ADR 0100: the guard lets the machine itself through; in use is a non-loopback listener; openings say from where; 09 in step with the flip
This commit is contained in:
@@ -179,7 +179,7 @@ machine already serving under a predecessor has a firewall of its own, and a sec
|
||||
table would close everything it serves. There the base ruleset is not loaded and the filter module
|
||||
is not assigned until the node converges; the foundation's ports are opened through the found
|
||||
firewall, and a table of the mesh's that only refuses keeps the store's port and the broker's
|
||||
management port from anyone off the private network — the same promise, the store's port never
|
||||
management port from anyone but the private network and the machine itself — the same promise, the store's port never
|
||||
answering from outside, kept by other means. The bus and the registry stay reachable from anywhere,
|
||||
as they are here, because a node enrols and pulls before it has a private-network address. The
|
||||
foundation's ports themselves are the node's, given at genesis and kept as its settings. **Checked**
|
||||
|
||||
Reference in New Issue
Block a user