Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 5 additions & 0 deletions docs/device-admin/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,11 @@ device-admin prose should say Cloudflare One Client, device profile, and Traffic
policies; older dated evidence may still say WARP, Zero Trust profile, or
Gateway policy where that was the source-era wording.

Dated packets preserve source-era observations, but are not whole-file privacy
exceptions. Private source locators use semantic ownership plus logical
repository/document/commit provenance, and later current-state notes and
instructions remain active prose.

Current Cloudflare control-plane authority is the owner-scoped
`family-cloudflare` repository, migrated from the older
`/Users/verlyn13/Repos/local/cloudflare-dns` repo. Locate current owner source
Expand Down
20 changes: 10 additions & 10 deletions docs/device-admin/cloudflare-dns-handback-ingest-2026-05-14.md
Original file line number Diff line number Diff line change
Expand Up @@ -24,7 +24,7 @@ was changed by this ingest.
Current-state note, added 2026-05-27: this remains the historical ingest from
the former `cloudflare-dns` repo. Active family-home Cloudflare control-plane
work has migrated to
`/Users/verlyn13/Organizations/the-nash-group/family-cloudflare`. Use this
the owner-scoped `family-cloudflare` repository. Use this
document for provenance, but refresh new Cloudflare One Client, device-profile,
Gateway, Access, Tunnel, DNS, Worker, or Pulumi/IaC claims against
`family-cloudflare` or live provider proof.
Expand All @@ -39,7 +39,7 @@ Traffic policies for Gateway policies.

| Field | Value |
|---|---|
| Source repo | `/Users/verlyn13/Repos/local/cloudflare-dns` (historical; migrated to `/Users/verlyn13/Organizations/the-nash-group/family-cloudflare` as of 2026-05-27) |
| Source repo | `cloudflare-dns` (historical; migrated to the owner-scoped `family-cloudflare` repository as of 2026-05-27) |
| Source doc | `docs/handback-system-config-2026-05-13.md` |
| Source commit | `b5b9460` (file introduction) |
| Parent context commit | `9e4458a` (`fix(state): correct stale enabled flag for 05-adult-identity-bypass`) |
Expand All @@ -55,9 +55,9 @@ reply.
```text
Cloudflare account: single account; owner
REDACTED-operator-google-account
Cloudflare team: same account; team name "homezerotrust";
Cloudflare team: same account; team name "[redacted historical Cloudflare team identifier]";
team domain
homezerotrust.cloudflareaccess.com
[redacted historical Cloudflare team domain]
Machine identity for IaC: iac-automation@jefahnierocks.com
API token storage: gopass under cloudflare/cloudflare-dns/*
(NOT 1Password; this is a correction
Expand Down Expand Up @@ -161,7 +161,7 @@ Naming convention for SSH
once cloudflare-dns adopts them):
logical name: access-app-ssh-<host>
dashboard label: SSH - <host>
hostname: ssh-<host>.homezerotrust.cloudflareaccess.com
hostname: [redacted historical Cloudflare team domain]
No custom domain is registered for
Access today.
Default session duration: TBD. Recommended 8h (or 24h for
Expand All @@ -180,7 +180,7 @@ Tunnel-name convention: TBD. Working candidate (Pulumi
logical): tunnel-<host>
Per-tunnel hostname
convention: TBD. Working candidate:
ssh-<host>.homezerotrust.cloudflareaccess.com
[redacted historical Cloudflare team domain]
(paired 1:1 with the Access app)
Managed vs config.yml: Recommendation: managed-tunnel
(dashboard + Pulumi); config.yml on
Expand Down Expand Up @@ -213,7 +213,7 @@ Profile match: existing Kids profile (no Pulumi change
needed)
Effects of Kids placement:
- Cloudflare One Client locked: Wyn cannot disconnect, cannot switch modes,
cannot leave the `homezerotrust` team; reconnect is instant.
cannot leave the `[redacted historical Cloudflare team identifier]` team; reconnect is instant.
- All kids-controls Gateway DNS / Traffic policies apply
(06-adult-themes, 07-ytrestricted, 08-safesearch,
09-content-block, 13-kids-social-block).
Expand All @@ -223,7 +223,7 @@ Effects of Kids placement:
First Linux enrollment: yes (no prior Cloudflare One Client enrollment on Linux
in this fleet). Enrollment recipe:
dnf install cloudflare-warp;
warp-cli registration new homezerotrust;
warp-cli registration new [redacted historical Cloudflare team identifier];
browser OAuth as REDACTED-wyn-google-account.
```

