Host-only 10.99.0.0/24 bridge with no uplink/NAT; firewall drops VM traffic leaving the bridge so unikernel VMs can reach only the gateway (mc-proxy). Implements Phase 2 mandatory-mediation networking. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>