Found by rehearsing the firewall cutover in the lab before doing it on an anchor, which is exactly what a rehearsal is for.
Three machines, one probing another, one change between two measurements: loading the mesh's rules refuses an ordinary port on the host and leaves a container port published on all addresses reachable. Same prober, same ports, same second.
It is deliberate. The mesh's table hooks input and output and no forward chain, because dropping in forward would drop container traffic the runtime explicitly allowed and stop every container on the node. That reasoning is sound — but traffic to a published port never traverses input, so a default-drop input chain says nothing about it, and the firewall is silent on the ports most likely to matter.
Measured rather than argued: the anchor this mesh is to be installed onto publishes 38 distinct container ports on all addresses — a document store, three cache sentinels, mail transfer and retrieval, the forge's own SSH, and thirty more. All are filtered today by the system being replaced, which hooks exactly the path this one leaves alone. So the cutover opens all thirty-eight at once, silently, on a machine with a public address, while every check reports a firewall that is up and dropping by default.
That is the worst shape a security fault takes: the mechanism is present, it reports success, and what it is believed to do is not what it does.
Found by rehearsing the firewall cutover in the lab before doing it on an anchor, which is exactly what a rehearsal is for.
Three machines, one probing another, one change between two measurements: loading the mesh's rules refuses an ordinary port on the host and leaves a container port published on all addresses reachable. Same prober, same ports, same second.
It is deliberate. The mesh's table hooks input and output and no forward chain, because dropping in forward would drop container traffic the runtime explicitly allowed and stop every container on the node. That reasoning is sound — but traffic to a published port never traverses input, so a default-drop input chain says nothing about it, and the firewall is silent on the ports most likely to matter.
Measured rather than argued: the anchor this mesh is to be installed onto publishes 38 distinct container ports on all addresses — a document store, three cache sentinels, mail transfer and retrieval, the forge's own SSH, and thirty more. All are filtered today by the system being replaced, which hooks exactly the path this one leaves alone. So the cutover opens all thirty-eight at once, silently, on a machine with a public address, while every check reports a firewall that is up and dropping by default.
That is the worst shape a security fault takes: the mechanism is present, it reports success, and what it is believed to do is not what it does.
Rehearsed on three lab machines before doing it on an anchor: loading the mesh's
rules refuses an ordinary host port and leaves a published container port
reachable, same prober, same second.
It is deliberate — no forward chain, because dropping there would stop every
container — but traffic to a published port never reaches the input chain, so
the firewall is silent about it. The anchor publishes 38 such ports today, all
filtered by the system being replaced, so the cutover would open every one of
them while reporting a firewall that is up.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Found by rehearsing the firewall cutover in the lab before doing it on an anchor, which is exactly what a rehearsal is for.
Three machines, one probing another, one change between two measurements: loading the mesh's rules refuses an ordinary port on the host and leaves a container port published on all addresses reachable. Same prober, same ports, same second.
It is deliberate. The mesh's table hooks input and output and no forward chain, because dropping in forward would drop container traffic the runtime explicitly allowed and stop every container on the node. That reasoning is sound — but traffic to a published port never traverses input, so a default-drop input chain says nothing about it, and the firewall is silent on the ports most likely to matter.
Measured rather than argued: the anchor this mesh is to be installed onto publishes 38 distinct container ports on all addresses — a document store, three cache sentinels, mail transfer and retrieval, the forge's own SSH, and thirty more. All are filtered today by the system being replaced, which hooks exactly the path this one leaves alone. So the cutover opens all thirty-eight at once, silently, on a machine with a public address, while every check reports a firewall that is up and dropping by default.
That is the worst shape a security fault takes: the mechanism is present, it reports success, and what it is believed to do is not what it does.