Say that the guard names the runtime's bridges where the filter names their addresses (hq ADR 0103)
This commit is contained in:
@@ -159,6 +159,16 @@ func Published(resources []map[string]any) map[string]map[int]int {
|
|||||||
// prerouting, ahead of the runtime's destination translation, so it matches the port the packet
|
// prerouting, ahead of the runtime's destination translation, so it matches the port the packet
|
||||||
// was sent to; in the inet family, so both address families.
|
// was sent to; in the inet family, so both address families.
|
||||||
//
|
//
|
||||||
|
// **The machine's own interfaces are named, where the derived filter names address ranges.** The
|
||||||
|
// filter accepts the container runtime's networks by CIDR; this excludes its bridges by name — lo,
|
||||||
|
// docker0, the br-* a compose network gets, and the mesh's own mesh0. A runtime whose bridge is
|
||||||
|
// named anything else (a podman or libvirt bridge, or a docker network created with a fixed name)
|
||||||
|
// would have its containers' traffic to a guarded port refused, which reads as the port being
|
||||||
|
// down. Names rather than addresses is deliberate: a source address can be claimed by whoever
|
||||||
|
// sends the packet, and this table exists to refuse what the found firewall never sees. Widening
|
||||||
|
// it means adding names here and in the installer's copy together, which the golden test holds to
|
||||||
|
// one text.
|
||||||
|
//
|
||||||
// The same text the installer raises on an adopted genesis; a test holds both to it.
|
// The same text the installer raises on an adopted genesis; a test holds both to it.
|
||||||
func AsGuard(ports []int) string {
|
func AsGuard(ports []int) string {
|
||||||
sorted := append([]int{}, ports...)
|
sorted := append([]int{}, ports...)
|
||||||
|
|||||||
Reference in New Issue
Block a user