nftables drops its container, NET_ADMIN, the container-runtime capability, the runtime base images and the Dockerfile; its tools are declared as a TypeScript bundle the toolchain compiles and node-tools loads on every node. The runtime runs as the operator's account, so the tool runs the filter's commands through sudo without a prompt when it is not root (ADR 0175 §4); the filter file is the path the manifest's filtering names, no container env carrying it.
19 lines
634 B
JSON
19 lines
634 B
JSON
{
|
|
"name": "@novox/module-nftables",
|
|
"version": "0.1.0",
|
|
"description": "nftables — loads the mesh's packet filter and holds the node-packet-filter seat: its verbs rules, reload and remove (novox/hq ADR 0045, ADR 0170).",
|
|
"type": "module",
|
|
"private": true,
|
|
"scripts": {
|
|
"build": "tsc client.ts tools/index.ts --module NodeNext --moduleResolution NodeNext --target ES2022 --rootDir . --outDir dist",
|
|
"test": "node --test --experimental-strip-types 'test/*.test.ts'"
|
|
},
|
|
"dependencies": {
|
|
"@novox/mesh-sdk": "^0.1.1"
|
|
},
|
|
"devDependencies": {
|
|
"@types/node": "^22.0.0",
|
|
"typescript": "^5.6.0"
|
|
}
|
|
}
|