feat(bcn01-lab): restrict 1:1 NAT to specific service ports, allow any source

Replace open any/any inbound rule on Synology NAT with explicit TCP ports:
443 (Synology), 9890 (Vaultwarden), 4769 (Zabbix), 8080 (Snipe-IT),
3000 (Metabase), 3333 (Gitea), 8081 (phpIPAM). Access allowed from any IP.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
Jose Martinez
2026-05-07 10:30:29 +02:00
co-authored by Claude Sonnet 4.6
parent 6d0f186795
commit 85ef316745
+3 -8
View File
@@ -7,14 +7,9 @@ locals {
uplink = "internet2"
allowed_inbound = [
{
protocol = "any"
destination_ports = ["Any"]
allowed_ips = ["188.0.0.0/8"]
},
{
protocol = "any"
destination_ports = ["Any"]
allowed_ips = ["57.133.120.176/28"]
protocol = "tcp"
destination_ports = ["443", "9890", "4769", "8080", "3000", "3333", "8081"]
allowed_ips = ["Any"]
},
]
},