oqyude 4dc4849d71 fix(vds-nftables): open SSH on all interfaces, not just tailscale0
Owner correction 2026-10-10: "не помню, чтобы просил ограничивать
22 порт". The previous T3 fix (5796786) restricted SSH to
iifname "tailscale0" based on a comment in the original vds.nix
that said "SSH is reachable only over Tailscale". The owner
did not actually request this restriction.

This commit:
- Changes  to
   (all interfaces, no iifname filter)
- Removes the  reference
- Updates comments to reflect the actual owner intent
  (SSH open everywhere, managed via nftables)
- Keeps the core R1.6 fix: explicit  on chain
  input, no firewall.* + nftables.* conflict (firewall.enable = false
  with lib.mkForce on shadow rules)
- Keeps Xray REALITY (443), ICMP, traceroute, log+drop
- Keeps port 80 closed (no nginx on otreca)

SSH on otreca is now reachable on:
  - Tailscale IP (100.64.1.0 or whatever current)
  - Public IP (109.248.161.5) on ens3
  - Any loopback

Deployment: otreca rebuild + nft verify.
2026-10-10 17:08:15 +03:00
2026-10-01 14:16:17 +03:00
2026-10-09 16:59:45 +03:00
2026-05-04 20:23:20 +03:00
2026-08-11 02:31:00 +03:00
2026-10-03 20:21:19 +03:00
ref
2026-03-29 14:46:01 +03:00
2026-03-09 10:50:12 +03:00
2026-10-03 21:59:46 +03:00
2026-06-10 12:38:23 +03:00

I'm a super newbie who just posted my stuff here. Now maybe about intermediate

S
Description
My NixOS configuration
Readme
2 MiB
Languages
Nix 90.9%
Python 8.1%
Dockerfile 1%