The anti-scanner rules dropped 53-byte Steam query packets above 1/hour with a burst of 2, per source IP, on the theory that only scanners send queries and that real players would already have been marked verified by the priority-2 rule when they sent something larger. That premise is inverted. A client's first contact with the server IS a 53-byte query, so nobody can be verified before querying, and nobody can query more than twice an hour without being dropped. The counters said so plainly: five packets had ever matched the verified-accept rule, against 30,563 drops. fail2ban then banned each dropped player for a week -- 32 live bans, 550 total, firing every ten minutes, every one of them a residential address. Keeps the shape of the protection and moves the threshold somewhere no real client reaches: opening the server browser or retrying a connection is a handful of queries, a flood is thousands. Removes the old rules first so hosts carrying them converge instead of stacking a second copy. The bans themselves were also hooked into INPUT for tcp only, so they never blocked the UDP game traffic they were meant to -- the drop rule was doing all the damage on its own. Cleared the outstanding 32. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Deploy Home
There's no place like home!
Just as Dorothy managed the simple task of clicking her heels together, the desire for an equally simple one-button push deployment was in my heart. Thus, this repository was made.
Ansible
Ansible, along with double encrypted secrets, deploys the necessary configurations to make the home fit for certain needs and desires. Namely, having access to my home from anywhere, securely, and a self-hosted CI server that easily ties into existing workflows.
Makefile
The makefile is primarily used as a wrapper script to ensure that necessary
files, such as the secret vault password file, are provisioned as part of this.
One such addition to the task is utilizing dependency pinning through the
utilization of Python's virtualenv to lock down the specific dependency
versions within the requirements.txt file. This, ideally, prevents any
deployment issues with dependency version woes (e.g. version conflicts, major
updates in newest versions, etc.)
| Target Name | Description |
|---|---|
lint |
(default) Runs yamllint and ansible-lint on all YAML files in ansible/ |
deploy |
Deploys everything, or only tasks specified in TAGS= environment variable |
check |
Runs deploy in a "dry-run", showing diff-style outputs on tasks indicating changes |
vault |
Opens the Ansible vault file for editing |