vps: WireGuard + rootless HAProxy Quadlet relay replaces frp #301
No reviewers
Labels
No labels
audit-work
bug
docs
general-admin
major-upgrade
needs-vps-sync
new-service
on-hold
outside-work
post-podman
renovate
upstream
vps
No milestone
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
mysticalsoap/docker!301
Loading…
Reference in a new issue
No description provided.
Delete branch "feat/vps-wireguard-relay"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Problem
frps on the VPS ran as root from a bare binary, taking token-authenticated logins on a public port, and held 80/443 so anything else on the box would have needed a second proxy stacked in front of it. Debian 12's Podman 4.3 predated Quadlet and pasta (#100, #101). The live
frps.tomlalso lacked the documentedallowPorts, and ufw had 22 onallowrather thanlimit.Fix
_helper/vps/is the whole host state;install.shconverges it,just vps-deployships it over avpsssh alias so the repo never holds the address.install.shrefuses to start the tunnel while the peer key is the placeholder and restarts the interface when the key file no longer matches the running one, so rotation is "delete the key, deploy".relay, pasta) on 80/443/27341 with PROXY v2 to the home end. A stick table on 27341 replacesufw limit; the 443 frontend already inspects the ClientHello so the status page later is ause_backendon SNI. No start limit on the unit: at boot the user manager can start pasta before the default route exists.wireguardcontainer (LSIO) dials the VPS; ahaproxysidecar in its network namespace re-emits PROXY v2 to Traefik and forwards 2222 to Forgejo. Forwarding is off in that namespace and each listener rejects any peer but the VPS's tunnel address, so the tunnel reaches those three listeners and nothing else. Traefik now trusts PROXY headers from the container's fixed/32instead of the whole proxy subnet.frpc.tomland the frp secret consumers removed. Docs, README, topology diagram, Renovate (regex manager for QuadletImage=lines;needs-vps-syncon_helper/vps/**) updated. A subagent security review's findings are folded in.Verification
just vps-deployon the fresh Debian 13: wg0 up,haproxy.serviceactive underuser@1002with pasta holding 80/443/27341, ~130 MB peak.just up infra:wireguardhealthy (handshake-age healthcheck), handshake 32 s old at check time, keepalive 25 s.curl --resolve mysticalsoap.com:443:<vps>from home: 200; port 80: 301. Traefik's access log shows the real client address, not172.18.3.254.ssh -Tto Forgejo through<vps>:27341: authenticated with the real key.proxyto172.18.3.254:8080gets no response; the same request through the tunnel gets the redirect.haproxy.cfgfiles passhaproxy -cwith the pinned image;docker compose configis clean.Closes #100, closes #101. PR #13 (frpc 0.71.0) is superseded; close it rather than merge.
After merge: the VPS already runs this tree, so no
just vps-deploy. Deleteinfra/secrets/frp_server_addr.txtandfrp_token.txtby hand.