Skip to content

DR-046 — Pipeline private ingress: Cloudflare Tunnel default; ingress is control-plane only

The pipeline’s private ingress target is Cloudflare Tunnel + Access service token (through the existing Traefik path-scope, bearer as second factor); Vercel Static-IP allowlist is the per-client escape hatch, mTLS last-resort. (Unbuilt as of S499: live ingress is still public HTTPS + Traefik path-scope + bearer — the deliberate interim posture, formerly DR-015, which stands until the {127.20} owner infra window runs the cutover — runbooks/private-ingress-cutover.md.) The DR co-carries the ingress-is-control-plane invariant: push-shaped inlets terminate at the app/bucket layer, connector inlets are outbound-pull, and each binding’s egress-host allowlist derives from the source-binding register ({138.3} must-encodes) — future inlets do not re-open this ruling. Provenance: S456 ratification (decisions 5+6 + item-6 addendum), reports/arch-assessment-compute-posture-s456.md §C/§F (re-filed from reference/ S504).