nftables drops its container, NET_ADMIN, the container-runtime capability, the runtime base images, the Dockerfile, and the bus credential and state directory only the container read; its tools are declared as a TypeScript bundle the toolchain compiles and node-tools loads on every node, and the iptables package the image used to carry is declared on the host. The runtime runs as the operator's account, so the tool runs the filter's commands through sudo without a prompt when it is not root (ADR 0175 §4, to-be 38 WP4), naming sudo's absence or refusal by how it failed; the filter file is the path the manifest's filtering names, held to it by a test; a found firewall that is present but will not answer stops a removal rather than passing for inactive; a legacy tool that is present but fails is said, not swallowed.
83 lines
2.0 KiB
JSON
83 lines
2.0 KiB
JSON
{
|
|
"module": "nftables",
|
|
"version": "1",
|
|
"capabilities": [
|
|
"firewall"
|
|
],
|
|
"claims": [
|
|
{
|
|
"name": "node-packet-filter",
|
|
"scope": "node",
|
|
"serves": [
|
|
"rules",
|
|
"reload",
|
|
"remove"
|
|
]
|
|
}
|
|
],
|
|
"filtering": {
|
|
"into": "/etc/nftables.conf"
|
|
},
|
|
"resources": [
|
|
{
|
|
"id": "package",
|
|
"type": "package",
|
|
"package": "nftables"
|
|
},
|
|
{
|
|
"id": "legacy-tools",
|
|
"type": "package",
|
|
"package": "iptables"
|
|
},
|
|
{
|
|
"id": "unit",
|
|
"type": "file",
|
|
"path": "/etc/systemd/system/mesh-filter.service",
|
|
"content": "[Unit]\nDescription=The mesh's packet filter, derived from what is assigned to this node\nWants=network-pre.target\nBefore=network-pre.target\n\n[Service]\nType=oneshot\nRemainAfterExit=yes\nExecStart=nft -f /etc/nftables.conf\nExecReload=nft -f /etc/nftables.conf\nExecStop=nft delete table inet mesh\n\n[Install]\nWantedBy=multi-user.target\n",
|
|
"mode": "0644"
|
|
},
|
|
{
|
|
"id": "stock-unit-stop",
|
|
"type": "file",
|
|
"path": "/etc/systemd/system/nftables.service.d/mesh.conf",
|
|
"content": "# The mesh: stopping the stock unit deletes only the mesh's table, never the whole ruleset\n# (novox/hq ADR 0100) — a flush would take the container runtime's rules and any firewall with it.\n[Service]\nExecStop=\nExecStop=nft delete table inet mesh\n",
|
|
"mode": "0644"
|
|
},
|
|
{
|
|
"id": "load",
|
|
"type": "service",
|
|
"unit": "mesh-filter.service",
|
|
"state": "running",
|
|
"boot": "enabled",
|
|
"restart-on": [
|
|
"unit",
|
|
"stock-unit-stop"
|
|
],
|
|
"reload-on": [
|
|
"filtering"
|
|
]
|
|
},
|
|
{
|
|
"id": "front-end",
|
|
"type": "package",
|
|
"package": "ufw",
|
|
"absent": true
|
|
}
|
|
],
|
|
"tools": [
|
|
"firewall_rules"
|
|
],
|
|
"build": {
|
|
"artifacts": [
|
|
{
|
|
"name": "tools",
|
|
"kind": "bundle",
|
|
"language": "typescript",
|
|
"entrypoints": [
|
|
"tools/index.js"
|
|
]
|
|
}
|
|
]
|
|
}
|
|
}
|