| Age | Commit message (Expand) | Author |
| 2026-06-13 | Update flake | Mel |
| 2026-05-17 | Add Claude Code | Mel |
| 2026-05-17 | Mitigate recent kernel exploits with kernel upgrade and blacklisting | Mel |
| 2026-05-02 | Change Xray + Nginx ordering, hide Xray behind Nginx streaming | Mel |
| 2026-05-01 | Add real domain to Xray server names to enable fallbacks | Mel |
| 2026-05-01 | Use egress destination domains in ingress instead of their names | Mel |
| 2026-05-01 | Don't set real_ip headers for Cloudflare on Tunnel egress hosts | Mel |
| 2026-05-01 | Add Docker 29 for nftables, clean-up daemon options | Mel |
| 2026-05-01 | Re-encrypt VPN & tunnel WireGuard private key | Mel |
| 2026-05-01 | Add Tunnel egress Xray fallback to re-enable all web & Nginx functionality | Mel |
| 2026-05-01 | Re-add simple VPN and simplify module with shared users with tunnel | Mel |
| 2026-04-25 | Downgrade fedifetcher from unstable to stable, due to package removal | Mel |
| 2026-04-25 | Update flake | Mel |
| 2026-04-24 | Migrate fully to systemd-networkd and nftables | Mel |
| 2026-04-24 | Remove generic foundation WireGuard server module, currently replaced by the ... | Mel |
| 2026-04-24 | Fix warning about read-only pkgs input | Mel |
| 2026-04-24 | Force disable Nginx on tunnel egress nodes | Mel |
| 2026-04-24 | Set MTU on all tunnel interfaces on ingress node | Mel |
| 2026-04-24 | Add nftables, iptables, and wireguard-tools | Mel |
| 2026-04-24 | Give the VPN its final name 'Tunnel' | Mel |
| 2026-04-24 | Add the ingress node public key to VPN definition as additional information | Mel |
| 2026-04-23 | Add new VPN user 'Fedor' | Mel |
| 2026-04-23 | Use sing-box gVisor stack for routing instead of system, fixing VPN TCP | Mel |
| 2026-04-23 | Don't shatter VPN ingress packets on local transmission between interfaces | Mel |
| 2026-04-23 | Define VPN egress & ingress default MTUs, routes, reverse paths, ... | Mel |
| 2026-04-22 | Extend Xray config generation service | Mel |
| 2026-04-22 | Let systemd-networkd handle VPN egress interface on ingress machine | Mel |
| 2026-04-22 | Fix VPN ingress private key file permissions | Mel |
| 2026-04-22 | Update sing-box deprecated seperate IPv4 TUN settings key | Mel |
| 2026-04-22 | Remove deprecated network config keys in VPN module | Mel |
| 2026-04-22 | Ingress VPN on truite | Mel |
| 2026-04-22 | Add static IPv6 address to truite | Mel |
| 2026-04-21 | Remove default WireGuard servers in favor of future VPN | Mel |
| 2026-04-21 | Update Tailscale IP for truite | Mel |
| 2026-04-21 | Update keys for truite | Mel |
| 2026-04-21 | Move truite to a better machine and Russian hosting provider | Mel |
| 2026-03-31 | VLESS/Reality VPN configuration for DPI evasion | Mel |
| 2026-03-13 | Disable printer probe (for now) | Mel |
| 2026-03-09 | Re-key base secrets for loup | Mel |
| 2026-03-09 | Transfer 'Wolfram' from minerals as new 'Loup' server | Mel |
| 2026-02-21 | Update nixpkgs-unstable | Mel |
| 2026-02-17 | Fix ACME Tailnet certificate service override naming | Mel |
| 2026-02-15 | Fix Mullvad country listings | Mel |
| 2026-02-14 | Move over deprecated option paths to new paths for 25.11 | Mel |
| 2026-02-14 | Move VPN container stack from PIA to Mullvad | Mel |
| 2026-02-14 | Remove options deleted in 25.11 | Mel |
| 2026-02-14 | Upgrade to 25.11 | Mel |
| 2026-02-14 | Add Matter server to HM stack | Mel |
| 2026-01-16 | Nix/NixOS shortcut script `nx` | Mel |
| 2025-10-04 | Factor out common public VPN peers to own module | Mel |