fix(caddy): stop advertising HTTP/3 — UDP/443 is filtered at the perimeter (#101) #117
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!117
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "fix/101-disable-http3"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Resolves #101 (option B). Verification proved HTTP/3 is broken on prod:
curl --http3-onlycan't connect (code 000) while cloudflare-quic/google negotiate h3 fine from the same client. Root cause: UDP/443 isn't open — nftables (tcp dport) and the Neutron SG (protocol=tcp) are both TCP-only, so inbound QUIC is dropped; Caddy nonetheless advertisedalt-svc: h3, so clients tried QUIC, failed, and fell back to h2 (a penalty for zero benefit).Chosen fix (B): drop the h3 listener rather than open a public UDP port — least-privilege, and h2 is entirely sufficient for a git host + portal.
caddy.socket: removeListenDatagram=443.Caddyfile: remove thefdgram/4h3 bind; the port-80 socket shifts fd/5 → fd/4 (updated thehttp://redirect bind to match — the fd-numbering hazard the unit comments warn about).Verified: rendered prod Caddyfile passes
caddy validateon the pinned image; syntax-check + ansible-lint clean.Apply note: rebinds the socket → brief caddy blip (off-peak). Per ADR 0030 I'll apply from
mainafter merge, then re-verify (alt-svc no longer offers h3; h2 still serves) and close #101.