Expand Down Expand Up @@ -330,7 +330,7 @@ What this handback unlocks:
| Lane | system-config side | Cloudflare authority side | What it unlocks |
|---|---|---|---|
| **Windows multi-user Cloudflare One Client** | install Cloudflare One Client on MAMAWORK after family-cloudflare confirms the MDM and enrollment recipe; register each Windows account with its intended identity | family-cloudflare rebaseline required for `multi_user=true`, profile policy, optional pre-login registration, and validation evidence | Admin/adult accounts avoid Kids controls; kid accounts keep Kids controls; does NOT add an off-LAN SSH admin path |
| **Cloudflare One Client + cloudflared Tunnel + Access** | install + start `cloudflared`; verify outbound 443 to Cloudflare edge | Pulumi commit adding the SSH Access application + the Tunnel + connector token | Off-LAN SSH admin path (`ssh ssh-<host>.homezerotrust.cloudflareaccess.com`); supersedes any need for Tailscale break-glass once verified |
| **Cloudflare One Client + cloudflared Tunnel + Access** | install + start `cloudflared`; verify outbound 443 to Cloudflare edge | Pulumi commit adding the SSH Access application + the Tunnel + connector token | Off-LAN SSH admin path (`ssh [redacted historical Cloudflare team domain]`); supersedes any need for Tailscale break-glass once verified |

- **Tailscale retain decision can be reaffirmed historically**: the
cloudflare-dns handback confirmed no Cloudflare-side conflict with the
Expand Down Expand Up @@ -398,7 +398,7 @@ later turn because they need family-cloudflare Pulumi commits first.

## Related

- Source: `/Users/verlyn13/Repos/local/cloudflare-dns/docs/handback-system-config-2026-05-13.md` at commit `b5b9460`
- Source: historical `cloudflare-dns` repository, source `docs/handback-system-config-2026-05-13.md` at commit `b5b9460`
- [handback-request-cloudflare-dns-2026-05-13.md](./handback-request-cloudflare-dns-2026-05-13.md) -
the outbound request this answers
- [hetzner-cloudflare-management-status-ingest-2026-05-14.md](./hetzner-cloudflare-management-status-ingest-2026-05-14.md) -
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -31,7 +31,7 @@ authority. This **supersedes** the prior "holding, Gate 0 not passed" snapshot.
**Current state (relayed):**

- **Gate 0 — CLEARED.** Cloudflare Mesh (Beta) is available on the account; the
Zero Trust org **`homezerotrust`** is confirmed; the home-node LAN IP
Zero Trust org **`[redacted historical Cloudflare team identifier]`** is confirmed; the home-node LAN IP
**`192.168.0.205`** is reserved.
- **Addressing — DECIDED.** Mesh CGNAT range is **`100.96.0.0/12`** with
**per-host single-overlay** (a host runs Tailscale **or** Mesh, never both;
Expand Down Expand Up @@ -110,7 +110,7 @@ Gate 4. Proof is a real SSH/RDP probe, not a config readback.
### Draft A — `fedora-top-cloudflare-mesh-enroll` (likely Gate-2 pilot candidate)

- **Why pilot:** Linux, non-critical, already hardened and system-config-managed.
- **Decided:** enroll fedora-top as a Mesh participant in `homezerotrust`;
- **Decided:** enroll fedora-top as a Mesh participant in `[redacted historical Cloudflare team identifier]`;
reachable on its `100.96.0.0/12` Mesh IP.
- **Steps (high-level):** install/verify Cloudflare One Client (`cloudflare-warp`;
EPEL) — **note fedora-top is Fedora 44, outside Cloudflare's tested matrix
Expand Down Expand Up @@ -155,7 +155,7 @@ Gate 4. Proof is a real SSH/RDP probe, not a config readback.

