delonix net ingress

Firewall de ENTRADA (regras L4 + publishes DNAT) de um container na SDN.

INBOUND firewall (L4 rules + DNAT publishes) for a container on the SDN.

Metade da superfície unificada de firewall (a outra é egress). Edita a única fonte de verdade — o ContainerFw por container, aplicado como regras nft na chain de ingress. ingress governa a ENTRADA: regras allow/deny por [proto/]porta e CIDR, a política por omissão, e os publishes DNAT. Só actua em containers numa rede custom (têm IP na delonix0); --net host é recusado.

Half of the unified firewall surface (the other is egress). Edits the single source of truth — the per-container ContainerFw, applied as nft rules in the ingress chain. ingress governs INBOUND traffic: allow/deny rules by [proto/]port and CIDR, the default policy, and DNAT publishes. Only acts on containers on a custom network (they have an IP on delonix0); --net host is refused.

Usage: delonix net ingress [OPTIONS] <COMMAND>

Commands:
  ls         Show the inbound firewall (policy + rules) and published ports
  allow      Allow inbound traffic to a container: `[proto/]port` from an optional CIDR
  deny       Deny inbound traffic to a container (same shape as `allow`)
  policy     Set the default inbound policy when no rule matches
  publish    Publish a host port to the container (DNAT through the ingress)
  unpublish  Remove a published host port
  clear      Remove all inbound rules (keeps published ports)
  rm         Remove inbound rule(s) matching `[proto/]port` (all protos if none given)
  help       Print this message or the help of the given subcommand(s)

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -h, --help
          Print help (see a summary with '-h')

COMMAND MAP:
  Inspect      ls
  Configure    allow · deny · policy
  Networking   publish · unpublish
  Maintenance  rm · clear

EXAMPLES:
  # what is open on a container, and from where
  delonix net ingress ls web

  # shut the door by default, so only the rules you write let anything in
  delonix net ingress policy db deny

  # then open Postgres to the SDN alone — nothing from the host's LAN
  delonix net ingress allow db tcp/5432 --from 10.200.0.0/16

SEE ALSO:
  delonix net egress ls · delonix net ingress publish · delonix container run
  · delonix net httproute apply

  delonix › net › ingress

ingress clear

Remove all inbound rules (keeps published ports)

Usage: delonix net ingress clear [OPTIONS] <CONTAINER>

Arguments:
  <CONTAINER>
          Container to govern. Must be on the SDN (`--net <network>`)

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # wipe the inbound rules and keep the published ports — the DNAT is a
  # different plane from the filter
  delonix net ingress clear web

SEE ALSO:
  delonix net ingress rm · delonix net ingress unpublish · delonix net egress
  clear

  delonix › net › ingress › clear

ExemplosExamples

Limpar a firewall inteira desse container
Clear that container's whole firewall
delonix net ingress clear web

ingress rm

Remove inbound rule(s) matching [proto/]port (all protos if none given)

Usage: delonix net ingress rm [OPTIONS] <CONTAINER> <PORT>

Arguments:
  <CONTAINER>
          Container to govern. Must be on the SDN (`--net <network>`)

  <PORT>
          `tcp/5432`, `5432` (any proto), or `*` (all ports) — the CONTAINER's port, the same one the rule was written with

Options:
      --from <FROM>
          Only rules from this source CIDR (default: any recorded source)

      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # drop every rule written for that port, whatever the protocol
  delonix net ingress rm web 8080

  # only the rule that named this source
  delonix net ingress rm db tcp/5432 --from 10.200.0.15/32

SEE ALSO:
  delonix net ingress clear · delonix net ingress allow · delonix net ingress
  ls

  delonix › net › ingress › rm

ExemplosExamples

Tirar UMA regra, sem limpar as outras
Remove ONE rule, without clearing the others
delonix net ingress rm web tcp/80

ingress unpublish

Remove a published host port

Usage: delonix net ingress unpublish [OPTIONS] <CONTAINER> <HOST_PORT>

Arguments:
  <CONTAINER>
          Container to govern. Must be on the SDN (`--net <network>`)

  <HOST_PORT>
          The HOST port to stop publishing — this one IS the host's, because a publish is `hostPort:containerPort` and the host side is its identity

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # give the host port back — the hostfwd and the DNAT go together, and the
  # port stops being owned
  delonix net ingress unpublish web 8080

SEE ALSO:
  delonix net ingress publish · delonix net ingress ls

  delonix › net › ingress › unpublish

ExemplosExamples

Deixar de publicar uma porta
Stop publishing a port
delonix net ingress unpublish 8080

ingress allow

Allow inbound traffic to a container: [proto/]port from an optional CIDR

Usage: delonix net ingress allow [OPTIONS] <CONTAINER> <PORT>

Arguments:
  <CONTAINER>
          Container the rule belongs to. Must be on the SDN (`--net <network>`) — a `--net host`/`none` container has no firewall to govern

  <PORT>
          `tcp/5432`, `udp/53`, `5432` (any proto), or `tcp/*` (all ports) — the CONTAINER's port and never the host's, because the DNAT already rewrote it in `prerouting`

Options:
      --from <FROM>
          Only from this source CIDR (default: anywhere)

      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

      --note <NOTE>
          Free-form note kept with the rule

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # open the port the CONTAINER listens on — the DNAT has already rewritten
  # the host port away by the time the rule is evaluated
  delonix net ingress allow web tcp/80

