Daniel Micay
|
58e107dd97
|
move zerotier-one to port 999
|
2025-07-23 00:26:41 -04:00 |
|
Daniel Micay
|
a948b7c244
|
move dnsdist control socket to port 55
This avoids unnecessary overlap with our ephemeral port range.
|
2025-07-23 00:26:41 -04:00 |
|
Daniel Micay
|
76b5b554ca
|
nftables: simplify nameserver control socket rules
|
2025-07-23 00:26:41 -04:00 |
|
Daniel Micay
|
7153fcbc8a
|
scale synproxy threshold based on conntrack max
|
2025-07-23 00:26:41 -04:00 |
|
Daniel Micay
|
5c41418606
|
nftables: add support for dnsdist control socket
|
2025-05-16 13:19:38 -04:00 |
|
Daniel Micay
|
e75172d57c
|
replace nginx with dnsdist for DNS-over-TLS
|
2025-05-13 21:42:53 -04:00 |
|
Daniel Micay
|
a6d1e00d07
|
drop SSH connections to new anycast IPs
|
2025-05-05 17:29:56 -04:00 |
|
Daniel Micay
|
029882f051
|
set up certificate replication for ns1 replicas
|
2025-05-05 17:29:54 -04:00 |
|
Daniel Micay
|
2784008a65
|
nftables: add support for rage4 anycast for ns1
|
2025-05-03 18:13:20 -04:00 |
|
Daniel Micay
|
9556ca4b79
|
use 4.releases.grapheneos.org as primary instance
|
2025-04-25 00:47:28 -04:00 |
|
Daniel Micay
|
1f4d7316b8
|
reorganize configurations into etc directory
|
2025-04-15 12:53:49 -04:00 |
|