Skip to content

Examples

segmented

Three networks and a router: the user lands on access, may reach the web server on front, and nothing on back; only front may reach the cache, and only on 6379.

Tested: Runs in CI on Docker with its checks, and was run on VirtualBox.

version: 1
name: segmented

networks:
  front:  { cidr: 10.61.10.0/24 }
  back:   { cidr: 10.61.20.0/24, internet: false }
  access: { cidr: 10.61.99.0/24 }

reach:
  - { from: access, to: front }
  - { from: front, to: back, ports: [6379] }

machines:
  cache:
    networks: { back: 20 }
    services: [{ port: 6379, name: redis }]
    resources: { cpus: 1, memory_mb: 1024, disk_gb: 10 }
    volumes: { data: /data }
    docker:
      image: "redis:7-alpine"
    vm:
      os: debian-12
      provision: [provision/cache.sh]

  web:
    networks: { front: 10 }
    services: [{ port: 80, http: true }]
    depends_on: [cache]
    docker:
      build: build/web
    vm:
      os: debian-12
      provision: [provision/web.sh]

  user:
    access: true
    networks: { access: 10 }
    vm:
      os: debian-12

checks:
  - checks/web-reachable.sh
  - checks/cache-blocked.sh

Targets

docker, hosted, cloud-docker, vagrant, proxmox, cloud-vm. See Targets for what each means.

Checks

  • checks/web-reachable.sh
  • checks/cache-blocked.sh

See Checks.