Converge openings through the firewall an adopted node was found with, and retire it only when the node converges (hq ADR 0100)

This commit is contained in:
2026-09-22 17:19:49 +02:00
parent 3a613113be
commit 3c90d155b3
10 changed files with 1522 additions and 7 deletions
+17
View File
@@ -83,6 +83,23 @@ type State struct {
// nothing here is ever removed as an orphan — what is held is not the host's to remove, even
// when its module is unassigned.
Held []Held `json:"held,omitempty"`
// Firewall is the firewall found on this machine when it was first adopted, and whether the
// mesh has since retired it (novox/hq ADR 0100). Nil on a node that was never adopted.
Firewall *FoundFirewall `json:"firewall,omitempty"`
}
// FoundFirewall is what the host found filtering this machine, and what it did about it.
type FoundFirewall struct {
// Kind is ufw or none: an unsupported kind is refused adoption, never recorded.
Kind string `json:"kind"`
// WasActive is whether it was in force when found — which is what converging the node
// retires, and returning it to adopted restores.
WasActive bool `json:"was_active,omitempty"`
// DisabledByMesh is set when converging retired it, so returning to adopted enables it again
// and nothing else ever does.
DisabledByMesh bool `json:"disabled_by_mesh,omitempty"`
FoundAt time.Time `json:"found_at"`
}
// Held is one file or container found on an adopted node — present at a declared path or name,