# ============================================================ # KahfGuard Critical Infrastructure — NEVER BLOCK # ============================================================ # # Subtracted from every router IP blocklist by scripts/ip_guards.py, on top # of lists/ip/allow.txt and the hard-coded RFC 6890 reserved space. # # This file is specifically about SELF-PRESERVATION, not policy. Everything # here is something a router needs in order to fetch its next list. Block any # of it and the router cannot download the correction — the failure is not # self-healing, it needs a truck roll. # # lists/ip/allow.txt is the operator allowlist (ISP forwarders, BDIX, dev # hosts). Keep the two separate: that one expresses "we choose not to filter # this", this one expresses "filtering this breaks the product". # # Entries are CIDR or bare address, one per line, with a trailing comment. # IPv4 and IPv6 may be mixed; the builder splits by family. # --- List distribution and control plane ------------------------------- # s3.kahf.co / kahf.co sit behind Cloudflare. These are the current A/AAAA # records; the builder also resolves S3_ENDPOINT at build time and adds # whatever it gets, so a Cloudflare IP rotation cannot strand a router. 104.21.78.17 # s3.kahf.co / kahf.co (Cloudflare) 172.67.214.132 # s3.kahf.co / kahf.co (Cloudflare) 2606:4700:3030::ac43:d684 # s3.kahf.co / kahf.co (Cloudflare) 2606:4700:3036::6815:4e11 # s3.kahf.co / kahf.co (Cloudflare) 157.180.4.107 # gitlab.kahf.co.uk (large1.kahf.co.uk, Hetzner) # --- Public DNS resolvers ---------------------------------------------- # Fallback resolution. If the router's own resolver is down or misconfigured # and these are blocked too, it has no way to resolve the list endpoint. # X4BNet's datacenter feed lists 8.8.8.0/24 as a datacenter range — that feed # is rejected for exactly this class of collision, and this entry is the # backstop if any future feed makes the same mistake. 1.1.1.1 # Cloudflare 1.0.0.1 # Cloudflare secondary 2606:4700:4700::1111 # Cloudflare IPv6 8.8.8.8 # Google Public DNS 8.8.4.4 # Google Public DNS secondary 2001:4860:4860::8888 # Google Public DNS IPv6 9.9.9.9 # Quad9 149.112.112.112 # Quad9 secondary 2620:fe::fe # Quad9 IPv6 208.67.222.222 # OpenDNS Family Shield — routers resolve through this 208.67.220.220 # OpenDNS Family Shield secondary 208.67.222.123 # OpenDNS FamilyShield 208.67.220.123 # OpenDNS FamilyShield secondary