boma/tests/integration
sjat 1042f161b6 test(integration): askari_inputonly — INPUT-only default-deny reboot gate
Adds the ADR-025 integration-test profile that proves the askari
mesh-hardening REDESIGN (INPUT-only default-deny, forward ACCEPT for Docker)
is reboot-safe on a throwaway KVM VM before the live cut-over.

Profile applies base (firewall + sshd) and offsite (docker_host +
reverse_proxy). Post-reboot verify checks: input policy drop, forward
policy accept, admin-addr break-glass SSH (192.168.150.1), Docker up,
and a published port answered from the controller. GREEN on 2026-06-19.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-06-19 19:14:55 +02:00
..
certs feat(integration): askari profile, stub overlay, cert-tier files 2026-06-18 12:37:32 +02:00
overrides test(integration): askari_inputonly — INPUT-only default-deny reboot gate 2026-06-19 19:14:55 +02:00
profiles test(integration): askari_inputonly — INPUT-only default-deny reboot gate 2026-06-19 19:14:55 +02:00
verify.yml test(integration): askari_inputonly — INPUT-only default-deny reboot gate 2026-06-19 19:14:55 +02:00