NixOS doesn't have /usr/share/tor/geoip — point the proxy at
pkgs.tor.geoip derivation paths instead.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Bind metrics to 0.0.0.0 so Alloy can scrape from k8s, add HOST_IP
downward API env var to alloy-ringtail DaemonSet, and add a dashboard
with connection rate, traffic rate, country breakdown, and process memory.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Add snowflake-proxy as a native systemd service on ringtail to help
censored users reach the Tor network. This is a bridge proxy, not an
exit node — traffic exits through Tor exit nodes elsewhere.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>