delonix net egress
Firewall de SAÍDA (regras L4 + política de egress→Internet por-rede).
OUTBOUND firewall (L4 rules + per-network egress→Internet policy).
A outra metade do firewall. Governa a SAÍDA de um container (regras allow/deny + política
por omissão) e, ao nível da REDE, a política de egress para a Internet: allow/deny,
ou allowlist (nega tudo excepto DNS e os CIDRs dados). Tudo sobre o mesmo ContainerFw
/nft do ingress.
The other half of the firewall. Governs a container's OUTBOUND traffic
(allow/deny rules + default policy) and, at the NETWORK level, egress policy to the Internet:
allow/deny, or allowlist (denies everything except DNS and
the given CIDRs). All on the same ContainerFw/nft as ingress.
📄 Implementação real em Rust: cmd/firewall.rs
Usage: delonix net egress [OPTIONS] <COMMAND>
Commands:
ls Show the outbound firewall (policy + rules)
show Show a NETWORK's egress policy
allow Allow outbound traffic from a container: `[proto/]port` to an optional CIDR
deny Deny outbound traffic from a container (same shape as `allow`)
host Allow a network's egress to a HOSTNAME (and `*.hostname`). Repeatable
net Govern a whole network's egress to the Internet
policy Set the default outbound policy when no rule matches
clear Remove all outbound rules
rm Remove outbound rule(s) matching `[proto/]port` (all protos if none given)
help Print this message or the help of the given subcommand(s)
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
COMMAND MAP:
Inspect ls · show
Configure allow · deny · policy · net · host
Maintenance rm · clear
EXAMPLES:
# what a container is allowed to reach on its way out
delonix net egress ls app
# cut a whole network off the Internet in one command
delonix net egress net app deny
# let it out to one hostname only, learnt live from the DNS answers
delonix net egress host app github.com
SEE ALSO:
delonix net ingress ls · delonix net egress show · delonix network create ·
delonix container run
delonix › net › egressegress clear
Remove all outbound rules
Usage: delonix net egress clear [OPTIONS] <CONTAINER>
Arguments:
<CONTAINER>
Container to govern. Must be on the SDN (`--net <network>`)
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# remove every outbound rule; the default policy stays as it was
delonix net egress clear app
SEE ALSO:
delonix net egress rm · delonix net egress policy · delonix net ingress
clear
delonix › net › egress › clearExemplosExamples
delonix net egress clear webegress rm
Remove outbound rule(s) matching [proto/]port (all protos if none given)
Usage: delonix net egress rm [OPTIONS] <CONTAINER> <PORT>
Arguments:
<CONTAINER>
Container to govern. Must be on the SDN (`--net <network>`)
<PORT>
`tcp/5432`, `5432` (any proto), or `*` (all ports) — the CONTAINER's port, the same one the rule was written with
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
--to <TO>
Only rules to this destination CIDR (default: any recorded destination)
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# drop every outbound rule for that port, whatever the protocol
delonix net egress rm app 5432
# only the rule that named this destination
delonix net egress rm app tcp/5432 --to 10.200.0.20/32
SEE ALSO:
delonix net egress clear · delonix net egress allow · delonix net egress ls
delonix › net › egress › rmExemplosExamples
delonix net egress rm web tcp/443egress deny
Deny outbound traffic from a container (same shape as allow)
Usage: delonix net egress deny [OPTIONS] <CONTAINER> <PORT>
Arguments:
<CONTAINER>
Container to govern. Must be on the SDN (`--net <network>`)
<PORT>
`tcp/5432`, `udp/53`, `5432` (any proto), or `tcp/*` (all ports) — the port on the DESTINATION this container is reaching for
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
--to <TO>
--note <NOTE>
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# block SMTP, so a compromised app cannot send mail from this node
delonix net egress deny app tcp/25
# block a whole destination network without closing the rest of the world
delonix net egress deny app tcp/* --to 192.168.1.0/24
SEE ALSO:
delonix net egress allow · delonix net egress rm · delonix net egress net
delonix › net › egress › denyExemplosExamples
delonix net egress deny web --to 10.0.0.0/8egress allow
Allow outbound traffic from a container: [proto/]port to an optional CIDR
Usage: delonix net egress allow [OPTIONS] <CONTAINER> <PORT>
Arguments:
<CONTAINER>
Container to govern. Must be on the SDN (`--net <network>`)
<PORT>
`tcp/5432`, `udp/53`, `5432` (any proto), or `tcp/*` (all ports) — the port on the DESTINATION this container is reaching for
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
--to <TO>
Only to this destination CIDR (default: anywhere)
--note <NOTE>
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# let the app reach a database elsewhere on the SDN
delonix net egress allow app tcp/5432 --to 10.200.0.20/32
# DNS out, which a default-deny policy would otherwise take away and leave
# nothing resolving
delonix net egress allow app udp/53
# HTTPS anywhere, for a workload that has to talk to the outside
delonix net egress allow app tcp/443
SEE ALSO:
delonix net egress deny · delonix net egress policy · delonix net egress
host · delonix net egress ls
delonix › net › egress › allowExemplosExamples
delonix net egress allow app tcp/443 --to 0.0.0.0/0egress policy
Set the default outbound policy when no rule matches
Usage: delonix net egress policy [OPTIONS] <CONTAINER> <POLICY>
Arguments:
<CONTAINER>
Container to govern. Must be on the SDN (`--net <network>`)
<POLICY>
[possible values: allow, deny]
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# deny by default: only what `egress allow` names gets out
delonix net egress policy app deny
# back to open — note that a policy change never tears down flows already
# established, it only decides new ones
delonix net egress policy app allow
SEE ALSO:
delonix net egress allow · delonix net egress ls · delonix net ingress
policy
delonix › net › egress › policyExemplosExamples
delonix net egress policy app denyegress net
Govern a whole network's egress to the Internet
Usage: delonix net egress net [OPTIONS] <NETWORK> <MODE>
Arguments:
<NETWORK>
Network whose egress this governs — the policy applies to every workload attached to it
<MODE>
Possible values:
- allow: Allow all egress (the default)
- deny: Block all egress to the Internet
- allowlist: Deny all egress EXCEPT DNS and the CIDRs given in `--to` (allowlist)
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
--to <TO>
CIDRs for `allowlist` mode (comma-separated), e.g. `10.0.0.0/8,1.1.1.1/32`
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# take a whole network off the Internet, containers and all
delonix net egress net app deny
# allow nothing but DNS and the CIDRs you name
delonix net egress net app allowlist --to 10.0.0.0/8,1.1.1.1/32
# back to the default, unrestricted
delonix net egress net app allow
SEE ALSO:
delonix net egress show · delonix net egress host · delonix network create
delonix › net › egress › netExemplosExamples
delonix net egress net backend allowlist --to 10.0.0.0/8,1.1.1.1/32egress host
Allow a network's egress to a HOSTNAME (and *.hostname). Repeatable.
