mirror of
https://github.com/GrapheneOS/infrastructure.git
synced 2025-07-22 22:40:35 -04:00
replace nginx with dnsdist for DNS-over-TLS
This commit is contained in:
parent
27fe524af6
commit
e75172d57c
10 changed files with 14 additions and 14 deletions
|
@ -119,7 +119,7 @@ table inet filter {
|
||||||
type filter hook output priority raw
|
type filter hook output priority raw
|
||||||
|
|
||||||
oif lo goto output-raw-loopback
|
oif lo goto output-raw-loopback
|
||||||
skuid != { root, systemd-network, unbound, alpm, chrony, http, powerdns, geoipupdate, zerotier-one, bird } counter goto graceful-reject
|
skuid != { root, systemd-network, unbound, alpm, chrony, http, powerdns, dnsdist, geoipupdate, zerotier-one, bird } counter goto graceful-reject
|
||||||
udp sport 53 notrack accept
|
udp sport 53 notrack accept
|
||||||
meta l4proto { icmp, ipv6-icmp } notrack accept
|
meta l4proto { icmp, ipv6-icmp } notrack accept
|
||||||
}
|
}
|
||||||
|
@ -128,8 +128,8 @@ table inet filter {
|
||||||
skuid unbound meta l4proto { tcp, udp } th sport 53 th dport >= 1024 notrack accept
|
skuid unbound meta l4proto { tcp, udp } th sport 53 th dport >= 1024 notrack accept
|
||||||
skuid { alpm, chrony, geoipupdate, zerotier-one } meta l4proto { tcp, udp } th sport >= 1024 th dport 53 notrack accept
|
skuid { alpm, chrony, geoipupdate, zerotier-one } meta l4proto { tcp, udp } th sport >= 1024 th dport 53 notrack accept
|
||||||
|
|
||||||
skuid powerdns meta l4proto tcp th sport 54 th dport >= 1024 notrack accept
|
skuid powerdns meta l4proto { tcp, udp } th sport 54 th dport >= 1024 notrack accept
|
||||||
skuid http meta l4proto tcp th sport >= 1024 th dport 54 notrack accept
|
skuid dnsdist meta l4proto { tcp, udp } th sport >= 1024 th dport 54 notrack accept
|
||||||
|
|
||||||
skuid powerdns meta l4proto tcp th sport 81 th dport >= 1024 notrack accept
|
skuid powerdns meta l4proto tcp th sport 81 th dport >= 1024 notrack accept
|
||||||
|
|
||||||
|
|
|
@ -117,7 +117,7 @@ table inet filter {
|
||||||
type filter hook output priority raw
|
type filter hook output priority raw
|
||||||
|
|
||||||
oif lo goto output-raw-loopback
|
oif lo goto output-raw-loopback
|
||||||
skuid != { root, systemd-network, unbound, alpm, chrony, http, powerdns, geoipupdate } counter goto graceful-reject
|
skuid != { root, systemd-network, unbound, alpm, chrony, http, powerdns, dnsdist, geoipupdate } counter goto graceful-reject
|
||||||
udp sport 53 notrack accept
|
udp sport 53 notrack accept
|
||||||
meta l4proto { icmp, ipv6-icmp } notrack accept
|
meta l4proto { icmp, ipv6-icmp } notrack accept
|
||||||
}
|
}
|
||||||
|
@ -126,8 +126,8 @@ table inet filter {
|
||||||
skuid unbound meta l4proto { tcp, udp } th sport 53 th dport >= 1024 notrack accept
|
skuid unbound meta l4proto { tcp, udp } th sport 53 th dport >= 1024 notrack accept
|
||||||
skuid { alpm, chrony, geoipupdate } meta l4proto { tcp, udp } th sport >= 1024 th dport 53 notrack accept
|
skuid { alpm, chrony, geoipupdate } meta l4proto { tcp, udp } th sport >= 1024 th dport 53 notrack accept
|
||||||
|
|
||||||
skuid powerdns meta l4proto tcp th sport 54 th dport >= 1024 notrack accept
|
skuid powerdns meta l4proto { tcp, udp } th sport 54 th dport >= 1024 notrack accept
|
||||||
skuid http meta l4proto tcp th sport >= 1024 th dport 54 notrack accept
|
skuid dnsdist meta l4proto { tcp, udp } th sport >= 1024 th dport 54 notrack accept
|
||||||
|
|
||||||
skuid powerdns meta l4proto tcp th sport 81 th dport >= 1024 notrack accept
|
skuid powerdns meta l4proto tcp th sport 81 th dport >= 1024 notrack accept
|
||||||
|
|
||||||
|
|
|
@ -4,6 +4,7 @@ certbot
|
||||||
chrony
|
chrony
|
||||||
cloud-guest-utils
|
cloud-guest-utils
|
||||||
