ADR 0100 after review: found means unrecorded; assigning prepares, taking cuts over; openings through the found firewall on both paths; the mesh guards its own ports; ports kept as node settings; a converged genesis refuses a machine in use; designs 05, 07, 08, 09 and 17 in step
This commit is contained in:
@@ -442,7 +442,8 @@ stopgap until the manifest layer can carry a label and a domain separately
|
||||
|
||||
**Derived from what is assigned here, and from the overlay's shape** — a node's open ports are a
|
||||
consequence of what runs on it and who must reach it, not an independent declaration to keep in
|
||||
step by hand.
|
||||
step by hand. That is true of a converged node; an adopted one keeps the firewall it was found
|
||||
with until it converges (below).
|
||||
|
||||
**A rule names its source** ([ADR 0007](../../02-DECISIONS/0007-connectivity.md)).
|
||||
A rule with no source is open, and must say so rather than appear to restrict something. `scope:`
|
||||
@@ -536,16 +537,24 @@ is why the check reads packets.*
|
||||
### On an adopted node
|
||||
|
||||
*2026-09-22, [ADR 0100](../../02-DECISIONS/0100-a-node-in-use-is-adopted-before-it-is-converged.md).* **The firewall found on the machine stays in force**, and the mesh
|
||||
loads no table of its own there — neither genesis's base ruleset nor the derived one. The kernel
|
||||
runs every table at a hook and a drop in any is final, so a second, stricter table would close
|
||||
every port the machine serves. What the mesh needs reachable — its foundation's ports and each
|
||||
migrated module's `listens` — it opens *through the found firewall*, as rules marked as the mesh's,
|
||||
and it removes only rules it marked. Converging the node replaces the found firewall with the
|
||||
derived filter in one step, after previewing which open ports will close. The mesh must speak the
|
||||
found firewall in its own terms; one kind is found on the machines measured, and a machine with
|
||||
another is not covered until someone writes for it. *How it is checked:* the adoption bed asserts
|
||||
the found firewall's rules differ only by the mesh's marked rules, that a second machine enrols
|
||||
through them, and that after the flip the declared port is open and the undeclared one closed.
|
||||
loads no table of its own there — neither genesis's base ruleset nor the derived one. Every base
|
||||
chain at a hook runs and a drop in any is final, whatever the other firewall is written in, so a
|
||||
second, stricter table would close every port the machine serves. What the mesh needs reachable
|
||||
it declares as **openings**: a port, from where, on the incoming path or the forwarded path — a
|
||||
published container port is forwarded, and a firewall that filters only incoming traffic never
|
||||
sees it. The host converges each opening through the found firewall in that firewall's own terms,
|
||||
marks it as the mesh's, removes only what it marked, and re-checks every opening on each reconcile
|
||||
so a reload or a reboot does not lose it. An opening is state, not a command, so it travels over
|
||||
the link like any other resource. **The mesh protects its own ports itself**: its foundation's ports
|
||||
are opened from the private network and refused from anywhere else on the forwarded path, so the
|
||||
store stays unreachable from outside whether or not the found firewall filters forwarded traffic.
|
||||
One kind of found firewall is spoken; a machine with another is refused adoption rather than
|
||||
adopted unprotected. Converging the node previews what is reachable now — listening sockets and
|
||||
published ports — and what will close, then loads the derived filter and disables the found
|
||||
firewall without flushing it. *How it is checked:* the adoption bed asserts the found firewall's
|
||||
rules differ only by the mesh's marked rules, that the store is unreachable from off the private
|
||||
network, that a second machine enrols through the openings before and after a reload and a reboot,
|
||||
and that after the flip the declared port is open and the undeclared one closed.
|
||||
|
||||
## 5 — Certificates
|
||||
|
||||
|
||||
Reference in New Issue
Block a user