Skip to content

Support Docker-native nftables without legacy firewall fallback - #4

Merged
chen21019 merged 3 commits into
mainfrom
verification/ipsec-vxlan-overlay-network-nft-native-2604
Sep 12, 2026
Merged

chen21019 merged 3 commits into
mainfrom
verification/ipsec-vxlan-overlay-network-nft-native-2604

Conversation

@chen21019

Copy link
Copy Markdown

Host-XFRM IPsec router now detects Docker's active firewall backend and uses only that path. Native nftables leaves host NAT/forwarding ownership to network-plugin-manager; iptables-nft and deliberately selected legacy retain compatibility. The container-netns mode keeps its original local rule. Added focused branch tests and a tag-gated release workflow. Validation: Go race/integration shell suite, backend mode tests, and Ubuntu 26.04 Docker 29.8 native-nft isolated VM script check; full platform lifecycle and GHCR publish remain pending. Do not tag or promote Catalog until same-SHA release gates and GHCR Actions Write are confirmed.

@chen21019
chen21019 requested a review from a team as a code owner September 12, 2026 06:42
@chen21019
chen21019 merged commit 5fe7fa6 into main Sep 12, 2026
5 checks passed
@chen21019
chen21019 deleted the verification/ipsec-vxlan-overlay-network-nft-native-2604 branch September 12, 2026 07:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant