ADR 0100 after re-review: the bus and registry stay reachable for enrolment; the mesh guards the store in a table that only refuses; a machine in use defined; the flip refuses while a found container is held; held containers and returning to adopted spelled out
This commit is contained in:
@@ -537,24 +537,32 @@ is why the check reads packets.*
|
||||
### On an adopted node
|
||||
|
||||
*2026-09-22, [ADR 0100](../../02-DECISIONS/0100-a-node-in-use-is-adopted-before-it-is-converged.md).* **The firewall found on the machine stays in force**, and the mesh
|
||||
loads no table of its own there — neither genesis's base ruleset nor the derived one. Every base
|
||||
chain at a hook runs and a drop in any is final, whatever the other firewall is written in, so a
|
||||
second, stricter table would close every port the machine serves. What the mesh needs reachable
|
||||
it declares as **openings**: a port, from where, on the incoming path or the forwarded path — a
|
||||
loads no table there that drops by default or that accepts — neither genesis's base ruleset nor
|
||||
the derived one. Every base chain at a hook runs and a drop in any is final, whatever the other
|
||||
firewall is written in, so a second, stricter table would close every port the machine serves, and
|
||||
an accept in one would open nothing the found firewall drops. What the mesh needs reachable it
|
||||
declares as **openings**: a port, from where, on the incoming path or the forwarded path — a
|
||||
published container port is forwarded, and a firewall that filters only incoming traffic never
|
||||
sees it. The host converges each opening through the found firewall in that firewall's own terms,
|
||||
marks it as the mesh's, removes only what it marked, and re-checks every opening on each reconcile
|
||||
so a reload or a reboot does not lose it. An opening is state, not a command, so it travels over
|
||||
the link like any other resource. **The mesh protects its own ports itself**: its foundation's ports
|
||||
are opened from the private network and refused from anywhere else on the forwarded path, so the
|
||||
store stays unreachable from outside whether or not the found firewall filters forwarded traffic.
|
||||
One kind of found firewall is spoken; a machine with another is refused adoption rather than
|
||||
adopted unprotected. Converging the node previews what is reachable now — listening sockets and
|
||||
published ports — and what will close, then loads the derived filter and disables the found
|
||||
firewall without flushing it. *How it is checked:* the adoption bed asserts the found firewall's
|
||||
rules differ only by the mesh's marked rules, that the store is unreachable from off the private
|
||||
network, that a second machine enrols through the openings before and after a reload and a reboot,
|
||||
and that after the flip the declared port is open and the undeclared one closed.
|
||||
sees it. The controller derives them from what the filter would be derived from: the assigned
|
||||
modules' `listens`, the hub's port, the foundation's ports. The host converges each opening through
|
||||
the found firewall in that firewall's own terms, marks it as the mesh's, removes only what it
|
||||
marked, and re-checks every opening on each reconcile so a reload or a reboot does not lose it for
|
||||
longer than one reconcile. An opening is state, not a command, so it travels over the link like any
|
||||
other resource. **The mesh guards its own ports in a table of its own that only refuses** —
|
||||
accepting by default and holding nothing but refusals, so it cannot close what the machine serves,
|
||||
and the found firewall's reload does not touch it. It refuses the store's port and the broker's
|
||||
management port from outside the private network, matched on the port the packet was sent to; the
|
||||
bus, the registry and the hub's port stay reachable from anywhere, as a node enrols and pulls
|
||||
before it has a private-network address. One kind of found firewall is spoken; a machine with none
|
||||
needs no openings, and a machine with another kind is refused adoption. Converging the node refuses
|
||||
while a found container is still held; otherwise it previews what is reachable now — listening
|
||||
sockets and published ports — what will close and which modules it will take, then loads the
|
||||
derived filter in place of the refusal-only table and disables the found firewall without flushing
|
||||
it. *How it is checked:* the adoption bed asserts the found firewall's rules differ only by the
|
||||
mesh's marked rules, that the store is unreachable from off the private network before and after
|
||||
the found firewall reloads, that a machine not yet enrolled reaches the bus, that a second machine
|
||||
enrols through the openings before and after a reload and a reboot, and that after the flip the
|
||||
declared port is open and the undeclared one closed.
|
||||
|
||||
## 5 — Certificates
|
||||
|
||||
|
||||
Reference in New Issue
Block a user