Users here in the community have asked for nftables support and here it is:
Fly Machine kernels now support nftables. If you’re running Docker or Tailscale on Fly.io, you should no longer need to use iptables-legacy as a workaround on newer containers.
For existing Machines, running fly deploy
or fly m update
is required to pick up the new kernel. New Machines will automatically use the new kernel.
Please let us know what problems you run into! A few forum posts lead to this being added: