- Shell 100%
| Filename | Latest commit message | Latest commit date |
|---|---|---|
| cli | ||
| grimoire | ||
| wards | ||
| .gitignore | ||
| install.sh | ||
| LICENSE | ||
| README.md | ||
| VERSION | ||
barrier
A collection of configs and bot tracking to help web servers use arcane magic to deflect automated bullshit. It's so stupid we need this stuff now
install
I made it easy. Just paste this in terminal and let the magic happen
curl -fsSL https://source.tube/brindly/barrier/raw/branch/main/install.sh | bash -s -- https://source.tube/brindly/barrier
what's it do though?
It clones the repo and installs the CLI tool globally. It won't activate anything unless you tell it to
Everything lives in /opt/barrier so you can go look for yourself. Or inspect the install scrip. Either way works
uninstall
remove global command
barrier uninstall
nuke everything
barrier uninstall --raze
--raze will ask before running. Just in case. It won't edit the web server configs though so make sure you remove those first
useful commands
Pull latest version. It'll back up any .toml edits you made, and attempt to merge them back in
barrier update
Build wards from grimoire. No flag does all of em. It will wipe out any already in there
You can edit the .toml files in grimoire to add exclusions, or disable entire sections, and generate will respect those
barrier generate [--nginx --apache --caddy --cloudflare --bunny]
Add includes for web server. Supports caddy, nginx, and apache atm. You can also use --site arg to tell it a specific domain you want to target. Otherwise it'll do em all
barrier enable <service> [path] [--site x]
Disables the includes. Basically comments them out
barrier disable <service> [path] [--site x]
Removes the includes. Bye bye
barrier remove <service> [path] [--site x]
Check barrier version. Cause why not
barrier -v
Any command accepts --dryrun as an arg to show what'll without doing stuff. If you're lost, try barrier <command> --help to get more info on a command
exclusions
You can totally tell the system if you want to exclude some of the default blocking. Just go in the .toml files, and either enable/disable whole sections, or just add specifics to the exclusion list (its an array)
Regenerate once saved and the new wards will have your tweaks. Just don't add new things to the toml lists because an update will wipe it. better off doing those in your own block partials seperate from barrier
nginx
As part of the nginx ward, there's 2 includes that get added to an nginx config file. The maps go in http {}, rules go in each server {} block you want protected. Below is a simple example:
http {
# 🛡️ barrier maps
include /opt/barrier/wards/nginx/maps/*.conf;
server {
# 🛡️ barrier rules
include /opt/barrier/wards/nginx/server.conf;
}
}
If adding these manually, you'll want to run the nginx config check, then reload nginx for them to take effect.
apache
Apache is easy its just a single line to include everything. Toss it in any <VirtualHost> you want to shield. Or i guess in a main config too maybe? idk I haven't touched apache in a long time i forgot the ins and outs. I just made sure this worked.
<VirtualHost *:443>
# 🛡️ barrier wards
Include /opt/barrier/wards/apache/*.conf
</VirtualHost>
Do a config test and then reload apache for it to engage
caddy
Caddy is the new hotness, so obviously adding that is simple. Just add a little line into any site block you want. Needs to go before handle blocks you have IF you want it to cover everything (order of handle operations thing)
example.com {
# 🛡️ barrier wards
import /opt/barrier/wards/caddy/*
}
Make sure to validate and reload caddy for it to start working.
barrier bypass
If you've got some stuff that NEEDS to make it through (and exlcudes aren't enough), you can set barrier_bypass to 1 (or true) and the wards will ignore it
id.example.com {
# 🛡️ barrier wards
import /opt/barrier/wards/caddy/*
# pocketID bypass
@pocketid path /api/oidc/* /.well-known/*
vars @pocketid barrier_bypass 1
}
Other patterns work too. so header User-Agent *UptimeKuma* or remote_ip 10.0.0.0/8 would also bypass rules for those. Don't put vars line inside a handle it wont work. it needs to be at the site level (like example). Also needs caddy 2.6 or newer because of a weird var placeholder thing
cloudflare
Each ward in wards/cloudflare/ is a cloudflare formatted rule. In your dashboard, go to "Security > Security Rules", create a custom rule, switch to the expression editor, and paste the file contents all up in there. Set the action to "Block" and hit save. You need 1 rule per file. Generator is designed to keep each one under the 4000 character limit of the free tier
Congrats! You blocking real good.
P.S. - Make sure proxy (orange cloud) is on for DNS entries you're trying to block for. Rules don't work without it.
bunny.net
Wards in wards/bunny/ are 1 edge rule each, formatted for the bunny API. Edge rules only allow 5 conditions per rule so I had to be creative with the generator. It also uses lua patterns which was another hiccup. Anyway thats why there's a ton of files for bunny exclusively
These are meant to be CLI only. Doing it by hand is just not feasible (no expression editor)
barrier enable bunny [--zone 123,456]
barrier disable bunny [--zone 123,456]
barrier remove bunny [--zone 123,456]
If you don't add a zone arg, it'll just ask you. It also requires your bunny API key to do anything, which it will politely ask you for, and store in .local/bunny.key for future use
manual install (wards)
Pre-generated files live in wards/. If you want to just grab files and use them on your server, go ahead thats why they exist. There's stuff for cloudflare, nginx, caddy, and apache. Do whatever works for you
DISCLAIMER
While i've used this myself, its still technically an alpha (CLI not the wards themselves). So if something goes wrong or could be improved PLEEAASSEEE just open an issue for a suggestion or a bug. I don't need to cater to everyone but I do want it to work and be somewhat sane