diff --git a/internal/catalogue/seats.go b/internal/catalogue/seats.go index 2cce385..c35f618 100644 --- a/internal/catalogue/seats.go +++ b/internal/catalogue/seats.go @@ -100,7 +100,25 @@ var defaultSeats = []Seat{ Accepts: []string{"build"}, Emits: []string{"started", "built", "log.*"}, Decision: "novox/hq ADR 0121"}, {Name: "node-dns-resolver", Scope: ScopeNode, Decision: "novox/hq ADR 0121"}, {Name: "node-intrusion-prevention", Scope: ScopeNode, Decision: "novox/hq ADR 0121"}, - {Name: "node-packet-filter", Scope: ScopeNode, Decision: "novox/hq ADR 0121"}, + // The packet filter's verbs (novox/hq ADR 0169): what a person asks a machine's filter whatever + // filter answers — the rules as enforced, reload the mesh's own, remove one thing the mesh did + // not write. Every holder serves all three; what differs by filter is the holder's own tools. + {Name: "node-packet-filter", Scope: ScopeNode, Decision: "novox/hq ADR 0121", + Serves: []Verb{ + {Name: "rules", Description: "The packet filter as this machine enforces it now: the nftables " + + "ruleset and, where the tool exists, the legacy filter's listings. Narrowed to one table or " + + "chain when asked.", + Input: schema(map[string]string{"table": "one nftables table, as `family name` (optional)", + "chain": "one chain of that table (optional)"}, nil)}, + {Name: "reload", Description: "Load the mesh's own filter again from the file the mesh writes, " + + "and answer with the mesh's table as loaded.", + Input: schema(map[string]string{}, nil)}, + {Name: "remove", Description: "Remove one rule set the mesh did not write, named exactly as the " + + "host reports it (novox/hq ADR 0168) — `chain X (iptables-legacy)` or `table ip6 filter, chain " + + "DOCKER-USER`. Refuses the mesh's tables, the runtime's own chains, a built-in chain and an " + + "active found firewall's chains. An operator's act, by name, never a flush.", + Input: schema(map[string]string{"where": "the rule set, as `node show` lists it"}, []string{"where"})}, + }}, // Deferred (novox/hq ADR 0121): renaming to mesh-private-network is a scope + server/client // model change, not a rename, so it stays until that is built. {Name: "the-private-network", Scope: ScopeNode, Decision: "novox/hq ADR 0110"},