Compare commits
7 Commits
v0.0.6l-em
...
v0.0.6p-ml
Author | SHA1 | Date | |
---|---|---|---|
b36505bf78 | |||
2546430f94 | |||
0624f3da72 | |||
40c8aeccd9 | |||
5c21400e29 | |||
33a9c5e8f6 | |||
6f25e4caa4 |
@ -18,7 +18,7 @@
|
|||||||
# - firewall-vpn-l
|
# - firewall-vpn-l
|
||||||
- wireguard-l
|
- wireguard-l
|
||||||
# - x509-l
|
# - x509-l
|
||||||
- fw-ferm
|
- post
|
||||||
- ssh-cli
|
- ssh-cli
|
||||||
- syslog-cli
|
- syslog-cli
|
||||||
- post
|
- fw-ferm
|
||||||
|
@ -1,47 +0,0 @@
|
|||||||
# -*- shell-script -*-
|
|
||||||
|
|
||||||
@def $DEV_VPN= wg0;
|
|
||||||
|
|
||||||
table filter {
|
|
||||||
chain INPUT {
|
|
||||||
policy DROP;
|
|
||||||
|
|
||||||
# connection tracking
|
|
||||||
mod state state INVALID DROP;
|
|
||||||
mod state state (ESTABLISHED RELATED) ACCEPT;
|
|
||||||
|
|
||||||
# allow local connections
|
|
||||||
interface lo ACCEPT;
|
|
||||||
interface $DEV_VPN{
|
|
||||||
# respond to ping
|
|
||||||
proto icmp icmp-type echo-request ACCEPT;
|
|
||||||
# disallow ssh
|
|
||||||
saddr proto tcp dport ssh DROP;
|
|
||||||
}
|
|
||||||
}#FIN INPUT
|
|
||||||
|
|
||||||
# outgoing connections are not limited
|
|
||||||
chain OUTPUT {
|
|
||||||
policy ACCEPT;
|
|
||||||
interface $DEV_VPN{
|
|
||||||
# allow ssh
|
|
||||||
daddr proto tcp dport ssh ACCEPT;
|
|
||||||
# respond to ping
|
|
||||||
proto icmp icmp-type echo-request ACCEPT;
|
|
||||||
}
|
|
||||||
}#FIN OUTPUT
|
|
||||||
|
|
||||||
chain FORWARD {
|
|
||||||
policy ACCEPT;
|
|
||||||
|
|
||||||
# connection tracking
|
|
||||||
mod state state INVALID DROP;
|
|
||||||
mod state state (ESTABLISHED RELATED) ACCEPT;
|
|
||||||
|
|
||||||
# connections from the internal net to the internet or to other
|
|
||||||
# internal nets are allowed
|
|
||||||
interface $DEV_VPN ACCEPT;
|
|
||||||
|
|
||||||
# the rest is dropped by the above policy
|
|
||||||
}#FIN FO
|
|
||||||
}
|
|
@ -50,15 +50,7 @@ table filter {
|
|||||||
|
|
||||||
chain FORWARD {
|
chain FORWARD {
|
||||||
policy ACCEPT;
|
policy ACCEPT;
|
||||||
|
|
||||||
interface $DEV_VPN{
|
|
||||||
# respond to ping
|
|
||||||
proto icmp icmp-type echo-request ACCEPT;
|
proto icmp icmp-type echo-request ACCEPT;
|
||||||
# disallow ssh
|
|
||||||
saddr($DEV_VPN) proto tcp dport ssh DROP;
|
|
||||||
# allow ssh
|
|
||||||
daddr($DEV_VPN) proto tcp dport ssh ACCEPT;
|
|
||||||
|
|
||||||
}
|
}
|
||||||
# connection tracking
|
# connection tracking
|
||||||
mod state state INVALID DROP;
|
mod state state INVALID DROP;
|
||||||
|
@ -20,11 +20,11 @@
|
|||||||
- name: copie de values.yaml...
|
- name: copie de values.yaml...
|
||||||
copy:
|
copy:
|
||||||
src: /root/tools/ansible/gsb2023/roles/peertube/files/values.yaml
|
src: /root/tools/ansible/gsb2023/roles/peertube/files/values.yaml
|
||||||
dest: /root/tools/peertube/Peertube-helm/helm/
|
dest: /root/tools/peertube/helm/
|
||||||
mode: '0644'
|
mode: '0644'
|
||||||
|
|
||||||
- name: installation de helm...
|
- name: installation de helm...
|
||||||
shell: curl https://raw.githubusercontent.com/helm/helm/main/scripts/get-helm-3 | bash
|
shell: curl https://raw.githubusercontent.com/helm/helm/main/scripts/get-helm-3 | bash
|
||||||
|
|
||||||
- name: installation de peertube...
|
- name: installation de peertube...
|
||||||
shell: helm build /root/tools/peertube/Peertube-helm/helm && helm install --create-namesapce -n peertube peertube-gsb
|
shell: helm repo add https://charts.bitnami.com/bitnami && helm repo add https://bokysan.github.io/docker-postfix && helm dependency build /root/tools/peertube/helm/ && helm install --create-namesapce -n peertube peertube-gsb /root/tools/peertube/helm
|
||||||
|
Reference in New Issue
Block a user