Commit Graph
2 Commits
Author SHA1 Message Date
jochen 5d01258b67 The packet filter's tools are a bundle the node's runtime serves; its container goes (hq to-be 38 WP4)
nftables drops its container, NET_ADMIN, the container-runtime capability, the runtime base
images and the Dockerfile; its tools are declared as a TypeScript bundle the toolchain compiles
and node-tools loads on every node. The runtime runs as the operator's account, so the tool
runs the filter's commands through sudo without a prompt when it is not root (ADR 0175 §4);
the filter file is the path the manifest's filtering names, no container env carrying it.
2026-10-03 12:46:35 +02:00
jschoubben 663e8143d4 nftables holds the node-packet-filter seat: rules, reload and remove, from a runtime with NET_ADMIN (hq ADR 0169)
The seat's three verbs over the machine's own tools: the filter as enforced
(nftables and the legacy filter), the mesh's own table reloaded from its file,
and one rule set the mesh did not write removed by the name the host reports
it under (ADR 0168) — a predecessor's chain loses its jumps and goes, the
runtime's user chain is emptied back to its return, a table of the machine's
own goes whole; the mesh's tables, the runtime's chains, a built-in chain and
an active found firewall's chains are refused. Tested over the shapes two
machines of the first mesh reported live. The module's own tool stays.
2026-10-02 13:28:33 +02:00