delonix net egress

Firewall de SAÍDA (regras L4 + política de egress→Internet por-rede).

OUTBOUND firewall (L4 rules + per-network egress→Internet policy).

A outra metade do firewall. Governa a SAÍDA de um container (regras allow/deny + política por omissão) e, ao nível da REDE, a política de egress para a Internet: allow/deny, ou allowlist (nega tudo excepto DNS e os CIDRs dados). Tudo sobre o mesmo ContainerFw /nft do ingress.

The other half of the firewall. Governs a container's OUTBOUND traffic (allow/deny rules + default policy) and, at the NETWORK level, egress policy to the Internet: allow/deny, or allowlist (denies everything except DNS and the given CIDRs). All on the same ContainerFw/nft as ingress.

Usage: delonix net egress [OPTIONS] <COMMAND>

Commands:
  ls      Show the outbound firewall (policy + rules)
  show    Show a NETWORK's egress policy
  allow   Allow outbound traffic from a container: `[proto/]port` to an optional CIDR
  deny    Deny outbound traffic from a container (same shape as `allow`)
  host    Allow a network's egress to a HOSTNAME (and `*.hostname`). Repeatable
  net     Govern a whole network's egress to the Internet
  policy  Set the default outbound policy when no rule matches
  clear   Remove all outbound rules
  rm      Remove outbound rule(s) matching `[proto/]port` (all protos if none given)
  help    Print this message or the help of the given subcommand(s)

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -h, --help
          Print help (see a summary with '-h')

COMMAND MAP:
  Inspect      ls · show
  Configure    allow · deny · policy · net · host
  Maintenance  rm · clear

EXAMPLES:
  # what a container is allowed to reach on its way out
  delonix net egress ls app

  # cut a whole network off the Internet in one command
  delonix net egress net app deny

  # let it out to one hostname only, learnt live from the DNS answers
  delonix net egress host app github.com

SEE ALSO:
  delonix net ingress ls · delonix net egress show · delonix network create ·
  delonix container run

  delonix › net › egress

egress clear

Remove all outbound rules

Usage: delonix net egress clear [OPTIONS] <CONTAINER>

Arguments:
  <CONTAINER>
          Container to govern. Must be on the SDN (`--net <network>`)

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # remove every outbound rule; the default policy stays as it was
  delonix net egress clear app

SEE ALSO:
  delonix net egress rm · delonix net egress policy · delonix net ingress
  clear

  delonix › net › egress › clear

ExemplosExamples

Limpar as regras de saída desse container
Clear that container's outbound rules
delonix net egress clear web

egress rm

Remove outbound rule(s) matching [proto/]port (all protos if none given)

Usage: delonix net egress rm [OPTIONS] <CONTAINER> <PORT>

Arguments:
  <CONTAINER>
          Container to govern. Must be on the SDN (`--net <network>`)

  <PORT>
          `tcp/5432`, `5432` (any proto), or `*` (all ports) — the CONTAINER's port, the same one the rule was written with

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

      --to <TO>
          Only rules to this destination CIDR (default: any recorded destination)

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # drop every outbound rule for that port, whatever the protocol
  delonix net egress rm app 5432

  # only the rule that named this destination
  delonix net egress rm app tcp/5432 --to 10.200.0.20/32

SEE ALSO:
  delonix net egress clear · delonix net egress allow · delonix net egress ls

  delonix › net › egress › rm

ExemplosExamples

Tirar UMA regra de saída
Remove ONE outbound rule
delonix net egress rm web tcp/443

egress deny

Deny outbound traffic from a container (same shape as allow)

Usage: delonix net egress deny [OPTIONS] <CONTAINER> <PORT>

Arguments:
  <CONTAINER>
          Container to govern. Must be on the SDN (`--net <network>`)

  <PORT>
          `tcp/5432`, `udp/53`, `5432` (any proto), or `tcp/*` (all ports) — the port on the DESTINATION this container is reaching for

