Design 07: the base ruleset closes the hub's port until the filter module derives one
This commit is contained in:
@@ -164,9 +164,13 @@ The bundle installs the packet filter and loads a base ruleset before the store
|
||||
up ([ADR 0088](../../02-DECISIONS/0088-the-foundation-filters-before-anything-listens.md)): drop by
|
||||
default, keep loopback, replies, ping, ssh, the bus and the registry, and the container runtime's
|
||||
networks through the forward chain. It is written into the same table the filter module derives,
|
||||
so that module replaces it wholesale once it can. **Checked** by the installer's bundle test
|
||||
(order and rules) and by the genesis bed, which probes the machine from outside for the length of
|
||||
the install: the store's port never answers, the bus's does.
|
||||
so that module replaces it wholesale once it can. Until it does, the machine admits nothing else —
|
||||
not the overlay hub's port, which is derived from the hub's endpoint — so the filter module is
|
||||
assigned to the control-node before a hub is placed there, as genesis does; a lab bed that raises
|
||||
the foundation without genesis must do the same, and says so by waiting for the hub's port in the
|
||||
ruleset the machine loaded. **Checked** by the installer's bundle test (order and rules) and by
|
||||
the genesis bed, which probes the machine from outside for the length of the install: the store's
|
||||
port never answers, the bus's does.
|
||||
|
||||
## Raising it
|
||||
|
||||
|
||||
Reference in New Issue
Block a user