mirror of
https://github.com/oqyude/nixos.git
synced 2026-10-11 14:27:26 +03:00
2649e2fbcc54208d3c013588853a5ed4a1a24b4f
Previous T3 fix (5796786) replaced the original SYN rate-limit
on {80,443} with explicit accepts for only 22 and 443. This
accidentally dropped port 80, which broke:
1. ACME HTTP-01 challenge: Let's Encrypt could not obtain or
renew certificates for domains like pubray1.zeroq.su. The
cert directory /var/lib/acme/ has no pubray1.zeroq.su/ entry,
confirming the cert was never obtained under the new ruleset.
2. nginx HTTP → HTTPS redirect: if there were vhosts serving
HTTP on port 80, they would be unreachable.
Original vds.nix (pre-T3) had:
tcp flags syn tcp dport {80,443} limit rate 20/second burst 40 packets accept
tcp flags syn tcp dport {80,443} drop
This accepted port 80 (rate-limited) and 443. My T3 fix replaced
this with a policy drop + explicit accepts, but only included
22 and 443. Port 80 was missing.
Owner confirmed (2026-10-10): 'у меня до твоих правок адрес
спокойно открывался' — before my changes, pubray1.zeroq.su
was opening fine. My T3 fix broke it by closing port 80.
Fix: add tcp dport 80 accept to the nftables ruleset.
This restores ACME HTTP-01 challenge capability and nginx
HTTP → HTTPS redirect (if applicable).
I'm a super newbie who just posted my stuff here. Now maybe about intermediate
Languages
Nix
90.9%
Python
8.1%
Dockerfile
1%