infra-configs¶
Version-controlled configurations for makanilani.com infrastructure. Each subdirectory is a self-contained snapshot of one host/role.
vpn-vps/ — vpn.makanilani.com (172.238.45.207, Hetzner/RackNerd VPS, Ubuntu 24.04)¶
Runs (native, non-docker):
- WireGuard outbound VPN server — /etc/wireguard/wg0.conf + params (PiVPN/Angristan layout)
- subnet 10.66.66.0/24, IPv6 fd42:42:42::/64, listen port 57218/udp, ip_forward=1
- AdGuard Home — /opt/AdGuardHome/AdGuardHome.yaml
- DNS :53, DoT :853, admin UI :81, DoH on :443 at https://vpn.makanilani.com/dns-query
- ufw + fail2ban active
Reconstruction runbook (fresh VPS)¶
apt update && apt upgrade -y- Install WireGuard using the
wireguard/paramsfile (PiVPN or Angristan script, non-interactive mode) — restores wg0.conf with 5 peers - Re-enable forwarding:
sysctl -w net.ipv4.ip_forward=1(script does this) - Install AdGuard Home binary to /opt/AdGuardHome, drop in
AdGuardHome/AdGuardHome.yaml,systemctl enable --now AdGuardHome - Replicate ufw rules: allow 22/tcp, 53, 80, 81, 443, 853, 57218/udp
- Install fail2ban with ssh/ufw jail
Pangolin (planned, not yet installed)¶
- Stack: pangolin (dashboard), gerbil (WireGuard tunnel server), traefik (reverse proxy)
- Traefik owns :80 + :443 (AdGuard DoH moved behind Traefik)
- Wildcard cert
*.p.makanilani.comvia DNS-01 challenge - AdGuard DoH routed through Traefik on :443, upstream to 127.0.0.1:8080
- AdGuard admin UI stays :81, DoT :853, DNS :53 unchanged
- WireGuard outbound VPN untouched (port 57218/udp, subnet 10.66.66.x)
Reboot checklist (all persisted, verified 2026-09-23)¶
- ufw rules live in
/etc/ufw/user.rules(survives reboot): 22/tcp, 53 tcp+udp, 80/tcp, 443/tcp, 853/tcp, 51820/udp, 21820/udp, 57218/udp, plus bridge rules for traefik->AGH (172.18.0.1:81 from pangolin bridge) - docker
restart: unless-stoppedon pangolin/gerbil/traefik — all auto-start on boot - systemd AdGuardHome + wireguard native units persist
- Gotcha: RackNerd provider firewall ALSO needs UDP 51820 AND 21820 allowed (was the "bad gateway" root cause; only host ufw allow is not enough)
- Any-sub hostname test:
*.p.makanilani.comresolves + wildcard cert (404 expected if no resource exists for that specific name)
Changeset 2026-09-22 (post-install finalization)¶
- Cloudflare DNS (zone id 21a621446aca66007d08ac85f8bbbceb):
- deleted explicit
pangolin.p.makanilani.comA - added wildcard
*.p.makanilani.comA → 172.238.45.207 (proxied=false) — covers pangolin + all future resource hosts - Traefik: switched LE resolver from http-01 to Cloudflare DNS-01 (token file
/opt/pangolin/config/traefik/.cf-envon VPS, NOT in git; recreate file path:CF_DNS_API_TOKEN=...) - wildcard cert issued:
p.makanilani.com+*.p.makanilani.com(LE YR1) - wildcard catchall router in dynamic_config (lower priority) drives cert issuance; publishes nothing (service points to port 9, empty)
vpn.makanilani.com(whole host) now → AdGuard: UI + DoH both on traefik :443;:81still works directly too- DoT (853) intentionally not re-enabled; certbot standalone renewal retired (
certbot delete+ timer off)
To recreate traefik wildcard CF token if machine lost¶
Create a fine-grained CF API token with Zone.DNS Edit on makanilani.com, write to /opt/pangolin/config/traefik/.cf-env as CF_DNS_API_TOKEN=..., chmod 600, docker compose up -d --force-recreate traefik in /opt/pangolin.