|
|
08ed18bb96
|
deploy: Let's Encrypt deploy-hook — installs the renewed cert into echoircd's tls/ (readable by the daemon user) and restarts only when it changed; symlink into certbot renewal-hooks
|
2026-08-15 01:12:37 +00:00 |
|
|
|
d8a963d0f9
|
deploy: add firewalld direct-rule flood-mitigation script (per-IP hashlimit on the IRC ports); gitignore the pinned bin/ artifact
|
2026-08-12 18:03:07 +00:00 |
|
|
|
be97089dfa
|
deploy: use firewalld direct-rule for the per-IP flood mitigation (this box runs firewalld — a raw iptables rule would be flushed on reload); replaces the plain-iptables draft
|
2026-08-12 18:02:45 +00:00 |
|
|
|
df160801c8
|
deploy: iptables hashlimit flood-mitigation script (per-source-IP rate limit on the IRC client ports; policy-accept, loopback-exempt, idempotent add/del) — kernel-layer defense-in-depth, not applied automatically
|
2026-08-12 17:55:46 +00:00 |
|
|
|
2aaa5ac091
|
deploy: persistent systemd unit running a pinned release binary with Restart=on-failure + boot enable, plus a liveness timer that restarts the daemon if a register round-trip stops answering
|
2026-08-12 16:01:58 +00:00 |
|