# TCP middlewares. The ssh entrypoint on :26 is allow-listed to one address;
# unrelated to the LLM stack, kept because it is in the real file.
tcp:
  middlewares:
    ssh-whitelist:
      IPAllowList:
        sourceRange:
          - "203.0.113.10/32"   # home; RFC 5737 documentation address here
