The missing applier. mesh-control already derives a node's whole nftables rule
set from the union of its modules' listens and writes it to /etc/nftables.conf;
this module declares filtering:{into} to receive it and loads it — the nftables
service, reloaded on 'filtering' whenever the rules change. A firewall_rules
tool reads the live table so a declared scope can be checked against what is
really enforced. Closes the loop from listens.from to a packet actually dropped.
Manifest parses; tool typechecks.
20 lines
802 B
TypeScript
20 lines
802 B
TypeScript
// firewall's tools — one, and the useful one: what is actually enforced. The rules are the mesh's,
|
|
// computed from every module's listens; this reads the live table so a declared scope can be checked
|
|
// against what the packet filter is really doing.
|
|
|
|
import { registerModuleTools, type ToolDefinition } from "@novox/mesh-sdk/tools";
|
|
import { FirewallClient } from "../client.js";
|
|
|
|
export function getFirewallTools(firewall: FirewallClient): ToolDefinition[] {
|
|
return [
|
|
{
|
|
name: "firewall_rules",
|
|
description: "The mesh's live nftables rules on this node — what is actually accepting and dropping.",
|
|
input: {},
|
|
run: async () => ({ ruleset: await firewall.ruleset() }),
|
|
},
|
|
];
|
|
}
|
|
|
|
registerModuleTools("firewall", () => getFirewallTools(FirewallClient.fromEnv()));
|