Merge pull request 'Adoption mode: guards, and a filter unit that never flushes the ruleset (hq ADR 0100, 0103)' (#38) from feat/adoption-mode into main
This commit was merged in pull request #38.
This commit is contained in:
@@ -53,6 +53,9 @@
|
|||||||
"why": "modules on any machine that were granted a queue"
|
"why": "modules on any machine that were granted a queue"
|
||||||
}
|
}
|
||||||
],
|
],
|
||||||
|
"guards": [
|
||||||
|
15672
|
||||||
|
],
|
||||||
"resources": [
|
"resources": [
|
||||||
{
|
{
|
||||||
"id": "mesh-state",
|
"id": "mesh-state",
|
||||||
|
|||||||
@@ -1,7 +1,8 @@
|
|||||||
// The firewall's own code, in the module (novox/hq ADR 0039). The mesh computes this node's whole
|
// The firewall's own code, in the module (novox/hq ADR 0039). The mesh computes this node's whole
|
||||||
// rule set from every module's `listens` and writes it to /etc/nftables.conf (novox/hq ADR 0045);
|
// rule set from every module's `listens` and writes it to /etc/nftables.conf (novox/hq ADR 0045);
|
||||||
// the module loads it (the nftables service, reloaded whenever the rules change). This code exists
|
// the module loads it through its own mesh-filter unit, reloaded whenever the rules change, whose
|
||||||
// only to read back what is actually enforced — the enforcement itself is declarative.
|
// stop deletes only the mesh's table and never flushes the whole ruleset (novox/hq ADR 0100). This
|
||||||
|
// code exists only to read back what is actually enforced — the enforcement itself is declarative.
|
||||||
|
|
||||||
import { execFile } from "node:child_process";
|
import { execFile } from "node:child_process";
|
||||||
import { promisify } from "node:util";
|
import { promisify } from "node:util";
|
||||||
|
|||||||
@@ -19,13 +19,31 @@
|
|||||||
"type": "package",
|
"type": "package",
|
||||||
"package": "nftables"
|
"package": "nftables"
|
||||||
},
|
},
|
||||||
|
{
|
||||||
|
"id": "unit",
|
||||||
|
"type": "file",
|
||||||
|
"path": "/etc/systemd/system/mesh-filter.service",
|
||||||
|
"content": "[Unit]\nDescription=The mesh's packet filter, derived from what is assigned to this node\nWants=network-pre.target\nBefore=network-pre.target\n\n[Service]\nType=oneshot\nRemainAfterExit=yes\nExecStart=nft -f /etc/nftables.conf\nExecReload=nft -f /etc/nftables.conf\nExecStop=nft delete table inet mesh\n\n[Install]\nWantedBy=multi-user.target\n",
|
||||||
|
"mode": "0644"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"id": "stock-unit-stop",
|
||||||
|
"type": "file",
|
||||||
|
"path": "/etc/systemd/system/nftables.service.d/mesh.conf",
|
||||||
|
"content": "# The mesh: stopping the stock unit deletes only the mesh's table, never the whole ruleset\n# (novox/hq ADR 0100) — a flush would take the container runtime's rules and any firewall with it.\n[Service]\nExecStop=\nExecStop=nft delete table inet mesh\n",
|
||||||
|
"mode": "0644"
|
||||||
|
},
|
||||||
{
|
{
|
||||||
"id": "load",
|
"id": "load",
|
||||||
"type": "service",
|
"type": "service",
|
||||||
"unit": "nftables.service",
|
"unit": "mesh-filter.service",
|
||||||
"state": "running",
|
"state": "running",
|
||||||
"boot": "enabled",
|
"boot": "enabled",
|
||||||
"restart-on": [
|
"restart-on": [
|
||||||
|
"unit",
|
||||||
|
"stock-unit-stop"
|
||||||
|
],
|
||||||
|
"reload-on": [
|
||||||
"filtering"
|
"filtering"
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -32,6 +32,9 @@
|
|||||||
"why": "modules on any machine that were granted a database"
|
"why": "modules on any machine that were granted a database"
|
||||||
}
|
}
|
||||||
],
|
],
|
||||||
|
"guards": [
|
||||||
|
5432
|
||||||
|
],
|
||||||
"serves": {
|
"serves": {
|
||||||
"postgres-database": {
|
"postgres-database": {
|
||||||
"port": 5432
|
"port": 5432
|
||||||
|
|||||||
Reference in New Issue
Block a user