Make the stock nftables unit's stop delete only the mesh's table on nodes that still have it enabled (hq ADR 0100)
This commit is contained in:
@@ -26,6 +26,13 @@
|
|||||||
"content": "[Unit]\nDescription=The mesh's packet filter, derived from what is assigned to this node\nWants=network-pre.target\nBefore=network-pre.target\n\n[Service]\nType=oneshot\nRemainAfterExit=yes\nExecStart=nft -f /etc/nftables.conf\nExecReload=nft -f /etc/nftables.conf\nExecStop=nft delete table inet mesh\n\n[Install]\nWantedBy=multi-user.target\n",
|
"content": "[Unit]\nDescription=The mesh's packet filter, derived from what is assigned to this node\nWants=network-pre.target\nBefore=network-pre.target\n\n[Service]\nType=oneshot\nRemainAfterExit=yes\nExecStart=nft -f /etc/nftables.conf\nExecReload=nft -f /etc/nftables.conf\nExecStop=nft delete table inet mesh\n\n[Install]\nWantedBy=multi-user.target\n",
|
||||||
"mode": "0644"
|
"mode": "0644"
|
||||||
},
|
},
|
||||||
|
{
|
||||||
|
"id": "stock-unit-stop",
|
||||||
|
"type": "file",
|
||||||
|
"path": "/etc/systemd/system/nftables.service.d/mesh.conf",
|
||||||
|
"content": "# The mesh: stopping the stock unit deletes only the mesh's table, never the whole ruleset\n# (novox/hq ADR 0100) — a flush would take the container runtime's rules and any firewall with it.\n[Service]\nExecStop=\nExecStop=nft delete table inet mesh\n",
|
||||||
|
"mode": "0644"
|
||||||
|
},
|
||||||
{
|
{
|
||||||
"id": "load",
|
"id": "load",
|
||||||
"type": "service",
|
"type": "service",
|
||||||
@@ -34,7 +41,8 @@
|
|||||||
"boot": "enabled",
|
"boot": "enabled",
|
||||||
"restart-on": [
|
"restart-on": [
|
||||||
"filtering",
|
"filtering",
|
||||||
"unit"
|
"unit",
|
||||||
|
"stock-unit-stop"
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
|
|||||||
Reference in New Issue
Block a user