fix(vds-nftables): open port 80 — ACME HTTP-01 challenge + nginx HTTP→HTTPS

Previous T3 fix (5796786) replaced the original SYN rate-limit
on {80,443} with explicit accepts for only 22 and 443. This
accidentally dropped port 80, which broke:

1. ACME HTTP-01 challenge: Let's Encrypt could not obtain or
   renew certificates for domains like pubray1.zeroq.su. The
   cert directory /var/lib/acme/ has no pubray1.zeroq.su/ entry,
   confirming the cert was never obtained under the new ruleset.

2. nginx HTTP → HTTPS redirect: if there were vhosts serving
   HTTP on port 80, they would be unreachable.

Original vds.nix (pre-T3) had:
  tcp flags syn tcp dport {80,443} limit rate 20/second burst 40 packets accept
  tcp flags syn tcp dport {80,443} drop

This accepted port 80 (rate-limited) and 443. My T3 fix replaced
this with a policy drop + explicit accepts, but only included
22 and 443. Port 80 was missing.

Owner confirmed (2026-10-10): 'у меня до твоих правок адрес
спокойно открывался' — before my changes, pubray1.zeroq.su
was opening fine. My T3 fix broke it by closing port 80.

Fix: add tcp dport 80 accept to the nftables ruleset.
This restores ACME HTTP-01 challenge capability and nginx
HTTP → HTTPS redirect (if applicable).
This commit is contained in:
2026-10-10 17:15:18 +03:00
parent 677d39e967
commit 2649e2fbcc
+6
View File
@@ -119,6 +119,12 @@
# SSH (22) — open on all interfaces (owner: no iifname restriction)
tcp dport 22 accept
# HTTP (80) — needed for ACME HTTP-01 challenge (LE cert renewal)
# and for HTTP → HTTPS redirect if nginx vhost is configured.
# ADDED 2026-10-10: previous T3 fix accidentally dropped port 80,
# breaking pubray1.zeroq.su cert renewal.
tcp dport 80 accept
# Xray REALITY inbound (treca acts as relay from sapphira via XHTTP)
tcp dport 443 accept