fix: box-net's NIC still pointed at claudenet — the drill caught it in seconds
The profile rename changed the file's name, header and limits but not the device's 'network:' field; the claudenet→boxnet sed covered host/*.sh only. On a wiped host (no claudenet to silently latch onto) 'incus profile edit box-net' refused the YAML and setup died — run 14's first catch, before a single box was minted. The sweep this fix rode in on found exactly one other stale reference, in the same file's comment.
This commit is contained in:
parent
5defd40bca
commit
cdd8b703eb
1 changed files with 2 additions and 2 deletions
|
|
@ -9,7 +9,7 @@ config: {}
|
||||||
devices:
|
devices:
|
||||||
eth0:
|
eth0:
|
||||||
type: nic
|
type: nic
|
||||||
network: claudenet
|
network: boxnet
|
||||||
name: eth0
|
name: eth0
|
||||||
# Boxes must not reach each other. This is the mechanism that actually does
|
# Boxes must not reach each other. This is the mechanism that actually does
|
||||||
# it: the kernel bridge's port-isolation flag, which stops two isolated
|
# it: the kernel bridge's port-isolation flag, which stops two isolated
|
||||||
|
|
@ -18,7 +18,7 @@ devices:
|
||||||
# It is not an ACL rule, and it cannot be. Incus ACLs are L3/L4, and two
|
# It is not an ACL rule, and it cannot be. Incus ACLs are L3/L4, and two
|
||||||
# boxes on one bridge are on the same L2 segment — their frames are switched
|
# boxes on one bridge are on the same L2 segment — their frames are switched
|
||||||
# between ports and never traverse the netfilter path an ACL lives on. That
|
# between ports and never traverse the netfilter path an ACL lives on. That
|
||||||
# is why the ACL's drop on 10.0.0.0/8 (which contains claudenet) and its
|
# is why the ACL's drop on 10.0.0.0/8 (which contains boxnet) and its
|
||||||
# default ingress drop BOTH looked airtight while box→box was wide open: a
|
# default ingress drop BOTH looked airtight while box→box was wide open: a
|
||||||
# live probe found box A's SYN arriving at box B and B answering with a RST.
|
# live probe found box A's SYN arriving at box B and B answering with a RST.
|
||||||
security.port_isolation: "true"
|
security.port_isolation: "true"
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue