ADR 0100 after review: found means unrecorded; assigning prepares, taking cuts over; openings through the found firewall on both paths; the mesh guards its own ports; ports kept as node settings; a converged genesis refuses a machine in use; designs 05, 07, 08, 09 and 17 in step

This commit is contained in:
2026-09-22 16:28:31 +02:00
parent 111456abb5
commit 02c40bcab4
7 changed files with 250 additions and 136 deletions
+20 -11
View File
@@ -442,7 +442,8 @@ stopgap until the manifest layer can carry a label and a domain separately
**Derived from what is assigned here, and from the overlay's shape** — a node's open ports are a
consequence of what runs on it and who must reach it, not an independent declaration to keep in
step by hand.
step by hand. That is true of a converged node; an adopted one keeps the firewall it was found
with until it converges (below).
**A rule names its source** ([ADR 0007](../../02-DECISIONS/0007-connectivity.md)).
A rule with no source is open, and must say so rather than appear to restrict something. `scope:`
@@ -536,16 +537,24 @@ is why the check reads packets.*
### On an adopted node
*2026-09-22, [ADR 0100](../../02-DECISIONS/0100-a-node-in-use-is-adopted-before-it-is-converged.md).* **The firewall found on the machine stays in force**, and the mesh
loads no table of its own there — neither genesis's base ruleset nor the derived one. The kernel
runs every table at a hook and a drop in any is final, so a second, stricter table would close
every port the machine serves. What the mesh needs reachable — its foundation's ports and each
migrated module's `listens` — it opens *through the found firewall*, as rules marked as the mesh's,
and it removes only rules it marked. Converging the node replaces the found firewall with the
derived filter in one step, after previewing which open ports will close. The mesh must speak the
found firewall in its own terms; one kind is found on the machines measured, and a machine with
another is not covered until someone writes for it. *How it is checked:* the adoption bed asserts
the found firewall's rules differ only by the mesh's marked rules, that a second machine enrols
through them, and that after the flip the declared port is open and the undeclared one closed.
loads no table of its own there — neither genesis's base ruleset nor the derived one. Every base
chain at a hook runs and a drop in any is final, whatever the other firewall is written in, so a
second, stricter table would close every port the machine serves. What the mesh needs reachable
it declares as **openings**: a port, from where, on the incoming path or the forwarded path — a
published container port is forwarded, and a firewall that filters only incoming traffic never
sees it. The host converges each opening through the found firewall in that firewall's own terms,
marks it as the mesh's, removes only what it marked, and re-checks every opening on each reconcile
so a reload or a reboot does not lose it. An opening is state, not a command, so it travels over
the link like any other resource. **The mesh protects its own ports itself**: its foundation's ports
are opened from the private network and refused from anywhere else on the forwarded path, so the
store stays unreachable from outside whether or not the found firewall filters forwarded traffic.
One kind of found firewall is spoken; a machine with another is refused adoption rather than
adopted unprotected. Converging the node previews what is reachable now — listening sockets and
published ports — and what will close, then loads the derived filter and disables the found
firewall without flushing it. *How it is checked:* the adoption bed asserts the found firewall's
rules differ only by the mesh's marked rules, that the store is unreachable from off the private
network, that a second machine enrols through the openings before and after a reload and a reboot,
and that after the flip the declared port is open and the undeclared one closed.
## 5 — Certificates