Guard the store and management ports on adopted nodes, and load the filter through a unit that never flushes the ruleset (hq ADR 0100)

This commit is contained in:
2026-09-22 17:32:32 +02:00
parent f4097b3c57
commit 0c37d7389d
4 changed files with 19 additions and 4 deletions
+10 -2
View File
@@ -19,14 +19,22 @@
"type": "package",
"package": "nftables"
},
{
"id": "unit",
"type": "file",
"path": "/etc/systemd/system/mesh-filter.service",
"content": "[Unit]\nDescription=The mesh's packet filter, derived from what is assigned to this node\nWants=network-pre.target\nBefore=network-pre.target\n\n[Service]\nType=oneshot\nRemainAfterExit=yes\nExecStart=nft -f /etc/nftables.conf\nExecReload=nft -f /etc/nftables.conf\nExecStop=nft delete table inet mesh\n\n[Install]\nWantedBy=multi-user.target\n",
"mode": "0644"
},
{
"id": "load",
"type": "service",
"unit": "nftables.service",
"unit": "mesh-filter.service",
"state": "running",
"boot": "enabled",
"restart-on": [
"filtering"
"filtering",
"unit"
]
}
]