@@ -1,4 +1,4 @@
|
||||
# Dockwatch v9.4.1
|
||||
# Dockwatch v9.5
|
||||
|
||||
> Go module: `git.send.nrw/sendnrw/dockwatch`
|
||||
|
||||
@@ -6,6 +6,19 @@ Dockwatch is a single-binary Go control plane for Docker Compose, Docker resourc
|
||||
|
||||
The same binary runs as `standalone`, `master` or `agent`. SQLite uses `modernc.org/sqlite`, so the application itself builds with `CGO_ENABLED=0`.
|
||||
|
||||
## v9.5 firewall-provider layer
|
||||
|
||||
- Host Security firewall management now uses a provider model: **Auto detect / UFW / firewalld / native nftables**
|
||||
- Auto detect adopts an already-active UFW or firewalld frontend instead of refusing all changes simply because one exists
|
||||
- multiple truly competing active frontends are still treated as a hard conflict
|
||||
- UFW rules are added with deterministic `dockwatch:` comments and Dockwatch removes only those managed rules; it never runs `ufw reset`
|
||||
- firewalld uses the selected native zone and managed rich rules while preserving unrelated services, ports, sources and rich rules
|
||||
- native nftables keeps the isolated `table inet dockwatch` model and never flushes the global ruleset
|
||||
- existing provider state/rules are displayed read-only in the firewall editor before changes are applied
|
||||
- provider selection, default inbound management, firewalld zone selection, ALLOW/DENY/REJECT/LIMIT rules and rule reordering are available in the unified UI
|
||||
- provider changes retain the timed rollback/explicit commit safety model; rollback restores the previous Dockwatch-managed policy and provider default snapshot where applicable
|
||||
- package installation/upgrade now installs the selected firewall frontend (`ufw`, `firewalld` or `nftables`) rather than always installing nftables
|
||||
|
||||
## v9.4.1 fixes
|
||||
|
||||
- fixed monitor creation when no monitor is selected (`state.monitor == null`)
|
||||
@@ -148,20 +161,21 @@ Dockwatch can optionally act as a host-security control plane for the selected l
|
||||
|
||||
The **System → Host Security** page provides a posture overview and managed workflows for:
|
||||
|
||||
**Firewall (nftables)**
|
||||
**Firewall (Auto / UFW / firewalld / nftables)**
|
||||
|
||||
- detect whether nftables is installed and whether Dockwatch's policy is active
|
||||
- configure an isolated `table inet dockwatch` INPUT policy
|
||||
- default inbound `ACCEPT` or `DROP`
|
||||
- stateful established/related allowance, loopback and invalid-state handling
|
||||
- optional ICMP/ICMPv6 allowance
|
||||
- trusted IPv4/IPv6 CIDRs
|
||||
- typed TCP/UDP allow/deny port and port-range rules
|
||||
- server-side `nft -c` validation before apply
|
||||
- conflict detection for active UFW/firewalld; Dockwatch refuses to become a second competing firewall owner
|
||||
- persistence through a Dockwatch-owned systemd unit or OpenRC local script
|
||||
- **Auto detect** adopts the already-active host firewall frontend: UFW first when it is the sole active frontend, firewalld when it is the sole active frontend, otherwise native nftables is used when available
|
||||
- an explicit provider can be selected when you intentionally want to migrate or standardize a host
|
||||
- only genuinely competing active frontends are treated as conflicts; for example UFW + firewalld, or UFW + an already-loaded Dockwatch nftables table
|
||||
- the editor shows installed/active frontends plus the provider's existing runtime rules/state before any mutation
|
||||
- common managed policy supports trusted IPv4/IPv6 CIDRs and ordered TCP/UDP **ALLOW / DENY / REJECT / LIMIT** rules
|
||||
- provider-global default inbound management is an explicit opt-in for UFW/firewalld; nftables keeps its default policy inside Dockwatch's own table
|
||||
- **UFW:** Dockwatch uses native `ufw` commands, tags its rules with deterministic `dockwatch:` comments and removes only those tagged rules; it never runs `ufw reset` and preserves foreign UFW rules
|
||||
- **firewalld:** Dockwatch targets a selected zone, uses native rich rules, and preserves unrelated zone services/ports/sources/rich rules; default zone target changes are opt-in
|
||||
- **nftables:** Dockwatch continues to own only `table inet dockwatch`, validates with `nft -c`, never runs `flush ruleset`, and does not alter Docker NAT/FORWARD chains
|
||||
- when an enabled policy is applied to an inactive UFW/firewalld provider, Dockwatch activates the selected frontend inside the rollback window; rollback restores the previous active state
|
||||
- **timed rollback** (30–600 seconds, UI default 90 seconds) after apply; changes must be explicitly kept after management connectivity is verified
|
||||
- no `flush ruleset`, no changes to Docker NAT/FORWARD chains and no arbitrary nftables text accepted from the browser
|
||||
- package installation/upgrade uses the selected provider package instead of always installing nftables
|
||||
- browser clients never submit arbitrary firewall command text; the backend renders and executes only the typed policy model
|
||||
|
||||
**Fail2Ban**
|
||||
|
||||
@@ -184,7 +198,7 @@ The **System → Host Security** page provides a posture overview and managed wo
|
||||
|
||||
**Installation and maintenance**
|
||||
|
||||
- install or upgrade `nftables`, `fail2ban` and `auditd`/`audit` using the detected host package manager
|
||||
- install or upgrade the selected firewall provider (`ufw`, `firewalld` or `nftables`), `fail2ban` and `auditd`/`audit` using the detected host package manager
|
||||
- supported package-manager families: apt, dnf, yum, zypper, apk and pacman
|
||||
- enable, disable, restart and (where meaningful) reload the corresponding host services
|
||||
- current package/service/config-drift information in the UI
|
||||
|
||||
Reference in New Issue
Block a user