# Глобальный план проекта WG Paid после R20QW

Версия публикации: **R20QX architecture checkpoint**.

## Текущая позиция

Автономный runtime VM100/VM101 закрыт до стабильного production checkpoint:

- transactional generation activation;
- local repair;
- full pool refresh;
- degraded retry state;
- zero-healthy Direct/fresh-pool recovery;
- topology reconciliation;
- controlled reboot proof;
- administrative `wg_remote → cs4`.

Текущая активная ветка — пользовательский контур VM121 и onboarding тестовых клиентов.

Audit: https://reports.secret-studio.ru/latest/20260802-102738_step050m07r20qw_r02_readonly_audit_publication_continuation/

## A. Runtime VM100/VM101

- [x] `wg_paid` и пять selector-классов.
- [x] Пять AmneziaWG egress-слотов.
- [x] Health, local repair и quarantine.
- [x] Full-pool refresh и transactional generation.
- [x] Durable degraded/retry state.
- [x] Zero-healthy Direct and recovery chain.
- [x] Topology redistribution of existing selector rows.
- [x] Controlled reboot proof.
- [x] `wg_remote` default `cs4`.
- [ ] Common multi-protocol peer membership/lifecycle registry.
- [ ] Automatic selector assignment for a new profile.
- [ ] Multi-interface selector/activity renderer.
- [ ] Multi-pool Direct/PBR generalization.
- [ ] User-facing `awg_paid` server interface.
- [ ] VM101 AWG Paid public DNAT.

## B. VM121 identity and user portal

- [x] Backend, PostgreSQL and health.
- [x] Legacy user/subscription/peer/job model.
- [x] Peer enable/disable and reconcile.
- [x] Subscription cancel/expiration maintenance.
- [x] Live source/database audit.
- [x] Multi-protocol architecture and quotas fixed.
- [ ] Bridge migration for live schema drift.
- [ ] Email cleanup and normalized unique identity.
- [ ] Plans, AccessGrant and per-protocol quotas.
- [ ] Connection profiles and encrypted credentials.
- [ ] Invite redemption and magic-link authentication.
- [ ] Secure sessions and audit events.
- [ ] Production image, TLS, admin protection and SMTP.
- [ ] Minimal account, config download and QR.
- [ ] Revoke/reissue and retryable jobs.

## C. Pilot users

- [ ] Synthetic WireGuard profile through the new lifecycle.
- [ ] First 2–3 existing Dedenево users with overlap.
- [ ] Expanded WireGuard cohort.
- [ ] Synthetic AmneziaWG profile.
- [ ] Selected AmneziaWG pilot users.
- [ ] Individual retirement of old home peers after confirmation.

## D. Referrals and payments

- [ ] User-issued invites with limits.
- [ ] Product plans and prices.
- [ ] YooKassa order/webhook/idempotency.
- [ ] Payment creates or extends AccessGrant.
- [ ] Renewal, grace, cancellation and refund policy.
- [ ] Notifications and payment history.

## E. Operations and security

- [x] VM130 workflow contract v2 and timestamped publication.
- [x] Machine Git snapshots for VM100/VM101/VM121.
- [x] Risk-proportional test standard.
- [ ] Validated VM121 DB backup/restore runbook.
- [ ] Encryption-key backup/rotation.
- [ ] Monitoring and alerting for portal/provisioning.
- [ ] Privacy and retention policy.
- [ ] Periodic restore drills.

## Ближайшая последовательность

1. [x] Publish R20QW canonical architecture and global plan.
2. [ ] P1.1 VM100 lifecycle registry design and targeted fixtures.
3. [ ] P1.2 VM100 WireGuard lifecycle implementation.
4. [ ] P1.3 VM121 agent integration without selector ownership.
5. [ ] P2 bridge migration and identity cleanup.
6. [ ] P3/P4 secure invite + magic-link MVP.
7. [ ] First WireGuard pilot users.
8. [ ] `awg_paid` transport and account enablement.
9. [ ] Expanded pilot and old-access migration.
10. [ ] Referrals and payments.

## Definition of Done for first tester milestone

- invite and magic-link login work;
- user has an explicit per-protocol quota;
- a WireGuard profile is provisioned transactionally;
- VM100 assigns and persists selector without VM121 involvement;
- config and QR are available securely;
- RU traffic is Direct and foreign traffic uses a healthy VPN slot;
- revoke/expire removes runtime peer and selector membership;
- old Dedenево access remains until user confirmation;
- backup/restore and audit evidence are available.

## Canonical references

- VM100: https://reports.secret-studio.ru/latest/20260801-190522_vm100_git_source_a8b7337674b9/
- VM101: https://reports.secret-studio.ru/latest/20260801-095331_vm101_git_source_ac678d1b3164/
- VM121: https://reports.secret-studio.ru/latest/20260713-182700_vm121_git_source_93e0e5a31f09/
- VM130: https://reports.secret-studio.ru/latest/20260801-060501_vm130_router_ops_source_snapshot_after_r20qua2_r03_canonical_contract/
- Access Map: https://reports.secret-studio.ru/latest/20260715-210236_access_map_canonical_current/
- VM101 local plan: https://reports.secret-studio.ru/latest/20260719-080444_local_architecture_plan_vm101_autonomous_hmn_recovery_r19/
- R20QW audit: https://reports.secret-studio.ru/latest/20260802-102738_step050m07r20qw_r02_readonly_audit_publication_continuation/
- Project Source post: published alongside this global plan in STEP R20QX.
