# vim: set syntax=yaml: variant: fcos version: 1.7.0 ignition: security: tls: certificate_authorities: - inline: | -----BEGIN CERTIFICATE----- MIIE6DCCA9CgAwIBAgIJANu+mC2Jt3uTMA0GCSqGSIb3DQEBCwUAMIGhMQswCQYD VQQGEwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTERMA8GA1UEBxMIU2FuIEpvc2Ux FTATBgNVBAoTDFpzY2FsZXIgSW5jLjEVMBMGA1UECxMMWnNjYWxlciBJbmMuMRgw FgYDVQQDEw9ac2NhbGVyIFJvb3QgQ0ExIjAgBgkqhkiG9w0BCQEWE3N1cHBvcnRA enNjYWxlci5jb20wIBcNMjUwMjAyMTYzODIwWhgPMjA1MjA2MjAxNjM4MjBaMIGh MQswCQYDVQQGEwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTERMA8GA1UEBxMIU2Fu IEpvc2UxFTATBgNVBAoTDFpzY2FsZXIgSW5jLjEVMBMGA1UECxMMWnNjYWxlciBJ bmMuMRgwFgYDVQQDEw9ac2NhbGVyIFJvb3QgQ0ExIjAgBgkqhkiG9w0BCQEWE3N1 cHBvcnRAenNjYWxlci5jb20wggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIB AQCpPtJNLFlFOAQUV/p2gdqNJzW+TmObOYzoFa46jTjgSxpNz15URX8eMf/UNbNm 1yt9OP6eLbTlqkxOUoFbdRhH6XIsdD0WhmINdhcrymgpJXn5ObRWWz/kpvyaSFVW q/suBgSa8Rjsc9j6LWcQZkJrjplcI6iEnSYES0H0lWWkMg76c3SFQwBhh1nUplYI w1/kn9pNmJKGyis3YDfyJI6F136ZxEziI0veCwu731eEqdGoqgd4fzeVV1+7VcF6 hDPPlXqADeRtG+EPCgiVMF4xrmXjJF0kB92mRsXOqLBKA12FvFMedhiisPMp+vas QUx2wxTQMd14Bl/vXX7UK6e5AgMBAAGjggEdMIIBGTAdBgNVHQ4EFgQUubfdSs3D DgyGnV3f7BwEacVOmN8wDwYDVR0TAQH/BAUwAwEB/zCB1gYDVR0jBIHOMIHLgBS5 t91KzcMODIadXd/sHARpxU6Y36GBp6SBpDCBoTELMAkGA1UEBhMCVVMxEzARBgNV BAgTCkNhbGlmb3JuaWExETAPBgNVBAcTCFNhbiBKb3NlMRUwEwYDVQQKEwxac2Nh bGVyIEluYy4xFTATBgNVBAsTDFpzY2FsZXIgSW5jLjEYMBYGA1UEAxMPWnNjYWxl ciBSb290IENBMSIwIAYJKoZIhvcNAQkBFhNzdXBwb3J0QHpzY2FsZXIuY29tggkA 276YLYm3e5MwDgYDVR0PAQH/BAQDAgGGMA0GCSqGSIb3DQEBCwUAA4IBAQBZ257u 6xcDnfq33Dhdi0h/g+5kz5wto+0w1U/y2V3bAfwOzvSiKfrOGEssYNVdv17qSOUC jFs/kvCmZnS2ZAr/iAxeD8qkC6Zb5552LRCiV4XHBaeN6Cd+YTJMgVKmBxFrsxlE PmauxO1aIwTf3eQmD+n5Yn7MkKClIedkfrwHq4s3ZvyvyplAwjSwyesmEz/5Gdk9 XdhsfrIlWq8DyJijNGysBOceYOB6jmCijtwFG02ubAfiIMZ/BRC8+O7wjzDgRALz OC2+mQytSkKo8K6MskfEdjQGZctKaPISG344PQY/y4zKBf1JNpSfsTBzaI9lj7PK m7q2TzMp8s5DuGbK -----END CERTIFICATE----- systemd: units: - name: podman-auto-update.timer enabled: true storage: directories: - path: /etc/bind mode: 0755 - path: /var/cache/bind mode: 0755 user: id: 53 group: id: 53 - path: /etc/nginx mode: 0755 files: - path: /etc/hostname mode: 0644 contents: inline: | caching.internal - path: /etc/zincati/config.d/50-update-strategy.toml mode: 0644 contents: inline: | [updates] strategy = "periodic" [[updates.periodic.window]] days = [ "Sat", "Sun" ] start_time = "07:00" length_minutes = 60 - path: /etc/pki/ca-trust/source/anchors/ZscalerRootCertificate-2048-SHA256-Feb2025.crt mode: 0644 contents: inline: | -----BEGIN CERTIFICATE----- MIIE6DCCA9CgAwIBAgIJANu+mC2Jt3uTMA0GCSqGSIb3DQEBCwUAMIGhMQswCQYD VQQGEwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTERMA8GA1UEBxMIU2FuIEpvc2Ux FTATBgNVBAoTDFpzY2FsZXIgSW5jLjEVMBMGA1UECxMMWnNjYWxlciBJbmMuMRgw FgYDVQQDEw9ac2NhbGVyIFJvb3QgQ0ExIjAgBgkqhkiG9w0BCQEWE3N1cHBvcnRA enNjYWxlci5jb20wIBcNMjUwMjAyMTYzODIwWhgPMjA1MjA2MjAxNjM4MjBaMIGh MQswCQYDVQQGEwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTERMA8GA1UEBxMIU2Fu IEpvc2UxFTATBgNVBAoTDFpzY2FsZXIgSW5jLjEVMBMGA1UECxMMWnNjYWxlciBJ bmMuMRgwFgYDVQQDEw9ac2NhbGVyIFJvb3QgQ0ExIjAgBgkqhkiG9w0BCQEWE3N1 cHBvcnRAenNjYWxlci5jb20wggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIB AQCpPtJNLFlFOAQUV/p2gdqNJzW+TmObOYzoFa46jTjgSxpNz15URX8eMf/UNbNm 1yt9OP6eLbTlqkxOUoFbdRhH6XIsdD0WhmINdhcrymgpJXn5ObRWWz/kpvyaSFVW