Daniel Micay
|
dfa2f48ae1
|
move zerotier-one to port 999
|
2025-06-27 14:11:44 -04:00 |
|
Daniel Micay
|
ac0dc27596
|
move dnsdist control socket to port 55
This avoids unnecessary overlap with our ephemeral port range.
|
2025-06-27 13:39:43 -04:00 |
|
Daniel Micay
|
3b2f6d546c
|
nftables: simplify nameserver control socket rules
|
2025-06-27 13:10:16 -04:00 |
|
Daniel Micay
|
8b87654075
|
scale synproxy threshold based on conntrack max
|
2025-06-22 22:27:48 -04:00 |
|
Daniel Micay
|
5c41418606
|
nftables: add support for dnsdist control socket
|
2025-05-16 13:19:38 -04:00 |
|
Daniel Micay
|
e75172d57c
|
replace nginx with dnsdist for DNS-over-TLS
|
2025-05-13 21:42:53 -04:00 |
|
Daniel Micay
|
a6d1e00d07
|
drop SSH connections to new anycast IPs
|
2025-05-05 17:29:56 -04:00 |
|
Daniel Micay
|
029882f051
|
set up certificate replication for ns1 replicas
|
2025-05-05 17:29:54 -04:00 |
|
Daniel Micay
|
2784008a65
|
nftables: add support for rage4 anycast for ns1
|
2025-05-03 18:13:20 -04:00 |
|
Daniel Micay
|
9556ca4b79
|
use 4.releases.grapheneos.org as primary instance
|
2025-04-25 00:47:28 -04:00 |
|
Daniel Micay
|
1f4d7316b8
|
reorganize configurations into etc directory
|
2025-04-15 12:53:49 -04:00 |
|