-- The networks a machine routes for what it hosts, beyond the container runtime's own defaults. -- -- novox/hq ADR 0137. The derived packet filter denies forwarding by default and then allows the -- container runtime's two default pools, named in the controller's code with a comment saying that -- a machine configured otherwise "needs this to say so" — and no way to say it. So the filter was -- correct only on a machine whose runtime used the defaults, and silently wrong on any other. -- -- Measured on 2026-09-28: flipping a workstation to the derived filter cut egress for five of its -- container networks and for every network its test beds create, because those are allocated from -- ranges the two defaults do not cover. Nothing reported a fault; the containers simply could not -- reach anything. -- -- A node-level fact, beside the node's public domain and for the same reason: it is a property of -- the machine, not of whichever module happens to load the filter today. Swapping that module must -- not lose it. -- -- Null for a machine that routes nothing but the runtime's defaults, which is the ordinary case and -- what every machine held before this column existed. alter table node add column routed_networks jsonb;