How an nftables ruleset is put together
nftables replaces the fixed tables and chains of iptables with ones you declare yourself. A table holds chains and sets for one address family; a base chain attaches to a netfilter hook and carries the policy applied when no rule matches. The generator writes one table with three base chains, all at priority 0, which is where the old filter table sat.
Inside a chain the rules are read top to bottom and the first terminal verdict wins, so the conntrack rules come first, your own rules follow, and the logging rule is last. A rule is a list of matches followed by a verdict: tcp dport { 80, 443 } ct state new accept matches new TCP connections to either port and accepts them.
A named set is declared once in the table and referenced as @name. Sets containing a CIDR block are declared with flags interval, which is what lets nftables store a prefix rather than a single address. Rule order matters within a chain but sets are unordered, so a set is the cheaper way to list many sources for one service.