From 84012fab2e41eb15b5db2e751476b79af818127d Mon Sep 17 00:00:00 2001 From: jochen Date: Tue, 22 Sep 2026 18:06:15 +0200 Subject: [PATCH] Make the stock nftables unit's stop delete only the mesh's table on nodes that still have it enabled (hq ADR 0100) --- modules/nftables/module.json | 10 +++++++++- 1 file changed, 9 insertions(+), 1 deletion(-) diff --git a/modules/nftables/module.json b/modules/nftables/module.json index 3a5c160..f381540 100644 --- a/modules/nftables/module.json +++ b/modules/nftables/module.json @@ -26,6 +26,13 @@ "content": "[Unit]\nDescription=The mesh's packet filter, derived from what is assigned to this node\nWants=network-pre.target\nBefore=network-pre.target\n\n[Service]\nType=oneshot\nRemainAfterExit=yes\nExecStart=nft -f /etc/nftables.conf\nExecReload=nft -f /etc/nftables.conf\nExecStop=nft delete table inet mesh\n\n[Install]\nWantedBy=multi-user.target\n", "mode": "0644" }, + { + "id": "stock-unit-stop", + "type": "file", + "path": "/etc/systemd/system/nftables.service.d/mesh.conf", + "content": "# The mesh: stopping the stock unit deletes only the mesh's table, never the whole ruleset\n# (novox/hq ADR 0100) — a flush would take the container runtime's rules and any firewall with it.\n[Service]\nExecStop=\nExecStop=nft delete table inet mesh\n", + "mode": "0644" + }, { "id": "load", "type": "service", @@ -34,7 +41,8 @@ "boot": "enabled", "restart-on": [ "filtering", - "unit" + "unit", + "stock-unit-stop" ] } ]