-
088eec369f
fix(haproxy): ACL 404 для HAProxy 2.8 и deploy-скрипт
main
PTah
2026-06-20 17:06:09 +10:00
-
ade8e4cafa
fix(haproxy): Autodiscover на :80 и точный fail2ban для Zabbix
PTah
2026-06-20 16:58:09 +10:00
-
900749457f
chore(docs): sync repository URLs for kalinamall mirror
PTah
2026-06-16 11:40:58 +10:00
-
f8617ec1e5
fix(scripts): Push-Mirror ignores untracked files
PTah
2026-06-16 11:40:49 +10:00
-
e73c86140d
chore(docs): GitHub repo URL in README, add mirror URL scripts
PTah
2026-06-16 11:36:52 +10:00
-
a7de0d0555
feat(security): fail2ban sshd.local с ignoreip admin и banaction ufw.
PTah
2026-06-15 15:06:53 +10:00
-
fc12d35f23
chore(security): executable bit на fail2ban-install.sh.
PTah
2026-06-15 15:03:39 +10:00
-
cd14f0a1c4
feat(security): fail2ban для HAProxy JSON reject и Zabbix 403.
PTah
2026-06-15 15:03:30 +10:00
-
2ce71df1f8
feat(haproxy): fe_stats, stats-allowed, sync с prod (0.7.7).
PTah
2026-06-15 14:05:17 +10:00
-
435a519b04
feat(haproxy): JSON tcplog с SNI capture на fe_https_sni (0.7.6).
PTah
2026-06-15 13:39:06 +10:00
-
027d64f245
chore: workspace-bootstrap перенесён в Answer.and.other.shit
Andrey Lutsenko
2026-06-14 19:43:05 +10:00
-
834595df6b
feat: workspace-bootstrap — init SSH/git/Cursor для Mac и Windows
Andrey Lutsenko
2026-06-14 19:34:52 +10:00
-
8e2a4ac1b9
docs(security): периметр 80/443→HAProxy, 25→KSMG; UFW на .117
Andrey Lutsenko
2026-06-13 22:34:57 +10:00
-
e3201ae41b
docs: периметр MikroTik — на HAProxy только 80/443
Andrey Lutsenko
2026-06-13 22:24:48 +10:00
-
a337bbdda1
fix: заменить Mermaid на статический SVG в architecture.md
Andrey Lutsenko
2026-06-13 21:58:21 +10:00
-
8688273971
fix: убрать br из Mermaid — Gitea ломает SVG/XML парсер
Andrey Lutsenko
2026-06-13 21:57:27 +10:00
-
905c762acc
fix: совместимый синтаксис Mermaid в architecture.md
Andrey Lutsenko
2026-06-13 21:56:54 +10:00
-
1a690d1d1c
chore(security): executable bit на UFW-скриптах.
PTah
2026-06-13 21:27:59 +10:00
-
787671f9ca
docs(security): план UFW, hardening HAProxy и бэкендов, скрипты deploy.
PTah
2026-06-13 21:27:49 +10:00
-
f26d52b3b4
docs: три SSH-remote home, kalinamall, github (без origin/HTTPS).
PTah
2026-06-13 19:23:23 +10:00
-
779bf0d921
feat(haproxy): allowlist rds-allowed для RDS из ipdeny RU (0.7.5).
PTah
2026-06-13 19:06:54 +10:00
-
fc448fd589
feat(haproxy): Synology DSM heap и exchange с allowlist syno-allowed (0.7.4).
Andrey Lutsenko
2026-06-13 16:54:06 +10:00
-
e3f968347d
feat(haproxy): HTTP-доступ к Zabbix с allowlist zabbix-allowed (0.7.3).
Andrey Lutsenko
2026-06-13 16:48:54 +10:00
-
e7e653a9e8
docs: политика Gitea как основной, GitHub — резерв без секретов.
