Closed dafydd2277 closed 3 years ago
I forgot to add/ask. If you're doing semantic versioning, I can make a fair argument that modifying the jump rules to only match local IP addresses is a feature add, making this pull request version 1.1.0. The code wasn't actually broken, I just needed to expand its capabilities.
@dafydd2277 , please fix linter issue and squash commits.
@dafydd2277 , LGTM 👍 Thank you for your contribution!
This solves Issue #12 .
1) Only jump to
cni-npr-<containerID>
if the destination address is on the local system.127.0.0.1
to thelo
interface blocks communication between the local system and the container network. Instead, explicitly prevent127.0.0.1
from appearing on any physical interface. Virtual interfaces are okay.