Retire the found firewall only on a converged declaration from the mesh, never on a carried apply (hq ADR 0100)

This commit is contained in:
2026-09-22 18:01:49 +02:00
parent c989b57439
commit 9033e3da98
3 changed files with 30 additions and 4 deletions
+7 -3
View File
@@ -57,10 +57,14 @@ func foundFirewall(ctx context.Context, d *declaration.Declaration, known *store
// which is when the mesh's derived filter has taken its place. Disabled, never flushed: its
// configuration stays on disk for a return to adopted, and the container runtime's rules are not
// its to take.
func retireFirewall(ctx context.Context, d *declaration.Declaration, known *store.State, run Runner,
log func(string)) error {
//
// Only a declaration from the mesh converges a node. A carried bundle never says a node is adopted
// — it cannot — so its silence is not the controller's word that the node was converged, and an
// adopted node re-applying its bundle keeps the firewall it was found with.
func retireFirewall(ctx context.Context, d *declaration.Declaration, origin string, known *store.State,
run Runner, log func(string)) error {
rec := known.Firewall
if d.Adoption != nil || rec == nil || rec.Kind != string(firewall.UFW) || !rec.WasActive ||
if origin != store.OriginDeclared || d.Adoption != nil || rec == nil || rec.Kind != string(firewall.UFW) || !rec.WasActive ||
rec.DisabledByMesh {
return nil
}