Gitea Actions Runner Test / test-job (push) Successful in 0s
CI / check (push) Successful in 30s
CI / tests-integration (push) Successful in 1m51s
CI / tests-unit (push) Successful in 1m54s
CI / tests-ui (push) Successful in 2m44s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 20s
- cloudflare-ips.conf (new): geo $cms_trusted_edge + set_real_ip_from from live CF IPv4/IPv6 ranges plus Traefik bridge and loopback - nginx-cms.conf: forward real client IP only from trusted peers, strip incoming CF-Connecting-IP, 403 any other peer that presents one (spoof gate); direct game clients on :9443 stay unaffected - cf-ips-sync.sh (new): fetch cloudflare.com/ips-v4/-v6, regenerate the nginx snippet and Traefik websecure.forwardedHeaders.trustedIPs - nginx-sync.sh: install the cloudflare-ips.conf snippet - cms_upstream_servers.conf: point default at the live green slot 3003
82 lines
2.8 KiB
Plaintext
82 lines
2.8 KiB
Plaintext
# Trusted edge networks + live Cloudflare CDN ranges.
|
|
# Managed/regenerated by scripts/cf-ips-sync.sh - do not hand-edit the ranges.
|
|
|
|
# Topology: Cloudflare -> Traefik (:443, docker bridge proxy_traefik-proxy) ->
|
|
# nginx (:9443) -> CMS. nginx ALSO receives direct connections on :9443 from
|
|
# Cloudflare edges and from the game client (ws.epicnabbo.nl is not proxied).
|
|
|
|
# nginx only trusts the peers listed here as a source of $remote_addr
|
|
# (via CF-Connecting-IP). Anyone else presenting a CF-Connecting-IP or
|
|
# CF-ray header is spoofing and is rejected in nginx-cms.conf.
|
|
|
|
# 1 = peer is a trusted edge or internal network (keyed on the raw peer,
|
|
# unaffected by real_ip rewrites).
|
|
geo $realip_remote_addr $cms_trusted_edge {
|
|
default 0;
|
|
127.0.0.0/8 1; # localhost (health checks, admin)
|
|
::1 1; # localhost v6
|
|
172.22.0.0/16 1; # Traefik (proxyserver_traefik-proxy)
|
|
# --- Cloudflare IPv4 ranges (live from cloudflare.com/ips-v4) ---
|
|
173.245.48.0/20 1;
|
|
103.21.244.0/22 1;
|
|
103.22.200.0/22 1;
|
|
103.31.4.0/22 1;
|
|
141.101.64.0/18 1;
|
|
108.162.192.0/18 1;
|
|
190.93.240.0/20 1;
|
|
188.114.96.0/20 1;
|
|
197.234.240.0/22 1;
|
|
198.41.128.0/17 1;
|
|
162.158.0.0/15 1;
|
|
104.16.0.0/13 1;
|
|
104.24.0.0/14 1;
|
|
172.64.0.0/13 1;
|
|
131.0.72.0/22 1;
|
|
# --- Cloudflare IPv6 ranges (live from cloudflare.com/ips-v6) ---
|
|
2400:cb00::/32 1;
|
|
2606:4700::/32 1;
|
|
2803:f800::/32 1;
|
|
2405:b500::/32 1;
|
|
2405:8100::/32 1;
|
|
2a06:98c0::/29 1;
|
|
2c0f:f248::/32 1;
|
|
}
|
|
|
|
# 1 when an UNTRUSTED peer still presents a CF-Connecting-IP header: that is a
|
|
# spoof attempt (only real Cloudflare edges or Traefik may do that lawfully).
|
|
map "$cms_trusted_edge:$http_cf_connecting_ip" $cms_disallow_forwarding {
|
|
default 0;
|
|
"~^0:.+" 1;
|
|
}
|
|
|
|
# Rewrite $remote_addr from CF-Connecting-IP but ONLY for the trusted peers
|
|
# above. Direct game clients (untrusted) keep their real peer address.
|
|
set_real_ip_from 127.0.0.0/8;
|
|
set_real_ip_from ::1;
|
|
set_real_ip_from 172.22.0.0/16;
|
|
set_real_ip_from 173.245.48.0/20;
|
|
set_real_ip_from 103.21.244.0/22;
|
|
set_real_ip_from 103.22.200.0/22;
|
|
set_real_ip_from 103.31.4.0/22;
|
|
set_real_ip_from 141.101.64.0/18;
|
|
set_real_ip_from 108.162.192.0/18;
|
|
set_real_ip_from 190.93.240.0/20;
|
|
set_real_ip_from 188.114.96.0/20;
|
|
set_real_ip_from 197.234.240.0/22;
|
|
set_real_ip_from 198.41.128.0/17;
|
|
set_real_ip_from 162.158.0.0/15;
|
|
set_real_ip_from 104.16.0.0/13;
|
|
set_real_ip_from 104.24.0.0/14;
|
|
set_real_ip_from 172.64.0.0/13;
|
|
set_real_ip_from 131.0.72.0/22;
|
|
set_real_ip_from 2400:cb00::/32;
|
|
set_real_ip_from 2606:4700::/32;
|
|
set_real_ip_from 2803:f800::/32;
|
|
set_real_ip_from 2405:b500::/32;
|
|
set_real_ip_from 2405:8100::/32;
|
|
set_real_ip_from 2a06:98c0::/29;
|
|
set_real_ip_from 2c0f:f248::/32;
|
|
|
|
real_ip_header CF-Connecting-IP;
|
|
real_ip_recursive off;
|