Private
Public Access
2
0
This commit is contained in:
2026-01-20 15:16:28 +03:00
parent f70924d910
commit cda556eec6
8 changed files with 59 additions and 26 deletions

View File

@@ -77,14 +77,14 @@ Fonctionnalités déjà implémentées:
- Alias avec redirection optionnelle vers nom canonique - Alias avec redirection optionnelle vers nom canonique
- Redirection HTTP vers HTTPS - Redirection HTTP vers HTTPS
- Certificats SSL (personnalisés automatiques via Let's Encrypt) - Certificats SSL (personnalisés automatiques via Let's Encrypt)
- Filtrage par: - Filtrage (blacklists) par:
- adresses IP - adresses IP
- réseaux IP - réseaux IP
- Antibot par: - Antibot par:
- défi JavaScript - défi JavaScript
- Passive backend checks - Passive backend checks
- Compression Gzip et zstd - Compression Gzip et zstd
- Mode détection sans blocage - Mode détection sans blocage par les CRS
- Filtrage par: - Filtrage par:
- méthode HTTP - méthode HTTP
- En-têtes de sécurité: - En-têtes de sécurité:
@@ -104,7 +104,7 @@ Urgemment:
- Connexion à consul, ACL consul - Connexion à consul, ACL consul
- Collection Ansible - Collection Ansible
- Gestion CORS - Revérifier gestion CORS
- Active backend checks - Active backend checks
- Correction de la collecte des logs via OVH LDP - Correction de la collecte des logs via OVH LDP
@@ -129,7 +129,6 @@ Fomctionnalités à ajouter:
- (ip:danmeuk-tor-exit, ua:mitchellkrogza-bad-user-agents, /etc/hapee-1.9/blacklist.acl) - (ip:danmeuk-tor-exit, ua:mitchellkrogza-bad-user-agents, /etc/hapee-1.9/blacklist.acl)
- Client cache - Client cache
- Proxy cache - Proxy cache
- Filtrage par pays
- Compression Brotli - Compression Brotli
- Reverse scan - Reverse scan
- Robots.txt (DarkVisitors API/Community Lists/Custom URLs/Manual Rules) - Robots.txt (DarkVisitors API/Community Lists/Custom URLs/Manual Rules)
@@ -142,7 +141,6 @@ Fomctionnalités à ajouter:
- HTML injection - HTML injection
- Metrics (Elasticsearch + Metabase) - Metrics (Elasticsearch + Metabase)
- Static files et FastCGI pour PHP (est-ce une bonne idée ?!) - Static files et FastCGI pour PHP (est-ce une bonne idée ?!)
- Lire doc. config JSON de Caddy
- Crowdsec - Crowdsec
- https://raw.githubusercontent.com/mitchellkrogza/nginx-ultimate-bad-bot-blocker/master/_generator_lists/bad-user-agents.list - https://raw.githubusercontent.com/mitchellkrogza/nginx-ultimate-bad-bot-blocker/master/_generator_lists/bad-user-agents.list

View File

@@ -15,7 +15,7 @@
``` ```
pipx ensurepath pipx ensurepath
``` ```
1. Installer *Ansible* (version 11, et au moins version core 2.16.9, pour 1. Installer *Ansible* (version 12, et au moins version core 2.16.9, pour
être compatible avec *Mitogen*) dans un environnement isolé (qui sera être compatible avec *Mitogen*) dans un environnement isolé (qui sera
nommé `ansible`) puis injecter *ansible-lint* et les librairies requises nommé `ansible`) puis injecter *ansible-lint* et les librairies requises
dans cet environnement: dans cet environnement:
@@ -27,14 +27,11 @@
pipx inject ansible passlib # pour |password_hash sur macOS (et autres) pipx inject ansible passlib # pour |password_hash sur macOS (et autres)
pipx inject ansible jmespath # pour |query_result pipx inject ansible jmespath # pour |query_result
pipx inject ansible pytz # pour plugin inventory auto pipx inject ansible pytz # pour plugin inventory auto
pipx inject ansible pynetbox # pour collection netbox.netbox
