nomad
created pr with
8.1
cmds
checkout latest patchset:
ssh pr.in0rdr.ch print 8 | git am -3checkout any patchset in a patch request:
ssh pr.in0rdr.ch print 8.[rev] | git am -3add changes to patch request:
git format-patch main --stdout | ssh pr.in0rdr.ch pr add 8
Patchset
8.1
feat(git): anubis sidecar
Andreas Gruhler
feat: RemoteIPProxyProtocol
2026-03-27Andreas Gruhler
fix: add podman net to trusted proxies
2026-03-30Andreas Gruhler
fix: ServerName in vHost
2026-03-31Andreas Gruhler
→ feat: change RemoteIPInternalProxy
2026-04-01Andreas Gruhler
feat: change RemoteIPInternalProxy
2026-04-01Andreas Gruhler
2026-04-01
feat: change RemoteIPInternalProxy
Andreas Gruhler
2026-04-01Semantic diff summary
0 added,
0 modified,
0 signature changed,
0 removed
across 0 analyzed files
(1 file skipped: unsupported file type)
+8
-9
hcl/default/git/templates/stagit.conf.tmpl
#
| ... | ... | @@ -10,17 +10,10 @@ LogFormat "%{X-Forwarded-For}i %h %l %u %t \"%r\" %>s %b" common | |
| 10 | 10 | SSLCertificateFile "/etc/letsencrypt/live/code.in0rdr.ch/fullchain.pem" | |
| 11 | 11 | SSLCertificateKeyFile "/etc/letsencrypt/live/code.in0rdr.ch/privkey.pem" | |
| 12 | 12 | ||
| 13 | - | # Haproxy sends real ip (send-proxy) | |
| 13 | + | # HAProxy sends real ip (send-proxy) | |
| 14 | 14 | # https://www.haproxy.com/documentation/haproxy-configuration-manual/latest/#send-proxy | |
| 15 | 15 | # https://httpd.apache.org/docs/2.4/mod/mod_remoteip.html#remoteipproxyprotocol | |
| 16 | 16 | RemoteIPProxyProtocol On | |
| 17 | - | # Haproxy network | |
| 18 | - | RemoteIPInternalProxy 10.0.0.0/24 | |
| 19 | - | RemoteIPInternalProxy 10.0.0.1 | |
| 20 | - | # Podman default bridge network | |
| 21 | - | # https://docs.podman.io/en/stable/markdown/podman-network.1.html | |
| 22 | - | RemoteIPInternalProxy 10.88.0.0/16 | |
| 23 | - | RemoteIPInternalProxy 10.88.0.1 | |
| 24 | 17 | ||
| 25 | 18 | # These headers need to be set or else Anubis will | |
| 26 | 19 | # throw an "admin misconfiguration" error. |
| ... | ... | @@ -40,6 +33,12 @@ LogFormat "%{X-Forwarded-For}i %h %l %u %t \"%r\" %>s %b" common | |
| 40 | 33 | <VirtualHost *:80> | |
| 41 | 34 | DocumentRoot /var/www/localhost/htdocs | |
| 42 | 35 | ||
| 36 | + | # HAProxy and Podman default bridge network | |
| 37 | + | # https://docs.podman.io/en/stable/markdown/podman-network.1.html | |
| 38 | + | RemoteIPHeader X-Real-Ip | |
| 39 | + | RemoteIPInternalProxy 10.0.0.0/8 | |
| 40 | + | RemoteIPTrustedProxy 127.0.0.1/32 | |
| 41 | + | ||
| 43 | 42 | <Directory /var/www/localhost/htdocs> | |
| 44 | 43 | Order allow,deny | |
| 45 | 44 | Allow from all |