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

      --to <TO>
          

      --note <NOTE>
          

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # block SMTP, so a compromised app cannot send mail from this node
  delonix net egress deny app tcp/25

  # block a whole destination network without closing the rest of the world
  delonix net egress deny app tcp/* --to 192.168.1.0/24

SEE ALSO:
  delonix net egress allow · delonix net egress rm · delonix net egress net

  delonix › net › egress › deny

ExemplosExamples

Bloquear a saída para uma rede
Block outbound traffic to a network
delonix net egress deny web --to 10.0.0.0/8

egress allow

Allow outbound traffic from a container: [proto/]port to an optional CIDR

Usage: delonix net egress allow [OPTIONS] <CONTAINER> <PORT>

Arguments:
  <CONTAINER>
          Container to govern. Must be on the SDN (`--net <network>`)

  <PORT>
          `tcp/5432`, `udp/53`, `5432` (any proto), or `tcp/*` (all ports) — the port on the DESTINATION this container is reaching for

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

      --to <TO>
          Only to this destination CIDR (default: anywhere)

      --note <NOTE>
          

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # let the app reach a database elsewhere on the SDN
  delonix net egress allow app tcp/5432 --to 10.200.0.20/32

  # DNS out, which a default-deny policy would otherwise take away and leave
  # nothing resolving
  delonix net egress allow app udp/53

  # HTTPS anywhere, for a workload that has to talk to the outside
  delonix net egress allow app tcp/443

SEE ALSO:
  delonix net egress deny · delonix net egress policy · delonix net egress
  host · delonix net egress ls

  delonix › net › egress › allow

ExemplosExamples

Só deixar sair HTTPS
Only let HTTPS out
delonix net egress allow app tcp/443 --to 0.0.0.0/0

egress policy

Set the default outbound policy when no rule matches

Usage: delonix net egress policy [OPTIONS] <CONTAINER> <POLICY>

Arguments:
  <CONTAINER>
          Container to govern. Must be on the SDN (`--net <network>`)

  <POLICY>
          [possible values: allow, deny]

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # deny by default: only what `egress allow` names gets out
  delonix net egress policy app deny

  # back to open — note that a policy change never tears down flows already
  # established, it only decides new ones
  delonix net egress policy app allow

SEE ALSO:
  delonix net egress allow · delonix net egress ls · delonix net ingress
  policy

  delonix › net › egress › policy

ExemplosExamples

Default-deny de saída
Default-deny outbound
delonix net egress policy app deny

egress net

Govern a whole network's egress to the Internet

Usage: delonix net egress net [OPTIONS] <NETWORK> <MODE>

Arguments:
  <NETWORK>
          Network whose egress this governs — the policy applies to every workload attached to it

  <MODE>
          Possible values:
          - allow:     Allow all egress (the default)
          - deny:      Block all egress to the Internet
          - allowlist: Deny all egress EXCEPT DNS and the CIDRs given in `--to` (allowlist)

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

      --to <TO>
          CIDRs for `allowlist` mode (comma-separated), e.g. `10.0.0.0/8,1.1.1.1/32`

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # take a whole network off the Internet, containers and all
  delonix net egress net app deny

  # allow nothing but DNS and the CIDRs you name
  delonix net egress net app allowlist --to 10.0.0.0/8,1.1.1.1/32

  # back to the default, unrestricted
  delonix net egress net app allow

SEE ALSO:
  delonix net egress show · delonix net egress host · delonix network create

  delonix › net › egress › net

ExemplosExamples

Egress de uma rede em allowlist (só DNS + estes CIDRs)
Network egress in allowlist mode (DNS + these CIDRs only)
delonix net egress net backend allowlist --to 10.0.0.0/8,1.1.1.1/32

egress host

Allow a network's egress to a HOSTNAME (and *.hostname). Repeatable.

Learnt live from DNS answers — the FQDN allowlist nft/CIDR can't express.