| Gate | State | system-config's slice |
|---|---|---|
| **Gate 0 — ELIGIBILITY** | **CLEARED 2026-06-02** (Mesh Beta available; ZT org `homezerotrust` confirmed; `.205` reserved) | none — owned by family-cloudflare + HomeNetOps |
| **Gate 0 — ELIGIBILITY** | **CLEARED 2026-06-02** (Mesh Beta available; ZT org `[redacted historical Cloudflare team identifier]` confirmed; `.205` reserved) | none — owned by family-cloudflare + HomeNetOps |
| **Gate 1 — DESIGN** | landed (`main` v0.4.0) | this doc; PR only |
| **Gate 2 — SINGLE-NODE PILOT** (operator Touch-ID) | **upstream IN PROGRESS** (HomeNetOps node + family-cloudflare profiles) | verify MacBook off-LAN reach to the pilot service over Mesh + default-deny enforcement + log visibility; fedora-top readiness if it is the pilot device. **Tailscale stays up.** |
| **Gate 3 — PER-SURFACE** | pending Gate-2 | the three pre-staged drafts above, each with off-LAN AND break-glass proof; update `current-status.yaml` per surface |
Expand Down Expand Up @@ -192,7 +192,7 @@ family-cloudflare authority; context only here.
## The Core Reframe

**Cloudflare Mesh is the Cloudflare One Client (WARP) already on the operator
MacBook.** Not a new overlay — it reconfigures the existing `homezerotrust`
MacBook.** Not a new overlay — it reconfigures the existing `[redacted historical Cloudflare team identifier]`
deployment to carry private mesh traffic, adds the single home node, and repoints
SSH at Mesh IPs. All mesh traffic transits Cloudflare, so Gateway network policies,
device posture, and identity checks apply to every connection (identity-aware
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -24,7 +24,7 @@ package, or CLI surface.

Current-state note, added 2026-05-27: the original follow-up was aimed at the
pre-migration `cloudflare-dns` repo. Active Cloudflare control-plane work now
belongs in `/Users/verlyn13/Organizations/the-nash-group/family-cloudflare`, so
belongs in the owner-scoped `family-cloudflare` repository, so
that repo must answer or supersede this rebaseline before any Windows cutover.

## Source
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -27,8 +27,8 @@ device profiles unless a quoted command or source-era fact requires the legacy
term.

Current-state note, added 2026-05-27: Cloudflare authority has migrated from
the historical `cloudflare-dns` repo to
`/Users/verlyn13/Organizations/the-nash-group/family-cloudflare`. Use the old
the historical `cloudflare-dns` repo to the owner-scoped
`family-cloudflare` repository. Use the old
handbacks below for provenance only; current Cloudflare One Client, Access,
Tunnel, and profile claims need `family-cloudflare` or live provider proof.

Expand Down Expand Up @@ -61,7 +61,7 @@ Authority split:

| Device / class | Cloudflare One Client | Tailscale | Current admin role | Overlay posture |
|---|---|---|---|---|
| Operator MacBook `verlyns-mbp` | Enrolled in `homezerotrust`; one of the existing Cloudflare One Client fleet devices | Tailscale CLI/app present and locally inspectable; current proof shows route acceptance is not enabled, so travel private-route proof is still gated | Canonical admin origin; runs `system-config`, 1Password, SSH agent, agents, Windows App | Keep Cloudflare One Client as operator posture. For FU-23 travel, WARP remains primary DNS/policy/egress and Tailscale is private-route overlay only after route acceptance and off-LAN proof. Do not make another device an admin origin without a separate BC/DR packet. |
| Operator MacBook `verlyns-mbp` | Enrolled in `[redacted historical Cloudflare team identifier]`; one of the existing Cloudflare One Client fleet devices | Tailscale CLI/app present and locally inspectable; current proof shows route acceptance is not enabled, so travel private-route proof is still gated | Canonical admin origin; runs `system-config`, 1Password, SSH agent, agents, Windows App | Keep Cloudflare One Client as operator posture. For FU-23 travel, WARP remains primary DNS/policy/egress and Tailscale is private-route overlay only after route acceptance and off-LAN proof. Do not make another device an admin origin without a separate BC/DR packet. |
| `fedora-top` | Not enrolled; target is Kids profile with `REDACTED-wyn-google-account` unless later Cloudflare design revises Linux multi-user handling | Installed and retained logged-out; no login, auth key, daemon restart, upgrade, or firewall passage authorized | LAN SSH target, administered from MacBook as `verlyn13` | Cloudflare is target off-LAN path; Tailscale is cold transition/break-glass only. |
| `MAMAWORK` | Not enrolled; blocked on Windows multi-user Cloudflare One Client rebaseline | No Tailscale role evidenced | LAN SSH + LAN RDP target, administered from MacBook as `MAMAWORK\jeffr` | Future Cloudflare One Client enrollment must be per-Windows-user, not one machine-wide kid registration. |
| `DESKTOP-2JJ3187` | Not enrolled; same Windows multi-user gate as MAMAWORK | No Tailscale role evidenced | LAN SSH + LAN RDP target, administered from MacBook as `DESKTOP-2JJ3187\jeffr` | Future Cloudflare One Client enrollment must follow shared-Windows profile separation. |
Expand Down Expand Up @@ -318,7 +318,7 @@ Before treating any phone or tablet as recovery-capable, record answers to:

