Adoption mode: guards, and a filter unit that never flushes the ruleset (hq ADR 0100, 0103) #38
@@ -53,6 +53,9 @@
|
||||
"why": "modules on any machine that were granted a queue"
|
||||
}
|
||||
],
|
||||
"guards": [
|
||||
15672
|
||||
],
|
||||
"resources": [
|
||||
{
|
||||
"id": "mesh-state",
|
||||
|
||||
@@ -1,7 +1,8 @@
|
||||
// The firewall's own code, in the module (novox/hq ADR 0039). The mesh computes this node's whole
|
||||
// rule set from every module's `listens` and writes it to /etc/nftables.conf (novox/hq ADR 0045);
|
||||
// the module loads it (the nftables service, reloaded whenever the rules change). This code exists
|
||||
// only to read back what is actually enforced — the enforcement itself is declarative.
|
||||
// the module loads it through its own mesh-filter unit, reloaded whenever the rules change, whose
|
||||
// stop deletes only the mesh's table and never flushes the whole ruleset (novox/hq ADR 0100). This
|
||||
// code exists only to read back what is actually enforced — the enforcement itself is declarative.
|
||||
|
||||
import { execFile } from "node:child_process";
|
||||
import { promisify } from "node:util";
|
||||
|
||||
@@ -19,13 +19,31 @@
|
||||
"type": "package",
|
||||
"package": "nftables"
|
||||
},
|
||||
{
|
||||
"id": "unit",
|
||||
"type": "file",
|
||||
"path": "/etc/systemd/system/mesh-filter.service",
|
||||
"content": "[Unit]\nDescription=The mesh's packet filter, derived from what is assigned to this node\nWants=network-pre.target\nBefore=network-pre.target\n\n[Service]\nType=oneshot\nRemainAfterExit=yes\nExecStart=nft -f /etc/nftables.conf\nExecReload=nft -f /etc/nftables.conf\nExecStop=nft delete table inet mesh\n\n[Install]\nWantedBy=multi-user.target\n",
|
||||
"mode": "0644"
|
||||
},
|
||||
{
|
||||
"id": "stock-unit-stop",
|
||||
"type": "file",
|
||||
"path": "/etc/systemd/system/nftables.service.d/mesh.conf",
|
||||
"content": "# The mesh: stopping the stock unit deletes only the mesh's table, never the whole ruleset\n# (novox/hq ADR 0100) — a flush would take the container runtime's rules and any firewall with it.\n[Service]\nExecStop=\nExecStop=nft delete table inet mesh\n",
|
||||
"mode": "0644"
|
||||
},
|
||||
{
|
||||
"id": "load",
|
||||
"type": "service",
|
||||
"unit": "nftables.service",
|
||||
"unit": "mesh-filter.service",
|
||||
"state": "running",
|
||||
"boot": "enabled",
|
||||
"restart-on": [
|
||||
"unit",
|
||||
"stock-unit-stop"
|
||||
],
|
||||
"reload-on": [
|
||||
"filtering"
|
||||
]
|
||||
}
|
||||
|
||||
@@ -32,6 +32,9 @@
|
||||
"why": "modules on any machine that were granted a database"
|
||||
}
|
||||
],
|
||||
"guards": [
|
||||
5432
|
||||
],
|
||||
"serves": {
|
||||
"postgres-database": {
|
||||
"port": 5432
|
||||
|
||||
Reference in New Issue
Block a user