Repository navigation
Add blocking rule sets for per-device policies - #411
Merged
Merged
Conversation
Rule sets give some devices their own block lists and their own blocked and allowed domains. A device joins one through its [[clients]] entry's rule_set, and blocking.default_lists narrows the lists for everyone else. Each rule set gets an on/off table over the compiler's owner sets, so choosing lists costs nothing per blocked domain. The query path parses the client address once and looks it up in an exact-address map, then the networks most specific first, with no allocations. Bypass clients are now a rule set with blocking off, so there is one path for both. Devices now replicate with the rest of the runtime settings, since a device's rule set decides how every node blocks for it. Refs #240
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Requested by Nick · project thread
Before: every blocking rule applied to every device. The only per-client control was
bypass_clients, which turned blocking off completely.After:
[[blocking.rule_sets]]give some devices their own block lists plus their own blocked and allowed domains. A device joins a set throughrule_seton its[[clients]]entry, andblocking.default_listspicks the lists for everyone else. Everyone else blocks exactly as before.This is PR 1 of #240: the engine and config only, no console UI. A device named by
mackeeps its rule set in config but only takes effect in PR 2, once identities feed an address table. The docs say so.How
[]boolover those owner sets. When the most specific match comes from a list the set doesn't use, the lookup keeps walking up to the parent name. A@@exception only counts when the set uses its list.blocking.domainsandblocking.allowed_domainsapply in every set.[[clients]]) now replicate with the runtime settings, because a device's rule set decides how every node blocks for it. A snapshot from an older primary leaves a replica's devices alone, and an empty list still clears them.[[clients]]device entry rather than in adeviceslist on the rule set as Blocking: per-device rules and "Block everything" for a device #240 sketched. That keeps one device registry, which the Insights drawer already writes.Benchmarks
BenchmarkPolicyDecisionuses 100k blocked domains with 2 lists, 200k iterations, median of 5 runs. The container's CPU is shared and noisy, so read these as "no regression":TestPolicyDecisionDoesNotAllocateWithRuleSetsasserts zero allocations for clients with no set, in a set, and bypassed.Checks
go tool mage verifypasses, andgofmt -l .is clean. The race detector passes ondnsserver,configandapp.Refs #240
Generated by Claude Code