# THE HUB ADOPTS THE PREDECESSOR'S TUNNEL (novox/hq ADR 0105). See README.md beside this file. # # hosting (public) # anchor 192.0.2.10 the predecessor's hub: wg0 on udp/51900, 10.10.0.1/24, two peers; then the # mesh adopted on it, taking the tunnel over # peer-a 192.0.2.20 a predecessor machine reaching a service on the anchor over the tunnel; # enrols later and keeps 10.10.0.2 # peer-b 192.0.2.30 a predecessor machine that never enrols: must notice nothing, ever # fresh 192.0.2.40 a new machine: enrols later and gets 10.10.0.4 # # inbound: allow on every machine — the anchor's firewall is the predecessor's, installed by the bed. scenario: adopt-the-tunnel segments: hosting: kind: public cidr: [192.0.2.0/24] machines: anchor: at: { segment: hosting, address: [192.0.2.10] } egress: true inbound: allow memory: 12GiB cpus: 6 disk: 60GiB peer-a: at: { segment: hosting, address: [192.0.2.20] } egress: true inbound: allow memory: 3GiB cpus: 2 disk: 20GiB peer-b: at: { segment: hosting, address: [192.0.2.30] } egress: true inbound: allow memory: 2GiB cpus: 2 disk: 15GiB fresh: at: { segment: hosting, address: [192.0.2.40] } egress: true inbound: allow memory: 3GiB cpus: 2 disk: 20GiB place: all: [host, runtime]