Until ESS 26.4.0 the auth service pointed straight at matrix-stack-synapse-main,
which allow-ingress-synapse permits, so nothing was needed here. ESS 26.8.0 moves
matrix.endpoint to the haproxy service — and MAS walked into the default-deny.
Login broke with 500 'failed to provision device' on /oauth2/token.
The rule was mine, from #0088 this morning. It named who may reach haproxy, and
the list was complete for the topology of that hour. A chart decided otherwise
six hours later.