diff options
| author | Jan Tuomi <jan@jantuomi.fi> | 2026-05-13 00:13:57 +0300 |
|---|---|---|
| committer | Jan Tuomi <jan@jantuomi.fi> | 2026-05-16 18:42:27 +0300 |
| commit | b5860daf11ac353049cb1654b9414a129e5cfb96 (patch) | |
| tree | 87ed89711e4f0e85ace0a97fa123199152c67302 /roles/host_prod/templates/usr_local_bin_safepf.sh | |
| parent | 4715a28fdcd87440400d17154bfa361d99db29cc (diff) | |
Rework
Diffstat (limited to 'roles/host_prod/templates/usr_local_bin_safepf.sh')
| -rw-r--r-- | roles/host_prod/templates/usr_local_bin_safepf.sh | 36 |
1 files changed, 36 insertions, 0 deletions
diff --git a/roles/host_prod/templates/usr_local_bin_safepf.sh b/roles/host_prod/templates/usr_local_bin_safepf.sh new file mode 100644 index 0000000..1b6efee --- /dev/null +++ b/roles/host_prod/templates/usr_local_bin_safepf.sh @@ -0,0 +1,36 @@ +#!/bin/sh + +set -eu + +cmd="pfctl -f /etc/pf.conf" +read -p "Run this command (y/n)? $cmd " answer +if [ "$answer" = "y" ]; then + (set -x; $cmd) +else + exit 0 +fi + +cmd="service pf restart" +read -p "Run this command (y/n)? $cmd " answer +if [ "$answer" = "y" ]; then + (set -x; $cmd) +else + exit 0 +fi + +timeout=60 +echo "Running safety timeout ($timeout seconds). Press CTRL-C if everything is working." +while [ $timeout -gt 0 ] +do + sleep 1 + timeout=$((timeout - 1)) + echo -n "." +done + +echo "Timeout reached. Enabling empty pf rules" + +set -x +mv /etc/pf.conf /etc/pf.conf.locked_out +echo "" > /etc/pf.conf +pfctl -f /etc/pf.conf +service pf restart |
