DR-046 — Pipeline private ingress: Cloudflare Tunnel default; ingress is control-plane only
The pipeline’s private ingress target is Cloudflare Tunnel + Access service token
(through the existing Traefik path-scope, bearer as second factor); Vercel Static-IP
allowlist is the per-client escape hatch, mTLS last-resort. (Unbuilt as of S499: live
ingress is still public HTTPS + Traefik path-scope + bearer — the deliberate interim
posture, formerly DR-015, which stands until the {127.20} owner infra window runs the
cutover — runbooks/private-ingress-cutover.md.) The DR co-carries the
ingress-is-control-plane invariant: push-shaped inlets terminate at the app/bucket
layer, connector inlets are outbound-pull, and each binding’s egress-host allowlist
derives from the source-binding register ({138.3} must-encodes) — future inlets do not
re-open this ruling. Provenance: S456 ratification (decisions 5+6 + item-6 addendum),
reports/arch-assessment-compute-posture-s456.md §C/§F (re-filed from reference/ S504).