pipx inject ansible netaddr # pour les rôles CheckMK
pipx inject ansible mitogen # optionnel, pour utiliser Mitogen pipx inject ansible mitogen # optionnel, pour utiliser Mitogen
``` ```
1. Vérifier l'environnement: 1. Vérifier l'environnement:
``` ```
pipx list --include-injected pipx list --include-injected
ansible --version -> ansible [core 2.16.9] ansible --version -> ansible [core 2.19.5]
ansible-lint --version -> ansible-lint 24.7.0 ansible-lint --version -> ansible-lint 26.1.1
``` ```

View File

@@ -2,6 +2,10 @@ linux:
vars: vars:
ansible_user: "root" ansible_user: "root"
debian13:
vars:
ansible_python_interpreter: "/usr/bin/python3.13"
ubuntu24: ubuntu24:
vars: vars:
ansible_python_interpreter: "/usr/bin/python3.12" ansible_python_interpreter: "/usr/bin/python3.12"

View File

@@ -4,3 +4,43 @@ Security:
- Consul agent communication - Consul agent communication
- mTLS for authentitication and encryption - mTLS for authentitication and encryption
- Certificate authority - Certificate authority
"acl": {
"enabled": true,
{% if not consul_acl_bootstraped %}
"default_policy": "allow",
{% else %}
"default_policy": "deny",
"tokens": {
"agent": "FIXME"
},
{% endif %}
"down_policy": "extend-cache"
},
FIXME:
Jan 20 14:00:20 waf1 consul[3863]: 2026-01-20T14:00:20.976+0300 [WARN] agent: The 'ca_file' field is deprecated. Use the 'tls.defaults.ca_file' field instead.
Jan 20 14:00:20 waf1 consul[3863]: 2026-01-20T14:00:20.976+0300 [WARN] agent: The 'cert_file' field is deprecated. Use the 'tls.defaults.cert_file' field instead.
Jan 20 14:00:20 waf1 consul[3863]: 2026-01-20T14:00:20.976+0300 [WARN] agent: The 'key_file' field is deprecated. Use the 'tls.defaults.key_file' field instead.
Jan 20 14:00:20 waf1 consul[3863]: 2026-01-20T14:00:20.976+0300 [WARN] agent: The 'verify_incoming' field is deprecated. Use the 'tls.defaults.verify_incoming' field instead.
Jan 20 14:00:20 waf1 consul[3863]: 2026-01-20T14:00:20.976+0300 [WARN] agent: The 'verify_outgoing' field is deprecated. Use the 'tls.defaults.verify_outgoing' field instead.
Jan 20 14:00:20 waf1 consul[3863]: 2026-01-20T14:00:20.976+0300 [WARN] agent: The 'verify_server_hostname' field is deprecated. Use the 'tls.internal_rpc.verify_server_hostname' field instead.
Jan 20 14:00:20 waf1 consul[3863]: 2026-01-20T14:00:20.976+0300 [WARN] agent: The 'ui' field is deprecated. Use the 'ui_config.enabled' field instead.
Jan 20 14:00:20 waf1 consul[3863]: 2026-01-20T14:00:20.976+0300 [WARN] agent: bootstrap_expect > 0: expecting 3 servers
Jan 20 14:00:20 waf1 consul[3863]: 2026-01-20T14:00:20.983+0300 [WARN] agent.auto_config: The 'ca_file' field is deprecated. Use the 'tls.defaults.ca_file' field instead.
Jan 20 14:00:20 waf1 consul[3863]: 2026-01-20T14:00:20.983+0300 [WARN] agent.auto_config: The 'cert_file' field is deprecated. Use the 'tls.defaults.cert_file' field instead.
Jan 20 14:00:20 waf1 consul[3863]: 2026-01-20T14:00:20.983+0300 [WARN] agent.auto_config: The 'key_file' field is deprecated. Use the 'tls.defaults.key_file' field instead.
Jan 20 14:00:20 waf1 consul[3863]: 2026-01-20T14:00:20.983+0300 [WARN] agent.auto_config: The 'verify_incoming' field is deprecated. Use the 'tls.defaults.verify_incoming' field instead.
Jan 20 14:00:20 waf1 consul[3863]: 2026-01-20T14:00:20.983+0300 [WARN] agent.auto_config: The 'verify_outgoing' field is deprecated. Use the 'tls.defaults.verify_outgoing' field instead.
