Merge pull request 'Adoption mode: guards, and a filter unit that never flushes the ruleset (hq ADR 0100, 0103)' (#38) from feat/adoption-mode into main

This commit was merged in pull request #38.
This commit is contained in:
2026-09-22 21:01:56 +02:00
4 changed files with 28 additions and 3 deletions
+3
View File
@@ -53,6 +53,9 @@
"why": "modules on any machine that were granted a queue" "why": "modules on any machine that were granted a queue"
} }
], ],
"guards": [
15672
],
"resources": [ "resources": [
{ {
"id": "mesh-state", "id": "mesh-state",
+3 -2
View File
@@ -1,7 +1,8 @@
// The firewall's own code, in the module (novox/hq ADR 0039). The mesh computes this node's whole // The firewall's own code, in the module (novox/hq ADR 0039). The mesh computes this node's whole
// rule set from every module's `listens` and writes it to /etc/nftables.conf (novox/hq ADR 0045); // rule set from every module's `listens` and writes it to /etc/nftables.conf (novox/hq ADR 0045);
// the module loads it (the nftables service, reloaded whenever the rules change). This code exists // the module loads it through its own mesh-filter unit, reloaded whenever the rules change, whose
// only to read back what is actually enforced — the enforcement itself is declarative. // stop deletes only the mesh's table and never flushes the whole ruleset (novox/hq ADR 0100). This
// code exists only to read back what is actually enforced — the enforcement itself is declarative.
import { execFile } from "node:child_process"; import { execFile } from "node:child_process";
import { promisify } from "node:util"; import { promisify } from "node:util";
+19 -1
View File
@@ -19,13 +19,31 @@
"type": "package", "type": "package",
"package": "nftables" "package": "nftables"
}, },
{
"id": "unit",
"type": "file",
"path": "/etc/systemd/system/mesh-filter.service",
"content": "[Unit]\nDescription=The mesh's packet filter, derived from what is assigned to this node\nWants=network-pre.target\nBefore=network-pre.target\n\n[Service]\nType=oneshot\nRemainAfterExit=yes\nExecStart=nft -f /etc/nftables.conf\nExecReload=nft -f /etc/nftables.conf\nExecStop=nft delete table inet mesh\n\n[Install]\nWantedBy=multi-user.target\n",
"mode": "0644"
},
{
"id": "stock-unit-stop",
"type": "file",
"path": "/etc/systemd/system/nftables.service.d/mesh.conf",
"content": "# The mesh: stopping the stock unit deletes only the mesh's table, never the whole ruleset\n# (novox/hq ADR 0100) — a flush would take the container runtime's rules and any firewall with it.\n[Service]\nExecStop=\nExecStop=nft delete table inet mesh\n",
"mode": "0644"
},
{ {
"id": "load", "id": "load",
"type": "service", "type": "service",
"unit": "nftables.service", "unit": "mesh-filter.service",
"state": "running", "state": "running",
"boot": "enabled", "boot": "enabled",
"restart-on": [ "restart-on": [
"unit",
"stock-unit-stop"
],
"reload-on": [
"filtering" "filtering"
] ]
} }
+3
View File
@@ -32,6 +32,9 @@
"why": "modules on any machine that were granted a database" "why": "modules on any machine that were granted a database"
} }
], ],
"guards": [
5432
],
"serves": { "serves": {
"postgres-database": { "postgres-database": {
"port": 5432 "port": 5432