From 51ea19aef468ac394be4c4466b9bb6241edb1109 Mon Sep 17 00:00:00 2001 From: oqyude Date: Sat, 10 Oct 2026 17:19:33 +0300 Subject: [PATCH] =?UTF-8?q?fix(vds-nftables):=20open=20port=208443=20?= =?UTF-8?q?=E2=80=94=203x-ui=20Xray=20REALITY=20inbound?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Previous T3 fix missed port 8443. In modules/containers/3x-ui.nix, the 3x-ui container's Xray REALITY inbound is mapped directly to host port 8443: basePorts = [ '127.0.0.1:2049:2049/tcp' # panel '127.0.0.1:2096:2096/tcp' # subscription '0.0.0.0:8443:8443/tcp' # Xray REALITY inbound ]; This is a DIRECT public mapping (0.0.0.0, not localhost), not proxied through nginx. The 'reality443Forwarding' option (погашен в T10) was a separate mechanism that forwarded host:443 → 127.0.0.1:15380 → container:443 via nginx stream. After T10, the nginx stream is removed. Xray is now ONLY on host port 8443 (direct mapping). Port 443 in the nftables ruleset is still open but not used by Xray — it was only used through the stream mechanism (now removed). Owner confirmation 2026-10-10: 'нужен 8443 порт для 3x-ui inbound'. Fix: add 'tcp dport 8443 accept' to the nftables ruleset. Xray REALITY is now reachable on: - 8443 (direct, always was the primary) - 443 (only if nginx vhost proxies to container, not the case here) --- configurations/vds.nix | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/configurations/vds.nix b/configurations/vds.nix index f45a4d9..06abf45 100644 --- a/configurations/vds.nix +++ b/configurations/vds.nix @@ -128,6 +128,13 @@ # Xray REALITY inbound (treca acts as relay from sapphira via XHTTP) tcp dport 443 accept + # 3x-ui Xray REALITY inbound on container (0.0.0.0:8443:8443 in + # modules/containers/3x-ui.nix). Direct public mapping — NOT + # proxied through nginx (that was `reality443Forwarding`, + # погашен в T10). ADDED 2026-10-10: previous T3 fix missed + # this port, Xray was unreachable from outside. + tcp dport 8443 accept + # log for diagnostics (journalctl -k | grep nft-drop) log prefix "nft-drop: " flags all counter drop }