Decision
Transport scope T6: retain and harden ZeroTier as a first-class private-network transport.
Definition of success
Parity means Onibi reliably uses an already user-managed ZeroTier network; it does not create networks, authorize members, or manage ZeroTier account/policy state.
Required behavior
- Deterministically select a joined, healthy ZeroTier network/address, with an explicit override for ambiguous hosts.
- Bind the Cockpit only to that selected private address and include it in the certificate/QR URL.
- Revalidate membership/interface/address health and fail closed on stale endpoint changes.
- Provide actionable
doctor diagnostics and real-phone pairing/reconnect coverage.
- Never modify ZeroTier membership, controller policy, or routes.
Acceptance criteria
- A configured phone and host can pair and use terminal/approval/reconnect flows over ZeroTier with the same owner-auth model as LAN/Tailscale Private.
- Selection, certificate, membership/address-change, error, and cleanup paths are tested and documented.
Decision
Transport scope T6: retain and harden ZeroTier as a first-class private-network transport.
Definition of success
Parity means Onibi reliably uses an already user-managed ZeroTier network; it does not create networks, authorize members, or manage ZeroTier account/policy state.
Required behavior
doctordiagnostics and real-phone pairing/reconnect coverage.Acceptance criteria