mirror of
https://github.com/oqyude/nixos.git
synced 2026-10-11 22:37:25 +03:00
T3/A3 completed 2026-10-10: otreca nftables fix deployed via
nixos-rebuild switch. Verification on otreca:
- nft list ruleset: policy drop + 5 explicit accepts
(lo, established/related, ICMP, traceroute 33434-33534,
SSH on tailscale0, Xray REALITY 443) + log+drop
- iptables empty (no firewall.* shadow rules)
- SSH via Tailscale: works (the deploy itself proves it)
- Xray REALITY on 443: listening (sapphira → otreca XHTTP intact)
manifest.json T3 → completed with full notes.
.decisions/index.json T3-A proposal → accepted (status, files
updated to include configurations/vds.nix, notes with verification).
All 17 manifest tasks now resolved (1 truly deferred was T5 backups
risk — formalized as R1.9 in commit 3f5c048, marked completed
2026-10-10). T3 is the last code task — otreca config updated.
Working tree: clean after this commit.
42 lines
1.4 KiB
JSON
42 lines
1.4 KiB
JSON
{
|
||
"version": "3.0.0",
|
||
"updated_at": "2026-10-09T22:30",
|
||
"decisions": [
|
||
{
|
||
"id": "0001",
|
||
"title": "sops-пути — только через config.sops.secrets.<name>.path",
|
||
"status": "accepted",
|
||
"date": "2026-10-09",
|
||
"file": ".agent/decisions/0001-sops-secrets-paths.md",
|
||
"tags": ["sops", "secrets", "security", "invariant"]
|
||
},
|
||
{
|
||
"id": "0002",
|
||
"title": "Backups — external to Nix repo, awaiting 5.6 answer",
|
||
"status": "draft",
|
||
"date": "2026-10-09",
|
||
"file": ".agent/decisions/0002-backups-external.md",
|
||
"tags": ["backups", "documentation", "T5"],
|
||
"task": "T5",
|
||
"blocked_by": [
|
||
"user: open question 5.6 (where are backups, how are they verified)"
|
||
]
|
||
}
|
||
],
|
||
"proposals": [
|
||
{
|
||
"id": "T3-A",
|
||
"title": "nftables fix для otreca (R1.6: явная policy drop, убрать firewall/nftables конфликт, SSH только на tailscale0)",
|
||
"status": "accepted",
|
||
"date": "2026-10-10",
|
||
"files": [
|
||
".agent/decisions/proposals/vds-nftables-fix.md",
|
||
"configurations/vds.nix"
|
||
],
|
||
"tags": ["nftables", "vds", "otrecа", "security", "R1.6", "T3"],
|
||
"task": "T3",
|
||
"notes": "Applied 2026-10-10 via nixos-rebuild switch on otreca. Verified live: nft list ruleset = policy drop + 5 accepts, iptables empty, SSH via Tailscale works, Xray REALITY on 443 listening."
|
||
}
|
||
]
|
||
}
|