Files
nixos/.agent/decisions/index.json
T
oqyude fafd3e2df7 docs(T3): mark nftables fix as applied + accepted
T3/A3 completed 2026-10-10: otreca nftables fix deployed via
nixos-rebuild switch. Verification on otreca:
  - nft list ruleset: policy drop + 5 explicit accepts
    (lo, established/related, ICMP, traceroute 33434-33534,
     SSH on tailscale0, Xray REALITY 443) + log+drop
  - iptables empty (no firewall.* shadow rules)
  - SSH via Tailscale: works (the deploy itself proves it)
  - Xray REALITY on 443: listening (sapphira → otreca XHTTP intact)

manifest.json T3 → completed with full notes.
.decisions/index.json T3-A proposal → accepted (status, files
updated to include configurations/vds.nix, notes with verification).

All 17 manifest tasks now resolved (1 truly deferred was T5 backups
risk — formalized as R1.9 in commit 3f5c048, marked completed
2026-10-10). T3 is the last code task — otreca config updated.

Working tree: clean after this commit.
2026-10-10 16:52:09 +03:00

42 lines
1.4 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
{
"version": "3.0.0",
"updated_at": "2026-10-09T22:30",
"decisions": [
{
"id": "0001",
"title": "sops-пути — только через config.sops.secrets.<name>.path",
"status": "accepted",
"date": "2026-10-09",
"file": ".agent/decisions/0001-sops-secrets-paths.md",
"tags": ["sops", "secrets", "security", "invariant"]
},
{
"id": "0002",
"title": "Backups — external to Nix repo, awaiting 5.6 answer",
"status": "draft",
"date": "2026-10-09",
"file": ".agent/decisions/0002-backups-external.md",
"tags": ["backups", "documentation", "T5"],
"task": "T5",
"blocked_by": [
"user: open question 5.6 (where are backups, how are they verified)"
]
}
],
"proposals": [
{
"id": "T3-A",
"title": "nftables fix для otreca (R1.6: явная policy drop, убрать firewall/nftables конфликт, SSH только на tailscale0)",
"status": "accepted",
"date": "2026-10-10",
"files": [
".agent/decisions/proposals/vds-nftables-fix.md",
"configurations/vds.nix"
],
"tags": ["nftables", "vds", "otrecа", "security", "R1.6", "T3"],
"task": "T3",
"notes": "Applied 2026-10-10 via nixos-rebuild switch on otreca. Verified live: nft list ruleset = policy drop + 5 accepts, iptables empty, SSH via Tailscale works, Xray REALITY on 443 listening."
}
]
}