Commit Graph

69 Commits

Author SHA1 Message Date
Fabian Peter Hammerle a75b7aebae add nft rule forwarding udp dns requests to tor 2021-05-07 00:08:52 +02:00
Fabian Peter Hammerle 6b811fe5c6 release v4.2.0 docker/4.2.0-tor0.4.4.8r0-armv7 docker/4.2.0-tor0.4.4.8r0-amd64 v4.2.0 2021-04-30 12:50:31 +02:00
Fabian Peter Hammerle db9609494e add nft rule redirecting tcp traffic to transparent proxy 2021-04-30 12:35:15 +02:00
dependabot[bot] f05b6c3765 build(deps): bump alpine from 3.13.4 to 3.13.5
Bumps alpine from 3.13.4 to 3.13.5.

Signed-off-by: dependabot[bot] <support@github.com>
2021-04-16 05:45:24 +00:00
dependabot[bot] f301bd9968 build(deps): bump alpine from 3.13.3 to 3.13.4
Bumps alpine from 3.13.3 to 3.13.4.

Signed-off-by: dependabot[bot] <support@github.com>
docker/4.1.0-tor0.4.4.8r0-arm64 docker/4.1.0-tor0.4.4.8r0-armv7
2021-04-02 06:28:41 +00:00
Fabian Peter Hammerle 76f7fcaf09 upgrade alpine base image v3.12.2->v3.13.3 including upgrade of tor v0.4.4.7-r1->v0.4.4.8-r0 (see below)
> One of these vulnerabilities (TROVE-2021-001) would allow an attacker
> who can send directory data to a Tor instance to force that Tor
> instance to consume huge amounts of CPU.
https://gitweb.torproject.org/tor.git/plain/ChangeLog

https://cve.circl.lu/cve/CVE-2021-28089

https://git.alpinelinux.org/aports/commit/community/tor?id=dc7ce7e4b63c64d11026e307ada830c33d8309a4

https://github.com/fphammerle/docker-onion-service/commit/48c53ae15c2780b3ac97ac55a91748e947a55ead
docker/4.1.0-tor0.4.4.8r0-amd64
2021-03-27 15:30:34 +01:00
dependabot[bot] 4e2545483d build(deps): bump alpine from 3.13.2 to 3.13.3
Bumps alpine from 3.13.2 to 3.13.3.

Signed-off-by: dependabot[bot] <support@github.com>
2021-03-26 06:19:03 +00:00
Fabian Peter Hammerle f9f3095cba readme: simplify control port commands (no longer invoke shell) 2021-03-03 18:57:41 +01:00
Fabian Peter Hammerle eac37ae895 readme: added instructions to disable safe logging; capitalize headlines 2021-03-03 18:54:14 +01:00
Fabian Peter Hammerle 579ec95c54 readme: added apt-get install cmd for onioncircuits 2021-03-03 17:12:48 +01:00
Fabian Peter Hammerle 63cc740dae readme: added command to launch onioncircuits 2021-03-03 17:07:44 +01:00
Fabian Peter Hammerle 71cd9e4843 release v4.1.0 docker/4.1.0-tor0.4.4.7r1-amd64 v4.1.0 2021-03-03 14:25:32 +01:00
Fabian Peter Hammerle 677e9db8e2 added image labels org.opencontainers.image.title, .source & .revision
https://github.com/fphammerle/docker-onion-service/commit/46ca6d70fb2d4570bfddac6b3f5e485183e72405
https://github.com/fphammerle/docker-onion-service/commit/aa124bde955047b2de6316ff72d6b1f76d14e3ba
2021-03-03 14:08:29 +01:00
Fabian Peter Hammerle 8ae9e9e5b7 makefile: added "podman-build" target
https://github.com/fphammerle/docker-onion-service/commit/77a062c4afcd96abe1ba7663a2914a94e01b9c24
https://github.com/fphammerle/docker-onion-service/commit/4c673eef480af3bb9498c0364a55dc3d8f8a5afc
https://github.com/fphammerle/docker-onion-service/commit/a3e89529767a7eb52c4bce52277715d388f6935a
https://github.com/fphammerle/docker-onion-service/commit/e8dfe51bb831c54d9a87be7c70f3f79e2f45d9ce
2021-03-03 13:48:47 +01:00
Fabian Peter Hammerle 1951c1f3a9 enable transparent proxy 2021-03-03 12:25:12 +01:00
Fabian Peter Hammerle edac4ed3da upgrade alpine base image v3.13.1->3.13.2 including upgrade of tor package v0.4.4.6-r1->0.4.4.7-r1 (diff links below)
https://git.alpinelinux.org/aports/commit/community/tor?id=3ff23770ebde5d5ce691e662d25ba01bd5020f3d
https://git.alpinelinux.org/aports/commit/community/tor?id=a9d54349aa5fec39e2d79c46838ce05904ca9bda
https://git.alpinelinux.org/aports/commit/community/tor?id=9ed5ece0dd0317f1976a1bb4729e911786d33af9

cherry-pick of https://github.com/fphammerle/docker-onion-service/commit/0599554fd6ae2ee3404dc63cec90730b14fa1fc2
2021-02-19 13:13:56 +01:00
dependabot[bot] 5cc893c3c3 build(deps): bump alpine from 3.13.1 to 3.13.2
Bumps alpine from 3.13.1 to 3.13.2.

