Age | Commit message (Collapse) | Author | |
---|---|---|---|
3 days | enable mimic on ethernet | Xiao Pan | |
3 days | meta | Xiao Pan | |
3 days | remove phantun, add mimic, add distccd-alarm-armv8 | Xiao Pan | |
3 days | remove phantun, because I switched to mimic | Xiao Pan | |
3 days | add distccd port and accept that in nft so pp distcc can connect | Xiao Pan | |
3 days | distccd config change to pp wg ip, and change port | Xiao Pan | |
Change to wg ip because stricter, safer. Also change to a port no one use. | |||
3 days | add default | Xiao Pan | |
9 days | meta | Xiao Pan | |
9 days | add and enable phantun_client service | Xiao Pan | |
9 days | meta | Xiao Pan | |
9 days | swgp go through phantun, more see vc notes | Xiao Pan | |
2025-07-15 | comment replace empty line with # to represent those comments are all ↵ | Xiao Pan | |
related to next several lines of code | |||
2025-07-15 | sshd allow from localhost | Xiao Pan | |
2025-07-15 | sshd config add comment about AllowUsers CIDR ip should be consistent | Xiao Pan | |
2025-07-15 | sshd config restrict only from wg ip to insp gitolite user | Xiao Pan | |
2025-07-14 | monero@.service more comment | Xiao Pan | |
2025-07-14 | nft only allow monerod-p2p port to wg_* network interfaces | Xiao Pan | |
Note I think this will not prevent monerod download things from public internet without wireguard tunnel. But a little more limit is still better, maybe upload will limit a little bit to wg_* network interfaces. | |||
2025-07-14 | monerod@.service add more notes about using ↵ | Xiao Pan | |
sys-subsystem-net-devices-wg_ba.device | |||
2025-07-14 | meta | Xiao Pan | |
2025-07-14 | run monerod only when all network thru wireguard | Xiao Pan | |
wg_ba network interface tunnels all network through wireguard to ba. I would like to only run monerod when this happened due to various reasons see comments in monerod@.service. Some measures I take are: systemd unit bind to wg_ba, networkmanager dispatcher stop monerod service pre wg_ba down, and vpn script kill monerod process before wg_ba down. The former two measures are in this commit. For bitmonero.conf, I also limit upload rate, reason see comment. I also enabled ipv6. I also try bind ip, which seems does not work, but I put there anyway. | |||
2025-07-11 | remove ssh-isp port | Xiao Pan | |
2025-07-10 | nft allow ssh from wg_* iifname, because I will let cfgs to push | Xiao Pan | |
2025-07-10 | meta | Xiao Pan | |
2025-07-10 | I move studio website to ca so I will remove studio so ssh port config for ↵ | Xiao Pan | |
studio is not needed any more | |||
2025-07-10 | add sshd config because I will enable sshd | Xiao Pan | |
2025-07-08 | sudoers pacdiff | Xiao Pan | |
related upstream PR and commit: https://github.com/sudo-project/sudo/pull/427 https://github.com/sudo-project/sudo/commit/7c121ff8340c6fa551ba4997dde9d450cf74e40c | |||
2025-07-03 | change timezone because I moved | Xiao Pan | |
2025-06-22 | pacdiff | Xiao Pan | |
2025-04-02 | pacdiff | Xiao Pan | |
2025-03-30 | meta | Xiao Pan | |
2025-03-30 | merge two swgp config into one | Xiao Pan | |
2025-03-29 | meta | Xiao Pan | |
2025-03-29 | aa swgp wg to ib instead of ca | Xiao Pan | |
2025-03-04 | pacdiff | Xiao Pan | |
2025-01-08 | add french locale, maybe useful | Xiao Pan | |
2025-01-08 | remove searxng | Xiao Pan | |
2025-01-08 | meta | Xiao Pan | |
2025-01-08 | remove searxng, because it always break | Xiao Pan | |
2025-01-03 | qg for qemu guix no need any more | Xiao Pan | |
2024-12-28 | meta | Xiao Pan | |
2024-12-28 | move to secret cfgs, because secret ip | Xiao Pan | |
2024-12-26 | meta | Xiao Pan | |
2024-12-12 | pacdiff | Xiao Pan | |
2024-11-18 | pacdiff | Xiao Pan | |
2024-11-08 | meta | Xiao Pan | |
2024-11-06 | pacdiff | Xiao Pan | |
2024-10-28 | pacdiff | Xiao Pan | |
2024-09-17 | pacman v7 need move repo so alpm user can read | Xiao Pan | |
2024-09-14 | forget to change opt-level to 3 | Xiao Pan | |
2024-09-14 | pacdiff | Xiao Pan | |