diff --git a/docs/core/tasks.md b/docs/core/tasks.md index 9812bd5..0c9261c 100644 --- a/docs/core/tasks.md +++ b/docs/core/tasks.md @@ -313,21 +313,24 @@ Complete Vaultwarden setup: SSH key + organization for shared credentials with M --- -### 7. The Frostwall Protocol — GRE Tunnel Security Architecture +### 7. The Frostwall Protocol — GRE Tunnel Security Architecture ⚠️ TOP PRIORITY **Time:** 3-4 hours -**Status:** REBUILD PENDING -**Priority:** CRITICAL +**Status:** REBUILD PENDING — ELEVATED TO TOP PRIORITY (March 10, 2026) +**Priority:** CRITICAL — blocks email, which is now urgent **Documentation:** `docs/tasks/frostwall-protocol/` Custom DDoS protection using GRE tunnels from Command Center to TX1/NC1. Hides real IPs, protects email reputation. +**Why urgent now:** Email is needed soon — Holly staff email, staff comms, subscriber notifications. Frostwall → Mailcow is the only path to get there. This is the critical blocker. + **Core Components:** - GRE tunneling (encrypted links) - 1-to-1 NAT/DMZ forwarding - Iron Wall UFW rules - IP hierarchy (scrubbing → backend → binding) -**Blocks:** Mailcow, AI stack, all Tier 2+ infrastructure +**Blocks:** Mailcow (email) → Holly email, staff email, subscriber comms, all Tier 2+ infrastructure +**Deployment doc:** https://docs.google.com/document/d/12Kh-AhUgJLOJrBgIjMiGi3xRZH1basRzv9Pa_-x1t_0/edit --- diff --git a/docs/tasks/frostwall-protocol/README.md b/docs/tasks/frostwall-protocol/README.md index 77df86e..ffb2513 100644 --- a/docs/tasks/frostwall-protocol/README.md +++ b/docs/tasks/frostwall-protocol/README.md @@ -2,9 +2,10 @@ **Status:** PLANNING COMPLETE - Ready to Deploy **Owner:** Michael "Frostystyle" Krause -**Priority:** CRITICAL - Tier 1 Security Foundation +**Priority:** CRITICAL - TOP PRIORITY (elevated March 10, 2026) **Last Updated:** 2026-02-17 **Time Estimate:** 3-4 hours deployment (SSH required) +**Elevated:** Email needed urgently — Frostwall → Mailcow is the only path ---