feat(proxy): sync Cloudflare ranges at nginx+Traefik, block IP spoofing
Gitea Actions Runner Test / test-job (push) Successful in 0s
CI / check (push) Successful in 30s
CI / tests-integration (push) Successful in 1m51s
CI / tests-unit (push) Successful in 1m54s
CI / tests-ui (push) Successful in 2m44s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 20s
Gitea Actions Runner Test / test-job (push) Successful in 0s
CI / check (push) Successful in 30s
CI / tests-integration (push) Successful in 1m51s
CI / tests-unit (push) Successful in 1m54s
CI / tests-ui (push) Successful in 2m44s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 20s
- cloudflare-ips.conf (new): geo $cms_trusted_edge + set_real_ip_from from live CF IPv4/IPv6 ranges plus Traefik bridge and loopback - nginx-cms.conf: forward real client IP only from trusted peers, strip incoming CF-Connecting-IP, 403 any other peer that presents one (spoof gate); direct game clients on :9443 stay unaffected - cf-ips-sync.sh (new): fetch cloudflare.com/ips-v4/-v6, regenerate the nginx snippet and Traefik websecure.forwardedHeaders.trustedIPs - nginx-sync.sh: install the cloudflare-ips.conf snippet - cms_upstream_servers.conf: point default at the live green slot 3003
This commit is contained in:
1 parent
7697728d07
commit
90b65c92a2
6 files changed
+322
-20
No files matched your search
@@ -109,6 +109,16 @@ server {
|
||||
ssl_protocols TLSv1.2 TLSv1.3;
|
||||
ssl_prefer_server_ciphers off;
|
||||
|
||||
# ─── Trusted Edge Gate ───
|
||||
# Real Cloudflare edges and Traefik are the only peers trusted to supply a
|
||||
# CF-Connecting-IP (see cloudflare-ips.conf). Any other peer that does is
|
||||
# spoofing and is rejected before it reaches the CMS. Legitimate direct
|
||||
# visitors (game client, :9443) never carry that header and pass through
|
||||
# with their real peer address.
|
||||
if ($cms_disallow_forwarding) {
|
||||
return 403;
|
||||
}
|
||||
|
||||
location /health {
|
||||
access_log off;
|
||||
return 200 "OK";
|
||||
@@ -122,10 +132,10 @@ server {
|
||||
proxy_set_header Connection "upgrade";
|
||||
proxy_set_header Host $host;
|
||||
|
||||
# Stuur het échte client IP direct door naar Polaris
|
||||
proxy_set_header CF-Connecting-IP $http_cf_connecting_ip;
|
||||
proxy_set_header X-Real-IP $http_cf_connecting_ip;
|
||||
proxy_set_header X-Forwarded-For $http_cf_connecting_ip;
|
||||
# Echt client IP (trusted peers via real_ip, directe clients = eigen peer)
|
||||
proxy_set_header CF-Connecting-IP "";
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
proxy_set_header X-Forwarded-For $remote_addr;
|
||||
proxy_set_header X-Forwarded-Proto $scheme;
|
||||
|
||||
proxy_read_timeout 86400s;
|
||||
@@ -162,6 +172,16 @@ server {
|
||||
add_header Permissions-Policy "camera=(), microphone=(), geolocation=()" always;
|
||||
add_header Strict-Transport-Security "max-age=63072000; includeSubDomains; preload" always;
|
||||
|
||||
# ─── Trusted Edge Gate ───
|
||||
# Real Cloudflare edges / Traefik are the only peers allowed to supply a
|
||||
# CF-Connecting-IP (see cloudflare-ips.conf). Any other peer presenting one
|
||||
# is spoofing (direct :9443 traffic), and is rejected before it reaches the
|
||||
# CMS. Legitimate direct visitors never carry that header and pass through
|
||||
# with their real peer address.
|
||||
if ($cms_disallow_forwarding) {
|
||||
return 403;
|
||||
}
|
||||
|
||||
# ─── Client Limits & Timeouts ───
|
||||
client_max_body_size 20m;
|
||||
client_body_buffer_size 16k;
|
||||
@@ -262,9 +282,10 @@ server {
|
||||
proxy_pass http://cms_app;
|
||||
proxy_http_version 1.1;
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header X-Real-IP $http_cf_connecting_ip;
|
||||
proxy_set_header X-Forwarded-For $http_cf_connecting_ip;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
proxy_set_header X-Forwarded-For $remote_addr;
|
||||
proxy_set_header X-Forwarded-Proto $scheme;
|
||||
proxy_set_header CF-Connecting-IP "";
|
||||
proxy_set_header Connection "";
