Skip to content

Commit b5d1045

Browse files
authored
feat: remove firewall rules
1 parent 5e95523 commit b5d1045

File tree

2 files changed

+1
-17
lines changed

2 files changed

+1
-17
lines changed

README.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,7 @@ A implementation of windows github custom runner (x64) based on vagrant VM, libv
1414
```
1515
PAT=<Replace with your personal access token>
1616
ORGANIZATION_URL=<Organization url>
17-
RUNNERS=2
17+
RUNNERS=1
1818
# Vagrant image settings
1919
MEMORY=8000 # 8GB
2020
CPU=4

startup.sh

Lines changed: 0 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -19,20 +19,4 @@ chown root:kvm /dev/kvm
1919

2020
VAGRANT_DEFAULT_PROVIDER=libvirt vagrant up #--debug
2121

22-
iptables-save > /root/firewall.txt
23-
iptables -A LIBVIRT_FWI -i eth0 -o virbr1 -p tcp --syn --dport 3389 -m conntrack --ctstate NEW -j ACCEPT
24-
iptables -A LIBVIRT_FWI -i eth0 -o virbr1 -p tcp --syn --dport 445 -m conntrack --ctstate NEW -j ACCEPT
25-
iptables -A LIBVIRT_FWI -i eth0 -o virbr1 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
26-
iptables -A LIBVIRT_FWI -i virbr0 -o eth0 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
27-
28-
iptables -t nat -A PREROUTING -i eth0 -p tcp --dport 3389 -j DNAT --to-destination 192.168.121.10
29-
iptables -t nat -A PREROUTING -i eth0 -p tcp --dport 445 -j DNAT --to-destination 192.168.121.10
30-
iptables -t nat -A LIBVIRT_PRT -o virbr1 -p tcp --dport 3389 -d 192.168.121.10 -j SNAT --to-source 192.168.121.1
31-
iptables -t nat -A LIBVIRT_PRT -o virbr1 -p tcp --dport 445 -d 192.168.121.10 -j SNAT --to-source 192.168.121.1
32-
33-
iptables -D LIBVIRT_FWI -o virbr1 -j REJECT --reject-with icmp-port-unreachable
34-
iptables -D LIBVIRT_FWI -o virbr0 -j REJECT --reject-with icmp-port-unreachable
35-
iptables -D LIBVIRT_FWO -i virbr1 -j REJECT --reject-with icmp-port-unreachable
36-
iptables -D LIBVIRT_FWO -i virbr0 -j REJECT --reject-with icmp-port-unreachable
37-
3822
exec "$@"

0 commit comments

Comments
 (0)