Guard only packets addressed to this machine, and load the guard before the network and stop it only at shutdown (hq ADR 0103)
This commit is contained in:
@@ -36,7 +36,8 @@ const (
|
||||
// by default; it refuses the ports except from the machine itself — its loopback and the container
|
||||
// runtime's own networks — and from the private network, known by the interface a packet arrives
|
||||
// on and never by its source address; at prerouting, ahead of the runtime's destination
|
||||
// translation, in the inet family so both address families.
|
||||
// translation, in the inet family so both address families. It matches only packets addressed to
|
||||
// this machine: what the machine routes for others is never its business (novox/hq ADR 0103).
|
||||
//
|
||||
// Character for character the controller's (mesh-controller internal/catalogue AsGuard); a test
|
||||
// on each side holds its copy to the same golden text.
|
||||
@@ -53,7 +54,7 @@ func AsGuard(ports []int) string {
|
||||
b.WriteString("table inet mesh_guard {\n")
|
||||
b.WriteString("\tchain prerouting {\n")
|
||||
b.WriteString("\t\ttype filter hook prerouting priority raw; policy accept;\n")
|
||||
fmt.Fprintf(&b, "\t\tiifname != \"lo\" iifname != \"docker0\" iifname != \"br-*\" "+
|
||||
fmt.Fprintf(&b, "\t\tfib daddr type local iifname != \"lo\" iifname != \"docker0\" iifname != \"br-*\" "+
|
||||
"iifname != \"mesh0\" tcp dport { %s } drop\n", strings.Join(listed, ", "))
|
||||
b.WriteString("\t}\n")
|
||||
b.WriteString("}\n")
|
||||
@@ -65,8 +66,10 @@ func AsGuard(ports []int) string {
|
||||
func guardUnitText() string {
|
||||
return "[Unit]\n" +
|
||||
"Description=The mesh's guard: refuses its own ports from outside (novox/hq ADR 0100)\n" +
|
||||
"Before=network-pre.target\n" +
|
||||
"DefaultDependencies=no\n" +
|
||||
"Wants=network-pre.target\n" +
|
||||
"Before=network-pre.target shutdown.target\n" +
|
||||
"Conflicts=shutdown.target\n" +
|
||||
"\n" +
|
||||
"[Service]\n" +
|
||||
"Type=oneshot\n" +
|
||||
|
||||
Reference in New Issue
Block a user