mirror of
https://github.com/oqyude/nixos.git
synced 2026-10-11 14:27:26 +03:00
Owner correction 2026-10-10: "не помню, чтобы просил ограничивать
22 порт". The previous T3 fix (5796786) restricted SSH to
iifname "tailscale0" based on a comment in the original vds.nix
that said "SSH is reachable only over Tailscale". The owner
did not actually request this restriction.
This commit:
- Changes to
(all interfaces, no iifname filter)
- Removes the reference
- Updates comments to reflect the actual owner intent
(SSH open everywhere, managed via nftables)
- Keeps the core R1.6 fix: explicit on chain
input, no firewall.* + nftables.* conflict (firewall.enable = false
with lib.mkForce on shadow rules)
- Keeps Xray REALITY (443), ICMP, traceroute, log+drop
- Keeps port 80 closed (no nginx on otreca)
SSH on otreca is now reachable on:
- Tailscale IP (100.64.1.0 or whatever current)
- Public IP (109.248.161.5) on ens3
- Any loopback
Deployment: otreca rebuild + nft verify.