Design 07: the base ruleset closes the hub's port until the filter module derives one
This commit is contained in:
@@ -164,9 +164,13 @@ The bundle installs the packet filter and loads a base ruleset before the store
|
|||||||
up ([ADR 0088](../../02-DECISIONS/0088-the-foundation-filters-before-anything-listens.md)): drop by
|
up ([ADR 0088](../../02-DECISIONS/0088-the-foundation-filters-before-anything-listens.md)): drop by
|
||||||
default, keep loopback, replies, ping, ssh, the bus and the registry, and the container runtime's
|
default, keep loopback, replies, ping, ssh, the bus and the registry, and the container runtime's
|
||||||
networks through the forward chain. It is written into the same table the filter module derives,
|
networks through the forward chain. It is written into the same table the filter module derives,
|
||||||
so that module replaces it wholesale once it can. **Checked** by the installer's bundle test
|
so that module replaces it wholesale once it can. Until it does, the machine admits nothing else —
|
||||||
(order and rules) and by the genesis bed, which probes the machine from outside for the length of
|
not the overlay hub's port, which is derived from the hub's endpoint — so the filter module is
|
||||||
the install: the store's port never answers, the bus's does.
|
assigned to the control-node before a hub is placed there, as genesis does; a lab bed that raises
|
||||||
|
the foundation without genesis must do the same, and says so by waiting for the hub's port in the
|
||||||
|
ruleset the machine loaded. **Checked** by the installer's bundle test (order and rules) and by
|
||||||
|
the genesis bed, which probes the machine from outside for the length of the install: the store's
|
||||||
|
port never answers, the bus's does.
|
||||||
|
|
||||||
## Raising it
|
## Raising it
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user