box/profiles/box-net.yaml
claude-hdb cdd8b703eb fix: box-net's NIC still pointed at claudenet — the drill caught it in seconds
The profile rename changed the file's name, header and limits but not
the device's 'network:' field; the claudenet→boxnet sed covered
host/*.sh only. On a wiped host (no claudenet to silently latch onto)
'incus profile edit box-net' refused the YAML and setup died — run 14's
first catch, before a single box was minted. The sweep this fix rode in
on found exactly one other stale reference, in the same file's comment.
2026-07-14 14:43:43 +00:00

28 lines
1.3 KiB
YAML

# The placement contract. Every box, whatever its template, launches with
# exactly this profile: the isolated NIC and the root disk — and NOTHING a
# template controls. Resources (limits.*) are per-instance, stamped from the
# template's box.env at mint time; they do not belong here, because a profile
# a template could point away from is a network a template could escape.
name: box-net
description: The box placement contract — isolated NIC + root disk, nothing else
config: {}
devices:
eth0:
type: nic
network: boxnet
name: eth0
# Boxes must not reach each other. This is the mechanism that actually does
# it: the kernel bridge's port-isolation flag, which stops two isolated
# ports exchanging frames at L2.
#
# It is not an ACL rule, and it cannot be. Incus ACLs are L3/L4, and two
# boxes on one bridge are on the same L2 segment — their frames are switched
# between ports and never traverse the netfilter path an ACL lives on. That
# is why the ACL's drop on 10.0.0.0/8 (which contains boxnet) and its
# default ingress drop BOTH looked airtight while box→box was wide open: a
# live probe found box A's SYN arriving at box B and B answering with a RST.
security.port_isolation: "true"
root:
type: disk
pool: default
path: /