Artifacts

Report

=== STEP_044G RESULT ===
step=STEP_044G_RUNTIME_EGRESS_ACTIVITY_COUNTERS_DESIGN
mode=READONLY_DESIGN_VM100_INNER_TRAFFIC_ACTIVITY_COUNTERS_FOR_RUNTIME_EGRESS_ALLOCATOR

db_summary:
  enabled_peers=5
  lease_rows=5
  active_leases=0
  idle_leases=5
  forced_leases=0
  pending_jobs=0

vm100_detected_interfaces:
  wg_paid_l3_device=wg_paid
  transit_vpn_l3_device=eth2
  transit_direct_l3_device=eth0

activity_counter_design:
  table=inet router_egress_activity
  chain=forward_activity
  hook=forward priority 0 policy accept
  counters_per_peer=2
  out_rule=iif wg_paid oif transit_vpn ip saddr TUNNEL_IP
  in_rule=iif transit_vpn oif wg_paid ip daddr TUNNEL_IP
  active_delta=out+in packets/bytes over sample window
  not_metric=WireGuard handshake/keepalive alone

generated_artifacts:
  candidate_router_egress_activity.nft
  counter_plan_rows.json
  sampler_contract.json

safety:
  read-only design step
  candidate nft not applied
  VM100 unchanged
  VM101 unchanged
  VM121 DB unchanged
  public_index_rebuilt=True

success_checks:
  vm121_read_model_collected=True
  postgres_container_found=True
  leases_query_ok=True
  settings_query_ok=True
  targets_query_ok=True
  enabled_peer_count_five=True
  lease_rows_five=True
  idle_leases_five=True
  active_leases_zero=True
  forced_leases_zero=True
  pending_jobs_zero=True
  vm100_inventory_collected=True
  vm100_wg_paid_l3_device_detected=True
  vm100_transit_vpn_l3_device_detected=True
  vm100_wg_paid_up_or_present=True
  vm100_transit_vpn_present=True
  vm100_wg_paid_peer_count_five=True
  vm100_allowed_ip_count_five=True
  vm100_selector_rows_five=True
  vm101_slot_map_collected=True
  vm101_cs1_to_vpn3_seen=True
  vm101_cs2_to_vpn4_seen=True
  vm101_cs3_to_vpn5_seen=True
  vm101_cs4_to_vpn1_seen=True
  vm101_cs5_to_vpn2_seen=True
  counter_plan_rows_five=True
  counter_plan_two_counters_per_peer=True
  candidate_nft_created=True
  candidate_nft_has_forward_hook=True
  candidate_nft_has_out_and_in_rules=True
  sampler_contract_created=True
  public_report_created=True
  public_index_rebuilt=True

expected_absence:
  private_material_published=False
  manual_agent_service_start_used=False
  vm100_changed=False
  vm101_changed=False
  vm121_changed=False
  activity_table_already_present_before_implementation=False
  candidate_nft_applied=False
  lease_rows_updated=False
  force_mode_enabled=False
  rebalance_paused=False

warnings:
  - STEP_044G is read-only design/inventory; candidate nft is generated but not applied.
  - Next implementation step should install a persistent VM100 init script/service for router_egress_activity counters and a read/parser tool.
  - Activity should be based on useful inner traffic both directions, not WireGuard handshake/keepalive.

all_ok=True
decision=PASS_STEP_044G_RUNTIME_EGRESS_ACTIVITY_COUNTERS_DESIGN
next_step=STEP_044H_RUNTIME_EGRESS_ACTIVITY_COUNTERS_IMPLEMENT_VM100
LOCAL_REPORT=http://127.0.0.1:8099/r/e94a0859747d7b96f29c7fdafc2d0351ba603bb0a7e9e5a4/20260709-133108_step044g_runtime_egress_activity_counters_design/
TRYCF_REPORT=https://helena-background-beam-harry.trycloudflare.com/r/e94a0859747d7b96f29c7fdafc2d0351ba603bb0a7e9e5a4/20260709-133108_step044g_runtime_egress_activity_counters_design/