projects
/
chef.git
/ history
commit
grep
author
committer
pickaxe
?
search:
re
summary
|
shortlog
|
log
|
commit
|
commitdiff
|
tree
first ⋅ prev ⋅
next
Merge http and https rules
[chef.git]
/
cookbooks
/
networking
/
2023-03-07
Tom Hughes
Merge http and https rules
tree
|
commitdiff
2023-03-07
Tom Hughes
Simpligy configuration of port numbers in firewall...
tree
|
commitdiff
2023-03-07
Tom Hughes
Use interval sets for blocklists
tree
|
commitdiff
2023-03-07
Tom Hughes
Rename firewall tables to avoid any clash with iptables
tree
|
commitdiff
2023-03-06
Tom Hughes
Drop test override that is no longer needed
tree
|
commitdiff
2023-03-06
Tom Hughes
Drop support for shorewall
tree
|
commitdiff
2023-03-05
Tom Hughes
Don't expire connection limit sets
tree
|
commitdiff
2023-03-05
Tom Hughes
Expire rate limit sets
tree
|
commitdiff
2023-03-05
Tom Hughes
Remove size limits on firewall sets
tree
|
commitdiff
2023-03-05
Tom Hughes
Enable rate limits
tree
|
commitdiff
2023-03-05
Tom Hughes
Enable connections limits on a per-source basis
tree
|
commitdiff
2023-03-05
Tom Hughes
Disable rate and connection limits
tree
|
commitdiff
2023-03-05
Tom Hughes
Allow AWS DNS queries through the firewall
tree
|
commitdiff
2023-03-05
Tom Hughes
Switch remaining servers to nftables
tree
|
commitdiff
2023-03-05
Tom Hughes
Match interfaces by name so we can start nftables befor...
tree
|
commitdiff
2023-03-05
Tom Hughes
Limit NAT to IPv4 interfaces
tree
|
commitdiff
2023-03-04
Tom Hughes
Fix typo
tree
|
commitdiff
2023-03-04
Tom Hughes
Fix flag matches to work on 20.04
tree
|
commitdiff
2023-03-04
Tom Hughes
Handle machines with no external interface
tree
|
commitdiff
2023-03-04
Tom Hughes
Block unspecified and multicast addresses on the outside
tree
|
commitdiff
2023-03-04
Tom Hughes
Limit echo on a per source basis
tree
|
commitdiff
2023-03-04
Tom Hughes
Make nftables block various invalid TCP flag combinations
tree
|
commitdiff
2023-03-04
Tom Hughes
Don't log rate limited echo request packets
tree
|
commitdiff
2023-03-04
Tom Hughes
Avoid dropping third party tables when stopping an...
tree
|
commitdiff
2023-03-04
Tom Hughes
Eliminate need for dummy addresses in when running...
tree
|
commitdiff
2023-03-04
Tom Hughes
Revert "Only flush our table to avoid disrupting other...
tree
|
commitdiff
2023-03-04
Tom Hughes
Only flush our table to avoid disrupting other nftables...
tree
|
commitdiff
2023-03-04
Tom Hughes
Use named sets for OSM IP addresses
tree
|
commitdiff
2023-03-04
Tom Hughes
Fix port range syntax for nftables
tree
|
commitdiff
2023-03-04
Tom Hughes
Don't bother disabling shorewall before we remove it
tree
|
commitdiff
2023-03-04
Tom Hughes
Fix typo
tree
|
commitdiff
2023-03-04
Tom Hughes
Use strings for network families
tree
|
commitdiff
2023-03-04
Tom Hughes
Add support for using an nftables based firewall
tree
|
commitdiff
2023-01-19
Tom Hughes
Drop wireguard tunnels from shenron to data centres
tree
|
commitdiff
2022-12-10
Tom Hughes
Merge remote-tracking branch 'github/pull/528'
tree
|
commitdiff
2022-12-04
Grant Slater
Do not install recommends for wireguard-tools
tree
|
commitdiff
2022-10-20
Tom Hughes
Only configure a primary slave in active-backup mode
tree
|
commitdiff
2022-10-12
Grant Slater
shorewall: minor config align to upstream
tree
|
commitdiff
2022-09-24
Tom Hughes
Limit wireguard special casing to shenron
tree
|
commitdiff
2022-08-03
Tom Hughes
Merge remote-tracking branch 'github/pull/514'
tree
|
commitdiff
2022-08-02
Grant Slater
Merge remote-tracking branch 'tigerfell/pr257'
tree
|
commitdiff
2022-08-01
Grant Slater
wireguard: use keepalive by default to survive NAT
tree
|
commitdiff
2022-07-28
Grant Slater
networking: add endpoint for my roaming device
tree
|
commitdiff
2022-07-28
Grant Slater
networking: grant roaming wg correct key
tree
|
commitdiff
2022-07-28
Grant Slater
networking: Add grant roaming wg
tree
|
commitdiff
2022-07-11
Tom Hughes
Update shorewall to use snat configuration file instead...
tree
|
commitdiff
2022-07-08
Grant Slater
Use Google DNS instead of Cloudflare
tree
|
commitdiff
2021-11-10
Tom Hughes
Use kitchen? instead of looking for TEST_KITCHEN in...
