Elektrine lite

← Feed

@danderson@hachyderm.io

Post #817483

2026-03-23 17:37 UTC

Today I'm finally learning about nftables in detail, and the result is that I'm quite sad. It comes very close to replicating the really useful, composable semantics of the Windows packet filter, but a couple blunders result in a system that ends up being _less_ expressive than classic iptables for common modern needs like "docker needs to have a few specific opinions about a few packets, in addition to global system policy".

Replies (0)

No replies.