conntrack-tools
|
conntrack-tools
|
||||||
|
dnsdist
|
||||||
fish
|
fish
|
||||||
geoip
|
geoip
|
||||||
geoipupdate
|
geoipupdate
|
||||||
|
@ -21,7 +22,6 @@ mtr
|
||||||
neovim
|
neovim
|
||||||
nftables
|
nftables
|
||||||
nginx
|
nginx
|
||||||
nginx-mod-stream
|
|
||||||
nmap
|
nmap
|
||||||
openssh
|
openssh
|
||||||
pacman-contrib
|
pacman-contrib
|
||||||
|
|
|
@ -3,6 +3,7 @@ certbot
|
||||||
chrony
|
chrony
|
||||||
cloud-guest-utils
|
cloud-guest-utils
|
||||||
conntrack-tools
|
conntrack-tools
|
||||||
|
dnsdist
|
||||||
fish
|
fish
|
||||||
geoip
|
geoip
|
||||||
geoipupdate
|
geoipupdate
|
||||||
|
@ -20,7 +21,6 @@ mtr
|
||||||
neovim
|
neovim
|
||||||
nftables
|
nftables
|
||||||
nginx
|
nginx
|
||||||
nginx-mod-stream
|
|
||||||
nmap
|
nmap
|
||||||
openssh
|
openssh
|
||||||
pacman-contrib
|
pacman-contrib
|
||||||
|
|
|
@ -3,6 +3,7 @@ bird
|
||||||
chrony
|
chrony
|
||||||
cloud-guest-utils
|
cloud-guest-utils
|
||||||
conntrack-tools
|
conntrack-tools
|
||||||
|
dnsdist
|
||||||
fish
|
fish
|
||||||
geoip
|
geoip
|
||||||
geoipupdate
|
geoipupdate
|
||||||
|
@ -20,7 +21,6 @@ mtr
|
||||||
neovim
|
neovim
|
||||||
nftables
|
nftables
|
||||||
nginx
|
nginx
|
||||||
nginx-mod-stream
|
|
||||||
nmap
|
nmap
|
||||||
openssh
|
openssh
|
||||||
pacman-contrib
|
pacman-contrib
|
||||||
|
|
|
@ -2,6 +2,7 @@ base
|
||||||
chrony
|
chrony
|
||||||
cloud-guest-utils
|
cloud-guest-utils
|
||||||
conntrack-tools
|
conntrack-tools
|
||||||
|
dnsdist
|
||||||
fish
|
fish
|
||||||
geoip
|
geoip
|
||||||
geoipupdate
|
geoipupdate
|
||||||
|
@ -19,7 +20,6 @@ mtr
|
||||||
neovim
|
neovim
|
||||||
nftables
|
nftables
|
||||||
nginx
|
nginx
|
||||||
nginx-mod-stream
|
|
||||||
nmap
|
nmap
|
||||||
openssh
|
openssh
|
||||||
pacman-contrib
|
pacman-contrib
|
||||||
|
|
|
@ -3,6 +3,7 @@ bird
|
||||||
chrony
|
chrony
|
||||||
cloud-guest-utils
|
cloud-guest-utils
|
||||||
conntrack-tools
|
conntrack-tools
|
||||||
|
dnsdist
|
||||||
fish
|
fish
|
||||||
geoip
|
geoip
|
||||||
geoipupdate
|
geoipupdate
|
||||||
|
@ -20,7 +21,6 @@ mtr
|
||||||
neovim
|
neovim
|
||||||
nftables
|
nftables
|
||||||
nginx
|
nginx
|
||||||
nginx-mod-stream
|
|
||||||
nmap
|
nmap
|
||||||
openssh
|
openssh
|
||||||
pacman-contrib
|
pacman-contrib
|
||||||
|
|
|
@ -2,6 +2,7 @@ base
|
||||||
chrony
|
chrony
|
||||||
cloud-guest-utils
|
cloud-guest-utils
|
||||||
conntrack-tools
|
conntrack-tools
|
||||||
|
dnsdist
|
||||||
fish
|
fish
|
||||||
geoip
|
geoip
|
||||||
geoipupdate
|
geoipupdate
|
||||||
|
@ -19,7 +20,6 @@ mtr
|
||||||
neovim
|
neovim
|
||||||
nftables
|
nftables
|
||||||
nginx
|
nginx
|
||||||
nginx-mod-stream
|
|
||||||
nmap
|
nmap
|
||||||
openssh
|
openssh
|
||||||
pacman-contrib
|
pacman-contrib
|
||||||
|
|
|
@ -3,6 +3,7 @@ bird
|
||||||
chrony
|
chrony
|
||||||
cloud-guest-utils
|
cloud-guest-utils
|
||||||
conntrack-tools
|
conntrack-tools
|
||||||
|
dnsdist
|
||||||
fish
|
fish
|
||||||
geoip
|
geoip
|
||||||
geoipupdate
|
geoipupdate
|
||||||
|
@ -20,7 +21,6 @@ mtr
|
||||||
neovim
|
neovim
|
||||||
nftables
|
nftables
|
||||||
nginx
|
nginx
|
||||||
nginx-mod-stream
|
|
||||||
nmap
|
nmap
|
||||||
openssh
|
openssh
|
||||||
pacman-contrib
|
pacman-contrib
|
||||||
|
|
|
@ -4,6 +4,7 @@ certbot
|
||||||
chrony
|
chrony
|
||||||
cloud-guest-utils
|
cloud-guest-utils
|
||||||
conntrack-tools
|
conntrack-tools
|
||||||
|
dnsdist
|
||||||
fish
|
fish
|
||||||
geoip
|
geoip
|
||||||
geoipupdate
|
geoipupdate
|
||||||
|
@ -21,7 +22,6 @@ mtr
|
||||||
neovim
|
neovim
|
||||||
nftables
|
nftables
|
||||||
nginx
|
nginx
|
||||||
nginx-mod-stream
|
|
||||||
nmap
|
nmap
|
||||||
openssh
|
openssh
|
||||||
pacman-contrib
|
pacman-contrib
|
||||||
|
|
Loading…
Add table
Add a link
Reference in a new issue