Protect your server with a strong iptables rules and ipset lists.
apt install ipset| docker run -p 39013:39013 \ | |
| -p 39017:39017 \ | |
| -p 39041-39045:39041-39045 \ | |
| -p 1128-1129:1128-1129 \ | |
| -p 59013-59014:59013-59014 \ | |
| -v /hana/:/hana/mounts \ | |
| --ulimit nofile=1048576:1048576 \ | |
| --sysctl kernel.shmmax=1073741824 \ | |
| --sysctl net.ipv4.ip_local_port_range='40000 60999' \ | |
| --sysctl kernel.shmmni=524288 \ |
| #!/bin/bash | |
| set -e | |
| bail() { | |
| printf "${RED}$1${NC}\n" 1>&2 | |
| exit 1 | |
| } | |
| function registry_pki_secret() { |
| --- | |
| apiVersion: apps/v1 | |
| kind: DaemonSet | |
| metadata: | |
| name: netshoot | |
| labels: | |
| app: netshoot | |
| spec: | |
| updateStrategy: | |
| type: RollingUpdate |
Unless otherwise noted (either in this file or in a file's copyright section) the contents of this gist are Copyright ©️2020 by Christopher Allen, and are shared under spdx:Creative Commons Attribution Share Alike 4.0 International (CC-BY-SA-4.) open-source license.
If you more tips and advice like these, you can become a monthly patron on my GitHub Sponsor Page for as little as $5 a month; and your contributions will be multipled, as GitHub is matching the first $5,000! This gist is all about Homebrew, so if you like it you can support it by donating to them or becoming one of their Github Sponsors.