docs(capabilities): note two-layer firewall model (ADR-020)

This commit is contained in:
sjat 2026-06-06 16:00:19 +02:00
parent a9287427e3
commit 2ad50e4d5b

View file

@ -31,6 +31,10 @@ decisions this frame enables.
_(DHCP, firewall, mDNS reflection live on OPNsense — Ansible-managed, not containers.)_
_Firewalling is two-layer (ADR-020): OPNsense at the perimeter + inter-VLAN, plus
per-host `nftables` (default-deny inbound + east-west allowlist) rendered by the `base`
role from a shared `group_vars` service catalog. Both layers are still to be built._
## 2. Identity & access — [P]
| Capability | Candidate service(s) | Tier | Commitment | What it does | Notes / open |