mirror of
https://github.com/oqyude/nixos.git
synced 2026-10-11 14:27:26 +03:00
fix(vds-nftables): open port 80 — ACME HTTP-01 challenge + nginx HTTP→HTTPS
Previous T3 fix (5796786) replaced the original SYN rate-limit
on {80,443} with explicit accepts for only 22 and 443. This
accidentally dropped port 80, which broke:
1. ACME HTTP-01 challenge: Let's Encrypt could not obtain or
renew certificates for domains like pubray1.zeroq.su. The
cert directory /var/lib/acme/ has no pubray1.zeroq.su/ entry,
confirming the cert was never obtained under the new ruleset.
2. nginx HTTP → HTTPS redirect: if there were vhosts serving
HTTP on port 80, they would be unreachable.
Original vds.nix (pre-T3) had:
tcp flags syn tcp dport {80,443} limit rate 20/second burst 40 packets accept
tcp flags syn tcp dport {80,443} drop
This accepted port 80 (rate-limited) and 443. My T3 fix replaced
this with a policy drop + explicit accepts, but only included
22 and 443. Port 80 was missing.
Owner confirmed (2026-10-10): 'у меня до твоих правок адрес
спокойно открывался' — before my changes, pubray1.zeroq.su
was opening fine. My T3 fix broke it by closing port 80.
Fix: add tcp dport 80 accept to the nftables ruleset.
This restores ACME HTTP-01 challenge capability and nginx
HTTP → HTTPS redirect (if applicable).
This commit is contained in:
@@ -119,6 +119,12 @@
|
||||
# SSH (22) — open on all interfaces (owner: no iifname restriction)
|
||||
tcp dport 22 accept
|
||||
|
||||
# HTTP (80) — needed for ACME HTTP-01 challenge (LE cert renewal)
|
||||
# and for HTTP → HTTPS redirect if nginx vhost is configured.
|
||||
# ADDED 2026-10-10: previous T3 fix accidentally dropped port 80,
|
||||
# breaking pubray1.zeroq.su cert renewal.
|
||||
tcp dport 80 accept
|
||||
|
||||
# Xray REALITY inbound (treca acts as relay from sapphira via XHTTP)
|
||||
tcp dport 443 accept
|
||||
|
||||
|
||||
Reference in New Issue
Block a user