Luigit
repositories / bugabinga.net

bugabinga.net

personal infrastructure for bugabinga!

owned by admin

.system/specs/BB-SPEC-613373B7-public-relay-infrastructure/index.md

Raw
Rendered preview

id: BB-SPEC-613373B7 type: spec title: Public relay infrastructure research:

  • BB-RESEARCH-4D80C31E

Public relay infrastructure

Topology

OpenTofu provisions one Hetzner Cloud relay with retained public IPv4 and IPv6 addresses. The relay and klops form a dual-stack WireGuard link. The design is single-relay and single-peer.

Ingress

Relay management SSH and WireGuard terminate on the relay. Only these public paths are forwarded to klops:

  • HTTP;
  • HTTPS;
  • Git SSH;
  • Luci SSH.

DNS and mail are not relay services. Every exposure must exist consistently in the Hetzner firewall and host nftables configuration.

Relay host

Cloud-init installs and configures WireGuard, nftables, fail2ban, automatic security updates, forwarding, and the configured management SSH port. Input and forward chains default to drop, permit established traffic, and admit only explicit paths. DNAT supports IPv4 and IPv6. IPv4 tunnel egress is masqueraded where configured.

Klops policy routing returns traffic sourced from its WireGuard addresses through the WireGuard table while preserving required residential routes.

Operational constraints

Use OpenTofu, never Terraform. Format recursively, validate, and review a plan before apply. A relay exposure change must update cloud and host firewalls together. Exact machine type, location, image, addresses, ports, and MTU remain typed configuration rather than prose constants.

---
id: BB-SPEC-613373B7
type: spec
title: Public relay infrastructure
research:
  - BB-RESEARCH-4D80C31E
---

# Public relay infrastructure

## Topology

OpenTofu provisions one Hetzner Cloud relay with retained public IPv4 and IPv6 addresses.
The relay and klops form a dual-stack WireGuard link.
The design is single-relay and single-peer.

## Ingress

Relay management SSH and WireGuard terminate on the relay.
Only these public paths are forwarded to klops:

- HTTP;
- HTTPS;
- Git SSH;
- Luci SSH.

DNS and mail are not relay services.
Every exposure must exist consistently in the Hetzner firewall and host nftables configuration.

## Relay host

Cloud-init installs and configures WireGuard, nftables, fail2ban, automatic security updates, forwarding, and the configured management SSH port.
Input and forward chains default to drop, permit established traffic, and admit only explicit paths.
DNAT supports IPv4 and IPv6.
IPv4 tunnel egress is masqueraded where configured.

Klops policy routing returns traffic sourced from its WireGuard addresses through the WireGuard table while preserving required residential routes.

## Operational constraints

Use OpenTofu, never Terraform.
Format recursively, validate, and review a plan before apply.
A relay exposure change must update cloud and host firewalls together.
Exact machine type, location, image, addresses, ports, and MTU remain typed configuration rather than prose constants.