Issue 047 — and the half that runs the other way #42

Merged
jschoubben merged 1 commits from issue/047-the-other-half into main 2026-09-14 13:09:37 +00:00
Owner

The report covered ports the firewall cannot close. There is a matching fault about ports it does close and should not, and together they are worse than either alone.

The rules are computed from what modules declare they listen on. During a migration the mesh knows about almost nothing — the services are still running under the system being replaced — so it opens almost nothing, and anything listening on the host rather than in a container is dropped.

Including ssh. No module in the catalogue declares an ssh port, and the generator has no built-in allowance for one. The session that loads the rules survives, because established connections are accepted; it survives until it drops. On a machine reached over the network that is the difference between a mistake and a journey to a rescue console.

So: the mesh gets no say over the ports most worth protecting, and full say over the one that must never be closed by accident.

The report covered ports the firewall cannot close. There is a matching fault about ports it does close and should not, and together they are worse than either alone. The rules are computed from what modules declare they listen on. During a migration the mesh knows about almost nothing — the services are still running under the system being replaced — so it opens almost nothing, and anything listening on the host rather than in a container is dropped. Including ssh. No module in the catalogue declares an ssh port, and the generator has no built-in allowance for one. The session that loads the rules survives, because established connections are accepted; it survives until it drops. On a machine reached over the network that is the difference between a mistake and a journey to a rescue console. So: the mesh gets no say over the ports most worth protecting, and full say over the one that must never be closed by accident.
jschoubben added 1 commit 2026-09-14 13:09:30 +00:00
The report covered ports the firewall cannot close. The matching fault is ports
it does close and should not: rules come from what modules declare, a migrating
mesh knows about almost nothing, and anything listening on the host is dropped.

No module declares an ssh port and the generator has no allowance for one. The
session that loads the rules survives on conntrack until it drops, and then the
machine is reached from a rescue console.
jschoubben merged commit 3121e47245 into main 2026-09-14 13:09:37 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/hq#42