initial commit

This commit is contained in:
2026-08-16 23:16:49 +00:00
commit 2dc83c0626
67 changed files with 1176 additions and 0 deletions
+3
View File
@@ -0,0 +1,3 @@
nft_managed_group: all
dnsmasq_managed_group: all
xray_managed_group: all
+73
View File
@@ -0,0 +1,73 @@
xray_ip_sets:
refilter:
urls:
- https://raw.githubusercontent.com/1andrevich/Re-filter-lists/refs/heads/main/community_ips.lst
- https://raw.githubusercontent.com/1andrevich/Re-filter-lists/refs/heads/main/discord_ips.lst
- https://raw.githubusercontent.com/1andrevich/Re-filter-lists/refs/heads/main/ipsum.lst
cdn:
urls:
- https://raw.githubusercontent.com/123jjck/cdn-ip-ranges/refs/heads/main/all/all_plain_ipv4.txt
telegram:
urls:
- https://raw.githubusercontent.com/fernvenue/telegram-cidr-list/refs/heads/master/CIDRv4.txt
russian_whitelist:
urls:
- https://raw.githubusercontent.com/hxehex/russia-mobile-internet-whitelist/refs/heads/main/cidrwhitelist.txt
- https://raw.githubusercontent.com/ebrasha/cidr-ip-ranges-by-country/refs/heads/master/CIDR/RU-ipv4-Hackers.Zone.txt
cloudflare:
static:
- 1.1.1.1
- 1.0.0.1
google:
urls:
- https://raw.githubusercontent.com/lord-alfred/ipranges/main/google/ipv4.txt
xray_domain_sets:
v2ray:
urls:
- https://raw.githubusercontent.com/v2ray/domain-list-community/refs/heads/master/data/spotify
- https://raw.githubusercontent.com/v2ray/domain-list-community/refs/heads/master/data/microsoft
- https://raw.githubusercontent.com/v2ray/domain-list-community/refs/heads/master/data/openai
torrent:
static:
- bt.t-ru.org
- bt2.t-ru.org
- bt3.t-ru.org
- bt4.t-ru.org
- rutracker.org
- rutracker.net
- tapochek.net
- nnmclub.to
- rutor.info
- bigfangroup.org
vps:
static:
- dev.oyacoi.ru
- vector.oyacoi.ru
terraform:
static:
- terraform.io
- hashicorp.com
xray_static_sets:
- private
xray_lists_global:
cache_dir: /var/lib/xray-lists/cache
output_dir: /var/lib/xray-lists/generated
dnsmasq_output: /var/lib/xray-lists/generated/nftsets.conf
proxy: "socks5h://127.0.0.1:1080"
proxy_user: "{{ lookup('env', 'SOCKS5_USERNAME') }}"
proxy_pass: "{{ lookup('env', 'SOCKS5_PASSWORD') }}"
http_timeout: 20
xray_tproxy_port: 61219
xray_fwmark: "0x00000001"
+5
View File
@@ -0,0 +1,5 @@
ansible_connection: community.proxmox.proxmox_pct_remote
ansible_host: 10.1.0.4
ansible_user: root
ansible_ssh_private_key_file: "~/.ssh/id_ed25519"
ansible_python_interpreter: /usr/bin/python3
+4
View File
@@ -0,0 +1,4 @@
nft_to:
- to: [workuter,oyacoi-odcm]
proto: tcp
port: 5000
+3
View File
@@ -0,0 +1,3 @@
dnsmasq:
- name: asf.oyacoi.ru
ip: 10.10.0.2
+3
View File
@@ -0,0 +1,3 @@
dnsmasq:
- name: bananawrt.oyacoi.ru
ip: 10.10.0.2
+3
View File
@@ -0,0 +1,3 @@
dnsmasq:
- name: bylampa.oyacoi.ru
ip: 10.10.0.2
+4
View File
@@ -0,0 +1,4 @@
nft_from:
- iface: [eth1,eth0.2]
to: camera0
proto: [tcp,udp]
+12
View File
@@ -0,0 +1,12 @@
