The derived filter denies forwarding by default and then allows the container runtime's two default pools, named in this code with a comment saying a machine configured otherwise needs to say so -- and no way to say it. So the filter was right on a machine using the defaults and silently wrong on any other. Measured today: flipping a workstation to the derived filter cut egress for five of its container networks and for every network its test beds create, because those come from ranges the defaults do not cover. Nothing reported a fault; the guests just could not reach anything, while the machine reported it had applied what it was told. A node-level fact beside the public domain, because the machine routes them and the module that loads the filter may be replaced. Added to the defaults, never replacing them. Their guests also keep address and name service, without which a network does not work at all, and the converge preview now says what a machine routes instead of leaving it to a sentence about what it cannot preview.
20 lines
1.2 KiB
SQL
20 lines
1.2 KiB
SQL
-- The networks a machine routes for what it hosts, beyond the container runtime's own defaults.
|
|
--
|
|
-- novox/hq ADR 0137. The derived packet filter denies forwarding by default and then allows the
|
|
-- container runtime's two default pools, named in the controller's code with a comment saying that
|
|
-- a machine configured otherwise "needs this to say so" — and no way to say it. So the filter was
|
|
-- correct only on a machine whose runtime used the defaults, and silently wrong on any other.
|
|
--
|
|
-- Measured on 2026-09-28: flipping a workstation to the derived filter cut egress for five of its
|
|
-- container networks and for every network its test beds create, because those are allocated from
|
|
-- ranges the two defaults do not cover. Nothing reported a fault; the containers simply could not
|
|
-- reach anything.
|
|
--
|
|
-- A node-level fact, beside the node's public domain and for the same reason: it is a property of
|
|
-- the machine, not of whichever module happens to load the filter today. Swapping that module must
|
|
-- not lose it.
|
|
--
|
|
-- Null for a machine that routes nothing but the runtime's defaults, which is the ordinary case and
|
|
-- what every machine held before this column existed.
|
|
alter table node add column routed_networks jsonb;
|