Last active
July 24, 2026 10:34
-
-
Save andrebrait/ee3a39dac388db0f2581be3a19449a7c to your computer and use it in GitHub Desktop.
Synchronize IP aliases from pfBlockerNG with HAProxy
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| #!/bin/sh | |
| # Drop this script in /usr/local/pkg/pfblockerng/hooks | |
| if [ "$PFB_PRE_UNINSTALL" -gt 0 ]; then | |
| echo "Skipping update on uninstall..." | |
| exit 0 | |
| fi | |
| # SIMPLE PID GUARD: Exit if this script is already running elsewhere | |
| if [ $(pgrep -f "$(basename "$0")" | wc -l) -gt 1 ]; then | |
| echo "Already running" | |
| exit 0 | |
| fi | |
| PFB_DIR="/var/db/pfblockerng" | |
| compare_files() { | |
| diff -wq $@ > /dev/null 2>&1 | |
| return $? | |
| } | |
| modified=0 | |
| # Checks whether the aliases have been changed since the last HAProxy restart | |
| aliases_sync() { | |
| local ALIAS_NAME="${1}" | |
| local ACL_FILE="/var/etc/haproxy/ipalias_${ALIAS_NAME}.lst" | |
| local ALIAS_FILE="/var/db/aliastables/${ALIAS_NAME}.txt" | |
| # Ensure the ACL file exists | |
| if [ ! -f "$ACL_FILE" ]; then | |
| # We need to use a dummy IP address because HAProxy checks it during its test run | |
| echo "1.1.1.1" > "$ACL_FILE" | |
| fi | |
| # If the newly combined dataset differs from what HAProxy has on disk | |
| if compare_files "$ACL_FILE" "$ALIAS_FILE"; then | |
| logger "HAProxy Aliases Cron Sync: no changes detected in ${ALIAS_NAME}. Continuing..." | |
| else | |
| logger "HAProxy Aliases Cron Sync: detected changes in ${ALIAS_NAME}. Will require a restart." | |
| modified=1 | |
| fi | |
| } | |
| # Run the checks for each alias we use | |
| # First, the pfB aliases and trigger a pfB update if necessary | |
| aliases_sync pfB_Deny_Aggregated_v4 | |
| aliases_sync pfB_Deny_Aggregated_v6 | |
| aliases_sync CloudflareProxy_IPv4 | |
| aliases_sync CloudflareProxy_IPv6 | |
| # Run the checks for each alias we use | |
| # First, the pfB aliases and trigger a pfB update if necessary | |
| echo "Firing up HAProxy ACL update hook" | |
| if [ "$1" = "force" ] || [ "$PFB_IP_CHANGED" -gt 0 ] || [ "$modified" -gt 0 ]; then | |
| echo "Reloading HAProxy" | |
| # This does a graceful restart and quick reload | |
| /usr/local/etc/rc.d/haproxy.sh restart | |
| echo "HAProxy Service restarted" | |
| else | |
| echo "No changes detected. Resuming..." | |
| fi |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment