docs(T3): mark nftables fix as applied + accepted

T3/A3 completed 2026-10-10: otreca nftables fix deployed via
nixos-rebuild switch. Verification on otreca:
  - nft list ruleset: policy drop + 5 explicit accepts
    (lo, established/related, ICMP, traceroute 33434-33534,
     SSH on tailscale0, Xray REALITY 443) + log+drop
  - iptables empty (no firewall.* shadow rules)
  - SSH via Tailscale: works (the deploy itself proves it)
  - Xray REALITY on 443: listening (sapphira → otreca XHTTP intact)

manifest.json T3 → completed with full notes.
.decisions/index.json T3-A proposal → accepted (status, files
updated to include configurations/vds.nix, notes with verification).

All 17 manifest tasks now resolved (1 truly deferred was T5 backups
risk — formalized as R1.9 in commit 3f5c048, marked completed
2026-10-10). T3 is the last code task — otreca config updated.

Working tree: clean after this commit.
This commit is contained in:
2026-10-10 16:52:09 +03:00
parent 3deaa75f5c
commit fafd3e2df7
2 changed files with 7 additions and 8 deletions
+5 -6
View File
@@ -27,16 +27,15 @@
{
"id": "T3-A",
"title": "nftables fix для otreca (R1.6: явная policy drop, убрать firewall/nftables конфликт, SSH только на tailscale0)",
"status": "proposed",
"date": "2026-10-09",
"status": "accepted",
"date": "2026-10-10",
"files": [
".agent/decisions/proposals/vds-nftables-fix.md"
".agent/decisions/proposals/vds-nftables-fix.md",
"configurations/vds.nix"
],
"tags": ["nftables", "vds", "otrecа", "security", "R1.6", "T3"],
"task": "T3",
"blocked_by": [
"user: SSH-доступ на otreca должен быть восстановлен до apply"
]
"notes": "Applied 2026-10-10 via nixos-rebuild switch on otreca. Verified live: nft list ruleset = policy drop + 5 accepts, iptables empty, SSH via Tailscale works, Xray REALITY on 443 listening."
}
]
}