Skip to content

Serve randomized decoy sites with robots.txt - #2

Merged
andre487 merged 5 commits into
mainfrom
feat/randomized-decoy-robots
Oct 5, 2026
Merged

andre487 merged 5 commits into
mainfrom
feat/randomized-decoy-robots

Conversation

@andre487

@andre487 andre487 commented Oct 5, 2026 •

Copy link
Copy Markdown
Owner

Masked HTTPS routes now serve a static site through GOST's built-in loopback file server, including /robots.txt with Disallow: / and HTML noindex,nofollow. A standard-library Python script generates a random heading and abstract SVG once; repeated Ansible runs preserve the site. Knock and authenticated proxy traffic retain their existing behavior.

Verification uses public route metadata so route-specific masking is checked without logging chain credentials. Includes generation tests and regeneration instructions. One-time migration commands and private inventory are excluded.

Validation:

  • 55 tests passed; Ruff, compilation, and all Ansible syntax checks passed.
  • Applied to four masked hosts; verified pages, SVG, robots.txt on all chain domains, knock, and authenticated CONNECT. A repeated apply on px-ru made zero changes.
  • All six chains passed exit-IP requests. Full verification remains limited by five unchanged direct exit proxies returning HTTP 407 with inventory user credentials.

Host provisioning now runs both Ubuntu 24.04 and Debian 12 two-host Jump on every PR and push, including main. Workflow YAML and event/job conditions were validated locally.

SSH configuration validation handlers now trigger their reload notifications after successful validation. A runnable Ansible regression test covers both admin and proxy handlers (56 local tests passed). The two-host CI test shares SSH identity/known-host settings with ProxyJump and no longer manually reloads SSH before testing, so unapplied configuration cannot be masked.

@andre487
andre487 merged commit ebf4b91 into main Oct 5, 2026
8 of 10 checks passed
@andre487
andre487 deleted the feat/randomized-decoy-robots branch October 5, 2026 15:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant