pull down to refresh

Keys that never leave encrypted NVS is the right default. The homelab version of the same idea is not letting the box that talks to the mesh share a WAN plane with anything else — one guest with a port-forward and the 'never touch a computer' story is gone.