Firewall (kind: firewall)
Security rules — an ordered set of allow/deny rules plus default in/out behavior.
Schema
spec.reset— iftrue, wipe all existing firewall rules before applying these (defaultfalse)spec.defaults[]— baseline{direction, permission, comment}rules (permission:allow/deny); directions must be uniquespec.allow[]/spec.deny[]— explicit rule lists, each a rule:direction—inoroutproto—tcp,udp, oricmp(required wheneverportis set)port— a single port, a range string ("80:90"), or a list of either; not valid foricmpinterface— optional network interface namefrom/to— source/destination IP or CIDR: a literal, or a${var:}/${secret:}/${feature:}tokencomment— optional documentationthe same rule (by signature) cannot appear in both
allowanddeny
spec.configuration— raw provisioner passthrough (e.g. Terraform NSG arguments)spec.default_tags/spec.custom_tags— cloud tagsspec.custom— free-form data
Example
apiVersion: strata.huybrechts.xyz/v2
kind: firewall
meta:
name: web-public
spec:
defaults:
- direction: in
permission: deny
- direction: out
permission: allow
allow:
- direction: in
proto: tcp
port: 443
from: "0.0.0.0/0"
comment: "Public HTTPS"
default_tags:
environment: example
Notes
from/towere v1’s proposed-but-never-builtspec.referencesgap (ADR-0001) — superseded by the same${var:}/${secret:}/${feature:}Value-token syntax every other kind uses, rather than a separate hand-authored declared-keys list.