Parent
#24 — Spec: One typed seam through which all NAT state flows
What to build
The natmap daemon's apply-a-mapping logic is implemented once per rule kind. A shared ensure_docker_mapping primitive carries the allocate→install→persist→rollback step for port mappings, and an ensure_static_rule primitive does the same for static NAT rules (dnat/hairpin). The reload path, on_container_start, and the reconcile routines all call these primitives instead of re-implementing the step independently. The orchestrators stay — they differ in what set of rules they process — but the per-rule apply step exists once. Behavior is unchanged from the operator's perspective.
Acceptance criteria
Blocked by
None — can start immediately.
Parent
#24 — Spec: One typed seam through which all NAT state flows
What to build
The natmap daemon's apply-a-mapping logic is implemented once per rule kind. A shared
ensure_docker_mappingprimitive carries the allocate→install→persist→rollback step for port mappings, and anensure_static_ruleprimitive does the same for static NAT rules (dnat/hairpin). The reload path,on_container_start, and the reconcile routines all call these primitives instead of re-implementing the step independently. The orchestrators stay — they differ in what set of rules they process — but the per-rule apply step exists once. Behavior is unchanged from the operator's perspective.Acceptance criteria
ensure_docker_mappingandensure_static_ruleprimitives exist and are the single place the allocate→install→rollback step is implemented for their rule kindon_container_start, and the reconcile routines all route through the primitives; duplicated per-rule apply logic is removedBlocked by
None — can start immediately.