docs: IPv6 paragraph describes the link, not a VPN client #302
No reviewers
Labels
No labels
audit-work
bug
docs
general-admin
major-upgrade
needs-vps-sync
new-service
on-hold
outside-work
post-podman
renovate
upstream
vps
No milestone
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
mysticalsoap/docker!302
Loading…
Reference in a new issue
No description provided.
Delete branch "docs/ipv6-paragraph"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Problem
Public-Exposure.md's IPv6 paragraph credits a ProtonVPN desktop client with blackholing IPv6 on the host. That client no longer exists; the VPN is gluetun in the media stack and only its containers use it. The stated reason the open
ip6tablesDOCKER-USERchain is safe was false.Fix
State the actual condition: the ISP link provides no global IPv6 address and no default route, so docker-proxy's
[::]listeners are unreachable from outside, and name the check that would signal that changing.Verification
On the host:
ip -6 addr show scope globalprints nothing,ip -6 route show defaultprints nothing,ip -brief linkshows no VPN or leak interface,disable_ipv6is 0.ss -6 -ltnshows docker-proxy on[::]:80,[::]:443,[::]:8443,[::]:53,[::]:853.