feat(proxy): sync Cloudflare ranges at nginx+Traefik, block IP spoofing
Gitea Actions Runner Test / test-job (push) Successful in 0s
CI / check (push) Successful in 30s
CI / tests-integration (push) Successful in 1m51s
CI / tests-unit (push) Successful in 1m54s
CI / tests-ui (push) Successful in 2m44s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 20s

- cloudflare-ips.conf (new): geo $cms_trusted_edge + set_real_ip_from from
  live CF IPv4/IPv6 ranges plus Traefik bridge and loopback
- nginx-cms.conf: forward real client IP only from trusted peers, strip
  incoming CF-Connecting-IP, 403 any other peer that presents one
  (spoof gate); direct game clients on :9443 stay unaffected
- cf-ips-sync.sh (new): fetch cloudflare.com/ips-v4/-v6, regenerate the
  nginx snippet and Traefik websecure.forwardedHeaders.trustedIPs
- nginx-sync.sh: install the cloudflare-ips.conf snippet
- cms_upstream_servers.conf: point default at the live green slot 3003
This commit is contained in:
openhands committed 2026-09-28 23:35:00 +02:00
1 parent 7697728d07
commit 90b65c92a2
6 files changed
+322 -20

No files matched your search

+81
View File
@@ -0,0 +1,81 @@
# Trusted edge networks + live Cloudflare CDN ranges.
# Managed/regenerated by scripts/cf-ips-sync.sh - do not hand-edit the ranges.
# Topology: Cloudflare -> Traefik (:443, docker bridge proxy_traefik-proxy) ->
# nginx (:9443) -> CMS. nginx ALSO receives direct connections on :9443 from
# Cloudflare edges and from the game client (ws.epicnabbo.nl is not proxied).
# nginx only trusts the peers listed here as a source of $remote_addr
# (via CF-Connecting-IP). Anyone else presenting a CF-Connecting-IP or
# CF-ray header is spoofing and is rejected in nginx-cms.conf.
# 1 = peer is a trusted edge or internal network (keyed on the raw peer,
# unaffected by real_ip rewrites).
geo $realip_remote_addr $cms_trusted_edge {
default 0;
127.0.0.0/8 1; # localhost (health checks, admin)
::1 1; # localhost v6
172.22.0.0/16 1; # Traefik (proxyserver_traefik-proxy)
# --- Cloudflare IPv4 ranges (live from cloudflare.com/ips-v4) ---
173.245.48.0/20 1;
103.21.244.0/22 1;
103.22.200.0/22 1;
103.31.4.0/22 1;
141.101.64.0/18 1;
108.162.192.0/18 1;
190.93.240.0/20 1;
188.114.96.0/20 1;
197.234.240.0/22 1;
198.41.128.0/17 1;
162.158.0.0/15 1;
104.16.0.0/13 1;
104.24.0.0/14 1;
172.64.0.0/13 1;
131.0.72.0/22 1;
# --- Cloudflare IPv6 ranges (live from cloudflare.com/ips-v6) ---
2400:cb00::/32 1;
2606:4700::/32 1;
2803:f800::/32 1;
2405:b500::/32 1;
2405:8100::/32 1;
2a06:98c0::/29 1;
2c0f:f248::/32 1;
}
# 1 when an UNTRUSTED peer still presents a CF-Connecting-IP header: that is a
# spoof attempt (only real Cloudflare edges or Traefik may do that lawfully).
map "$cms_trusted_edge:$http_cf_connecting_ip" $cms_disallow_forwarding {
default 0;
"~^0:.+" 1;
}
# Rewrite $remote_addr from CF-Connecting-IP but ONLY for the trusted peers
# above. Direct game clients (untrusted) keep their real peer address.
set_real_ip_from 127.0.0.0/8;
set_real_ip_from ::1;
set_real_ip_from 172.22.0.0/16;
set_real_ip_from 173.245.48.0/20;
set_real_ip_from 103.21.244.0/22;
set_real_ip_from 103.22.200.0/22;
set_real_ip_from 103.31.4.0/22;
set_real_ip_from 141.101.64.0/18;
set_real_ip_from 108.162.192.0/18;
set_real_ip_from 190.93.240.0/20;
set_real_ip_from 188.114.96.0/20;
set_real_ip_from 197.234.240.0/22;
set_real_ip_from 198.41.128.0/17;
set_real_ip_from 162.158.0.0/15;
set_real_ip_from 104.16.0.0/13;
set_real_ip_from 104.24.0.0/14;
set_real_ip_from 172.64.0.0/13;
set_real_ip_from 131.0.72.0/22;
set_real_ip_from 2400:cb00::/32;
set_real_ip_from 2606:4700::/32;
set_real_ip_from 2803:f800::/32;
set_real_ip_from 2405:b500::/32;
set_real_ip_from 2405:8100::/32;
set_real_ip_from 2a06:98c0::/29;
set_real_ip_from 2c0f:f248::/32;
real_ip_header CF-Connecting-IP;
real_ip_recursive off;
+1 -1
View File
@@ -1,2 +1,2 @@
# Default; ci-deploy.sh (blue/green) herschrijft dit bestand bij elke switch.
server 127.0.0.1:3002;
server 127.0.0.1:3003;
+45 -18
View File
@@ -109,6 +109,16 @@ server {
ssl_protocols TLSv1.2 TLSv1.3;
ssl_prefer_server_ciphers off;
# ─── Trusted Edge Gate ───
# Real Cloudflare edges and Traefik are the only peers trusted to supply a
# CF-Connecting-IP (see cloudflare-ips.conf). Any other peer that does is
# spoofing and is rejected before it reaches the CMS. Legitimate direct
# visitors (game client, :9443) never carry that header and pass through
# with their real peer address.
if ($cms_disallow_forwarding) {
return 403;
}
location /health {
access_log off;
return 200 "OK";
@@ -122,10 +132,10 @@ server {
proxy_set_header Connection "upgrade";
proxy_set_header Host $host;
# Stuur het échte client IP direct door naar Polaris
proxy_set_header CF-Connecting-IP $http_cf_connecting_ip;
proxy_set_header X-Real-IP $http_cf_connecting_ip;
proxy_set_header X-Forwarded-For $http_cf_connecting_ip;
# Echt client IP (trusted peers via real_ip, directe clients = eigen peer)
proxy_set_header CF-Connecting-IP "";
