fix(caddy): stop advertising HTTP/3 — UDP/443 is filtered at the perimeter (#101) #117

Sammanfogat
supernaut sammanfogade 1 incheckning från fix/101-disable-http3 in i main 2026-07-18 22:07:08 +00:00
Ägare

Resolves #101 (option B). Verification proved HTTP/3 is broken on prod: curl --http3-only can't connect (code 000) while cloudflare-quic/google negotiate h3 fine from the same client. Root cause: UDP/443 isn't open — nftables (tcp dport) and the Neutron SG (protocol=tcp) are both TCP-only, so inbound QUIC is dropped; Caddy nonetheless advertised alt-svc: h3, so clients tried QUIC, failed, and fell back to h2 (a penalty for zero benefit).

Chosen fix (B): drop the h3 listener rather than open a public UDP port — least-privilege, and h2 is entirely sufficient for a git host + portal.

  • caddy.socket: remove ListenDatagram=443.
  • Caddyfile: remove the fdgram/4 h3 bind; the port-80 socket shifts fd/5 → fd/4 (updated the http:// redirect bind to match — the fd-numbering hazard the unit comments warn about).

Verified: rendered prod Caddyfile passes caddy validate on the pinned image; syntax-check + ansible-lint clean.

Apply note: rebinds the socket → brief caddy blip (off-peak). Per ADR 0030 I'll apply from main after merge, then re-verify (alt-svc no longer offers h3; h2 still serves) and close #101.

Resolves #101 (option B). Verification proved HTTP/3 is broken on prod: `curl --http3-only` can't connect (code 000) while cloudflare-quic/google negotiate h3 fine from the same client. **Root cause: UDP/443 isn't open** — nftables (`tcp dport`) and the Neutron SG (`protocol=tcp`) are both TCP-only, so inbound QUIC is dropped; Caddy nonetheless advertised `alt-svc: h3`, so clients tried QUIC, failed, and fell back to h2 (a penalty for zero benefit). **Chosen fix (B):** drop the h3 listener rather than open a public UDP port — least-privilege, and h2 is entirely sufficient for a git host + portal. - `caddy.socket`: remove `ListenDatagram=443`. - `Caddyfile`: remove the `fdgram/4` h3 bind; the port-80 socket shifts fd/5 → **fd/4** (updated the `http://` redirect bind to match — the fd-numbering hazard the unit comments warn about). **Verified:** rendered prod Caddyfile passes `caddy validate` on the pinned image; syntax-check + ansible-lint clean. **Apply note:** rebinds the socket → brief caddy blip (off-peak). Per ADR 0030 I'll apply from `main` after merge, then re-verify (alt-svc no longer offers h3; h2 still serves) and close #101.
supernaut lade till 1 incheckning 2026-07-18 21:59:17 +00:00
fix(caddy): stop advertising HTTP/3 — UDP/443 is filtered at the perimeter (#101)
Alla kontroller lyckades
ci / ci (pull_request) Successful in 2m32s
1e7ce3ae17
Verified h3 is broken on prod: curl --http3-only can't connect (code
000) while cloudflare/google negotiate h3 fine from the same client. Root
cause: UDP/443 is not open — nftables (tcp dport) and the Neutron SG
(protocol=tcp) are both TCP-only, so inbound QUIC is dropped. Caddy still
advertised alt-svc h3, so clients tried QUIC, failed, and fell back to h2.

Per #101 option B (chosen): drop the h3 listener rather than open a public
UDP port (least privilege; h2 is sufficient). Remove ListenDatagram=443
from caddy.socket and the fdgram/4 h3 bind from the Caddyfile; the port-80
socket shifts fd/5 → fd/4 (updated the http:// redirect bind to match).

Verified: rendered prod Caddyfile passes `caddy validate` on the pinned
image. Apply rebinds the socket (brief caddy blip) — off-peak.

Closes #101.
supernaut sammanfogade incheckning 2cf03de9c8 till main 2026-07-18 22:07:08 +00:00
supernaut tog bort grenen fix/101-disable-http3 2026-07-18 22:07:08 +00:00
Logga in för att delta i denna konversation.
Inga granskare
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra!117
Ingen beskrivning angiven.