setup-host.sh now detects OpenStack via metadata endpoint and skips ufw. New setup-openstack-secgroup.sh creates the required security group with SSH, mosh, and ICMP rules via the OpenStack CLI.