Initial scaffold for tomswall

Spiritual successor to shorewall — manages nftables directly via
google/nftables. Reads a single YAML config covering zones, interfaces,
hosts, policy, rules, snat, and named portgroups. Computes differential
changes against the running nftables state and applies them atomically.
Supports detecting and purging rules added outside of tomswall.
This commit is contained in:
2026-06-28 23:43:16 +10:00
commit 2a3eb3b04d
18 changed files with 1672 additions and 0 deletions
+21
View File
@@ -0,0 +1,21 @@
module git.unkin.net/unkin/tomswall
go 1.23
require (
github.com/google/nftables v0.2.0
github.com/spf13/cobra v1.8.1
golang.org/x/sys v0.18.0
gopkg.in/yaml.v3 v3.0.1
)
require (
github.com/google/go-cmp v0.6.0 // indirect
github.com/inconshreveable/mousetrap v1.1.0 // indirect
github.com/josharian/native v1.1.0 // indirect
github.com/mdlayher/netlink v1.7.2 // indirect
github.com/mdlayher/socket v0.5.1 // indirect
github.com/spf13/pflag v1.0.5 // indirect
golang.org/x/net v0.23.0 // indirect
golang.org/x/sync v0.6.0 // indirect
)