|
||||
# Auth is per sessie: nooit cachen, en de app-header onderdrukken zodat
|
||||
# er precies één Cache-Control overblijft.
|
||||
@@ -284,9 +305,10 @@ server {
|
||||
proxy_pass http://cms_app;
|
||||
proxy_http_version 1.1;
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header X-Real-IP $http_cf_connecting_ip;
|
||||
proxy_set_header X-Forwarded-For $http_cf_connecting_ip;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
proxy_set_header X-Forwarded-For $remote_addr;
|
||||
proxy_set_header X-Forwarded-Proto $scheme;
|
||||
proxy_set_header CF-Connecting-IP "";
|
||||
proxy_set_header Connection "";
|
||||
|
||||
proxy_hide_header Cache-Control;
|
||||
@@ -311,9 +333,10 @@ server {
|
||||
proxy_pass http://cms_app;
|
||||
proxy_http_version 1.1;
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header X-Real-IP $http_cf_connecting_ip;
|
||||
proxy_set_header X-Forwarded-For $http_cf_connecting_ip;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
proxy_set_header X-Forwarded-For $remote_addr;
|
||||
proxy_set_header X-Forwarded-Proto $scheme;
|
||||
proxy_set_header CF-Connecting-IP "";
|
||||
proxy_set_header Connection "";
|
||||
|
||||
proxy_buffering off;
|
||||
@@ -334,9 +357,10 @@ server {
|
||||
proxy_pass http://127.0.0.1:2096;
|
||||
proxy_http_version 1.1;
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header X-Real-IP $http_cf_connecting_ip;
|
||||
proxy_set_header X-Forwarded-For $http_cf_connecting_ip;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
proxy_set_header X-Forwarded-For $remote_addr;
|
||||
proxy_set_header X-Forwarded-Proto $scheme;
|
||||
proxy_set_header CF-Connecting-IP "";
|
||||
proxy_set_header Connection "";
|
||||
# De emulator levert zelf geen Cache-Control; zonder proxy_hide_header
|
||||
# zou de app-header hier een tweede keer worden toegevoegd.
|
||||
@@ -351,9 +375,10 @@ server {
|
||||
proxy_pass http://cms_app;
|
||||
proxy_http_version 1.1;
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header X-Real-IP $http_cf_connecting_ip;
|
||||
proxy_set_header X-Forwarded-For $http_cf_connecting_ip;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
proxy_set_header X-Forwarded-For $remote_addr;
|
||||
proxy_set_header X-Forwarded-Proto $scheme;
|
||||
proxy_set_header CF-Connecting-IP "";
|
||||
proxy_set_header Connection "";
|
||||
proxy_read_timeout 30s;
|
||||
}
|
||||
@@ -362,9 +387,10 @@ server {
|
||||
proxy_pass http://cms_app;
|
||||
proxy_http_version 1.1;
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header X-Real-IP $http_cf_connecting_ip;
|
||||
proxy_set_header X-Forwarded-For $http_cf_connecting_ip;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
proxy_set_header X-Forwarded-For $remote_addr;
|
||||
proxy_set_header X-Forwarded-Proto $scheme;
|
||||
proxy_set_header CF-Connecting-IP "";
|
||||
proxy_set_header Connection "";
|
||||
}
|
||||
|
||||
@@ -373,9 +399,10 @@ server {
|
||||
proxy_pass http://cms_app;
|
||||
proxy_http_version 1.1;
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header X-Real-IP $http_cf_connecting_ip;
|
||||
proxy_set_header X-Forwarded-For $http_cf_connecting_ip;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
proxy_set_header X-Forwarded-For $remote_addr;
|
||||
proxy_set_header X-Forwarded-Proto $scheme;
|
||||
proxy_set_header CF-Connecting-IP "";
|
||||
proxy_set_header Connection "";
|
||||
# De HTML is per sessie: `auth()` in de homepage-layout stuurt
|
||||
# ingelogde bezoekers door naar /me, en de CSP-nonce is per request.
|
||||
|
||||
Reference in new issue
Block a user