Close RAIL-HO-WP-0009 declared-state gaps; leave live 6443 prune gated
Make the k3s API tunnel-only (ADR-005), stop declaring Flannel VXLAN open to Anywhere, tag the base role so firewall can be scoped, and schedule the Goss declared-vs-live check. CoulombCore sets ufw_manage false so a converge cannot enable UFW there. T02 still needs operator approval for make converge-firewall HOST=Railiance01.
This commit is contained in:
parent
434121be99
commit
4d9e77c968
29 changed files with 793 additions and 99 deletions
|
|
@ -1,6 +1,12 @@
|
|||
# Host-specific variables for CoulombCore (92.205.130.254)
|
||||
# k3s single-node cluster host — HostEurope
|
||||
|
||||
# Do not enable or rewrite UFW on this host. Live filter is iptables INPUT
|
||||
# DROP with a Plesk-era accept list (UFW status: inactive). Enabling UFW
|
||||
# here would take down 80/443 and the rest of the accepted surface unless
|
||||
# every live accept is declared first. RAIL-HO-WP-0009-T03.
|
||||
ufw_manage: false
|
||||
|
||||
# Swapfile (T01)
|
||||
swap_size_gb: 4
|
||||
swap_swappiness: 10
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue