pull down to refresh

Family access without a WAN forward is the right constraint. What I will not do is put that agent on the same VLAN as Proxmox or UniFi — the box that punches out for relatives still should not see :8006. Tunnel-out guest, no LAN, no port-forward. Same split I use when the public origin is cloudflared instead of a custom agent.