firewall: the module that applies the mesh-computed packet filter (ADR 0050)
The missing applier. mesh-control already derives a node's whole nftables rule
set from the union of its modules' listens and writes it to /etc/nftables.conf;
this module declares filtering:{into} to receive it and loads it — the nftables
service, reloaded on 'filtering' whenever the rules change. A firewall_rules
tool reads the live table so a declared scope can be checked against what is
really enforced. Closes the loop from listens.from to a packet actually dropped.
Manifest parses; tool typechecks.
This commit is contained in:
@@ -0,0 +1,21 @@
|
||||
// The firewall's own code, in the module (novox/hq ADR 0044). The mesh computes this node's whole
|
||||
// rule set from every module's `listens` and writes it to /etc/nftables.conf (novox/hq ADR 0050);
|
||||
// the module loads it (the nftables service, reloaded whenever the rules change). This code exists
|
||||
// only to read back what is actually enforced — the enforcement itself is declarative.
|
||||
|
||||
import { execFile } from "node:child_process";
|
||||
import { promisify } from "node:util";
|
||||
|
||||
const run = promisify(execFile);
|
||||
|
||||
export class FirewallClient {
|
||||
static fromEnv(_env: NodeJS.ProcessEnv = process.env): FirewallClient {
|
||||
return new FirewallClient();
|
||||
}
|
||||
|
||||
/** The mesh's live table — exactly what is dropping and accepting on this node right now. */
|
||||
async ruleset(): Promise<string> {
|
||||
const { stdout } = await run("nft", ["list", "table", "inet", "mesh"]);
|
||||
return stdout;
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user