Guard only packets addressed to this machine, and order the guard's unit before the network and against shutdown (hq ADR 0103)
This commit is contained in:
@@ -146,8 +146,9 @@ func Published(resources []map[string]any) map[string]map[int]int {
|
|||||||
//
|
//
|
||||||
// It passes everything by default and holds nothing but a refusal, so it cannot close anything
|
// It passes everything by default and holds nothing but a refusal, so it cannot close anything
|
||||||
// the machine serves; and it is the mesh's own table, so the found firewall reloading does not
|
// the machine serves; and it is the mesh's own table, so the found firewall reloading does not
|
||||||
// touch it. It refuses the ports except from the machine itself — its loopback and the container
|
// touch it. It refuses only packets addressed to this machine, and the ports except from the
|
||||||
// runtime's own networks — and from the private network, known by the interface a packet arrives
|
// machine itself — its loopback and the container runtime's own networks — and from the private
|
||||||
|
// network, known by the interface a packet arrives
|
||||||
// on and never by its source address. At prerouting, ahead of the runtime's destination
|
// on and never by its source address. At prerouting, ahead of the runtime's destination
|
||||||
// translation, so it matches the port the packet was sent to; in the inet family, so both address
|
// translation, so it matches the port the packet was sent to; in the inet family, so both address
|
||||||
// families.
|
// families.
|
||||||
@@ -166,8 +167,11 @@ func AsGuard(ports []int) string {
|
|||||||
b.WriteString("table inet mesh_guard {\n")
|
b.WriteString("table inet mesh_guard {\n")
|
||||||
b.WriteString("\tchain prerouting {\n")
|
b.WriteString("\tchain prerouting {\n")
|
||||||
b.WriteString("\t\ttype filter hook prerouting priority raw; policy accept;\n")
|
b.WriteString("\t\ttype filter hook prerouting priority raw; policy accept;\n")
|
||||||
fmt.Fprintf(&b, "\t\tiifname != \"lo\" iifname != \"docker0\" iifname != \"br-*\" "+
|
// Only packets addressed to this machine: traffic it routes for others — a predecessor's hub,
|
||||||
"iifname != \"mesh0\" tcp dport { %s } drop\n", strings.Join(listed, ", "))
|
// say — is never the guard's business (novox/hq ADR 0103).
|
||||||
|
fmt.Fprintf(&b, "\t\tfib daddr type local iifname != \"lo\" iifname != \"docker0\" "+
|
||||||
|
"iifname != \"br-*\" iifname != \"mesh0\" tcp dport { %s } drop\n",
|
||||||
|
strings.Join(listed, ", "))
|
||||||
b.WriteString("\t}\n")
|
b.WriteString("\t}\n")
|
||||||
b.WriteString("}\n")
|
b.WriteString("}\n")
|
||||||
return b.String()
|
return b.String()
|
||||||
@@ -178,8 +182,12 @@ func AsGuard(ports []int) string {
|
|||||||
func GuardUnitText() string {
|
func GuardUnitText() string {
|
||||||
return "[Unit]\n" +
|
return "[Unit]\n" +
|
||||||
"Description=The mesh's guard: refuses its own ports from outside (novox/hq ADR 0100)\n" +
|
"Description=The mesh's guard: refuses its own ports from outside (novox/hq ADR 0100)\n" +
|
||||||
"Before=network-pre.target\n" +
|
// Early, before the network is up, and without the default dependencies that would
|
||||||
|
// order it after the network; stopped at shutdown like any unit.
|
||||||
|
"DefaultDependencies=no\n" +
|
||||||
"Wants=network-pre.target\n" +
|
"Wants=network-pre.target\n" +
|
||||||
|
"Before=network-pre.target shutdown.target\n" +
|
||||||
|
"Conflicts=shutdown.target\n" +
|
||||||
"\n" +
|
"\n" +
|
||||||
"[Service]\n" +
|
"[Service]\n" +
|
||||||
"Type=oneshot\n" +
|
"Type=oneshot\n" +
|
||||||
|
|||||||
@@ -200,13 +200,33 @@ delete table inet mesh_guard
|
|||||||
table inet mesh_guard {
|
table inet mesh_guard {
|
||||||
chain prerouting {
|
chain prerouting {
|
||||||
type filter hook prerouting priority raw; policy accept;
|
type filter hook prerouting priority raw; policy accept;
|
||||||
iifname != "lo" iifname != "docker0" iifname != "br-*" iifname != "mesh0" tcp dport { 5432, 15672 } drop
|
fib daddr type local iifname != "lo" iifname != "docker0" iifname != "br-*" iifname != "mesh0" tcp dport { 5432, 15672 } drop
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
`
|
`
|
||||||
if got := AsGuard([]int{15672, 5432}); got != golden {
|
if got := AsGuard([]int{15672, 5432}); got != golden {
|
||||||
t.Fatalf("the guard changed:\n%s", got)
|
t.Fatalf("the guard changed:\n%s", got)
|
||||||
}
|
}
|
||||||
|
const unit = `[Unit]
|
||||||
|
Description=The mesh's guard: refuses its own ports from outside (novox/hq ADR 0100)
|
||||||
|
DefaultDependencies=no
|
||||||
|
Wants=network-pre.target
|
||||||
|
Before=network-pre.target shutdown.target
|
||||||
|
Conflicts=shutdown.target
|
||||||
|
|
||||||
|
[Service]
|
||||||
|
Type=oneshot
|
||||||
|
RemainAfterExit=yes
|
||||||
|
ExecStart=nft -f /etc/mesh/guard.nft
|
||||||
|
ExecReload=nft -f /etc/mesh/guard.nft
|
||||||
|
ExecStop=nft delete table inet mesh_guard
|
||||||
|
|
||||||
|
[Install]
|
||||||
|
WantedBy=multi-user.target
|
||||||
|
`
|
||||||
|
if got := GuardUnitText(); got != unit {
|
||||||
|
t.Fatalf("the guard's unit changed:\n%s", got)
|
||||||
|
}
|
||||||
if GuardResources(nil) != nil {
|
if GuardResources(nil) != nil {
|
||||||
t.Fatal("a guard with nothing to guard is an empty set nft refuses to load")
|
t.Fatal("a guard with nothing to guard is an empty set nft refuses to load")
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user