nft_dst:
- iface: [eth0,eth0.2]
proto: [tcp,udp]
port: [3478,5349]
nft_from:
- iface: [eth0,eth0.2,eth0.3,eth0.4,wg0]
proto: [tcp,udp]
port: [3478,5349]
- iface: [eth0,eth0.2,eth0.3,eth0.4,wg0]
proto: udp
port: ["49152-65535"]
+3
View File
@@ -0,0 +1,3 @@
dnsmasq:
- name: proxmox.oyacoi.ru
ip: 10.10.0.2
+8
View File
@@ -0,0 +1,8 @@
nft_from:
- iface: wg0
proto: tcp
port: 22
dnsmasq:
- name: gitea.oyacoi.ru
ip: 10.10.0.2
+4
View File
@@ -0,0 +1,4 @@
nft_to:
- to: nginx
proto: tcp
port: [80, 81, 443, 444, 24445]
+3
View File
@@ -0,0 +1,3 @@
dnsmasq:
- name: jellyfin.oyacoi.ru
ip: 10.10.0.2
+13
View File
@@ -0,0 +1,13 @@
nft_dst:
- iface: [eth0,eth0.2]
proto: tcp
port: 25565
nft_from:
- iface: [eth0,wg0]
proto: tcp
port: 25565
dnsmasq:
- name: mcsmanager.oyacoi.ru
ip: 10.10.0.2
+7
View File
@@ -0,0 +1,7 @@
nft_to:
- to: workuter
proto: [tcp, udp]
port: 32765
- to: oyacoi-odcm
proto: [tcp, udp]
port: 32765
+42
View File
@@ -0,0 +1,42 @@
nft_to:
- to: vaultwarden
proto: tcp
port: 8000
- to: gitea
proto: tcp
port: 3000
- to: radicale
proto: tcp
port: 5232
- to: slskd
proto: tcp
port: 5030
- to: asf
proto: tcp
port: 1337
- to: rtorrent
proto: tcp
port: 80
- to: jellyfin
proto: tcp
port: 8096
- to: prosody
proto: tcp
port: 5280
- to: torrserver
proto: tcp
port: 8090
- to: prowlarr
proto: tcp
port: 9696
- to: prowlarr #jackett
proto: tcp
port: 9117
- to: bylampa
proto: tcp
port: 80
nft_from:
- iface: [eth0,eth0.2]
proto: tcp
port: [80,443,24444]
+3
View File
@@ -0,0 +1,3 @@
dnsmasq:
- name: ntfy.oyacoi.ru
ip: 10.10.0.2
+15
View File
@@ -0,0 +1,15 @@
nft_to:
- to: nfs
proto: [tcp, udp]
port: [2049, 111, 32765, 32767]
- to: [zone:eth0.10,zone:eth0.11,zone:eth0.12]
proto: tcp
port: 22
- to: [xiawrt,rbpi4]
proto: tcp
port: 22
xray_policy:
- bypass: private
- bypass: russian_whitelist
- proxy: all
+20
View File
@@ -0,0 +1,20 @@
nft_dst:
- iface: [eth0,eth0.2]
proto: tcp
port: [5000,5222,5223,5280,5270,5269]
nft_to:
- to: pgsql
proto: tcp
port: 5432
nft_from:
- iface: [eth0,eth0.2,wg0]
proto: tcp
port: [5000,5222,5223,5269,5270,5280]
dnsmasq:
- name: talk.oyacoi.ru
ip: 10.10.0.2
- name: upload.oyacoi.ru
ip: 10.10.0.2
+5
View File
@@ -0,0 +1,5 @@
dnsmasq:
- name: prowlarr.oyacoi.ru
ip: 10.10.0.2
- name: jackett.oyacoi.ru
ip: 10.10.0.2
+8
View File
@@ -0,0 +1,8 @@
nft_to:
- to: ps3netsrv
proto: tcp
port: 38008
dnsmasq:
- name: ps3.oyacoi.ru
ip: 10.10.0.2
+3
View File
@@ -0,0 +1,3 @@
dnsmasq:
- name: radicale.oyacoi.ru
ip: 10.10.0.2
+3
View File
@@ -0,0 +1,3 @@
dnsmasq:
- name: rustdesk.dttx.ru
ip: 176.119.157.97
+6
View File
@@ -0,0 +1,6 @@
ansible_host: 10.1.0.1
ansible_connection: ssh
ansible_user: root
ansible_ssh_private_key_file: ~/.ssh/id_ed25519
zone_iface: eth0
container_ip: 10.1.0.1
+13
View File
@@ -0,0 +1,13 @@
nft_dst:
- iface: eth1
proto: tcp
port: ["6890-6899"]
nft_from:
- iface: eth1
proto: tcp
port: ["6890-6899"]
dnsmasq:
- name: rutorrent.oyacoi.ru
ip: 10.10.0.2
+4
View File
@@ -0,0 +1,4 @@
nft_to:
- to: firebat
proto: tcp
port: [22, 8006]
+13
View File
@@ -0,0 +1,13 @@
nft_dst:
- iface: eth1
proto: tcp
port: 50300
nft_from:
- iface: eth1
proto: tcp
port: 50300
dnsmasq:
- name: slskd.oyacoi.ru
ip: 10.10.0.2
+9
View File
@@ -0,0 +1,9 @@
nft_dst:
- iface: eth0
proto: udp
port: 2456
nft_from:
- iface: [eth0,wg0]
proto: udp
port: [2456,2457]
+18
View File
@@ -0,0 +1,18 @@
nft_dst:
- iface: eth1
proto: [tcp, udp]
port: 6990
nft_to:
- to: flaresolverr
proto: tcp
port: 8191
nft_from:
- iface: eth1
proto: [tcp,udp]
port: 6990
dnsmasq:
- name: torrserver.oyacoi.ru
ip: 10.10.0.2
+8
View File
@@ -0,0 +1,8 @@
nft_to:
- to: pgsql
proto: tcp
port: 5432
dnsmasq:
- name: vaultwarden.oyacoi.ru
ip: 10.10.0.2
+10
View File
@@ -0,0 +1,10 @@
nft_to:
- to: nfs
proto: [tcp, udp]
port: [2049, 111, 32765, 32767]
- to: [zone:eth0.10,zone:eth0.11,zone:eth0.12]
proto: tcp
port: 22
- to: [xiawrt,rbpi4]
proto: tcp
port: 22
+8
View File
@@ -0,0 +1,8 @@
nft_to:
- to: zabbix
proto: tcp
port: 10051
dnsmasq:
- name: xiawrt.oyacoi.ru
ip: 10.10.0.2
+11
View File
@@ -0,0 +1,11 @@
nft_to:
- to: "zone:eth0.11"
proto: tcp
port: 10050
- to: xiawrt
proto: tcp
port: 10050
dnsmasq:
- name: zabbix.oyacoi.ru
ip: 10.10.0.2
+13
View File
@@ -0,0 +1,13 @@
plugin: community.proxmox.proxmox
url: https://10.1.0.4:8006
user: root@pam
password: "{{ lookup('env', 'PROXMOX_PASSWORD') }}"
validate_certs: false
want_facts: true
filter_by_types:
- lxc
compose:
zone_iface: "'eth0.' ~ proxmox_net0.tag"
container_ip: "proxmox_net0.ip | default('') | regex_replace('/.*', '')"
+82
View File
@@ -0,0 +1,82 @@
all:
children:
static:
hosts:
workuter:
container_ip: "10.1.0.2"
zone_iface: "eth0"
oyacoi-odcm:
container_ip: "10.1.0.3"
zone_iface: "eth0"
firebat:
container_ip: "10.1.0.4"
zone_iface: "eth0"
ansible_host: 10.1.0.4
ansible_user: root
ansible_ssh_private_key_file: "~/.ssh/id_ed25519"
ps2:
container_ip: "10.1.0.5"
zone_iface: "eth0"
ps3:
container_ip: "10.1.0.6"
zone_iface: "eth0"
tanix:
container_ip: "10.1.0.8"
zone_iface: "eth0"
bananawrt:
container_ip: "10.1.0.100"
zone_iface: "eth0"
ps4:
container_ip: "10.2.0.2"
zone_iface: "eth0.2"
note13:
container_ip: "10.2.0.3"
zone_iface: "eth0.2"
iphone11:
container_ip: "10.2.0.4"
zone_iface: "eth0.2"
huawei-tablet:
container_ip: "10.2.0.5"
zone_iface: "eth0.2"
uni:
container_ip: "10.2.0.6"
zone_iface: "eth0.2"
papperwhite:
container_ip: "10.2.0.7"
zone_iface: "eth0.2"
psp:
container_ip: "10.2.0.8"
zone_iface: "eth0.2"
dsi:
container_ip: "10.2.0.9"
zone_iface: "eth0.2"
3ds:
container_ip: "10.2.0.10"
zone_iface: "eth0.2"
camera0:
container_ip: "10.3.0.5"
zone_iface: "eth0.3"
xiawrt:
container_ip: "10.250.250.1"
zone_iface: "wg0"
rbpi4:
container_ip: "10.250.250.5"
zone_iface: "wg0"