Learnt live from DNS answers — the FQDN allowlist nft/CIDR can't express.
Usage: delonix net egress host [OPTIONS] <NETWORK> <HOSTNAME>
Arguments:
<NETWORK>
Network whose egress this governs — the policy applies to every workload attached to it
<HOSTNAME>
e.g. `github.com` (matches `github.com` and `*.github.com`)
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# let a network reach GitHub and its subdomains — the FQDN allowlist that
# nft and CIDRs cannot express on their own
delonix net egress host app github.com
# repeat it per name; the addresses are learnt as the DNS answers come back,
# so a CDN that renumbers keeps working
delonix net egress host app registry.npmjs.org
SEE ALSO:
delonix net egress net · delonix net egress show · delonix net egress allow
delonix › net › egress › hostO que o nft/CIDR não faz: allowlist por hostname. O resolver DNS
interno do ingress passa a snoopar os A-records das respostas e injecta-os num set nft
por-rede (com timeout = expira com o TTL); o egress aceita esse set + DNS e dropa o resto. 100%
rootless (sem eBPF) — a FQDN-policy do Cilium, via nftables. Repetível para vários hostnames.
What nft/CIDR can't do: allowlisting by hostname.
The internal ingress DNS resolver starts snooping the A-records in responses and injects them into
a per-network nft set (with a timeout = expires with the TTL); egress accepts that
set plus DNS and drops the rest. 100% rootless (no eBPF) — Cilium's FQDN policy, via nftables.
Repeatable for several hostnames.
ExemplosExamples
delonix net egress host backend github.comegress show
Show a NETWORK's egress policy.
CIDR allowlist, FQDN hosts, and the IPs currently learnt from DNS for those hosts.
Usage: delonix net egress show [OPTIONS] <NETWORK>
Arguments:
<NETWORK>
Network whose egress this governs — the policy applies to every workload attached to it
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# a network's egress mode, its CIDR allowlist, and the addresses learnt so
# far for each allowed hostname
delonix net egress show app
SEE ALSO:
delonix net egress net · delonix net egress host · delonix network inspect
delonix › net › egress › showExemplosExamples
delonix net egress show backendegress ls
Show the outbound firewall (policy + rules)
Usage: delonix net egress ls [OPTIONS] [CONTAINER]
Arguments:
[CONTAINER]
Container to inspect (omit to list every container's outbound state)
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-o, --output <OUTPUT>
Output format: `table` (default) or `json` (ADR-0005). `json` carries `governed` as its own field — a container off the SDN cannot HAVE a firewall, and a script must tell that from «open» without parsing a human sentence
[default: table]
[possible values: table, json]
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# one container's outbound policy and rules
delonix net egress ls app
# every container's, side by side
delonix net egress ls
SEE ALSO:
delonix net egress show · delonix net ingress ls · delonix net egress allow
delonix › net › egress › lsExemplosExamples
delonix net egress ls appLaboratórioLab
Nega tudo excepto DNS e um destino específico — a política
allowlist por rede.
delonix net egress net minha-rede allowlist --to 1.1.1.1/32
delonix container run --rm --net minha-rede alpine wget -qO- https://1.1.1.1
delonix container run --rm --net minha-rede alpine wget -qO- https://example.comDeny everything except DNS and one specific destination — the
per-network allowlist policy.
delonix net egress net my-net allowlist --to 1.1.1.1/32
delonix container run --rm --net my-net alpine wget -qO- https://1.1.1.1
delonix container run --rm --net my-net alpine wget -qO- https://example.comDesafioChallenge
Abre uma ligação de saída de longa duração e só DEPOIS aplica
egress policy deny. Confirma que a ligação já estabelecida continua viva — só ligações
NOVAS são bloqueadas.
Open a long-lived outbound connection and only THEN apply
egress policy deny. Confirm the already-established connection keeps working — only
NEW connections get blocked.