Skip to content
#

origin-security

Here is 1 public repository matching this topic...

A self-contained hardening script for Debian/Ubuntu/windows servers that only allows HTTP(S) traffic from Cloudflare's official IP ranges. It fetches Cloudflare's latest CIDR lists, writes nftables sets, and keeps the configuration transactional so you can safely apply, update, or roll back with a single command.

  • Updated Jan 28, 2026
  • Shell

Improve this page

Add a description, image, and links to the origin-security topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the origin-security topic, visit your repo's landing page and select "manage topics."

Learn more