Commit Graph
15 Commits
Author SHA1 Message Date
oqyude 51ea19aef4 fix(vds-nftables): open port 8443 — 3x-ui Xray REALITY inbound
Previous T3 fix missed port 8443. In modules/containers/3x-ui.nix,
the 3x-ui container's Xray REALITY inbound is mapped directly
to host port 8443:

  basePorts = [
    '127.0.0.1:2049:2049/tcp'  # panel
    '127.0.0.1:2096:2096/tcp'  # subscription
    '0.0.0.0:8443:8443/tcp'     # Xray REALITY inbound
  ];

This is a DIRECT public mapping (0.0.0.0, not localhost), not
proxied through nginx. The 'reality443Forwarding' option
(погашен в T10) was a separate mechanism that forwarded host:443
→ 127.0.0.1:15380 → container:443 via nginx stream.

After T10, the nginx stream is removed. Xray is now ONLY on
host port 8443 (direct mapping). Port 443 in the nftables
ruleset is still open but not used by Xray — it was only used
through the stream mechanism (now removed).

Owner confirmation 2026-10-10: 'нужен 8443 порт для 3x-ui inbound'.

Fix: add 'tcp dport 8443 accept' to the nftables ruleset.
Xray REALITY is now reachable on:
  - 8443 (direct, always was the primary)
  - 443 (only if nginx vhost proxies to container, not the case here)
2026-10-10 17:19:33 +03:00
oqyude 2649e2fbcc fix(vds-nftables): open port 80 — ACME HTTP-01 challenge + nginx HTTP→HTTPS
Previous T3 fix (5796786) replaced the original SYN rate-limit
on {80,443} with explicit accepts for only 22 and 443. This
accidentally dropped port 80, which broke:

1. ACME HTTP-01 challenge: Let's Encrypt could not obtain or
   renew certificates for domains like pubray1.zeroq.su. The
   cert directory /var/lib/acme/ has no pubray1.zeroq.su/ entry,
   confirming the cert was never obtained under the new ruleset.

2. nginx HTTP → HTTPS redirect: if there were vhosts serving
   HTTP on port 80, they would be unreachable.

Original vds.nix (pre-T3) had:
  tcp flags syn tcp dport {80,443} limit rate 20/second burst 40 packets accept
  tcp flags syn tcp dport {80,443} drop

This accepted port 80 (rate-limited) and 443. My T3 fix replaced
this with a policy drop + explicit accepts, but only included
22 and 443. Port 80 was missing.

Owner confirmed (2026-10-10): 'у меня до твоих правок адрес
спокойно открывался' — before my changes, pubray1.zeroq.su
was opening fine. My T3 fix broke it by closing port 80.

Fix: add tcp dport 80 accept to the nftables ruleset.
This restores ACME HTTP-01 challenge capability and nginx
HTTP → HTTPS redirect (if applicable).
2026-10-10 17:15:18 +03:00
oqyude 4dc4849d71 fix(vds-nftables): open SSH on all interfaces, not just tailscale0
Owner correction 2026-10-10: "не помню, чтобы просил ограничивать
22 порт". The previous T3 fix (5796786) restricted SSH to
iifname "tailscale0" based on a comment in the original vds.nix
that said "SSH is reachable only over Tailscale". The owner
did not actually request this restriction.

This commit:
- Changes  to
   (all interfaces, no iifname filter)
- Removes the  reference
- Updates comments to reflect the actual owner intent
  (SSH open everywhere, managed via nftables)
- Keeps the core R1.6 fix: explicit  on chain
  input, no firewall.* + nftables.* conflict (firewall.enable = false
  with lib.mkForce on shadow rules)
- Keeps Xray REALITY (443), ICMP, traceroute, log+drop
- Keeps port 80 closed (no nginx on otreca)

SSH on otreca is now reachable on:
  - Tailscale IP (100.64.1.0 or whatever current)
  - Public IP (109.248.161.5) on ens3
  - Any loopback

Deployment: otreca rebuild + nft verify.
2026-10-10 17:08:15 +03:00
oqyude 3deaa75f5c fix(vds-nftables): remove allowPing — not a top-level networking option
networking.allowPing was a top-level networking option when
firewall.enable = true. With firewall.enable = false (T3 Option A),
the option no longer exists at the networking level. ICMP is now
handled by the nftables ruleset directly
().

Rebuild error: 'The option networking.allowPing does not exist.
Definition values: networking.domain, networking.vlans, networking.wicd.'

Fix: remove the line. No behavior change — ICMP is still accepted
via nftables.
2026-10-10 16:47:02 +03:00
oqyude 57967861c1 fix(vds-nftables): apply Option A — whitelist + policy drop, remove firewall conflict
T3/A3. otreca nftables had no final policy (implicit accept, R1.6
violation) and conflicted with networking.firewall.enable = true
(R1.6 conflict). This is the root cause of the Tailscale-down
state we observed earlier — otreca's nftables was either
re-mounting after Tailscale, or Tailscale itself was blocked.

Option A applied:
- networking.firewall.enable = false (eliminates the
  firewall.* + nftables.* conflict, R1.6)
- lib.mkForce [] on allowedTCPPorts, lib.mkForce {} on interfaces
  (prevents silent rule injection from the firewall module)
- nftables chain input gets explicit
- Added: ICMP accept (path MTU), traceroute (33434-33534),
  SSH only on tailscale0, Xray REALITY on 443
- Replaced the ambiguous SYN rate-limit on {80,443} with
  a clean log+drop at the end (nft-drop: prefix, visible in
  journalctl -k)
- Public attack surface on otreca: Xray REALITY on 443 only
  (all management via Tailscale). HTTP/80 closed.

Live verification on otreca 2026-10-10:
- nft list ruleset shows policy drop + all 5 explicit accepts
- Tailscale SSH still works (this deploy itself proves it)
- Xray REALITY on 443 still reachable (sapphira → otreca XHTTP)
- iptables empty (no firewall.* shadow rules)
2026-10-10 16:46:33 +03:00
oqyude b0191bc7d1 otreca vds: pin 3x-ui:v3.8.5 + nginx stream + ssh tailscale-only + patch-3xui-xray-config 2026-10-04 04:47:33 +03:00
oqyude d49fd5a358 big refactoring 2026-10-01 14:16:17 +03:00
oqyude 843f0bafa1 br v2 2026-08-11 03:05:52 +03:00
oqyude 871fad26d4 big refactoring 2026-08-11 02:31:00 +03:00
oqyude f6027f7b9a nix flake update 2026-05-25 20:18:58 +03:00
oqyude 52e88c1da1 systemd-routine - prebuild 2026-05-18 14:19:51 +03:00
oqyude 94b7d30c02 syn ddos defence 2026-04-13 11:13:54 +03:00
oqyude c3f8acad12 remnawave init 2026-04-05 02:28:14 +03:00
oqyude c8c7c68c04 some fix 2026-03-27 17:56:12 +03:00
oqyude f1a81a6408 Init 2026-03-09 10:50:12 +03:00