=== STEP_034E3 CANONICAL ACCESS MAP APPLY === timestamp=20260708-115045 mode=docs/inventory apply only admin_endpoint=wg-studio.secret-studio.ru:51820 wgpay_endpoint=wg-studio.secret-studio.ru:51830 no active WG/network changes === Backup inventory files === backup /opt/router-ops/inventory/access-map.yml -> /opt/router-ops/state/access-map-backup-20260708-115045/access-map.yml.before backup /opt/router-ops/inventory/access-map.md -> /opt/router-ops/state/access-map-backup-20260708-115045/access-map.md.before backup /opt/router-ops/inventory/README.md -> /opt/router-ops/state/access-map-backup-20260708-115045/README.md.before === Apply conservative endpoint replacements + append map note === UPDATED /opt/router-ops/inventory/access-map.yml DIFF /opt/router-ops/state/access-map-backup-20260708-115045/access-map.yml.diff --- /opt/router-ops/inventory/access-map.yml.before +++ /opt/router-ops/inventory/access-map.yml.after @@ -89,7 +89,7 @@ address: 10.250.100.4/32 systemd_service: wg-quick@router-ops-mgts expected_service_state: enabled and active - current_test_endpoint: 192.168.30.218:51820 + current_test_endpoint: wg-studio.secret-studio.ru:51820 server: mgts_vm100_core wg_remote 10.250.100.1 UDP 51820 allowed_ips: - 10.250.100.0/24 @@ -472,3 +472,16 @@ key_paths_recorded: true fingerprints_allowed: true + + +# STEP_034E3_XSMAP_WG_STUDIO_BEGIN +# Permanent MGTS public identity: +# dns: wg-studio.secret-studio.ru +# public_ip: 95.165.105.4 +# admin_wg_endpoint: wg-studio.secret-studio.ru:51820 +# wgpaid_client_endpoint: wg-studio.secret-studio.ru:51830 +# Access-map correction: +# VM130/router-ops -> VM101 MGTS edge access was added and must remain documented. +# VM101 MGTS edge IP: 10.71.100.2 +# WGPay clients are WireGuard peers, not DHCP leases. +# STEP_034E3_XSMAP_WG_STUDIO_END UPDATED /opt/router-ops/inventory/access-map.md DIFF /opt/router-ops/state/access-map-backup-20260708-115045/access-map.md.diff --- /opt/router-ops/inventory/access-map.md.before +++ /opt/router-ops/inventory/access-map.md.after @@ -182,7 +182,7 @@ router-ops-mgts currently uses temporary DDN test endpoint: - 192.168.30.218:51820 + wg-studio.secret-studio.ru:51820 On MGTS site, update endpoint to real public IP/DNS or MGTS router forward/DMZ address. @@ -252,3 +252,24 @@ Private keys are not recorded here. Only key paths, public keys and fingerprints may be recorded. + + + +## WG Studio / MGTS endpoint update + +Updated: 2026-07-08 11:50:45 + +Permanent MGTS public identity: + +- DNS: `wg-studio.secret-studio.ru` +- Public IP: `95.165.105.4` +- Admin WireGuard endpoint: `wg-studio.secret-studio.ru:51820` +- WG Paid client endpoint: `wg-studio.secret-studio.ru:51830` + +Important access-map correction: + +- VM130/router-ops now has direct SSH access to MGTS VM101 and this must stay represented in the map. +- VM101 MGTS edge address: `10.71.100.2` +- WGPay clients are WireGuard peers, not DHCP clients; canary/source selection must use WG peer tunnel IP / AllowedIPs / subscription records, not DHCP leases. + + UPDATED /opt/router-ops/inventory/README.md DIFF /opt/router-ops/state/access-map-backup-20260708-115045/README.md.diff --- /opt/router-ops/inventory/README.md.before +++ /opt/router-ops/inventory/README.md.after @@ -45,3 +45,24 @@ VM121 has direct wg-mgts access