The vocabulary has no word for a unit that runs and exits
Found by the firewall: every packet filtered as declared, and the machine reported as not doing what it was told, because the unit that loaded the rules had finished. Stated as a gap rather than worked around silently.
This commit is contained in:
@@ -317,6 +317,18 @@ something:
|
|||||||
| **flush the ruleset** when loading | that empties every table on the machine, the runtime's among them. Only the mesh's own table is replaced, and it is declared empty first so the replacement works on a machine loading one for the first time |
|
| **flush the ruleset** when loading | that empties every table on the machine, the runtime's among them. Only the mesh's own table is replaced, and it is declared empty first so the replacement works on a machine loading one for the first time |
|
||||||
| carry a **command to load itself** | the link may not carry an action ([ADR 0005](../../02-DECISIONS/0005-the-node-host.md)). A service is declared to reflect the file instead, so replacing it restarts what loads it — the shape that rule leaves, used here for the first time for its real purpose |
|
| carry a **command to load itself** | the link may not carry an action ([ADR 0005](../../02-DECISIONS/0005-the-node-host.md)). A service is declared to reflect the file instead, so replacing it restarts what loads it — the shape that rule leaves, used here for the first time for its real purpose |
|
||||||
|
|
||||||
|
**A module that wants a rule set brings the unit that loads it.** Found the hard way: the unit a
|
||||||
|
distribution packages for nftables runs, applies the rules and exits, so it is neither running nor
|
||||||
|
stopped — and a host asked for a service that is "running" reports, quite correctly, that it is
|
||||||
|
stopped. Every packet was filtered exactly as declared and the machine was marked as not doing what
|
||||||
|
it was told.
|
||||||
|
|
||||||
|
**The vocabulary has no word for "ran, did its job, and exited"**, and that is a real gap rather
|
||||||
|
than a wording problem: the whole class of configuration-applying units — packet filters, sysctl,
|
||||||
|
tmpfiles — is shaped that way. Until there is one, a module ships a unit that stays, which is also
|
||||||
|
the better shape: how a machine enforces rules is a fact about the machine, and the mesh has no
|
||||||
|
business depending on what a distribution happens to package.
|
||||||
|
|
||||||
**One thing is derived from what is assigned and not yet from the overlay's shape**, and it is
|
**One thing is derived from what is assigned and not yet from the overlay's shape**, and it is
|
||||||
stated here rather than discovered: **a hub's own listening port.** A hub accepts inbound
|
stated here rather than discovered: **a hub's own listening port.** A hub accepts inbound
|
||||||
connections from every node at other sites; a node that is not a hub dials out and needs nothing
|
connections from every node at other sites; a node that is not a hub dials out and needs nothing
|
||||||
|
|||||||
Reference in New Issue
Block a user