- General improvements
- Parallel download of only needed files at start
- Prettier console output with all streams merged (openvpn, unbound, shadowsocks etc.)
- Simplified Docker final image
- Faster bootup
- DNS over TLS
- Finer grain blocking at DNS level: malicious, ads and surveillance
- Choose your DNS over TLS providers
- Ability to use multiple DNS over TLS providers for DNS split horizon
- Environment variables for DNS logging
- DNS block lists needed are downloaded and built automatically at start, in parallel
- PIA
- A random region is selected if the REGION parameter is left empty (thanks @rorph for your PR)
- Routing and iptables adjusted so it can work as a Kubernetes pod sidecar (thanks @rorph for your PR)
35 lines
909 B
Go
35 lines
909 B
Go
package settings
|
|
|
|
import (
|
|
"net"
|
|
"strings"
|
|
|
|
"github.com/qdm12/private-internet-access-docker/internal/params"
|
|
)
|
|
|
|
// Firewall contains settings to customize the firewall operation
|
|
type Firewall struct {
|
|
AllowedSubnets []net.IPNet
|
|
}
|
|
|
|
func (f *Firewall) String() string {
|
|
var allowedSubnets []string
|
|
for _, net := range f.AllowedSubnets {
|
|
allowedSubnets = append(allowedSubnets, net.String())
|
|
}
|
|
settingsList := []string{
|
|
"Firewall settings:",
|
|
"Allowed subnets: " + strings.Join(allowedSubnets, ", "),
|
|
}
|
|
return strings.Join(settingsList, "\n |--")
|
|
}
|
|
|
|
// GetFirewallSettings obtains firewall settings from environment variables using the params package.
|
|
func GetFirewallSettings(params params.ParamsReader) (settings Firewall, err error) {
|
|
settings.AllowedSubnets, err = params.GetExtraSubnets()
|
|
if err != nil {
|
|
return settings, err
|
|
}
|
|
return settings, nil
|
|
}
|