about summary refs log tree commit diff
path: root/bundles/firewall/items.py
diff options
context:
space:
mode:
authorRobert Günzler <r@gnzler.io>2025-09-07 17:32:13 +0200
committerRobert Günzler <r@gnzler.io>2025-09-07 17:42:42 +0200
commit38be6c13f76e893cf47636257071b440dec0c5b2 (patch)
treef7ded3235a7e3362cbd1ed3d91523968fe0faf90 /bundles/firewall/items.py
initial commit
Signed-off-by: Robert Günzler <r@gnzler.io>
Diffstat (limited to 'bundles/firewall/items.py')
-rw-r--r--bundles/firewall/items.py43
1 files changed, 43 insertions, 0 deletions
diff --git a/bundles/firewall/items.py b/bundles/firewall/items.py
new file mode 100644
index 0000000..1949d13
--- /dev/null
+++ b/bundles/firewall/items.py
@@ -0,0 +1,43 @@
+if node.os != "alpine":
+    raise BundleError(f"{node.name}: OS {node.os} is not supported.")
+
+from os.path import join
+
+actions = {
+    "restart_container_bundle": {
+        "command": "s6-rc -bt 30000 stop containers && s6-rc -bt 30000 start containers",
+        "triggered": True,
+    }
+}
+
+# TODO: fix on shimakaze, missing rules for photos./tv.
+svc_openrc = {
+    "nftables": {
+        "runlevel": "boot",
+        "enabled": True,
+        "running": True,
+        "needs": {
+            "pkg_apk:nftables",
+        },
+        "triggers": {
+            # NOTE: required because restart nftables drops all rules and
+            # podman will install rules to enable container networking
+            "action:restart_container_bundle",
+        },
+    },
+}
+
+files = {
+    # overwrite content_type to allowing templating ssh port
+    "/etc/nftables.d/22-ssh.nft": { "content_type": "mako" }
+}
+
+repo.libs.gen.add_files_recursive(
+    files,
+    join(repo.path, "bundles", "firewall", "files"),
+    {
+        "triggers": {
+            "svc_openrc:nftables:restart",
+        },
+    }
+)