forked from nico/dots
caddy: add block_non_private_ips snippet
blocks ips not in tailnet or in local network from accessing services using `important block_non_private_ips` in their caddy config
This commit is contained in:
parent
a37e71055f
commit
7537a1e5b6
8 changed files with 18 additions and 0 deletions
|
|
@ -22,6 +22,12 @@
|
|||
|
||||
services.caddy = {
|
||||
enable = true;
|
||||
extraConfig = ''
|
||||
(block_non_private_ips) {
|
||||
@non_private_ips not remote_ip 100.64.0.0/10 fd7a:115c:a1e0::/48 private_ranges
|
||||
abort @non_private_ips
|
||||
}
|
||||
'';
|
||||
};
|
||||
|
||||
security.acme = {
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue