Skip to content

Instantly share code, notes, and snippets.

View sepsemi's full-sized avatar
💭
Buzz Buzz

semsepi sepsemi

💭
Buzz Buzz
View GitHub Profile
@sepsemi
sepsemi / torrc
Created January 19, 2021 17:13
A Generic torrc configuration
ClientOnly 1
ExitRelay 0
RunAsDaemon 1
StrictNodes 1
SocksPort 0.0.0.0:9050
SocksPolicy accept 0.0.0.0/24
DataDirectory /var/lib/tor
# misc
@sepsemi
sepsemi / base.sh
Created January 17, 2021 09:09
Full disk encryption using luks 1 and lvm encrypt /boot and make a keyfile to avoid double password partiton scheme seperated (/var, /tmp /home, swap) )
#!/bin/sh
PRE_INSTALL_PKG_LIST="parted"
POST_INSTALL_PKG_LIST="parted grub cryptsetup lvm2 zsh nano runit elogind-runit linux linux-firmware"
STATIC_SIZE_ROOT=50G
STATIC_SIZE_VAR=20G
STATIC_SIZE_TMP=5G
STATIC_SIZE_SWAP=8G
STATIC_DISK="/dev/sda"
STATIC_LUKS_PASSWORD='toor'
@sepsemi
sepsemi / stubby.yml
Last active September 24, 2025 20:27
Dns over tls (unbound + stubby)
resolution_type: GETDNS_RESOLUTION_STUB
round_robin_upstreams: 1
tls_authentication: GETDNS_AUTHENTICATION_REQUIRED
tls_query_padding_blocksize: 256
edns_client_subnet_private: 1
idle_timeout: 9000
listen_addresses:
- 127.0.0.1@8053
- 0::1@8053
dns_transport_list: