ADR 0100: the guard lets the machine itself through; in use is a non-loopback listener; openings say from where; 09 in step with the flip
This commit is contained in:
@@ -179,7 +179,7 @@ machine already serving under a predecessor has a firewall of its own, and a sec
|
||||
table would close everything it serves. There the base ruleset is not loaded and the filter module
|
||||
is not assigned until the node converges; the foundation's ports are opened through the found
|
||||
firewall, and a table of the mesh's that only refuses keeps the store's port and the broker's
|
||||
management port from anyone off the private network — the same promise, the store's port never
|
||||
management port from anyone but the private network and the machine itself — the same promise, the store's port never
|
||||
answering from outside, kept by other means. The bus and the registry stay reachable from anywhere,
|
||||
as they are here, because a node enrols and pulls before it has a private-network address. The
|
||||
foundation's ports themselves are the node's, given at genesis and kept as its settings. **Checked**
|
||||
|
||||
@@ -537,21 +537,25 @@ is why the check reads packets.*
|
||||
### On an adopted node
|
||||
|
||||
*2026-09-22, [ADR 0100](../../02-DECISIONS/0100-a-node-in-use-is-adopted-before-it-is-converged.md).* **The firewall found on the machine stays in force**, and the mesh
|
||||
loads no table there that drops by default or that accepts — neither genesis's base ruleset nor
|
||||
loads no table there that drops by default or holds an accept — neither genesis's base ruleset nor
|
||||
the derived one. Every base chain at a hook runs and a drop in any is final, whatever the other
|
||||
firewall is written in, so a second, stricter table would close every port the machine serves, and
|
||||
an accept in one would open nothing the found firewall drops. What the mesh needs reachable it
|
||||
declares as **openings**: a port, from where, on the incoming path or the forwarded path — a
|
||||
published container port is forwarded, and a firewall that filters only incoming traffic never
|
||||
sees it. The controller derives them from what the filter would be derived from: the assigned
|
||||
modules' `listens`, the hub's port, the foundation's ports. The host converges each opening through
|
||||
sees it. The controller derives them from what the filter would be derived from, each from where
|
||||
the filter would admit it: the assigned modules' `listens`, the hub's port, the bus and the registry
|
||||
from anywhere; the store's port and the broker's management port from the private network. The host converges each opening through
|
||||
the found firewall in that firewall's own terms, marks it as the mesh's, removes only what it
|
||||
marked, and re-checks every opening on each reconcile so a reload or a reboot does not lose it for
|
||||
longer than one reconcile. An opening is state, not a command, so it travels over the link like any
|
||||
other resource. **The mesh guards its own ports in a table of its own that only refuses** —
|
||||
accepting by default and holding nothing but refusals, so it cannot close what the machine serves,
|
||||
and the found firewall's reload does not touch it. It refuses the store's port and the broker's
|
||||
management port from outside the private network, matched on the port the packet was sent to; the
|
||||
passing everything by default and holding nothing but refusals of the foundation's own two ports,
|
||||
checked free at genesis, so it cannot close what the machine serves, and the found firewall's
|
||||
reload does not touch it. It refuses the store's port and the broker's management port except from
|
||||
the private network and the machine itself — loopback and the container runtime's networks — at
|
||||
the prerouting hook, before the container runtime redirects the packet, so it matches the port the
|
||||
packet was sent to, for both address families; the
|
||||
bus, the registry and the hub's port stay reachable from anywhere, as a node enrols and pulls
|
||||
before it has a private-network address. One kind of found firewall is spoken; a machine with none
|
||||
needs no openings, and a machine with another kind is refused adoption. Converging the node refuses
|
||||
@@ -560,7 +564,7 @@ sockets and published ports — what will close and which modules it will take,
|
||||
derived filter in place of the refusal-only table and disables the found firewall without flushing
|
||||
it. *How it is checked:* the adoption bed asserts the found firewall's rules differ only by the
|
||||
mesh's marked rules, that the store is unreachable from off the private network before and after
|
||||
the found firewall reloads, that a machine not yet enrolled reaches the bus, that a second machine
|
||||
the found firewall reloads and reachable from a container on the node, that a machine not yet enrolled reaches the bus, that a second machine
|
||||
enrols through the openings before and after a reload and a reboot, and that after the flip the
|
||||
declared port is open and the undeclared one closed.
|
||||
|
||||
|
||||
@@ -297,11 +297,13 @@ the others — and the controller records it and says so in every declaration, w
|
||||
**taken** on that node. On an adopted node what is found is held until its module is taken
|
||||
([05-the-node-host](05-the-node-host.md)): assigning a module prepares it, taking it is its
|
||||
cutover. The firewall found there stays in force and the mesh opens what it needs through it
|
||||
([08-connectivity](08-connectivity.md)). **Converging is one act per node, previewed**: it lists
|
||||
what is reachable on the machine now — listening sockets and published ports — and whether an
|
||||
assigned module declares each or it will close, then takes every module not yet taken, loads the
|
||||
mesh's own filter and disables the found one without flushing it. Returning a converged node to
|
||||
adopted enables the found firewall again. *How it is checked:* a lab bed prepares a machine the way
|
||||
([08-connectivity](08-connectivity.md)). **Converging is one act per node, previewed**: it refuses
|
||||
while an assigned module still holds a found container; otherwise it lists what is reachable on the
|
||||
machine now — listening sockets and published ports — whether an assigned module declares each or
|
||||
it will close, and which modules it will take, then takes them, loads the mesh's own filter in place
|
||||
of its refusal-only table and disables the found firewall without flushing it. Returning a
|
||||
converged node to adopted unloads the derived filter, restores the refusal-only table, enables the
|
||||
found firewall again and converges the openings through it; what was taken stays taken. *How it is checked:* a lab bed prepares a machine the way
|
||||
a predecessor leaves one and asserts nothing that serves changes until a module is taken or the
|
||||
node is converged, and that the flip closes exactly what the preview said.
|
||||
|
||||
|
||||
@@ -113,8 +113,8 @@ checks the private network's range does not overlap a tunnel the predecessor run
|
||||
**does not load the base ruleset**: the machine's own firewall already filters; the mesh opens its
|
||||
foundation's ports through it and keeps the store from outside with a table of its own that only
|
||||
refuses ([08-connectivity](08-connectivity.md)). **A converged genesis refuses a machine in use** —
|
||||
a container running, or a port listening that is neither ssh nor the operating system's own — so a
|
||||
forgotten flag cannot close a working machine. *How it is checked:* the adoption bed raises genesis converged on a machine in use and
|
||||
a container running, or a port listening on an address other than loopback that is not ssh's —
|
||||
and names every one it counted, so a forgotten flag cannot close a working machine. *How it is checked:* the adoption bed raises genesis converged on a machine in use and
|
||||
asserts the refusal, then adopted with the registry's port held and asserts the refusal names its
|
||||
holder, then with another port given asserts the foundation comes up, stays on that port once
|
||||
adopted as modules, and the machine's service is still reachable.
|
||||
|
||||
Reference in New Issue
Block a user