Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps - Status | Demo | Docs | Install
  1. Cloudron Forum
  2. Support
  3. Cloudron breaks IPv6 support on Amazon Lightsail

Cloudron breaks IPv6 support on Amazon Lightsail

Scheduled Pinned Locked Moved Solved Support
lightsailipv6
4 Posts 2 Posters 739 Views 2 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • H Offline
    H Offline
    hcj-online
    wrote on last edited by girish
    #1

    Dear all,

    Unfortunately, Cloudron breaks the IPv6 support of Amazon Lightsail.

    Steps to reproduce:

    1. Create a Lightsail instance (e.g., a dual-stack IPv4 and IPv6 instance in Frankfurt with Ubuntu 24.04 OS only for USD 12).
    2. Log into the new instance and confirm that IPv6 is working, e.g., by running:
    curl https://ipv6.icanhazip.com
    
    1. Install Cloudron (with or without the --provider lightsail flag).
    wget https://cloudron.io/cloudron-setup
    chmod +x cloudron-setup
    ./cloudron-setup --provider lightsail
    
    1. Reboot at the end of the installation.
    2. Log in to the instance again. Important: Wait at least 10 minutes.
    3. Try
    curl https://ipv6.icanhazip.com
    

    again. IPv6 is no longer working.

    When executing

    ip a
    

    you see the lifetime of the IPv6 address. Once this lifetime expires, the IPv6 connection breaks.

    Is there a known fix for this issue?

    girishG 1 Reply Last reply
    1
    • H hcj-online

      Dear all,

      Unfortunately, Cloudron breaks the IPv6 support of Amazon Lightsail.

      Steps to reproduce:

      1. Create a Lightsail instance (e.g., a dual-stack IPv4 and IPv6 instance in Frankfurt with Ubuntu 24.04 OS only for USD 12).
      2. Log into the new instance and confirm that IPv6 is working, e.g., by running:
      curl https://ipv6.icanhazip.com
      
      1. Install Cloudron (with or without the --provider lightsail flag).
      wget https://cloudron.io/cloudron-setup
      chmod +x cloudron-setup
      ./cloudron-setup --provider lightsail
      
      1. Reboot at the end of the installation.
      2. Log in to the instance again. Important: Wait at least 10 minutes.
      3. Try
      curl https://ipv6.icanhazip.com
      

      again. IPv6 is no longer working.

      When executing

      ip a
      

      you see the lifetime of the IPv6 address. Once this lifetime expires, the IPv6 connection breaks.

      Is there a known fix for this issue?

      girishG Do not disturb
      girishG Do not disturb
      girish
      Staff
      wrote on last edited by
      #2

      @hcj-online yes, this was fixed a while ago in https://git.cloudron.io/platform/box/-/commit/7f87af5a0827af431a3ecb8bfca4bc693c3707b0 . It's part of the next release.

      To fix locally:

      • Edit /home/yellowtent/box/setup/start/cloudron-firewall.sh
      • Around line 111, add the line $ip6tables -t filter -A CLOUDRON -p udp --sport 547 --dport 546 -j ACCEPT
      • Reboot server
      1 Reply Last reply
      0
      • girishG Do not disturb
        girishG Do not disturb
        girish
        Staff
        wrote on last edited by
        #3

        The code around that block should look like this:

        # ICMPv6 is very fundamental to IPv6 connectivity unlike ICMPv4
        echo "==> Allow ICMP"
        $iptables -t filter -A CLOUDRON -p icmp --icmp-type echo-request -j ACCEPT
        $iptables -t filter -A CLOUDRON -p icmp --icmp-type echo-reply -j ACCEPT
        $ip6tables -t filter -A CLOUDRON -p ipv6-icmp -j ACCEPT
        $ip6tables -t filter -A CLOUDRON -p udp --sport 547 --dport 546 -j ACCEPT
        
        ipxtables -t filter -A CLOUDRON -p udp --sport 53 -j ACCEPT
        # for ldap,dockerproxy server (ipv4 only) to accept connections from apps. for connecting to addons and mail container ports, docker already has rules
        $iptables -t filter -A CLOUDRON -p tcp -s 172.18.0.0/16 -d 172.18.0.1 -m multiport --dports 3002,3003 -j ACCEPT
        
        
        1 Reply Last reply
        0
        • H Offline
          H Offline
          hcj-online
          wrote on last edited by
          #4

          Thanks! Adding the line solves the issue. Time to roll out the update!

          1 Reply Last reply
          2
          • girishG girish has marked this topic as solved on

          Hello! It looks like you're interested in this conversation, but you don't have an account yet.

          Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

          With your input, this post could be even better 💗

          Register Login
          Reply
          • Reply as topic
          Log in to reply
          • Oldest to Newest
          • Newest to Oldest
          • Most Votes


          • Login

          • Don't have an account? Register

          • Login or register to search.
          • First post
            Last post
          0
          • Categories
          • Recent
          • Tags
          • Popular
          • Bookmarks
          • Search