Merge after mesh-controller. Its strict manifest parser must know guards first.
postgres and lavinmq declare guards: the store's port and the broker's management port.
nftables now loads the filter through its own mesh-filter.service, whose stop deletes only table inet mesh. The stock unit's stop runs nft flush ruleset, which wipes the container runtime's rules and any other firewall's rules on every filter change. The resource id load is kept, so existing nodes never stop the old unit, and nothing is flushed on the way over.
The stock unit keeps a drop-in. On nodes where nftables.service is still enabled, it gets a drop-in whose ExecStop deletes only the mesh's table.
The manifests are validated by mesh-controller's catalogue tests (foundation_manifests_test.go).
**Merge after mesh-controller.** Its strict manifest parser must know `guards` first.
- **postgres** and **lavinmq** declare `guards`: the store's port and the broker's management port.
- **nftables** now loads the filter through its own `mesh-filter.service`, whose stop deletes only `table inet mesh`. The stock unit's stop runs `nft flush ruleset`, which wipes the container runtime's rules and any other firewall's rules on every filter change. The resource id `load` is kept, so existing nodes never stop the old unit, and nothing is flushed on the way over.
- **The stock unit keeps a drop-in.** On nodes where `nftables.service` is still enabled, it gets a drop-in whose `ExecStop` deletes only the mesh's table.
The manifests are validated by mesh-controller's catalogue tests (`foundation_manifests_test.go`).
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Merge after mesh-controller. Its strict manifest parser must know
guardsfirst.guards: the store's port and the broker's management port.mesh-filter.service, whose stop deletes onlytable inet mesh. The stock unit's stop runsnft flush ruleset, which wipes the container runtime's rules and any other firewall's rules on every filter change. The resource idloadis kept, so existing nodes never stop the old unit, and nothing is flushed on the way over.nftables.serviceis still enabled, it gets a drop-in whoseExecStopdeletes only the mesh's table.The manifests are validated by mesh-controller's catalogue tests (
foundation_manifests_test.go).