Traefik: - Enable access logs → /var/log/traefik/access.log (needed for CrowdSec) - Add global security headers middleware: HSTS, X-Frame-Options, CSP, nosniff, XSS filter, referrer policy, permissions policy - Add rate limiting: default 100/s, API 30/s, admin 10/s (strict) - Add Authelia ForwardAuth middleware for SSO integration CrowdSec (new service): - Analyzes Traefik access logs + auth.log in real time - Community IP reputation blocklist (crowdsecurity/traefik + http-cve) - Firewall bouncer: bans malicious IPs at kernel level (iptables) Authelia (new service, auth.csrx.ru): - 2FA/SSO portal with TOTP (Google Authenticator) - Protects: traefik.csrx.ru, sync.csrx.ru, /god-mode/ in Plane - Session: 12h expiry, 30m inactivity, Redis backend - argon2id password hashing Container security: - Add security_opt: no-new-privileges to traefik, vaultwarden, forgejo, grafana, authelia CI/CD security: - Remove hardcoded server IP 87.249.49.32 from workflow - Use SSH_KNOWN_HOSTS secret instead of ssh-keyscan (prevents MITM) - Added SSH_KNOWN_HOSTS secret to Forgejo Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
76 lines
5.9 KiB
YAML
76 lines
5.9 KiB
YAML
$ANSIBLE_VAULT;1.1;AES256
|
|
61316166393964386231353533353731353730326134323862666166373430346531383435396264
|
|
3339363034336365363263643165656264333030323036640a313937396562326539633430643931
|
|
61626330343235646637653065666237626564376130376662366238336135373836613362643963
|
|
6335393437333362390a393930373132366161333762643535373232613136306664346662366231
|
|
33643832306638306130653937323863643237346231363432623462313534386162373866663362
|
|
34313665323632393766626535656239333231396438383833663835623963323530323663323539
|
|
38373639623235396133373632613337353538666666303538333637333537363162323238376366
|
|
65393233366162643835316439613262326531373961646336626232626334643331643438663834
|
|
66386332316561333435313535666161323661663038343464383130663131363130303238626632
|
|
62383934643539623434333566376463653930353833333433633364383764393732633734633636
|
|
37646139656634666666613161396631353164363831353366393365643336376330613565353966
|
|
32363431666534316165366636376164353165333738326230326232386137666366353636633865
|
|
66623264623730653866663030646431386238633662336162623665356536613832346131316230
|
|
34353664373930636361383961646334633838366636343335313438663836623761666235383431
|
|
33373534653930623666323433326636633133336538633166333362353663356264323936623763
|
|
37396338623962626638346538363565316262646232336266393936323839613533666465663439
|
|
63343635346333636539373335323831366630356536336262353534643035323765653366656363
|
|
63393534396135393061653234646362303066386133333736643739373164623034396361363539
|
|
37326532643064656666363735333535643765643433633131356334393434333939623239343761
|
|
32383966646435363936346464616233313865303264333331613437396635373336383664326665
|
|
30366436303264633762336234356431666238353535396234383133353362366465363834643666
|
|
33653732646264343636646266653138313634346239623764656136303462316364656234623833
|
|
35313561323464346435656565633036383264373436313164363262643164616436663564643032
|
|
30646637653036663533663430386134663237333030336430373936323738653030353564313464
|
|
39393562383735313237366433646431356364363039353539366133333237303532653965666364
|
|
35393830336533373133366666653765366562336539646131636633326434393164343530633737
|
|
34626263636163626333373438376137636139643263646336643735316462313361663834613031
|
|
37396233633831393536313838313964343762383363356238393761646230393334303836633735
|
|
65666366393932346636396237333166323936613732333036323333343637393931393534323166
|
|
61626334613035353137303365373365373837616336343838643365616538623538653238363664
|
|
30356539663763633337393162623764376265646435663064303930643364396439626661666532
|
|
38306364356463643866336530303430633766336236616135326462353163343637336438373534
|
|
37616536386131366634633663633566313238366133376131353666663464306463313232626436
|
|
61306236663332373764303566643332343530366362376134653437356630613937346663323131
|
|
65376563666434653132383032643830386465363965653530323036623034313764306136366239
|
|
34666538623232646266666537353033386661333861386564316662386233636265366536386135
|
|
35653735383231616664366338623264326663353730623461613766613432396233383061383464
|
|
35376461323233633938646532373663396233396463323565633539353630653934616231636166
|
|
39633037333963653061386362316662613235646236326666633164336661373963386339633932
|
|
64616436333637373930373062333463336562303439623937643136323735616231303762373161
|
|
62666438613038363833626664316435316331373030343738356438323563313565613039326639
|
|
65386533306132663964386330396566623063633433653439383235373761363037633138376461
|
|
65323465663137363135336662643432616437323466656666313437333366626234623765643033
|
|
30633132636235383561373566366465393664663464643965363634323466303433623361613061
|
|
66623861336537333339636161636564356239636562363166326635646166653933376634626234
|
|
61643738346263646664356134313138373331343731366532383264613931353030313061636135
|
|
30343430383630633966393933396238366463373934653130656433633437323137326666633964
|
|
32626639396165323334393263393961663666623137643834373065383966353835613335636362
|
|
31646635356233323730393039366162613331393465633139616432353462363165333530373364
|
|
32343935643933326136383835633232356263343264373437383630313537343138383135613832
|
|
32383738353435323437336137626231343535633364666663633133353662383139383364373837
|
|
37386133383135326662383661346639393134313931383637613631343836646663663834336632
|
|
64383734373362316666343031393764393161613035373863323839383237643863326664656465
|
|
34306637316466366332666237313064366534323961373166663339333439303365633137386236
|
|
64313338383037613439626462323737393034303732303537636565353033386365653239326131
|
|
32326162663766626264653965323134366664386238393564386163613165383661303832633565
|
|
31306335393439323635653731363931663364613438373130623437376638386364333266643838
|
|
35303436383839653434316632616163623264326531616439643437663538376333366432666165
|
|
38363635653864383662346235353561316233656332383031643938613735396635363436313735
|
|
66396535383030353437626165626432646634613434643830303434643530636566333063323366
|
|
30663738326562343732376662366566636330346435373838363165643666393764343832656638
|
|
65666134616265633138376133386438666465666661323631373539666330616638306439636533
|
|
34346365333462623438333930376133383233373064366336343937616638376163303435313163
|
|
34303537306532396230383236393731663230393135386133316638343735373666306337376235
|
|
34616639326432386266373361306537343637356335613136346261316433613464323263646134
|
|
31326232323738313830353535313363663363393037653631353932613834346133616535666361
|
|
62353539646331656665323763396662313137366261336139356231646663646564646536373433
|
|
62646234393737666635626536656636316535343661626364376536633461383530633135396137
|
|
32343163373265623138333162653231636336373661316530633331346463393365353462336136
|
|
66336236313765616436646532336164363261656262646135653734376331646665353139613037
|
|
65323338316139353837623661353134656164613362313632656163643737353435366432666564
|
|
36303631643331373965616239353762663862636232326234643663383664613666303538316465
|
|
36323232663263653238393066663839653539343536316461333964316132353531333936663461
|
|
37326337653930306637333163343431626663633139303263646639313862313365326665376264
|
|
373039623038653731373939343537376634
|