Found 2026-09-20, building phoenix (#436)
build-the-jumpbox.md §4 writes ADR-0043's one line — IN ACCEPT -source 10.0.30.70 -p tcp -dport 8006 — beneath ADR-0014's three in Saruman's host.fw. There is no such file. On Saruman:
pve-firewall status → Status: disabled/running
/etc/pve/firewall/cluster.fw → does not exist
/etc/pve/nodes/*/host.fw → does not exist
and from morpheus (10.0.30.1, not on 10.0.50.0/24), nc -z 10.0.30.110 8006 and 22 both connect. ADR-0014's management-plane rule — 8006, 8007 and 22 from Hicks only — was decided in 2026-09 and is applied by build-the-playground.md §4, which is gated on #101 and has not run. Nothing in SECURITY.md, network.md or architecture.md claimed it was on; ADR-0043 did ("today nothing on VLAN 30 is admitted"), and #544 corrects that with a marked note.
Also found: the Proxmox node is Saruman, capitalised, as pvesh get /nodes prints it. The runbook said lower-case, so its /nodes/saruman ACL, host.fw path and API URL were wrong; #544 fixes all three.
What this means today
Every address on VLAN 30 — and anything routed to it — reaches the hypervisor's login surface. The token is the control and the rule was only ever the door, as ADR-0043 says, but the door is recorded in two ADRs as if it stood. It does not. phoenix was built without writing the line, per the runbook's CAUTION: a DROP input policy with the rules unrendered locks the console out of a machine whose console is a KVM switch away, and that is not a side effect to take while building a guest.
Done when
build-the-playground.md §4 has been run on Saruman with the console to hand — cluster.fw with policy_in: DROP, /etc/pve/nodes/Saruman/host.fw with ADR-0014's three rules and ADR-0043's fourth, firewall=0 on every guest NIC (140 and 170 today) — and:
Not gated on #101: the range's other constraints are, but the estate's own hypervisor closing its management plane needs no attack VM to exist first.
Refs #436, ADR-0014, ADR-0039, ADR-0043.
Found 2026-09-20, building
phoenix(#436)build-the-jumpbox.md§4 writes ADR-0043's one line —IN ACCEPT -source 10.0.30.70 -p tcp -dport 8006— beneath ADR-0014's three inSaruman'shost.fw. There is no such file. OnSaruman:and from
morpheus(10.0.30.1, not on10.0.50.0/24),nc -z 10.0.30.110 8006and22both connect. ADR-0014's management-plane rule —8006,8007and22from Hicks only — was decided in 2026-09 and is applied bybuild-the-playground.md§4, which is gated on #101 and has not run. Nothing inSECURITY.md,network.mdorarchitecture.mdclaimed it was on; ADR-0043 did ("today nothing on VLAN 30 is admitted"), and #544 corrects that with a marked note.Also found: the Proxmox node is
Saruman, capitalised, aspvesh get /nodesprints it. The runbook said lower-case, so its/nodes/sarumanACL,host.fwpath and API URL were wrong; #544 fixes all three.What this means today
Every address on VLAN 30 — and anything routed to it — reaches the hypervisor's login surface. The token is the control and the rule was only ever the door, as ADR-0043 says, but the door is recorded in two ADRs as if it stood. It does not.
phoenixwas built without writing the line, per the runbook's CAUTION: aDROPinput policy with the rules unrendered locks the console out of a machine whose console is a KVM switch away, and that is not a side effect to take while building a guest.Done when
build-the-playground.md§4 has been run onSarumanwith the console to hand —cluster.fwwithpolicy_in: DROP,/etc/pve/nodes/Saruman/host.fwwith ADR-0014's three rules and ADR-0043's fourth,firewall=0on every guest NIC (140 and 170 today) — and:pve-firewall statussaysenabled/running;phoenix, the §4curlinbuild-the-jumpbox.mdstill returns the guest list;morpheus,nc -z -w 3 10.0.30.110 8006is refused;Saruman's Alloy still remote-writes to10.0.99.20(outbound is unaffected bypolicy_in, but checkup{instance="saruman"}after);network.mdandarchitecture.mdthat docs: phoenix is built at 10.0.30.70 on Saruman, the lab has its first off-host client, and Saruman admits it to 8006 (#436) #544 rewrote to say "decided, not applied" are rewritten again to say applied, with the date.Not gated on #101: the range's other constraints are, but the estate's own hypervisor closing its management plane needs no attack VM to exist first.
Refs #436, ADR-0014, ADR-0039, ADR-0043.