Scrub node
On-demand diversion: the controller announces the attacked /32 or /128 with this node as next-hop. XDP applies vector rules. Clean traffic returns over a VLAN or GRE.
Enroll
- On the operator dashboard, open Scrub nodes and create a one-time enrollment token.
- Install the package (
.deb,.rpm, static binary, systemd unit, or container). - In
/etc/templass/scrub.yaml, setenroll_token. - Start
templass-scrub. After enrollment the node keeps a per-node token. - Set up the clean-return VLAN or GRE, IP forwarding, and policy routing so diverted prefixes do not loop.
- Set the group's host mode to
scrub.
Operations
Drain or disable a node from the GUI. If the node stops reporting for about 15 seconds, the controller uses the group's fallback chain and logs it. After the node is healthy for the stability window (default 60 seconds, set on System), traffic returns to scrubbing, make-before-break.
The node reports drop and pass rates.
Host and driver list: Requirements.