Usage: delonix net egress host [OPTIONS] <NETWORK> <HOSTNAME>

Arguments:
  <NETWORK>
          Network whose egress this governs — the policy applies to every workload attached to it

  <HOSTNAME>
          e.g. `github.com` (matches `github.com` and `*.github.com`)

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # let a network reach GitHub and its subdomains — the FQDN allowlist that
  # nft and CIDRs cannot express on their own
  delonix net egress host app github.com

  # repeat it per name; the addresses are learnt as the DNS answers come back,
  # so a CDN that renumbers keeps working
  delonix net egress host app registry.npmjs.org

SEE ALSO:
  delonix net egress net · delonix net egress show · delonix net egress allow

  delonix › net › egress › host

O que o nft/CIDR não faz: allowlist por hostname. O resolver DNS interno do ingress passa a snoopar os A-records das respostas e injecta-os num set nft por-rede (com timeout = expira com o TTL); o egress aceita esse set + DNS e dropa o resto. 100% rootless (sem eBPF) — a FQDN-policy do Cilium, via nftables. Repetível para vários hostnames.

What nft/CIDR can't do: allowlisting by hostname. The internal ingress DNS resolver starts snooping the A-records in responses and injects them into a per-network nft set (with a timeout = expires with the TTL); egress accepts that set plus DNS and drops the rest. 100% rootless (no eBPF) — Cilium's FQDN policy, via nftables. Repeatable for several hostnames.

ExemplosExamples

Só deixar sair para o GitHub (e *.github.com), aprendido do DNS
Only let traffic out to GitHub (and *.github.com), learned from DNS
delonix net egress host backend github.com

egress show

Show a NETWORK's egress policy.

CIDR allowlist, FQDN hosts, and the IPs currently learnt from DNS for those hosts.

Usage: delonix net egress show [OPTIONS] <NETWORK>

Arguments:
  <NETWORK>
          Network whose egress this governs — the policy applies to every workload attached to it

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # a network's egress mode, its CIDR allowlist, and the addresses learnt so
  # far for each allowed hostname
  delonix net egress show app

SEE ALSO:
  delonix net egress net · delonix net egress host · delonix network inspect

  delonix › net › egress › show

ExemplosExamples

Ver a política de egress de uma rede + os IPs FQDN aprendidos ao vivo
See a network's egress policy + the FQDN IPs learned live
delonix net egress show backend

egress ls

Show the outbound firewall (policy + rules)

Usage: delonix net egress ls [OPTIONS] [CONTAINER]

Arguments:
  [CONTAINER]
          Container to inspect (omit to list every container's outbound state)

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -o, --output <OUTPUT>
          Output format: `table` (default) or `json` (ADR-0005). `json` carries `governed` as its own field — a container off the SDN cannot HAVE a firewall, and a script must tell that from «open» without parsing a human sentence
          
          [default: table]
          [possible values: table, json]

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # one container's outbound policy and rules
  delonix net egress ls app

  # every container's, side by side
  delonix net egress ls

SEE ALSO:
  delonix net egress show · delonix net ingress ls · delonix net egress allow

  delonix › net › egress › ls

ExemplosExamples

delonix net egress ls app

LaboratórioLab

Nega tudo excepto DNS e um destino específico — a política allowlist por rede.

delonix net egress net minha-rede allowlist --to 1.1.1.1/32
delonix container run --rm --net minha-rede alpine wget -qO- https://1.1.1.1
delonix container run --rm --net minha-rede alpine wget -qO- https://example.com

Deny everything except DNS and one specific destination — the per-network allowlist policy.

delonix net egress net my-net allowlist --to 1.1.1.1/32
delonix container run --rm --net my-net alpine wget -qO- https://1.1.1.1
delonix container run --rm --net my-net alpine wget -qO- https://example.com

DesafioChallenge

Abre uma ligação de saída de longa duração e só DEPOIS aplica egress policy deny. Confirma que a ligação já estabelecida continua viva — só ligações NOVAS são bloqueadas.

Open a long-lived outbound connection and only THEN apply egress policy deny. Confirm the already-established connection keeps working — only NEW connections get blocked.