6dc5fb5f3b8a264a53476d398e5b6dd9475e311f
- Updated the `evofw-firewall.sh` script to clarify the handling of incoming traffic for port ACLs, ensuring accurate rule application for Docker NAT and local addresses. - Enhanced the UI description for port ACLs to specify that only incoming traffic is affected, improving user understanding of the firewall behavior. - Revised documentation to reflect the updated logic for port ACLs, emphasizing the distinction between incoming and outgoing traffic and the implications for service accessibility. These changes improve the clarity and functionality of port ACL management, enhancing user experience and system reliability.
EvoFirewall
Централизованный firewall controller: Linux / MikroTik agents, IP lists, allow/deny политики, статистика.
Интеграции: auth-portal (SSO, app id fw), EvoBGP (источник префиксов).
Стек
- Monorepo: pnpm workspaces + turbo
apps/web— Vite + React + TanStack + shadcn/ui + ReUI Frameapps/api— Fastify 5 + Drizzle + SQLite- Packages:
@evofw/ui,@evofw/shared,@evofw/db
Быстрый старт
pnpm install
cp .env.example .env
pnpm --filter @evofw/db build
pnpm --filter @evofw/shared build
pnpm --filter @evofw/api dev # :8080
pnpm --filter @evofw/web dev # :5177
Linux agent (short link из UI /agents → Добавить агента):
curl -fsSL http://localhost:8080/agent-install/<id> | bash
# или:
curl -fsSL http://localhost:8080/<slug> | bash
Legacy one-liner:
curl -fsSL http://localhost:8080/v1/agent/install.sh | \
EVOFW_CP_URL=http://localhost:8080 \
EVOFW_SEED=dev-enroll-seed-change-me \
EVOFW_CLIENT_NAME="web-01" \
bash
Затем Approve в UI /agents.
Docs
См. docs/README.md.
Git
origin https://git.shts.su/denozord/EvoFirewall.git