feat: kit-busrouter v2.0 — complete Synology + GL fleet router platform
Includes: - package/ GL-XE3000 kit-busrouter (opkg) - scripts/provision.sh (GL) and provision-synology.sh (Synology) - syno-balance/ — new WAN balancer replacing aiwanbal (SmartWAN adapter) - kit-connect/ — unified connectivity SPK (Tailscale + reverse SSH) - docs/deployment/synology-rt2600ac-checklist.md — 62-point checklist - docs/provisioning/device-identity.md — fleet identity spec - docs/pilot/checklist.md — field pilot validation - x4078_20260721.dss — reference config backup Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,34 @@
|
||||
# kit-busrouter
|
||||
|
||||
Configuration and operational notes for the bus-fleet edge routers.
|
||||
|
||||
## Hardware
|
||||
|
||||
**GL.iNet GL-XE3000** (5G "Puli") running OpenWrt. LAN address `192.168.8.1`, login `root`.
|
||||
|
||||
## Management access
|
||||
|
||||
Routers are managed out-of-band over a **WireGuard tunnel** to the busfleet hub. Each
|
||||
router dials the hub and mgmt SSH is allowed *inbound over the tunnel only* — never
|
||||
exposed on the WAN.
|
||||
|
||||
| Item | Value |
|
||||
|------|-------|
|
||||
| WG client interface / firewall zone | `wgclient1` (`proto=wgclient`) |
|
||||
| Router tunnel IP | `10.88.0.2/32` |
|
||||
| Hub tunnel IP | `10.88.0.1` |
|
||||
| Hub endpoint | `167.172.237.162:51820` (UDP) |
|
||||
| Tunnel subnet | `10.88.0.0/24` |
|
||||
| Inbound mgmt SSH rule | `Allow-WG-mgmt-SSH` — tcp/22 from `10.88.0.0/24`, `src` zone **`wgclient1`** |
|
||||
| Hub jump key | `busfleet-hub-jump` (ed25519) in `/etc/dropbear/authorized_keys`, perms `600` |
|
||||
|
||||
The hub reaches a router with:
|
||||
|
||||
```sh
|
||||
ssh -J busfleet-hub-jump root@10.88.0.2 # over the established tunnel
|
||||
```
|
||||
|
||||
## Docs
|
||||
|
||||
- [docs/mgmt-tunnel-ssh.md](docs/mgmt-tunnel-ssh.md) — provisioning and troubleshooting inbound
|
||||
mgmt SSH over the WireGuard tunnel.
|
||||
Reference in New Issue
Block a user