# kit-busrouter Configuration and operational notes for the bus-fleet edge routers. ## Hardware **GL.iNet GL-XE3000** (5G "Puli") running OpenWrt. LAN address `192.168.8.1`, login `root`. ## Management access Routers are managed out-of-band over a **WireGuard tunnel** to the busfleet hub. Each router dials the hub and mgmt SSH is allowed *inbound over the tunnel only* — never exposed on the WAN. | Item | Value | |------|-------| | WG client interface / firewall zone | `wgclient1` (`proto=wgclient`) | | Router tunnel IP | `10.88.0.2/32` | | Hub tunnel IP | `10.88.0.1` | | Hub endpoint | `167.172.237.162:51820` (UDP) | | Tunnel subnet | `10.88.0.0/24` | | Inbound mgmt SSH rule | `Allow-WG-mgmt-SSH` — tcp/22 from `10.88.0.0/24`, `src` zone **`wgclient1`** | | Hub jump key | `busfleet-hub-jump` (ed25519) in `/etc/dropbear/authorized_keys`, perms `600` | The hub reaches a router with: ```sh ssh -J busfleet-hub-jump root@10.88.0.2 # over the established tunnel ``` ## Docs - [docs/mgmt-tunnel-ssh.md](docs/mgmt-tunnel-ssh.md) — provisioning and troubleshooting inbound mgmt SSH over the WireGuard tunnel.