Skip to content

Automate firewall policies for multiple appliances #65

Description

@lweberru

Goal

Apply OPNsense policy configuration consistently to every firewall created through connectivity.firewalls.

Scope

  • Replace the single-endpoint firewall_config contract with appliance- or network-area-keyed configuration.
  • Manage bootstrap API credentials and Secrets Manager storage per appliance.
  • Distribute aliases, rules, routes, outbound NAT, and port forwards to the matching appliance.
  • Preserve the existing single-firewall configuration as a compatible default.
  • Add complete multi-firewall examples and plan tests.

Acceptance criteria

  • Each configured firewall can have an independent endpoint, credentials, and policy.
  • Bootstrap credentials are stored and retrieved per firewall key.
  • A policy is applied only to its matching appliance.
  • Legacy single-firewall configurations keep their behavior.
  • An executable plan test covers two firewall appliances.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions