-
Notifications
You must be signed in to change notification settings - Fork 469
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
[RFC] prevent host services from being accessible through service IPs (…
…#618) * prevent host services from being accessible through service IPs - on startup create ipsets and firewall rules - on sync update ipsets - on cleanup remove firewall rules and ipsets Fixes #282. Signed-off-by: Steven Armstrong <[email protected]> * ensure iptables rules are also available during cleanup Signed-off-by: Steven Armstrong <[email protected]> * first check if chain exists Signed-off-by: Steven Armstrong <[email protected]> * err not a new variable Signed-off-by: Steven Armstrong <[email protected]> * more redeclared vars Signed-off-by: Steven Armstrong <[email protected]> * maintain a ipset for local addresses and exclude those from our default deny rule Signed-off-by: Steven Armstrong <[email protected]> * copy/paste errors Signed-off-by: Steven Armstrong <[email protected]>
- Loading branch information
1 parent
4efc6cc
commit 4da8ee7
Showing
1 changed file
with
202 additions
and
22 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters