delonix net ingress
Firewall de ENTRADA (regras L4 + publishes DNAT) de um container na SDN.
INBOUND firewall (L4 rules + DNAT publishes) for a container on the SDN.
Metade da superfície unificada de firewall (a outra é egress). Edita a
única fonte de verdade — o ContainerFw por container, aplicado como regras nft na chain de
ingress. ingress governa a ENTRADA: regras allow/deny por [proto/]porta e CIDR,
a política por omissão, e os publishes DNAT. Só actua em containers numa rede custom (têm IP na
delonix0); --net host é recusado.
Half of the unified firewall surface (the other is egress). Edits
the single source of truth — the per-container ContainerFw, applied as nft rules in
the ingress chain. ingress governs INBOUND traffic: allow/deny rules by
[proto/]port and CIDR, the default policy, and DNAT publishes. Only acts on
containers on a custom network (they have an IP on delonix0); --net host
is refused.
📄 Implementação real em Rust: cmd/firewall.rs
Usage: delonix net ingress [OPTIONS] <COMMAND>
Commands:
ls Show the inbound firewall (policy + rules) and published ports
allow Allow inbound traffic to a container: `[proto/]port` from an optional CIDR
deny Deny inbound traffic to a container (same shape as `allow`)
policy Set the default inbound policy when no rule matches
publish Publish a host port to the container (DNAT through the ingress)
unpublish Remove a published host port
clear Remove all inbound rules (keeps published ports)
rm Remove inbound rule(s) matching `[proto/]port` (all protos if none given)
help Print this message or the help of the given subcommand(s)
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
COMMAND MAP:
Inspect ls
Configure allow · deny · policy
Networking publish · unpublish
Maintenance rm · clear
EXAMPLES:
# what is open on a container, and from where
delonix net ingress ls web
# shut the door by default, so only the rules you write let anything in
delonix net ingress policy db deny
# then open Postgres to the SDN alone — nothing from the host's LAN
delonix net ingress allow db tcp/5432 --from 10.200.0.0/16
SEE ALSO:
delonix net egress ls · delonix net ingress publish · delonix container run
· delonix net httproute apply
delonix › net › ingressingress clear
Remove all inbound rules (keeps published ports)
Usage: delonix net ingress clear [OPTIONS] <CONTAINER>
Arguments:
<CONTAINER>
Container to govern. Must be on the SDN (`--net <network>`)
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# wipe the inbound rules and keep the published ports — the DNAT is a
# different plane from the filter
delonix net ingress clear web
SEE ALSO:
delonix net ingress rm · delonix net ingress unpublish · delonix net egress
clear
delonix › net › ingress › clearExemplosExamples
delonix net ingress clear webingress rm
Remove inbound rule(s) matching [proto/]port (all protos if none given)
Usage: delonix net ingress rm [OPTIONS] <CONTAINER> <PORT>
Arguments:
<CONTAINER>
Container to govern. Must be on the SDN (`--net <network>`)
<PORT>
`tcp/5432`, `5432` (any proto), or `*` (all ports) — the CONTAINER's port, the same one the rule was written with
Options:
--from <FROM>
Only rules from this source CIDR (default: any recorded source)
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# drop every rule written for that port, whatever the protocol
delonix net ingress rm web 8080
# only the rule that named this source
delonix net ingress rm db tcp/5432 --from 10.200.0.15/32
SEE ALSO:
delonix net ingress clear · delonix net ingress allow · delonix net ingress
ls
delonix › net › ingress › rmExemplosExamples
delonix net ingress rm web tcp/80ingress unpublish
Remove a published host port
Usage: delonix net ingress unpublish [OPTIONS] <CONTAINER> <HOST_PORT>
Arguments:
<CONTAINER>
Container to govern. Must be on the SDN (`--net <network>`)
<HOST_PORT>
The HOST port to stop publishing — this one IS the host's, because a publish is `hostPort:containerPort` and the host side is its identity
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# give the host port back — the hostfwd and the DNAT go together, and the
# port stops being owned
delonix net ingress unpublish web 8080
SEE ALSO:
delonix net ingress publish · delonix net ingress ls
delonix › net › ingress › unpublishExemplosExamples
delonix net ingress unpublish 8080ingress allow
Allow inbound traffic to a container: [proto/]port from an optional CIDR
Usage: delonix net ingress allow [OPTIONS] <CONTAINER> <PORT>
Arguments:
<CONTAINER>
Container the rule belongs to. Must be on the SDN (`--net <network>`) — a `--net host`/`none` container has no firewall to govern
<PORT>
`tcp/5432`, `udp/53`, `5432` (any proto), or `tcp/*` (all ports) — the CONTAINER's port and never the host's, because the DNAT already rewrote it in `prerouting`
Options:
--from <FROM>
Only from this source CIDR (default: anywhere)
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
--note <NOTE>
Free-form note kept with the rule
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# open the port the CONTAINER listens on — the DNAT has already rewritten
# the host port away by the time the rule is evaluated
delonix net ingress allow web tcp/80
