fix: add NAT blacklist for dangerous ports in iptables#269
Conversation
Co-authored-by: Mossaka <5447827+Mossaka@users.noreply.github.com>
✅ Coverage Check PassedOverall Coverage
Coverage comparison generated by |
|
📰 VERDICT: Smoke Copilot has concluded. All systems operational. This is a developing story. 🎤 |
|
🌑 The shadows whisper... Smoke Codex failed. The oracle requires further meditation... |
|
🎬 THE END — Smoke Claude MISSION: ACCOMPLISHED! The hero saves the day! ✨ |
Smoke Test Results (Claude)Last 2 Merged PRs:
Test Results:
Overall Status: PASS
|
✅ Smoke Test PASSEDLast 2 Merged PRs:
Test Results:
|
|
📰 VERDICT: Smoke Copilot has concluded. All systems operational. This is a developing story. 🎤 |
|
🌑 The shadows whisper... Smoke Codex failed. The oracle requires further meditation... |
|
🎬 THE END — Smoke Claude MISSION: ACCOMPLISHED! The hero saves the day! ✨ |
Smoke Test Results - Claude EngineLast 2 Merged PRs:
Test Results:
Status: PASS
|
Smoke Test ResultsLast 2 Merged PRs:
Test Results:
Overall: PARTIAL PASS (4/5 - Playwright library issue) cc: @Mossaka
|
Adds defense-in-depth layer at the iptables NAT level to block dangerous ports, complementing existing Squid ACL filtering.
Changes
DANGEROUS_PORTSarray incontainers/agent/setup-iptables.shmatching the list insquid-config.tsBlocked Ports
SSH (22), Telnet (23), SMTP (25), POP3 (110), IMAP (143), SMB (445), MSSQL (1433), Oracle (1521), MySQL (3306), RDP (3389), PostgreSQL (5432), Redis (6379), MongoDB (27017/27018/28017)
Traffic Flow
Original prompt
✨ Let Copilot coding agent set things up for you — coding agent works faster and does higher quality work when set up for your repo.