oqyude 2649e2fbcc fix(vds-nftables): open port 80 — ACME HTTP-01 challenge + nginx HTTP→HTTPS
Previous T3 fix (5796786) replaced the original SYN rate-limit
on {80,443} with explicit accepts for only 22 and 443. This
accidentally dropped port 80, which broke:

1. ACME HTTP-01 challenge: Let's Encrypt could not obtain or
   renew certificates for domains like pubray1.zeroq.su. The
   cert directory /var/lib/acme/ has no pubray1.zeroq.su/ entry,
   confirming the cert was never obtained under the new ruleset.

2. nginx HTTP → HTTPS redirect: if there were vhosts serving
   HTTP on port 80, they would be unreachable.

Original vds.nix (pre-T3) had:
  tcp flags syn tcp dport {80,443} limit rate 20/second burst 40 packets accept
  tcp flags syn tcp dport {80,443} drop

This accepted port 80 (rate-limited) and 443. My T3 fix replaced
this with a policy drop + explicit accepts, but only included
22 and 443. Port 80 was missing.

Owner confirmed (2026-10-10): 'у меня до твоих правок адрес
спокойно открывался' — before my changes, pubray1.zeroq.su
was opening fine. My T3 fix broke it by closing port 80.

Fix: add tcp dport 80 accept to the nftables ruleset.
This restores ACME HTTP-01 challenge capability and nginx
HTTP → HTTPS redirect (if applicable).
2026-10-10 17:15:18 +03:00
2026-10-01 14:16:17 +03:00
2026-10-09 16:59:45 +03:00
2026-05-04 20:23:20 +03:00
2026-08-11 02:31:00 +03:00
2026-10-03 20:21:19 +03:00
ref
2026-03-29 14:46:01 +03:00
2026-03-09 10:50:12 +03:00
2026-10-03 21:59:46 +03:00
2026-06-10 12:38:23 +03:00

I'm a super newbie who just posted my stuff here. Now maybe about intermediate

S
Description
My NixOS configuration
Readme
2 MiB
Languages
Nix 90.9%
Python 8.1%
Dockerfile 1%