This commit is contained in:
parent
6e4e0b3d17
commit
7aa17517ed
2 changed files with 37 additions and 0 deletions
12
deploy.yml
12
deploy.yml
|
|
@ -31,3 +31,15 @@
|
||||||
apt:
|
apt:
|
||||||
name: python3-pip
|
name: python3-pip
|
||||||
state: latest
|
state: latest
|
||||||
|
|
||||||
|
|
||||||
|
- name: add docker rules to ufw
|
||||||
|
blockinfile:
|
||||||
|
path: /etc/ufw/after.rules
|
||||||
|
marker_begin: BEGIN UFW AND DOCKER
|
||||||
|
marker_end: END UFW AND DOCKER
|
||||||
|
state: present
|
||||||
|
block: "{{ lookup('ansible.builtin.file', 'ufw-docker.rules') }}"
|
||||||
|
tags:
|
||||||
|
- ufw
|
||||||
|
|
||||||
|
|
|
||||||
25
files/ufw-docker.rules
Normal file
25
files/ufw-docker.rules
Normal file
|
|
@ -0,0 +1,25 @@
|
||||||
|
*filter
|
||||||
|
:ufw-user-forward - [0:0]
|
||||||
|
:ufw-docker-logging-deny - [0:0]
|
||||||
|
:DOCKER-USER - [0:0]
|
||||||
|
-A DOCKER-USER -j ufw-user-forward
|
||||||
|
|
||||||
|
-A DOCKER-USER -j RETURN -s 10.0.0.0/8
|
||||||
|
-A DOCKER-USER -j RETURN -s 172.16.0.0/12
|
||||||
|
-A DOCKER-USER -j RETURN -s 192.168.0.0/16
|
||||||
|
|
||||||
|
-A DOCKER-USER -p udp -m udp --sport 53 --dport 1024:65535 -j RETURN
|
||||||
|
|
||||||
|
-A DOCKER-USER -j ufw-docker-logging-deny -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK SYN -d 192.168.0.0/16
|
||||||
|
-A DOCKER-USER -j ufw-docker-logging-deny -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK SYN -d 10.0.0.0/8
|
||||||
|
-A DOCKER-USER -j ufw-docker-logging-deny -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK SYN -d 172.16.0.0/12
|
||||||
|
-A DOCKER-USER -j ufw-docker-logging-deny -p udp -m udp --dport 0:32767 -d 192.168.0.0/16
|
||||||
|
-A DOCKER-USER -j ufw-docker-logging-deny -p udp -m udp --dport 0:32767 -d 10.0.0.0/8
|
||||||
|
-A DOCKER-USER -j ufw-docker-logging-deny -p udp -m udp --dport 0:32767 -d 172.16.0.0/12
|
||||||
|
|
||||||
|
-A DOCKER-USER -j RETURN
|
||||||
|
|
||||||
|
-A ufw-docker-logging-deny -m limit --limit 3/min --limit-burst 10 -j LOG --log-prefix "[UFW DOCKER BLOCK] "
|
||||||
|
-A ufw-docker-logging-deny -j DROP
|
||||||
|
|
||||||
|
COMMIT
|
||||||
Loading…
Add table
Reference in a new issue