Skip to main content

work with iptables in a declarative manner

Project description

simple tables

A simple interface to managing iptables on linux

The hardest part of managing iptables is that they are a central piece of data that's constantly changing from many different directions. Because its state isn't guaranteed, making a simple modification to it can have undesired consequences. This project aims to solve this problem by making yet another interface to iptables.

This interface aims to be declarative. Rather than looking at issuing changes directly to iptables, this package defines the desired state. The significance is that it matters less what the tables look like at any given time and instead the goal is to end up with what it should look like.

Additionally, because it's unknown what changes other systems have made, any tables and rules that have not been declared are left untouched.

Example

import iptables

plan = iptables.Plan()

# this will delete an existing table and create it from scratch
berto_chain = plan.add_chain('OPENVPN_BERTO')

# rules are added with a default priority of 50
berto_chain.add_rule(iptables.Rule('-o tun0 -s 192.168.2.2 -d 192.168.1.1 -j ACCEPT'))

# this will get an existing table and create it if it does not exist
openvpn_chain = plan.get_chain('OPENVPN')

# rules with higher number priority get added to the chain first
# when updating an existing chain, rules already in the chain get a priority of 70.
# being added is compared to existing rules and will be added if missing or left alone.
openvpn_chain.add_rule(iptables.Rule('-o ! tun0 -j RETURN', priority=100))
openvpn_chain.add_rule(berto_chain.jump)

# make necessary changes to achieve the desired outcome
plan_execute()

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

declarative-iptables-0.1.2.tar.gz (7.2 kB view details)

Uploaded Source

File details

Details for the file declarative-iptables-0.1.2.tar.gz.

File metadata

  • Download URL: declarative-iptables-0.1.2.tar.gz
  • Upload date:
  • Size: 7.2 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/2.0.0 pkginfo/1.5.0.1 requests/2.22.0 setuptools/52.0.0 requests-toolbelt/0.9.1 tqdm/4.36.1 CPython/3.6.6

File hashes

Hashes for declarative-iptables-0.1.2.tar.gz
Algorithm Hash digest
SHA256 afeacdb4241f8301df15e1750bb29e09beb5962a4af01e1fd7bf82f0fe8a886c
MD5 df3e0d1095e069b086dc2d21729e5de4
BLAKE2b-256 f0e9bd2788865820f771b18943e13d591a720b76d8b0e44ac4c3d0777c3625fa

See more details on using hashes here.

Supported by

AWS AWS Cloud computing and Security Sponsor Datadog Datadog Monitoring Fastly Fastly CDN Google Google Download Analytics Microsoft Microsoft PSF Sponsor Pingdom Pingdom Monitoring Sentry Sentry Error logging StatusPage StatusPage Status page