mirror of
https://github.com/oqyude/nixos.git
synced 2026-10-11 22:37:25 +03:00
revert(vds-nftables): restore original config — T3 fix needs discussion
Owner request 2026-10-10: 'отмени вообще правки файрволла, верни пока какие были до твоих работ. это требует обсуждения, потому что по прежнему ничего не работает, сайт не открывается, reality не работает.' This reverts 5 T3 code commits + 2 T3 doc commits:5796786fix(vds-nftables): apply Option A3deaa75fix(vds-nftables): remove allowPing4dc4849fix(vds-nftables): open SSH on all interfaces2649e2ffix(vds-nftables): open port 8051ea19afix(vds-nftables): open port 8443677d39edocs(T3): note correctionfafd3e2docs(T3): mark nftables fix as applied Restored: - configurations/vds.nix → original from61b3724(firewall.enable = true, firewall.interfaces.tailscale0.allowedTCPPorts = [22], nftables with SYN rate-limit on {80,443}) - .agent/tasks/manifest.json T3 → status = 'pending' (was 'completed') - .agent/decisions/index.json T3-A → status = 'proposed' (was 'accepted') The proposal .agent/decisions/proposals/vds-nftables-fix.md is NOT removed — it's still a proposal for future discussion, just not applied. nft list ruleset on otreca will return to the original (firewall-managed) state after rebuild. T3 needs proper discussion with owner before re-applying. The issues observed (site not opening, reality not working) need diagnostic before any new fix attempt.
This commit is contained in:
@@ -27,15 +27,16 @@
|
|||||||
{
|
{
|
||||||
"id": "T3-A",
|
"id": "T3-A",
|
||||||
"title": "nftables fix для otreca (R1.6: явная policy drop, убрать firewall/nftables конфликт, SSH только на tailscale0)",
|
"title": "nftables fix для otreca (R1.6: явная policy drop, убрать firewall/nftables конфликт, SSH только на tailscale0)",
|
||||||
"status": "accepted",
|
"status": "proposed",
|
||||||
"date": "2026-10-10",
|
"date": "2026-10-09",
|
||||||
"files": [
|
"files": [
|
||||||
".agent/decisions/proposals/vds-nftables-fix.md",
|
".agent/decisions/proposals/vds-nftables-fix.md"
|
||||||
"configurations/vds.nix"
|
|
||||||
],
|
],
|
||||||
"tags": ["nftables", "vds", "otrecа", "security", "R1.6", "T3"],
|
"tags": ["nftables", "vds", "otrecа", "security", "R1.6", "T3"],
|
||||||
"task": "T3",
|
"task": "T3",
|
||||||
"notes": "Applied 2026-10-10 via nixos-rebuild switch on otreca. Verified live: nft list ruleset = policy drop + 5 accepts, iptables empty, SSH via Tailscale works, Xray REALITY on 443 listening."
|
"blocked_by": [
|
||||||
|
"user: SSH-доступ на otreca должен быть восстановлен до apply"
|
||||||
|
]
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -50,7 +50,7 @@
|
|||||||
"id": "T3",
|
"id": "T3",
|
||||||
"title": "A3: явная финальная политика nftables на VDS",
|
"title": "A3: явная финальная политика nftables на VDS",
|
||||||
"type": "fix",
|
"type": "fix",
|
||||||
"status": "completed",
|
"status": "pending",
|
||||||
"origin": "user:direct",
|
"origin": "user:direct",
|
||||||
"depends_on": [],
|
"depends_on": [],
|
||||||
"acceptance_criteria": [
|
"acceptance_criteria": [
|
||||||
@@ -60,7 +60,7 @@
|
|||||||
],
|
],
|
||||||
"files": ["configurations/vds.nix"],
|
"files": ["configurations/vds.nix"],
|
||||||
"blocks": ["T11", "T12"],
|
"blocks": ["T11", "T12"],
|
||||||
"notes": "Applied 2026-10-10. 3 коммита: 5796786 (initial fix) + 3deaa75 (fix allowPing) + 4dc4849 (CORRECTION: removed iifname \"tailscale0\" restriction on SSH — owner said 'не помню, чтобы просил ограничивать 22 порт'. SSH now on all interfaces). Final ruleset: policy drop + 6 accepts (lo, established/related, ICMP, traceroute 33434-33534, SSH 22 on all interfaces, Xray REALITY 443) + log+drop. firewall.enable = false (R1.6 conflict resolved). lib.mkForce on allowedTCPPorts/interfaces prevents shadow rules. Verified live 2026-10-10: nft list shows policy drop + all 6 accepts, public SSH (109.248.161.5:22) works, Tailscale SSH (100.64.1.0:22) works, Xray 443 listening."
|
"notes": "REVERTED 2026-10-10: owner requested revert of all T3 firewall changes. 'по прежнему ничего не работает, сайт не открывается, reality не работает. это требует обсуждения.' Original vds.nix restored (commit 61b3724 baseline). 5 T3 commits reverted: 5796786, 3deaa75, 4dc4849, 2649e2f, 51ea19a + docs 677d39e, fafd3e2. Requires discussion before re-applying."
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"id": "T4",
|
"id": "T4",
|
||||||
|
|||||||
+13
-64
@@ -2,23 +2,6 @@
|
|||||||
#
|
#
|
||||||
# The host record lives in configurations/default.nix; this file is only the
|
# The host record lives in configurations/default.nix; this file is only the
|
||||||
# module body. `xlib` (identity, dirs, helpers) arrives as a module argument.
|
# module body. `xlib` (identity, dirs, helpers) arrives as a module argument.
|
||||||
#
|
|
||||||
# T3 FIX (minimal, R1.6 only) 2026-10-10:
|
|
||||||
# - Explicit `policy drop` on chain input (R1.6 fix — original ruleset
|
|
||||||
# had no policy, so it was implicit accept)
|
|
||||||
# - Removed `firewall.enable = true` to eliminate the
|
|
||||||
# `firewall.*` + `nftables.*` conflict (R1.6)
|
|
||||||
# - SSH (22) open on ALL interfaces (no iifname restriction)
|
|
||||||
# - Xray REALITY (443) open
|
|
||||||
# - ICMP + traceroute (33434-33534) for diagnostics
|
|
||||||
# - 80/HTTP closed by default
|
|
||||||
# - Log + drop at the end (nft-drop: prefix) for diagnostics
|
|
||||||
#
|
|
||||||
# CORRECTED 2026-10-10: removed `iifname "tailscale0"` restriction on
|
|
||||||
# SSH — owner did not ask for that. SSH is open on ens3 too.
|
|
||||||
#
|
|
||||||
# On otreca: management via Tailscale OR public SSH. Public attack
|
|
||||||
# surface is SSH (22) + Xray REALITY (443).
|
|
||||||
{
|
{
|
||||||
lib,
|
lib,
|
||||||
modulesPath,
|
modulesPath,
|
||||||
@@ -59,21 +42,17 @@
|
|||||||
};
|
};
|
||||||
|
|
||||||
host.ssh.enable = true;
|
host.ssh.enable = true;
|
||||||
# SSH is reachable on all interfaces (public + Tailscale). The
|
# SSH is reachable only over Tailscale (not on the public internet).
|
||||||
# nftables ruleset below opens 22 explicitly. `openFirewall = false`
|
# This otreca VDS is reached by deploy-rs and by oqyude over the
|
||||||
# because we manage the firewall via nftables, not the NixOS
|
# tailnet, so exposing 22 to ens3 is pure attack surface.
|
||||||
# firewall module (see `firewall.enable = false` further down).
|
|
||||||
services.openssh.openFirewall = false;
|
services.openssh.openFirewall = false;
|
||||||
|
|
||||||
services.tailscale = {
|
services.tailscale = {
|
||||||
enable = true;
|
enable = true;
|
||||||
openFirewall = true;
|
openFirewall = true;
|
||||||
};
|
};
|
||||||
# REMOVED 2026-10-10: networking.firewall.interfaces.tailscale0.allowedTCPPorts = [ 22 ].
|
# Open port 22 only on the tailscale interface.
|
||||||
# SSH is now opened on ALL interfaces via the nftables ruleset below
|
networking.firewall.interfaces.tailscale0.allowedTCPPorts = [ 22 ];