q/suBgSa8Rjsc9j6LWcQZkJrjplcI6iEnSYES0H0lWWkMg76c3SFQwBhh1nUplYI w1/kn9pNmJKGyis3YDfyJI6F136ZxEziI0veCwu731eEqdGoqgd4fzeVV1+7VcF6 hDPPlXqADeRtG+EPCgiVMF4xrmXjJF0kB92mRsXOqLBKA12FvFMedhiisPMp+vas QUx2wxTQMd14Bl/vXX7UK6e5AgMBAAGjggEdMIIBGTAdBgNVHQ4EFgQUubfdSs3D DgyGnV3f7BwEacVOmN8wDwYDVR0TAQH/BAUwAwEB/zCB1gYDVR0jBIHOMIHLgBS5 t91KzcMODIadXd/sHARpxU6Y36GBp6SBpDCBoTELMAkGA1UEBhMCVVMxEzARBgNV BAgTCkNhbGlmb3JuaWExETAPBgNVBAcTCFNhbiBKb3NlMRUwEwYDVQQKEwxac2Nh bGVyIEluYy4xFTATBgNVBAsTDFpzY2FsZXIgSW5jLjEYMBYGA1UEAxMPWnNjYWxl ciBSb290IENBMSIwIAYJKoZIhvcNAQkBFhNzdXBwb3J0QHpzY2FsZXIuY29tggkA 276YLYm3e5MwDgYDVR0PAQH/BAQDAgGGMA0GCSqGSIb3DQEBCwUAA4IBAQBZ257u 6xcDnfq33Dhdi0h/g+5kz5wto+0w1U/y2V3bAfwOzvSiKfrOGEssYNVdv17qSOUC jFs/kvCmZnS2ZAr/iAxeD8qkC6Zb5552LRCiV4XHBaeN6Cd+YTJMgVKmBxFrsxlE PmauxO1aIwTf3eQmD+n5Yn7MkKClIedkfrwHq4s3ZvyvyplAwjSwyesmEz/5Gdk9 XdhsfrIlWq8DyJijNGysBOceYOB6jmCijtwFG02ubAfiIMZ/BRC8+O7wjzDgRALz OC2+mQytSkKo8K6MskfEdjQGZctKaPISG344PQY/y4zKBf1JNpSfsTBzaI9lj7PK m7q2TzMp8s5DuGbK -----END CERTIFICATE----- - path: /etc/systemd/resolved.conf.d/disable-stub.conf mode: 0644 contents: inline: | [Resolve] DNSStubListener=no - path: /etc/sysctl.d/90-nginx-tuning.conf mode: 0644 contents: inline: | # Network Stack net.ipv4.tcp_fin_timeout = 15 net.ipv4.ip_local_port_range = 1024 65535 net.core.somaxconn = 4096 net.ipv4.tcp_tw_reuse = 1 net.ipv4.tcp_max_syn_backlog = 8192 net.core.netdev_max_backlog = 10000 # Memory & I/O fs.file-max = 2097152 vm.dirty_ratio = 10 vm.dirty_background_ratio = 5 vm.swappiness = 10 - path: /etc/nginx/nginx.conf mode: 0644 contents: inline: | user nginx; worker_processes auto; worker_rlimit_nofile 200000; error_log /dev/stderr warn; pid /var/run/nginx.pid; thread_pool default threads=32 max_queue=65536; include /etc/nginx/modules/*.conf; events { worker_connections 20000; use epoll; multi_accept on; } stream { # Set resolvers against DNS servers not used for local interception. You may wish to change these to your ISP's DNS servers. resolver 8.8.8.8 8.8.4.4 valid=300s ipv6=off; # Log format for stream log_format stream 'HTTPS [$time_local] $remote_addr $protocol $ssl_preread_server_name:$server_port $status'; access_log /dev/stdout stream buffer=32k flush=1s; server { # Pass through SSL connections upstream using SNI preread listen 443; proxy_buffer_size 16k; ssl_preread on; proxy_pass "${ssl_preread_server_name}:443"; # Restrict each client to a set bandwidth - Eg. 1m = 10mbps #proxy_download_rate 1m; #proxy_upload_rate 1m; # Allow only internal networks in case of accidental internet exposure. allow 10.0.0.0/8; allow 172.16.0.0/12; allow 192.168.0.0/16; deny all; } } http { include /etc/nginx/mime.types; default_type application/octet-stream; # Logging format #log_format main 'HTTP [$time_local] $remote_addr $request_method $host$request_uri $status ' # '"$http_user_agent" "$upstream_cache_status"'; #log_format main_ext '$remote_addr - $remote_user [$time_local] "$request" ' # '$status $body_bytes_sent "$http_referer" ' # '"$http_user_agent" "$http_x_forwarded_for" ' # '"$host" sn="$server_name" ' # 'rt=$request_time ' # 'ua="$upstream_addr" us="$upstream_status" ' # 'ut="$upstream_response_time" ul="$upstream_response_length" ' # 'cs=$upstream_cache_status' ; # Do not log slices map $status $log_206 { ~^206$ 0; default 1; } log_format