{ "module": "nftables", "version": "1", "capabilities": [ "firewall", "container-runtime" ], "claims": [ { "name": "node-packet-filter", "scope": "node", "serves": [ "rules", "reload", "remove" ] } ], "filtering": { "into": "/etc/nftables.conf" }, "resources": [ { "id": "mesh-state", "type": "directory", "mode": "0700", "place": "mesh" }, { "id": "package", "type": "package", "package": "nftables" }, { "id": "unit", "type": "file", "path": "/etc/systemd/system/mesh-filter.service", "content": "[Unit]\nDescription=The mesh's packet filter, derived from what is assigned to this node\nWants=network-pre.target\nBefore=network-pre.target\n\n[Service]\nType=oneshot\nRemainAfterExit=yes\nExecStart=nft -f /etc/nftables.conf\nExecReload=nft -f /etc/nftables.conf\nExecStop=nft delete table inet mesh\n\n[Install]\nWantedBy=multi-user.target\n", "mode": "0644" }, { "id": "stock-unit-stop", "type": "file", "path": "/etc/systemd/system/nftables.service.d/mesh.conf", "content": "# The mesh: stopping the stock unit deletes only the mesh's table, never the whole ruleset\n# (novox/hq ADR 0100) \u2014 a flush would take the container runtime's rules and any firewall with it.\n[Service]\nExecStop=\nExecStop=nft delete table inet mesh\n", "mode": "0644" }, { "id": "load", "type": "service", "unit": "mesh-filter.service", "state": "running", "boot": "enabled", "restart-on": [ "unit", "stock-unit-stop" ], "reload-on": [ "filtering" ] }, { "id": "runtime", "type": "container", "name": "mesh-nftables", "network": "host", "capabilities": [ "NET_ADMIN" ], "volumes": [ "${dir:mesh-state}/broker:/run/secrets/broker:ro", "/etc/nftables.conf:/etc/nftables.conf:ro" ], "env": { "MESH_BROKER_FILE": "/run/secrets/broker", "MESH_FILTER_FILE": "/etc/nftables.conf" }, "artifact": "runtime" } ], "tools": [ "firewall_rules" ], "own-secrets": { "broker": "${dir:mesh-state}/broker" }, "build": { "on": [ { "arg": "BUILD_BASE", "module": "mesh-tools", "artifact": "build" }, { "arg": "RUNTIME_BASE", "module": "mesh-tools", "artifact": "runtime" } ], "artifacts": [ { "name": "runtime", "kind": "image", "from": "Dockerfile" } ] } }