Guard the store and management ports on adopted nodes, and load the filter through a unit that never flushes the ruleset (hq ADR 0100)
This commit is contained in:
@@ -1,7 +1,8 @@
|
||||
// The firewall's own code, in the module (novox/hq ADR 0039). The mesh computes this node's whole
|
||||
// rule set from every module's `listens` and writes it to /etc/nftables.conf (novox/hq ADR 0045);
|
||||
// the module loads it (the nftables service, reloaded whenever the rules change). This code exists
|
||||
// only to read back what is actually enforced — the enforcement itself is declarative.
|
||||
// the module loads it through its own mesh-filter unit, reloaded whenever the rules change, whose
|
||||
// stop deletes only the mesh's table and never flushes the whole ruleset (novox/hq ADR 0100). This
|
||||
// code exists only to read back what is actually enforced — the enforcement itself is declarative.
|
||||
|
||||
import { execFile } from "node:child_process";
|
||||
import { promisify } from "node:util";
|
||||
|
||||
Reference in New Issue
Block a user