Andrey Lutsenko
2026-06-13 16:29:18 +10:00
-
f802a5ac46
HAProxy 0.7.2: sac-api для Seaca, check-ssl на всех HTTPS-бэкендах.
PTah
2026-06-13 12:01:06 +10:00
-
ed77ec1e56
Fix line endings to LF, add .gitattributes
PTah
2026-06-01 12:07:46 +10:00
-
6eb396279f
HAProxy: sac.kalinamall.ru, allowlist git-sac-allowed и 1c-allowed
PTah
2026-06-01 12:00:18 +10:00
-
1314eb8010
README: сократить до заголовка и таблицы, вынести инструкции в docs/
PTah
2026-06-01 11:43:12 +10:00
-
6a75c9b7a2
HAProxy: git.kalinamall.ru → 192.168.160.129, доступ только с 5.100.81.121
PTah
2026-04-27 08:58:46 +10:00
-
18dc084c10
README: after Certbot, wire LE certs to nginx ssl_* and optional HTTP redirect
PTah
2026-04-11 20:16:47 +10:00
-
9af9797cd6
README: step-by-step nginx+Certbot webroot for ACME on Ubuntu
PTah
2026-04-11 20:11:48 +10:00
-
bd39118589
README: fix ubuntu2 internal IP to 192.168.160.60
PTah
2026-04-11 20:09:42 +10:00
-
f4d477344c
README: ACME example for ubuntu1/ubuntu2 via Host on port 80
PTah
2026-04-11 20:09:23 +10:00
-
e739ead995
README: port 80, ACME challenges (HTTP-01/DNS/TLS-ALPN), future HAProxy sketch
PTah
2026-04-11 20:03:41 +10:00
-
81e5819d0e
Remove RDP (3389); clients use RDS over HTTPS only
PTah
2026-04-11 19:58:49 +10:00
-
0e7f9b1dbe
haproxy: tcp-request reject before use_backend (fix parser warning)
PTah
2026-04-11 19:34:47 +10:00
-
642e22f26b
RDS: restore hostname k6a-dc3.b26.kalinamall.ru (keep :4430)
PTah
2026-04-11 19:33:13 +10:00
-
e81eaf091e
RDS: backend 192.168.160.40:4430, hostname b27 (SNI rds still on :443)
PTah
2026-04-11 19:32:34 +10:00
-
7e2ef061b6
Remove SSH (port 22) from HAProxy; drop ssh.lst and port-22 docs
PTah
2026-04-11 19:27:27 +10:00
-
b10e0c0439
Docs: port 22 conflict with sshd, bind alternatives and DNAT
PTah
2026-04-11 19:25:11 +10:00
-
212d564acf
haproxy: use tcp-request content reject after SNI (fix phase-order warning)
PTah
2026-04-11 19:22:37 +10:00
-
743a94afec
README: expand PAT creation steps (GitHub UI) in-repo
PTah
2026-04-11 19:12:49 +10:00
-
6740b2d37f
README: clone on Ubuntu, git pull, SSH/PAT auth
PTah
2026-04-11 19:04:51 +10:00
-
c411a4940b
Document OWA /owa under ext SNI (no extra HAProxy rules)
PTah
2026-04-11 18:33:31 +10:00
-
ea7568a74d
README: install HAProxy 2.8 (Noble) or 3.3+ via PPA on Ubuntu 24.04
PTah
2026-04-11 12:39:02 +10:00
-
bbb1a5e2e2
Add SNI for autodiscover.kalinamall.ru to Exchange backend
PTah
2026-04-11 12:27:03 +10:00
-
bfca1c97f5
Resolve README merge: full kalinamall HAProxy documentation
PTah
2026-04-11 12:15:26 +10:00
-
-
6cd45fbc42
HAProxy: perimeter TCP+SNI for kalinamall.ru (Exchange, RDS, 1C, KSMG, RDP, SSH)
PTah
2026-04-11 12:14:18 +10:00
-
-
e45ff5cd62
Initial commit
PapaTramp
2026-04-11 12:12:14 +10:00