tree
|
commitdiff
2021-10-19
Grant Slater
Add firefishy wireguard peer
tree
|
commitdiff
2021-10-05
Tom Hughes
Mark slave interfaces in a bond as optional
tree
|
commitdiff
2021-09-26
Tom Hughes
Avoid installing a private network default route on...
tree
|
commitdiff
2021-09-25
Tom Hughes
Cleanup any netplan config created by the Ubuntu installer
tree
|
commitdiff
2021-09-19
Tom Hughes
Add equinix-dub role
tree
|
commitdiff
2021-08-26
Tom Hughes
Fix new cookstyle warnings
tree
|
commitdiff
2021-08-25
Tom Hughes
Merge remote-tracking branch 'github/pull/440'
tree
|
commitdiff
2021-08-25
Grant Slater
Add shorewall stoppedrules support
tree
|
commitdiff
2021-08-25
Grant Slater
Override systemd shorewall to not use clear
tree
|
commitdiff
2021-08-25
Grant Slater
Add docker support to shorewall
tree
|
commitdiff
2021-05-14
Tom Hughes
Enable unified mode for custom resources
tree
|
commitdiff
2021-05-11
Tom Hughes
Sort wireguard peers to keep file content stable
tree
|
commitdiff
2021-03-09
Tigerfell
Merge branch 'patch-2' of https://github.com/Tigerfell...
tree
|
commitdiff
2021-01-27
Tom Hughes
Establish wireguard tunnels from gateways to prometheus...
tree
|
commitdiff
2020-11-28
Tom Hughes
Merge remote-tracking branch 'github/pull/350' into...
tree
|
commitdiff
2020-11-28
Tom Hughes
Merge remote-tracking branch 'github/pull/349' into...
tree
|
commitdiff
2020-11-22
Grant
Merge pull request #360 from Firefishy/torrent-rss
tree
|
commitdiff
2020-11-19
Tom Hughes
Process firewall_rule resources at compile time
tree
|
commitdiff
2020-10-08
Tom Hughes
Use a common set of default resolvers, defaulting to...
tree
|
commitdiff
2020-09-25
Tom Hughes
Ignore failures starting shorewall
tree
|
commitdiff
2020-09-24
Tom Hughes
Ignore failures disabling shorewall
tree
|
commitdiff
2020-09-20
Tom Hughes
Go back to unmounting resolv.conf but prevent path...
tree
|
commitdiff
2020-09-18
Tom Hughes
Attempt to fix test failures caused by crazy docker...
tree
|
commitdiff
2020-09-18
Tom Hughes
Estabish tunnels between shenron and gateway machines
tree
|
commitdiff
2020-09-16
Tom Hughes
Fix prometheus test
tree
|
commitdiff
2020-09-16
Tom Hughes
Allow prometheus to use wireguard or direct external...
tree
|
commitdiff
2020-09-16
Tom Hughes
Enable wireguard support on all machines that support it
tree
|
commitdiff
2020-09-15
Tom Hughes
Allow wireguard connections from anywhere
tree
|
commitdiff
2020-09-15
Tom Hughes
Enable wireguard access for tomh
tree
|
commitdiff
2020-09-15
Tom Hughes
Remove a few legacy settings
tree
|
commitdiff
2020-09-14
Tom Hughes
Remove cleanup code
tree
|
commitdiff
2020-09-14
Tom Hughes
Configure v4 address for wireguard endpoints with an...
tree
|
commitdiff
2020-09-14
Tom Hughes
Cleanup any old "normal" priority networking configuration
tree
|
commitdiff
2020-09-14
Tom Hughes
Fix configuration of wireguard keys on 18.04
tree
|
commitdiff
2020-09-14
Tom Hughes
Make updating wireguard configuration work on 18.04
tree
|
commitdiff
2020-09-14
Tom Hughes
Add routes to wireguard peers
tree
|
commitdiff
2020-09-14
Tom Hughes
Use correct network prefix for wireguard tunnels
tree
|
commitdiff
2020-09-14
Tom Hughes
Strip trailing newline from public key
tree
|
commitdiff
2020-09-14
Tom Hughes
Generate wireguard addresses without systemd-id128
tree
|
commitdiff
2020-09-14
Tom Hughes
Fix cookstyle warnings
tree
|
commitdiff
2020-09-14
Tom Hughes
Replace OpenVPN with wireguard for VPN tunnels
tree
|
commitdiff
2020-09-13
Tom Hughes
Add basic infrastructure for wireguard tunnels
tree
|
commitdiff
2020-09-06
Tom Hughes
Disable firewall on lambton
tree
|
commitdiff
2020-07-30
Tom Hughes
Allow connection_limit to be an integer
tree
|
commitdiff
2020-07-30
Tom Hughes
Convert firewall_rule to a resource
tree
|
commitdiff
2020-07-30
Tom Hughes
Include VPN routes in the netplan config
tree
|
commitdiff
2020-07-21
Tom Hughes
Convert some normal attributes to default or override
tree
|
commitdiff
2020-07-21
Tom Hughes
Remove code to set (now unused) tcp fastopen keys
tree
|
commitdiff
2020-07-21
Tom Hughes
Use strings for file modes
tree
|
commitdiff
2020-05-29
Tom Hughes
Handle interfaces with no address
tree
|
commitdiff
2020-05-29
Tom Hughes
Bond interfaces on pummelzacken
tree
|
commitdiff
2020-05-13
Tom Hughes
Fix hostnamect call
tree
|
commitdiff
next