Signed-off-by: dependabot[bot] <support@github.com>
2021-02-19 06:10:22 +00:00
dependabot[bot] 4e2e1bbf4f build(deps): bump alpine from 3.13.0 to 3.13.1
Bumps alpine from 3.13.0 to 3.13.1.

Signed-off-by: dependabot[bot] <support@github.com>
2021-01-29 05:49:05 +00:00
Fabian Peter Hammerle 40b88ec7d5 upgrade alpine base image v3.12.3->v3.13.0 including upgrade of tor v0.4.3.7-r0->v0.4.4.6-r1 (diff links below)
https://gitweb.torproject.org/tor.git/plain/ChangeLog

https://git.alpinelinux.org/aports/commit/community/tor?id=d181b0289ff7c32d371dcd976276672bbe2e7b72
https://git.alpinelinux.org/aports/commit/community/tor?id=9a0a0a5045901ab97ef455b54ffe19c91ca6993e
https://git.alpinelinux.org/aports/commit/community/tor?id=5edd132382384956e1787d4dcd5f1ffa9c520571
https://git.alpinelinux.org/aports/commit/community/tor?id=4ecb636d72d13db0f95f6e840e755bb260c91165
2021-01-15 12:46:01 +01:00
dependabot[bot] 67c5c44495 build(deps): bump alpine from 3.12.3 to 3.13.0
Bumps alpine from 3.12.3 to 3.13.0.

Signed-off-by: dependabot[bot] <support@github.com>
2021-01-15 06:05:59 +00:00
Fabian Peter Hammerle ba4cafac27 make: add tor package version to image tag 2021-01-01 17:40:10 +01:00
Fabian Peter Hammerle fea43b11d8 make: abort docker-build if changes uncommitted; suggest git tag command
https://github.com/fphammerle/wireless-sensor-mqtt/blob/222d2e124d231b207da647c1f7a9c5ec9a37b4ac/Makefile#L34
2021-01-01 17:29:38 +01:00
Fabian Peter Hammerle 4f6950af1d make: added docker-build & docker-push target
https://github.com/fphammerle/systemctl-mqtt/commit/54a3c74eae0e85307ac5f9258c345bc133d3133a#diff-76ed074a9305c04054cdebb9e9aad2d818052b07091de1f20cad0bbac34ffb52
https://github.com/fphammerle/systemctl-mqtt/commit/7887079ebeed7e26cfc36bbdcbdfd6ceeb65bdee#diff-76ed074a9305c04054cdebb9e9aad2d818052b07091de1f20cad0bbac34ffb52
2021-01-01 17:25:40 +01:00
Fabian Peter Hammerle 7cbef67a3f release v4.0.0 docker/4.0.0-tor0.4.3.7r0-amd64 v4.0.0 2021-01-01 17:20:14 +01:00
Fabian Peter Hammerle dfe104eb09 healthcheck: replace dig with pre-installed nslookup 2021-01-01 16:38:41 +01:00
Fabian Peter Hammerle 6a9e7a1f42 healthcheck: restore dns request as network-liveness is too optimistic
partial revert of commit 8d1a635ddc.
2021-01-01 16:36:24 +01:00
Fabian Peter Hammerle 8d1a635ddc healthcheck: improve privacy by probing network-liveness instead of periodic http and dns requests 2021-01-01 13:59:50 +01:00
Fabian Peter Hammerle d573073454 upgrade tor v0.4.3.5 -> v0.4.3.7 (diff links below)
https://gitweb.torproject.org/tor.git/plain/ChangeLog

https://git.alpinelinux.org/aports/commit/community/tor?id=3a247b9dbce3988d52b1a17a3d0bb5f1dc9b4863

removes support for zstd-compressed directory traffic from armhf builds:
https://git.alpinelinux.org/aports/commit/?id=2849fa38b9a76d1ef0a9df10aa70bafa00a5ab27

