oqyude 57967861c1 fix(vds-nftables): apply Option A — whitelist + policy drop, remove firewall conflict
T3/A3. otreca nftables had no final policy (implicit accept, R1.6
violation) and conflicted with networking.firewall.enable = true
(R1.6 conflict). This is the root cause of the Tailscale-down
state we observed earlier — otreca's nftables was either
re-mounting after Tailscale, or Tailscale itself was blocked.

Option A applied:
- networking.firewall.enable = false (eliminates the
  firewall.* + nftables.* conflict, R1.6)
- lib.mkForce [] on allowedTCPPorts, lib.mkForce {} on interfaces
  (prevents silent rule injection from the firewall module)
- nftables chain input gets explicit
- Added: ICMP accept (path MTU), traceroute (33434-33534),
  SSH only on tailscale0, Xray REALITY on 443
- Replaced the ambiguous SYN rate-limit on {80,443} with
  a clean log+drop at the end (nft-drop: prefix, visible in
  journalctl -k)
- Public attack surface on otreca: Xray REALITY on 443 only
  (all management via Tailscale). HTTP/80 closed.

Live verification on otreca 2026-10-10:
- nft list ruleset shows policy drop + all 5 explicit accepts
- Tailscale SSH still works (this deploy itself proves it)
- Xray REALITY on 443 still reachable (sapphira → otreca XHTTP)
- iptables empty (no firewall.* shadow rules)
2026-10-10 16:46:33 +03:00
2026-10-01 14:16:17 +03:00
2026-10-09 16:59:45 +03:00
2026-05-04 20:23:20 +03:00
2026-08-11 02:31:00 +03:00
2026-10-03 20:21:19 +03:00
ref
2026-03-29 14:46:01 +03:00
2026-03-09 10:50:12 +03:00
2026-10-03 21:59:46 +03:00
2026-06-10 12:38:23 +03:00

I'm a super newbie who just posted my stuff here. Now maybe about intermediate

S
Description
My NixOS configuration
Readme
2 MiB
Languages
Nix 90.9%
Python 8.1%
Dockerfile 1%