Artifacts
Report
=== STEP_044G RESULT ===
step=STEP_044G_RUNTIME_EGRESS_ACTIVITY_COUNTERS_DESIGN
mode=READONLY_DESIGN_VM100_INNER_TRAFFIC_ACTIVITY_COUNTERS_FOR_RUNTIME_EGRESS_ALLOCATOR
db_summary:
enabled_peers=5
lease_rows=5
active_leases=0
idle_leases=5
forced_leases=0
pending_jobs=0
vm100_detected_interfaces:
wg_paid_l3_device=wg_paid
transit_vpn_l3_device=eth2
transit_direct_l3_device=eth0
activity_counter_design:
table=inet router_egress_activity
chain=forward_activity
hook=forward priority 0 policy accept
counters_per_peer=2
out_rule=iif wg_paid oif transit_vpn ip saddr TUNNEL_IP
in_rule=iif transit_vpn oif wg_paid ip daddr TUNNEL_IP
active_delta=out+in packets/bytes over sample window
not_metric=WireGuard handshake/keepalive alone
generated_artifacts:
candidate_router_egress_activity.nft
counter_plan_rows.json
sampler_contract.json
safety:
read-only design step
candidate nft not applied
VM100 unchanged
VM101 unchanged
VM121 DB unchanged
public_index_rebuilt=True
success_checks:
vm121_read_model_collected=True
postgres_container_found=True
leases_query_ok=True
settings_query_ok=True
targets_query_ok=True
enabled_peer_count_five=True
lease_rows_five=True
idle_leases_five=True
active_leases_zero=True
forced_leases_zero=True
pending_jobs_zero=True
vm100_inventory_collected=True
vm100_wg_paid_l3_device_detected=True
vm100_transit_vpn_l3_device_detected=True
vm100_wg_paid_up_or_present=True
vm100_transit_vpn_present=True
vm100_wg_paid_peer_count_five=True
vm100_allowed_ip_count_five=True
vm100_selector_rows_five=True
vm101_slot_map_collected=True
vm101_cs1_to_vpn3_seen=True
vm101_cs2_to_vpn4_seen=True
vm101_cs3_to_vpn5_seen=True
vm101_cs4_to_vpn1_seen=True
vm101_cs5_to_vpn2_seen=True
counter_plan_rows_five=True
counter_plan_two_counters_per_peer=True
candidate_nft_created=True
candidate_nft_has_forward_hook=True
candidate_nft_has_out_and_in_rules=True
sampler_contract_created=True
public_report_created=True
public_index_rebuilt=True
expected_absence:
private_material_published=False
manual_agent_service_start_used=False
vm100_changed=False
vm101_changed=False
vm121_changed=False
activity_table_already_present_before_implementation=False
candidate_nft_applied=False
lease_rows_updated=False
force_mode_enabled=False
rebalance_paused=False
warnings:
- STEP_044G is read-only design/inventory; candidate nft is generated but not applied.
- Next implementation step should install a persistent VM100 init script/service for router_egress_activity counters and a read/parser tool.
- Activity should be based on useful inner traffic both directions, not WireGuard handshake/keepalive.
all_ok=True
decision=PASS_STEP_044G_RUNTIME_EGRESS_ACTIVITY_COUNTERS_DESIGN
next_step=STEP_044H_RUNTIME_EGRESS_ACTIVITY_COUNTERS_IMPLEMENT_VM100
LOCAL_REPORT=http://127.0.0.1:8099/r/e94a0859747d7b96f29c7fdafc2d0351ba603bb0a7e9e5a4/20260709-133108_step044g_runtime_egress_activity_counters_design/
TRYCF_REPORT=https://helena-background-beam-harry.trycloudflare.com/r/e94a0859747d7b96f29c7fdafc2d0351ba603bb0a7e9e5a4/20260709-133108_step044g_runtime_egress_activity_counters_design/