Raise a machine in use adopted: keep its firewall, load no dropping table, guard the mesh's own ports, and take only the mesh's own modules (hq ADR 0100)

This commit is contained in:
2026-09-22 17:32:44 +02:00
parent 4811f176fd
commit 5e3dd3f59c
8 changed files with 467 additions and 14 deletions
+7
View File
@@ -135,6 +135,11 @@ const usage = `mesh-bootstrap — make a bare machine into a mesh
--overlay-range the private network's range (default 10.42.0.0/16); refused
if it overlaps an interface or route the machine already has
--adopted raise a machine in use as an adopted node: what it runs and its
firewall stay as they are, the foundation's filter is not loaded and
the mesh guards its own ports instead, and each module is taken on it
one at a time. Without it, a machine in use is refused
The installer carries a builder, not a control plane. What raises a mesh is therefore
the same thing that will maintain it, and the control plane a mesh ends up running is
one it built itself, from a repository and a commit it can name and build again.
@@ -312,6 +317,8 @@ func newFlagSet(opts *bootstrap.Options, jsonOut *bool) *flag.FlagSet {
} {
set.IntVar(p.into, p.name, *p.into, "the machine's port for "+p.what)
}
set.BoolVar(&opts.Adopted, "adopted", false,
"raise this machine adopted: keep what it runs and its firewall until each module is taken")
set.StringVar(&opts.OverlayRange, "overlay-range", opts.OverlayRange,
"the private network's address range; must not overlap a tunnel the machine already runs")
if opts.Answers == nil {