{ "module": "nftables", "version": "1", "capabilities": [ "firewall" ], "claims": [ { "name": "the-packet-filter", "scope": "node" } ], "filtering": { "into": "/etc/nftables.conf" }, "resources": [ { "id": "package", "type": "package", "package": "nftables" }, { "id": "unit", "type": "file", "path": "/etc/systemd/system/mesh-filter.service", "content": "[Unit]\nDescription=The mesh's packet filter, derived from what is assigned to this node\nWants=network-pre.target\nBefore=network-pre.target\n\n[Service]\nType=oneshot\nRemainAfterExit=yes\nExecStart=nft -f /etc/nftables.conf\nExecReload=nft -f /etc/nftables.conf\nExecStop=nft delete table inet mesh\n\n[Install]\nWantedBy=multi-user.target\n", "mode": "0644" }, { "id": "stock-unit-stop", "type": "file", "path": "/etc/systemd/system/nftables.service.d/mesh.conf", "content": "# The mesh: stopping the stock unit deletes only the mesh's table, never the whole ruleset\n# (novox/hq ADR 0100) — a flush would take the container runtime's rules and any firewall with it.\n[Service]\nExecStop=\nExecStop=nft delete table inet mesh\n", "mode": "0644" }, { "id": "load", "type": "service", "unit": "mesh-filter.service", "state": "running", "boot": "enabled", "restart-on": [ "unit", "stock-unit-stop" ], "reload-on": [ "filtering" ] } ] }