Commit Graph
12 Commits
Author SHA1 Message Date
oqyude 3deaa75f5c fix(vds-nftables): remove allowPing — not a top-level networking option
networking.allowPing was a top-level networking option when
firewall.enable = true. With firewall.enable = false (T3 Option A),
the option no longer exists at the networking level. ICMP is now
handled by the nftables ruleset directly
().

Rebuild error: 'The option networking.allowPing does not exist.
Definition values: networking.domain, networking.vlans, networking.wicd.'

Fix: remove the line. No behavior change — ICMP is still accepted
via nftables.
2026-10-10 16:47:02 +03:00
oqyude 57967861c1 fix(vds-nftables): apply Option A — whitelist + policy drop, remove firewall conflict
T3/A3. otreca nftables had no final policy (implicit accept, R1.6
violation) and conflicted with networking.firewall.enable = true
(R1.6 conflict). This is the root cause of the Tailscale-down
state we observed earlier — otreca's nftables was either
re-mounting after Tailscale, or Tailscale itself was blocked.

Option A applied:
- networking.firewall.enable = false (eliminates the
  firewall.* + nftables.* conflict, R1.6)
- lib.mkForce [] on allowedTCPPorts, lib.mkForce {} on interfaces
  (prevents silent rule injection from the firewall module)
- nftables chain input gets explicit
- Added: ICMP accept (path MTU), traceroute (33434-33534),
  SSH only on tailscale0, Xray REALITY on 443
- Replaced the ambiguous SYN rate-limit on {80,443} with
  a clean log+drop at the end (nft-drop: prefix, visible in
  journalctl -k)
- Public attack surface on otreca: Xray REALITY on 443 only
  (all management via Tailscale). HTTP/80 closed.

Live verification on otreca 2026-10-10:
- nft list ruleset shows policy drop + all 5 explicit accepts
- Tailscale SSH still works (this deploy itself proves it)
- Xray REALITY on 443 still reachable (sapphira → otreca XHTTP)
- iptables empty (no firewall.* shadow rules)
2026-10-10 16:46:33 +03:00
oqyude b0191bc7d1 otreca vds: pin 3x-ui:v3.8.5 + nginx stream + ssh tailscale-only + patch-3xui-xray-config 2026-10-04 04:47:33 +03:00
oqyude d49fd5a358 big refactoring 2026-10-01 14:16:17 +03:00
oqyude 843f0bafa1 br v2 2026-08-11 03:05:52 +03:00
oqyude 871fad26d4 big refactoring 2026-08-11 02:31:00 +03:00
oqyude f6027f7b9a nix flake update 2026-05-25 20:18:58 +03:00
oqyude 52e88c1da1 systemd-routine - prebuild 2026-05-18 14:19:51 +03:00
oqyude 94b7d30c02 syn ddos defence 2026-04-13 11:13:54 +03:00
oqyude c3f8acad12 remnawave init 2026-04-05 02:28:14 +03:00
oqyude c8c7c68c04 some fix 2026-03-27 17:56:12 +03:00
oqyude f1a81a6408 Init 2026-03-09 10:50:12 +03:00