The machine is now running fine, but I had a few roadblocks setting it up:
• My provisioning scripts download a release of 'dry'[0] from GitHub, which does not support IPv6. I ended up assigning my new machine a temporary IPv4 address and removing it later.
• The scripts also import a key from 'keyserver.ubuntu.com'[1], which, again, does not support IPv6. Attempting to connect just timed out, and if I hadn't just solved the other issue, I would have assumed the host was down.
• There seems to be a bug in Scaleway's cloud firewall (the things it calls Security Groups), where you cannot allow inbound ICMPv6, only standard ICMP (for IPv4). This meant my pings never responded and I thought the machine wasn't up when it was up.
Basically, what I want you to take away from this post is that if you disable IPv6, it's still the case that during maintenance, things are going to break, often mysteriously and with bad error messages, but outside of maintenance, things will likely run smoothly. My machine runs Sentry, and after the problems I had setting it up, I didn't dare run the Sentry './install.sh' script with IPv4 disabled as I didn't trust it to handle that case correctly — and even if the script reported no errors, I wouldn't have trusted there to actually be no errors. Since then, though, it's been running fine, so having an IPv6-only server is certainly possible, even if you have to give in and assign it an IPv4 address at the start, then take it away again later.
[0]: https://github.com/moncho/dry [1]: https://keyserver.ubuntu.com/
In the past, setting up the server was hard(npm, composer, docker) but it has become less of a problem now.
GitHub is the major pain point even now. Even though I use bitbucket for scm which supports IPv6, surprising number of developer tools is centralized on GitHub.
To get IPv6 on all computers I just installed radvd on the router. On the router I also set up a VPN to give the IPv6 addresses over IPv4 even when they're not local.
It's great.
Original implementation of DirectAccess (Always-On, transparent VPN) in Windows Vista required working IPv6 connection, this was extended with HTTPS-over-v4 backup tunnel support later on when MS found out how hard it was to get consumer v6 in 2007. Inside of DirectAccess, connectivity is pure v6 still.
In fact, since NT6, Windows is IPv6-first system in many aspects, and Microsoft made news last year when they complained that they couldn't disable v4 on guest wifi at many offices due to non-Microsoft visiting workers having issues connecting to their VPNs due to software that didn't work with NAT64/DNS64.
Maybe the solution for more IPv6 adoption is for tech giants like Apple, Google, Microsoft to make proxies like Private Relay ubiquitous on every device/browser.
Unfortunately in the meantime spammers have discovered HE tunnels and now I get a lot more CAPCHA's than I used to. I still check my FiOS link every month to see if Verizon has turned it on yet.
It worked perfect for that in almost every situation since my cell carrier supported v6 so any time I'm not home I could still access it.