forked from heavy-duty/box
The profile rename changed the file's name, header and limits but not the device's 'network:' field; the claudenet→boxnet sed covered host/*.sh only. On a wiped host (no claudenet to silently latch onto) 'incus profile edit box-net' refused the YAML and setup died — run 14's first catch, before a single box was minted. The sweep this fix rode in on found exactly one other stale reference, in the same file's comment.
28 lines
1.3 KiB
YAML
28 lines
1.3 KiB
YAML
# The placement contract. Every box, whatever its template, launches with
|
|
# exactly this profile: the isolated NIC and the root disk — and NOTHING a
|
|
# template controls. Resources (limits.*) are per-instance, stamped from the
|
|
# template's box.env at mint time; they do not belong here, because a profile
|
|
# a template could point away from is a network a template could escape.
|
|
name: box-net
|
|
description: The box placement contract — isolated NIC + root disk, nothing else
|
|
config: {}
|
|
devices:
|
|
eth0:
|
|
type: nic
|
|
network: boxnet
|
|
name: eth0
|
|
# Boxes must not reach each other. This is the mechanism that actually does
|
|
# it: the kernel bridge's port-isolation flag, which stops two isolated
|
|
# ports exchanging frames at L2.
|
|
#
|
|
# It is not an ACL rule, and it cannot be. Incus ACLs are L3/L4, and two
|
|
# boxes on one bridge are on the same L2 segment — their frames are switched
|
|
# between ports and never traverse the netfilter path an ACL lives on. That
|
|
# is why the ACL's drop on 10.0.0.0/8 (which contains boxnet) and its
|
|
# default ingress drop BOTH looked airtight while box→box was wide open: a
|
|
# live probe found box A's SYN arriving at box B and B answering with a RST.
|
|
security.port_isolation: "true"
|
|
root:
|
|
type: disk
|
|
pool: default
|
|
path: /
|