- Add snat/masquerade, netmap, and 1:1 nat as stored, terraformable resources:
migration 0003, model types, store CRUD (id-keyed, generation-bumping), and
REST handlers. These are the global-intent/device-resolved NAT tier; compiler
rendering of NAT into per-device configs is a tracked follow-up.
- Add a testcontainers-backed store integration suite exercising the CRUD
lifecycle, generation bumping, source/dest grammar validation, and FK cascade
against a real Postgres. It self-skips under 'go test -short' (the CI path) so
a container runtime is only needed for the full run.
Project the fleet-global model through a device's bindings into a rendered,
interface-agnostic config: rules compile to saddr/daddr forward matches with no
iif/oif so they are correct under FRR/ECMP. Firewalls always enforce; routers
enforce only when their fabric opts into defense-in-depth. Referenced address
groups are emitted as named sets carrying their source (static CIDRs, dns FQDNs,
or asn numbers) so membership churns out-of-band without a rule reload. Wire
GET /devices/{name}/config to compile and serve YAML, generation-stamped. Add
portgroups/policies/settings store methods and portgroup CRUD. Pure Render is
unit-tested for enforcement gating, ASN set emission, and resolver precedence.