Skip to content

Test policy firewall ownership across Docker modes - #3

Merged
chen21019 merged 1 commit into
mainfrom
test/firewall-owner-vm-gate
Sep 12, 2026
Merged

chen21019 merged 1 commit into
mainfrom
test/firewall-owner-vm-gate

Conversation

@chen21019

Copy link
Copy Markdown

Add an opt-in isolated-root-VM integration test that rejects pre-existing policy state or a nonempty Docker host, applies/reapplies/removes only the policy-owned nftables table, and verifies Docker-owned firewall rules remain byte-for-byte unchanged. Ran against Ubuntu 26.04.1 / Docker 29.8 in native nftables, iptables-nft, and iptables-legacy modes. No runtime enforcement code changes; a full multi-host traffic/upgrade gate is separate.

@chen21019
chen21019 requested a review from a team as a code owner September 12, 2026 13:48
@chen21019
chen21019 merged commit 898833d into main Sep 12, 2026
4 checks passed
@chen21019
chen21019 deleted the test/firewall-owner-vm-gate branch September 12, 2026 13:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant