mirror of
https://github.com/GrapheneOS/infrastructure.git
synced 2025-03-14 19:06:30 -04:00
allow mjolnir to connect via nginx HTTPS
This is needed because mjolnir connecting directly to synapse causes it to repeatedly disconnect around every hour, likely due to an issue with keepalive.
This commit is contained in:
parent
bd4e51a18c
commit
a374df4aa3
@ -109,7 +109,7 @@ table inet filter {
|
||||
|
||||
chain output-raw-loopback {
|
||||
skuid unbound meta l4proto { tcp, udp } th sport 53 th dport >= 1024 th dport != 8008 notrack accept
|
||||
skuid { alpm, chrony, synapse, matterbridge } meta l4proto { tcp, udp } th sport >= 1024 th sport != 8008 th dport 53 notrack accept
|
||||
skuid { alpm, chrony, synapse, matterbridge, mjolnir } meta l4proto { tcp, udp } th sport >= 1024 th sport != 8008 th dport 53 notrack accept
|
||||
|
||||
skuid postgres udp sport >= 1024 udp sport != 8008 udp dport >= 1024 udp dport != 8008 notrack accept
|
||||
|
||||
@ -120,6 +120,7 @@ table inet filter {
|
||||
skuid http tcp sport 443 tcp dport >= 1024 tcp dport != 8008 notrack accept
|
||||
skuid matterbridge tcp sport >= 1024 tcp sport != 8008 tcp dport 443 notrack accept
|
||||
skuid synapse tcp sport >= 1024 tcp sport != 8008 tcp dport 443 notrack accept
|
||||
skuid mjolnir tcp sport >= 1024 tcp sport != 8008 tcp dport 443 notrack accept
|
||||
|
||||
skuid != root counter goto graceful-reject
|
||||
notrack accept
|
||||
|
Loading…
x
Reference in New Issue
Block a user