boma/inventories/production
sjat 3b30e70ba5 feat(firewall): public zone + askari's public services in the catalog
Adds a public (0.0.0.0/0) zone and askari's Caddy (80/443) + NetBird STUN
(3478/udp) ingress so the base nftables default-deny does not drop the live
public services when applied to askari. Molecule + filter unit test cover the
public-zone rendering. Mesh-hardening 1/3 (ADR-020/024/016).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-17 20:46:03 +02:00
..
group_vars feat(firewall): public zone + askari's public services in the catalog 2026-06-17 20:46:03 +02:00
hosts.yml inventory: add ubongo to control group; set ssh-from-control addr 2026-06-11 10:32:24 +02:00
offsite.yml feat(tf): provision askari — cx23/hel1 (CAX11 ARM was out of stock) 2026-06-14 16:23:01 +02:00