cache_status_plus '$remote_addr: $host $upstream_cache_status ' '$request $status $body_bytes_sent ' 'rt=$request_time urt=$upstream_response_time'; access_log /dev/stdout cache_status_plus if=$log_206 buffer=32k flush=1s; # Set resolvers against DNS servers not used for local interception. You may wish to change these to your ISP's DNS servers. resolver 8.8.8.8 8.8.4.4 valid=300s ipv6=off; # Global cache paths and variables proxy_cache_path /var/cache/nginx/cache levels=1:2 keys_zone=cache:40m max_size=80g inactive=14d use_temp_path=off; # Performance tweaks sendfile on; sendfile_max_chunk 512k; tcp_nopush on; tcp_nodelay on; # Thread pooling aio threads; # Set to 'on' for HDD, 'threads' for SSD. directio 512; # Set to '4m' for HDD, '512' for SSD # Align the buffer for disk sectors (usually 512 or 4k) directio_alignment 4k; # Set to '4k' for XFS, otherwise '512' keepalive_timeout 60; keepalive_requests 1000; client_max_body_size 20G; client_body_buffer_size 16M; server_names_hash_max_size 1024; # Allow only internal networks in case of accidental internet exposure. allow 10.0.0.0/8; allow 172.16.0.0/12; allow 192.168.0.0/16; deny all; # User agent mappings to no cache rules map $http_user_agent $no_cache { # Don't cache downloads by Apple caching servers ~(swupd_syncd) 1; # Set default to cache default 0; } # Health check server { location /health { access_log off; return 200 'health\n'; add_header Content-Type text/plain; } } # Default Caching server { listen 80 backlog=4095; server_name officecdn.microsoft.com.edgesuite.net dl.google.com ardownload.adobe.com ccmdl.adobe.com agsupdate.adobe.com; proxy_ignore_headers X-Accel-Expires Expires Cache-Control Set-Cookie Vary; ignore_invalid_headers off; location / { # Slice configuration slice 16M; proxy_cache cache; proxy_cache_key "$request_method|$host$uri|$slice_range"; proxy_set_header Range $slice_range; # Prevent "Cache Stampede" proxy_cache_lock on; proxy_cache_lock_timeout 600s; proxy_cache_use_stale error timeout updating http_500 http_502 http_503 http_504; # Upstream settings proxy_http_version 1.1; proxy_set_header Connection ""; # Enable keepalive to upstream proxy_set_header Host $host; proxy_pass http://${host}; # Caching logic proxy_cache_valid 200 206 30d; proxy_hide_header ETag; # ETags can sometimes break slice matching # Better buffer tuning for 16M slices proxy_buffers 20 1M; proxy_buffer_size 1M; proxy_busy_buffers_size 2M; proxy_no_cache $no_cache; proxy_cache_methods GET; proxy_cache_lock_age 600s; proxy_pass_request_headers on; proxy_set_header Upgrade-Insecure-Requests ""; # Troubleshooting Headers add_header X-Cache-Status $upstream_cache_status always; add_header X-Cache-Slice $slice_range always; add_header X-Upstream-Addr $upstream_addr always; add_header X-Debug-Host $host always; } } # Aggressive Caching server { listen 80; server_name tlu.dl.delivery.mp.microsoft.com *.tlu.dl.delivery.mp.microsoft.com download.windowsupdate.com *.download.windowsupdate.com *.gvt1.com; proxy_ignore_headers X-Accel-Expires Expires Cache-Control Set-Cookie Vary; ignore_invalid_headers off; location / { # Slice configuration slice 16M; proxy_cache cache; proxy_cache_key "$request_method|$uri|$slice_range"; proxy_set_header Range $slice_range; # Prevent "Cache Stampede" proxy_cache_lock on; proxy_cache_lock_timeout 600s; proxy_cache_lock_age 600s; proxy_cache_use_stale error timeout updating http_500 http_502 http_503 http_504; # Upstream settings proxy_http_version 1.1; proxy_set_header Connection ""; proxy_set_header Host $host; proxy_pass http://${host}; # Caching logic proxy_cache_valid 200 206 30d; proxy_hide_header ETag; # ETags can sometimes break slice matching # Better buffer tuning for 16M slices proxy_buffers 20 1M; proxy_buffer_size 1M; proxy_busy_buffers_size 2M; proxy_no_cache $no_cache; proxy_cache_methods GET; proxy_pass_request_headers on; proxy_set_header Upgrade-Insecure-Requests ""; # Troubleshooting Headers add_header X-Cache-Status $upstream_cache_status always; add_header X-Cache-Slice $slice_range always; add_header X-Upstream-Addr $upstream_addr always; add_header X-Debug-Host $host always; } } # No Caching server { listen 80 default_server; server_name redirector.gvt1.com wsus.ds.download.windowsupdate.com; location /health { access_log off; return 200 'health\n'; add_header Content-Type text/plain; } location / { proxy_http_version 1.1; proxy_pass http://${host}; proxy_pass_request_headers on; proxy_set_header Host $host; } } # Office CDN Redirect server { listen 80; server_name officecdn.microsoft.com; return 301 http://officecdn.microsoft.com.edgesuite.net$request_uri; } } - path: /etc/containers/systemd/nginx/nginx_cache.volume mode: 0644 contents: inline: | [Unit] Description=NGINX Cache Volume [Volume] - path: /etc/containers/systemd/nginx/nginx.container mode: 0644 contents: inline: | [Unit] Description=NGINX Cache Server [Container] Image=docker.io/library/nginx:latest ContainerName=nginx PublishPort=80:80 PublishPort=443:443 Volume=/etc/nginx/nginx.conf:/etc/nginx/nginx.conf:ro,Z Volume=nginx_cache.volume:/var/cache/nginx/cache:Z HealthCmd=curl -f http://localhost/health || exit 1 HealthStartPeriod=5s HealthInterval=30s HealthRetries=3 HealthTimeout=5s Notify=healthy AutoUpdate=registry [Service] Restart=always LimitNOFILE=200000 [Install] WantedBy=multi-user.target - path: /var/cache/bind/rpz.nxdomain.db mode: 0644 user: id: 53 group: id: 53 contents: inline: | ; ; BIND data file for root domain ; $TTL 5m @ IN SOA localhost. admin.localhost. ( 1 ; Serial 4h ; Refresh 15m ; Retry 8h ; Expire 4m ) ; Negative Cache TTL ; @ IN NS cache.lan. mask.icloud.com IN CNAME . mask-h2.icloud.com IN CNAME . - path: /var/cache/bind/rpz.caching.db mode: 0644 user: id: 53 group: id: 53 contents: inline: | ; ; BIND data file for root domain ; $TTL 5m @ IN SOA localhost. admin.localhost. ( 1 ; Serial 4h ; Refresh 15m ; Retry 8h ; Expire 4m ) ; Negative Cache TTL ; @ IN NS cache.lan. ; Google dl.google.com IN A 192.0.2.1 *.gvt1.com IN A 192.0.2.1 ; Microsoft download.windowsupdate.com IN A 192.0.2.1 *.download.windowsupdate.com IN A 192.0.2.1 tlu.dl.delivery.mp.microsoft.com IN A 192.0.2.1 *.tlu.dl.delivery.mp.microsoft.com IN A 192.0.2.1 officecdn.microsoft.com IN A 192.0.2.1 officecdn.microsoft.com.edgesuite.net IN A 192.0.2.1 ; Abobe ardownload.adobe.com IN A 192.0.2.1 ccmdl.adobe.com IN A 192.0.2.1 agsupdate.adobe.com IN A 192.0.2.1 - path: /etc/bind/named.conf mode: 0644 contents: inline: | // // named.conf // // This configuration provides a recursive DNS server for use with // // See /usr/share/doc/bind*/sample/ for example named configuration files. // options { listen-on