• Łukasz Nowak's avatar
    kvm: Implement whitelist firewall · 97225683
    Łukasz Nowak authored
    Sources of domains and IPs are:
    
     * default hardcoded in template/whitelist-domains-default
     * /etc/resolv.conf
     * provided in the request
     * provided in the special downloadble repository
    
    Then they are parsed with dnsresolver and .slapos-whitelist-firewall file is
    produced with list of IPs to be whitelisted.
    
    This allows slapos.core whitelistfirewall manager to lock-down the partition
    to only whitelisted list of IPs.
    97225683
whitelist-domains-default 513 Bytes
# Minimal whitelisted domains needed to instantiate the instance
# Does not guarantee good usage of the guest VM itself
# The full list shall end up in whitelist-domains-download:url
# shcache.nxdcdn.com is default source for a lot of operations
shacache.nxdcdn.com
# stream.nxdcdn.com is needed by partition itself
stream.nxdcdn.com
# partition has to access default SlapOS Master
slap.vifib.com
slapos.vifib.com
# Partition needs access to SlapOS Master related resources
hnode.cdn.vifib.com
node.cdn.vifib.com