mirror of
https://github.com/RWejlgaard/pez-infra.git
synced 2026-05-06 04:14:43 +00:00
The rules.v4.j2 template deployed a ruleset with INPUT ACCEPT and zero custom rules — effectively a no-op. nuremberg-a is a public-facing mail server and needs actual filtering. Changes: - INPUT default policy set to DROP - Allow loopback, established/related, Tailscale interface, SSH, ICMP - FORWARD stays ACCEPT for Docker port-forwarding - Added firewall_alpine_extra_input_rules variable for host-specific rules Mail ports remain handled by Docker's FORWARD chain, not INPUT. Closes PESO-119 |
||
|---|---|---|
| .. | ||
| backup/tasks | ||
| caddy | ||
| common | ||
| docker/tasks | ||
| docker_services/tasks | ||
| dotfiles/tasks | ||
| firewall_alpine | ||
| media_stack | ||
| node_exporter | ||
| status_page | ||
| systemd_services | ||
| zfs | ||