STEP_037A5_CREATE_CS2_SCHEMA_DERIVED PASS_CS2_TEST_PEER_CREATED_AND_APPLIED timestamp: 20260708-134255 Created second WGPay test peer: - subscription_id: e0dc09ca-5ef2-49d3-b8bc-2bb07a26717e - peer_id: cb533a1a-7070-416d-9272-846327545060 - tunnel_ip: 10.253.1.11 - create_guard_safe_final: 1 - derived_request_keys: auto_renew,email,months,node_id,plan_code - derived_request_email: wgpay-cs2-canary-20260708-134255@example.com - derived_request_plan_code: manual - create_http_code: 200 - parse_ok: 1 - agent_start_rc: 0 Backend/API: - peer_count_after: 22 - enabled_peer_count_after: 2 - enabled_peer_count_delta: 1 - new_enabled_peer_count: 1 - pending_job_count_after: 0 - cs2_peer_found/enabled/matches: True / True / True - cs2_job_found/status: True / completed - endpoint_final_lines: 1 VM100: - wg_paid peer count: 2 - existing canary visible rc: 0 - cs2 peer visible rc: 0 - selector active entry count: 1 - selector has cs2 ip rc: 1 - selector rule visible rc: 0 Rollback: - VM121: /root/rollback-step037a5-cs2-test-peer.sh Changes: - created second backend subscription/peer if HTTP succeeded - ran WG Access agent only if HTTP succeeded - no selector expansion yet - no mapper changes - no policy switch - no backend restart - private client config saved only under VM121 backup dir, not published Next: - if PASS, add VM100 selector entry: 10.253.1.11 cs2 canary_vpn4 - then observe cs2 -> 0x204 -> vpn4 traffic.