Your OpenCode agent that only speaks OPNsense. No raw pfctl, no iptables, no hand-edited firewall configs โ if it can’t go through the OPNsense API into config.xml, opnsense won’t build it that way. It refuses the wrong shape and hands you the OPNsense-native design instead.
Restart OpenCode, verify with opencode agent list (expect opnsense).
Host / key / secret travel per command as env vars โ never stored in the repo, never logged.
Safety default: search โ stage โ apply, config.xml backup before mutating sessions, confirm before production apply.
โ Verification record
measured, not claimed
API shapes verified 29 Sep 2026 โ firewall plane (filter/searchRule/addRule/setRule/delRule/toggleRule/apply, alias/*, NAT controllers, filter_util/rule_stats) read against the live API reference; all other planes cite module/controller names from the same reference, parameters copied from GUI /api/ traffic.
Unknown-parameter rule banked: repeat the action in the GUI with devtools open, copy the /api/ request verbatim โ never invent model fields.
Gotchas banked: staged writes are not live before apply/reconfigure; automation-namespace rules are separate from core GUI rules; curl -k is lab-only.