Research 020: what a bundled tool is given; design 38 WP4: fail2ban followed, proven live

This commit is contained in:
jochen
2026-10-03 15:11:08 +02:00
parent 22e96e5bc7
commit ee17cddb74
3 changed files with 129 additions and 1 deletions
@@ -215,7 +215,15 @@ file and answers with the table, `remove` refuses the mesh's own table by name
`mesh-nftables` on any, the container's credential is gone with it, and `status` is well. One thing
the step found is issue
[210](../../04-ISSUES/210-the-host-re-creates-the-nodes-runtime-on-every-reconcile/00-report.md):
the host re-creates the runtime's process on every reconcile.
the host re-creates the runtime's process on every reconcile (resolved the same day, mesh-host #80).
*fail2ban followed 2026-10-03* (mesh-catalog `aa5bf7d`), the same shape: container, base images,
credential and state directory gone, the client through `sudo` since the daemon's socket is root's;
proven on all four machines — `status`, `banned` and the module's own `fail2ban_settings` answer from
the runtime, no `mesh-fail2ban` container, the runtime serving both bundles. Two holders moved; of the
thirty-three tool containers the catalogue held, thirty-one remain, and all but these two carried their
module's configuration and secrets in the container's environment, which a bundle does not have — the
question research [020](../../01-RESEARCH/020-what-a-bundled-tool-is-given/00-overview.md) opens
before the rest move.
## WP5 — The shell, on a server first