance.
|
||||
# Don't disable the Via header unless you know what you are doing...
|
||||
#
|
||||
#DisableViaHeader Yes
|
||||
|
||||
#
|
||||
# Filter: This allows you to specify the location of the filter file.
|
||||
#
|
||||
#Filter "/etc/tinyproxy/filter"
|
||||
|
||||
#
|
||||
# FilterURLs: Filter based on URLs rather than domains.
|
||||
#
|
||||
#FilterURLs On
|
||||
|
||||
#
|
||||
# FilterExtended: Use POSIX Extended regular expressions rather than
|
||||
# basic.
|
||||
#
|
||||
#FilterExtended On
|
||||
|
||||
#
|
||||
# FilterCaseSensitive: Use case sensitive regular expressions.
|
||||
#
|
||||
#FilterCaseSensitive On
|
||||
|
||||
#
|
||||
# FilterDefaultDeny: Change the default policy of the filtering system.
|
||||
# If this directive is commented out, or is set to "No" then the default
|
||||
# policy is to allow everything which is not specifically denied by the
|
||||
# filter file.
|
||||
#
|
||||
# However, by setting this directive to "Yes" the default policy becomes
|
||||
# to deny everything which is _not_ specifically allowed by the filter
|
||||
# file.
|
||||
#
|
||||
#FilterDefaultDeny Yes
|
||||
|
||||
#
|
||||
# Anonymous: If an Anonymous keyword is present, then anonymous proxying
|
||||
# is enabled. The headers listed are allowed through, while all others
|
||||
# are denied. If no Anonymous keyword is present, then all headers are
|
||||
# allowed through. You must include quotes around the headers.
|
||||
#
|
||||
# Most sites require cookies to be enabled for them to work correctly, so
|
||||
# you will need to allow Cookies through if you access those sites.
|
||||
#
|
||||
#Anonymous "Host"
|
||||
#Anonymous "Authorization"
|
||||
#Anonymous "Cookie"
|
||||
|
||||
#
|
||||
# ConnectPort: This is a list of ports allowed by tinyproxy when the
|
||||
# CONNECT method is used. To disable the CONNECT method altogether, set
|
||||
# the value to 0. If no ConnectPort line is found, all ports are
|
||||
# allowed.
|
||||
#
|
||||
# The following two ports are used by SSL.
|
||||
#
|
||||
ConnectPort 443
|
||||
ConnectPort 563
|
||||
|
||||
#
|
||||
# Configure one or more ReversePath directives to enable reverse proxy
|
||||
# support. With reverse proxying it's possible to make a number of
|
||||
# sites appear as if they were part of a single site.
|
||||
#
|
||||
# If you uncomment the following two directives and run tinyproxy
|
||||
# on your own computer at port 8888, you can access Google using
|
||||
# http://localhost:8888/google/ and Wired News using
|
||||
# http://localhost:8888/wired/news/. Neither will actually work
|
||||
# until you uncomment ReverseMagic as they use absolute linking.
|
||||
#
|
||||
#ReversePath "/google/" "http://www.google.com/"
|
||||
#ReversePath "/wired/" "http://www.wired.com/"
|
||||
|
||||
#
|
||||
# When using tinyproxy as a reverse proxy, it is STRONGLY recommended
|
||||
# that the normal proxy is turned off by uncommenting the next directive.
|
||||
#
|
||||
#ReverseOnly Yes
|
||||
|
||||
#
|
||||
# Use a cookie to track reverse proxy mappings. If you need to reverse
|
||||
# proxy sites which have absolute links you must uncomment this.
|
||||
#
|
||||
#ReverseMagic Yes
|
||||
|
||||
#
|
||||
# The URL that's used to access this reverse proxy. The URL is used to
|
||||
# rewrite HTTP redirects so that they won't escape the proxy. If you
|
||||
# have a chain of reverse proxies, you'll need to put the outermost
|
||||
# URL here (the address which the end user types into his/her browser).
|
||||
#
|
||||
# If not set then no rewriting occurs.
|
||||
#
|
||||
#ReverseBaseURL "http://localhost:8888/"
|
||||
Reference in new issue
Block a user