For posterity: Fly has nftables support now! Our setup no longer uses the iptables-legacy workaround.