nftables, Default Deny And A Port That Really Times Out
nftables from AppStream on EL 10: default-deny inbound with a port allowlist, in its own table, checked by nft before it loads. The live test opens a listener on an allowed port and on one that is not: the first answers, the second times out, the drop counter moves, and loopback still answers. Original role, live-tested on Rocky Linux 10.
Verification
Live-testedReally deployed to a container sandbox, proven idempotent (a second run changes nothing), verified against the role’s assertions, then torn down.
Conformance
- Static validation (yamllint · ansible-lint)
Provenance
- SHA-256 checksum
- Signature (pending)
Functional
- Live-tested - applied, verified, destroyed
Last verified 2026-09-26 · podman 4.9.3 · ansible 2.21.4 · how we verify
Cite it in your README
badge · attributionPaste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads live-tested because the record says so, and the link lands on this page.
[](https://www.iac-bazaar.com/catalog/ansible-nftables?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
Ansible role 1.0.0, live-tested on IaC Bazaar: [nftables, Default Deny And A Port That Really Times Out](https://www.iac-bazaar.com/catalog/ansible-nftables?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
```yaml
# nftables, Default Deny And A Port That Really Times Out: https://www.iac-bazaar.com/catalog/ansible-nftables (download from your IaC Bazaar account)
```Preview:
Documentation
nftables
A host firewall in one table, and the proof that it drops. The role writes a
default-deny inbound ruleset with an allowlist of ports, checked by nft
itself before it loads, and enables the nftables.service the distribution
ships. Everything lives inside this role's own table, so podman's, libvirt's or
fail2ban's rules are left alone.
No download, and no version to pin. EL 10 packages nftables and ships
nftables.service, so the role installs it by name, writes the ruleset the unit
reads, and takes what the distribution gives: systemctl cat nftables shows the
distribution's unit, not one this role invented. What the role owns is the
ruleset and the proof that it drops what it says it drops.
The file deletes its own table before loading it. nft -f ADDS what it
reads: loading the same file twice appends every rule a second time, and an
edited file leaves the rules it no longer contains in the kernel. The two lines
at the top of /etc/sysconfig/nftables.conf make the loaded ruleset exactly
what the files say, and the live test counts the rules in the input chain to
prove it.
The live test needs CAP_NET_ADMIN. The container the lane boots does not
carry it, and without it the kernel refuses the very call this role exists to
make, so the test would pass having changed nothing. The lane is therefore run
as live-ansible.sh ... --cap-add=NET_ADMIN, and the receipt records it: a pass
under an added capability is not the same claim as a pass without one.
Loopback is accepted by source address, not by interface. iif lo accept is
the usual first rule and it is too wide: on a single machine, traffic to the
host's own external address also arrives on lo, so that rule accepts it and the
allowlist below is never consulted. Matching ip saddr 127.0.0.0/8 instead is
both the stronger rule - the ruleset also drops a spoofed loopback source
arriving from outside, and counts it - and what makes the drop testable from one
host.
policy is a reserved word in nft's grammar, so it cannot be a table name.
table inet policy does not parse, and a ruleset that never loaded reads much
like one with no rules.
License
Commercial - IaC Bazaar EULA. (c) IaC Bazaar.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Variables
- Test
Related modules
ansible-aide
AIDE from AppStream on EL 10: a watched tree, a baseline database built once, and the oneshot unit and timer the package does not ship. The live test passes on an unchanged host, FAILS when a file appears inside a watched path and names it, ignores one inside an excluded path, and passes again once the change is gone. Original role, live-tested on Rocky Linux 10.
ansible-authelia
Authelia from the upstream release (sha256-verified) as a hardened system service on loopback with file users and sqlite; its secrets are generated once on the host and reach the service as AUTHELIA_*_FILE variables. The live test hashes a password with Authelia's hasher, logs in, sees a wrong password refused and an anonymous visitor sent to the portal. Original role, live-tested on Rocky 10.
ansible-bandit
bandit on EL 10 from PyPI into a venv of its own with a link in the PATH; the live test runs pip check, then scans a module that passes a string to subprocess.call with shell=True (B602, High, exit 1) and a clean module (exit 0). Pinned. Original role, live-tested on Rocky Linux 10.
ansible-base-hardening
An SSH hardening drop-in sshd reads back: root login and password authentication off, MaxAuthTries 4, idle timeouts. A sysctl security profile under /etc/sysctl.d that a boot applies, and chrony installed with the distribution preset enabling it. The evidence is sshd's own effective configuration, read with sshd -T on Rocky Linux 10.
ansible-boundary
boundary on EL 10 from releases.hashicorp.com; SHA256SUMS is signature-checked against HashiCorp's key before get_url trusts it, the live test re-checks both, then runs authenticate against a dead address ('connection refused') and database init with a throwaway config (parsed, root key loaded, then the database refused). Pinned. Original role, live-tested on Rocky Linux 10.
ansible-dockle
dockle on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then scans a one-layer image whose config names no user, expecting CIS-DI-0001 in the output, exit code 1 with --exit-level warn, and the warning counted in the JSON form. Pinned. Original role, live-tested on Rocky Linux 10.