diff options
| author | Robert Günzler <r@gnzler.io> | 2025-09-07 17:32:13 +0200 |
|---|---|---|
| committer | Robert Günzler <r@gnzler.io> | 2025-09-07 17:42:42 +0200 |
| commit | 38be6c13f76e893cf47636257071b440dec0c5b2 (patch) | |
| tree | f7ded3235a7e3362cbd1ed3d91523968fe0faf90 /bundles/firewall/items.py | |
initial commit
Signed-off-by: Robert Günzler <r@gnzler.io>
Diffstat (limited to 'bundles/firewall/items.py')
| -rw-r--r-- | bundles/firewall/items.py | 43 |
1 files changed, 43 insertions, 0 deletions
diff --git a/bundles/firewall/items.py b/bundles/firewall/items.py new file mode 100644 index 0000000..1949d13 --- /dev/null +++ b/bundles/firewall/items.py @@ -0,0 +1,43 @@ +if node.os != "alpine": + raise BundleError(f"{node.name}: OS {node.os} is not supported.") + +from os.path import join + +actions = { + "restart_container_bundle": { + "command": "s6-rc -bt 30000 stop containers && s6-rc -bt 30000 start containers", + "triggered": True, + } +} + +# TODO: fix on shimakaze, missing rules for photos./tv. +svc_openrc = { + "nftables": { + "runlevel": "boot", + "enabled": True, + "running": True, + "needs": { + "pkg_apk:nftables", + }, + "triggers": { + # NOTE: required because restart nftables drops all rules and + # podman will install rules to enable container networking + "action:restart_container_bundle", + }, + }, +} + +files = { + # overwrite content_type to allowing templating ssh port + "/etc/nftables.d/22-ssh.nft": { "content_type": "mako" } +} + +repo.libs.gen.add_files_recursive( + files, + join(repo.path, "bundles", "firewall", "files"), + { + "triggers": { + "svc_openrc:nftables:restart", + }, + } +) |