port 53 { any; }; listen-on-v6 { none; }; directory "/var/cache/bind"; dump-file "data/cache_dump.db"; statistics-file "data/named_stats.txt"; memstatistics-file "data/named_mem_stats.txt"; secroots-file "data/named.secroots"; recursing-file "data/named.recursing"; allow-query { 127.0.0.1; 10.0.0.0/8; 172.16.0.0/12; 192.168.0.0/16; }; /* Set your forward lookup servers here. */ forwarders { 8.8.8.8; 1.1.1.1; }; response-policy { //zone "rpz.nxdomain" policy nxdomain; zone "rpz.caching" log no; }; /* - If you are building an AUTHORITATIVE DNS server, do NOT enable recursion. - If you are building a RECURSIVE (caching) DNS server, you need to enable recursion. - If your recursive DNS server has a public IP address, you MUST enable access control to limit queries to your legitimate users. Failing to do so will cause your server to become part of large scale DNS amplification attacks. Implementing BCP38 within your network would greatly reduce such attack surface */ recursion yes; dnssec-validation auto; session-keyfile "/run/named/session.key"; /* https://fedoraproject.org/wiki/Changes/CryptoPolicy */ //include "/etc/crypto-policies/back-ends/bind.config"; }; logging { channel default_debug { stderr; print-category yes; print-severity yes; severity dynamic; }; }; zone "rpz.caching" { type master; file "rpz.caching.db"; }; // AD Zones /* masters "ad" { # These addresses should be DCs that allow Zone Transfers to this server for the listed zones. 192.0.2.10; 192.0.2.11; }; zone "ad.example.lan" { type slave; file "slaves/forward.ad.example.lan.db"; masters { ad; }; allow-query { any; }; notify no; }; zone "_msdcs.ad.example.lan" { type slave; file "slaves/forward._msdcs.ad.example.lan.db"; masters { ad; }; allow-query { any; }; notify no; }; */ // RPZ Zone for filtering // // This is, by default, a secondary zone to be used with a primary zone hosted on a central DNS server // /* zone "rpz.nxdomain" { type slave; file "slaves/forward.rpz.nxdomain.db"; masters { ad; }; allow-query { any; }; notify no; }; */ - path: /etc/containers/systemd/bind/bind_lib.volume mode: 0644 contents: inline: | [Unit] Description=BIND9 Lib Volume [Volume] - path: /etc/containers/systemd/bind/bind_log.volume mode: 0644 contents: inline: | [Unit] Description=BIND9 Log Volume [Volume] - path: /etc/containers/systemd/bind/bind.container mode: 0644 contents: inline: | [Unit] Description=BIND9 DNS Server [Container] Image=docker.io/internetsystemsconsortium/bind9:9.20 ContainerName=bind PublishPort=53:53/tcp PublishPort=53:53/udp HealthCmd=dig -4 +short @localhost localhost || exit 1 HealthInterval=10s HealthRetries=3 HealthTimeout=5s Notify=healthy Volume=/etc/bind:/etc/bind:Z Volume=/var/cache/bind:/var/cache/bind:Z Volume=bind_lib.volume:/var/lib/bind:Z Volume=bind_log.volume:/var/log:Z AutoUpdate=registry [Service] Restart=always # Uncomment the following line to have the BIND service start on boot. #[Install] #WantedBy=multi-user.target links: - path: /etc/resolv.conf target: /run/systemd/resolve/resolv.conf overwrite: true passwd: users: - name: core groups: - wheel # Default password: CacheAdmin password_hash: $y$j9T$wzjkdSRzaN0VwAloEDHgj.$8LSTMr1jvneVMY4wEPD9Neru474dJiic2IqT/1asZp8 ssh_authorized_keys: - ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIHt5t46RUmxq0X1h+9G1b7vmwrEMgSFQapqOF18P3QYn