firewall: the module that applies the mesh-computed packet filter (ADR 0050)
The missing applier. mesh-control already derives a node's whole nftables rule
set from the union of its modules' listens and writes it to /etc/nftables.conf;
this module declares filtering:{into} to receive it and loads it — the nftables
service, reloaded on 'filtering' whenever the rules change. A firewall_rules
tool reads the live table so a declared scope can be checked against what is
really enforced. Closes the loop from listens.from to a packet actually dropped.
Manifest parses; tool typechecks.
This commit is contained in:
@@ -0,0 +1,21 @@
|
|||||||
|
// The firewall's own code, in the module (novox/hq ADR 0044). The mesh computes this node's whole
|
||||||
|
// rule set from every module's `listens` and writes it to /etc/nftables.conf (novox/hq ADR 0050);
|
||||||
|
// the module loads it (the nftables service, reloaded whenever the rules change). This code exists
|
||||||
|
// only to read back what is actually enforced — the enforcement itself is declarative.
|
||||||
|
|
||||||
|
import { execFile } from "node:child_process";
|
||||||
|
import { promisify } from "node:util";
|
||||||
|
|
||||||
|
const run = promisify(execFile);
|
||||||
|
|
||||||
|
export class FirewallClient {
|
||||||
|
static fromEnv(_env: NodeJS.ProcessEnv = process.env): FirewallClient {
|
||||||
|
return new FirewallClient();
|
||||||
|
}
|
||||||
|
|
||||||
|
/** The mesh's live table — exactly what is dropping and accepting on this node right now. */
|
||||||
|
async ruleset(): Promise<string> {
|
||||||
|
const { stdout } = await run("nft", ["list", "table", "inet", "mesh"]);
|
||||||
|
return stdout;
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,33 @@
|
|||||||
|
{
|
||||||
|
"module": "firewall",
|
||||||
|
"version": "1",
|
||||||
|
"capabilities": [
|
||||||
|
"firewall"
|
||||||
|
],
|
||||||
|
"claims": [
|
||||||
|
{
|
||||||
|
"name": "the-packet-filter",
|
||||||
|
"scope": "node"
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"filtering": {
|
||||||
|
"into": "/etc/nftables.conf"
|
||||||
|
},
|
||||||
|
"resources": [
|
||||||
|
{
|
||||||
|
"id": "package",
|
||||||
|
"type": "package",
|
||||||
|
"package": "nftables"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"id": "load",
|
||||||
|
"type": "service",
|
||||||
|
"unit": "nftables.service",
|
||||||
|
"state": "running",
|
||||||
|
"boot": "enabled",
|
||||||
|
"restart-on": [
|
||||||
|
"filtering"
|
||||||
|
]
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
@@ -0,0 +1,14 @@
|
|||||||
|
{
|
||||||
|
"name": "@novox/module-firewall",
|
||||||
|
"version": "0.1.0",
|
||||||
|
"description": "firewall — applies the mesh-computed packet filter (ADR 0050). Its diagnostic tool lives here.
|
||||||
|
"type": "module",
|
||||||
|
"private": true,
|
||||||
|
"dependencies": {
|
||||||
|
"@novox/mesh-sdk": "^0.1.0"
|
||||||
|
},
|
||||||
|
"devDependencies": {
|
||||||
|
"@types/node": "^22.0.0",
|
||||||
|
"typescript": "^5.6.0"
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,19 @@
|
|||||||
|
// firewall's tools — one, and the useful one: what is actually enforced. The rules are the mesh's,
|
||||||
|
// computed from every module's listens; this reads the live table so a declared scope can be checked
|
||||||
|
// against what the packet filter is really doing.
|
||||||
|
|
||||||
|
import { registerModuleTools, type ToolDefinition } from "@novox/mesh-sdk/tools";
|
||||||
|
import { FirewallClient } from "../client.js";
|
||||||
|
|
||||||
|
export function getFirewallTools(firewall: FirewallClient): ToolDefinition[] {
|
||||||
|
return [
|
||||||
|
{
|
||||||
|
name: "firewall_rules",
|
||||||
|
description: "The mesh's live nftables rules on this node — what is actually accepting and dropping.",
|
||||||
|
input: {},
|
||||||
|
run: async () => ({ ruleset: await firewall.ruleset() }),
|
||||||
|
},
|
||||||
|
];
|
||||||
|
}
|
||||||
|
|
||||||
|
registerModuleTools("firewall", () => getFirewallTools(FirewallClient.fromEnv()));
|
||||||
@@ -0,0 +1,15 @@
|
|||||||
|
{
|
||||||
|
"compilerOptions": {
|
||||||
|
"target": "ES2022",
|
||||||
|
"module": "NodeNext",
|
||||||
|
"moduleResolution": "NodeNext",
|
||||||
|
"strict": true,
|
||||||
|
"esModuleInterop": true,
|
||||||
|
"skipLibCheck": true,
|
||||||
|
"noEmit": true
|
||||||
|
},
|
||||||
|
"include": [
|
||||||
|
"client.ts",
|
||||||
|
"tools/index.ts"
|
||||||
|
]
|
||||||
|
}
|
||||||
Reference in New Issue
Block a user