Skip to content

control

control

Live nft-mutation verbs — allow, deny, up, down, quarantine, rules, preview.

Each verb mutates or inspects a running container's shield ruleset. The handlers accept (shield, [container], **kwargs) and print to stdout; the CLI dispatcher builds the Shield and forwards the parsed argv.

ALLOW = CommandDef(name='allow', help='Live-allow a domain or IP for a container', handler=_handle_allow, extras=NEEDS_CTR, args=(CONTAINER_ARG, ArgDef(name='target', help='Domain name or IP address to allow'))) module-attribute

DENY = CommandDef(name='deny', help='Live-deny a domain or IP for a container', handler=_handle_deny, extras=NEEDS_CTR, args=(CONTAINER_ARG, ArgDef(name='target', help='Domain name or IP address to deny'))) module-attribute

DOWN = CommandDef(name='down', help='Switch container to the DOWN posture (accept + log; private ranges still rejected)', handler=_handle_down, extras=NEEDS_CTR, args=(CONTAINER_ARG, CONTAINER_ID_ARG, ArgDef(name='--disengage', action='store_true', dest='disengaged', help='Enforce nothing — lift the deny set and every range reject (DISENGAGED posture)'))) module-attribute

UP = CommandDef(name='up', help='Restore deny-all mode for a container', handler=_handle_up, extras=NEEDS_CTR, args=(CONTAINER_ARG, CONTAINER_ID_ARG)) module-attribute

RESET = CommandDef(name='reset', help='Forget DNS-learned allow state (back to authored policy seeds)', handler=_handle_reset, extras=NEEDS_CTR, args=(CONTAINER_ARG,)) module-attribute

QUARANTINE = CommandDef(name='quarantine', help='Total network blackout (drop all, log dropped traffic)', handler=_handle_quarantine, extras=NEEDS_CTR, args=(CONTAINER_ARG,)) module-attribute

RULES = CommandDef(name='rules', help='Show current nft rules for a container', handler=_handle_rules, extras=NEEDS_CTR, args=(CONTAINER_ARG,)) module-attribute

PREVIEW = CommandDef(name='preview', help='Show ruleset that would be applied', handler=_handle_preview, args=(ArgDef(name='--down', action='store_true', help='Show the DOWN-posture ruleset'), ArgDef(name='--disengage', action='store_true', dest='disengaged', help='Show the DISENGAGED ruleset: no deny set, no range rejects (requires --down)'))) module-attribute