// The firewall's own code, in the module (novox/hq ADR 0039). The mesh computes this node's whole // rule set from every module's `listens` and writes it to /etc/nftables.conf (novox/hq ADR 0045); // the module loads it through its own mesh-filter unit, reloaded whenever the rules change, whose // stop deletes only the mesh's table and never flushes the whole ruleset (novox/hq ADR 0100). This // code exists only to read back what is actually enforced — the enforcement itself is declarative. import { execFile } from "node:child_process"; import { promisify } from "node:util"; const run = promisify(execFile); export class FirewallClient { static fromEnv(_env: NodeJS.ProcessEnv = process.env): FirewallClient { return new FirewallClient(); } /** The mesh's live table — exactly what is dropping and accepting on this node right now. */ async ruleset(): Promise { const { stdout } = await run("nft", ["list", "table", "inet", "mesh"]); return stdout; } }