mirror of
https://github.com/oqyude/nixos.git
synced 2026-10-11 14:27:26 +03:00
revert(vds-nftables): restore original config — T3 fix needs discussion
Owner request 2026-10-10: 'отмени вообще правки файрволла, верни пока какие были до твоих работ. это требует обсуждения, потому что по прежнему ничего не работает, сайт не открывается, reality не работает.' This reverts 5 T3 code commits + 2 T3 doc commits:5796786fix(vds-nftables): apply Option A3deaa75fix(vds-nftables): remove allowPing4dc4849fix(vds-nftables): open SSH on all interfaces2649e2ffix(vds-nftables): open port 8051ea19afix(vds-nftables): open port 8443677d39edocs(T3): note correctionfafd3e2docs(T3): mark nftables fix as applied Restored: - configurations/vds.nix → original from61b3724(firewall.enable = true, firewall.interfaces.tailscale0.allowedTCPPorts = [22], nftables with SYN rate-limit on {80,443}) - .agent/tasks/manifest.json T3 → status = 'pending' (was 'completed') - .agent/decisions/index.json T3-A → status = 'proposed' (was 'accepted') The proposal .agent/decisions/proposals/vds-nftables-fix.md is NOT removed — it's still a proposal for future discussion, just not applied. nft list ruleset on otreca will return to the original (firewall-managed) state after rebuild. T3 needs proper discussion with owner before re-applying. The issues observed (site not opening, reality not working) need diagnostic before any new fix attempt.
This commit is contained in:
@@ -27,15 +27,16 @@
|
||||
{
|
||||
"id": "T3-A",
|
||||
"title": "nftables fix для otreca (R1.6: явная policy drop, убрать firewall/nftables конфликт, SSH только на tailscale0)",
|
||||
"status": "accepted",
|
||||
"date": "2026-10-10",
|
||||
"status": "proposed",
|
||||
"date": "2026-10-09",
|
||||
"files": [
|
||||
".agent/decisions/proposals/vds-nftables-fix.md",
|
||||
"configurations/vds.nix"
|
||||
".agent/decisions/proposals/vds-nftables-fix.md"
|
||||
],
|
||||
"tags": ["nftables", "vds", "otrecа", "security", "R1.6", "T3"],
|
||||
"task": "T3",
|
||||
"notes": "Applied 2026-10-10 via nixos-rebuild switch on otreca. Verified live: nft list ruleset = policy drop + 5 accepts, iptables empty, SSH via Tailscale works, Xray REALITY on 443 listening."
|
||||
"blocked_by": [
|
||||
"user: SSH-доступ на otreca должен быть восстановлен до apply"
|
||||
]
|
||||
}
|
||||
]
|
||||
}
|
||||
|
||||
@@ -50,7 +50,7 @@
|
||||
"id": "T3",
|
||||
"title": "A3: явная финальная политика nftables на VDS",
|
||||
"type": "fix",
|
||||
"status": "completed",
|
||||
"status": "pending",
|
||||
"origin": "user:direct",
|
||||
"depends_on": [],
|
||||
"acceptance_criteria": [
|
||||
@@ -60,7 +60,7 @@
|
||||
],
|
||||
"files": ["configurations/vds.nix"],
|
||||
"blocks": ["T11", "T12"],
|
||||
"notes": "Applied 2026-10-10. 3 коммита: 5796786 (initial fix) + 3deaa75 (fix allowPing) + 4dc4849 (CORRECTION: removed iifname \"tailscale0\" restriction on SSH — owner said 'не помню, чтобы просил ограничивать 22 порт'. SSH now on all interfaces). Final ruleset: policy drop + 6 accepts (lo, established/related, ICMP, traceroute 33434-33534, SSH 22 on all interfaces, Xray REALITY 443) + log+drop. firewall.enable = false (R1.6 conflict resolved). lib.mkForce on allowedTCPPorts/interfaces prevents shadow rules. Verified live 2026-10-10: nft list shows policy drop + all 6 accepts, public SSH (109.248.161.5:22) works, Tailscale SSH (100.64.1.0:22) works, Xray 443 listening."
|
||||
"notes": "REVERTED 2026-10-10: owner requested revert of all T3 firewall changes. 'по прежнему ничего не работает, сайт не открывается, reality не работает. это требует обсуждения.' Original vds.nix restored (commit 61b3724 baseline). 5 T3 commits reverted: 5796786, 3deaa75, 4dc4849, 2649e2f, 51ea19a + docs 677d39e, fafd3e2. Requires discussion before re-applying."
|
||||
},
|
||||
{
|
||||
"id": "T4",
|
||||
|
||||
Reference in New Issue
Block a user