It is the commonest home LAN range there is, so on an ordinary workstation the lab's private segment and the machine's own network are the same addresses. The scenario routes an egress machine explicitly and marks the rest unreachable, so nothing leaked — but that guard was carrying the whole weight of a collision nobody chose, and a guard is a bad place for that. 10.99.1.0/24 is still RFC 1918, so the bed still models a home LAN behind an access point. It is simply far from what this kind of machine already has: 192.168.1 is the LAN, 172.16-31 and 192.168.16-95 are container bridges, and 10.10/10.42/10.208 are a tunnel, the mesh overlay and the virtualisation daemon. Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
82 lines
2.0 KiB
YAML
82 lines
2.0 KiB
YAML
# One machine with a routable address, one publicly named but behind a household
|
|
# connection, one stationary machine on that network, one that roams.
|
|
#
|
|
# Three unrelated public networks, routed to each other and never bridged — putting them
|
|
# in one prefix would make ARP adjacency, non-decrementing TTL and crossing multicast
|
|
# true in the lab and false in production.
|
|
scenario: the-ordinary-shape
|
|
|
|
segments:
|
|
hosting:
|
|
kind: public
|
|
cidr: [192.0.2.0/24, "2001:db8:a::/48"]
|
|
|
|
isp-home:
|
|
kind: public
|
|
cidr: [198.51.100.0/24, "2001:db8:b::/48"]
|
|
|
|
isp-mobile:
|
|
kind: public
|
|
cidr: [203.0.113.0/24, "2001:db8:c::/48"]
|
|
|
|
home:
|
|
kind: private
|
|
cidr: [10.99.1.0/24, "2001:db8:b:1::/64"]
|
|
mtu: 1492
|
|
gateway:
|
|
to: isp-home
|
|
address: [198.51.100.7, "2001:db8:b::7"]
|
|
nat: [v4]
|
|
forwardable: true
|
|
mapping_ttl: 120s
|
|
|
|
devices:
|
|
kind: private
|
|
cidr: [192.168.30.0/24]
|
|
gateway:
|
|
to: isp-home
|
|
address: [198.51.100.7]
|
|
nat: [v4]
|
|
forwardable: true
|
|
mapping_ttl: 120s
|
|
|
|
cafe:
|
|
kind: private
|
|
cidr: [10.50.0.0/16]
|
|
mtu: 1400
|
|
gateway:
|
|
to: isp-mobile
|
|
address: [203.0.113.129]
|
|
nat: [v4]
|
|
forwardable: false
|
|
mapping_ttl: 30s
|
|
|
|
policy:
|
|
- { from: devices, to: home, allow: false }
|
|
- { from: home, to: devices, allow: true }
|
|
|
|
machines:
|
|
anchor:
|
|
at: { segment: hosting, address: [192.0.2.10, "2001:db8:a::10"] }
|
|
inbound: allow
|
|
|
|
home-server:
|
|
at: { segment: home, address: [10.99.1.135, "2001:db8:b:1::135"] }
|
|
published:
|
|
- { port: 443, on: home }
|
|
inbound: allow
|
|
|
|
workstation:
|
|
at: { segment: home, address: [10.99.1.250, "2001:db8:b:1::250"] }
|
|
inbound: deny
|
|
|
|
laptop:
|
|
at: { segment: home, address: [10.99.1.98, "2001:db8:b:1::98"] }
|
|
inbound: deny
|
|
|
|
# No `place:` yet. The node host it would place does not exist — this lab is being built to
|
|
# develop it, and the lab refuses declarations it cannot materialise rather than raising a
|
|
# mesh that silently lacks them.
|
|
|
|
snapshot: raised
|