adds patches to curl for irrelevant CVE-2020-8286, CVE-2020-82850 & CVE-2020-8231
https://git.alpinelinux.org/aports/commit/?id=90e58b3d833e1a1e51c524cdaa5091dbcd80c0f0
https://git.alpinelinux.org/aports/commit/main/curl?id=52697341e47e456d2ee900a53c8ef65ce8a75c23
2021-01-01 12:50:11 +01:00
Fabian Peter Hammerle ccb9eb52a1 configure github's dependabot to keep base image up-to-date
https://github.com/fphammerle/docker-postfix/commit/b273cbb38193eaa52562688522475c7e6e7df6b7
2021-01-01 12:42:38 +01:00
Fabian Peter Hammerle b85bfc4d53 ansible-playbook: select image via fingerprint 2020-10-03 17:32:38 +02:00
Fabian Peter Hammerle 9d8903fbee release v3.0.0 v3.0.0 docker/3.0.0-tor0.4.3.5-amd64 2020-10-03 17:29:06 +02:00
Fabian Peter Hammerle 8cc0734979 create mount point at data dir /var/lib/tor to be able to make container's root filesystem read-only
https://github.com/fphammerle/docker-tor-obfs4-bridge/commit/8d6514c2bda98488876f67116aa4c306a9dc28c2
https://github.com/fphammerle/docker-onion-service/commit/345840bda88620983bbf3d0f9a2975b561101ffc
2020-10-03 17:24:55 +02:00
Fabian Peter Hammerle 2778ba83d0 readme: split in sections 2020-10-03 17:12:58 +02:00
Fabian Peter Hammerle d12b5387bd readme / show circuit command: wrap, add quit command
https://github.com/fphammerle/docker-onion-service/commit/5cb7c809f30b2ac098bdf8530c9587dc659387ef
2020-10-03 11:03:34 +02:00
Fabian Peter Hammerle 97aca0c2c6 move tor's data directory to /var/lib/tor; run as user tor (uid=100)
https://github.com/fphammerle/docker-tor-obfs4-bridge/commit/8d6514c2bda98488876f67116aa4c306a9dc28c2
https://github.com/fphammerle/docker-onion-service/commit/345840bda88620983bbf3d0f9a2975b561101ffc
2020-10-03 10:52:34 +02:00
Fabian Peter Hammerle a28bf73885 ansible-playbook: drop capabilities 2020-10-03 10:36:54 +02:00
Fabian Peter Hammerle 1440258718 readme: added link to relay search 2020-09-27 09:04:02 +02:00
Fabian Peter Hammerle 7fb3c50db6 upgrade curl default package version 2020-09-27 08:53:39 +02:00
Fabian Peter Hammerle c44166f264 release v2.1.0 docker/2.1.0-tor0.4.3.5-amd64 v2.1.0 2020-09-27 08:47:11 +02:00
Fabian Peter Hammerle b0d0e8da22 docker-compose: drop capabilities 2020-09-27 08:45:20 +02:00
Fabian Peter Hammerle ef97bc410f healthcheck: remove circuit-established check via control port to avoid spamming container log
> [notice] New control connection opened from 127.0.0.1.
2020-09-26 22:56:19 +02:00
Fabian Peter Hammerle a4f7946ced enable control listener 2020-09-26 22:52:13 +02:00
Fabian Peter Hammerle dcb78b66c5 upgrade default tor version: 0.4.1.9 -> 0.4.3.5 docker/2.0.0-tor0.4.3.5-amd64 2020-09-26 21:56:41 +02:00
Fabian Peter Hammerle 7bce89fedf fix DNS port in readme & sample playbook 2020-03-24 20:18:30 +01:00
Fabian Peter Hammerle 22dcf7e9f4 release v2.0.0 docker/2.0.0-tor0.4.1.9-amd64 v2.0.0 2020-03-24 20:14:53 +01:00
Fabian Peter Hammerle 95b977d216 run tor as unprivileged user; DNS port 53 -> 9053 (breaking)
> [warn] You are running Tor as root. You don't need to, and you probably shouldn't.
2020-03-24 20:08:49 +01:00
Fabian Peter Hammerle db4522974f fix invalid torrc path
introduced in 60bad462e4 (v1.1.0)

> [notice] Configuration file "/etc/tor/torrc" not present, using reasonable defaults.
docker/1.1.1-tor0.4.1.9-amd64 v1.1.1
2020-03-21 21:15:08 +01:00
Fabian Peter Hammerle cf5401be4e release v1.1.0 docker/1.1.0-tor0.4.1.9-amd64 v1.1.0 2020-03-21 21:04:32 +01:00
Fabian Peter Hammerle d2d2f4aaf7 reduce verbosity of entrypoint 2020-03-21 21:03:09 +01:00
Fabian Peter Hammerle 60bad462e4 change SocksTimeout by setting $SOCKS_TIMEOUT_SECONDS 2020-03-21 21:00:07 +01:00