to MGTS 10.71.100.0/24. VM130/router-ops is not a transit router for VM121. + + + +## WG Studio / MGTS endpoint update + +Updated: 2026-07-08 11:50:45 + +Permanent MGTS public identity: + +- DNS: `wg-studio.secret-studio.ru` +- Public IP: `95.165.105.4` +- Admin WireGuard endpoint: `wg-studio.secret-studio.ru:51820` +- WG Paid client endpoint: `wg-studio.secret-studio.ru:51830` + +Important access-map correction: + +- VM130/router-ops now has direct SSH access to MGTS VM101 and this must stay represented in the map. +- VM101 MGTS edge address: `10.71.100.2` +- WGPay clients are WireGuard peers, not DHCP clients; canary/source selection must use WG peer tunnel IP / AllowedIPs / subscription records, not DHCP leases. + + === Validate access-map command and grep final values === --- files --- -rw-r--r-- 1 ops ops 1786 Jul 8 11:50 /opt/router-ops/inventory/README.md -rw-r--r-- 1 ops ops 6202 Jul 8 11:50 /opt/router-ops/inventory/access-map.md -rw-r--r-- 1 ops ops 14891 Jul 8 11:50 /opt/router-ops/inventory/access-map.yml --- grep old/temp/final endpoints --- /opt/router-ops/inventory/access-map.yml:29: management_ip: 10.71.100.222 /opt/router-ops/inventory/access-map.yml:34: vmbr1: 10.71.100.222/24 internal LAN /opt/router-ops/inventory/access-map.yml:36: vmbr3: VM100-VM101 VPN transit bridge /opt/router-ops/inventory/access-map.yml:37: vmbr4: VM100-VM101 direct transit bridge /opt/router-ops/inventory/access-map.yml:55: listen_udp: 51820 /opt/router-ops/inventory/access-map.yml:66: mgts_vm101_edge: /opt/router-ops/inventory/access-map.yml:68: hostname: VM101-OpenWRT-edge /opt/router-ops/inventory/access-map.yml:72: host: 10.71.100.2 /opt/router-ops/inventory/access-map.yml:76: mgmt_eth2: 10.71.100.2/24 /opt/router-ops/inventory/access-map.yml:83: - MGTS_VM101_CURRENT_20260702_OK /opt/router-ops/inventory/access-map.yml:92: current_test_endpoint: wg-studio.secret-studio.ru:51820 /opt/router-ops/inventory/access-map.yml:93: server: mgts_vm100_core wg_remote 10.250.100.1 UDP 51820 /opt/router-ops/inventory/access-map.yml:106: expected_target: 10.71.100.222 /opt/router-ops/inventory/access-map.yml:118: pve_wg_paid_to_mgts_vm101: /opt/router-ops/inventory/access-map.yml:120: to: mgts_vm101_edge /opt/router-ops/inventory/access-map.yml:121: command: ssh -n -i /root/.ssh/pve_to_openwrt_mgts_ed25519 root@10.71.100.2 /opt/router-ops/inventory/access-map.yml:173: home_vm101_edge: /opt/router-ops/inventory/access-map.yml:174: hostname: VM101-OpenWRT-edge /opt/router-ops/inventory/access-map.yml:247: wg_remote_udp: 51820 /opt/router-ops/inventory/access-map.yml:249: client001_vm101_edge: /opt/router-ops/inventory/access-map.yml:250: hostname: client001 VM101-OpenWRT-edge /opt/router-ops/inventory/access-map.yml:274: ssh_connection: 10.250.100.4 -> 10.71.100.222:22 /opt/router-ops/inventory/access-map.yml:303: home_vm101: /opt/router-ops/inventory/access-map.yml:321: client001_vm101: /opt/router-ops/inventory/access-map.yml:338: listen_port: 51830 /opt/router-ops/inventory/access-map.yml:364:# MGTS VM101 VPN-egress audit: /opt/router-ops/inventory/access-map.yml:373:# /opt/router-ops/inventory/STATUS-MGTS-VM101-VPN-EGRESS-OLD-AWG-PARTIAL.txt /opt/router-ops/inventory/access-map.yml:395: vm101_edge: /opt/router-ops/inventory/access-map.yml:396: ip: "10.71.100.2" /opt/router-ops/inventory/access-map.yml:399: ssh_command: "ssh root@10.71.100.2" /opt/router-ops/inventory/access-map.yml:401: ip: "10.71.100.222" /opt/router-ops/inventory/access-map.yml:414: listen_port_udp: 51830 /opt/router-ops/inventory/access-map.yml:450: vm101_edge: /opt/router-ops/inventory/access-map.yml:451: ip: "10.71.100.2" /opt/router-ops/inventory/access-map.yml:453: ssh_from_pve_mgts: "ssh -i /root/.ssh/pve_to_openwrt_mgts_ed25519 root@10.71.100.2" /opt/router-ops/inventory/access-map.yml:455: ip: "10.71.100.222" /opt/router-ops/inventory/access-map.yml:464: listen_port_udp: 51830 /opt/router-ops/inventory/access-map.yml:479:# dns: wg-studio.secret-studio.ru /opt/router-ops/inventory/access-map.yml:480:# public_ip: 95.165.105.4 /opt/router-ops/inventory/access-map.yml:481:# admin_wg_endpoint: wg-studio.secret-studio.ru:51820 /opt/router-ops/inventory/access-map.yml:482:# wgpaid_client_endpoint: wg-studio.secret-studio.ru:51830 /opt/router-ops/inventory/access-map.yml:484:# VM130/router-ops -> VM101 MGTS edge access was added and must remain documented. /opt/router-ops/inventory/access-map.yml:485:# VM101 MGTS edge IP: 10.71.100.2 /opt/router-ops/inventory/access-map.md:32: -> Proxmox pve-wg-paid 10.71.100.222 /opt/router-ops/inventory/access-map.md:41: target: 10.71.100.222 /opt/router-ops/inventory/access-map.md:87: 10.71.100.222 /opt/router-ops/inventory/access-map.md:94: vmbr1: 10.71.100.222/24 internal LAN /opt/router-ops/inventory/access-map.md:134: listen UDP: 51820 /opt/router-ops/inventory/access-map.md:149:MGTS VM101 edge /opt/router-ops/inventory/access-map.md:156: VM101-OpenWRT-edge /opt/router-ops/inventory/access-map.md:163: ssh -n -i /root/.ssh/pve_to_openwrt_mgts_ed25519 root@10.71.100.2 /opt/router-ops/inventory/access-map.md:167: mgmt eth2: 10.71.100.2/24 /opt/router-ops/inventory/access-map.md:177: MGTS_VM101_CURRENT_20260702_OK /opt/router-ops/inventory/access-map.md:185: wg-studio.secret-studio.ru:51820 /opt/router-ops/inventory/access-map.md:214: 10.71.100.2 MGTS VM101 OpenWRT edge /opt/router-ops/inventory/access-map.md:215: 10.71.100.222 MGTS Proxmox pve-wg-paid /opt/router-ops/inventory/access-map.md:221: target: 10.71.100.222 /opt/router-ops/inventory/access-map.md:232: pve-mgts -> MGTS VM101: /opt/router-ops/inventory/access-map.md:233: command: ssh -i /root/.ssh/pve_to_openwrt_mgts_ed25519 root@10.71.100.2 /opt/router-ops/inventory/access-map.md:238: VM121 -> 10.71.100.2 OK /opt/router-ops/inventory/access-map.md:239: VM121 -> 10.71.100.222 OK /opt/router-ops/inventory/access-map.md:264:- DNS: `wg-studio.secret-studio.ru` /opt/router-ops/inventory/access-map.md:265:- Public IP: `95.165.105.4` /opt/router-ops/inventory/access-map.md:266:- Admin WireGuard endpoint: `wg-studio.secret-studio.ru:51820` /opt/router-ops/inventory/access-map.md:267:- WG Paid client endpoint: `wg-studio.secret-studio.ru:51830` /opt/router-ops/inventory/access-map.md:271:- VM130/router-ops now has direct SSH access to MGTS VM101 and this must stay represented in the map. /opt/router-ops/inventory/access-map.md:272:- VM101 MGTS edge address: `10.71.100.2` /opt/router-ops/inventory/README.md:57:- DNS: `wg-studio.secret-studio.ru` /opt/router-ops/inventory/README.md:58:- Public IP: `95.165.105.4` /opt/router-ops/inventory/README.md:59:- Admin WireGuard endpoint: `wg-studio.secret-studio.ru:51820` /opt/router-ops/inventory/README.md:60:- WG Paid client endpoint: `wg-studio.secret-studio.ru:51830` /opt/router-ops/inventory/README.md:64:- VM130/router-ops now has direct SSH access to MGTS VM101 and this must stay represented in the map. /opt/router-ops/inventory/README.md:65:- VM101 MGTS edge address: `10.71.100.2` --- access-map command --- # Access Map — router-ops / WG Paid This file is the human-readable source of truth for access paths. No private keys. No public keys. No WireGuard client configs. No passwords or tokens. Allowed here: - machine names - roles - IP addresses - SSH aliases - key file paths - non-secret operational notes Rules: - Do not create new SSH/WG keys unless explicitly requested. - Before suggesting access commands, read /opt/router-ops/inventory/access-map.yml. - Prefer existing SSH aliases and existing key files. - Do not print private keys or WireGuard configs. - Use ssh -n for nested SSH from Proxmox to OpenWRT inside heredocs. ============================================================ MAIN ACCESS PATH TO PVE-WG-PAID ============================================================ router-ops WG router-ops-mgts 10.250.100.4/32 -> VM100 wg_remote 10.250.100.1/24 -> Proxmox pve-wg-paid 10.71.100.222 Command from router-ops: ssh pve-mgts Expected SSH path: source: 10.250.100.4 target: 10.71.100.222 ============================================================ MACHINES ============================================================ router-ops ---------- Role: operations VM User: ops Known address: 192.168.30.84 WG interface: router-ops-mgts WG address: 10.250.100.4/32 Systemd service: wg-quick@router-ops-mgts Expected service state: enabled active ------------------------------------------------------------ pve-wg-paid ----------- Role: Proxmox host for WG Paid / MGTS deployment SSH alias from router-ops: pve-mgts SSH user: root Management IP: 10.71.100.222 SSH key path on router-ops: ~/.ssh/router_ops_pve_mgts_ed25519 Network: vmbr0: WAN bridge, no IPv4 on Proxmox host vmbr1: 10.71.100.222/24 internal LAN vmbr2: 192.168.99.1/24 emergency vmbr3: transit VPN bridge, no host IP vmbr4: transit direct bridge, no host IP Route back to WG admin net: 10.250.100.0/24 via 10.71.100.1 dev vmbr1 Old temporary DDN IP: 192.168.30.249 Old temporary DDN IP status: deprecated do not rely on it ------------------------------------------------------------ MGTS VM100 core --------------- VMID: 100 Hostname: VM100-OpenWRT-core Role: OpenWRT core router for pve-wg-paid SSH from Proxmox: ssh -n -i /root/.ssh/pve_to_openwrt_mgts_ed25519 root@10.71.100.1 Addresses: br-lan: 10.71.100.1/24 wg_remote: 10.250.100.1/24 direct transit: 10.201.0.1/24 vpn transit: 10.200.0.1/24 wg_remote: listen UDP: 51820 wg_remote peers: support-mgts: 10.250.100.2/32 owner-mgts: 10.250.100.3/32 router-ops-mgts: 10.250.100.4/32 Snapshots: MGTS_RESTORED_BEFORE_FIRST_BOOT MGTS_INTERNAL_LAN_RENUMBERED_OK MGTS_VM100_WG_REMOTE_ROTATED_OK MGTS_VM100_ROUTER_OPS_WG_PEER_OK ------------------------------------------------------------ MGTS VM101 edge --------------- VMID: 101 Hostname: VM101-OpenWRT-edge Role: OpenWRT edge / WAN / VPN egress for pve-wg-paid SSH from Proxmox: ssh -n -i /root/.ssh/pve_to_openwrt_mgts_ed25519 root@10.71.100.2 Addresses: WAN eth0: DHCP behind vmbr0 mgmt eth2: 10.71.100.2/24 vpn_in eth1: 10.200.0.2/24 direct_in eth3: 10.201.0.2/24 Route back to admin WG: 10.250.100.0/24 via 10.71.100.1 dev eth2 Snapshots: MGTS_RESTORED_BEFORE_FIRST_BOOT MGTS_INTERNAL_LAN_RENUMBERED_OK MGTS_VM101_CURRENT_20260702_OK ============================================================ TEMPORARY NOTES ============================================================ router-ops-mgts currently uses temporary DDN test endpoint: wg-studio.secret-studio.ru:51820 On MGTS site, update endpoint to real public IP/DNS or MGTS router forward/DMZ address. HideMyName/AWG keys still need future replacement before production use. --- ## VM121 direct MGTS admin access Status: confirmed. Recorded: 2026-07-06T15:42:33 Purpose: VM121 wg-access-dev has its own direct administrative WireGuard access to MGTS 10.71.100.0/24. VM130/router-ops is only an operator/control node. VM130 is not a transit router for VM121. Direct admin WireGuard: VM121 interface: wg-mgts VM121 WG address: 10.250.100.121/32 MGTS server side: VM100 wg_remote MGTS WG server addr: 10.250.100.1/24 MGTS LAN reachable: 10.71.100.0/24 Confirmed reachable targets from VM121: 10.71.100.1 MGTS VM100 OpenWRT core 10.71.100.2 MGTS VM101 OpenWRT edge 10.71.100.222 MGTS Proxmox pve-wg-paid SSH access paths: router-ops -> pve-mgts: command: ssh pve-mgts target: 10.71.100.222 key path: ~/.ssh/router_ops_pve_mgts_ed25519 router-ops -> VM121: command: ssh vm121 target: 192.168.30.83 key path: ~/.ssh/router_ops_ed25519 pve-mgts -> MGTS VM100: command: ssh -i /root/.ssh/pve_to_openwrt_mgts_ed25519 root@10.71.100.1 pve-mgts -> MGTS VM101: command: ssh -i /root/.ssh/pve_to_openwrt_mgts_ed25519 root@10.71.100.2 Confirmed smoke tests: VM121 -> 10.71.100.1 OK VM121 -> 10.71.100.2 OK VM121 -> 10.71.100.222 OK wg_paid live temp client smoke: temp client: 10.253.254.121/32 target: 10.253.1.1 handshake: OK server ping: OK internet: OK external IP during smoke: 94.45.208.160 cleanup: temp peer/client removed Secrets policy: Private keys are not recorded here. Only key paths, public keys and fingerprints may be recorded. ## WG Studio / MGTS endpoint update Updated: 2026-07-08 11:50:45 ACCESS_MAP_RC=0 === Refresh visible XS_MAP_LATEST === INDEX=/opt/router-ops/public/r/e94a0859747d7b96f29c7fdafc2d0351ba603bb0a7e9e5a4/index.html === STEP_034E3 RESULT === updated_file_lines=3 final_domain_lines=/opt/router-ops/inventory/access-map.yml:4 /opt/router-ops/inventory/access-map.md:4 /opt/router-ops/inventory/README.md:3 old_local_endpoint_remaining_lines=/opt/router-ops/inventory/access-map.yml:0 /opt/router-ops/inventory/access-map.md:0 /opt/router-ops/inventory/README.md:0 temp_public_ip_endpoint_remaining_lines=/opt/router-ops/inventory/access-map.yml:0 /opt/router-ops/inventory/access-map.md:0 /opt/router-ops/inventory/README.md:0 vm101_documented_lines=/opt/router-ops/inventory/access-map.yml:32 /opt/router-ops/inventory/access-map.md:18 /opt/router-ops/inventory/README.md:2 visible_map_ok=1 backup_dir=/opt/router-ops/state/access-map-backup-20260708-115045 visible_url=https://maple-movie-urls-cigarettes.trycloudflare.com/r/e94a0859747d7b96f29c7fdafc2d0351ba603bb0a7e9e5a4/XS_MAP_LATEST/ decision=PASS_CANONICAL_ACCESS_MAP_APPLIED