Extends ADR 0168. The node-packet-filter seat serves rules, reload and remove; every holder implements them; a holder may add its own tools; a container may declare a capability; 0168's "by hand" is read as "by the operator, through the seat". Designs 33 and 08 revised; index regenerated; checks pass. Built on the matching branches in mesh-host (capabilities), mesh-controller (the seat's verbs) and mesh-catalog (the nftables module's runtime and verbs).
Extends ADR 0168. The `node-packet-filter` seat serves `rules`, `reload` and `remove`; every holder implements them; a holder may add its own tools; a container may declare a capability; 0168's "by hand" is read as "by the operator, through the seat". Designs 33 and 08 revised; index regenerated; checks pass. Built on the matching branches in mesh-host (capabilities), mesh-controller (the seat's verbs) and mesh-catalog (the nftables module's runtime and verbs).
Designs 33 and 08 revised. The first node-scoped seat with verbs: rules,
reload, remove; the nftables module holds it from a runtime with NET_ADMIN,
the first container to declare a capability.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Extends ADR 0168. The
node-packet-filterseat servesrules,reloadandremove; every holder implements them; a holder may add its own tools; a container may declare a capability; 0168's "by hand" is read as "by the operator, through the seat". Designs 33 and 08 revised; index regenerated; checks pass. Built on the matching branches in mesh-host (capabilities), mesh-controller (the seat's verbs) and mesh-catalog (the nftables module's runtime and verbs).