Skip to content

Own overlay NAT exclusion in Network Plugin Manager - #15

Merged
chen21019 merged 1 commit into
mainfrom
fix/firewall-owner-boundary
Sep 12, 2026
Merged

chen21019 merged 1 commit into
mainfrom
fix/firewall-owner-boundary

Conversation

@chen21019

Copy link
Copy Markdown

Keep same-subnet overlay sources outside masquerade in iptables-nft and iptables-legacy, matching native nftables. Add opt-in isolated-VM apply/reapply/cleanup gates for both xtables frontends and document exclusive host NAT/host-port ownership and manager-first upgrade order. Verified on isolated Ubuntu 26.04.1 / Docker 29.8 VM in both xtables modes; target Go unit packages passed. Native mode unchanged. Full managed-service lifecycle and production promotion remain separate gates.

@chen21019
chen21019 requested a review from a team as a code owner September 12, 2026 13:29
@chen21019
chen21019 enabled auto-merge (squash) September 12, 2026 13:34
@chen21019
chen21019 merged commit 44432a0 into main Sep 12, 2026
5 checks passed
@chen21019
chen21019 deleted the fix/firewall-owner-boundary branch September 12, 2026 13:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant