The firewall governs what is forwarded, and never closes ssh
Two faults, opposite directions, both in issue 047. There was no forward chain, on the reasoning that dropping there stops every container the runtime allowed. The first half is true; the conclusion was not. A published port is redirected and then forwarded, so it never reaches the input chain — the firewall was silent about the ports most worth protecting. The way through is the one the system being replaced already used: deny by default, then allow the runtime's own networks explicitly. A forwarded rule matches what the client originally asked for, because the destination has been rewritten by the time the chain sees it. And ssh is now a floor nothing derives. Every other line comes from what is assigned, which is the point — but a mesh part-way through adopting a machine has been assigned almost nothing, so what it computed was a chain that shut the port used to fix it. From the mesh always; from outside on a machine that faces outward, because that is the way in when the private network is what broke. Rehearsed on three machines: a docker-published port declared mesh-only is now reachable from inside the mesh and refused from outside. Before, it was reachable from both.
This commit is contained in:
@@ -207,7 +207,7 @@ func (r Resolution) Declaration(with Rendering) ([]map[string]any, error) {
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
filtering := AsNftables(rules, with.Mesh)
|
||||
filtering := AsNftables(rules, with.Mesh, r.PublicDomain != "")
|
||||
|
||||
var out []map[string]any
|
||||
for _, m := range r.Modules {
|
||||
|
||||
Reference in New Issue
Block a user