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $remote_addr;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_read_timeout 86400s;
@@ -162,6 +172,16 @@ server {
add_header Permissions-Policy "camera=(), microphone=(), geolocation=()" always;
add_header Strict-Transport-Security "max-age=63072000; includeSubDomains; preload" always;
# ─── Trusted Edge Gate ───
# Real Cloudflare edges / Traefik are the only peers allowed to supply a
# CF-Connecting-IP (see cloudflare-ips.conf). Any other peer presenting one
# is spoofing (direct :9443 traffic), and is rejected before it reaches the
# CMS. Legitimate direct visitors never carry that header and pass through
# with their real peer address.
if ($cms_disallow_forwarding) {
return 403;
}
# ─── Client Limits & Timeouts ───
client_max_body_size 20m;
client_body_buffer_size 16k;
@@ -262,9 +282,10 @@ server {
proxy_pass http://cms_app;
proxy_http_version 1.1;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $http_cf_connecting_ip;
proxy_set_header X-Forwarded-For $http_cf_connecting_ip;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $remote_addr;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header CF-Connecting-IP "";
proxy_set_header Connection "";
# Auth is per sessie: nooit cachen, en de app-header onderdrukken zodat
# er precies één Cache-Control overblijft.
@@ -284,9 +305,10 @@ server {
proxy_pass http://cms_app;
proxy_http_version 1.1;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $http_cf_connecting_ip;
proxy_set_header X-Forwarded-For $http_cf_connecting_ip;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $remote_addr;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header CF-Connecting-IP "";
proxy_set_header Connection "";
proxy_hide_header Cache-Control;
@@ -311,9 +333,10 @@ server {
proxy_pass http://cms_app;
proxy_http_version 1.1;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $http_cf_connecting_ip;
proxy_set_header X-Forwarded-For $http_cf_connecting_ip;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $remote_addr;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header CF-Connecting-IP "";
proxy_set_header Connection "";
proxy_buffering off;
@@ -334,9 +357,10 @@ server {
proxy_pass http://127.0.0.1:2096;
proxy_http_version 1.1;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $http_cf_connecting_ip;
proxy_set_header X-Forwarded-For $http_cf_connecting_ip;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $remote_addr;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header CF-Connecting-IP "";
proxy_set_header Connection "";
# De emulator levert zelf geen Cache-Control; zonder proxy_hide_header
# zou de app-header hier een tweede keer worden toegevoegd.
@@ -351,9 +375,10 @@ server {
proxy_pass http://cms_app;
proxy_http_version 1.1;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $http_cf_connecting_ip;
proxy_set_header X-Forwarded-For $http_cf_connecting_ip;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $remote_addr;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header CF-Connecting-IP "";
proxy_set_header Connection "";
proxy_read_timeout 30s;
}
@@ -362,9 +387,10 @@ server {
proxy_pass http://cms_app;
proxy_http_version 1.1;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $http_cf_connecting_ip;
proxy_set_header X-Forwarded-For $http_cf_connecting_ip;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $remote_addr;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header CF-Connecting-IP "";
proxy_set_header Connection "";
}
@@ -373,9 +399,10 @@ server {
proxy_pass http://cms_app;
proxy_http_version 1.1;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $http_cf_connecting_ip;
proxy_set_header X-Forwarded-For $http_cf_connecting_ip;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $remote_addr;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header CF-Connecting-IP "";
proxy_set_header Connection "";
# De HTML is per sessie: `auth()` in de homepage-layout stuurt
# ingelogde bezoekers door naar /me, en de CSP-nonce is per request.
+7 -1
View File
@@ -3,7 +3,9 @@
# and this file. Installed/synced by scripts/nginx-sync.sh so it cannot be
# lost again while nginx keeps running on an in-memory copy.
#
# Traffic path: Cloudflare -> Traefik (:443) -> nginx (:9443) -> CMS (:3002).
# Traffic path: Cloudflare -> Traefik (:443) -> nginx (:9443) -> CMS (:3002),
# with direct Cloudflare-origin and game-client (ws.epicnabbo.nl) connections
# also terminating on :9443.
# nginx is the last layer that can still rewrite Cache-Control, so it owns the
# headers it adds explicitly; everything proxied to the CMS is passed through
# untouched unless this file says otherwise.
@@ -46,4 +48,8 @@ http {
# Cache policy maps and server blocks live in the site file so they are
# synced together and can never drift apart.
include /etc/nginx/sites-enabled/*.conf;
# Trusted edge / real-IP handling (regenerated by scripts/cf-ips-sync.sh
# from the live Cloudflare ranges; installed via scripts/nginx-sync.sh).
include /etc/nginx/conf.d/cloudflare-ips.conf;
}