Goal
Apply OPNsense policy configuration consistently to every firewall created through connectivity.firewalls.
Scope
- Replace the single-endpoint firewall_config contract with appliance- or network-area-keyed configuration.
- Manage bootstrap API credentials and Secrets Manager storage per appliance.
- Distribute aliases, rules, routes, outbound NAT, and port forwards to the matching appliance.
- Preserve the existing single-firewall configuration as a compatible default.
- Add complete multi-firewall examples and plan tests.
Acceptance criteria
Goal
Apply OPNsense policy configuration consistently to every firewall created through connectivity.firewalls.
Scope
Acceptance criteria