Skip to content

Instantly share code, notes, and snippets.

@andrebrait
Last active July 22, 2026 21:46
Show Gist options
  • Select an option

  • Save andrebrait/51611ccb73e0060aa118af60b95916e3 to your computer and use it in GitHub Desktop.

Select an option

Save andrebrait/51611ccb73e0060aa118af60b95916e3 to your computer and use it in GitHub Desktop.
pfBlockerNG post-update hook for usage of aliases inside HAProxy ACLs
#!/bin/sh
# Install as /usr/local/pkg/pfblockerng/hooks/hook_post_haproxy.sh so it appears in the Hooks GUI (pfBlockerNG >= 4.0.0)
# We are not using pfBlockerNG's modification flags because HAProxy may be out of sync even though nothing changed in *this* update via pfBlockerNG
if [ "$PFB_PRE_UNINSTALL" -gt 0 ]; then
echo "Skipping update on uninstall..."
exit 0
fi
# SIMPLE PID GUARD: Exit if this script is already running elsewhere
if [ $(pgrep -f "$(basename "$0")" | wc -l) -gt 1 ]; then
echo "Already running"
exit 0
fi
PFB_DIR="/var/db/pfblockerng"
compare_files() {
diff -wq $@ > /dev/null 2>&1
return $?
}
modified=0
# Checks whether the aliases have been changed since the last HAProxy restart
aliases_sync() {
local ALIAS_NAME="${1}"
local ACL_FILE="/var/etc/haproxy/ipalias_${ALIAS_NAME}.lst"
local ALIAS_FILE="/var/db/aliastables/${ALIAS_NAME}.txt"
# Ensure the ACL file exists
if [ ! -f "$ACL_FILE" ]; then
# We need to use a dummy IP address because HAProxy checks it during its test run
echo "127.1.7.7" > "$ACL_FILE"
fi
# If the newly combined dataset differs from what HAProxy has on disk
if compare_files "$ACL_FILE" "$ALIAS_FILE"; then
logger "HAProxy Aliases Sync: no changes detected in ${ALIAS_NAME}. Continuing..."
else
logger "HAProxy Aliases Sync: detected changes in ${ALIAS_NAME}. Will require a restart."
modified=1
fi
}
# Run the checks for each alias we use
# First, the pfB aliases and trigger a pfB update if necessary
echo "Firing up HAProxy ACL update hook"
aliases_sync pfB_Deny_Aggregated_v4
aliases_sync pfB_Deny_Aggregated_v6
# aliases_sync pfB_GeoIP_Aggregated_v4 # Not yet used in HAProxy
# aliases_sync pfB_GeoIP_Aggregated_v6 # Not yet used in HAProxy
# aliases_sync TrustedSubnets_IPv4 # Still have not figured this one out
aliases_sync CloudflareProxy_IPv4
aliases_sync CloudflareProxy_IPv6
if [ "$1" = "force" ] || [ "$PFB_IP_CHANGED" -gt 0 ] || [ $modified -gt 0 ]; then
echo "Reloading HAProxy"
# This does a graceful restart and quick reload
/usr/local/etc/rc.d/haproxy.sh restart
echo "HAProxy Service restarted"
else
echo "No changes detected. Resuming..."
fi
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment