mirror of
https://github.com/oqyude/nixos.git
synced 2026-10-11 14:27:26 +03:00
Owner request 2026-10-10: 'отмени вообще правки файрволла, верни пока какие были до твоих работ. это требует обсуждения, потому что по прежнему ничего не работает, сайт не открывается, reality не работает.' This reverts 5 T3 code commits + 2 T3 doc commits:5796786fix(vds-nftables): apply Option A3deaa75fix(vds-nftables): remove allowPing4dc4849fix(vds-nftables): open SSH on all interfaces2649e2ffix(vds-nftables): open port 8051ea19afix(vds-nftables): open port 8443677d39edocs(T3): note correctionfafd3e2docs(T3): mark nftables fix as applied Restored: - configurations/vds.nix → original from61b3724(firewall.enable = true, firewall.interfaces.tailscale0.allowedTCPPorts = [22], nftables with SYN rate-limit on {80,443}) - .agent/tasks/manifest.json T3 → status = 'pending' (was 'completed') - .agent/decisions/index.json T3-A → status = 'proposed' (was 'accepted') The proposal .agent/decisions/proposals/vds-nftables-fix.md is NOT removed — it's still a proposal for future discussion, just not applied. nft list ruleset on otreca will return to the original (firewall-managed) state after rebuild. T3 needs proper discussion with owner before re-applying. The issues observed (site not opening, reality not working) need diagnostic before any new fix attempt.
43 lines
1.3 KiB
JSON
43 lines
1.3 KiB
JSON
{
|
||
"version": "3.0.0",
|
||
"updated_at": "2026-10-09T22:30",
|
||
"decisions": [
|
||
{
|
||
"id": "0001",
|
||
"title": "sops-пути — только через config.sops.secrets.<name>.path",
|
||
"status": "accepted",
|
||
"date": "2026-10-09",
|
||
"file": ".agent/decisions/0001-sops-secrets-paths.md",
|
||
"tags": ["sops", "secrets", "security", "invariant"]
|
||
},
|
||
{
|
||
"id": "0002",
|
||
"title": "Backups — external to Nix repo, awaiting 5.6 answer",
|
||
"status": "draft",
|
||
"date": "2026-10-09",
|
||
"file": ".agent/decisions/0002-backups-external.md",
|
||
"tags": ["backups", "documentation", "T5"],
|
||
"task": "T5",
|
||
"blocked_by": [
|
||
"user: open question 5.6 (where are backups, how are they verified)"
|
||
]
|
||
}
|
||
],
|
||
"proposals": [
|
||
{
|
||
"id": "T3-A",
|
||
"title": "nftables fix для otreca (R1.6: явная policy drop, убрать firewall/nftables конфликт, SSH только на tailscale0)",
|
||
"status": "proposed",
|
||
"date": "2026-10-09",
|
||
"files": [
|
||
".agent/decisions/proposals/vds-nftables-fix.md"
|
||
],
|
||
"tags": ["nftables", "vds", "otrecа", "security", "R1.6", "T3"],
|
||
"task": "T3",
|
||
"blocked_by": [
|
||
"user: SSH-доступ на otreca должен быть восстановлен до apply"
|
||
]
|
||
}
|
||
]
|
||
}
|