Need help creating a netifd compatible nebula package

So usually, the firewall reload is triggered by hotplug, specifically /etc/hotplug.d/iface/20-firewall

But I think the reason why it might not be working in your case is because your nebula interface is not part of any zone, so that the condition at line 8 causes the hotplug handler to bail out: