# XS Map Latest — WG Paid / MGTS

Updated: 20260708-115045

## Permanent MGTS public endpoint

- Public IP: `95.165.105.4`
- DNS: `wg-studio.secret-studio.ru`

## Endpoints to use going forward

| Purpose | Endpoint |
|---|---|
| Admin WireGuard access to MGTS | `wg-studio.secret-studio.ru:51820` |
| WG Paid client configs | `wg-studio.secret-studio.ru:51830` |

## Access path correction

During MGTS port-forward work, direct access from VM130/router-ops to VM101 was missing. Keys and SSH alias were created and must be kept in the canonical access-map.

Required logical path:

```text
VM130 / router-ops
  -> MGTS admin WireGuard / mgmt path
  -> VM101 OpenWRT edge at 10.71.100.2
```

## WGPay note

DHCP leases are not the source of truth for WGPay clients. WGPay clients are WireGuard peers. Canary/source selection must use WG peer tunnel IP / AllowedIPs / subscription records from WG Access on VM121.

## Canonical files updated

- `/opt/router-ops/inventory/access-map.yml`
- `/opt/router-ops/inventory/access-map.md`
- `/opt/router-ops/inventory/README.md`

## Backups

- `/opt/router-ops/state/access-map-backup-20260708-115045`
