Update
release-tag / release-image (push) Successful in 2m45s

This commit is contained in:
2026-09-01 13:59:25 +02:00
parent c609c34f16
commit 6eb4e093ec
8 changed files with 1267 additions and 137 deletions
+28 -14
View File
@@ -1,4 +1,4 @@
# Dockwatch v9.4.1
# Dockwatch v9.5
> Go module: `git.send.nrw/sendnrw/dockwatch`
@@ -6,6 +6,19 @@ Dockwatch is a single-binary Go control plane for Docker Compose, Docker resourc
The same binary runs as `standalone`, `master` or `agent`. SQLite uses `modernc.org/sqlite`, so the application itself builds with `CGO_ENABLED=0`.
## v9.5 firewall-provider layer
- Host Security firewall management now uses a provider model: **Auto detect / UFW / firewalld / native nftables**
- Auto detect adopts an already-active UFW or firewalld frontend instead of refusing all changes simply because one exists
- multiple truly competing active frontends are still treated as a hard conflict
- UFW rules are added with deterministic `dockwatch:` comments and Dockwatch removes only those managed rules; it never runs `ufw reset`
- firewalld uses the selected native zone and managed rich rules while preserving unrelated services, ports, sources and rich rules
- native nftables keeps the isolated `table inet dockwatch` model and never flushes the global ruleset
- existing provider state/rules are displayed read-only in the firewall editor before changes are applied
- provider selection, default inbound management, firewalld zone selection, ALLOW/DENY/REJECT/LIMIT rules and rule reordering are available in the unified UI
- provider changes retain the timed rollback/explicit commit safety model; rollback restores the previous Dockwatch-managed policy and provider default snapshot where applicable
- package installation/upgrade now installs the selected firewall frontend (`ufw`, `firewalld` or `nftables`) rather than always installing nftables
## v9.4.1 fixes
- fixed monitor creation when no monitor is selected (`state.monitor == null`)
@@ -148,20 +161,21 @@ Dockwatch can optionally act as a host-security control plane for the selected l
The **System → Host Security** page provides a posture overview and managed workflows for:
**Firewall (nftables)**
**Firewall (Auto / UFW / firewalld / nftables)**
- detect whether nftables is installed and whether Dockwatch's policy is active
- configure an isolated `table inet dockwatch` INPUT policy
- default inbound `ACCEPT` or `DROP`
- stateful established/related allowance, loopback and invalid-state handling
- optional ICMP/ICMPv6 allowance
- trusted IPv4/IPv6 CIDRs
- typed TCP/UDP allow/deny port and port-range rules
- server-side `nft -c` validation before apply
- conflict detection for active UFW/firewalld; Dockwatch refuses to become a second competing firewall owner
- persistence through a Dockwatch-owned systemd unit or OpenRC local script
- **Auto detect** adopts the already-active host firewall frontend: UFW first when it is the sole active frontend, firewalld when it is the sole active frontend, otherwise native nftables is used when available
- an explicit provider can be selected when you intentionally want to migrate or standardize a host
- only genuinely competing active frontends are treated as conflicts; for example UFW + firewalld, or UFW + an already-loaded Dockwatch nftables table
- the editor shows installed/active frontends plus the provider's existing runtime rules/state before any mutation
- common managed policy supports trusted IPv4/IPv6 CIDRs and ordered TCP/UDP **ALLOW / DENY / REJECT / LIMIT** rules
- provider-global default inbound management is an explicit opt-in for UFW/firewalld; nftables keeps its default policy inside Dockwatch's own table
- **UFW:** Dockwatch uses native `ufw` commands, tags its rules with deterministic `dockwatch:` comments and removes only those tagged rules; it never runs `ufw reset` and preserves foreign UFW rules
- **firewalld:** Dockwatch targets a selected zone, uses native rich rules, and preserves unrelated zone services/ports/sources/rich rules; default zone target changes are opt-in
- **nftables:** Dockwatch continues to own only `table inet dockwatch`, validates with `nft -c`, never runs `flush ruleset`, and does not alter Docker NAT/FORWARD chains
- when an enabled policy is applied to an inactive UFW/firewalld provider, Dockwatch activates the selected frontend inside the rollback window; rollback restores the previous active state
- **timed rollback** (30–600 seconds, UI default 90 seconds) after apply; changes must be explicitly kept after management connectivity is verified
- no `flush ruleset`, no changes to Docker NAT/FORWARD chains and no arbitrary nftables text accepted from the browser
- package installation/upgrade uses the selected provider package instead of always installing nftables
- browser clients never submit arbitrary firewall command text; the backend renders and executes only the typed policy model
**Fail2Ban**
@@ -184,7 +198,7 @@ The **System → Host Security** page provides a posture overview and managed wo
**Installation and maintenance**
- install or upgrade `nftables`, `fail2ban` and `auditd`/`audit` using the detected host package manager
- install or upgrade the selected firewall provider (`ufw`, `firewalld` or `nftables`), `fail2ban` and `auditd`/`audit` using the detected host package manager
- supported package-manager families: apt, dnf, yum, zypper, apk and pacman
- enable, disable, restart and (where meaningful) reload the corresponding host services
- current package/service/config-drift information in the UI