Files
EvoFirewall/docs/architecture.md
T
Denozordec a2ad637a38
Build and Push EvoFirewall Docker Image / build-and-push (push) Successful in 2m20s
Build and Push EvoFirewall Docker Image / create-release (push) Skipped
feat(api, web): enhance port ACL handling and documentation
- Updated the `evofw-firewall.sh` script to refine the port ACL logic, ensuring the correct order of operations for deny and allow rules.
- Introduced a new structure for port ACL rows in the UI, allowing for better management of system and EvoFW rules.
- Enhanced the documentation to clarify the new port ACL behavior, including implicit drops for open ports and the distinction between EvoFW and system rules.
- Improved the handling of port ranges and source addresses in the UI, ensuring accurate representation of firewall rules.

These changes improve the functionality and clarity of port ACL management, enhancing user experience and system reliability.
2026-08-16 16:28:11 +07:00

2.4 KiB
Raw Blame History

Архитектура EvoFirewall

Централизованный control plane для firewall-агентов (Linux nft/ipset, MikroTik address-list).

Компоненты

Компонент Путь Роль
Web SPA apps/web ReUI Frame, TanStack Router/Query
API apps/api Fastify 5, JWT + agent tokens
DB packages/db Drizzle + SQLite WAL
Shared packages/shared Zod-контракты, RBAC helpers
UI packages/ui shadcn primitives @evofw/ui
Agents apps/api/src/agent-scripts install.sh, sync, MikroTik RSC

Потоки

  1. EnrollPOST /v1/agent/enroll + X-EvoFW-Seed → pending agent
  2. Approve — UI/API → status approved
  3. PolicyGET /v1/agent/policy → deny/allow CIDRs + default_action + optional port_rules + hash (apply_version: 3) + script_sha256 (Linux; не в policy.hash)
  4. Linux self-update — timer: GET /v1/agent/sync-script (ETag / If-None-Match) → при новой версии заменить /usr/local/sbin/evofw-firewall.sh и exec до policy
  5. Apply — agent пишет kernel rules (L3 + L4 port ACL на nft), POST /v1/agent/apply-report + stats + optional host_firewall snapshot
  6. Lists refresh — cron каждые 5 мин (json_url / domains / evobgp_community)

Политика

  • Именованные наборы правил (policy_sets); агенту назначается M:N через agent_policy_sets
  • Правило в наборе: action: deny | allow + ровно один источник — IP-список (list_id), CIDR или DNS-имя (hostname → A/AAAA, кэш в policy_rule_resolved)
  • Evaluate: правила всех назначенных enabled-наборов (sort + priority) + ip_overrides
  • Цепочка ядра всегда: deny → allow → default_action (accept | drop на агенте)
  • На Linux nft: deny → Port ACL (close drop, open accept, затем implicit drop для портов с open) → allow → default_action
  • Exact overlap: allow \ deny (conflicts_dropped); deny wins
  • Overrides, смена наборов, default_action, Port ACL и refresh DNS/lists бампят policy_generation

Auth

  • Portal SSO app id fw, permissions fw:*
  • Agent bearer token (sha256 hash в БД)