PTah
|
e73c86140d
|
chore(docs): GitHub repo URL in README, add mirror URL scripts
Co-authored-by: Cursor <cursoragent@cursor.com>
|
2026-06-16 11:39:19 +10:00 |
|
PTah
|
a7de0d0555
|
feat(security): fail2ban sshd.local с ignoreip admin и banaction ufw.
|
2026-06-15 15:06:53 +10:00 |
|
PTah
|
fc12d35f23
|
chore(security): executable bit на fail2ban-install.sh.
|
2026-06-15 15:03:39 +10:00 |
|
PTah
|
cd14f0a1c4
|
feat(security): fail2ban для HAProxy JSON reject и Zabbix 403.
|
2026-06-15 15:03:30 +10:00 |
|
Andrey Lutsenko
|
027d64f245
|
chore: workspace-bootstrap перенесён в Answer.and.other.shit
guides/init.new.comps — см. scripts/workspace-bootstrap/README.md
|
2026-06-14 19:43:05 +10:00 |
|
Andrey Lutsenko
|
834595df6b
|
feat: workspace-bootstrap — init SSH/git/Cursor для Mac и Windows
Единый workspace.local.env для адресов и паролей, init-machine,
Set-GitRemotes, push-safe и check-no-secrets для политики kalinamall/github.
|
2026-06-14 19:34:52 +10:00 |
|
Andrey Lutsenko
|
8e2a4ac1b9
|
docs(security): периметр 80/443→HAProxy, 25→KSMG; UFW на .117
Переписаны docs/security под текущий этап: SSH/stats из SSH_ALLOWED,
80/443 для всех. Скрипт UFW дополнен правилом 8404.
|
2026-06-13 22:34:57 +10:00 |
|
Andrey Lutsenko
|
e3201ae41b
|
docs: периметр MikroTik — на HAProxy только 80/443
Уточнено: порт 25 с интернета не проброшен; inbound-почта не через HAProxy.
|
2026-06-13 22:24:48 +10:00 |
|
PTah
|
1a690d1d1c
|
chore(security): executable bit на UFW-скриптах.
|
2026-06-13 21:27:59 +10:00 |
|
PTah
|
787671f9ca
|
docs(security): план UFW, hardening HAProxy и бэкендов, скрипты deploy.
|
2026-06-13 21:27:49 +10:00 |
|
PTah
|
779bf0d921
|
feat(haproxy): allowlist rds-allowed для RDS из ipdeny RU (0.7.5).
|
2026-06-13 19:06:54 +10:00 |
|