Jan 20 14:00:20 waf1 consul[3863]: 2026-01-20T14:00:20.983+0300 [WARN] agent.auto_config: The 'verify_server_hostname' field is deprecated. Use the 'tls.internal_rpc.verify_server_hostname' field instead.
Jan 20 14:00:20 waf1 consul[3863]: 2026-01-20T14:00:20.983+0300 [WARN] agent.auto_config: The 'ui' field is deprecated. Use the 'ui_config.enabled' field instead.
Jan 20 14:00:20 waf1 consul[3863]: agent.auto_config: The 'ca_file' field is deprecated. Use the 'tls.defaults.ca_file' field instead.
Jan 20 14:00:20 waf1 consul[3863]: 2026-01-20T14:00:20.983+0300 [WARN] agent.auto_config: bootstrap_expect > 0: expecting 3 servers
Jan 20 14:00:20 waf1 consul[3863]: agent.auto_config: The 'cert_file' field is deprecated. Use the 'tls.defaults.cert_file' field instead.
Jan 20 14:00:20 waf1 consul[3863]: agent.auto_config: The 'key_file' field is deprecated. Use the 'tls.defaults.key_file' field instead.
Jan 20 14:00:20 waf1 consul[3863]: agent.auto_config: The 'verify_incoming' field is deprecated. Use the 'tls.defaults.verify_incoming' field instead.
Jan 20 14:00:20 waf1 consul[3863]: agent.auto_config: The 'verify_outgoing' field is deprecated. Use the 'tls.defaults.verify_outgoing' field instead.
Jan 20 14:00:20 waf1 consul[3863]: agent.auto_config: The 'verify_server_hostname' field is deprecated. Use the 'tls.internal_rpc.verify_server_hostname' field instead.
Jan 20 14:00:20 waf1 consul[3863]: agent.auto_config: The 'ui' field is deprecated. Use the 'ui_config.enabled' field instead.

View File

@@ -3,6 +3,12 @@
name: name:
- "unzip" - "unzip"
- name: Disable IPv6 on all interfaces
ansible.posix.sysctl:
name: "net.ipv6.conf.all.disable_ipv6"
value: "1"
sysctl_set: true
- name: Create Consul directory - name: Create Consul directory
ansible.builtin.file: ansible.builtin.file:
path: "/usr/local/consul-{{ consul_version }}" path: "/usr/local/consul-{{ consul_version }}"

View File

@@ -18,23 +18,11 @@
"client_addr": "{{ consul_client_addr }}", "client_addr": "{{ consul_client_addr }}",
"bind_addr": "{{ consul_bind_addr }}", "bind_addr": "{{ consul_bind_addr }}",
"advertise_addr": "{{ consul_advertise_addr }}", "advertise_addr": "{{ consul_advertise_addr }}",
"bootstrap_expect": {{ consul_servers | length }}, "bootstrap_expect": {{ (consul_servers | length) - 1 }},
"enable_syslog": true, "enable_syslog": true,
"performance": { "performance": {
"raft_multiplier": 1 "raft_multiplier": 1
}, },
"acl": {
"enabled": true,
{% if not consul_acl_bootstraped %}
"default_policy": "allow",
{% else %}
"default_policy": "deny",
"tokens": {
"agent": "FIXME"
},
{% endif %}
"down_policy": "extend-cache"
},
{% endif %} {% endif %}
"retry_join": ["{{ consul_servers | join('", "') }}"] "retry_join": ["{{ consul_servers | join('", "') }}"]
} }

View File

@@ -2,7 +2,7 @@ terraform {
required_providers { required_providers {
multipass = { multipass = {
source = "larstobi/multipass" source = "larstobi/multipass"
version = "~> 1.4.2" version = "1.4.3"
} }
} }
} }

View File

@@ -4,6 +4,6 @@ variable "vms" {
cpus = optional(number, 2), cpus = optional(number, 2),
memory = optional(string, "2g"), memory = optional(string, "2g"),
disk = optional(string, "12g"), disk = optional(string, "12g"),
image = optional(string, "24.04"), image = optional(string, "https://cloud.debian.org/images/cloud/trixie/latest/debian-13-generic-amd64.qcow2"),
})) }))
} }