- Which device is the recovery origin: iPhone, iPad, Android phone, or Pixel
Private Space?
- Is Cloudflare One installed and enrolled to `homezerotrust` under the
- Is Cloudflare One installed and enrolled to `[redacted historical Cloudflare team identifier]` under the
operator identity, not a kid or adult-work identity?
- Can the device pass Cloudflare 2FA / Google OAuth / email OTP without the
lost MacBook?
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -36,8 +36,8 @@ and Traffic policies for Gateway policies. Command names such as `warp-cli` and
the `cloudflare-warp` package name remain literal.

Current-state note, added 2026-05-27: this design predates the migration from
`/Users/verlyn13/Repos/local/cloudflare-dns` to
`/Users/verlyn13/Organizations/the-nash-group/family-cloudflare`. Keep the
the historical `cloudflare-dns` repository to the owner-scoped
`family-cloudflare` repository. Keep the
design conclusions, but refresh Cloudflare-side evidence in `family-cloudflare`
before authoring or applying any cutover packet.

Expand Down Expand Up @@ -80,7 +80,7 @@ This design crosses three repos. The boundary is strict:
|---|---|---|---|
| Host hardening, host firewall, host package state, host SSH config, host daemon state | `system-config` (this repo) | All of it. | This document, packets, apply records. |
| LAN routing, OPNsense rules, ISC DHCP, Unbound DNS, NAT, HAProxy frontends, WoL | HomeNetOps (`~/Repos/verlyn13/HomeNetOps`) | All LAN-layer state. | "We need <X>" requests via the handback-format pattern; never reach in. |
| Cloudflare DNS records, Cloudflare Tunnel, Access policies, Traffic policies, Cloudflare One Client device enrollment, device profiles, account-level tokens | `family-cloudflare` (`/Users/verlyn13/Organizations/the-nash-group/family-cloudflare`) | All Cloudflare-side state, including current device-profile assignments and adult-vs-kids profile membership. | "We need <X>" requests; never claim live Cloudflare state unless current `family-cloudflare` proof or provider evidence supplies it. |
| Cloudflare DNS records, Cloudflare Tunnel, Access policies, Traffic policies, Cloudflare One Client device enrollment, device profiles, account-level tokens | `family-cloudflare` (owner-scoped `family-cloudflare` repository) | All Cloudflare-side state, including current device-profile assignments and adult-vs-kids profile membership. | "We need <X>" requests; never claim live Cloudflare state unless current `family-cloudflare` proof or provider evidence supplies it. |

Implication: any statement in any subsequent packet of the form
"the Cloudflare Access policy for `fedora-top` is N" must cite a
Expand Down Expand Up @@ -189,7 +189,7 @@ routing layer.
**Mechanism**: `cloudflared` runs as a service on `fedora-top` and
maintains an outbound-initiated tunnel to Cloudflare's edge. The
operator's MacBook (and any other admin device) joins the same
`homezerotrust` team via the Cloudflare One Client. A Cloudflare Access
`[redacted historical Cloudflare team identifier]` team via the Cloudflare One Client. A Cloudflare Access
policy binds an `ssh.fedora-top.<org-domain>` hostname (or equivalent)
to the operator's identity. SSH traffic flows MacBook -> Cloudflare One
Client -> Cloudflare edge -> tunnel -> `fedora-top:22`.
Expand Down Expand Up @@ -357,7 +357,7 @@ that supplies the following non-secret evidence:

1. **Current Cloudflare account and team structure**:
- Account / team name(s) and their relation to Jefahnierocks.
- Whether the `homezerotrust` team is on the same account or a separate one.
- Whether the `[redacted historical Cloudflare team identifier]` team is on the same account or a separate one.
- The current `family-cloudflare` repo path and the latest commit
that should be cited.

Expand Down Expand Up @@ -527,4 +527,4 @@ boundaries, nothing more.
- [../secrets.md](../secrets.md)
- HomeNetOps repo (external authority): `~/Repos/verlyn13/HomeNetOps`
- `family-cloudflare` repo (external authority):
`/Users/verlyn13/Organizations/the-nash-group/family-cloudflare`
owner-scoped `family-cloudflare` repository
Loading
Loading