IP Aliases & Address Groups

Name groups of source IP addresses, reference them in readable firewall commands and maintain membership as your network changes.

Based on the supplied One-Click Rule Engine source · Verify behaviour on your installed revision

What IP aliases do

Rather than repeatedly typing each trusted workstation, VPN gateway or office egress address into rules, you can give the addresses a memorable name such as office. When the Rule Engine encounters from office, its parser looks up the associated source addresses and expands them into the commands it generates.

These are source-address aliases, distinct from the built-in service/port aliases. For example, allow nginx maps to the predefined nginx ports, while from office selects addresses that you define yourself. An alias is a convenience for authoring rules, not a firewall-backed dynamic IP set.

Create a named IP group

Use alias-create with a short group name and space-separated IP addresses. The supplied parser's creation pattern expects at least two addresses, so the initial example includes two.

one-click engine 'alias-create office 192.0.2.10 198.51.100.20'

These are documentation-only TEST-NET addresses, not addresses to copy into production. A group name may contain lowercase letters, digits, underscores or hyphens. The existing implementation stores the alias as a comma-separated list. If the name exists, the original workflow offers an interactive replacement confirmation rather than silently overwriting it.

Check address accuracy first

Keep aliases limited to verified hosts or networks you control. The legacy parser's address input and duplicate handling are version-dependent; review the resulting group before using it in access rules.

Append, prune and inspect

Add new source addresses to an existing alias without rewriting the entire definition, then remove individual addresses when access is no longer appropriate.

# Add one new office egress address
one-click engine 'alias-append office 203.0.113.8'

# Show every group and its address members
one-click engine 'list aliases'

# Remove one member (one IP per prune command)
one-click engine 'alias-prune office 203.0.113.8'

# Inspect the resulting group again
one-click engine 'show aliases'

alias-append requires an existing group. alias-prune accepts one address at a time in the parser version inspected. When the final member is removed, the helper may remove the empty group. A separate interactive delete alias operation removes a whole named group; it is not equivalent to pruning one address.

Use an alias in a firewall rule

Use the alias after from to scope a rule to its listed source addresses. For example, you might author an HTTPS allowance for a known office IP group:

one-click engine --dry-run 'allow tcp 443 from office'

The expansion happens when the Rule Engine parses the input. Inspect the individual generated commands and run the existing isolated namespace checks before approving a production change. If the installed backend or parser cannot safely represent the requested address expansion, do not bypass that check with a broad rule.

Membership changes are not retroactive

Adding an IP to an alias does not necessarily change firewall rules already installed. Aliases are resolved during rule generation, not maintained as an automatically synchronised kernel address set. Review and deliberately update existing live rules when membership changes.

IP aliases versus service aliases

allow nginxBuilt-in service alias expands to the configured TCP ports (typically 80 and 443).
from officeAdministrator-managed source alias expands to one or more stored IP addresses.
sensitive:443Marks a port sensitive for additional warnings; does not create an IP alias or firewall rule.

These concepts can be combined in commands, but they must not be mistaken for the same configuration layer. See Sensitive Ports & Warnings for the separate confirmation policy.

Storage and lifecycle

The supplied implementation keeps the address mappings in /etc/one-click/rule-engine/.alias.conf, using entries of the form office=192.0.2.10,198.51.100.20. Treat this as administrative configuration, keep backup copies under normal host-recovery procedures, and restrict write access. Use list aliases to inspect definitions rather than editing them casually while operating the firewall.

In an offboarding workflow, prune the departed organisation's addresses, then separately inspect and update the active firewall rules that were created from the old definition. Alias pruning alone is not a reliable revocation operation.

Troubleshooting

Alias does not existCreate it first with alias-create, then retry alias-append.
Unknown host/aliasCheck spelling and confirm the group exists with list aliases.
Alias updated but live access unchangedInspect live rules. Refresh the affected rules through the normal guarded workflow; the alias file is not a live IP set.
Alias-create accepts unexpected inputConfirm the installed version; the inspected source uses different matching expressions for create, append and prune.

For rule approval, namespace verification and rollback limitations, continue with the Rule Engine guide. Use the firewall command reference for related command syntax.