otreca vds: pin 3x-ui:v3.8.5 + nginx stream + ssh tailscale-only + patch-3xui-xray-config

This commit is contained in:
2026-10-04 04:47:33 +03:00
parent 543fcc61d9
commit b0191bc7d1
4 changed files with 190 additions and 7 deletions
+6 -1
View File
@@ -42,12 +42,17 @@
};
host.ssh.enable = true;
services.openssh.openFirewall = true;
# SSH is reachable only over Tailscale (not on the public internet).
# This otreca VDS is reached by deploy-rs and by oqyude over the
# tailnet, so exposing 22 to ens3 is pure attack surface.
services.openssh.openFirewall = false;
services.tailscale = {
enable = true;
openFirewall = true;
};
# Open port 22 only on the tailscale interface.
networking.firewall.interfaces.tailscale0.allowedTCPPorts = [ 22 ];
networking = {
nameservers = [
"1.1.1.1"