Files
mesh-catalog/modules/nftables/module.json
T

50 lines
1.5 KiB
JSON

{
"module": "nftables",
"version": "1",
"capabilities": [
"firewall"
],
"claims": [
{
"name": "the-packet-filter",
"scope": "node"
}
],
"filtering": {
"into": "/etc/nftables.conf"
},
"resources": [
{
"id": "package",
"type": "package",
"package": "nftables"
},
{
"id": "unit",
"type": "file",
"path": "/etc/systemd/system/mesh-filter.service",
"content": "[Unit]\nDescription=The mesh's packet filter, derived from what is assigned to this node\nWants=network-pre.target\nBefore=network-pre.target\n\n[Service]\nType=oneshot\nRemainAfterExit=yes\nExecStart=nft -f /etc/nftables.conf\nExecReload=nft -f /etc/nftables.conf\nExecStop=nft delete table inet mesh\n\n[Install]\nWantedBy=multi-user.target\n",
"mode": "0644"
},
{
"id": "stock-unit-stop",
"type": "file",
"path": "/etc/systemd/system/nftables.service.d/mesh.conf",
"content": "# The mesh: stopping the stock unit deletes only the mesh's table, never the whole ruleset\n# (novox/hq ADR 0100) — a flush would take the container runtime's rules and any firewall with it.\n[Service]\nExecStop=\nExecStop=nft delete table inet mesh\n",
"mode": "0644"
},
{
"id": "load",
"type": "service",
"unit": "mesh-filter.service",
"state": "running",
"boot": "enabled",
"restart-on": [
"filtering",
"unit",
"stock-unit-stop"
]
}
]
}