  # Postgres, but only from the SDN
  delonix net ingress allow db tcp/5432 --from 10.200.0.0/16

  # leave a reason behind, so `ingress ls` explains itself to the next person
  delonix net ingress allow api tcp/8080 --note "public API"

  # every port from a single peer, when the rule is about the source and not
  # the service
  delonix net ingress allow db tcp/* --from 10.200.0.15/32

SEE ALSO:
  delonix net ingress deny · delonix net ingress policy · delonix net ingress
  ls · delonix net ingress rm

  delonix › net › ingress › allow

ExemplosExamples

Deixar entrar Postgres só da própria SDN
Only let Postgres in from the SDN itself
delonix net ingress allow db tcp/5432 --from 10.219.0.0/16

ingress deny

Deny inbound traffic to a container (same shape as allow)

Usage: delonix net ingress deny [OPTIONS] <CONTAINER> <PORT>

Arguments:
  <CONTAINER>
          Container the rule belongs to. Must be on the SDN (`--net <network>`) — a `--net host`/`none` container has no firewall to govern

  <PORT>
          `tcp/5432`, `udp/53`, `5432` (any proto), or `tcp/*` (all ports) — the CONTAINER's port and never the host's, because the DNAT already rewrote it in `prerouting`

Options:
      --from <FROM>
          

      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

      --note <NOTE>
          

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # close one port without touching the default policy
  delonix net ingress deny web tcp/8080

  # block one noisy peer from a port everyone else may use
  delonix net ingress deny api tcp/8080 --from 10.200.0.99/32

  # the last command for the same match wins — a later `allow` on this very
  # rule re-opens it, no need to remove anything first
  delonix net ingress deny db tcp/5432

SEE ALSO:
  delonix net ingress allow · delonix net ingress rm · delonix net ingress
  policy

  delonix › net › ingress › deny

ExemplosExamples

Bloquear uma porta específica
Block a specific port
delonix net ingress deny web tcp/22

ingress policy

Set the default inbound policy when no rule matches

Usage: delonix net ingress policy [OPTIONS] <CONTAINER> <POLICY>

Arguments:
  <CONTAINER>
          Container to govern. Must be on the SDN (`--net <network>`)

  <POLICY>
          [possible values: allow, deny]

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # default-deny: only what `ingress allow` names gets in
  delonix net ingress policy db deny

  # back to open, keeping the explicit rules already written
  delonix net ingress policy db allow

SEE ALSO:
  delonix net ingress allow · delonix net ingress ls · delonix net egress
  policy

  delonix › net › ingress › policy

ExemplosExamples

Default-deny (allowlist)
Default-deny (allowlist)
delonix net ingress policy db deny

ingress publish

Publish a host port to the container (DNAT through the ingress)

Usage: delonix net ingress publish [OPTIONS] <CONTAINER> <SPEC>

Arguments:
  <CONTAINER>
          Container to govern. Must be on the SDN (`--net <network>`)

  <SPEC>
          `hostPort:containerPort[/tcp|udp]` or just `port`

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # host 8080 onto the container's 80
  delonix net ingress publish web 8080:80

  # the same number on both sides
  delonix net ingress publish web 8443

  # a UDP service — rootless cannot bind host ports below 1024, so publish
  # high and let a proxy own :53 if you need it
  delonix net ingress publish dns 5353:53/udp

SEE ALSO:
  delonix net ingress unpublish · delonix net ingress ls · delonix container
  update · delonix net httproute apply

  delonix › net › ingress › publish

ExemplosExamples

Publicar uma porta pelo ingress (DNAT)
Publish a port via ingress (DNAT)
delonix net ingress publish web 8080:80

ingress ls

Show the inbound firewall (policy + rules) and published ports

Usage: delonix net ingress ls [OPTIONS] [CONTAINER]

Arguments:
  [CONTAINER]
          Container to inspect (omit to list every container's inbound state)

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -o, --output <OUTPUT>
          Output format: `table` (default) or `json` (ADR-0005). `json` carries `governed` as its own field — a container off the SDN cannot HAVE a firewall, and a script must tell that from «open» without parsing a human sentence
          
          [default: table]
          [possible values: table, json]

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # one container: policy, rules with their packet counters, and the ports
  # published to it
  delonix net ingress ls web

  # the whole node at once — a `--net host` container shows as `n/a`, because
  # the firewall does not govern it
  delonix net ingress ls

SEE ALSO:
  delonix net egress ls · delonix net ingress allow · delonix net flow

  delonix › net › ingress › ls

ExemplosExamples

Ver regras + publishes
See rules + publishes
delonix net ingress ls db

LaboratórioLab

Fecha tudo por omissão e abre só uma porta — o modelo default-deny.

delonix net ingress policy web deny
delonix net ingress allow web 80
curl web-host:80

Close everything by default and open just one port — the default-deny model.

delonix net ingress policy web deny
delonix net ingress allow web 80
curl web-host:80

DesafioChallenge

Reproduz o bug histórico já corrigido: ingress allow web 9999 (SEM indicar proto) só deveria abrir a porta 9999. Confirma com ingress ls que as outras portas continuam fechadas — o veredicto da coluna tem de bater com o que o curl mostra.

Reproduce the historical bug that's already fixed: ingress allow web 9999 (with NO proto given) should only open port 9999. Confirm with ingress ls that the other ports stay closed — the column's verdict has to match what curl actually shows.