Files
mesh-controller/internal/catalogue/print_rehearsal_test.go
T
jschoubben 55d468798d ssh is never left without a rule
The floor allowed ssh from the mesh's addresses, and from everywhere on a
machine that faces outward. On a machine the mesh knows no addresses for it
emitted neither — so the chain dropped by default and ssh was simply shut.

That is the first machine anybody adopts: reached over the network, with the
port needed to fix it closed by the act of adopting it. Found by reading the
rules off a live machine rather than trusting the generator.
2026-09-14 16:53:39 +02:00

17 lines
397 B
Go

package catalogue
import (
"os"
"testing"
)
func TestPrintRehearsalRuleset(t *testing.T) {
if os.Getenv("PRINT_RULESET") == "" {
t.Skip("set PRINT_RULESET")
}
rules := mustFilter(t, Resolution{Modules: []Manifest{
{Module: "pub", Listens: []Listening{{Port: 8099, From: FromMesh, Why: "the thing it serves"}}},
}}, nil)
t.Log("\n" + AsNftables(rules, []string{"192.0.2.20"}, true))
}