Adds a public (0.0.0.0/0) zone and askari's Caddy (80/443) + NetBird STUN (3478/udp) ingress so the base nftables default-deny does not drop the live public services when applied to askari. Molecule + filter unit test cover the public-zone rendering. Mesh-hardening 1/3 (ADR-020/024/016). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| tags.yml | ||
| test_capacity_scan.py | ||
| test_check_tags.py | ||
| test_firewall_rules.py | ||
| test_friction_scan.py | ||
| test_public_dns.py | ||
| test_repo_scan.py | ||
| test_tf_to_inventory.py | ||