--- id: BB-SPEC-613373B7 type: spec title: Public relay infrastructure research: - BB-RESEARCH-4D80C31E --- # Public relay infrastructure ## Topology OpenTofu provisions one Hetzner Cloud relay with retained public IPv4 and IPv6 addresses. The relay and klops form a dual-stack WireGuard link. The design is single-relay and single-peer. ## Ingress Relay management SSH and WireGuard terminate on the relay. Only these public paths are forwarded to klops: - HTTP; - HTTPS; - Git SSH; - Luci SSH. DNS and mail are not relay services. Every exposure must exist consistently in the Hetzner firewall and host nftables configuration. ## Relay host Cloud-init installs and configures WireGuard, nftables, fail2ban, automatic security updates, forwarding, and the configured management SSH port. Input and forward chains default to drop, permit established traffic, and admit only explicit paths. DNAT supports IPv4 and IPv6. IPv4 tunnel egress is masqueraded where configured. Klops policy routing returns traffic sourced from its WireGuard addresses through the WireGuard table while preserving required residential routes. ## Operational constraints Use OpenTofu, never Terraform. Format recursively, validate, and review a plan before apply. A relay exposure change must update cloud and host firewalls together. Exact machine type, location, image, addresses, ports, and MTU remain typed configuration rather than prose constants.