@@ -25,8 +25,7 @@ accept_dst_port $CHAIN_ALWAYS_IN tcp $SSH_CONTROL_PORT "SSH control port"
2525accept_dst_port $CHAIN_ALWAYS_IN udp $SEARCHER_INPUT_PORT "Searcher input channel"
2626
2727# We drive op-geth in the searcher container from external op-node
28- # TODO: parametrize op-node IP range
29- accept_src_ip_dst_port $CHAIN_ALWAYS_IN tcp "10.0.0.0/8" $ENGINE_API_PORT "Engine API"
28+ accept_src_ip_dst_port $CHAIN_ALWAYS_IN tcp "$METADATA_BOB_L2_OP_NODE_CIDR" $ENGINE_API_PORT "Engine API"
3029
3130# CVM reverse-proxy serves server attestation
3231# Also forwards request to ssh pubkey server on localhost:5001,
@@ -41,7 +40,7 @@ accept_dst_port $CHAIN_ALWAYS_IN tcp $CVM_REVERSE_PROXY_PORT "CVM reverse-proxy"
4140# See also init-container.sh
4241accept_dst_port $CHAIN_ALWAYS_OUT udp $NTP_PORT "NTP"
4342
44- # TODO: simulator bundle endpoint will be here, parameterized
43+ accept_dst_ip_port $CHAIN_ALWAYS_OUT tcp "$METADATA_BOB_L2_BACKRUNS_IP" $HTTP_PORT "bundle"
4544
4645###########################################################################
4746# (3) MAINTENANCE_IN: Inbound rules for Maintenance Mode
@@ -57,6 +56,9 @@ accept_dst_port $CHAIN_MAINTENANCE_IN udp $OP_GETH_P2P_PORT "op-geth P2P (UDP)"
5756# (4) MAINTENANCE_OUT: Outbound rules for Maintenance Mode
5857###########################################################################
5958
59+ # Block tx endpoint during maintenance
60+ drop_dst_ip $CHAIN_MAINTENANCE_OUT "$METADATA_BOB_L2_TX_STREAM_IP" "tx stream (DROP before accept-all rules)"
61+
6062accept_dst_port $CHAIN_MAINTENANCE_OUT udp $DNS_PORT "DNS (UDP)"
6163accept_dst_port $CHAIN_MAINTENANCE_OUT tcp $DNS_PORT "DNS (TCP)"
6264
@@ -76,6 +78,4 @@ accept_dst_port $CHAIN_MAINTENANCE_OUT udp $OP_GETH_P2P_PORT "op-geth P2P (UDP)"
7678# (6) PRODUCTION_OUT: Outbound rules for Production Mode
7779###########################################################################
7880
79- # None at the moment
80-
81- # TODO: simulator tx stream websocket will be here, parameterized
81+ accept_dst_ip_port $CHAIN_PRODUCTION_OUT tcp "$METADATA_BOB_L2_TX_STREAM_IP" $HTTP_PORT "tx stream"
0 commit comments