feat(proxy): sync Cloudflare ranges at nginx+Traefik, block IP spoofing
Gitea Actions Runner Test / test-job (push) Successful in 0s
CI / check (push) Successful in 30s
CI / tests-integration (push) Successful in 1m51s
CI / tests-unit (push) Successful in 1m54s
CI / tests-ui (push) Successful in 2m44s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 20s

- cloudflare-ips.conf (new): geo $cms_trusted_edge + set_real_ip_from from
  live CF IPv4/IPv6 ranges plus Traefik bridge and loopback
- nginx-cms.conf: forward real client IP only from trusted peers, strip
  incoming CF-Connecting-IP, 403 any other peer that presents one
  (spoof gate); direct game clients on :9443 stay unaffected
- cf-ips-sync.sh (new): fetch cloudflare.com/ips-v4/-v6, regenerate the
  nginx snippet and Traefik websecure.forwardedHeaders.trustedIPs
- nginx-sync.sh: install the cloudflare-ips.conf snippet
- cms_upstream_servers.conf: point default at the live green slot 3003
This commit is contained in:
openhands committed 2026-09-28 23:35:00 +02:00
1 parent 7697728d07
commit 90b65c92a2
6 files changed
+322 -20

No files matched your search

+7 -1
View File
@@ -3,7 +3,9 @@
# and this file. Installed/synced by scripts/nginx-sync.sh so it cannot be
# lost again while nginx keeps running on an in-memory copy.
#
# Traffic path: Cloudflare -> Traefik (:443) -> nginx (:9443) -> CMS (:3002).
# Traffic path: Cloudflare -> Traefik (:443) -> nginx (:9443) -> CMS (:3002),
# with direct Cloudflare-origin and game-client (ws.epicnabbo.nl) connections
# also terminating on :9443.
# nginx is the last layer that can still rewrite Cache-Control, so it owns the
# headers it adds explicitly; everything proxied to the CMS is passed through
# untouched unless this file says otherwise.
@@ -46,4 +48,8 @@ http {
# Cache policy maps and server blocks live in the site file so they are
# synced together and can never drift apart.
include /etc/nginx/sites-enabled/*.conf;
# Trusted edge / real-IP handling (regenerated by scripts/cf-ips-sync.sh
# from the live Cloudflare ranges; installed via scripts/nginx-sync.sh).
include /etc/nginx/conf.d/cloudflare-ips.conf;
}