Skip to main content

Dataplane observe + control pack

Implemented via policy_control (Rust) / policyControls (TS) — not a separate policy_engine module.

FeatureSurface
Open / Audit / Guard / Invert / Block / AllowPolicy tab + fabricctl dataplane policy …
Explain dest:portPolicy tab + fabricctl dataplane explain
Dry-run GuardPolicy tab + fabricctl dataplane dry-run
Templatesopen, guard, web, dns-only, no-world
Block from flow rowVM Dataplane → Flows
Drop reasonsPOLICY_DENIED, DEFAULT_DENY, PORT_DENIED, AUDIT_WOULD_DROP
fabricctl dataplane policy guard web-1
fabricctl dataplane explain web-1 1.1.1.1 --port 443 --proto tcp
fabricctl dataplane dry-run web-1
python3 scripts/test-policy-engine.py

See also: user dataplane, fluxvm-dataplane.