Commit 5294d93
committed
feat: Add Rust eBPF firewall, Wolfi containers, and expanded CLI
This commit adds the runtime infrastructure components for the
Wharf/Yacht security architecture:
## Rust eBPF Firewall (wharf-ebpf)
- Pure Rust XDP program using Aya framework (no C code)
- IP blocklist for APL replacement
- Protocol lockdown (TCP/UDP only)
- Port allowlist (80, 443, 3306, 4242)
- Userspace loader for kernel module management
## Wolfi Containers
- php.Dockerfile: Hardened PHP-FPM with disabled dangerous functions
- nginx.Dockerfile: Non-root Nginx with security headers
- nginx.conf: JSON logging, rate limiting, temp paths in tmpfs
- php-fpm.conf: Static process manager, session security
- wordpress-rules.conf: Dark Matter /wp-admin blocking
## Podman Pod Definition
- yacht.yaml: Multi-container pod (nginx, php, agent)
- Read-only root filesystem with tmpfs overlays
- NET_ADMIN capability for eBPF loading
- Shadow database port (33060) configuration
## Expanded CLI (wharf-cli)
- State management: freeze, thaw, diff, list, prune
- Security operations: audit, rotate-keys, gen-firewall, scan
- Database commands: policy, export, import, status
- Fleet management: list, add, remove, status
- Container operations: build, deploy, logs
## Yacht Agent Updates
- Dynamic port binding (MySQL 3306, PostgreSQL 5432, Redis 6379)
- Protocol detection and routing
- MySQL/PostgreSQL query inspection
- Full database proxy implementation
## Justfile Updates (19 sections, 80+ recipes)
- Container management: build-containers, deploy-pod
- Database operations: db-policy, db-export, db-stats
- eBPF firewall: build-ebpf, load-shield
- Fleet management: fleet-list, fleet-add, fleet-remove
- State management: snapshot, restore, diff-state
- Emergency operations: panic, kill-yacht, restore-yacht
The Yacht is now a fully operational micro-runtime.1 parent 55390f0 commit 5294d93
15 files changed
Lines changed: 2152 additions & 52 deletions
File tree
- bin
- wharf-cli
- src
- yacht-agent
- src
- crates/wharf-ebpf
- src
- infra
- config
- containers
- podman
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
3 | 3 | | |
| 4 | + | |
4 | 5 | | |
5 | 6 | | |
6 | 7 | | |
| |||
53 | 54 | | |
54 | 55 | | |
55 | 56 | | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
461 | 461 | | |
462 | 462 | | |
463 | 463 | | |
| 464 | + | |
| 465 | + | |
| 466 | + | |
| 467 | + | |
| 468 | + | |
| 469 | + | |
| 470 | + | |
| 471 | + | |
| 472 | + | |
| 473 | + | |
| 474 | + | |
| 475 | + | |
| 476 | + | |
| 477 | + | |
| 478 | + | |
| 479 | + | |
| 480 | + | |
| 481 | + | |
| 482 | + | |
| 483 | + | |
| 484 | + | |
| 485 | + | |
| 486 | + | |
| 487 | + | |
| 488 | + | |
| 489 | + | |
| 490 | + | |
| 491 | + | |
| 492 | + | |
| 493 | + | |
| 494 | + | |
| 495 | + | |
| 496 | + | |
| 497 | + | |
| 498 | + | |
| 499 | + | |
| 500 | + | |
| 501 | + | |
| 502 | + | |
| 503 | + | |
| 504 | + | |
| 505 | + | |
| 506 | + | |
| 507 | + | |
| 508 | + | |
| 509 | + | |
| 510 | + | |
| 511 | + | |
| 512 | + | |
| 513 | + | |
| 514 | + | |
| 515 | + | |
| 516 | + | |
| 517 | + | |
| 518 | + | |
| 519 | + | |
| 520 | + | |
| 521 | + | |
| 522 | + | |
| 523 | + | |
| 524 | + | |
| 525 | + | |
| 526 | + | |
| 527 | + | |
| 528 | + | |
| 529 | + | |
| 530 | + | |
| 531 | + | |
| 532 | + | |
| 533 | + | |
| 534 | + | |
| 535 | + | |
| 536 | + | |
| 537 | + | |
| 538 | + | |
| 539 | + | |
| 540 | + | |
| 541 | + | |
| 542 | + | |
| 543 | + | |
| 544 | + | |
| 545 | + | |
| 546 | + | |
| 547 | + | |
| 548 | + | |
| 549 | + | |
| 550 | + | |
| 551 | + | |
| 552 | + | |
| 553 | + | |
| 554 | + | |
| 555 | + | |
| 556 | + | |
| 557 | + | |
| 558 | + | |
| 559 | + | |
| 560 | + | |
| 561 | + | |
| 562 | + | |
| 563 | + | |
| 564 | + | |
| 565 | + | |
| 566 | + | |
| 567 | + | |
| 568 | + | |
| 569 | + | |
| 570 | + | |
| 571 | + | |
| 572 | + | |
| 573 | + | |
| 574 | + | |
| 575 | + | |
| 576 | + | |
| 577 | + | |
| 578 | + | |
| 579 | + | |
| 580 | + | |
| 581 | + | |
| 582 | + | |
| 583 | + | |
| 584 | + | |
| 585 | + | |
| 586 | + | |
| 587 | + | |
| 588 | + | |
| 589 | + | |
| 590 | + | |
| 591 | + | |
| 592 | + | |
| 593 | + | |
| 594 | + | |
| 595 | + | |
| 596 | + | |
| 597 | + | |
| 598 | + | |
| 599 | + | |
| 600 | + | |
| 601 | + | |
| 602 | + | |
| 603 | + | |
| 604 | + | |
| 605 | + | |
| 606 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
30 | 30 | | |
31 | 31 | | |
32 | 32 | | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
0 commit comments