The mesh says what filters a converged machine: filters kept per node, shown, named by status, previewed with fates (hq ADR 0168) #211

Merged
mesh-admin merged 1 commits from feat/one-thing-filters-a-converged-machine into main 2026-10-02 10:03:01 +00:00
Contributor

Group 7's controller half (hq ADR 0168; issues 143, 144). Pairs with mesh-host 67, merged first: a host reports filters (every refusing table and legacy chain with an owner) and, converged, found_firewall (active, retired by mesh or found-inactive).

  • Kept. Migration 0054 adds node.filters and node.found_firewall; Heard records them from every report that carries them and never clears them on a bare one; inventory.FilteringOf reads them, with Alone() and Others().
  • Shown. node show lists what filters a machine — the mesh alone (mesh 2, runtime 3, ban 1) or NOT the mesh alone, each foreign rule set with where, owner and what it refuses — and, converged, the found firewall's state and who retired it.
  • Named. status names every converged machine that something other than the mesh's own, the runtime's plumbing and bans filters, in text and as filtered in the JSON, and such a machine is not well.
  • Previewed. The converge preview lists what filters the machine now and the fate of each: retired with the front end, left as the runtime's, left as a ban, or left in force and not the mesh's.

make check green after one fixture fix (19 packages). Merge after host 67 has rolled; the plan rolls the controller; migration 0054 runs at its start.

Group 7's controller half (hq ADR 0168; issues 143, 144). Pairs with mesh-host 67, merged first: a host reports `filters` (every refusing table and legacy chain with an owner) and, converged, `found_firewall` (active, retired by `mesh` or `found-inactive`). - **Kept.** Migration 0054 adds `node.filters` and `node.found_firewall`; `Heard` records them from every report that carries them and never clears them on a bare one; `inventory.FilteringOf` reads them, with `Alone()` and `Others()`. - **Shown.** `node show` lists what filters a machine — *the mesh alone (mesh 2, runtime 3, ban 1)* or *NOT the mesh alone*, each foreign rule set with where, owner and what it refuses — and, converged, the found firewall's state and who retired it. - **Named.** `status` names every converged machine that something other than the mesh's own, the runtime's plumbing and bans filters, in text and as `filtered` in the JSON, and such a machine is not well. - **Previewed.** The converge preview lists what filters the machine now and the fate of each: retired with the front end, left as the runtime's, left as a ban, or *left in force and not the mesh's*. `make check` green after one fixture fix (19 packages). Merge after host 67 has rolled; the plan rolls the controller; migration 0054 runs at its start.
mesh-admin added 1 commit 2026-10-02 10:00:33 +00:00
A host reports every table and chain that refuses traffic with its owner,
and a converged machine's found firewall's state. The controller keeps both
on the node's record (migration 0054), shows them on node show, names every
converged machine something other than the mesh filters in status — text
and JSON, and such a machine is not well — and the converge preview lists
what filters the machine with the fate of each: retired with the front end,
left as the runtime's, left as a ban, or left in force and not the mesh's.
What was invisible for eleven hours (issues 144, 145) is said by name.
mesh-admin merged commit 1587fd97f9 into main 2026-10-02 10:03:01 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-controller#211