The packet filter's tools are a bundle the node's runtime serves; its container goes (hq to-be 38 WP4)

nftables drops its container, NET_ADMIN, the container-runtime capability, the runtime base
images and the Dockerfile; its tools are declared as a TypeScript bundle the toolchain compiles
and node-tools loads on every node. The runtime runs as the operator's account, so the tool
runs the filter's commands through sudo without a prompt when it is not root (ADR 0175 §4);
the filter file is the path the manifest's filtering names, no container env carrying it.
This commit is contained in:
jochen
2026-10-03 12:46:35 +02:00
parent 853ace3828
commit 5d01258b67
5 changed files with 38 additions and 64 deletions
+7 -1
View File
@@ -4,7 +4,7 @@
// and the same in an iptables-nft table. It refuses what is not the operator's to remove.
import { test } from "node:test";
import assert from "node:assert/strict";
import { FirewallClient, chainsJumpingTo, type Runner } from "../client.ts";
import { FirewallClient, chainsJumpingTo, escalated, type Runner } from "../client.ts";
const legacy = [
"-P INPUT ACCEPT", "-P FORWARD DROP", "-P OUTPUT ACCEPT",
@@ -72,3 +72,9 @@ test("which chains jump to a target is read from a listing", () => {
const listing = "table ip6 own {\n\tchain a {\n\t\tjump deny\n\t}\n\tchain b {\n\t\tgoto deny\n\t}\n\tchain deny {\n\t\tdrop\n\t}\n}\n";
assert.deepEqual(chainsJumpingTo(listing, "deny"), ["a", "b"]);
});
test("the filter's commands run as given by root and through sudo without a prompt by anyone else", () => {
assert.deepEqual(escalated("nft", ["list", "ruleset"], 0), ["nft", ["list", "ruleset"]]);
assert.deepEqual(escalated("nft", ["-f", "/etc/nftables.conf"], 1000), ["sudo", ["-n", "nft", "-f", "/etc/nftables.conf"]]);
assert.deepEqual(escalated("iptables-legacy", ["-S"], undefined), ["sudo", ["-n", "iptables-legacy", "-S"]]);
});