|
||||||
# (`tcp dport 22 accept` — no iifname restriction).
|
|
||||||
# Owner corrected: "не помню, чтобы просил ограничивать 22 порт".
|
|
||||||
|
|
||||||
networking = {
|
networking = {
|
||||||
nameservers = [
|
nameservers = [
|
||||||
"1.1.1.1"
|
"1.1.1.1"
|
||||||
@@ -85,24 +64,16 @@
|
|||||||
enable = true;
|
enable = true;
|
||||||
IPv6rs = false;
|
IPv6rs = false;
|
||||||
};
|
};
|
||||||
# T3 (R1.6 fix): `firewall.enable = false` eliminates the
|
firewall = {
|
||||||
# `firewall.*` + `nftables.*` conflict. The `lib.mkForce` on
|
enable = true;
|
||||||
# `allowedTCPPorts` and `interfaces` prevents the NixOS firewall
|
allowPing = true;
|
||||||
# module from silently injecting rules that would shadow our
|
};
|
||||||
# nftables ruleset. All filtering is now done by the ruleset below.
|
|
||||||
firewall.enable = false;
|
|
||||||
firewall.allowedTCPPorts = lib.mkForce [ ];
|
|
||||||
firewall.interfaces = lib.mkForce { };
|
|
||||||
# `networking.allowPing` was removed because with firewall.enable = false
|
|
||||||
# it no longer exists as a top-level option. ICMP accept is handled
|
|
||||||
# by the nftables ruleset below (`ip protocol icmp accept`).
|
|
||||||
nftables = {
|
nftables = {
|
||||||
enable = true;
|
enable = true;
|
||||||
ruleset = ''
|
ruleset = ''
|
||||||
table inet filter {
|
table inet filter {
|
||||||
chain input {
|
chain input {
|
||||||
type filter hook input priority 0;
|
type filter hook input priority 0;
|
||||||
policy drop;
|
|
||||||
|
|
||||||
# loopback
|
# loopback
|
||||||
iif lo accept
|
iif lo accept
|
||||||
@@ -110,33 +81,11 @@
|
|||||||
# уже установленные
|
# уже установленные
|
||||||
ct state established,related accept
|
ct state established,related accept
|
||||||
|
|
||||||
# ICMP (path MTU discovery + diagnostics)
|
# РЕЖЕМ SYN СРАЗУ
|
||||||
ip protocol icmp accept
|
tcp flags syn tcp dport {80,443} limit rate 20/second burst 40 packets accept
|
||||||
|
tcp flags syn tcp dport {80,443} drop
|
||||||
|
|
||||||
# traceroute
|
# остальное по необходимости
|
||||||
udp dport 33434-33534 accept
|
|
||||||
|
|
||||||
# SSH (22) — open on all interfaces (owner: no iifname restriction)
|
|
||||||
tcp dport 22 accept
|
|
||||||
|
|
||||||
# HTTP (80) — needed for ACME HTTP-01 challenge (LE cert renewal)
|
|
||||||
# and for HTTP → HTTPS redirect if nginx vhost is configured.
|
|
||||||
# ADDED 2026-10-10: previous T3 fix accidentally dropped port 80,
|
|
||||||
# breaking pubray1.zeroq.su cert renewal.
|
|
||||||
tcp dport 80 accept
|
|
||||||
|
|
||||||
# Xray REALITY inbound (treca acts as relay from sapphira via XHTTP)
|
|
||||||
tcp dport 443 accept
|
|
||||||
|
|
||||||
# 3x-ui Xray REALITY inbound on container (0.0.0.0:8443:8443 in
|
|
||||||
# modules/containers/3x-ui.nix). Direct public mapping — NOT
|
|
||||||
# proxied through nginx (that was `reality443Forwarding`,
|
|
||||||
# погашен в T10). ADDED 2026-10-10: previous T3 fix missed
|
|
||||||
# this port, Xray was unreachable from outside.
|
|
||||||
tcp dport 8443 accept
|
|
||||||
|
|
||||||
# log for diagnostics (journalctl -k | grep nft-drop)
|
|
||||||
log prefix "nft-drop: " flags all counter drop
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
'';
|
'';
|
||||||
|
|||||||
Reference in New Issue
Block a user