Last active
July 22, 2026 21:46
-
-
Save andrebrait/51611ccb73e0060aa118af60b95916e3 to your computer and use it in GitHub Desktop.
pfBlockerNG post-update hook for usage of aliases inside HAProxy ACLs
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| #!/bin/sh | |
| # Install as /usr/local/pkg/pfblockerng/hooks/hook_post_haproxy.sh so it appears in the Hooks GUI (pfBlockerNG >= 4.0.0) | |
| # We are not using pfBlockerNG's modification flags because HAProxy may be out of sync even though nothing changed in *this* update via pfBlockerNG | |
| if [ "$PFB_PRE_UNINSTALL" -gt 0 ]; then | |
| echo "Skipping update on uninstall..." | |
| exit 0 | |
| fi | |
| # SIMPLE PID GUARD: Exit if this script is already running elsewhere | |
| if [ $(pgrep -f "$(basename "$0")" | wc -l) -gt 1 ]; then | |
| echo "Already running" | |
| exit 0 | |
| fi | |
| PFB_DIR="/var/db/pfblockerng" | |
| compare_files() { | |
| diff -wq $@ > /dev/null 2>&1 | |
| return $? | |
| } | |
| modified=0 | |
| # Checks whether the aliases have been changed since the last HAProxy restart | |
| aliases_sync() { | |
| local ALIAS_NAME="${1}" | |
| local ACL_FILE="/var/etc/haproxy/ipalias_${ALIAS_NAME}.lst" | |
| local ALIAS_FILE="/var/db/aliastables/${ALIAS_NAME}.txt" | |
| # Ensure the ACL file exists | |
| if [ ! -f "$ACL_FILE" ]; then | |
| # We need to use a dummy IP address because HAProxy checks it during its test run | |
| echo "127.1.7.7" > "$ACL_FILE" | |
| fi | |
| # If the newly combined dataset differs from what HAProxy has on disk | |
| if compare_files "$ACL_FILE" "$ALIAS_FILE"; then | |
| logger "HAProxy Aliases Sync: no changes detected in ${ALIAS_NAME}. Continuing..." | |
| else | |
| logger "HAProxy Aliases Sync: detected changes in ${ALIAS_NAME}. Will require a restart." | |
| modified=1 | |
| fi | |
| } | |
| # Run the checks for each alias we use | |
| # First, the pfB aliases and trigger a pfB update if necessary | |
| echo "Firing up HAProxy ACL update hook" | |
| aliases_sync pfB_Deny_Aggregated_v4 | |
| aliases_sync pfB_Deny_Aggregated_v6 | |
| # aliases_sync pfB_GeoIP_Aggregated_v4 # Not yet used in HAProxy | |
| # aliases_sync pfB_GeoIP_Aggregated_v6 # Not yet used in HAProxy | |
| # aliases_sync TrustedSubnets_IPv4 # Still have not figured this one out | |
| aliases_sync CloudflareProxy_IPv4 | |
| aliases_sync CloudflareProxy_IPv6 | |
| if [ "$1" = "force" ] || [ "$PFB_IP_CHANGED" -gt 0 ] || [ $modified -gt 0 ]; then | |
| echo "Reloading HAProxy" | |
| # This does a graceful restart and quick reload | |
| /usr/local/etc/rc.d/haproxy.sh restart | |
| echo "HAProxy Service restarted" | |
| else | |
| echo "No changes detected. Resuming..." | |
| fi |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment