Adoption mode: guards, and a filter unit that never flushes the ruleset (hq ADR 0100, 0103) #38

Merged
jschoubben merged 3 commits from feat/adoption-mode into main 2026-09-22 19:01:56 +00:00
Owner

Merge after mesh-controller. Its strict manifest parser must know guards first.

  • postgres and lavinmq declare guards: the store's port and the broker's management port.
  • nftables now loads the filter through its own mesh-filter.service, whose stop deletes only table inet mesh. The stock unit's stop runs nft flush ruleset, which wipes the container runtime's rules and any other firewall's rules on every filter change. The resource id load is kept, so existing nodes never stop the old unit, and nothing is flushed on the way over.
  • The stock unit keeps a drop-in. On nodes where nftables.service is still enabled, it gets a drop-in whose ExecStop deletes only the mesh's table.

The manifests are validated by mesh-controller's catalogue tests (foundation_manifests_test.go).

**Merge after mesh-controller.** Its strict manifest parser must know `guards` first. - **postgres** and **lavinmq** declare `guards`: the store's port and the broker's management port. - **nftables** now loads the filter through its own `mesh-filter.service`, whose stop deletes only `table inet mesh`. The stock unit's stop runs `nft flush ruleset`, which wipes the container runtime's rules and any other firewall's rules on every filter change. The resource id `load` is kept, so existing nodes never stop the old unit, and nothing is flushed on the way over. - **The stock unit keeps a drop-in.** On nodes where `nftables.service` is still enabled, it gets a drop-in whose `ExecStop` deletes only the mesh's table. The manifests are validated by mesh-controller's catalogue tests (`foundation_manifests_test.go`).
jschoubben added 2 commits 2026-09-22 17:28:26 +00:00
jschoubben added 1 commit 2026-09-22 18:07:18 +00:00
jschoubben merged commit 6e88982498 into main 2026-09-22 19:01:56 +00:00
jschoubben deleted branch feat/adoption-mode 2026-09-22 19:01:56 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-catalog#38