Files
mesh-catalog/modules/firewall/module.json
T
jschoubben 0e102dd350 firewall: the module that applies the mesh-computed packet filter (ADR 0050)
The missing applier. mesh-control already derives a node's whole nftables rule
set from the union of its modules' listens and writes it to /etc/nftables.conf;
this module declares filtering:{into} to receive it and loads it — the nftables
service, reloaded on 'filtering' whenever the rules change. A firewall_rules
tool reads the live table so a declared scope can be checked against what is
really enforced. Closes the loop from listens.from to a packet actually dropped.
Manifest parses; tool typechecks.
2026-09-04 20:52:26 +02:00

34 lines
531 B
JSON

{
"module": "firewall",
"version": "1",
"capabilities": [
"firewall"
],
"claims": [
{
"name": "the-packet-filter",
"scope": "node"
}
],
"filtering": {
"into": "/etc/nftables.conf"
},
"resources": [
{
"id": "package",
"type": "package",
"package": "nftables"
},
{
"id": "load",
"type": "service",
"unit": "nftables.service",
"state": "running",
"boot": "enabled",
"restart-on": [
"filtering"
]
}
]
}