feat(proxy): sync Cloudflare ranges at nginx+Traefik, block IP spoofing
Gitea Actions Runner Test / test-job (push) Successful in 0s
CI / check (push) Successful in 30s
CI / tests-integration (push) Successful in 1m51s
CI / tests-unit (push) Successful in 1m54s
CI / tests-ui (push) Successful in 2m44s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 20s
Gitea Actions Runner Test / test-job (push) Successful in 0s
CI / check (push) Successful in 30s
CI / tests-integration (push) Successful in 1m51s
CI / tests-unit (push) Successful in 1m54s
CI / tests-ui (push) Successful in 2m44s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 20s
- cloudflare-ips.conf (new): geo $cms_trusted_edge + set_real_ip_from from live CF IPv4/IPv6 ranges plus Traefik bridge and loopback - nginx-cms.conf: forward real client IP only from trusted peers, strip incoming CF-Connecting-IP, 403 any other peer that presents one (spoof gate); direct game clients on :9443 stay unaffected - cf-ips-sync.sh (new): fetch cloudflare.com/ips-v4/-v6, regenerate the nginx snippet and Traefik websecure.forwardedHeaders.trustedIPs - nginx-sync.sh: install the cloudflare-ips.conf snippet - cms_upstream_servers.conf: point default at the live green slot 3003
This commit is contained in:
1 parent
7697728d07
commit
90b65c92a2
6 files changed
+322
-20
No files matched your search
@@ -3,7 +3,9 @@
|
||||
# and this file. Installed/synced by scripts/nginx-sync.sh so it cannot be
|
||||
# lost again while nginx keeps running on an in-memory copy.
|
||||
#
|
||||
# Traffic path: Cloudflare -> Traefik (:443) -> nginx (:9443) -> CMS (:3002).
|
||||
# Traffic path: Cloudflare -> Traefik (:443) -> nginx (:9443) -> CMS (:3002),
|
||||
# with direct Cloudflare-origin and game-client (ws.epicnabbo.nl) connections
|
||||
# also terminating on :9443.
|
||||
# nginx is the last layer that can still rewrite Cache-Control, so it owns the
|
||||
# headers it adds explicitly; everything proxied to the CMS is passed through
|
||||
# untouched unless this file says otherwise.
|
||||
@@ -46,4 +48,8 @@ http {
|
||||
# Cache policy maps and server blocks live in the site file so they are
|
||||
# synced together and can never drift apart.
|
||||
include /etc/nginx/sites-enabled/*.conf;
|
||||
|
||||
# Trusted edge / real-IP handling (regenerated by scripts/cf-ips-sync.sh
|
||||
# from the live Cloudflare ranges; installed via scripts/nginx-sync.sh).
|
||||
include /etc/nginx/conf.d/cloudflare-ips.conf;
|
||||
}
|
||||
Reference in new issue
Block a user