Skip to content

infra-configs

Version-controlled configurations for makanilani.com infrastructure. Each subdirectory is a self-contained snapshot of one host/role.

vpn-vps/ — vpn.makanilani.com (172.238.45.207, Hetzner/RackNerd VPS, Ubuntu 24.04)

Runs (native, non-docker): - WireGuard outbound VPN server — /etc/wireguard/wg0.conf + params (PiVPN/Angristan layout) - subnet 10.66.66.0/24, IPv6 fd42:42:42::/64, listen port 57218/udp, ip_forward=1 - AdGuard Home — /opt/AdGuardHome/AdGuardHome.yaml - DNS :53, DoT :853, admin UI :81, DoH on :443 at https://vpn.makanilani.com/dns-query - ufw + fail2ban active

Reconstruction runbook (fresh VPS)

  1. apt update && apt upgrade -y
  2. Install WireGuard using the wireguard/params file (PiVPN or Angristan script, non-interactive mode) — restores wg0.conf with 5 peers
  3. Re-enable forwarding: sysctl -w net.ipv4.ip_forward=1 (script does this)
  4. Install AdGuard Home binary to /opt/AdGuardHome, drop in AdGuardHome/AdGuardHome.yaml, systemctl enable --now AdGuardHome
  5. Replicate ufw rules: allow 22/tcp, 53, 80, 81, 443, 853, 57218/udp
  6. Install fail2ban with ssh/ufw jail

Pangolin (planned, not yet installed)

  • Stack: pangolin (dashboard), gerbil (WireGuard tunnel server), traefik (reverse proxy)
  • Traefik owns :80 + :443 (AdGuard DoH moved behind Traefik)
  • Wildcard cert *.p.makanilani.com via DNS-01 challenge
  • AdGuard DoH routed through Traefik on :443, upstream to 127.0.0.1:8080
  • AdGuard admin UI stays :81, DoT :853, DNS :53 unchanged
  • WireGuard outbound VPN untouched (port 57218/udp, subnet 10.66.66.x)

Reboot checklist (all persisted, verified 2026-09-23)

  • ufw rules live in /etc/ufw/user.rules (survives reboot): 22/tcp, 53 tcp+udp, 80/tcp, 443/tcp, 853/tcp, 51820/udp, 21820/udp, 57218/udp, plus bridge rules for traefik->AGH (172.18.0.1:81 from pangolin bridge)
  • docker restart: unless-stopped on pangolin/gerbil/traefik — all auto-start on boot
  • systemd AdGuardHome + wireguard native units persist
  • Gotcha: RackNerd provider firewall ALSO needs UDP 51820 AND 21820 allowed (was the "bad gateway" root cause; only host ufw allow is not enough)
  • Any-sub hostname test: *.p.makanilani.com resolves + wildcard cert (404 expected if no resource exists for that specific name)

Changeset 2026-09-22 (post-install finalization)

  • Cloudflare DNS (zone id 21a621446aca66007d08ac85f8bbbceb):
  • deleted explicit pangolin.p.makanilani.com A
  • added wildcard *.p.makanilani.com A → 172.238.45.207 (proxied=false) — covers pangolin + all future resource hosts
  • Traefik: switched LE resolver from http-01 to Cloudflare DNS-01 (token file /opt/pangolin/config/traefik/.cf-env on VPS, NOT in git; recreate file path: CF_DNS_API_TOKEN=...)
  • wildcard cert issued: p.makanilani.com + *.p.makanilani.com (LE YR1)
  • wildcard catchall router in dynamic_config (lower priority) drives cert issuance; publishes nothing (service points to port 9, empty)
  • vpn.makanilani.com (whole host) now → AdGuard: UI + DoH both on traefik :443; :81 still works directly too
  • DoT (853) intentionally not re-enabled; certbot standalone renewal retired (certbot delete + timer off)

To recreate traefik wildcard CF token if machine lost

Create a fine-grained CF API token with Zone.DNS Edit on makanilani.com, write to /opt/pangolin/config/traefik/.cf-env as CF_DNS_API_TOKEN=..., chmod 600, docker compose up -d --force-recreate traefik in /opt/pangolin.