The home segment moves off 192.168.1.0/24

It is the commonest home LAN range there is, so on an ordinary workstation the
lab's private segment and the machine's own network are the same addresses. The
scenario routes an egress machine explicitly and marks the rest unreachable, so
nothing leaked — but that guard was carrying the whole weight of a collision
nobody chose, and a guard is a bad place for that.

10.99.1.0/24 is still RFC 1918, so the bed still models a home LAN behind an
access point. It is simply far from what this kind of machine already has:
192.168.1 is the LAN, 172.16-31 and 192.168.16-95 are container bridges, and
10.10/10.42/10.208 are a tunnel, the mesh overlay and the virtualisation daemon.

Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
This commit is contained in:
2026-09-11 00:00:19 +02:00
parent a4c2a9b90b
commit 94e617915c
12 changed files with 48 additions and 48 deletions
+2 -2
View File
@@ -11,7 +11,7 @@ segments:
home:
kind: private
cidr: [192.168.1.0/24]
cidr: [10.99.1.0/24]
gateway:
to: hosting
address: [192.0.2.50] # what the world sees the household as
@@ -25,7 +25,7 @@ machines:
inbound: allow
home-server: # a dash in the name, on purpose
at: { segment: home, address: [192.168.1.135] }
at: { segment: home, address: [10.99.1.135] }
published:
- { port: 8080, on: home }
inbound: allow
+2 -2
View File
@@ -15,7 +15,7 @@ segments:
home:
kind: private
cidr: [192.168.1.0/24]
cidr: [10.99.1.0/24]
gateway:
to: hosting
address: [192.0.2.50]
@@ -53,7 +53,7 @@ machines:
inbound: allow
home-server:
at: { segment: home, address: [192.168.1.135] }
at: { segment: home, address: [10.99.1.135] }
inbound: allow
thermostat:
+4 -4
View File
@@ -21,7 +21,7 @@ segments:
home:
kind: private
cidr: [192.168.1.0/24, "2001:db8:b:1::/64"]
cidr: [10.99.1.0/24, "2001:db8:b:1::/64"]
mtu: 1492
gateway:
to: isp-home
@@ -61,17 +61,17 @@ machines:
inbound: allow
home-server:
at: { segment: home, address: [192.168.1.135, "2001:db8:b:1::135"] }
at: { segment: home, address: [10.99.1.135, "2001:db8:b:1::135"] }
published:
- { port: 443, on: home }
inbound: allow
workstation:
at: { segment: home, address: [192.168.1.250, "2001:db8:b:1::250"] }
at: { segment: home, address: [10.99.1.250, "2001:db8:b:1::250"] }
inbound: deny
laptop:
at: { segment: home, address: [192.168.1.98, "2001:db8:b:1::98"] }
at: { segment: home, address: [10.99.1.98, "2001:db8:b:1::98"] }
inbound: deny
# No `place:` yet. The node host it would place does not exist — this lab is being built to
+7 -7
View File
@@ -8,9 +8,9 @@
# — the access point — reachable from the outside only through what they dial out to.
#
# hosting (public, routable) home (private, behind the access point)
# novox 192.0.2.20 ── anchor ace 192.168.1.10 home server, media/IoT set
# substrate + novox set shanks 192.168.1.20 workstation (light)
# overlay hub, ingress g14 192.168.1.30 workstation (light)
# novox 192.0.2.20 ── anchor ace 10.99.1.10 home server, media/IoT set
# substrate + novox set shanks 10.99.1.20 workstation (light)
# overlay hub, ingress g14 10.99.1.30 workstation (light)
#
# The `home` gateway masquerades v4 outbound and forwards inbound (an ordinary household router).
# Home nodes reach novox's public 192.0.2.20 by dialling OUT through it: the substrate broker (5671),
@@ -58,7 +58,7 @@ segments:
# is exactly the NAT hole a WireGuard keepalive has to hold open.
home:
kind: private
cidr: [192.168.1.0/24]
cidr: [10.99.1.0/24]
gateway:
to: hosting
address: [192.0.2.50] # what the world sees the household as
@@ -100,7 +100,7 @@ machines:
# The home server: the whole ace media/home set — 24 modules, ~50 containers, several heavy
# (Plex, Home Assistant, Letta, Baserow, the UniFi JVM, mssql). Behind the gateway.
ace:
at: { segment: home, address: [192.168.1.10] }
at: { segment: home, address: [10.99.1.10] }
egress: true
inbound: allow
memory: 18GiB
@@ -140,7 +140,7 @@ machines:
# nodes with no overlay endpoint of their own hairpin the hub rather than peering directly, which
# is the normal case and is fine.
shanks:
at: { segment: home, address: [192.168.1.20] }
at: { segment: home, address: [10.99.1.20] }
egress: true
inbound: allow
memory: 3GiB
@@ -151,7 +151,7 @@ machines:
# everywhere" was never a description of anything real.
images: [mesh-runtime-portainer:development]
g14:
at: { segment: home, address: [192.168.1.30] }
at: { segment: home, address: [10.99.1.30] }
egress: true
inbound: allow
memory: 3GiB