mirror of
https://github.com/oqyude/nixos.git
synced 2026-10-11 14:27:26 +03:00
docs(T3): mark nftables fix as applied + accepted
T3/A3 completed 2026-10-10: otreca nftables fix deployed via
nixos-rebuild switch. Verification on otreca:
- nft list ruleset: policy drop + 5 explicit accepts
(lo, established/related, ICMP, traceroute 33434-33534,
SSH on tailscale0, Xray REALITY 443) + log+drop
- iptables empty (no firewall.* shadow rules)
- SSH via Tailscale: works (the deploy itself proves it)
- Xray REALITY on 443: listening (sapphira → otreca XHTTP intact)
manifest.json T3 → completed with full notes.
.decisions/index.json T3-A proposal → accepted (status, files
updated to include configurations/vds.nix, notes with verification).
All 17 manifest tasks now resolved (1 truly deferred was T5 backups
risk — formalized as R1.9 in commit 3f5c048, marked completed
2026-10-10). T3 is the last code task — otreca config updated.
Working tree: clean after this commit.
This commit is contained in:
@@ -27,16 +27,15 @@
|
|||||||
{
|
{
|
||||||
"id": "T3-A",
|
"id": "T3-A",
|
||||||
"title": "nftables fix для otreca (R1.6: явная policy drop, убрать firewall/nftables конфликт, SSH только на tailscale0)",
|
"title": "nftables fix для otreca (R1.6: явная policy drop, убрать firewall/nftables конфликт, SSH только на tailscale0)",
|
||||||
"status": "proposed",
|
"status": "accepted",
|
||||||
"date": "2026-10-09",
|
"date": "2026-10-10",
|
||||||
"files": [
|
"files": [
|
||||||
".agent/decisions/proposals/vds-nftables-fix.md"
|
".agent/decisions/proposals/vds-nftables-fix.md",
|
||||||
|
"configurations/vds.nix"
|
||||||
],
|
],
|
||||||
"tags": ["nftables", "vds", "otrecа", "security", "R1.6", "T3"],
|
"tags": ["nftables", "vds", "otrecа", "security", "R1.6", "T3"],
|
||||||
"task": "T3",
|
"task": "T3",
|
||||||
"blocked_by": [
|
"notes": "Applied 2026-10-10 via nixos-rebuild switch on otreca. Verified live: nft list ruleset = policy drop + 5 accepts, iptables empty, SSH via Tailscale works, Xray REALITY on 443 listening."
|
||||||
"user: SSH-доступ на otreca должен быть восстановлен до apply"
|
|
||||||
]
|
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -50,7 +50,7 @@
|
|||||||
"id": "T3",
|
"id": "T3",
|
||||||
"title": "A3: явная финальная политика nftables на VDS",
|
"title": "A3: явная финальная политика nftables на VDS",
|
||||||
"type": "fix",
|
"type": "fix",
|
||||||
"status": "pending",
|
"status": "completed",
|
||||||
"origin": "user:direct",
|
"origin": "user:direct",
|
||||||
"depends_on": [],
|
"depends_on": [],
|
||||||
"acceptance_criteria": [
|
"acceptance_criteria": [
|
||||||
@@ -60,7 +60,7 @@
|
|||||||
],
|
],
|
||||||
"files": ["configurations/vds.nix"],
|
"files": ["configurations/vds.nix"],
|
||||||
"blocks": ["T11", "T12"],
|
"blocks": ["T11", "T12"],
|
||||||
"notes": "Apply deferred: требуется SSH на otreca (100.64.1.0 Tailscale и 109.248.161.5:22 оба timeout на 2026-10-10). VDS-провайдер должен восстановить доступ через KVM/IPMI/serial console. Proposal Option A в .agent/decisions/proposals/vds-nftables-fix.md готов к apply. До восстановления SSH — только README-уровень."
|
"notes": "Apply done 2026-10-10 (Tailscale на otreca восстановился). Option A из .agent/decisions/proposals/vds-nftables-fix.md: firewall.enable=false (R1.6 conflict resolved), lib.mkForce на allowedTCPPorts/interfaces, nftables chain input с policy drop + 5 explicit accepts (lo, established/related, ICMP, traceroute 33434-33534, SSH on tailscale0, Xray REALITY 443) + log+drop. Verified live: nft list ruleset показывает все правила, iptables пуст (нет shadow rules), SSH через Tailscale работает, Xray на 443 слушает. 2 коммита: 5796786 (основной fix) + 3deaa75 (fix allowPing — не существует на top-level networking когда firewall off)."
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"id": "T4",
|
"id": "T4",
|
||||||
|
|||||||
Reference in New Issue
Block a user