diff --git a/docs/pfi/headscale-mesh-plan.md b/docs/pfi/headscale-mesh-plan.md index 0740f88..a8e2a71 100644 --- a/docs/pfi/headscale-mesh-plan.md +++ b/docs/pfi/headscale-mesh-plan.md @@ -208,3 +208,10 @@ edge, blackholing Matrix/gitea/chat for the whole ESH site (see services over the mesh (100.64/10 via ana-scale) rather than the public FortiGate VIP, that traffic never reaches CrowdSec — a concrete win beyond replacing the tunnels, worth weighing when prioritising the cut-over. + +### 06:35Z — ESH egress whitelisted in CrowdSec (operator-directed, temporary) + +`/opt/docker/conf/crowdsec/postoverflows/s01-whitelist/pfi-esh-egress.yaml` (bind mount, +persists) whitelists 23.164.40.160; SIGHUP reload, `crowdsec -t` clean, parser loaded. +TEMPORARY — remove when ESH gets its static IP. crowdsec stack is NOT in stacks/ canonical +(only stacks-mirror), so this lives on the host; re-mirror with sync-stacks.sh.