# Postgres, but only from the SDN
delonix net ingress allow db tcp/5432 --from 10.200.0.0/16
# leave a reason behind, so `ingress ls` explains itself to the next person
delonix net ingress allow api tcp/8080 --note "public API"
# every port from a single peer, when the rule is about the source and not
# the service
delonix net ingress allow db tcp/* --from 10.200.0.15/32
SEE ALSO:
delonix net ingress deny · delonix net ingress policy · delonix net ingress
ls · delonix net ingress rm
delonix › net › ingress › allowExemplosExamples
delonix net ingress allow db tcp/5432 --from 10.219.0.0/16ingress deny
Deny inbound traffic to a container (same shape as allow)
Usage: delonix net ingress deny [OPTIONS] <CONTAINER> <PORT>
Arguments:
<CONTAINER>
Container the rule belongs to. Must be on the SDN (`--net <network>`) — a `--net host`/`none` container has no firewall to govern
<PORT>
`tcp/5432`, `udp/53`, `5432` (any proto), or `tcp/*` (all ports) — the CONTAINER's port and never the host's, because the DNAT already rewrote it in `prerouting`
Options:
--from <FROM>
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
--note <NOTE>
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# close one port without touching the default policy
delonix net ingress deny web tcp/8080
# block one noisy peer from a port everyone else may use
delonix net ingress deny api tcp/8080 --from 10.200.0.99/32
# the last command for the same match wins — a later `allow` on this very
# rule re-opens it, no need to remove anything first
delonix net ingress deny db tcp/5432
SEE ALSO:
delonix net ingress allow · delonix net ingress rm · delonix net ingress
policy
delonix › net › ingress › denyExemplosExamples
delonix net ingress deny web tcp/22ingress policy
Set the default inbound policy when no rule matches
Usage: delonix net ingress policy [OPTIONS] <CONTAINER> <POLICY>
Arguments:
<CONTAINER>
Container to govern. Must be on the SDN (`--net <network>`)
<POLICY>
[possible values: allow, deny]
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# default-deny: only what `ingress allow` names gets in
delonix net ingress policy db deny
# back to open, keeping the explicit rules already written
delonix net ingress policy db allow
SEE ALSO:
delonix net ingress allow · delonix net ingress ls · delonix net egress
policy
delonix › net › ingress › policyExemplosExamples
delonix net ingress policy db denyingress publish
Publish a host port to the container (DNAT through the ingress)
Usage: delonix net ingress publish [OPTIONS] <CONTAINER> <SPEC>
Arguments:
<CONTAINER>
Container to govern. Must be on the SDN (`--net <network>`)
<SPEC>
`hostPort:containerPort[/tcp|udp]` or just `port`
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# host 8080 onto the container's 80
delonix net ingress publish web 8080:80
# the same number on both sides
delonix net ingress publish web 8443
# a UDP service — rootless cannot bind host ports below 1024, so publish
# high and let a proxy own :53 if you need it
delonix net ingress publish dns 5353:53/udp
SEE ALSO:
delonix net ingress unpublish · delonix net ingress ls · delonix container
update · delonix net httproute apply
delonix › net › ingress › publishExemplosExamples
delonix net ingress publish web 8080:80ingress ls
Show the inbound firewall (policy + rules) and published ports
Usage: delonix net ingress ls [OPTIONS] [CONTAINER]
Arguments:
[CONTAINER]
Container to inspect (omit to list every container's inbound state)
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-o, --output <OUTPUT>
Output format: `table` (default) or `json` (ADR-0005). `json` carries `governed` as its own field — a container off the SDN cannot HAVE a firewall, and a script must tell that from «open» without parsing a human sentence
[default: table]
[possible values: table, json]
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# one container: policy, rules with their packet counters, and the ports
# published to it
delonix net ingress ls web
# the whole node at once — a `--net host` container shows as `n/a`, because
# the firewall does not govern it
delonix net ingress ls
SEE ALSO:
delonix net egress ls · delonix net ingress allow · delonix net flow
delonix › net › ingress › lsExemplosExamples
delonix net ingress ls dbLaboratórioLab
Fecha tudo por omissão e abre só uma porta — o modelo default-deny.
delonix net ingress policy web deny
delonix net ingress allow web 80
curl web-host:80Close everything by default and open just one port — the default-deny model.
delonix net ingress policy web deny
delonix net ingress allow web 80
curl web-host:80DesafioChallenge
Reproduz o bug histórico já corrigido: ingress allow web
9999 (SEM indicar proto) só deveria abrir a porta 9999. Confirma com ingress ls
que as outras portas continuam fechadas — o veredicto da coluna tem de bater com o que o
curl mostra.
Reproduce the historical bug that's already fixed: ingress allow
web 9999 (with NO proto given) should only open port 9999. Confirm with
ingress ls that the other ports stay closed — the column's verdict has to match what
curl actually shows.