Files
nixos/configurations
oqyude 57967861c1 fix(vds-nftables): apply Option A — whitelist + policy drop, remove firewall conflict
T3/A3. otreca nftables had no final policy (implicit accept, R1.6
violation) and conflicted with networking.firewall.enable = true
(R1.6 conflict). This is the root cause of the Tailscale-down
state we observed earlier — otreca's nftables was either
re-mounting after Tailscale, or Tailscale itself was blocked.

Option A applied:
- networking.firewall.enable = false (eliminates the
  firewall.* + nftables.* conflict, R1.6)
- lib.mkForce [] on allowedTCPPorts, lib.mkForce {} on interfaces
  (prevents silent rule injection from the firewall module)
- nftables chain input gets explicit
- Added: ICMP accept (path MTU), traceroute (33434-33534),
  SSH only on tailscale0, Xray REALITY on 443
- Replaced the ambiguous SYN rate-limit on {80,443} with
  a clean log+drop at the end (nft-drop: prefix, visible in
  journalctl -k)
- Public attack surface on otreca: Xray REALITY on 443 only
  (all management via Tailscale). HTTP/80 closed.

Live verification on otreca 2026-10-10:
- nft list ruleset shows policy drop + all 5 explicit accepts
- Tailscale SSH still works (this deploy itself proves it)
- Xray REALITY on 443 still reachable (sapphira → otreca XHTTP)
- iptables empty (no firewall.* shadow rules)
2026-10-10 16:46:33 +03:00
..
2026-04-05 02:28:14 +03:00
2026-08-11 04:03:42 +03:00
2026-10-01 15:14:37 +03:00
2026-10-01 14:16:17 +03:00
2026-10-01 14:16:17 +03:00
2026-10-04 18:34:39 +03:00
2026-10-04 18:34:39 +03:00