jschoubben
|
0f3eedd163
|
Do not guard a port this node is told to open to everyone (hq ADR 0103)
|
2026-09-22 19:44:35 +02:00 |
|
jschoubben
|
dd6aad4a2f
|
Give a machine port only to a port a module's container publishes, which is the only one the mesh can move (hq ADR 0038)
|
2026-09-22 19:44:35 +02:00 |
|
jschoubben
|
cc47330884
|
Reload the guard on its table rather than restart it, so a change leaves no port unguarded (hq ADR 0103)
|
2026-09-22 18:27:27 +02:00 |
|
jschoubben
|
4bb19c9e40
|
Give a machine port one holder: refuse ssh's, another module's and a doubled one, and release the assignment a given port replaces (hq ADR 0100)
|
2026-09-22 18:05:31 +02:00 |
|
jschoubben
|
ade6b2bfb6
|
Declare nftables before the guard's table, so a node joining adopted without nft can load it (hq ADR 0103)
|
2026-09-22 17:59:32 +02:00 |
|
jschoubben
|
a2dfaaf4d1
|
Guard only packets addressed to this machine, and order the guard's unit before the network and against shutdown (hq ADR 0103)
|
2026-09-22 17:59:09 +02:00 |
|
jschoubben
|
a82bfb41f2
|
Leave an IPv6 loopback mapping out of what a container publishes, reading ports from the end (hq ADR 0100)
|
2026-09-22 17:58:50 +02:00 |
|
jschoubben
|
8db66e9532
|
Derive the guard from taken modules only: their published private-network ports and their manifests' guards (hq ADR 0103)
|
2026-09-22 17:58:37 +02:00 |
|
jschoubben
|
dbf62b5212
|
Read the foundation's ports from each node's settings, wherever a port is used (hq ADR 0100)
|
2026-09-22 17:31:07 +02:00 |
|
jschoubben
|
c3b1617693
|
Declare openings and a refusal-only guard on an adopted node in place of the filter (hq ADR 0100)
|
2026-09-22 17:21:44 +02:00 |
|