// The firewall's own code, in the module (novox/hq ADR 0039). The mesh computes this node's whole // rule set from every module's `listens` and writes it to /etc/nftables.conf (novox/hq ADR 0045); // the module loads it (the nftables service, reloaded whenever the rules change). This code exists // only to read back what is actually enforced — the enforcement itself is declarative. import { execFile } from "node:child_process"; import { promisify } from "node:util"; const run = promisify(execFile); export class FirewallClient { static fromEnv(_env: NodeJS.ProcessEnv = process.env): FirewallClient { return new FirewallClient(); } /** The mesh's live table — exactly what is dropping and accepting on this node right now. */ async ruleset(): Promise { const { stdout } = await run("nft", ["list", "table", "inet", "mesh"]); return stdout; } }