diff --git a/internal/catalogue/adoption.go b/internal/catalogue/adoption.go index c7957c0..6debcb5 100644 --- a/internal/catalogue/adoption.go +++ b/internal/catalogue/adoption.go @@ -159,6 +159,16 @@ func Published(resources []map[string]any) map[string]map[int]int { // prerouting, ahead of the runtime's destination translation, so it matches the port the packet // was sent to; in the inet family, so both address families. // +// **The machine's own interfaces are named, where the derived filter names address ranges.** The +// filter accepts the container runtime's networks by CIDR; this excludes its bridges by name — lo, +// docker0, the br-* a compose network gets, and the mesh's own mesh0. A runtime whose bridge is +// named anything else (a podman or libvirt bridge, or a docker network created with a fixed name) +// would have its containers' traffic to a guarded port refused, which reads as the port being +// down. Names rather than addresses is deliberate: a source address can be claimed by whoever +// sends the packet, and this table exists to refuse what the found firewall never sees. Widening +// it means adding names here and in the installer's copy together, which the golden test holds to +// one text. +// // The same text the installer raises on an adopted genesis; a test holds both to it. func AsGuard(ports []int) string { sorted := append([]int{}, ports...)