diff --git a/Dockerfile b/Dockerfile index 8223bef..7b00256 100644 --- a/Dockerfile +++ b/Dockerfile @@ -31,6 +31,8 @@ COPY haproxy_manager.py /haproxy/ COPY scripts /haproxy/scripts COPY trusted_ips.list /etc/haproxy/trusted_ips.list COPY trusted_ips.map /etc/haproxy/trusted_ips.map +COPY cloudflare_ips.list /etc/haproxy/cloudflare_ips.list +COPY trusted_proxies.list /etc/haproxy/trusted_proxies.list # /etc/haproxy is a named volume in deployed containers, so baked-in files # under that path get shadowed by the volume on existing deployments. # Place errorfiles outside the volumed path; the HAProxy config references diff --git a/cloudflare_ips.list b/cloudflare_ips.list new file mode 100644 index 0000000..b3f9b17 --- /dev/null +++ b/cloudflare_ips.list @@ -0,0 +1,34 @@ +# Cloudflare edge ranges — peers allowed to set CF-Connecting-IP / X-Real-IP / +# X-Forwarded-For. Referenced by templates/hap_listener.tpl: +# acl from_trusted_proxy src -f /etc/haproxy/cloudflare_ips.list -f /etc/haproxy/trusted_proxies.list +# +# PUBLIC DATA — safe to commit. Source: https://www.cloudflare.com/ips-v4 +# and https://www.cloudflare.com/ips-v6. Keep in sync with the IPv4 snapshot in +# WHP's ssl_renewal_orchestrator.php::isCloudflareIP() (that one is IPv4-only). +# Refresh at release time; Cloudflare has not added a range since 2021. +# +# IPv4 +173.245.48.0/20 +103.21.244.0/22 +103.22.200.0/22 +103.31.4.0/22 +141.101.64.0/18 +108.162.192.0/18 +190.93.240.0/20 +188.114.96.0/20 +197.234.240.0/22 +198.41.128.0/17 +162.158.0.0/15 +104.16.0.0/13 +104.24.0.0/14 +172.64.0.0/13 +131.0.72.0/22 +# +# IPv6 +2400:cb00::/32 +2606:4700::/32 +2803:f800::/32 +2405:b500::/32 +2405:8100::/32 +2a06:98c0::/29 +2c0f:f248::/32 diff --git a/scripts/start-up.sh b/scripts/start-up.sh index 1e782e2..fc648c9 100755 --- a/scripts/start-up.sh +++ b/scripts/start-up.sh @@ -21,6 +21,8 @@ set -eo pipefail mkdir -p /etc/haproxy [ -f /etc/haproxy/trusted_ips.list ] || : > /etc/haproxy/trusted_ips.list [ -f /etc/haproxy/trusted_ips.map ] || : > /etc/haproxy/trusted_ips.map +[ -f /etc/haproxy/cloudflare_ips.list ] || : > /etc/haproxy/cloudflare_ips.list +[ -f /etc/haproxy/trusted_proxies.list ] || : > /etc/haproxy/trusted_proxies.list cron & diff --git a/trusted_proxies.list b/trusted_proxies.list new file mode 100644 index 0000000..444a0e7 --- /dev/null +++ b/trusted_proxies.list @@ -0,0 +1,13 @@ +# Additional trusted reverse proxies — peers permitted to set CF-Connecting-IP, +# X-Real-IP and X-Forwarded-For. Anything NOT matched here or in +# cloudflare_ips.list has those headers stripped before real-IP resolution. +# +# Referenced by templates/hap_listener.tpl. +# +# Leave EMPTY unless a real proxy sits in front of HAProxy on this host. Adding +# a range here lets that peer assert any client identity, which bypasses rate +# limits, IP blocks and the WAF for it. +# +# Do NOT commit real IPs — this repo is mirrored publicly. Add entries directly +# on the server; the file lives in the /etc/haproxy named volume and persists +# across container recreates.