acl localnet src 0.0.0.1-0.255.255.255 acl localnet src 10.0.0.0/8 acl localnet src 100.64.0.0/10 acl localnet src 169.254.0.0/16 acl localnet src 172.16.0.0/12 acl localnet src 192.168.0.0/16 acl localnet src fc00::/7 acl localnet src fe80::/10 acl SSL_ports port 443 acl Safe_ports port 80 acl Safe_ports port 21 acl Safe_ports port 443 acl Safe_ports port 70 acl Safe_ports port 210 acl Safe_ports port 1025-65535 acl Safe_ports port 280 acl Safe_ports port 488 acl Safe_ports port 591 acl Safe_ports port 777 http_access deny !Safe_ports http_access deny CONNECT !SSL_ports http_access allow localhost manager http_access deny manager http_access allow localnet http_access allow localhost http_access deny all http_port 3128 ssl-bump \ cert=/certs/ca/cert.pem key=/certs/ca/key.pem \ generate-host-certificates=on dynamic_cert_mem_cache_size=4MB cache_dir aufs /var/cache/squid 200000 16 256 coredump_dir /var/cache/squid maximum_object_size 8 GB maximum_object_size_in_memory 4 MB refresh_pattern ^ftp: 1440 20% 10080 refresh_pattern ^gopher: 1440 0% 1440 refresh_pattern -i (/cgi-bin/|\?) 0 0% 0 refresh_pattern (Release|Packages)(\.[zZ]|\.gz|\.bz2?|\.xz|\.zstd?)?$ 15 100% 129600 override-expire ignore-no-cache reload-into-ims refresh_pattern /repomd\.xml(\.asc|\.metalink)?(\.[zZ]|\.gz|\.bz2?|\.xz|\.zstd?)?$ 15 100% 129600 override-expire ignore-no-cache reload-into-ims refresh_pattern /APKINDEX\.tar(\.[zZ]|\.gz|\.bz2?|\.xz|\.zstd?)?$ 15 100% 129600 override-expire ignore-no-cache reload-into-ims refresh_pattern \.u?deb$ 129600 100% 129600 refresh_pattern \.rpm$ 129600 100% 129600 refresh_pattern \.apk$ 129600 100% 129600 refresh_pattern \.(tar|iso)(\.[zZ]|\.gz|\.bz2?|\.xz|\.zstd?)?(\.sig)?$ 129600 100% 129600 refresh_pattern . 0 20% 4320 url_rewrite_children 4 startup=1 idle=1 concurrency=5 url_rewrite_program /usr/bin/nc -q 0 127.0.0.1 7777 store_id_children 4 startup=1 idle=1 concurrency=5 store_id_program /usr/bin/nc -q 0 127.0.0.1 7777 sslcrtd_program /usr/lib/squid/security_file_certgen -s /certs/ssl_db -M 4MB acl step1 at_step SslBump1 ssl_bump peek step1 ssl_bump bump all logfile_rotate 0 cache_log syslog:daemon.info squid access_log syslog:daemon.info squid