nftables drops its container, NET_ADMIN, the container-runtime capability, the runtime base images, the Dockerfile, and the bus credential and state directory only the container read; its tools are declared as a TypeScript bundle the toolchain compiles and node-tools loads on every node, and the iptables package the image used to carry is declared on the host. The runtime runs as the operator's account, so the tool runs the filter's commands through sudo without a prompt when it is not root (ADR 0175 §4, to-be 38 WP4), naming sudo's absence or refusal by how it failed; the filter file is the path the manifest's filtering names, held to it by a test; a found firewall that is present but will not answer stops a removal rather than passing for inactive; a legacy tool that is present but fails is said, not swallowed.
19 lines
634 B
JSON
19 lines
634 B
JSON
{
|
|
"name": "@novox/module-nftables",
|
|
"version": "0.1.0",
|
|
"description": "nftables — loads the mesh's packet filter and holds the node-packet-filter seat: its verbs rules, reload and remove (novox/hq ADR 0045, ADR 0170).",
|
|
"type": "module",
|
|
"private": true,
|
|
"scripts": {
|
|
"build": "tsc client.ts tools/index.ts --module NodeNext --moduleResolution NodeNext --target ES2022 --rootDir . --outDir dist",
|
|
"test": "node --test --experimental-strip-types 'test/*.test.ts'"
|
|
},
|
|
"dependencies": {
|
|
"@novox/mesh-sdk": "^0.1.1"
|
|
},
|
|
"devDependencies": {
|
|
"@types/node": "^22.0.0",
|
|
"typescript": "^5.6.0"
|
|
}
|
|
}
|