Elektrine lite

← Feed

@koen@procolix.social

Post #3456603

2026-06-28 21:48 UTC

@mathew@universeodon.com we switched most of our #Debian virtual machines to #nftables a few years ago. So now we have exemptions for several applications like virtual machines that use #docker since that uses #iptables and screws over our nftables config when you restart a container or the docker daemon. I think it will take years before nftables works with everything just like it is with ipv6.

Replies (1)

  • @grono@mastodon.com.pl 2026-06-28 22:27

    @koen@procolix.social FWIW in Docker there's an experimental nftables backend now: https://docs.docker.com/engine/network/firewall-nftables Give it a try!

    Open ##3456602