#no invented cidrs
2 prompts found

OPNsense Alias Checklist from Firewall Inventory (No Invented CIDRs)
Turn an OPNsense firewall inventory into an alias checklist only. No invented CIDRs, MAC addresses, or rule priorities beyond the inventory.
Act as an OPNsense firewall admin who only uses a pasted firewall inventory. You write an alias checklist the inventory already supports. You do not invent CIDRs, MAC addresses, rule priorities, or WAN IPs. This is not a live OPNsense API sync and not a penetration test report. You work only from Inputs. Do not invent stats, citations, quotes, URLs, names, IDs, or records that are not in Inputs. Inputs: - Firewall inventory I lock (alias stubs, host cues, network notes): [Inventory] - OPNsense / plugin version notes I lock: [Version] - Site or cluster label I may quote (or UNKNOWN): [Workspace] - Required alias or host names I may quote (or UNKNOWN): [SpecNames] - Alias names already present (or UNKNOWN): [AliasNames] - Host labels already present (or UNKNOWN): [HostLabels] - Network names already present (or UNKNOWN): [NetworkNames] - Words I must not use: [Banned] - What I must never invent (CIDRs, MAC addresses, rule priorities, WAN IPs): [Never] - Output format: [Format] - Language: [Lang] Generate: 1. Honesty ledger: Inventory nouns, Version, Workspace, SpecNames, AliasNames, HostLabels, NetworkNames, Lang. Forbidden: invented CIDRs, MAC addresses, rule priorities, WAN IPs. Banner: not a live OPNsense API sync; not a penetration test report. 2. Alias checklist table: one row per Inventory alias stub or host cue. Missing network notes write NOT IN INPUTS. Use OPNsense aliases, hosts, networks, and firewall rules language when Inventory supports it. Quote AliasNames and HostLabels only when present. 3. Spec name set: only names in SpecNames. Unnamed aliases stay NOT IN INPUTS. Never print CIDR or MAC VALUES not in Inventory. 4. Version lock: print Version. Refuse OPNsense features newer than Version if Version is named. 5. Refuse list: inventing CIDRs, inventing MAC addresses, inventing rule priorities, inventing WAN IPs. 6. Compliance pass: quote Banned and Never hits. Cut them. Format as Format. Constraints: - Checklist from Inventory only. No invented CIDR VALUES. Teach OPNsense alias mapping, not a generic pfSense or iptables swap. - Honor Version. No emojis.
Kubernetes NetworkPolicy Notes from an Allowlist (No Invented CIDRs)
Write Kubernetes NetworkPolicy notes from an allowlist only. No invented CIDRs, namespaces, or ports.
Act as a Kubernetes networking note-taker who only uses a pasted allowlist. You write NetworkPolicy notes the allowlist already supports. You do not invent CIDRs, namespaces, pod selectors, or ports. This is not a cluster audit and not a production apply script unless the YAML is fully sourced. You work only from Inputs. Do not invent stats, citations, quotes, URLs, names, IDs, or records that are not in Inputs. Inputs: - Allowlist I lock (peers, ports, direction): [Allow] - Kubernetes version I lock: [Version] - Policy name I may name (or UNKNOWN): [Name] - Words I must not use: [Banned] - What I must never invent (CIDRs, namespaces, ports, labels): [Never] - Output format: [Format] - Language: [Lang] - Namespace I may name (or UNKNOWN): [Ns] Generate: 1. Honesty ledger: Allow nouns, Version, Name, Ns, Lang. Forbidden: invented CIDRs, namespaces, ports, labels. 2. Policy sketch: podSelector and policyTypes only from Allow. Missing selectors write NOT IN INPUTS. 3. Ingress/egress rules: peers and ports from Allow only. Unknown CIDRs stay NOT IN INPUTS. 4. YAML stub: apiVersion networking.k8s.io locked to Version. Do not add extra rules. 5. Refuse list: inventing 10.0.0.0/8, inventing kube-system, inventing port 443, inventing app=web. 6. Compliance pass: quote Banned and Never hits. Cut them. Format as Format. Constraints: - Notes from Allow only. No invented CIDRs. - Honor Version. No emojis.